Recovery audit contractors working for the Centers for Medicare and Medicaid Services review providers’ program billings on a post-payment basis, creating substantial financial risks.
Providers facing RAC audits risk being forced to repay Medicare using funds they may or may not have readily available, placing serious strain on operations.
Beyond financial liability, RAC audits can trigger pre-payment review, which can delay valid reimbursements by weeks or even months in some cases.
In situations involving allegations of egregious Medicaid fraud, program exclusion from Medicare entirely is also a very real risk that providers must consider.
“Healthcare services provided under Medicare are subject to strict billing rules and regulations,” said Dr. Nick Oberheiden, Founding Attorney of Oberheiden P.C., adding that “a strategic defense focused on challenging auditors’ allegations of noncompliance is essential.”
RAC auditors operate on a fee-for-service basis, meaning they receive a contingency fee when they help CMS correct what are deemed improper payments from providers.
Because auditors are incentivised to find overpayments, the RAC team is not on the provider’s side and audits tend to focus almost exclusively on identifying reimbursements paid improperly.
The first and most critical step for any targeted provider is to engage experienced Medicare fraud defence counsel promptly, ensuring issues are preserved for any potential appeal down the line.
Providers should also keep copies of all communications with the RAC auditor, including the initial audit notice and all subsequent correspondence, along with billing records, medical records, and compliance programme documentation.
Conducting an internal Medicare billing compliance assessment under the oversight of defence counsel is the third key step, as attorney-client privilege protects the findings from being used against the provider.
If auditors are likely to uncover genuine improper payments, providers must address these proactively, as knowingly ignoring overpayments could trigger a referral to the HHS Office of Inspector General for civil or criminal enforcement.
Providers must also be prepared to defend against false allegations, since flawed conclusions by RAC auditors are not uncommon and it falls to the targeted provider to challenge inaccurate determinations.
Working with defence counsel to develop a custom audit defence strategy is essential, incorporating a clear internal chain of command and a plan for responding to any allegations of noncompliance.
Finally, providers must focus on ensuring ongoing compliance with Medicare billing rules going forward, as even inadvertent coding or documentation errors can lead to serious and lasting consequences.

