An additional documentation request from your Medicare Administrative Contractor lands in the mail on a Tuesday. It names 22 claims, asks for the full record supporting each one, and gives you 45 calendar days. Your billing lead wants to scan everything and upload it. Your medicare compliance obligation and your HIPAA obligation both live inside that decision, and they do not point in exactly the same direction.

This guide is for the person who owns that response: practice administrator, billing manager, privacy officer, or the one human who is all three. It covers the operational mechanics of Medicare documentation requests and compliance-program expectations, then makes the privacy, records-handling, and vendor consequences explicit. Coding decisions stay where they belong — with your providers and your documented internal process.

What Medicare Compliance Actually Covers Inside a Practice

For a clinic, medicare compliance is four distinct workstreams that get lumped under one label:

  • Enrollment and eligibility integrity. Accurate PECOS data, correct practice locations, ownership disclosures, revalidation on schedule.
  • Claims and documentation integrity. Services billed match what the record supports, and your providers can explain how they selected each code.
  • Audit and review response. ADRs, RAC reviews, UPIC requests, CERT sampling, SMRC projects, and Part C plan reviews.
  • Program infrastructure. Written standards, a designated compliance contact, training, a reporting channel, monitoring, and a documented response when something goes wrong.

The federal government has expected provider compliance programs since the Affordable Care Act made them a condition of enrollment, and the HHS Office of Inspector General has published general compliance program guidance describing the elements it looks for. Nothing about it is optional in spirit even where the implementing detail is thin. Auditors do not grade your binder; they grade whether the behaviors described in it actually happen.

Answering a Medicare Audit Request Without Breaking HIPAA

Do you need patient authorization to send records to a Medicare contractor? No. Disclosures to Medicare and its contractors for payment purposes are permitted under the Privacy Rule without patient authorization, and disclosures to program-integrity contractors also fall under the health oversight permission. You do not stop the clock to chase signatures.

Three qualifications matter operationally:

  1. Send what was asked for, not the whole chart. The minimum necessary standard applies to payment disclosures. If the request names three dates of service, three dates of service go out.
  2. You may rely on the request itself to define scope. When a public official or their contractor states what records are needed for a lawful purpose, the Privacy Rule lets you treat that representation as the minimum necessary. Keep the letter — it is your justification.
  3. Health oversight disclosures get logged. Payment disclosures are excluded from the accounting of disclosures. Disclosures made under the health oversight permission are not. Log them.

HHS's guidance on disclosures for treatment, payment, and health care operations is the plain-language reference to hand your front desk when they ask why a payer gets records and a patient's employer does not.

The Log Field People Forget

An accounting of disclosures must reach back six years and must be produced within 60 days of a patient's request. If your only record of a UPIC submission is a shipping receipt in the billing manager's email, you cannot produce it. Add four fields to whatever tracker you already use: date sent, recipient entity, records included, and legal basis (payment or health oversight). Two minutes per response, and the request from a patient's attorney two years later becomes a lookup instead of an archaeology project.

Who Touches the Chart: Role Assignments for a 60-Chart Postpayment Review

A postpayment review naming 60 claims across four providers is where informal processes fail. Assign it before it happens:

  • Billing manager — owns the claim list, reconciles it against your practice management system, confirms which encounters are actually in scope, and tracks the deadline in a shared calendar with a 10-day warning.
  • Records staff — pull only the encounters listed plus any explicitly requested supporting items (orders, results, signed consents). No "while I'm in there" additions.
  • Providers — review their own encounters for completeness before submission, and sign any late attestation your policy permits. They do not change documentation after the fact; they identify gaps for future correction.
  • Privacy officer — verifies the transmission method, confirms the recipient address or portal identity, and records the disclosure in the log.
  • Administrator — signs off on the package and owns the appeal decision if money comes back.

Write the names next to the roles. "Billing" is not a person and will not remember a 45-day deadline in week six.

Transmission: Rank Your Channels Before the Deadline, Not During It

Electronic submission through CMS's esMD gateway or a contractor's secure portal is the cleanest path — authenticated, logged, and no envelope to misaddress. Encrypted secure file transfer is next. Fax remains common and remains the single most reliable source of misdirected-PHI incidents in small practices, because the number lives in someone's muscle memory. If you fax, require a second person to verify the number against the request letter and initial the cover sheet.

A 60-chart package sent to the wrong fax number is a potential breach, and you have 60 days from discovery to complete notifications if the risk assessment does not rule one out. HHS's breach notification guidance sets out the four-factor assessment your privacy officer should be documenting either way.

The Vendor Question Your Medicare Compliance Program Exposes

Audit responses drag your entire vendor chain into daylight. Sort the participants into three buckets, because the paperwork differs.

Not Business Associates

Medicare itself, your MAC, RACs, UPICs, and other program-integrity contractors are not your business associates. They receive PHI as a health plan or as a health oversight agency, not on your behalf. You do not need a BAA with your MAC, and you should not waste a quarter chasing one. Part C plans are health plans — also not business associates for this purpose, though their delegated vendors may be.

Definitely Business Associates

The entities working on your side of the transaction need signed agreements before they see a chart:

  • Outsourced billing and revenue cycle companies
  • Contract coders and coding-audit consultants
  • Release-of-information and record-retrieval services
  • Scanning and document-imaging vendors
  • Cloud storage where you stage audit packages
  • Transcription and AI documentation assistants
  • Law firms handling appeals (yes, even them)

The audit-response consultant you hire in a panic is the one most likely to start work on a handshake. If you need a signature-ready agreement the same afternoon, a guided business associate agreement builder gets you a completed document without a legal-review queue.

The Ambiguous Middle

Clearinghouses, EHR hosts, and portal vendors are business associates, but the operative question during an audit is different: can they produce what you need in the format the contractor requires, on your timeline? Add one line to every renewal checklist — audit-support turnaround and export capability. A vendor who takes 15 business days to produce a legible complete record has just consumed a third of your response window.

Coding and Documentation: Describe Your Process, Don't Guess at Codes

Denials in postpayment review usually come down to documentation that does not support the code submitted, not to fraud. Your job as an administrator is to make code selection a documented process rather than an individual habit.

That means: a written policy naming which code sets and official guidelines your practice follows; a defined role for whoever performs coding (provider, in-house coder, or contractor) with credentials on file; a periodic internal review sampling encounters per provider; and a documented feedback loop when a review finds a mismatch. When an auditor asks how your practice determines code selection, you should be able to answer with a process and a sample, not an opinion.

Two habits that survive scrutiny: date-stamp and attribute every documentation correction so amendments are visibly amendments, and keep your internal review findings in a file you can produce. Practices sometimes hide self-audit results out of fear. Self-identification followed by correction is the behavior the government asks for.

Where Medicare Compliance and HIPAA Paperwork Overlap

Both programs want the same artifacts, and most practices build them twice. A security risk analysis, written privacy and security policies, workforce training records, a sanction policy, an incident-response procedure, and a current vendor inventory with executed BAAs satisfy Security Rule requirements and populate the written-standards and monitoring elements of a compliance program. NIST's SP 800-66r2 maps Security Rule requirements to concrete controls if you want a defensible structure rather than a template.

The gap in most practices is the risk analysis: either it does not exist, or it was done once during EHR implementation and never touched. It is the most frequently cited deficiency in OCR enforcement, and it is also the document a compliance-program reviewer asks for when testing whether your written standards are real. If yours is stale or missing, automated HIPAA risk analysis and policy generation produces the full document set — risk analysis, policies, training records — in hours instead of the six weeks it takes to write from scratch. No product grants a government certification, and nobody should tell you otherwise; what you get is documentation that stands up when someone asks to see it.

HHS also proposed a substantial Security Rule overhaul in January 2025. Nothing in it is final for you to comply with today, but the direction — explicit asset inventories, tighter vendor verification, mandatory periodic testing — matches what audit-ready practices already do.

A 30-Day Setup for Practices Starting From Nothing

Week 1. Name your compliance contact and your privacy officer in writing. If it is the same person, say so and note who covers vacations. Build the vendor inventory: every entity that touches PHI, what they do, whether a BAA exists, and the date it was signed.

Week 2. Write the audit-response workflow described above, with names in the role slots. Create the disclosure log with the four fields. Set your fax-verification rule and put it on paper by the machine.

Week 3. Confirm your security risk analysis exists and reflects your current systems, including remote access and any AI documentation tool your providers adopted without asking. Update policies to match reality.

Week 4. Run a tabletop. Hand your billing manager a fake ADR for eight claims and time the response. You will find the bottleneck — it is usually record retrieval or provider sign-off — and you will find it on a week when nothing is actually due.

Sustained medicare compliance is not a project with an end date. It is a small number of workflows that run the same way every time, documented well enough that a stranger reading the file can tell what happened and who decided it. Start with the vendor inventory and the risk analysis — generate the document set, then spend your attention on the workflow that has an actual deadline attached.