Practice  /  340B Audit

Audit 03

340B Audit

Purchase to accumulation to audit defense. Two audits sit inside it: the ESP Audit and the Rebate Audit.

A single item, from the moment someone asks for a charge code to the moment an accumulation decision is defended in front of an auditor, crosses nine operational stages, at least six departments, and two systems of record that were never designed to agree. Almost nobody maps it as one chain. We do, with one owner named per stage, because the failures happen in the space between the stages rather than inside any of them.

Repayment risk is not reduced by being right. It is reduced by being able to show it. So the work builds the audit file before the audit: the mapping table, the exclusion position with the date it was last confirmed, contract pharmacy reconciliation exceptions, sample walkthroughs, and a dated change log.

Where the 340B chain splits from the revenue chain Nine stages run from the charge description master through remit and denial. At stage three, charge capture, the 340B chain branches off into purchase and accumulation, site and patient eligibility, and duplicate discount and audit defense. THE REVENUE CHAIN 010203040506 Chargemaster Chargetrigger Chargecapture Coding& CDI Claimedits Remit &denial THE 340B CHAIN, BRANCHING FROM STAGE 03 070809 Purchase &accumulation Site & patienteligibility Duplicate discount& audit defense Two artifacts feed both lanes and usually belong to nobody: the location mapping table, and the unit conversion.
The chain, stage by stage Nine stages, where each one breaks, how we improve it

Charge master to 340B is one chain. Almost nobody maps it as one.

"End to end" is the most abused phrase in healthcare consulting. Here is what we mean by it. A single item, from the moment someone asks for a charge code to the moment a 340B accumulation decision is defended in front of an auditor, crosses nine operational stages, at least six departments, and two systems of record that were never designed to agree. We map all of it, in one model, with one owner per stage.

The revenue chain
01Charge Description MasterRevenue Integrity
02Order & Charge TriggerClinical Informatics
03Charge CapturePoint of Care↓ The 340B chain splits here
04Coding & DocumentationHIM / CDI
05Claim EditsPatient Financial Services
06Remit & DenialDenials Management
Two bricks connect both stacks. In most organizations neither one has an owner.

These two artifacts decide whether a claim is correct and whether a 340B accumulation is defensible. They are consumed by pharmacy, revenue cycle, compliance and the split billing vendor. They are almost never owned by any of them. When we find a program in trouble, the failure is usually here, not in anyone's competence.

The 340B chain, branching from stage 03
07Purchase & AccumulationPharmacy / 340B Program
08Patient & Site Eligibility340B Program / Compliance
09Duplicate Discount & Audit DefenseCompliance / Finance
STAGE 01

Charge Description Master

Revenue Integrity
Where it breaks

New charge codes enter through whichever path is fastest: a ticket, an email, a service line meeting. The request rarely carries the fields the rest of the chain needs, so revenue code, NDC, billing units, modifier defaults and 340B eligibility get filled in later by someone reasoning from the last similar code. Annual CPT and HCPCS updates arrive as a file to load rather than a change with downstream owners. Dormant codes are never retired, so the file only grows.

How we improve it

One intake path with a required downstream impact block on every request: revenue code, NDC and package size, billing unit conversion, modifier logic, and whether the item is a covered outpatient drug. Quarterly three way reconciliation of the CDM against the pharmacy formulary and the accumulator drug file. A retirement rule with a date attached, so the file shrinks as often as it grows.

STAGE 02

Order & Charge Trigger

Clinical Informatics
Where it breaks

Whether a charge fires on order, on dispense or on administration is a build decision made inside an order set ticket, usually by someone who will never see the claim. Charge on order looks harmless until the drug is not given, or is only partly given. Then billed units and administered units separate, and the accumulator, reading the same record, qualifies units that were never used.

How we improve it

Order set change control that states the charge trigger and its accumulation effect in the same document as the clinical rationale, signed by informatics, revenue integrity and pharmacy before build. No carve out for "clinical only" changes, because there is no such thing once a charge trigger is attached to the order.

STAGE 03

Charge Capture

Nursing, Pharmacy, Procedural
Where it breaks

The person documenting the administration is the only one who can make the record accurate and the one furthest from any consequence of getting it wrong. Waste documentation is treated as a billing formality rather than a clinical record. Quantity gets entered in the unit the clinician thinks in, not the unit the claim and the accumulator require. Late charges arrive after the bill has dropped and get written off quietly.

How we improve it

Every exception type gets a named owner and a threshold: administration missing against a dispense, waste not documented, unit outliers, late charges past bill hold. Your team works them, because your team is the only one who can. We audit them on a cadence you set, monthly, quarterly or twice a year depending on volume and risk, and we report what the exception rate is doing rather than what the training completion rate is doing. Where the workflow forces a unit conversion in someone's head, we change the workflow rather than repeat the training.

STAGE 04

Coding & Documentation Integrity

HIM / Clinical Documentation Integrity
Where it breaks

DNFB grows because documentation is incomplete, and the coder is the first person who can see the gap and the last one with authority to close it. Query topics get chosen by what is easy to query rather than by what actually moves a denial. Nobody connects a template change made in month one to the medical necessity denials that arrive in month four.

How we improve it

Select query topics off the denial reason codes the organization is actually losing on, refreshed quarterly. Register every documentation template change with a review date ninety days out, then read the denial categories at that date. If nothing moved, the change was safe. If something did, you know exactly which change to look at.

STAGE 05

Claim Edits & Scrubber

Patient Financial Services
Where it breaks

Edits are worked to clear the queue, which is the right incentive for the person in the queue and the wrong one for the organization. The same edit recurs because its cause sits back at stage one or stage two and the queue has no route back there. Volume is reported every week. Cause is reported never.

How we improve it

A cause loop on a fixed cadence. Top edit reasons by volume and by dollars get traced to the stage that produced them and assigned to that stage's owner. At the next audit read, monthly, quarterly or twice a year, each one is reported as fixed or not fixed. The measure that matters is recurrence, not throughput.

STAGE 06

Remit, Denial & Appeal

Denials Management
Where it breaks

Denial categories are built for workflow routing, so they describe who works the denial rather than what caused it. Overturn rate is tracked; cost per appeal usually is not. Leadership sees a denial number with no upstream address, which leaves adding appeal staff as the only visible response.

How we improve it

A denial taxonomy mapped to the nine stages on this page, so every denial carries an origin as well as an owner. Then a standing quarterly read: which stage is producing the most recoverable loss, and what would it cost to fix it there instead of appealing it here.

STAGE 07

Purchase & Accumulation

Pharmacy / 340B Program
Where it breaks

The split billing system reads an extract of dispense and administration data that almost nobody in revenue cycle has ever looked at. It decides 340B, GPO or WAC on rules configured once, often by the vendor, against a drug file that drifts steadily away from the CDM. For disproportionate share hospitals, children's hospitals and free standing cancer hospitals, the GPO prohibition makes that a compliance event rather than a purchasing preference. Accumulation errors do not announce themselves. They compound.

How we improve it

Reconcile three files against each other on a fixed cadence: the CDM, the pharmacy formulary and the accumulator drug file. Anything present in one and absent from another becomes an exception with an owner. Then walk a sample of encounters end to end, from order through administration to the accumulator decision to the claim line and its modifier, and confirm all four agree.

STAGE 08

Patient & Site Eligibility

340B Program / Compliance
Where it breaks

Eligibility rests on three facts living in three different systems: whether the individual meets the HRSA patient definition, whether the location is a registered child site on OPAIS and on a filed cost report line, and whether the prescribing relationship qualifies. A new clinic goes live in the EHR the day it opens and reaches OPAIS at the next quarterly registration window, if someone remembers. Mixed use areas, referral prescriptions and telehealth sit in the gap by design. Acquisitions arrive with none of it documented.

How we improve it

One mapping table, owned jointly by pharmacy and revenue cycle, tying EHR department and location to the OPAIS registered site, to the accumulator site, to the service location on the claim. Reviewed before any new location opens and again at every quarterly registration window. This is the single artifact most programs cannot produce, and it is the first thing an auditor asks to see.

STAGE 09

Duplicate Discount & Audit Defense

Compliance / Finance
Where it breaks

Duplicate discount exposure is created by a Medicaid Exclusion File decision, carve in or carve out, made per state and per entity and then rarely revisited. Managed Medicaid follows different rules than fee for service, often plan by plan. Contract pharmacy arrangements introduce a second set of claim data the covered entity does not control, and manufacturer restrictions have rewritten the operating rules repeatedly since 2020. Compliance attests to all of it against data it cannot independently reproduce.

How we improve it

Build the audit file before the audit. A standing evidence pack: the mapping table, the exclusion file position by state with the date it was last confirmed, contract pharmacy reconciliation exceptions, the stage 07 sample walkthroughs, and a dated change log. Self audit against the HRSA audit protocol on the same cadence as the two audits described below. Repayment risk is not reduced by being right. It is reduced by being able to show it.

Why we start here

This chain is where the two most expensive numbers in a health system meet: net revenue leakage and 340B program risk. They are produced by the same records, touched by the same people, and governed by two entirely separate committees. Mapping one without the other is how organizations end up optimizing the claim and quietly disqualifying the drug. Everything in this section applies whether or not you are facing an EHR transition. A transition simply moves the whole chain at once, which is why the surprises are larger and arrive together. One boundary worth stating plainly: we do not sit in your queues and we do not run your operation. Your team owns the daily work. We build the model, name the owners and the thresholds, and then audit against them on a cadence you set, monthly, quarterly or twice a year, so you find out from the model rather than from the denial report.

Every handoff, and what drops on it Eleven roles, ten passes

Process maps show steps. We map the people between them.

A process diagram tells you what happens. It does not tell you who lets go and who picks up, or what falls in the space between the two. That space is where the money and the compliance risk live, because it is the only part of the operation nobody's job description covers. Eleven roles carry a single chargeable item across the chain. Here is every pass, and what drops on each one.

01Department ManagerRequests the item
02CDM AnalystRevenue Integrity
03EHR Build AnalystClinical Informatics
04Pharmacy InformaticsDrug file & units
05Point of Care StaffNurse, pharmacist, tech
06Coder / CDIHealth Information
07Billing Edit AnalystPatient Financial Services
08Denials AnalystFollow up & appeals
09340B Program ManagerPharmacy
10ComplianceInternal audit
11Decision SupportFinance & reporting

Ten passes. Every one of them is a place where the record can stay technically correct and operationally wrong.

01

Department ManagerCDM Analyst  ·  passes: a request for a new chargeable item

The request arrives without the fields the rest of the chain depends on.

Where it drops

The request carries a description and a price. It does not carry the NDC, the package size, the billing unit conversion, the revenue code, or whether the item is a covered outpatient drug. The CDM analyst fills those in from the closest existing code, which is a guess with a very long tail.

What we install

A single request form with those fields required, and a named pharmacy approver on anything carrying an NDC. The request cannot move until the fields exist.

02

CDM AnalystEHR Build Analyst  ·  passes: an approved charge code

The code and its trigger are built in two tickets that never reference each other.

Where it drops

The code gets built. The charge trigger is decided separately, in a different queue, by a person optimizing for clinical usability. Both decisions are correct in isolation and jointly determine whether the accumulator sees reality.

What we install

One change record covering both, with the charge trigger and its accumulation effect stated in the same document and signed by both owners.

03

EHR Build AnalystPharmacy Informatics  ·  passes: a live order set or medication record

Pharmacy finds out at the dispense.

Where it drops

Pharmacy informatics frequently learns about the change when something fails to map. The drug file and the CDM separate at that moment, the workaround gets applied locally, and nothing is logged.

What we install

Pharmacy informatics as a required reviewer on any build touching a covered outpatient drug, plus a drug file to charge master mismatch report your team owns, read against the same audit cadence as the rest of the chain.

04

Pharmacy InformaticsPoint of Care Staff  ·  passes: the workflow that will actually be used

The person entering the quantity has no idea what the quantity feeds.

Where it drops

Nothing in the interface says that this field feeds both the claim and the 340B accumulator. The nurse or tech is right to think in clinical units. Training closes the gap for about a quarter, then turnover reopens it.

What we install

Take the conversion out of the human wherever the system allows. Where it cannot be removed, make the consequence visible in the workflow and measure the exception rate rather than training completion.

05

Point of Care StaffCoder / CDI  ·  passes: the clinical record

Late charges arrive after the account is already closed.

Where it drops

The coder cannot reopen what has already dropped, so the correction becomes a write off or a rebill. The cause never reaches the department that produced it, so next month it happens again at the same volume.

What we install

A late charge feedback loop by department, in volume and dollars, routed to the same department manager who started this chain at handoff one. The loop closes on the person who can actually change it, and we audit whether it is closing rather than whether it exists.

06

Coder / CDIBilling Edit Analyst  ·  passes: a coded claim

The edit clears and the reason it fired stays where it fired.

Where it drops

There is no route backward and nobody is measured on recurrence, so the analyst who fixes it fastest is rewarded and the cause survives intact.

What we install

Recurrence tracking by edit reason, each mapped to a named upstream owner, reviewed on a set cadence against the prior read, so recurrence is visible rather than reconstructed.

07

Billing Edit AnalystDenials Analyst  ·  passes: a submitted claim, and later a denial

The denial is categorized for routing, not for cause.

Where it drops

Two very different failures land in the same bucket because the same team works both. The aggregate denial rate then hides which stage is actually producing the loss.

What we install

A second, mandatory cause field mapped to the nine stages, populated at the moment the denial is worked rather than reconstructed at quarter end.

08

Denials Analyst340B Program Manager  ·  passes: nothing, formally

This is the widest gap on the page, and it is a structural one.

Where it drops

Revenue cycle changes charge triggers, units and locations continuously. The 340B program reconciles against a configuration it was never told had changed. The two functions share a data record and share no calendar, no forum and no owner. Neither is doing anything wrong, which is precisely why it persists for years.

What we install

A standing joint review on a fixed cadence, monthly where volume warrants it and quarterly where it does not, with one agenda: configuration changes made, accumulator exceptions open, new or changed locations, unit conversion variances, and denials with a 340B adjacency. Two functions, one written record, and it is the first thing we read at every audit.

09

340B Program ManagerCompliance  ·  passes: an attestation that the program is operating correctly

Compliance signs against evidence it cannot reproduce.

Where it drops

The underlying reconciliation lives inside a vendor system, on rules configured by someone who may no longer work there. The attestation is honest and unverifiable at the same time.

What we install

An evidence pack compliance can verify without the program manager in the room. If a second person cannot reproduce it from the documentation, it is not evidence yet.

10

ComplianceDecision Support & Finance  ·  passes: the numbers leadership will act on

Three numbers reach the board with no shared origin.

Where it drops

Leadership receives a denial rate, a capture rate and a compliance attestation built from different extracts on different dates. When two of them disagree, the meeting resolves it by choosing the more credible person rather than the more traceable number.

What we install

Every board level number carries its stage of origin and its owner. Disagreement becomes a data question with an address instead of a status question with a personality.

What you get, and in what order.

We audit the 340B program end to end. How a drug is purchased, how it is accumulated, whether the site and the patient qualify, and whether you could prove any of it to an auditor without relying on one person's memory. This is the practice's deepest bench, and two audits sit inside it that can also be run on their own.

ESP Audit

Draft — confirm definition with Jack An audit of your position on 340B ESP. We look at what claims data is going out, whether it goes out complete and on time, and whether what you submitted can be reconciled back to your own dispensing and purchase records. Then we look at where manufacturer restrictions have moved against you and what your submissions would show if someone asked.

The finding is the same shape as everywhere else on this page: what is being sent, what you can evidence, and where the gap is between the two.

Rebate Audit

Draft — confirm definition with Jack An audit of what you were owed against what you actually received. We reconcile purchase records, dispensing records and the rebate or credit that came back, unit by unit on a sample, and name where the three stop agreeing.

Where a rebate did not arrive, the useful answer is not that it is missing. It is which step produced the mismatch, and who owns that step.

What you get, in order

  1. 01
    Audit Results

    The findings, written to evidence-file standard rather than to slide standard. Every one carries a severity, a named owner and a due date, so your compliance and internal audit teams can use it as evidence instead of filing it as opinion.

  2. 02
    Operational Changes

    What gets fixed, where, and by whom. Your team owns the daily work. We name the change, the owner, and the threshold it has to hold to, and we say plainly what each fix is worth against what it costs to make.

  3. 03
    Ongoing Audits

    Scheduled re-checks at month six and month twelve to confirm the fix held. Anything still open carries forward with its age attached, so nothing quietly ages out. If the numbers did not move, that finding is the deliverable.

  4. 04
    Ongoing Support

    A standing accountability call on a cadence you set. We work the open items, look at what has drifted since the last audit, and pressure-test the changes you have coming before they get built rather than after.

Each one runs on its own, or alongside this one.

Compliance discipline. This work follows the same HIPAA-aware, BAA-ready discipline as the rest of the NoBullStrategy practice, with PHI handled on a minimum-necessary basis and de-identified or synthetic data used wherever the work allows. A Business Associate Agreement is executed before any protected health information is accessed. NoBullStrategy does not practice medicine and does not provide legal advice; compliance, coding, and legal determinations are confirmed with your counsel and your compliance officer.

Start a Conversation

Every organization is different. That's the whole reason to talk first.

One direct conversation. We'll tell you honestly which engagement fits where you are, what the work looks like, and whether the sequencing makes sense given what you're facing. No deck, no retainer pitch, no software to sell you.