Skip to main content
Call
Complianceaka RAC, Medicare RAC, Recovery Auditor

What is Recovery Audit Contractor? Definition, Formula, and Benchmark

Reviewed by QuickIntell RCM Editorial Team · Last reviewed

Updated

Definition

A Recovery Audit Contractor (RAC) is a CMS contractor paid on a contingency-fee basis to identify and recover improper Medicare payments — both overpayments and (less commonly) underpayments. RACs conduct automated and complex post-payment audits on specific CMS-approved audit issues, with a three-year look-back and defined limits on claim-request volume.

Overview

Recovery Audit Contractors (RACs) are CMS contractors paid on a contingency basis to identify and recover improper Medicare payments. The RAC program was established by Congress in 2003 as a pilot, expanded nationally in 2010, and operates continuously today. Four RACs currently hold regional contracts covering different geographic jurisdictions. Each RAC reviews claims for specific CMS-approved audit issues, identifies overpayments (and, less commonly, underpayments), and collects contingency fees on the recovered amounts.

RAC audits come in two forms. Automated reviews are algorithm-based — the RAC identifies overpayments by matching claims against rules without requiring medical record review (e.g., duplicate claims, non-covered services under LCD). Complex reviews require medical-record documentation review and are used for medical-necessity, coding accuracy, and DRG-validation audits. Complex reviews are more expensive per claim but address higher-dollar and harder-to-detect improper payments.

RAC processes are time-bound. Providers receive an ADR (Additional Documentation Request) for complex reviews, typically with a 45-day response window. After RAC determination, providers receive a demand letter with identified overpayment amount and appeal rights. The appeal process has five levels: RAC reconsideration, MAC Redetermination, QIC Reconsideration, ALJ hearing, Medicare Appeals Council, federal court. Each level has strict filing deadlines; missing any window defaults the case.

RAC look-back is limited to three years from the claim payment date. Claim-request volumes are capped per provider based on provider size and prior RAC history. These limits were strengthened in the early 2010s after complaints about RAC audit volume. Current caps make RAC audits a manageable — though still demanding — part of provider compliance workflow.

Operationally, responding to RAC audits requires robust medical-records retrieval, organized response packaging, and timely filing. Providers with good compliance infrastructure typically win 40–60% of RAC denials on first-level appeal. Providers with weaker infrastructure lose on procedure — missing deadlines, incomplete documentation submission — even when the underlying coding and documentation would have supported the claim. Investment in ADR-response workflow has strong ROI for any facility routinely seeing RAC audits.

Recovery Audit Contractor is one of the compliance areas where documentation discipline determines audit outcomes more than policy sophistication. Practices that invest in clean Recovery Audit Contractor records, consistent program integrity workflows, and auditable false claims act evidence come out of OIG, RAC, and MAC audits with materially smaller recoupment exposure than practices with equivalent policies but weaker paper trails.

From a board-reporting standpoint, Recovery Audit Contractor belongs in the compliance committee's quarterly dashboard. The reporting line should include volume, exception rate, and any open remediation action; reviewers tie Recovery Audit Contractor metrics to the broader compliance program KPIs so an emerging Recovery Audit Contractor risk surfaces before it becomes a formal finding. Pairing the Recovery Audit Contractor trend with program integrity gives the committee a single view of whether the control environment is strengthening or drifting.

Industry benchmark

CMS Recovery Audit Program. Historical RAC recoveries: billions collected annually since program expansion. ADR response rate and appeal success rates published in provider benchmarking.

Worked example

A 400-bed hospital receives a RAC ADR for 28 inpatient admissions flagged as potentially not meeting inpatient criteria. The hospital's documentation team responds within 45 days with complete medical records. RAC determination: 12 overpayments identified totaling $184K. The hospital appeals at level 1 (MAC Redetermination) with additional clinical documentation and case-management notes; 8 of 12 denials are reversed. Net recoupment: $62K on 4 admissions.

Frequently asked questions — Recovery Audit Contractor

How are RACs paid?

Contingency fee on recovered overpayments (and underpayments). Rates vary by contract but typically 9–12.5% of recoveries. The contingency structure drives RAC focus on high-volume, high-dollar, clear-cut audit issues.

How far back can a RAC audit?

Three years from the claim payment date. Beyond three years, the RAC cannot review the claim. Some complex reviews covering different Medicare program areas (Medicare Part D, Medicare Advantage encounters) have different look-back rules.

How do we appeal a RAC determination?

Through the five-level Medicare appeal process: Redetermination (MAC, 120 days), Reconsideration (QIC, 180 days), ALJ hearing (60 days after QIC), Medicare Appeals Council (60 days after ALJ), federal court. Each has strict filing windows. Most appeals settle at the first two levels.

Can RACs identify underpayments too?

Yes, and they're paid contingency on underpayments too. In practice, overpayments vastly outnumber identified underpayments — partly because overpayments are easier to identify and partly because some underpayment issues depend on clinical documentation that RACs don't have full access to.

Disclaimer

This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.