top of page
Search

Common Findings During CMS Data Validation Audits

Writer: HealthSpective
HealthSpective
Aug 31
9 min read

CMS data validation audits consistently surface the same categories of findings year after year. Despite regulatory guidance, published enforcement reports, and industry-wide awareness, the errors that trigger corrective action plans, civil money penalties, and Star Rating consequences in 2026 are largely the same ones CMS identified in prior years.


This persistence is instructive. It tells us that most data validation findings are not the result of ignorance organizations generally know what CMS expects. They are the result of operational gaps: workflows that do not consistently produce compliant outcomes, documentation systems that leave records incomplete, delegated entities that are not adequately overseen, and data pipelines that introduce inaccuracies that internal teams do not detect.


The CY 2025 CMS Program Audit and Enforcement Report released July 2026 identified recurring problems involving prior authorization and appeals processing, beneficiary access to medications and services, care coordination, enrollment and eligibility errors, and oversight of delegated entities. These same themes have appeared in multiple consecutive enforcement reports. The pattern is unmistakable.


At HealthSpective, our audit readiness and compliance monitoring and healthcare consulting work gives us direct visibility into what drives these findings and how organizations can address them systematically. Here is what plans consistently get wrong and what to do about it.



Category 1: Coverage Determinations and Prior Authorization Failures

Coverage determination and prior authorization compliance is the most consistently cited finding area in CMS program audits. The CY 2025 enforcement report specifically emphasized "recurring problems involving prior authorization and appeals processing" as a primary concern.


What auditors find:

  • Timeliness failures: CMS finalized requirements for expedited authorization decisions within 72 hours and standard decisions within 7 calendar days. Audits routinely find that plans fail these timelines across meaningful percentages of sampled requests particularly for complex cases handled through delegated utilization management entities.

  • Inadequate denial notices: When authorization requests are denied, CMS requires that members receive a notice that includes the specific reason for denial, the criteria used in the decision, and information about their appeal rights. Auditors find notices that are vague, omit required elements, or reference internal criteria that members cannot access.

  • Missing documentation: The coverage determination record must include sufficient documentation to reconstruct the decision-making process the request received, the clinical criteria applied, the decision reached, and the notice issued. Incomplete coverage determination files are a frequent finding.

  • Delegated entity oversight failures: When plans delegate utilization management to a downstream entity, CMS holds the plan responsible for the delegated entity's compliance. Auditors consistently find that plans have inadequate oversight of their UM vendors no performance monitoring, no delegation agreement that requires CMS-compliant timelines, no regular auditing of the delegated entity's decisions.


What to do: Build a monthly sample review of completed coverage determinations, measuring both timeliness and notice quality. Audit your delegated UM entities on the same basis. Ensure your delegation agreements expressly require CMS-compliant timelines and authorize your access to audit their operations.


Category 2: Grievance and Appeals Processing Errors

The appeals and grievance system is one of the most heavily monitored areas in both Part C and Part D audits. CMS views failures in this domain as direct threats to beneficiary rights and treats them accordingly.


What auditors find:

  • Wrong classification: Whether a member contact is classified as a grievance, an organization determination request, or an appeal has significant procedural consequences. Auditors find that plans routinely misclassify member contacts most commonly classifying issues that should be treated as organization determinations as grievances, which triggers different (typically less protective) timelines and procedures.

  • Auto-forward failures: When a member files a timely appeal to the plan and the plan upholds its denial, the case must be automatically forwarded to the Independent Review Entity (IRE). Auditors find that auto-forwards are not always completed, completed outside required timelines, or not completed with the required documentation.

  • Acknowledgment and resolution notice deficiencies: Every grievance must be acknowledged and resolved within defined timelines, with notices that meet CMS content requirements. Audits find missing acknowledgments, late resolutions, and notices that omit required content.

  • Universe integrity problems: When CMS requests a universe of all grievances or appeals processed during an audit period, the submitted universe must be complete. Auditors find universes that are missing records, inconsistently coded, or produced from data systems that do not capture all required data elements.


What to do: Implement a rigorous universe quality assurance process. Conduct regular internal reviews of grievance and appeals classification decisions. Track auto-forward completion rates and timeliness in real time. Ensure your notices are produced from templates that are regularly reviewed against current CMS requirements.


Category 3: Part D Documentation and Drug Event Errors

As reported in CMS FY 2025 findings, 75% of Part D payment errors are classified as missing or invalid documentation errors. This makes documentation quality the most significant driver of Part D audit risk.


What auditors find:

  • Prescription documentation gaps: Claims submitted for Part D covered drugs must be supported by valid prescriptions. Auditors find prescriptions that are missing, expired, not signed by the prescriber, or not specific to the drug and quantity dispensed.

  • Days' supply calculation errors: Incorrect days' supply calculations are among the most commonly identified PDE (prescription drug event) errors. Over-calculated days' supply can constitute improper billing; under-calculation can affect member cost-sharing and formulary tier determination.

  • Low-income subsidy (LIS) eligibility errors: Part D LIS beneficiaries receive reduced cost-sharing. Auditors find plans that are applying incorrect LIS levels based on outdated eligibility data, or not updating LIS status when eligibility changes.

  • Transition supply compliance: CMS requires plans to provide a transition supply to new enrollees who are on medications not covered by the plan's formulary, within defined quantity and timeframe limits. Auditors find plans that are not providing transition supplies as required, or not tracking transition supply dispensing accurately.

  • Medication Therapy Management (MTM) program failures: MTM programs must meet CMS eligibility criteria and comprehensive medication review (CMR) requirements. Auditors find MTM programs that include ineligible beneficiaries, do not complete CMRs within required timelines, or do not document CMR outcomes as required.


What to do: Implement a pre-claim submission documentation verification step for high-risk drug categories. Build LIS eligibility update workflows that respond to CMS-sent eligibility data in real time. Conduct quarterly internal reviews of MTM program completion rates and CMR documentation quality.


Category 4: Enrollment and Eligibility Data Errors

Enrollment data accuracy is foundational errors in enrollment and eligibility data cascade into payment errors, coverage determination failures, and beneficiary access problems.


What auditors find:

  • Disenrollment processing failures: When members request disenrollment, the request must be processed within CMS-defined timelines. Auditors find delayed disenrollments that result in continued premium collection, coverage that members believe they have terminated, and downstream coordination of benefits failures.

  • Effective date errors: Enrollment effective dates that do not match CMS records create discrepancies in payment calculations and member coverage determinations. Plans may be providing coverage for periods CMS has not paid for, or failing to provide coverage for paid periods.

  • PECOS data mismatches: For plans that cover Medicare-eligible providers, discrepancies between plan enrollment data and CMS's PECOS (Provider Enrollment, Chain, and Ownership System) database create compliance exposure. CMS has escalated its attention to PECOS data accuracy in 2026.

  • Special Enrollment Period (SEP) eligibility errors: Members can only enroll or change plans outside the Annual Enrollment Period under specific qualifying circumstances. Auditors find plans that have accepted SEP enrollments without adequate documentation of qualifying events, or that have applied incorrect SEP types.


What to do: Establish automated disenrollment timeline tracking with escalation alerts for cases approaching CMS deadlines. Reconcile enrollment data against CMS-transmitted records monthly. Implement a PECOS validation step in your provider enrollment workflow.


Category 5: Risk Adjustment Data Validation (RADV) Findings

RADV audits are technically separate from Part C data validation but represent the most financially significant audit risk for Medicare Advantage organizations. CMS confirmed that Payment Year 2020 RADV audits began in February 2026 on a quarterly cadence.


What auditors find:

  • Codes without MEAT-compliant documentation: The most common RADV finding. Diagnosis codes are submitted for risk adjustment but the corresponding medical record does not contain documentation showing the condition was Monitored, Evaluated, Assessed, or Treated during a face-to-face encounter in the payment year.

  • Problem-list-only diagnoses: Conditions listed only in a problem list or referenced in past medical history, without any connection to current care documented in the encounter note, do not satisfy RADV requirements. Auditors consistently find diagnoses that were coded from problem lists rather than from clinically active encounter documentation.

  • Unspecified codes without clinical justification: When a coder assigns an unspecified ICD-10 code (e.g., E11.9 for Type 2 diabetes without complications) when more specific coding is supported by the documentation, the code may still validate but may carry a lower RAF value than the clinical record would support. Conversely, if a specific code is submitted without specific documentation support, it fails validation.

  • Incorrect rendering provider type: RADV audits require that diagnoses be coded from encounters with providers of acceptable types (physicians, other licensed practitioners, inpatient facilities, or outpatient facilities). Diagnoses coded from unacceptable encounter types such as telephone encounters or non-qualifying provider types do not validate.

  • Illegible or incomplete medical records: Records that cannot be read, are missing required elements, or cannot be matched to the specific enrollee being audited fail RADV validation regardless of the underlying clinical accuracy.


What to do: Implement a continuous RADV readiness program that includes quarterly pre-submission MEAT documentation audits, provider education on documentation standards, and prospective coding workflows that close HCC gaps during the encounter rather than retrospectively.


Our audit readiness and compliance monitoring and risk adjustment coding integrity services are specifically designed to address RADV readiness as an ongoing operational discipline.


Category 6: Delegated Entity Oversight Failures

CMS holds plans fully responsible for the compliance of functions they delegate to downstream vendors, subcontractors, and partner organizations. Delegated entity oversight failures are among the fastest-growing finding categories in recent CMS audit cycles.


What auditors find:

  • Delegation agreements that do not require CMS compliance: Plans must ensure their delegation agreements include explicit requirements for the delegated entity to comply with applicable CMS regulations and plan policies. Vague agreements that reference "applicable laws" without specificity are increasingly cited.

  • No performance monitoring of delegated functions: Plans must regularly monitor delegated entities for compliance with required standards. Auditors find plans that have delegation agreements but no documented evidence of monitoring activities no audit reports, no performance dashboards, no corrective action records.

  • PBM data quality failures flowing upstream: For Part D, PBM data quality directly affects plan data submissions. Plans that do not audit PBM data accuracy before incorporating it into their own submissions may inadvertently submit inaccurate PDE data and bear the compliance consequences.

  • Inadequate corrective action for delegated entity deficiencies: When a delegated entity is found to be non-compliant, the plan must implement corrective action and document it. Auditors find plans that identified delegated entity problems but took no documented remediation action.


What to do: Build a formal delegated entity oversight program with quarterly performance reviews, documented audit findings, and escalation protocols. Ensure all delegation agreements are reviewed against current CMS requirements annually.


Quick Reference: Most Common CMS Audit Findings by Category

Finding Category

Most Common Specific Issue

Regulatory Risk

Coverage determinations

Timeliness failures; inadequate denial notices

CMPs; beneficiary access

Grievances and appeals

Misclassification; auto-forward failures

CMPs; IRE violations

Part D documentation

Missing/invalid documentation (75% of errors)

Payment recoupment

Enrollment data

Disenrollment delays; SEP eligibility errors

Payment and coverage errors

RADV (risk adjustment)

No MEAT documentation; problem-list-only coding

Diagnosis code recoupment

Delegated entity oversight

No monitoring; non-compliant agreements

Full plan liability

HEDIS data quality

Biased rates; incomplete hybrid records

Star Rating impact

Frequently Asked Questions

Q: Which CMS audit finding category carries the highest financial risk in 2026? A: RADV-related findings and Part D documentation failures carry the largest direct financial risk. RADV findings can result in payment recoupment across extrapolated populations; Part D documentation failures resulted in approximately $4.23 billion in gross improper payment estimates for CY 2023 alone.

Q: How does CMS decide which plans to audit? A: CMS uses a combination of random selection, complaint-driven triggers, data analytics that flag statistical anomalies, and risk-based targeting that focuses on plans with prior audit findings or compliance patterns of concern. No plan should assume it will not be audited all contracts are eligible.

Q: What is the most effective thing an organization can do to reduce CMS audit findings? A: Build a continuous, internal compliance monitoring program that tests the same areas CMS audits on a regular cadence. Organizations that regularly audit their own coverage determination timeliness, grievance processing, and documentation quality find the same issues auditors find but while there is still time to fix them. HealthSpective's audit readiness and compliance monitoring services are designed around exactly this principle.

Q: What is the difference between a program audit finding and a data validation finding? A: CMS program audits assess operational compliance across a broad range of functions (coverage determinations, appeals, enrollment, etc.). Data validation audits specifically assess the accuracy of data submitted in Part C and Part D reporting requirements. Both types of reviews can result in corrective action requirements and financial consequences but they focus on different aspects of plan operations.

Q: Does HealthSpective help organizations prepare for CMS data validation audits and RADV? A: Yes. HealthSpective provides medicare data validation and audit readiness services for Medicare Advantage and Part D sponsors, including pre-audit internal reviews, RADV preparation and documentation quality programs, corrective action support, and ongoing compliance monitoring. Contact Info@HealthSpective.net or (713) 581-4320.

Q: How often does CMS publish data on program audit findings? A: CMS publishes an annual Part C and Part D Program Audit and Enforcement Report. The CY 2025 report was released in July 2026. These reports detail audit activity, common findings, civil money penalties, and enforcement trends and are essential reading for compliance teams at every Medicare Advantage and Part D organization.


Address Your Audit Risks Before CMS Does

The most effective time to remediate a CMS data validation or RADV finding is before the auditor arrives. Organizations that invest in proactive audit readiness and compliance monitoring testing their own workflows against the same standards CMS applies consistently achieve better audit outcomes than those that wait for external review to identify problems.


HealthSpective's experienced team is ready to help your organization build the compliance infrastructure to get ahead of these recurring findings and maintain defensible data quality year-round.

 
 
 

Comments


HEDIS® is a registered trademark of the National Committee for Quality Assurance (NCQA) and any reference thereto by HealthSpective does not imply any endorsement by NCQA of HealthSpective and its offerings.

14019 SW Freeway, Suite 301-705

Sugar Land, Texas 77478


Info@HealthSpective.net  | (713) 581-4320

 

© HealthSpective 2026

bottom of page