Government Audit Programs: RAC, MAC, CERT, ZPIC/UPIC, and MIC

Key Takeaways

  • Medicare Administrative Contractors (MACs) execute routine claims processing, Medical Review (MR), Local Coverage Determinations (LCDs), and the Targeted Probe and Educate (TPE) audit program.
  • Recovery Audit Contractors (RACs) are statutorily mandated entities compensated on a contingency fee basis to identify and recover Medicare overpayments and underpayments using automated and complex reviews.
  • Unified Program Integrity Contractors (UPICs) (formerly ZPICs) specialize in investigating suspected healthcare fraud, waste, and abuse, possessing authority to institute payment suspensions and coordinate with law enforcement.
  • Comprehensive Error Rate Testing (CERT) calculates the national Medicare improper payment rate through random sampling, providing macro-level data that drives target selection for MACs, RACs, and UPICs.
Last updated: July 2026

Government Audit Programs: RAC, MAC, CERT, ZPIC/UPIC, and MIC

Federal and state governments employ a sophisticated network of specialized audit contractors to safeguard public healthcare funds, recover overpayments, detect improper coding, and prosecute healthcare fraud. For Certified Professional Medical Auditors (CPMAs), navigating this complex audit ecosystem requires a deep understanding of each contractor's specific legal mandate, audit authority, target selection methodology, and appellate procedures. This section details Medicare Administrative Contractors (MACs) and Targeted Probe and Educate (TPE), Recovery Audit Contractors (RACs), Comprehensive Error Rate Testing (CERT), Zone/Unified Program Integrity Contractors (ZPICs/UPICs), and Medicaid Integrity Contractors (MICs).


1. Medicare Administrative Contractors (MACs) and Targeted Probe and Educate (TPE)

Medicare Administrative Contractors (MACs) are private healthcare insurers contracted by CMS to process Medicare Fee-for-Service (FFS) Part A and Part B claims, enroll providers, issue Local Coverage Determinations (LCDs), and execute Medical Review (MR) programs.

Targeted Probe and Educate (TPE) Program

CMS established the Targeted Probe and Educate (TPE) program to assist providers in improving billing accuracy through customized education rather than immediate financial punishment.

TPE Operational Rules:

  • Target Selection: TPE audits are data-driven, targeting providers who exhibit high billing error rates, unusual billing patterns, or statistical coding deviations compared to regional peers.
  • Three-Round Structure:
    • Round 1 Probe: The MAC requests medical records for 20 to 40 claims.
    • 1-on-1 Education: If errors are identified, the MAC conducts a mandatory telephonic or in-person 1-on-1 educational session explaining specific documentation deficiencies.
    • 45-Day Corrective Action: The provider is given 45 days to implement internal corrective action plans and process improvements before Round 2 begins.
    • Rounds 2 and 3: If the error rate remains unacceptably high, the MAC repeats the 20–40 claim probe audit up to two additional times.
  • Escalation Consequences: If a provider fails to pass after Round 3, the MAC refers the provider to CMS for severe administrative action, including 100% Prepayment Review, extrapolation of overpayments, or referral to a UPIC for fraud investigation.

2. Recovery Audit Contractors (RACs)

Authorized by the Medicare Modernization Act (MMA) of 2003 and expanded nationwide under the Tax Relief and Health Care Act of 2006, Recovery Audit Contractors (RACs) are independent commercial entities contracted by CMS to identify and recover improper Medicare overpayments and underpayments.

Contingency Fee Structure

Unlike standard government contractors, RACs are paid on a contingency fee basis—receiving a percentage (typically 9% to 12.5%) of all overpayments recovered from providers, as well as a percentage for identifying underpayments returned to providers.

RAC Audit Methodologies

RACs utilize three distinct review mechanisms:

  1. Automated Reviews: Computerized data analysis algorithms detect clear-cut coding errors (such as billing mutually exclusive CPT codes, exceeding Medically Unlikely Edits [MUEs], or duplicate claim submissions) without requesting paper medical records.
  2. Semi-Automated Reviews: Automated data prompts trigger a targeted notification requiring the provider to submit medical documentation to verify specific billing criteria.
  3. Complex Reviews: Human reviewers (registered nurses or certified coders) analyze complete paper or electronic medical records to evaluate medical necessity, DRG coding validation, and documentation compliance.

Statutory Limits and Discussion Period

  • Additional Documentation Request (ADR) Limits: CMS imposes strict limits on the number of medical records a RAC can request from a provider every 45 days, based on the provider's NPI and prior billing volume.
  • Discussion Period: Before a RAC issues a formal overpayment demand, the provider has a mandatory 30-day Discussion Period to submit supplemental documentation or dispute the finding directly with the RAC auditor.

3. Comprehensive Error Rate Testing (CERT) Program

The Comprehensive Error Rate Testing (CERT) program is managed by CMS to measure the national Medicare Fee-for-Service improper payment rate, fulfilling statutory requirements under the Improper Payments Information Act (IPIA).

Key Features of CERT:

  • Random Statistical Sampling: CERT randomly selects a representative sample of processed Medicare claims across all MAC jurisdictions nationwide.
  • Documentation Review: The CERT documentation contractor requests medical records from providers, and independent medical reviewers evaluate whether the claim was correctly coded and medically necessary.
  • Macro-Level Focus: CERT is non-punitive in terms of direct fraud prosecution. Its primary purpose is calculating national error rates reported annually to Congress. However, individual claim errors identified by CERT must be repaid to the MAC, and national CERT error trends directly shape future OIG Work Plans, RAC audit topics, and MAC LCD policies.

4. Zone / Unified Program Integrity Contractors (ZPICs / UPICs)

Unified Program Integrity Contractors (UPICs)—which consolidated the legacy Zone Program Integrity Contractors (ZPICs) and Medicaid Program Integrity Contractors—are the investigative enforcement arm of CMS dedicated to investigating suspected Healthcare Fraud, Waste, and Abuse (FWA).

UPIC Mandate and Aggressive Tactics

UPICs operate across five regional zones covering both Medicare and Medicaid. Unlike MACs or RACs that perform routine medical review, UPICs step in when there is a credible allegation or statistical indication of intentional fraud.

UPIC Operational Powers:

  • Unannounced On-Site Audits: UPIC investigators appear without prior notice to inspect facilities, copy patient records, and interview clinical staff and patients.
  • Advanced Data Mining: UPICs utilize sophisticated algorithms to identify extreme billing outliers (e.g., billing 24 hours of care in a day, abnormal modifier utilization).
  • Payment Suspensions: UPICs have statutory authority to recommend that CMS institute an immediate Payment Suspension, withholding all Medicare/Medicaid claim reimbursements during an active fraud investigation.
  • Law Enforcement Referrals: UPICs work closely with the HHS-OIG, FBI, and Department of Justice (DOJ) to build criminal indictments and civil False Claims Act cases.

5. Medicaid Integrity Contractors (MICs)

Created under the Deficit Reduction Act (DRA) of 2005, the Medicaid Integrity Program (MIP) established Medicaid Integrity Contractors (MICs) to combat fraud and improper payments in state Medicaid programs.

Three Operational Categories of MICs:

  1. Review MICs: Analyze state Medicaid statistical data to identify billing trends, anomalies, and high-risk provider groups.
  2. Audit MICs: Perform field audits and post-payment reviews of specific Medicaid providers.
  3. Education MICs: Develop educational materials and training programs for Medicaid providers and state compliance staff.

6. Comparative Matrix of Government Audit Contractors

ContractorPrimary MissionCompensationMethod / SamplingKey Enforcement Outcome
MAC (TPE)Medical review & provider educationAdministrative ContractTargeted probe (20–40 charts)3-round probe; 100% prepay review on failure
RACOver/underpayment recoveryContingency Fee (%)Automated & Complex reviewsOverpayment demand letter + statutory interest
CERTCalculate national improper payment rateFederal ContractRandom statistical sampleMacro reporting to Congress; claim refund
UPIC / ZPICFraud investigation & prosecutionFederal ContractOutlier mining & fraud tipsPayment suspension, site visits, OIG/DOJ referral
MICMedicaid program integrity & auditFederal ContractState Medicaid data analyticsState Medicaid overpayment recovery
Test Your Knowledge

A multispecialty clinic receives an official notice from its Medicare Administrative Contractor (MAC) stating that 30 Medicare Part B claims for Modifier -25 have been selected for a Round 1 audit under the Targeted Probe and Educate (TPE) program. What happens if the MAC identifies a 25% error rate during this Round 1 review?

A
B
C
D
Test Your Knowledge

An unannounced team of investigators arrives at an outpatient surgical center, presents credentials from a Unified Program Integrity Contractor (UPIC), demands immediate access to electronic medical records, and interviews clinical staff regarding suspected phantom billing. What distinguishes a UPIC audit from a standard RAC audit?

A
B
C
D
Test Your Knowledge

A hospital finance department notices that a Recovery Audit Contractor (RAC) has issued a semi-automated audit determination asserting an overpayment on 15 inpatient hospital claims. Under CMS RAC guidelines, what initial procedural step is available to the hospital before a formal overpayment demand is issued?

A
B
C
D
Test Your Knowledge

The Comprehensive Error Rate Testing (CERT) contractor contacts a family medicine practice requesting 20 patient charts for claims processed six months ago. What is the primary purpose of the CERT audit program?

A
B
C
D