OIG Work Plan Update: Medicare Hospital Compliance Audits

On its list of Recently Added items, The Office of Inspector General (OIG) of the Health and Human Services (HHS) Department announced in July 2025…

Read More

Jim Hook, MPH

By Jim Hook, MPH | September 1, 2025

Stack of blocks with regulatory terms on them and finger pointing at them to call attention to Medicare Hospital Compliance Audits

On its list of Recently Added items, The Office of Inspector General (OIG) of the Health and Human Services (HHS) Department announced in July 2025 that it will conduct Medicare Hospital Compliance audits as part of its Work Plan. Quoting the notice: “We will review Medicare payments to acute care hospitals to determine hospitals’ compliance with selected billing requirements and recommend recovery of overpayments and hospital-specific compliance remediation measures.” So what does that specifically mean, and what should healthcare organizations that submit claims to Medicare do with this notice?

What is the OIG Work Plan?

The OIG Work Plan is a comprehensive list of audits, investigations, and evaluations addressing a wide range of financial integrity issues, corresponding to the diverse range of programs and activities administered by HHS. 

The OIG Work Plan lists audits, investigations, and evaluations. These address many financial integrity issues across HHS programs and activities. Projects in the Work Plan span across HHS, including:

  • Centers for Medicare & Medicaid Services (CMS)
  • Public health agencies such as:
    • Centers for Disease Control and Prevention (CDC)
    • National Institutes of Health (NIH)
  • Human resources agencies such as:
    • Administration for Children and Families (ACF)
    • Substance Abuse and Mental Health Services Administration (SAMHSA)
    • Administration on Community Living (ACL)

The OIG also plans work related to cross-departmental issues, such as:

  • State and local governments’ use of Federal funds
  • Functional areas of the Office of the Secretary of Health & Human Services (HHS)

Some Work Plan items reflect work that is statutorily required.

There are currently 272 projects listed on the Work Plan, of which 200 are related to CMS programs and administrative activities.

Many of the Work Plan compliance audits have focus areas related to the administration of the Medicare and Medicaid services by contractors or other divisions within CMS. Some recent examples of selected types of audits include:

  • Wisconsin Physicians Service (WPS) Government Health Administrators Reopened and Corrected Cost Report Final Settlements for Desk Reviews Only With Obvious Errors To Correct Payments Made to Medicare Providers. WPS is a Medicare Administrative Contractor (MAC). MACs are responsible for administering provider claims to the Medicare program on behalf of CMS. There are currently 12 MACs that administer claims for Medicare Parts A & B. This is an example of an audit of an administrative service of CMS.
  • Maine Could Better Ensure That Intermediate Care Facilities for Individuals With Intellectual Disabilities Comply With Federal Requirements for Life Safety, Emergency Preparedness, and Infection Control. This is an example of an audit of a program administered by a state agency.

But the vast majority of audits and evaluations concern regulatory compliance of healthcare organizations, including:

  • Hospitals
  • Physicians
  • Home health agencies
  • Hospices
  • Laboratories

Most of these organizations submit claims for fee-for-service payments.

In recent years, OIG has commenced or completed audit processes of hospital claims in many areas:

  • OIG is auditing medical records on patients who left the hospital against medical advice, or AMA. This was triggered by an academic report that indicates patients who sign out AMA may have experienced poor quality of care.
  • OIG is auditing payments for trauma team activations. CMS does not maintain a list of verified trauma centers, and it is concerned about claims for trauma team activation that may not be medically necessary.
  • The OIG reviewed Medicare payments for inpatient hospital claims with specific MS-DRG assignments requiring mechanical ventilation. It examined whether hospitals’ DRG assignments and the resulting Medicare payments were appropriate. This audit covered 250 claims for mechanical ventilation exceeding 96 hours, with findings of compliance with Medicare requirements in 233 cases. However, the OIG calculated that this represented overpayments of $382k for the 17 claims out of compliance. It then extrapolated that figure to an overpayment of $79.4 million on all claims from every hospital for the six-year audit period. This is a good example of a situation where, despite a high level of compliance with Medicare billing requirements, the OIG may determine that overpayments or repayments should be substantial.
  • OIG has undertaken several Medicare compliance audits of independent clinical laboratories. This audit spilled over to include a hospital in North Carolina. Using its statistical methodology, the OIG extrapolated $432k of overpayments on the specific inpatient and outpatient service claims into an overpayment of $3.4m for the 2-year audit period.
  • OIG began hospital compliance audits related to the 2021 Hospital Transparency Rule. This audit, prompted in part by media accounts, attempted to measure compliance with the regulations requiring hospitals to make their standard charges available to the public. The audit found that:
    • 34 hospitals did not comply with 1 or more of the requirements associated with publishing comprehensive machine-readable files.
    • 14 hospitals did not comply with 1 or more of the requirements associated with displaying shoppable services in a consumer-friendly manner.

Again, the OIG then extrapolated that to mean 46 percent of the 5,879 hospitals required to comply with the HPT rule did not comply with the requirements to make information on their standard charges available to the public.

Has the OIG undertaken Medicare Hospital Compliance Audits in the past?

Yes, most definitely! Between 2016 and 2018, the OIG conducted a series of hospital compliance audits that covered both inpatient and outpatient services. The data analysis techniques utilized by the OIG concluded that the 12 hospitals audited had received over $5m in estimated overpayments during the respective audit periods. At the end of these audits, the institutions were expected to convert the estimated overpayments into actual returned overpayments.

How should Hospitals react to this new compliance audit initiative? 

  • First of all, subscribe to the “What’s New Newsletter” published by the OIG. Whenever the OIG announces compliance audits for services in your healthcare sector, please take note of it. Then, identify if internal audits of the OIG’s audit targets could be included in your organization’s existing compliance audit plan.
  • Second, review the current topics you have included in your annual audit plan. Ensure that you focus on meeting proper documentation requirements, as well as identifying and avoiding billing errors. Your audit plan should also include reviews that analyze medical and billing records together. If not, add these audits to the compliance risk areas without delay.
  • Ensure that staff members receiving mail are aware of where to forward official correspondence from CMS or your Medicare Administrative Contractor (MAC). Some hospitals have received notices of noncompliance with requests for medical and billing records because the notices never reached the right person.
  • Finally, if you don’t have a formal Compliance Program or a Compliance Officer, consider carefully if you can do without one and someone competent to manage it. And don’t forget that outsourcing your compliance program can be a very cost-effective solution!