Internal Controls Over SNF Revenue Cycle That Auditors Evaluate
Auditors focus on clinical documentation and coding accuracy to catch SNF reimbursement risk.

Skilled nursing facilities sit inside one of the tightest reimbursement environments in healthcare, and the reason is structural: pay is tied directly to clinical classification, so every coding decision doubles as a financial decision. This piece walks through the checkpoints auditors actually use when they evaluate SNF revenue cycle controls, from the moment a resident is admitted through the cost report that closes out the year, and lays out what separates a control that exists on paper from one that holds up when someone comes looking.
SNF revenue cycle controls and sustained auditor and regulator attention
Payment tied to a clinical score creates a built-in incentive problem. When the diagnosis code, the functional score, or the nursing acuity level determines the check size, errors appear in the coding, and not all of them are innocent. That's the basic tension regulators are watching.
The dollar figures involved make the stakes concrete. The FY 2026 final rule finalized a net 3.2% rate update, which translates into roughly $1.16 billion in additional SNF payments flowing through the system. That's real money moving on the back of clinical paperwork, and it draws sustained regulatory attention rather than a one-time look.
Profitability adds another layer to the story. MedPAC found that, excluding federal relief funds, the aggregate fee-for-service Medicare margin for freestanding SNFs in 2023 sat at 22%, the 24th consecutive year that margin cleared 10%. Two decades of consistent double-digit margins tends to raise a question in a regulator's mind: is that margin coming from efficient care, or from coding that leans favorable? OIG currently runs 13 active work plans aimed at nursing homes, some dating back to 2023, and OIG and CMS have maintained an ongoing enforcement posture targeting facilities where billed services don't line up with the care actually delivered, not a hypothetical threat, but an active one.
PDPM case-mix integrity as the central coding control question
PDPM changed what auditors look for, and understanding that shift matters. Payment used to track therapy minutes; now it tracks patient characteristics, meaning primary diagnosis, functional scores, nursing acuity, and non-therapy ancillary needs carry the financial weight. The audit risk moved from "did the therapy happen" to "was the patient classified correctly," which is a much harder thing to fake convincingly and a much easier thing to get wrong by accident.
PDPM breaks reimbursement into six components: Physical Therapy, Occupational Therapy, Speech-Language Pathology, Nursing, Non-Therapy Ancillary, and a non-case-mix adjusted piece. Each one carries its own case-mix index, and each one can be misstated independently of the others. A facility can nail the nursing component and still misstate the NTA score, so a control that checks the MDS as a whole without checking each component separately is going to miss things.
Then there's the coding map itself, which moved under everyone's feet on October 1, 2025. Thirty-four ICD-10 mapping revisions took effect, and 33 of those 34 diagnoses got reclassified to Return to Provider status, meaning claims using the old mapping bounce back rather than pay out. One diagnosis moved from Acute Neurologic to Medical Management, a smaller change but still consequential for any facility still coding off the old crosswalk. Facilities that didn't update their coding workflows by that date are now generating systematic misclassification risk, not occasional slip-ups.
A more basic question lies at the center of that: does the primary diagnosis on the claim actually explain why the resident needs daily skilled care? A vague or templated diagnosis selection, even one that's clinically defensible in isolation, creates a gap between the code and the record that an auditor can walk right into.
MDS assessment accuracy and the documentation that must support it
The Minimum Data Set is where PDPM classification actually gets decided, so it's also where every auditor examining PDPM compliance starts. Nothing downstream, no billing decision, no revenue calculation, matters if the MDS itself doesn't hold up.
Whether what's coded on the MDS matches what's written in the clinical record is the central control question, simple to state and harder to satisfy. A mismatch there, a functional score that doesn't track with the therapy notes, a nursing acuity level not backed up by documented interventions, is one of the most common triggers for a compliance finding. CMS's newer validation program has specific targets it's watching, including falls with major injury, pressure ulcer and pressure injury rates, Drug Regimen Review with follow-up, Discharge Function scores, Discharge to Community rates, and Transfer of Health Information. Each of those is a specific MDS item with a specific documentation trail behind it, and auditors know exactly where to look for the underlying support.
Every MDS entry needs a documented reason behind it: daily skilled nursing or therapy needs, clinical progress notes, physician orders, and an interdisciplinary care plan that actually reflects what's happening with the resident. Auditors cross-reference each of these pieces against the MDS entries one by one, so a facility with strong clinical documentation but sloppy MDS coding is just as exposed as one with accurate coding and thin documentation. Both halves have to hold.
Front-end admissions and eligibility controls auditors examine before a claim is ever filed
Revenue leakage often starts before a single service gets billed. It starts the moment a resident's record gets entered into the system, and any error introduced there travels through every step that follows, compounding rather than staying isolated.
Auditors look at a defined set of front-end checkpoints: whether the demographic data captured at intake is accurate and complete, whether insurance eligibility got verified and documented before admission (not after), how resident financial responsibility got determined and recorded, and whether hospital transfer records were actually obtained and reviewed against the admission record. If any one of those steps is skipped, the claim built on top of it inherits the gap.
Prior authorization is its own layer of scrutiny. Auditors check which payers require pre-authorization, recertification, or reauthorization, and for which specific services, then check whether each authorization request and approval got documented in the EMR. They also want to know whether an authorization tracking system exists at all, and whether someone with clinical understanding, such as a nursing staff member, is assigned clear responsibility for that process. One recurring weakness auditors flag: authorization tracking that's informal, or split across multiple staff members with no single accountable owner. When that happens, approvals don't consistently land before services get rendered and billed. The facility ends up billing ahead of its own authorization. That pattern becomes visible quickly once someone starts pulling records.
The Triple Check Process as an internal pre-submission control, what auditors look for in how it is run
The Triple Check Process is the internal review most SNFs run before submitting Medicare claims, and it's the pre-submission control auditors expect to find operating, not just referenced in a policy manual somewhere. A typical team pulls together the MDS coordinator, a financial administrator, the director of nursing, social workers, and therapists, and auditors check whether that mix of disciplines is actually represented in practice, with participation documented rather than assumed.
What the process is supposed to catch before a claim goes out: MDS data lining up with the claim, insurance authorization in place and actually covering the billed services, medical records supporting the level of care billed, and hospital transfer records reviewed against the claim, multiple checkpoints, one submission gate.
Auditors don't just confirm the Triple Check happens. They dig into how it happens, and three things tend to separate a real control from a rubber stamp. First, whether responsibilities are clearly assigned to specific people rather than left to "whoever's available" that month. Second, whether meetings are structured, documented, and follow a written checklist, because the meeting record itself becomes the evidence that the control actually operated rather than existing only in theory. Third, whether staff understand the process well enough to execute it consistently and correctly. A facility that can produce the checklist and the sign-in sheet is in a very different position than one that can only describe the process verbally.
Accounts receivable management and denial tracking as auditable control functions
Days AR Outstanding, a standard ratio reflecting how long receivables take to convert to payment, is the metric auditors reach for first when assessing collection efficiency. A rising number over several months tells a specific story: claims are sitting longer, and something upstream, eligibility, authorization, coding, is generating friction that isn't getting resolved.
Auditors want AR aging reports produced and reviewed on a defined schedule, daily or monthly depending on the facility's size and financial condition, and they want management to be able to explain what's driving the aged balances by payer, by denial reason, and by time bucket. A vague answer here (something amounting to "collections are slow") signals that nobody's actually looking at the composition of that balance.
Denial management gets the same treatment. Auditors check whether denials are categorized by root cause, eligibility, authorization, coding, medical necessity, and whether that root-cause data actually feeds back into fixing the upstream process instead of just getting logged and forgotten. A high denial rate concentrated in one payer or one denial code isn't a one-off billing mistake; it's a systemic control weakness that keeps generating the same error until someone addresses the cause rather than the symptom. The sooner rejections and denials get identified, analyzed, and worked, the faster they get resolved, and auditors specifically look for evidence that this loop actually closes rather than running one direction only. Revenue leakage can happen and go unnoticed at any point across the full cycle, from intake through final payment, so auditors trace claims end to end to find exactly where they're falling out.
Payroll-Based Journal submissions and staffing data as a financial control area
Staffing data isn't just an operational metric anymore, it's a financial control area, largely because of Value-Based Purchasing. SNFs have to report nurse staffing hours and turnover data accurately through the Payroll-Based Journal system, and that reported data feeds directly into performance scores tied to payment.
Auditors compare payroll records against PBJ submissions looking for consistency, and even small discrepancies between what payroll shows and what got submitted can move a facility's VBP score. The control question at the root of all of it is this: does the facility have a documented process for reconciling PBJ submissions against actual payroll before hitting submit, or does the data go out unchecked? That reconciliation step, or the absence of one, is exactly the kind of thing auditors ask to see evidence of. The scale of what's riding on this data is not small: projected SNF VBP Program reductions for FY 2026 are $208 million, a number that reflects just how materially staffing-linked quality scores move aggregate reimbursement across the industry.
Cost report preparation and the controls that support accurate reporting
Cost reports carry three categories of data that auditors dig into: financial statement data covering revenue, expenses, and net income, Medicare settlement data reflecting reimbursement adjustments, and utilization data like patient days, bed occupancy, and service volumes. Each category has its own failure points, and auditors know which ones tend to break first.
Within the report, cost centers break expenses down by department, nursing, therapy, dietary, and others, giving auditors a way to check whether reported costs actually landed in the right bucket and match how the facility really operates. Misallocated costs between cost centers are one of the more common findings, not because anyone's hiding anything, necessarily, but because the underlying general ledger and the cost report don't always speak the same language.
The scale of the problem became hard to ignore in a report OIG published. Reviewing 122 cost reports settled by the Novitas MAC, OIG found obvious errors or inconsistencies with Medicare requirements across those reports. That's not a sample flagging a handful of outliers, that's a finding that points to a systemic weakness running across the industry rather than isolated mistakes at a few facilities. Auditors responding to that kind of finding check whether reported costs align with actual expenditures and carry documentation behind them, whether there's a real reconciliation process tying cost report line items back to the general ledger, whether utilization figures come from a reliable source cross-checked against clinical census records, and whether the facility could actually produce what's needed if a MAC desk review or field audit showed up tomorrow.
Related-party transaction disclosure as a cost reporting control auditors specifically target
Related-party transactions get their own dedicated scrutiny inside OIG's broader financial review of SNFs. The rule is straightforward in principle: when a facility pays a related organization, one under common ownership or control, for services, facilities, or supplies, the allowable cost is capped at the lower of that related organization's actual cost or what comparable services would cost on the open market. In practice, enforcing that principle requires the facility to actually know who its related parties are and to price those transactions honestly.
That's not always what happens. A notable OIG report found some SNFs overstated allowable costs by millions of dollars simply by failing to identify or properly adjust related-party transactions, and that's precisely the pattern auditors are trained to look for now. What gets examined: whether ownership disclosures in the cost report are complete and accurate, whether related-party contracts are disclosed with pricing tested against arm's-length comparables, whether the expense detail for related-party services is granular enough to confirm actual cost rather than a marked-up intercompany charge, and whether the facility has any real process for identifying every related party, management companies, therapy contractors, real estate entities, supply companies under common ownership.
Ownership transparency is also becoming a formal requirement rather than a best practice. A CMS final rule dated November 17, 2023 requires SNFs to disclose detailed ownership and management information, including private equity companies and real estate investment trusts, and enrolled SNFs had to submit revalidation by January 1, 2026. That deadline turns what used to be a disclosure recommendation into a compliance obligation with a hard date attached, and it gives auditors a much clearer paper trail to check against when they ask who actually stands behind a facility's related-party arrangements.


