Minimum Data Set Accuracy and Financial Reporting

The Minimum Data Set is a federally mandated clinical assessment, but treating it as purely a clinical document misses half the story. Every MDS field a nurse or coordinator codes flows directly into the payment calculation that determines what Medicare and Medicaid pay a skilled nursing facility for that resident's stay, which means MDS accuracy is a financial reporting issue as much as it is a clinical one. This piece walks through why that's true, where the money actually shows up when coding goes wrong, and what auditors and finance teams need to understand about a workflow that most of them didn't design and don't control.
Start with the basics. Every Medicare- or Medicaid-certified nursing home has to complete an MDS assessment for its residents, evaluating functional status, cognitive ability, clinical conditions, and care needs, and under the Patient Driven Payment Model, CMS uses those coded fields, diagnosis codes, therapy minutes, cognitive scores, to sort each resident into clinical categories that set the per-diem Medicare rate. Get one field wrong and the error doesn't stay contained to a single claim; it rides forward through the whole assessment schedule for that resident's stay. The MDS coordinator who enters that data is doing clinical work, but the consequence of a mistake shows up in accounting, not in the chart.
The size of the financial exposure when MDS coding goes wrong
Start with the number that should get any CFO's attention: the improper payment rate for SNF inpatient claims hit 17.9% in 2024, translating to roughly $5.6 billion in projected improper payments, according to CMS's 2024 Medicare Fee-for-Service Supplemental Improper Payment Data. That's not a one-year blip, and the rate climbed from 7.79% in 2021 to 17.2% in 2024, more than doubling in three years. SNFs have emerged as a leading source of documentation errors among care settings, which is exactly why the sector has become a focal point for federal enforcement attention.
Here's where it gets interesting, though, and where a lot of people's assumptions probably go wrong. If you assume the bulk of that $5.6 billion comes from bad actors gaming the system, the 2024 root cause breakdown says otherwise: insufficient documentation accounted for 75.5% of improper payments, "other errors" made up 20.4%, no documentation at all was 3.8%, and incorrect coding, the category people tend to picture when they hear "improper payment," was just 0.3%.
So what does that distribution actually tell us? It tells us the dominant failure mode isn't fraud, but rather a documentation gap, a mismatch between what happened clinically and what got written down and coded. That distinction matters enormously for anyone auditing these financials, because it means the revenue recognition risk lives inside the care documentation process itself, not just in the billing system sitting downstream of it. A facility auditor looking at SNF revenue has to treat it as inherently higher risk than a typical service business receivable, and standard billing controls alone won't catch what's really going on.
How specific PDPM coding patterns drew CMS scrutiny
CMS hasn't been quiet about where it's looking. In its proposed pay rule, the agency flagged specific diagnosis codes where prevalence jumped so sharply after PDPM's rollout that it reads as a case-mix upcoding signal, and it said so in rulemaking, not just in audit findings after the fact. Malnutrition coding (I-5600) went from 5% of skilled nursing patients before PDPM to 47% in fiscal 2024. Swallowing disorder (K0100) went from 4% to 21%. Depression coding (D0160 or D0600) reached 19% in fiscal 2024, a figure CMS flagged as a sharp rise from prior rates.
None of that proves fraud on its own; it's entirely possible documentation genuinely improved once PDPM gave facilities a financial reason to capture conditions they'd been under-coding for years. But the size of these jumps is exactly what invites scrutiny, and it means any facility coding these diagnoses at elevated rates needs documentation that can withstand a second look.
New CMS surveyor guidance effective February 2025 raises the stakes considerably. Surveyors are now directed to refer patterns of inaccurate MDS assessments to the Office of Inspector General for potential fraud investigation, with schizophrenia diagnoses and PDPM coding practices facing the sharpest scrutiny. CMS defines "pattern" with real precision here too: three or more assessments with inaccurate diagnosis coding unsupported by physician documentation triggers a citation at pattern or widespread scope. Three assessments — that's a low bar, and it converts what used to look like a routine compliance matter into potential fraud exposure, a contingent liability that belongs squarely on an auditor's radar rather than filed away as a clinical quality issue.
It's also worth considering that this scrutiny isn't staying inside traditional Medicare. CMS has announced plans to expand audit efforts into Medicare Advantage contracts, estimating tens of billions of dollars per year in overpayments unsupported by medical records. Documentation-based enforcement is spreading, not narrowing.
The QRP reporting requirements that translate MDS errors into direct revenue deductions
The SNF Quality Reporting Program works on a pay-for-reporting model: miss the reporting requirements and a facility eats a 2% reduction in its Annual Payment Update. The threshold that triggers this is specific, and facilities need to report 100% of required quality measure data on at least 90% of the assessments they submit to CMS, a standard that tightened starting with FY 2026.
The penalty exposure tells its own story about how fast this is escalating: the number of facilities penalized jumped from 298 in fiscal 2024 to 2,285 in fiscal 2026, roughly a sevenfold increase in two years. That's not a rounding error in enforcement intensity; that's a structural shift in how tightly CMS is now watching the threshold.
Value-Based Purchasing layers a second mechanism on top. CMS withholds 2% of Medicare payments and redistributes those funds based on performance and improvement, which means, unlike QRP's binary penalty, VBP creates winners and losers rather than a flat cut. CMS estimates VBP reductions at roughly $203.6 million for FY 2027. For financial reporting purposes, both mechanisms raise a genuine revenue recognition question: if a facility expects to miss the 90% threshold, should its Medicare revenue be recorded net of the anticipated APU reduction? And under VBP, does a facility's expected performance tier mean it should book additional revenue, or account for a loss of withheld funds? These aren't hypothetical questions anymore, and CMS is adding an audit component to QRP data validation beginning with FY 2027, which means another layer of scrutiny arrives after submission, not just before it.
How the FY 2027 rule and the coming all-payer expansion are compressing the margin for error
Timing is becoming the whole game. The FY 2027 Final Rule shortens the MDS reporting window from roughly four and a half months down to approximately 45 days after the end of each quarter. That change takes effect for data collection beginning January 2027 and affects the FY 2029 QRP payment determination, which means facilities have months, not years, to rebuild workflows, staffing models, and quality-control checkpoints before the compressed clock starts running. A shorter window means less time to catch an error before it becomes a submission, and less time to catch a submission before it becomes an improper payment.
Layer onto that a proposed all-payer MDS expansion targeted for 2031, which would require MDS assessments for every patient regardless of payer, including those on commercial Medicare Advantage plans. CMS projects this would generate 1.1 million additional MDS submissions per year, and combined with two new quality measures proposed for the same year, the sector-wide reporting burden is estimated to grow by one million hours annually. That's a lot of new coding surface area for errors to hide in.
There's also a risk-based survey program launching in September 2026, and MDS validation audit results are among the factors CMS will use to decide how intensively a facility gets surveyed. Roughly 12% of facilities are expected to qualify for the lighter-touch survey track initially, which means facilities with weak MDS accuracy face a double penalty: payment risk on one side, and more intensive survey scrutiny compounding the operational disruption on the other. For anyone auditing these numbers, the practical takeaway is that the gap between a clinical event, its coding, its submission, and a potential audit challenge is shrinking fast. Revenue estimates and contingency accruals need to reflect that faster-moving uncertainty, not the leisurely timeline that used to exist.
Where MDS errors show up in the financial statements and what auditors need to examine
The most direct hit lands on net patient service revenue. Medicare and Medicaid revenue gets recognized based on the rates PDPM coding generates, so overstated coding produces overstated revenue recognition, plain and simple. Estimated third-party settlements and contractual adjustments need to build in the real probability of MDS-related takebacks and audit adjustments, not just historical collection patterns.
Contingent liabilities are the next layer. When a CMS audit or OIG investigation is known or probable, GAAP requires disclosure and, depending on likelihood, an accrual, and that's a direct downstream consequence of an F641 citation or active RAC or ZPIC audit activity. This is where a piece of paper most people outside the industry have never heard of becomes essential: the SNF Cost Report. CMS's public cost report file contains facility characteristics, utilization data, cost and charges by cost center, Medicare settlement data, and financial statement data, all organized by CMS Certification Number. Auditors should be reconciling that data against internal financials and digging into any material variance rather than treating the cost report as a compliance filing that lives in its own silo.
Three audit risk assertions carry the most exposure here. Completeness and accuracy of revenue: is every billed service actually supported by MDS documentation? Valuation of accounts receivable: do outstanding Medicare and Medicaid receivables reflect a realistic net realizable value once you factor in potential adjustments? And disclosure: are known audit risks and potential recoupments actually spelled out adequately in the financial statements? Auditors working through SNF financials should be requesting MDS validation reports directly, reviewing any open RAC or ZPIC findings, and pressure-testing whether the facility's revenue recognition approach accounts for documentation-related denial risk. Given that 75.5% documentation-deficiency figure from the improper payment data, the most material risk sitting in these financials usually isn't intentional fraud, but rather a systematic gap between what happened at the bedside and what got captured on paper, and that gap quietly understates collection risk if nobody's looking for it.
Internal controls that connect clinical documentation to reliable financial reporting
The MDS coordinator is a control point, not just a job title on a clinical org chart. Timely review of CMS validation reports functions as a preventive control in the truest sense: catch the error before submission and it never becomes an improper payment in the first place. That means facilities need an actual defined workflow here, coordinator review, clinical team sign-off, supervisory QA, before anything goes out the door, rather than relying on one person's diligence.
Why does documentation insufficiency dominate the error data the way it does? Look at where the information originates. Therapy, nursing, dietary, and social services each feed coded data into the MDS, and when those departments document in isolation from each other, the gaps show up exactly where CMS's insufficient-documentation category says they show up. Controls have to bridge clinical departments and the billing function directly; a care plan that never translates into a properly supported MDS item is sitting there as unrecognized revenue risk, whether anyone's looking at it that way or not.
Given CMS's specific attention to malnutrition, swallowing disorder, and depression coding, facilities need formal physician documentation protocols for any newly coded diagnosis in those categories. Remember, three unsupported assessments is the threshold that triggers an OIG referral under the new F641 guidance, so a control gap of that size carries real audit materiality, not just compliance risk. Facilities should be tracking their own coding rates for these high-scrutiny diagnoses against sector benchmarks, the same kind of analysis CMS itself is running, and running mock validation audits before submission windows close rather than after. With the 45-day reporting window arriving in January 2027, quality-control cycles that currently stretch across months will need to compress substantially. Now is the moment to redesign that process, not after the rule takes effect and the clock is already running. For auditors, evaluating whether these controls are actually designed well and operating as intended is part of genuine risk assessment; taking management's word for MDS accuracy isn't sufficient anymore, if it ever was.
Why SNF financial statement audits require industry-specific expertise to execute reliably
Step back and look at the shape of this risk profile, because it's genuinely unusual compared to most service businesses an auditor might encounter. Revenue gets determined by clinical coding decisions made by nursing staff and MDS coordinators, people with no accounting background and no reason to think about GAAP when they're filling out a swallowing disorder assessment. Material misstatement risk lives inside that clinical workflow, not just inside the billing system that receives its output. And contingent liabilities can originate from a federal enforcement action that starts with a clinical surveyor walking the floor, not a financial examiner reviewing a ledger.
An auditor without specific SNF background may simply not know to request MDS validation reports as audit evidence, or to ask whether third-party settlement estimates realistically reflect current CMS enforcement priorities, or to evaluate whether disclosures around open RAC, ZPIC, or OIG activity are adequate given what's actually happening in the sector. They might not connect QRP penalty exposure or a VBP performance shortfall to the revenue line at all.
The regulatory pace here isn't slowing down either. The FY 2027 reporting rule, the proposed 2031 all-payer expansion, and the new risk-based survey program launching in 2026 all demand an auditor who tracks CMS rulemaking as an ongoing discipline, not an annual refresher. RAI Manual updates typically finalize each August or September for an October 1 implementation date, which means regulatory literacy has to be continuous, not something picked up once a year during audit planning season.
Pease Bell's skilled nursing facility accounting practice is built around exactly this intersection: understanding how MDS mechanics and PDPM payment structures actually work, what the cost report requires, and what audit procedures give SNF leadership and their boards real confidence in the numbers, not just a checkbox opinion attached to a complicated set of financials. The right external auditor functions less like a year-end formality and more like an early-warning system, surfacing revenue recognition risk, flagging control gaps in the MDS workflow, and helping management understand how these enforcement trends will hit the financial statements before CMS or the OIG finds the problem first.


