Government Audit Programs: RAC, MAC, CERT, ZPIC/UPIC, and MIC
Key Takeaways
- Medicare Administrative Contractors (MACs) execute routine claims processing, Medical Review (MR), Local Coverage Determinations (LCDs), and the Targeted Probe and Educate (TPE) audit program.
- Recovery Audit Contractors (RACs) are statutorily mandated entities compensated on a contingency fee basis to identify and recover Medicare overpayments and underpayments using automated and complex reviews.
- Unified Program Integrity Contractors (UPICs) (formerly ZPICs) specialize in investigating suspected healthcare fraud, waste, and abuse, possessing authority to institute payment suspensions and coordinate with law enforcement.
- Comprehensive Error Rate Testing (CERT) calculates the national Medicare improper payment rate through random sampling, providing macro-level data that drives target selection for MACs, RACs, and UPICs.
Government Audit Programs: RAC, MAC, CERT, ZPIC/UPIC, and MIC
Federal and state governments employ a sophisticated network of specialized audit contractors to safeguard public healthcare funds, recover overpayments, detect improper coding, and prosecute healthcare fraud. For Certified Professional Medical Auditors (CPMAs), navigating this complex audit ecosystem requires a deep understanding of each contractor's specific legal mandate, audit authority, target selection methodology, and appellate procedures. This section details Medicare Administrative Contractors (MACs) and Targeted Probe and Educate (TPE), Recovery Audit Contractors (RACs), Comprehensive Error Rate Testing (CERT), Zone/Unified Program Integrity Contractors (ZPICs/UPICs), and Medicaid Integrity Contractors (MICs).
1. Medicare Administrative Contractors (MACs) and Targeted Probe and Educate (TPE)
Medicare Administrative Contractors (MACs) are private healthcare insurers contracted by CMS to process Medicare Fee-for-Service (FFS) Part A and Part B claims, enroll providers, issue Local Coverage Determinations (LCDs), and execute Medical Review (MR) programs.
Targeted Probe and Educate (TPE) Program
CMS established the Targeted Probe and Educate (TPE) program to assist providers in improving billing accuracy through customized education rather than immediate financial punishment.
TPE Operational Rules:
- Target Selection: TPE audits are data-driven, targeting providers who exhibit high billing error rates, unusual billing patterns, or statistical coding deviations compared to regional peers.
- Three-Round Structure:
- Round 1 Probe: The MAC requests medical records for 20 to 40 claims.
- 1-on-1 Education: If errors are identified, the MAC conducts a mandatory telephonic or in-person 1-on-1 educational session explaining specific documentation deficiencies.
- 45-Day Corrective Action: The provider is given 45 days to implement internal corrective action plans and process improvements before Round 2 begins.
- Rounds 2 and 3: If the error rate remains unacceptably high, the MAC repeats the 20–40 claim probe audit up to two additional times.
- Escalation Consequences: If a provider fails to pass after Round 3, the MAC refers the provider to CMS for severe administrative action, including 100% Prepayment Review, extrapolation of overpayments, or referral to a UPIC for fraud investigation.
2. Recovery Audit Contractors (RACs)
Authorized by the Medicare Modernization Act (MMA) of 2003 and expanded nationwide under the Tax Relief and Health Care Act of 2006, Recovery Audit Contractors (RACs) are independent commercial entities contracted by CMS to identify and recover improper Medicare overpayments and underpayments.
Contingency Fee Structure
Unlike standard government contractors, RACs are paid on a contingency fee basis—receiving a percentage (typically 9% to 12.5%) of all overpayments recovered from providers, as well as a percentage for identifying underpayments returned to providers.
RAC Audit Methodologies
RACs utilize three distinct review mechanisms:
- Automated Reviews: Computerized data analysis algorithms detect clear-cut coding errors (such as billing mutually exclusive CPT codes, exceeding Medically Unlikely Edits [MUEs], or duplicate claim submissions) without requesting paper medical records.
- Semi-Automated Reviews: Automated data prompts trigger a targeted notification requiring the provider to submit medical documentation to verify specific billing criteria.
- Complex Reviews: Human reviewers (registered nurses or certified coders) analyze complete paper or electronic medical records to evaluate medical necessity, DRG coding validation, and documentation compliance.
Statutory Limits and Discussion Period
- Additional Documentation Request (ADR) Limits: CMS imposes strict limits on the number of medical records a RAC can request from a provider every 45 days, based on the provider's NPI and prior billing volume.
- Discussion Period: Before a RAC issues a formal overpayment demand, the provider has a mandatory 30-day Discussion Period to submit supplemental documentation or dispute the finding directly with the RAC auditor.
3. Comprehensive Error Rate Testing (CERT) Program
The Comprehensive Error Rate Testing (CERT) program is managed by CMS to measure the national Medicare Fee-for-Service improper payment rate, fulfilling statutory requirements under the Improper Payments Information Act (IPIA).
Key Features of CERT:
- Random Statistical Sampling: CERT randomly selects a representative sample of processed Medicare claims across all MAC jurisdictions nationwide.
- Documentation Review: The CERT documentation contractor requests medical records from providers, and independent medical reviewers evaluate whether the claim was correctly coded and medically necessary.
- Macro-Level Focus: CERT is non-punitive in terms of direct fraud prosecution. Its primary purpose is calculating national error rates reported annually to Congress. However, individual claim errors identified by CERT must be repaid to the MAC, and national CERT error trends directly shape future OIG Work Plans, RAC audit topics, and MAC LCD policies.
4. Zone / Unified Program Integrity Contractors (ZPICs / UPICs)
Unified Program Integrity Contractors (UPICs)—which consolidated the legacy Zone Program Integrity Contractors (ZPICs) and Medicaid Program Integrity Contractors—are the investigative enforcement arm of CMS dedicated to investigating suspected Healthcare Fraud, Waste, and Abuse (FWA).
UPIC Mandate and Aggressive Tactics
UPICs operate across five regional zones covering both Medicare and Medicaid. Unlike MACs or RACs that perform routine medical review, UPICs step in when there is a credible allegation or statistical indication of intentional fraud.
UPIC Operational Powers:
- Unannounced On-Site Audits: UPIC investigators appear without prior notice to inspect facilities, copy patient records, and interview clinical staff and patients.
- Advanced Data Mining: UPICs utilize sophisticated algorithms to identify extreme billing outliers (e.g., billing 24 hours of care in a day, abnormal modifier utilization).
- Payment Suspensions: UPICs have statutory authority to recommend that CMS institute an immediate Payment Suspension, withholding all Medicare/Medicaid claim reimbursements during an active fraud investigation.
- Law Enforcement Referrals: UPICs work closely with the HHS-OIG, FBI, and Department of Justice (DOJ) to build criminal indictments and civil False Claims Act cases.
5. Medicaid Integrity Contractors (MICs)
Created under the Deficit Reduction Act (DRA) of 2005, the Medicaid Integrity Program (MIP) established Medicaid Integrity Contractors (MICs) to combat fraud and improper payments in state Medicaid programs.
Three Operational Categories of MICs:
- Review MICs: Analyze state Medicaid statistical data to identify billing trends, anomalies, and high-risk provider groups.
- Audit MICs: Perform field audits and post-payment reviews of specific Medicaid providers.
- Education MICs: Develop educational materials and training programs for Medicaid providers and state compliance staff.
6. Comparative Matrix of Government Audit Contractors
| Contractor | Primary Mission | Compensation | Method / Sampling | Key Enforcement Outcome |
|---|---|---|---|---|
| MAC (TPE) | Medical review & provider education | Administrative Contract | Targeted probe (20–40 charts) | 3-round probe; 100% prepay review on failure |
| RAC | Over/underpayment recovery | Contingency Fee (%) | Automated & Complex reviews | Overpayment demand letter + statutory interest |
| CERT | Calculate national improper payment rate | Federal Contract | Random statistical sample | Macro reporting to Congress; claim refund |
| UPIC / ZPIC | Fraud investigation & prosecution | Federal Contract | Outlier mining & fraud tips | Payment suspension, site visits, OIG/DOJ referral |
| MIC | Medicaid program integrity & audit | Federal Contract | State Medicaid data analytics | State Medicaid overpayment recovery |
A multispecialty clinic receives an official notice from its Medicare Administrative Contractor (MAC) stating that 30 Medicare Part B claims for Modifier -25 have been selected for a Round 1 audit under the Targeted Probe and Educate (TPE) program. What happens if the MAC identifies a 25% error rate during this Round 1 review?
An unannounced team of investigators arrives at an outpatient surgical center, presents credentials from a Unified Program Integrity Contractor (UPIC), demands immediate access to electronic medical records, and interviews clinical staff regarding suspected phantom billing. What distinguishes a UPIC audit from a standard RAC audit?
A hospital finance department notices that a Recovery Audit Contractor (RAC) has issued a semi-automated audit determination asserting an overpayment on 15 inpatient hospital claims. Under CMS RAC guidelines, what initial procedural step is available to the hospital before a formal overpayment demand is issued?
The Comprehensive Error Rate Testing (CERT) contractor contacts a family medicine practice requesting 20 patient charts for claims processed six months ago. What is the primary purpose of the CERT audit program?