Overview
Program Integrity is the umbrella term for all activities CMS and HHS conduct to prevent, detect, and recover from fraud, waste, and abuse in federal healthcare programs. It is a $BB-dollar scale enterprise: CMS publishes annual improper-payment rates (CERT), OIG recovers multiple billions annually, and dedicated enforcement contractors operate continuously across claim-level review, pattern analysis, and targeted audits. Understanding program integrity is essential for any provider billing federal programs.
The CMS Program Integrity Manual (CMS Publication 100-08) is the operational reference for Medicare program-integrity activities — coverage analysis, claim review, audit procedures, appeal rights, and enforcement contractor responsibilities. It defines the rules under which RACs, MACs, ZPICs/UPICs, and SMRC operate. Providers who understand the manual know what auditors look for and how audit processes mechanically work.
Key enforcement contractor types include: Medicare Administrative Contractors (MACs), who process claims and conduct targeted probe-and-educate (TPE) audits on high-risk patterns; Recovery Audit Contractors (RACs), who conduct post-payment audits for overpayments and underpayments with contingency-fee compensation; Unified Program Integrity Contractors (UPICs), which replaced ZPICs for Medicaid/Medicare integration and handle complex fraud investigations; Supplemental Medical Review Contractors (SMRC), which review specific topics identified by CMS or OIG; and Comprehensive Error Rate Testing (CERT) contractors, which sample claims to measure improper-payment rates.
Provider-level responses to program-integrity activity include: compliance programs that meet OIG guidance standards; auditing and monitoring programs that mirror external-audit focus areas; documentation practices that support the claims submitted; response procedures for ADR (additional documentation request) letters; and overpayment refund processes that meet the 60-day ACA deadline. Mature operations integrate program-integrity awareness into every compliance-adjacent workflow.
Denial and recoupment exposure from program integrity activity is substantial. An organization with insufficient program-integrity orientation may face TPE audit expansion to full probe, RAC targeting, UPIC complex audits, and potentially OIG investigations with FCA exposure. Organizations that maintain strong program-integrity hygiene — robust documentation, internal audits, responsive ADR handling — typically see routine audit activity stay routine and minimize escalation.
Program Integrity is one of the compliance areas where documentation discipline determines audit outcomes more than policy sophistication. Practices that invest in clean Program Integrity records, consistent recovery audit contractor workflows, and auditable false claims act evidence come out of OIG, RAC, and MAC audits with materially smaller recoupment exposure than practices with equivalent policies but weaker paper trails.
From a board-reporting standpoint, Program Integrity belongs in the compliance committee's quarterly dashboard. The reporting line should include volume, exception rate, and any open remediation action; reviewers tie Program Integrity metrics to the broader compliance program KPIs so an emerging Program Integrity risk surfaces before it becomes a formal finding. Pairing the Program Integrity trend with recovery audit contractor gives the committee a single view of whether the control environment is strengthening or drifting.
Industry benchmark
CMS Publication 100-08 Program Integrity Manual. CMS CERT annual improper-payment report. OIG annual work plan and semiannual report to Congress.
Worked example
A physician practice receives a TPE round-1 ADR on E/M level-4 and 5 services. The MAC reviews 20 claims and finds 6 with documentation not supporting the level coded. Error rate 30%. The practice completes mandatory education and enters round 2. Round 2 finds error rate 8% after process improvements. TPE closes without escalation. Had the practice failed round 2 (still high error rate), round 3 would have followed; failure at round 3 can escalate to RAC or UPIC review.
Frequently asked questions — Program Integrity
What is CERT?
Comprehensive Error Rate Testing — the CMS program that samples claims annually to measure the Medicare improper-payment rate. CERT findings drive national program-integrity priorities and audit contractor focus areas.
What's the difference between MAC and RAC audits?
MACs are CMS claim-processing contractors who also conduct prepayment and post-payment reviews including TPE. RACs are separate contractors paid on contingency to find overpayments (and underpayments) through claim audits. Their scopes and compensation structures differ but both feed back into overall program integrity.
How do we respond to an ADR letter?
Within 45 days (typical Medicare deadline). Gather all relevant documentation, address each claim in the request specifically, and submit through the specified channel. Missing the deadline forfeits the case and causes automatic denial with full recoupment.
What is TPE?
Targeted Probe and Educate — a MAC audit program with a graduated structure. Round 1 reviews 20-40 claims; educational feedback follows. Round 2 re-samples with higher stakes; round 3 can escalate to RAC or UPIC review. TPE is one of the most common program-integrity activities providers encounter.
Disclaimer
This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.