Risk Management

DME Compliance & Audits: How You Get Reviewed — and How to Stay Clean

DME is among the most heavily audited segments of U.S. healthcare. This guide explains who audits, what they look for, what happens when findings come in, and — most usefully — the concrete compliance program that prevents the findings before they exist.

Why DME Is an Audit Magnet

Four structural factors make DME a permanent priority for federal and state audit programs:

  • High per-claim value with low clinical visibility. A $20,000 power wheelchair claim is a small number of documents, and the item sits in a patient's home — there's no hospital chart to cross-check against.
  • Home delivery weakens natural controls. No clinician witnesses delivery, no facility staff verifies the item matches the order; the provider's own delivery documentation is the only evidence.
  • Government payer concentration. Medicare and Medicaid fund a large share of DME revenue, so the federal and state treasuries have both the motive and the statutory tools to police it.
  • Historical fraud patterns. DME has a long history of specific, well-documented fraud schemes (phantom deliveries, upcoding, duplicate rentals, falsified oxygen studies), which means auditors arrive with mature playbooks for detecting them.

Who Audits DME Providers

WhoWhat They DoWhat Triggers Them
RAC (Recovery Audit Contractor)Post-payment claims review; identify overpayments; demand returnData-mining algorithms flagging coding, POS, frequency, or documentation anomalies
ZPIC / MAC audit unitsPre- and post-payment review; medical necessity checksRandom samples, targeted categories, referral from other programs
OIG (Dept. of Health & Human Services Inspector General)Investigations, audits, exclusions, settlementsWhistleblower (qui tam) complaints, patterns, referrals from law enforcement
State Medicaid programs / state AGsState-level DME audits and enforcementState data-mining, complaints, cross-referencing with state licensing violations
AccreditorsPeriodic quality surveys (not "audits" in the financial sense, but with serious consequences)Scheduled survey cycle; can trigger or inform government action
Commercial payers / TPA auditorsClaims audits for commercial linesPlan-specific risk models; often follow federal findings

What Auditors Look For (the recurring fact patterns)

  • Documentation gaps: missing or late physician orders; orders from the wrong practitioner type for the item; expired prior authorizations; delivery without a documented authorization where one was required.
  • Medical necessity failures: for oxygen, studies that don't meet the required thresholds or are out of date; for power mobility, incomplete functional assessments; for home dialysis, missing facility coordination documentation.
  • Coding errors: upcoding (billing a higher-level code than the item furnished), wrong POS code, duplicate or overlapping rental claims, billing for a period with no valid enrollment, category mismatches (billing an item outside enrolled categories).
  • Delivery integrity: missing signatures, delivery addresses that don't match patient addresses, delivery dates that predate order dates, or (the classic phantom-delivery pattern) claims with no credible delivery evidence at all.
  • Rental lifecycle errors: billing past the 13-month depreciation point, failing to stop billing when an item is returned or a patient dies, and (a big one) billing multiple patients for the same serial-numbered unit simultaneously.
  • Enrollment integrity: claims submitted after a deactivation or during a lapse; ownership changes not reported; excluded individuals involved in the billing (see below).

Overpayments: The Clock That Runs Whether or Not You Know

One of the most misunderstood rules in DME: the 60-day overpayment rule (from the ACA's Affordable Care Act section 6402, as amended). Once an overpayment is "identified," the provider must report and return it within 60 days (or include the return in the next claim submitted) — and knowingly retaining it past the deadline is itself a False Claims Act "reverse false claim." "Identified" has been interpreted broadly (a credible analysis pointing to an overpayment can start the clock, even if the amount isn't finalized), which means: if an audit, a data pull, or an internal review surfaces a potential overpayment, the 60-day clock is a real operational event, and your first move is documented, good-faith analysis — not silence. Build an overpayment-response procedure before you need it: who gets notified, what documentation is preserved, how the analysis is done, and how the return is executed.

Exclusion Screening: The Non-Negotiable

Anyone excluded from federal healthcare programs — by OIG or HHS, or by a state Medicaid agency — cannot be employed in any role involving federal claims, and employing one is a federal crime for the entity. Screening is not a one-time event: OIG recommends screening the OIG LEIE and SAM.gov exclusion lists at least monthly, for every owner, officer, board member, employee, and contractor with any role in billing or patient care. Many DME audits that look like billing audits are actually exclusion audits — the finding that an excluded individual touched the billing process is one of the most severe outcomes a provider can receive, and one of the most preventable. Put monthly exclusion screening in your compliance calendar and keep the results on file.

The Compliance Program That Actually Works

CMS and OIG publish guidance on what a "compliant" provider looks like. Translated into operational DME terms, a defensible compliance program has eight elements:

  1. Written policies & procedures — covering ordering/authorization, delivery, billing, rental management, overpayment response, complaints, and exclusion screening — current, versioned, and actually followed.
  2. Designated compliance officer — a named person (a title, not a job description buried in an HR manual) with the authority to stop a billing practice, and a reporting line that reaches the owner.
  3. Training with records — initial training at hire, annual retraining, and targeted training on new rules (new HCPCS codes, new documentation requirements), all with sign-in sheets and materials on file.
  4. Internal audit program — periodic self-review of claims (a monthly sample, say 20–50 claims, checked against the documentation standards) — done before an external auditor defines the sample for you. Internal audits that find and fix problems are a mitigating factor; internal audits that never exist are an aggravating one.
  5. Line of communication for complaints — a way for staff (and ideally patients) to raise billing or documentation concerns without fear, with a documented intake and resolution process.
  6. Enforcement & discipline — documented consequences for policy violations, applied consistently.
  7. Corrective action system — every audit finding (internal or external) gets a root-cause analysis, a fix, a verification that the fix held, and a closure. This is the system accreditors and OIG both look for.
  8. Risk assessment — an annual (at minimum) written assessment of where this provider's risk is: which categories, which payers, which documentation types, which processes.

None of this requires a compliance department — for a small provider, a compliance officer plus a good document system plus a monthly internal-audit routine covers most of it. What it does require is consistency and records: the value of a compliance program is largely evidentiary. When a finding arrives, "we have a program and we followed it" is a fundamentally different conversation than "we bill a lot and hope for the best."

When an Audit Letter Arrives: The First 30 Days

  • Don't panic; do triage.

    Identify the auditor (RAC? MAC? OIG? State?), the scope (claims sample, period, categories), and the response deadline. The deadline is the most important number on the letter — it is not negotiable and missing it changes everything.

  • Preserve everything.

    Immediately suspend any routine document destruction that could touch the audit period. Litigation/audit hold is a real thing and informal is fine — but it must be done.

  • Designate the response team.

    One owner, one document lead, one (external) counsel if the scope or dollar value is significant. Every document out the door should go through the same two people.

  • Build the document log.

    Every claim in the sample gets a complete file: order, auth, medical necessity docs, delivery doc with signature, item receipt, all claim versions and EOBs. If a file is incomplete, that is a finding you can control the narrative on — say so, and say why.

  • Respond completely and on time.

    Submit the complete file set, with a clear index. Incomplete or late responses convert manageable findings into severe ones.

  • Run the overpayment clock in parallel.

    If the sample suggests overpayments, the 60-day rule analysis runs in parallel with the response, not after it. If you find an overpayment during the response, document the good-faith analysis and the return decision — that documentation is your protection.

  • The False Claims Act in Plain Terms Knowingly submitting a false claim for payment to a federal program — or knowingly retaining an overpayment — exposes the provider to treble damages plus per-claim penalties, and can trigger exclusion. "Knowingly" includes deliberate ignorance and reckless disregard, which is why a functioning compliance program (internal audits, training, corrective action) is not just good hygiene — it is the legal line between an error and a violation. If you believe you have knowingly billed incorrectly, the correct move is immediate counsel, not quiet remediation.

    Building the Audit-Proof Documentation Habit

    The deepest protection is boring: every claim has a complete file, built at the time of service, not reconstructed at audit time. The files that audits most often find missing are the "easy" ones — the delivery signature, the auth expiration date, the second set of oxygen studies. A provider whose documentation system makes completeness the path of least resistance (delivery can't be marked complete without a signature; billing can't be released without an unexpired auth) will rarely be surprised by an auditor, because the auditor will find the same thing the internal audit already found: nothing.

    Still building the license? Get the sequence right first.

    The full step-by-step path from entity to first payable claim, with timelines.

    Start the Step-by-Step →