A Medicare audit notice is not the beginning of your problem. By the time a Recovery Audit Contractor (RAC), Medicare Administrative Contractor (MAC) or Zone Program Integrity Contractor (ZPIC, now rebranded as Unified Program Integrity Contractors) shows up in your inbox, the conditions that triggered their attention have likely existed for months. The healthcare systems that handle these audits best are the ones that stopped treating compliance as a reaction and started treating it as infrastructure.
Understanding what you are actually up against
RAC, MAC and ZPIC auditors operate under the Medicare Integrity Program, authorized by 42 U.S.C. § 1395ddd, which gives the federal government broad authority to identify and recover improper payments. These are not random reviews. Auditors use data analytics to target billing patterns that deviate from peer benchmarks, and large health systems with high claim volumes present a wide surface area for scrutiny.
The financial exposure is real. A single audit can trigger demand letters in the millions. More damaging, a pattern of noncompliance can result in exclusion from Medicare and Medicaid participation, a consequence that can threaten the viability of an entire system.
Building the internal controls that reduce your exposure
Waiting for an audit to test your documentation practices is the wrong order of operations. Strong internal controls do not just improve your audit outcomes. They also reduce the likelihood that an audit will find anything worth pursuing in the first place. Focus your infrastructure on these areas:
- Conduct regular internal claim audits across your highest-volume service lines, comparing your documentation against Medicare’s Local Coverage Determinations and National Coverage Determinations.
- Train clinical and coding staff together, not separately, so that documentation and billing code selection stay aligned at the source.
- Establish a clear document retention and retrieval protocol so you can respond to a records request quickly and completely.
- Monitor your denial rates by payer and by provider. A spike in denials often signals a billing or documentation pattern that auditors will notice before you do.
Getting these fundamentals in place before an audit request arrives puts you in a far stronger position to respond.
Handling an active audit without losing ground
If you receive an audit request, your response window is short and your documentation standards will face scrutiny under the Medicare appeals process, which protects your right to challenge adverse determinations. Use that right. The Medicare appeals process has five levels, and health systems that pursue appeals through the Administrative Law Judge level or beyond often recover a meaningful portion of initially denied claims.
When you respond to an audit, keep these priorities in order:
- Submit only the records requested. Producing documents beyond the audit’s scope invites additional scrutiny.
- Respond within the stated deadline. Late submissions can forfeit your appeal rights at that level.
- Document every communication with the auditing contractor, including dates, names and the substance of each exchange.
A disciplined, well-documented response is often the difference between a contained review and an expanded one.
Turning audit pressure into long-term resilience
The healthcare systems that come out of a Medicare audit in a stronger position treat the process as a diagnostic, not a penalty. Every finding points to a gap in your documentation, coding or compliance workflow. Your job is to close that gap before the next review cycle begins.
RAC and ZPIC audits grow more complex when your system manages multiple facilities and service lines, and a weak response strategy compounds that complexity fast. An attorney who understands Medicare regulatory structure can help you assess your exposure, build your appeal arguments and surface the systemic issues that claims data alone may not reveal.

