Est.

Medicaid Cost Report Audit Defense Documentation Standards

Documentation gaps, not fraud, drive most Medicaid audit findings and can be fixed with process.

Senior Writer · · 11 min read
Cover illustration for “Medicaid Cost Report Audit Defense Documentation Standards”
Healthcare Audit Readiness · September 24, 2026 · 11 min read · 2,423 words

A single number ought to reset the way providers think about audit risk: 77.17% of Medicaid improper payments trace back to insufficient documentation, not fraud, not coding mistakes, not eligibility errors. That figure comes from CMS improper payment reporting, and it means the compliance conversation most facilities are having is aimed at the wrong target. Fraud prevention programs, forensic billing reviews, and eligibility verification systems all matter, but they solve for a smaller slice of the problem than most administrators assume. Documentation, the paperwork trail that proves a claim was earned and coded correctly, is where the real exposure sits, and that's actually good news, because unlike fraud, documentation gaps are fixable with process, not policing.

Auditors, whether working a Medicare claim or a Medicaid cost report, build their case primarily from what a provider hands them in writing. In most of these reviews, the written record carries the weight, and opportunities to explain a judgment call in real time are limited and not guaranteed. The record speaks, or it doesn't. This piece walks through what that record needs to contain at each stage of a Medicaid cost report audit, what's changed for FY 2026, and where CMS's own oversight gaps create both risk and opportunity for providers who keep their documentation tight.

Diagram: Where Medicaid Improper Payments Actually Come From. Visualizes: Show the breakdown of Medicaid improper payment causes, with insufficient documentation at 77.17% dwarfing all other causes (fraud, coding mistakes, eligibility errors).

How a Medicaid cost report audit unfolds in practice

Every audit moves through three phases, and each one asks something different of a provider's paperwork.

Initiation starts with a written notice from CMS or its contractor, laying out the scope of review, the timeline, and instructions for submitting documents. Providers have the right to legal representation starting at this exact moment, not later, and facilities that wait until findings are drafted before calling counsel have already given up ground.

Investigation is where the audit actually gets decided. Auditors comb through medical records, billing records, vendor invoices, and internal compliance policies, and this review happens almost entirely through the documents a provider submits. Staff interviews sometimes happen, but they're not guaranteed, and a provider cannot count on getting a chance to talk an auditor through a gap in the file. A preliminary draft report often follows, with a short window to respond before findings get locked in. That window is narrow. The underlying documentation has to be right before the audit ever starts, not scrambled together after a draft report lands.

Reporting and closeout produce a final audit report stating what was found and whether an overpayment exists. From there, the provider chooses: accept the finding, correct it, or appeal.

Not every audit is random. Some are triggered by patterns, unusually high claim volume, frequent billing adjustments, a concentration of high-cost service claims that stand out against peer facilities. Medicaid audits also carry a distinct risk profile from Medicare audits: financial and licensure consequences can compound, and disputed overpayments sometimes require an administrative hearing to resolve, adding a legal layer that Medicare disputes don't always involve.

The investigation phase deserves the most attention because it's the only phase where the provider has real control. A facility with complete, organized, internally consistent records controls how the story gets told. A facility with gaps has no other channel to make its case. That asymmetry is the whole ballgame.

The baseline documentation obligations that apply to every cost report

Cost reports run on accrual accounting, full stop. Facilities still operating on a cash basis have to convert before filing, and that conversion itself needs to be defensible, not just mathematically correct but documented in a way that shows the conversion logic.

Accrual accuracy comes down to a few concrete habits: costs need to be accrued accurately at period end, and costs tied to service and maintenance contracts need to land in the correct period, not smeared across periods for convenience. None of this works if the underlying documentation isn't sitting there, ready for review, at the moment the cost report gets filed. Auditors don't wait for a facility to go find the paperwork after the fact.

The mechanical requirements matter too. Dollar amounts round to the nearest dollar, and the report has to foot and cross-foot, so the numbers add up both down the columns and across the rows. A submission that doesn't foot creates a material deficiency that can delay or disrupt the review process. A simple arithmetic error can cost a facility weeks of delay before the substantive review even starts.

The minimum documentation package that has to accompany a cost report is longer than most administrators expect. A working trial balance, covering every entity on the cost report, has to tie back to the cost report in a way that is organized and auditor-ready. Depreciation schedules are required, and if book depreciation and Medicaid depreciation diverge, both versions need to be submitted side by side, not reconciled into one number. Facilities with a home office need depreciation documentation that accounts for home office assets separately. Hospital-based nursing facilities carry an extra layer: a depreciation schedule that separates hospital-only assets, NF-only assets, and shared assets, with the shared-asset allocation clearly shown.

Small-dollar assets create their own trap. Anything under $5,000 that gets expensed for Medicaid purposes but capitalized on the books needs a separate Medicaid-only schedule with those assets stripped out. If that step is missed, the reviewer is left reconciling two sets of books that were never meant to match. Amortization schedules, where applicable, round out the numeric side. On the narrative side, purchased management services need supporting documentation, and any home office or management company cost allocation needs a documented basis, backed by cost allocation worksheets that show the math, not just the conclusion.

Documentation Requirements Under the FY 2026 Medicare Bad Debt and Uncompensated Care Rules

The FY 2026 IPPS Final Rule, released in 2025, brought updates that sharpened the documentation standard providers have to meet for Medicare bad debt claims. That distinction matters: the rules haven't changed in substance, but the evidentiary bar for proving compliance with them has gotten more exacting.

Take the 120-day rule. Medicare Administrative Contractors now verify that every payment received on an account restarts the 120-day collection clock. A provider's internal systems have to capture payment activity in enough detail to reconstruct that timeline on demand. A billing system that logs a payment date but not enough context to show how it interacts with the collection period leaves a gap a reviewing auditor will flag.

Dual-eligible accounts carry a documentation requirement that hasn't loosened at all: a valid Medicaid Remittance Advice remains mandatory to support any bad-debt claim tied to a dual-eligible patient. If that single document is missing, the claim doesn't survive review, regardless of how sound the underlying collection effort was.

Electronic bad-debt logs are allowed, which is a practical convenience, but MACs expect the bad-debt log, the collection history, and the general ledger to cross-reference cleanly. Three documents, one story. If the log says one thing and the ledger says another, that inconsistency becomes the finding, even when the underlying facts were fine.

Disproportionate Share Hospital audit documentation: the independent certified audit and its 18-element reporting requirement

DSH payments come with one of the more elaborate documentation regimes in the entire Medicaid system, because the federal government's financial participation in those payments depends on it. States seeking Federal Financial Participation for DSH payments have to submit both an independent certified audit and an annual report, and under 42 CFR 447.299(c), that report has to include 18 distinct data elements alongside the completed audit.

The independent certified audit itself has to verify four specific things, and each one closes off a different avenue for gaming the system. It has to confirm that hospitals actually retain the DSH payment, rather than passing it back through some side arrangement. It has to confirm payments stay within hospital-specific DSH limits. It has to confirm that uncompensated care counted toward the calculation includes only inpatient and outpatient services, nothing broader. And it has to confirm the state separately documented and retained records showing the methodology used to calculate each hospital's individual DSH payment, not just the aggregate number.

Timing on this is fixed and unforgiving: the annual independent certified audit has to be completed by the last day of the federal fiscal year that falls three years after the end of the State Plan Rate Year under review. That's a long runway, but it also means errors can sit undiscovered for years before an audit catches them.

DSH annual reporting now includes a "financial impact of audit findings" element, requiring a quantified estimate of what audit findings actually cost, plus disclosure of data caveats that don't fit cleanly into the other 17 elements, a meaningful shift in what states must report. That's a meaningful shift. It's no longer enough to report that a finding occurred; the state has to put a number on what it means financially.

Skilled nursing facility cost reports: what the CMS-2540-24 transition and QRP rules require documentation-wise

For reporting periods ending on or after September 30, 2025, skilled nursing facilities move to the CMS-2540-24 cost report form, and the new form asks for meaningfully more than its predecessor. Ownership reporting expands to capture more detail on related-party transactions and ownership interests. Facilities with complex ownership structures need to have that documentation organized well before filing season, not assembled under deadline pressure.

Agency and contract labor now gets tracked separately from regular payroll, a change that reflects how heavily some facilities have come to rely on temporary staffing and how differently that cost behaves compared to permanent labor. The form also wants clearer detail on facility characteristics and utilization, along with sharper identification of Medicare Advantage and Medicaid managed-care utilization. Filing itself moves fully electronic, through the Medicare Cost Report e-Filing portal, known as MCReF.

Layered on top of the form change is the FY 2026 SNF PPS Final Rule, effective October 1, 2025, which updates payment rates alongside Quality Reporting Program and Value-Based Purchasing requirements. Those quality metrics aren't a side conversation from the cost report, either: they feed directly into what cost data has to be traceable and consistent.

QRP non-compliance opens a second, separate documentation risk that's easy to overlook because it doesn't run through the cost report. CMS issued QRP non-compliance notifications for calendar year 2025 non-compliance, affecting the FY 2027 Annual Payment Update, with those notifications placed in the iQIES system on August 5, 2026. Facilities had until September 4, 2026, a one-month window, to submit reconsideration requests by email. The consequence lands on the Annual Payment Update, a financial hit that stacks on top of, and is entirely separate from, any cost report disallowance. Two different documentation failures, two different penalties, both hitting the same facility's bottom line.

Filing deadlines round things out: cost reports are due within five months of the close of a facility's fiscal year, and state-level Medicaid filing deadlines generally follow a similar standard.

The Impact of CMS's Own Oversight Failures on Providers Defending Their Positions

CMS doesn't always follow its own rules either. An OIG audit found that CMS did not consistently apply its own policies and procedures when overseeing Medicaid state expenditures reported on the CMS-64 form, the document states use to report Medicaid spending to the federal government for reimbursement.

Quarterly review work papers for five selected states weren't always clear, accurate, or consistent enough for OIG to confirm that CMS analysts had actually completed the required review procedures. Quarterly review work papers for five selected states weren't always clear, accurate, or consistent enough for OIG to confirm that CMS analysts had actually completed the required review procedures. Separately, CMS's handling of deferred expenditures didn't line up with the timely resolution timelines set out in federal regulation, and some deferred payments sat unresolved for years rather than getting closed out on schedule. On top of that, OIG found that CMS's tracking of disallowed expenditures needs improvement before disallowed payment information can be reported accurately and accessed easily.

CMS agreed with all four OIG recommendations. As of the report date, all four remain open and unimplemented, with updates expected December 2, 2026.

What does this mean for a provider sitting across the table from an auditor? It suggests, at minimum, that the agency doing the reviewing is not immune from the same documentation weaknesses it penalizes providers for. That should not read as an invitation to get sloppy. If anything, it cuts the other way: when the reviewing body's own records may be incomplete or inconsistent, a provider whose documentation is clear, self-explanatory, and internally consistent gives an auditor far less room to manufacture a finding out of administrative confusion rather than genuine error. The provider's paper trail becomes the tiebreaker when the government's own paper trail has gaps in it.

Five compliance controls that create audit-defensible evidence before an audit begins

Good documentation doesn't get built during an audit. It gets built in the eighteen months before one, through habits that produce a paper trail almost as a byproduct of doing the work correctly. Five controls stand out.

Quarterly internal coding audits, run on statistically valid sample sizes, create an ongoing record showing a facility catches and corrects its own errors before an outside auditor ever shows up. That record, by itself, changes how a regulator interprets an isolated mistake found later.

Documented training programs for billing and clinical staff matter for a specific legal reason: "reasonable diligence" is the actual standard compliance defense hinges on, and a training program with attendance records and content logs is direct evidence of that diligence.

Written policies covering medical necessity determinations, modifier usage, and authorization tracking give an auditor something concrete to measure claims against. Without a written standard, every judgment call looks arbitrary in hindsight, even when it wasn't.

Annual OIG exclusion list checks, run against every employee and contractor and documented as completed, protect against a liability that has nothing to do with clinical quality: employing someone on the exclusion list creates exposure regardless of how well that person actually performed their job.

Documented response procedures for audit notifications close the loop. When the notice letter arrives, a facility that has already mapped out who responds, what gets pulled first, and how legal counsel gets looped in, is not improvising its opening move under a deadline. Each of these five controls produces a written record on its own, and taken together, they are what "audit-defensible" actually means in practice: a stack of dated, specific documents that were sitting in a file long before anyone from CMS asked to see them.

Sources

  1. CMS Should Improve Its Policies and Procedures for the Oversight of States’ Reported Medicaid Expenditures to Better Protect the Financial Integrity of the Medicaid Program
  2. Instructions
  3. Billing for Medicaid: The Complete 2026 Provider Guide - Claim Max Rcm
  4. Understanding the Medicare and Medicaid Audit Process
  5. General DSH Audit Protocol
  6. Additional Information on the DSH Reporting and Audit Requirements (Part 1)
  7. Medicare Bad Debt Issues
  8. cms.gov

More in Healthcare Audit Readiness