5.1 Designing Annual Auditing & Monitoring Work Plans & Risk-Based Sampling
Key Takeaways
- Monitoring consists of ongoing, operational reviews conducted by management within daily workflows, whereas auditing involves formal, independent, objective evaluations executed by compliance or internal audit.
- Annual compliance audit work plans must be risk-based, driven by internal risk assessments, previous audit findings, OIG Work Plan priorities, RAC/UPIC focus areas, and billing data analytics.
- Statistically valid random sampling (SVRS) allows healthcare organizations to project audit findings and financial error rates across a total population of claims with measurable confidence and precision.
- RAT-STATS is the free, official OIG statistical software used to compute sample sizes, select random numbers, and calculate extrapolated overpayments for healthcare audits and self-disclosures.
5.1 Designing Annual Auditing & Monitoring Work Plans & Risk-Based Sampling
Distinguishing Monitoring vs. Auditing
In healthcare compliance, the terms monitoring and auditing are frequently used together, yet they represent two distinct operational functions within an effective compliance program. The Department of Health and Human Services Office of Inspector General (OIG) emphasizes that both functions are necessary to prevent, detect, and correct non-compliance, but they differ fundamentally in terms of independence, frequency, scope, and operational ownership.
Monitoring refers to ongoing, real-time, or periodic operational reviews conducted by management and operational personnel within their respective departments. The primary goal of monitoring is to assess whether daily operational processes, internal controls, and clinical/billing workflows are functioning as intended. For example, a billing department manager reviewing ten randomly selected claim files each week to verify that pre-authorization codes are attached is conducting monitoring. Monitoring is built into normal business operations, provides immediate feedback, and allows management to make prompt operational adjustments.
Auditing, by contrast, is a formal, independent, and objective evaluation conducted by individuals who do not have operational responsibility for the processes being reviewed. Auditing is typically performed by the Compliance Department, an internal audit team, or external independent consultants. The primary purpose of an audit is to evaluate compliance with specific federal and state healthcare laws, billing rules, coding standards, and internal policies. Audits follow a structured audit protocol, utilize defined sampling methodologies, and produce formal written audit reports submitted directly to the Chief Compliance Officer (CCO), Executive Leadership, and the Board of Directors.
| Attribute | Monitoring | Auditing |
|---|---|---|
| Primary Responsibility | Operational management & departmental supervisors | Independent compliance auditors, internal audit, or external experts |
| Objectivity / Independence | Operational (low to moderate independence) | High independence (auditor has no operational duties in the area audited) |
| Frequency | Ongoing, continuous, daily, or monthly workflow reviews | Scheduled periodically (e.g., annual work plan, quarterly, or ad-hoc) |
| Methodology | Informal spot-checks, quality control sampling, dashboard tracking | Formal audit protocols, statistically valid sampling, structured testing |
| Primary Reporting Line | Department management, operational leaders, CCO | Chief Compliance Officer, Executive Committee, Board Audit Committee |
| Main Objective | Verify operational control adherence in real-time | Evaluate regulatory compliance and quantify risk/financial exposure |
Developing a Risk-Based Annual Compliance Work Plan
An effective compliance auditing and monitoring program cannot operate reactively or randomly. The OIG expects healthcare organizations to establish a formal Annual Compliance Audit Work Plan that targets high-risk operational, clinical, and financial areas. The annual work plan must be risk-based, meaning audit resources are deployed where the potential for regulatory non-compliance, financial overpayment, or patient harm is highest.
Sources of Compliance Risk Intelligence
To build a robust risk-based audit plan, the Chief Compliance Officer and Compliance Committee must aggregate and analyze risk signals from both internal and external sources:
-
Internal Risk Intelligence Sources:
- Previous Audit Findings: Unresolved findings or high error rates from prior internal or external audits.
- Hotline & Internal Reporting Trends: Spikes in complaints regarding specific departments, coding practices, or physician documentation.
- Data Analytics & Outlier Reports: Outbound billing data showing high utilization of specific modifiers, billing above peer benchmarks, or high denial rates.
- Annual Enterprise Compliance Risk Assessment: Risk scoring and prioritization conducted across clinical, operational, financial, and privacy domains.
- Operational Changes: Implementation of new Electronic Health Record (EHR) systems, acquisition of new physician practices, or launching new service lines.
-
External Risk Intelligence Sources:
- OIG Annual Work Plan: The OIG publishes monthly updates to its Work Plan detailing ongoing and upcoming federal audits, evaluations, and enforcement focus areas (e.g., modifier 25 usage, telehealth billing, inpatient rehabilitation therapy hours).
- CMS Medicare Learning Network (MLN) Bulletins: National coverage updates, billing rule revisions, and Transmittals issued by the Centers for Medicare & Medicaid Services (CMS).
- MAC, RAC, and UPIC Focus Areas: Audit topics published by Medicare Administrative Contractors (MACs), Recovery Audit Contractors (RACs), and Unified Program Integrity Contractors (UPICs).
- OIG Advisory Opinions & Fraud Alerts: Guidance issued by HHS-OIG regarding Anti-Kickback Statute (AKS) and Stark Law risks.
- Department of Justice (DOJ) Enforcement Actions: Recent False Claims Act (FCA) settlements and enforcement actions within the organization's geographic region or healthcare sector.
Workflow of Annual Work Plan Development
Developing the annual work plan follows a systematic workflow:
- Risk Identification: Brainstorm and list potential audit topics from internal and external risk intelligence sources.
- Risk Scoring & Prioritization: Evaluate each potential audit topic based on impact (financial risk, regulatory exposure, reputational damage) and likelihood of occurrence.
- Resource & Capability Allocation: Determine available auditor hours, budget, and specialized external expertise required.
- Work Plan Draft & Governance Approval: Present the proposed annual audit work plan to the Compliance Committee for review and to the Board of Directors (or Audit/Compliance Committee) for formal approval.
- Periodic Review & Dynamic Re-alignment: Maintain flexibility within the work plan to accommodate emergent high-risk issues, government subpoenas, or urgent internal hotline reports during the plan year.
Sampling Methodologies in Healthcare Compliance
When conducting compliance audits, reviewing 100% of claims or patient records is rarely feasible due to resource constraints. Compliance professionals must master sampling methodologies to draw valid, defensible conclusions about large populations of claims.
Statistically Valid Random Sampling (SVRS)
Statistically Valid Random Sampling (SVRS) is the gold standard for compliance auditing when an organization needs to estimate total error rates or extrapolate financial overpayments across a broad population of claims. When conducting a self-disclosure to the OIG or CMS, an SVRS is mandatory under the OIG Self-Disclosure Protocol (SDP).
Key statistical concepts governing SVRS include:
- Universe (Population): The complete set of items under review (e.g., all Medicare Part B claims submitted by a clinic during a two-year period).
- Sampling Frame: The actual list of items from which the sample is drawn.
- Sample Size: The number of items selected from the frame. The sample size must be calculated using statistical principles rather than arbitrary rules of thumb.
- Confidence Level: The probability that the true population value falls within the calculated confidence interval. Healthcare compliance audits typically utilize a 90% or 95% confidence level.
- Precision (Margin of Error): The measure of how close the sample estimate is to the true population value. The OIG SDP generally requires a precision rate of 25% or tighter.
- Financial Extrapolation: Applying the net error rate calculated from the random sample to the total dollar value of the universe to determine the estimated total overpayment. Under the OIG SDP, when precision is wider than 25%, the organization must repay using the lower confidence limit (LCL) of the point estimate to ensure conservatism.
RAT-STATS Statistical Software
RAT-STATS is a free statistical software package developed and maintained by the HHS Office of Inspector General’s Regional Financial Audit staff. It is widely recognized as the industry standard tool for statistical sampling in healthcare compliance audits.
Primary applications of RAT-STATS include:
- Generating Random Numbers: Selecting unbiased random samples from a populated dataset.
- Sample Size Determination: Calculating exact sample size requirements based on desired confidence levels, expected error rates, and population size.
- Single-Stage & Stratified Sampling: Supporting simple random sampling or stratified sampling (dividing the population into distinct subgroups, such as low-dollar vs. high-dollar claims, to reduce variance).
- Overpayment Estimation: Calculating the statistical point estimate, standard error, and upper/lower confidence bounds for financial overpayments across audited claim universes.
Non-Statistical (Targeted / Judgmental) Sampling
Non-statistical sampling (also referred to as judgmental, targeted, or convenience sampling) involves selecting claims based on specific risk criteria rather than random selection. For instance, an auditor might select all claims billed with Modifier 59 by a single physician whose documentation has historically been incomplete.
While targeted sampling is highly effective for identifying specific compliance vulnerabilities, educating providers, or establishing whether a problem exists, findings from non-statistical samples cannot be statistically extrapolated across the entire population of claims. Attempting to calculate a total financial overpayment by extrapolating a targeted sample is legally and statistically invalid.
Real-World Healthcare Compliance Scenario: Work Plan Execution
Scenario: Apex Health System, a 400-bed regional hospital network, is developing its Annual Compliance Audit Work Plan. During the risk identification phase, the CCO reviews the latest OIG Work Plan updates and notes heightened federal scrutiny on Modifier 25 (billing a significant, separately identifiable Evaluation and Management [E/M] service on the same day as a minor procedure).
An internal data query reveals that Apex's outpatient orthopedic clinic has billed Modifier 25 on 62% of all minor procedure encounters over the past 12 months—compared to a regional CMS benchmark of 24%.
Compliance Action:
- Work Plan Integration: The CCO adds an "Outpatient Orthopedic Modifier 25 Documentation Audit" to the Annual Work Plan as a High-Priority project.
- Phase 1 (Probe Audit): Compliance selects a targeted non-statistical sample of 30 claims (5 claims from each of 6 orthopedic surgeons) to evaluate medical record documentation. The probe audit reveals a 45% error rate, where the E/M service was either not separately identifiable or lacked documentation of a distinct medical decision-making process.
- Phase 2 (Expanded SVRS Audit): Because the probe audit error rate exceeded acceptable limits (>10%), Compliance utilizes RAT-STATS to select a Statistically Valid Random Sample of 120 claims from the total 12-month universe of 1,800 Modifier 25 claims.
- Extrapolation & Remediation: The SVRS audit yields a 38% improper payment rate. Compliance calculates the point estimate overpayment using RAT-STATS, coordinates with Legal Counsel to determine 60-Day Overpayment Rule refund obligations, and establishes mandatory provider documentation retraining.
Which of the following best characterizes the operational distinction between compliance monitoring and compliance auditing?
A compliance officer is preparing to conduct an expanded billing audit for an OIG Voluntary Self-Disclosure. Which software tool is officially designated and maintained by the HHS-OIG for sample size calculation and overpayment estimation?
When conducting a risk-based compliance audit, what is the primary limitation of utilizing a non-statistical (targeted or judgmental) sampling methodology?