Est.

SNF Audit Preparation and Common Deficiency Areas

Staff Writer · · 13 min read
Cover illustration for “SNF Audit Preparation and Common Deficiency Areas”
Nursing Facilities · August 16, 2026 · 13 min read · 2,826 words

Skilled nursing facilities are getting audited at rates and depths that didn't exist five years ago, and the errors keep clustering in the same handful of spots: MDS documentation that doesn't match the clinical record, billing that outpaces what the chart supports, related-party costs that inflate the cost report, and staffing data that doesn't reconcile to payroll. This piece walks through each of those failure points and what it actually takes to prepare for them, because the facilities getting hit hardest right now aren't unlucky. They're unprepared in predictable ways.

The numbers alone should stop anyone in this industry. The improper payment rate for nursing home services, as tracked by CMS's Comprehensive Error Rate Testing program, climbed from 7.79% in 2021 to 17.2% in 2024. That's not a gradual drift; that's the sharpest increase of any care setting CERT reviews. It followed a 2022 CERT projection of 15.1% for skilled nursing services, which nearly doubled the prior year's figure and set off the wave of policy responses now landing on facility doorsteps. SNF errors aren't a side note in federal program integrity reports anymore. They're the headline finding.

Diagram: SNF Improper Payment Rate: A Near-Tripling in Three Years. Visualizes: Show the sharp rise in CMS CERT improper payment rates for skilled nursing facilities across three data points: 7.79% in 2021, a projected 15.1% in 2022, and 17.2% in…

The audit programs SNF leaders are now subject to — and what each one targets

Table: Major SNF Audit Programs Compared. Compares Launched, Administered By, Scope, Primary Focus, and 1 more by Five-Claim Probe & Educate, Targeted Probe & Educate and SNF Validation Program.

Start with the Five-Claim Probe & Educate program, launched in 2023. Every SNF in the country gets five claims pulled by its Medicare Administrative Contractor. Find errors, and the facility gets education first; keep making the same mistakes, and the review escalates into something closer to a full program integrity investigation. It's a low-stakes entry point by design, but it's also a signal: if a facility can't pass five claims cleanly, there's a documentation problem worth finding before the sample size grows.

Targeted Probe & Educate, or TPE, is the more serious cousin. MACs use billing data to flag providers with high denial rates or unusual billing patterns, then pull 20 to 40 claims per round. One-on-one education follows if errors turn up, but the program is built to convert chronic non-correction into referral. It's not a one-time check; it's a mechanism that keeps circling back until the pattern stops.

The newest and, frankly, most consequential addition is the SNF Validation Program, which launched in September 2025 and is active for fiscal year 2026. This is the first audit process built specifically to confirm that the MDS data a facility submits to CMS actually matches what's documented in the clinical record. Up to 1,500 SNFs get selected at random each fiscal year. Each one has to submit documentation for up to 10 MDS assessment records within 45 calendar days of notification. Miss that window, and the MAC sends a non-compliance letter, followed by a 2% cut to the facility's Annual Payment Update the following fiscal year. Healthcare Management Solutions, LLC runs the program on CMS's behalf, and the tight turnaround means there's no room to reconstruct records after the fact. The documentation has to already exist.

Layer onto that the ongoing post-payment work from Recovery Audit Contractors and Unified Program Integrity Contractors, both of which are increasing in parallel with these pre-payment mechanisms. A facility can face pre-payment and post-payment exposure at the same time, on the same claims, from different contractors asking different questions.

Then there's the OIG's own workplan, which currently carries 13 active items targeting nursing homes, some running since 2023 and carried into the 2025 to 2026 review cycles. Reimbursement accuracy, Part B services billed during a Part A stay, Medicaid supplemental payments, Part D financial responsibility: these aren't abstract policy topics, they're line items with active federal reviewers behind them. The OIG also announced in 2023 that it was auditing staffing hours submitted through the Payroll-Based Journal, with findings expected in 2025, adding a data-integrity dimension that sits outside the usual billing and clinical review.

Here's the frame worth holding onto as you read the rest of this: these programs overlap in time and in what they touch. A facility with weak MDS documentation is very often the same facility with billing gaps and PBJ reconciliation problems. The exposure isn't siloed, so the preparation can't be either.

Where MDS documentation breaks down and why it creates cascading risk

The MDS is not a form you fill out at the end of the week. It's a coded summary of clinical reality, and that reality gets built at the bedside, in nursing notes, therapy records, and physician documentation, all of which have to tell the same story the MDS codes claim to tell.

The mismatch the Validation Program exists to catch is almost embarrassingly simple once you see it written out: Section GG codes a resident as "independent," but the therapy discharge note says "moderate assist." Auditors don't need a forensic accountant to find that. They need a Ctrl+F.

Under PDPM, which took effect in October 2019, CMS sets the per diem rate using resident-specific variables pulled straight from the MDS: diagnoses, treatments, functional status. A coding error here isn't just a paperwork problem. It's simultaneously a billing error and a reimbursement error, because the same bad code that misrepresents the resident's condition is also the number driving what Medicare pays for that day of care. The OIG's November 2024 nursing facility compliance guidance, the first industry-specific guidance issued since the general update in November 2023, calls out regular auditing and monitoring specifically to confirm that coding reflects residents' actual characteristics and comorbidities. That's not a suggestion buried in a footnote; it's a named expectation.

Where does this actually break down in practice? A few recurring spots: Section GG functional scores that don't match what therapy documented, diagnosis codes that don't line up with the clinical record or physician orders, assessment reference dates that drift from the actual observation window, and interdisciplinary team members working off different versions of the resident's status because nobody synced the chart before the assessment locked.

Missing or incomplete documentation here doesn't just draw a citation. It leads directly to denied claims or recoupment demands, which for a sector already running negative margins is a cash-flow event, not a compliance footnote. And that 45-day submission window under the Validation Program means there's no after-the-fact fix. The record has to be complete and retrievable the day the notification letter arrives, not the day after.

Medicare billing compliance and the False Claims Act exposure most facilities underestimate

Under the OIG's November 2024 guidance, regular billing and coding review isn't a nice-to-have or a once-a-year project. It's treated as a core piece of the compliance program itself, something that runs continuously rather than getting dusted off before a survey.

Here's the number that should worry every finance director in the sector: a single, isolated billing error that results in an overpayment has to be repaid, or the facility risks False Claims Act liability. Read that again. The threshold for FCA exposure isn't a pattern of bad billing. It's one claim.

The OIG's workplan flags specific risk areas worth knowing by name: Medicare Part B services billed separately during a Part A stay, which is a well-known double-billing risk; Part D medication costs where the SNF holds financial responsibility but may be shifting the cost improperly; and Medicaid supplemental payments, where the question is whether the add-on amount was actually earned and eligible. None of these are exotic. They're the kind of thing a billing team catches in five minutes if they're looking, and misses for years if they're not.

TPE's structure reinforces just how serious this gets. A 20 to 40 claim probe followed by education sounds almost gentle, until you notice that failure to correct triggers additional rounds or a referral. The program is explicitly designed to take what starts as an education opportunity and convert it into an enforcement action if the facility doesn't fix the underlying problem.

What causes most of this? In nearly every case, it traces back to the billing team and the clinical documentation team working from two different versions of the truth. One department sees what was coded; another sees what was actually done. When those two don't match, that gap is the most common path to an FCA-relevant error. The financial exposure isn't theoretical, either: a single Florida SNF accumulated roughly $948,000 in civil monetary penalties over three years, and a Tennessee provider tallied around $935,000 over a similar stretch. These penalties compound across survey cycles; they don't reset.

Most multi-facility SNF operators run through a web of affiliated entities, management companies, real estate holding firms, staffing agencies, all owned by the same parent group. That structure is common and entirely legal. It's also one of the most heavily regulated corners of the Medicare cost report.

The rule is straightforward even if the enforcement gets complicated: costs reported for related-party relationships have to reflect the actual cost incurred by the related party, not whatever marked-up amount got charged to the SNF. Inflated costs passed through the cost report inflate reimbursement, and that's the deficiency auditors are trained to find.

A case worth knowing: a Florida operator's SNFs were paying rent to affiliated real estate entities at rates significantly above what comparable market rents would suggest. OIG determined the excess wasn't a legitimate facility cost at all, it was related-party profit dressed up as an operating expense. CMS required the rent to be recalculated at fair market value, and the adjustments landed across multiple cost reports, not just one.

What makes this a bigger deal going forward is a specific OIG recommendation: that MACs build related-party cost review into the normal desk review or audit process. That's a meaningful shift. This isn't an occasional OIG special project anymore; it's becoming a routine, desk-level check that every cost report can expect to face.

The OIG's compliance standards for these arrangements come down to three things: costs have to sit at fair market value, services have to equal or exceed what a non-related vendor would provide, and vendor selection has to be driven by what's good for residents, not by what's profitable for the ownership group. Facilities need contemporaneous fair-market-value documentation, meaning it was created at the time of the arrangement, not reconstructed after an auditor asks for it. Reconstruction after the fact is, itself, a red flag that invites more scrutiny, not less.

This connects directly to the financial statement audit too. An auditor reviewing SNF financials tests related-party disclosures, checks whether management fees look reasonable, and reads lease terms closely. Facilities with undocumented or undisclosed related-party arrangements aren't just risking an OIG finding; they're risking an audit finding and, in some cases, a restatement.

Staffing data and PBJ reporting as an emerging audit front

SNFs submit direct care staffing data to CMS's Payroll-Based Journal system every quarter, and for a long time this felt like a reporting obligation with low audit risk. That's changing. The OIG announced in 2023 that it was auditing PBJ-reported staffing hours, with findings expected sometime in 2025, and the sector should read those findings, when they land, as a preview of what corrective expectations come next.

Why does PBJ data matter beyond the audit itself? Because CMS uses it to monitor staffing levels, judge quality of care, and flag anomalies. It feeds directly into Five-Star ratings and into enforcement decisions. A facility that submits sloppy PBJ data isn't just risking an audit finding; it's risking its public rating and its standing with CMS more broadly.

The common failure points here are almost mechanical: hours submitted by staffing category that don't reconcile to actual payroll records, contract staff hours reported inconsistently from quarter to quarter, and staff classifications that don't match the person's actual job duties or licensure. None of these require malicious intent. They require someone to not have reconciled the numbers before hitting submit.

Worth noting alongside this: the OIG's clinical workplan items on falls prevalence and antipsychotic medication use run through 2025 and 2026 as well, and they demand the same kind of documentation discipline. If a facility's clinical data systems can't support accurate reporting there, the same weakness that shows up in PBJ tends to show up again.

The point to sit with is that "we submitted what our system generated" isn't a defense CMS accepts. The facility certifies the data. The facility owns the accuracy.

What internal controls gaps look like when auditors find them

A financial statement auditor working through an SNF engagement isn't just checking whether the numbers foot correctly. They're evaluating whether the controls behind those numbers are designed well and actually operating the way they're supposed to, which is a different and often harder question.

The deficiencies that show up again and again in these engagements have a familiar shape. No formal reconciliation between what gets submitted on the MDS and what the billing system generates. A cost report prepared by staff with no independent review from someone who actually understands related-party rules. PBJ submissions that go out the door without ever being checked against payroll. Related-party agreements that exist only as a verbal understanding, or written agreements whose terms don't match what's actually happening in the transactions. No defined process for catching an overpayment and repaying it within the required window. And maybe most telling: a compliance function that has no real authority to flag a billing or documentation problem before the claim goes out the door, only after.

The OIG's November 2024 guidance treats auditing and monitoring as a continuous function, not a once-a-year checklist item. That means defined roles, defined escalation paths, and someone whose job is specifically to catch these problems early rather than explain them later.

Why does this matter beyond the audit report itself? A material weakness or significant deficiency finding is a formal, documented conclusion. It affects the audit opinion. It surfaces in regulatory filings if the facility carries HUD financing. And it tends to draw additional attention from MACs and RACs, who read these reports too. In a sector already facing negative operating margins, per the McKinsey analysis projecting that trend through 2026, a control failure that triggers a recoupment demand or a cost report adjustment doesn't land in isolation. It compounds financial stress that's already there.

Building targeted preparation that holds up under concurrent review

So what does real preparation look like, given that all of this overlaps?

On MDS readiness: run internal crosswalk audits that match coded MDS values against therapy notes, nursing documentation, and physician records for a sample of recent assessments, not just the ones that already look clean. Figure out which assessment types are most likely to fall into the Validation Program's 10-record scope and make sure those specific records are complete and easy to pull. Train the interdisciplinary team on what it actually means for "the record to tell one story." Not a lecture. A working session built around real Section GG mismatches, the kind auditors flag in the first five minutes.

On billing compliance: build a pre-submission review that reconciles the clinical documentation to the claim before it goes out, not a review of what already went out the door. Put a formal overpayment identification and repayment protocol in writing; given the single-claim FCA threshold, a facility cannot afford to discover an overpayment during someone else's audit. Take a fresh look at Part B billing during Part A stays against current MAC guidance, since that's an active OIG workplan item right now, not a historical concern.

On the cost report: pull every related-party agreement in the building and check that the written terms match the actual dollar amounts moving between entities. Refresh or obtain fair-market-value documentation for management fees, lease payments, and staffing arrangements tied to affiliated entities, and do it now, contemporaneously, not after a MAC desk reviewer asks for it. Have someone who didn't prepare the cost report review the related-party schedules before filing. That second set of eyes catches what the preparer, by definition, can't see in their own work.

On PBJ and staffing: reconcile every quarterly submission to actual payroll records before certifying, treating it as a financial close step the way you'd treat a bank reconciliation, not an IT task someone runs and forgets. Document that reconciliation happened, because if the OIG's 2025 findings prompt a wave of MAC follow-up, the facility needs to show the process existed all along, not that it got built in response to a letter.

And on internal controls broadly: map out what's supposed to prevent each of the gaps described above. Where a control exists only informally, someone's memory, an unwritten habit, write it down and make it real. Where no control exists at all, build one. The compliance function needs the standing and the access to flag a problem before the claim goes out, not after the MAC already found it. That single shift, from after-the-fact discovery to before-the-fact prevention, is what separates a facility that survives concurrent review from one that gets buried by it.

Sources

  1. mdaudit.com
  2. skillednursingnews.com

More in Nursing Facilities