Compliance Audits and Financial Controls

DME Audits: CERT, TPE, SMRC, RAC, and UPIC

Distinguish review contractors, triggers, timelines, evidence requests, recoupment, and appeal implications.

Estimated time: 65 minutes / Reviewed 2026-07-12

Lesson progress0%

Learning objectives

  • Explain dme audits: cert, tpe, smrc, rac, and upic using current claim facts and official sources.
  • Apply the 13-step workflow to a de-identified reimbursement case.
  • Distinguish administrative, coding, coverage, documentation, and procedural-status questions.
  • Document a bounded conclusion, unresolved facts, and the next supported action.

Core instruction

The acronyms are not interchangeable. CERT measures improper payments through sampled claims; TPE is a MAC-led targeted review and education process; SMRC performs CMS-directed nationwide medical reviews; RAC identifies post-payment overpayments and underpayments; and UPIC investigates potential fraud, waste, and abuse. Read the letter, identify the contractor and authority, preserve the record, and respond to the exact request by its stated deadline.

Compare Medicare review contractors, prepayment and postpayment audits, the complete SMRC timeline, recurring DME documentation failures, appeal timing, and an audit-prevention system.

  • SMRC conducts CMS-directed nationwide reviews of Medicare Part A/B and DMEPOS claims for coverage, coding, payment, billing, and documentation compliance.
  • CERT uses a statistically valid sample to estimate the Medicare FFS improper-payment rate; a CERT error is not automatically a finding of fraud.
  • TPE is run by a MAC and generally combines a targeted claim probe with one-on-one education; traditional rounds usually review 20 to 40 claims and may repeat up to three times.
  • RAC performs post-payment automated or complex reviews to identify and correct overpayments and underpayments; the nationwide Region 5 RAC covers DMEPOS, home health, and hospice.
  • UPIC prevents, detects, and investigates suspected fraud, waste, and abuse and may support payment suspension, revocation, overpayment, or law-enforcement referral actions.
  • An Additional Documentation Request is the mechanism for obtaining records, not the name of a single audit program; the sender determines the review context.
  • The response should prove the billed claim as it existed for the date of service, including eligibility, order, medical necessity, coding, modifiers, delivery, and continued-need or use evidence when applicable.
  • Appeal rights, rebuttal options, escalation paths, and deadlines depend on the contractor, review result, and subsequent MAC action; never assume one program's process applies to another.
  • Review selection may involve national or local vulnerabilities, high-error services, unusual utilization or billing patterns, prior findings, complaints, referrals, and data analysis. A review does not by itself establish wrongdoing, and an SMRC project may target a service nationally rather than one supplier individually.
  • Prepayment review holds or denies payment before funds are released. Postpayment review examines an already paid claim and may lead the MAC to adjust the claim, issue an overpayment demand, accrue interest, and recoup from future payments, creating a larger operational cash-flow risk.
  • The current SMRC Provider Compliance Group flow starts with an ADR and generally allows 45 calendar days from the ADR date for records. After timely records arrive, SMRC generally reviews them within 30 calendar days and sends a Final Review Results letter.
  • A supplier generally has 14 calendar days from the Final Review Results letter to request Discussion and Education and/or notify SMRC of intent to submit additional documentation. The current flowchart provides different submission and review periods depending on the chosen path, so the actual letter controls.
  • The SMRC does not collect the resulting debt itself. It reports improper-payment findings; the MAC adjusts claims and issues the overpayment or underpayment notice, after which standard MAC recovery and appeal procedures apply.
  • A first-level redetermination is generally due within 120 days of the demand letter, but filing by day 30 may be necessary to prevent recoupment beginning around day 41 for overpayments subject to recoupment limitation. Interest timing and the demand letter require immediate review.
  • KX is an attestation that requirements specified in the applicable medical policy are met. It is not a routine formatting modifier, and unsupported KX use can turn a documentation weakness into a broader compliance concern.
  • CMS eliminated remaining CMNs and DIFs for dates of service on or after January 1, 2023. The underlying medical-necessity and coverage evidence did not disappear; the information must be supported by the claim, order, treating record, and other required documentation.
  • Audit-ready means each document proves its own fact without silent assumptions: who, what, when, where, why, author, signature, date, item, quantity, and relationship to the billed claim must be internally clear and consistent with the rest of the record.

Module frame: payment integrity continues after payment

A paid claim can still be reviewed, adjusted, or recouped. Compliance operations must preserve source records, identify overpayments, answer documentation requests, monitor audit findings, and distinguish informational data from controlling coverage or payment decisions.

The strongest defense is not a larger response packet. It is a reproducible pre-bill record showing that eligibility, coding, documentation, delivery, and claim facts were tested before submission.

Deep dive

CERT measures improper payments, TPE targets provider-specific error patterns with education, SMRC performs CMS-directed reviews, RAC identifies overpayments and underpayments, and UPIC investigates program-integrity concerns. Scope, timing, contractor authority, and response rights differ.

  • Prepayment review delays adjudication; postpayment review can create recoupment.
  • An ADR is a deadline-controlled evidence request.
  • Audit response and appeal strategy must remain coordinated.

Review programs

ConceptMeaningOperational control
CERTImproper-payment measurementSampled claim documentation
TPETargeted provider review and educationProbe rounds and corrective action
RAC or SMRCPostpayment reviewIssue-specific evidence and appeal
UPICProgram integrityEscalated compliance and legal coordination

Decision workflow

  1. 01

    Date-stamp the notice and verify the sender, contractor type, claim list, dates of service, requested records, submission channel, and deadline.

    Complete workflow control 1, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  2. 02

    Confirm the request is authentic using official contractor contact information, especially before disclosing beneficiary records.

    Complete workflow control 2, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  3. 03

    Assign one response owner and preserve the complete request, envelope or portal notice, claim image, remittance, communications, and submission evidence.

    Complete workflow control 3, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  4. 04

    Build a claim-by-claim index that maps every requested element to the exact page or file where the reviewer can find it.

    Complete workflow control 4, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  5. 05

    Reconcile the order, treating record, coverage criteria, HCPCS, modifiers, units, delivery, refill, continued need or use, and date-specific policy without altering the historical record.

    Complete workflow control 5, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  6. 06

    Submit through an approved channel before the stated deadline and retain proof of receipt; use esMD when supported by the contractor and workflow.

    Complete workflow control 6, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  7. 07

    Track findings by root cause, assess appeal or other response rights, and correct systemic controls across similar claims without automatically rebilling or refunding unrelated claims.

    Complete workflow control 7, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  8. 08

    Escalate suspected UPIC matters, large extrapolations, payment suspensions, subpoenas, or potential self-disclosure issues to qualified healthcare counsel and compliance leadership.

    Complete workflow control 8, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  9. 09

    For an SMRC response, calendar the 45-day ADR period, create a separate indexed packet for each claim, validate secure delivery, and retain acceptance evidence; request good-cause relief promptly if an extraordinary event prevents timely response.

    Complete workflow control 9, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  10. 10

    When the Final Review Results letter arrives, compare every finding to the submitted index and policy, then calendar the 14-day D&E or re-review election period and the applicable additional-document submission deadline stated in the letter.

    Complete workflow control 10, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  11. 11

    Use D&E to understand rationale and prevention, and use re-review when additional contemporaneous evidence can support the claim. Do not create, alter, backdate, or mischaracterize records after the fact.

    Complete workflow control 11, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  12. 12

    When the MAC demand arrives, reconcile claim adjustments and interest, notify finance and leadership, preserve appeal rights, and target day 30 for redetermination when recoupment limitation applies rather than treating day 120 as the operating deadline.

    Complete workflow control 12, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

  13. 13

    Prevent recurrence with a pre-billing QA gate, date-specific coverage verification, item-level policy checklist, signed-order control, delivery reconciliation, refill and continued-use monitoring, modifier validation, monthly denial review, and risk-based internal sample audits.

    Complete workflow control 13, retain the supporting evidence, and resolve exceptions before moving to the next claim decision.

Worked case

Forty-five-day document request

Known facts

  • An ADR requests records for 20 claims.
  • Files are stored across three systems.
  • Several delivery documents are missing.

Decision question

How should the response be managed?

Analysis

  1. 1. Validate request scope and deadline.
  2. 2. Build a claim-level index and gap log.
  3. 3. Escalate missing evidence without recreating records.

Resolution: Submit an organized, truthful response under the applicable process while preserving appeal and compliance review.

Common failure patterns

Assuming every ADR is routine and missing the significance of the contractor named in the notice.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Sending an unindexed document dump that does not connect evidence to coverage criteria or individual claims.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Submitting only supplier-created forms when the request also requires contemporaneous treating-practitioner records.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Changing, recreating, or backdating historical documentation instead of supplying an accurate record and a clearly labeled explanation when appropriate.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Missing a deadline, failing to retain delivery confirmation, or sending protected information through an unapproved channel.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Treating an improper-payment finding as synonymous with fraud, or treating a UPIC inquiry as an ordinary educational review.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Order failure: missing, incomplete, unsigned, late, or inconsistent order elements, including item description, quantity, practitioner identity, signature, or date.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Medical-record failure: treating notes do not independently establish the condition, functional limitation, test result, or item-specific coverage criterion for the date of service.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Delivery failure: proof does not identify the beneficiary, item, quantity, delivery date, address or method, recipient, or link to the exact billed equipment and accessories.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Continued-need, continued-use, or refill failure: recurring claims lack timely beneficiary contact, affirmative refill request, usage evidence, or policy-specific follow-up.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Coding and modifier failure: product, HCPCS, units, accessories, rental or purchase, laterality, replacement, or KX and liability modifiers do not match the facts and policy.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Eligibility and supplier failure: beneficiary coverage, place of service, ordering practitioner, supplier enrollment, accreditation, licensing, same-or-similar history, or payer jurisdiction is unsupported.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Record-integrity failure: conflicting dates, templated language, unexplained corrections, unsigned entries, illegible records, supplier-generated conclusions, or missing provenance prevent the reviewer from trusting the file.

Why it fails: The conclusion is no longer reliably tied to the controlling facts, source, or procedural status and may produce rejection, denial, incorrect liability, or audit exposure.

Prevention: Reperform the relevant workflow step, identify the accountable owner, and preserve the supporting record or source citation.

Key terms

ADR
Additional Documentation Request seeking records for claim review.
Recoupment
Recovery of an alleged overpayment through offset or repayment processes.

Field checklist

  • Contractor and authority
  • Claims and dates
  • Deadline
  • Evidence index
  • Gap escalation
  • Submission proof

Independent practice

Chapter assignment: DME Audits: CERT, TPE, SMRC, RAC, and UPIC

  1. 1. Answer the worked-case question: How should the response be managed?
  2. 2. Complete the field checklist for a fictional or fully de-identified case: Contractor and authority; Claims and dates; Deadline; Evidence index; Gap escalation; Submission proof.
  3. 3. Build a source log that identifies the controlling publication, effective or reviewed date, and the fact it supports.
  4. 4. Write a one-page finding that separates facts, unresolved evidence, procedural status, owner, deadline, and next action.

Submit or produce

  • DME Audits: CERT, TPE, SMRC, RAC, and UPIC case analysis
  • Completed field checklist
  • Source and evidence log
  • One-page professional finding

Self-evaluation criteria

  • Uses only supplied facts
  • Applies the correct distinction and workflow
  • Cites primary authority
  • Explains the resolution
  • Assigns an operational next step

Key takeaways

  • SMRC conducts CMS-directed nationwide reviews of Medicare Part A/B and DMEPOS claims for coverage, coding, payment, billing, and documentation compliance.
  • CERT uses a statistically valid sample to estimate the Medicare FFS improper-payment rate; a CERT error is not automatically a finding of fraud.
  • TPE is run by a MAC and generally combines a targeted claim probe with one-on-one education; traditional rounds usually review 20 to 40 claims and may repeat up to three times.
  • RAC performs post-payment automated or complex reviews to identify and correct overpayments and underpayments; the nationwide Region 5 RAC covers DMEPOS, home health, and hospice.
  • UPIC prevents, detects, and investigates suspected fraud, waste, and abuse and may support payment suspension, revocation, overpayment, or law-enforcement referral actions.

Related in-depth guide

Knowledge check

Which program primarily measures the Medicare FFS improper-payment rate through sampled claims? Explain why the correct answer is supported and why one alternative fails.

Linked HCPCS records

No HCPCS record is linked to this lesson.

Official sources

Report an Issue