Est.

OIG Work Plan Items Affecting Long-Term Care Providers

OIG's Work Plan signals thirteen compliance risks nursing homes should address before audits arrive.

Senior Writer · · 13 min read
Cover illustration for “OIG Work Plan Items Affecting Long-Term Care Providers”
Healthcare Audit Readiness · September 21, 2026 · 13 min read · 2,999 words

OIG posts its Work Plan in public, and for skilled nursing operators, that list works less like a compliance archive and more like an early warning system. Thirteen active items currently target nursing homes, a number that spans multiple review cycles and continues to grow. The real value here is operational: OIG tells you what it plans to examine before it examines it, and that gap between posting and fieldwork is the entire game. Providers who read the Work Plan when items post get a runway that providers who wait for an audit letter never get, and that difference alone should settle any debate about whether the Work Plan is worth a compliance officer's time.

OIG reviews vulnerabilities across major government health programs, votes on which ones warrant a formal project, and posts the approved item, sometimes years before fieldwork produces a finding. Findings and recommendations follow later, along with tracking on whether agencies and providers actually put them into practice. None of this carries the force of a regulation, and that's exactly where operators get it wrong. Alicia Cantinieri of Zimmet Healthcare, quoted in Skilled Nursing News, said OIG guidance should be treated like rules anyway, because so much of it tracks directly against existing federal requirements already on the books. Calling a Work Plan item "just guidance" and setting it aside is a mistake, not a shortcut.

The backdrop for all of this is the November 20, 2024 release of the Industry Segment-Specific Compliance Program Guidance for nursing facilities, OIG's fullest statement yet of what it expects a compliance program to look like in a SNF. Every item below sits downstream of that document. The sections that follow work through each one in turn, pointing back where useful to how the ICPG's core idea, that compliance is something a facility practices rather than files, shows up in the mechanics of billing, financial reporting, staffing data, and quality metrics.

PDPM billing scrutiny: what the Pinnacle audit tells providers about their own exposure

Diagram: Pinnacle Audit: From 100 Sampled Claims to $31.2 Million. Visualizes: Illustrate the magnitude leap from a sampled audit to an extrapolated liability using three concrete numbers from the article: OIG sampled 100 claims at Pinnacle…

CMS rolled out the Patient-Driven Payment Model in October 2019, replacing the old therapy-minutes model with a system built on six payment components, five of which adjust based on case-mix. That shift, moving reimbursement away from volume of therapy and toward diagnosis and acuity coding, opened a new set of places where billing can go wrong, and OIG has been auditing those places methodically ever since.

The audit series carrying this work, SRS-A-25-010, was announced July 1, 2022, and as of its last update on July 15, 2026, it has grown to eight total projects, seven of them still active, with an estimated completion date in fiscal year 2028. A series that keeps adding projects four years after it launched is speeding up. It's speeding up, and providers who assume this kind of scrutiny fades over time are reading the calendar wrong.

One completed audit inside that series shows what OIG finds when it looks closely, and providers should read the numbers as a floor, not a ceiling, for what a similar review could turn up in their own claims. The review of Pinnacle Multicare Nursing and Rehabilitation Center, closed out November 14, 2025, sampled 100 claims and found 99 of them out of compliance with Medicare requirements. Overpayments on just the sampled claims came to $1.1 million, covering services rendered in 2020 and 2021. Extrapolated across the facility's full claims population, OIG estimated total overpayments of at least $31.2 million.

What drove that number? Incorrect rate code assignment, services billed for patients who didn't need skilled nursing care, and documentation that didn't back up what was billed. The finding that should worry compliance officers most is OIG's conclusion that clinical and billing staff didn't consistently follow the facility's own internal procedures. The finding points to a breakdown between the facility's written procedures and actual practice, which means the compliance program itself wasn't functioning as designed. That's a far harder problem to fix after the fact than a coding mistake. A code gets corrected once. A compliance program that people quietly stopped following needs retraining, rebuilt audit habits, and proof, sustained over time, that the fix actually held.

The audit period was 2020 and 2021, years most facilities probably consider closed business by now. With three new project announcements in this series landing in 2026 alone (March 16, April 15, and June 17), OIG is expanding its PDPM review footprint across multiple facilities, not closing the book on it. Internal audits of rate code assignment and medical necessity documentation stop being optional under those conditions. They become the thing standing between a facility and a settlement of comparable size.

An active OIG work plan item asks a direct question: are SNFs reporting related-party costs the way federal regulations require, and is the allocation of Medicare dollars, including overhead, cutting into what's actually available for resident care? The regulatory standard behind the question is old and well established, requiring that allowable cost for services, facilities, or supplies purchased from a related organization not exceed what that organization actually paid to provide them. Allowable cost for services, facilities, or supplies purchased from a related organization can't exceed what that organization actually paid to provide them, capped at whatever comparable services would cost on the open market.

Why now? Because the SNF ownership landscape has gotten genuinely tangled. Management companies, real estate holding entities, and therapy staffing arms often sit under common ownership with the facility itself, and that structure creates dozens of intercompany transactions in a typical operating year. Each one is a place where cost allocation can drift from arm's-length pricing, whether by design or by accident, and each one is now a potential audit target under this Work Plan item.

The most common failure mode is neglect. It's neglect: a management fee or a lease payment set years ago, never re-benchmarked against market rates, and never documented well enough to show how the number was reached. That gap compounds when it meets the annual audited financial statements, the evidentiary foundation both OIG and CMS lean on when assessing compliance. A facility with incomplete related-party disclosures, or a cost allocation methodology that isn't documented in the audit workpapers, is exposed on two fronts at once: the audit finding itself, and the overpayment demand that can follow it.

For SNFs financed through HUD Section 232, there's a third layer. Borrowers must submit audited financial statements meeting Related-party scrutiny under this work plan item runs alongside other federal oversight frameworks, not in place of them. Related-party agreements need arm's-length pricing documented at the time of the transaction, not reconstructed later under pressure, and annual audit workpapers need to support the cost allocation methodology on their own terms, without leaning on whatever explanation a facility offers after the fact.

Medical director oversight: why PBJ data is now a compliance liability, not just a staffing report

OIG announced a new evaluation focused on medical director engagement in nursing homes, with CMS reviews starting in 2026 and project completion estimated for fiscal year 2027. The scope covers three things: whether medical directors are actually performing the duties required of them, whether Payroll Based Journal data on medical director hours is accurate enough to support real oversight, and where CMS might improve transparency around how nursing homes engage and fund these positions.

CMS requires nursing homes to report medical director hours regardless of whether the director is a salaried employee or an independent contractor, but only onsite hours count. Remote work, consulting calls, chart review from home, policy review done outside the building: none of it can go into PBJ. That's a narrower definition than most facilities probably assume, and it opens a gap between what a medical director actually does and what the federal staffing dataset records.

Cantinieri's read on this, from the same Skilled Nursing News piece, is that thin or inaccurate PBJ hours can create real compliance exposure under F-tag F841, the survey tag governing medical director responsibilities, and that an OIG finding here could elevate the issue within CMS and state survey processes. A data reporting gap becomes a survey-level deficiency. That's the escalation path, and it runs faster than most facilities expect.

OIG isn't approaching this evaluation as a neutral inquiry, either. Reported medical director hours have already raised concerns about the adequacy of engagement in some nursing homes. OIG is walking into this project with a documented suspicion already in hand, not starting from a blank slate. Facilities should audit their own PBJ medical director submissions against the full scope of F841 duties before that evaluation reaches them, and keep contemporaneous, retrievable records of onsite activities, QAPI participation, policy development, and facility assessment contributions. If the paper trail doesn't exist, the hours reported won't defend the position on their own.

Background check compliance: what a multi-state audit series, now largely complete, reveals

The background check series, W-00-24-31553, has been running since March 1, 2023, and as of its most recent update on July 1, 2026, it has produced eight state-level projects. Multiple projects are complete, covering Louisiana, Florida, Alabama, Hawaii, New Jersey, Indiana, Connecticut, and New York, with New York's review closing out the series on July 1, 2026.

The federal standard at the center of this is 42 CFR 483.12(a)(3), which bars nursing homes from employing prospective staff with disqualifying criminal offenses. The National Background Check Program, enacted in 2010, was meant to help states build systems capable of enforcing that standard consistently. OIG didn't launch this series on a hunch, either: prior OIG work had already established that not every state was complying with the program, so this series exists to document a known problem, state by state, one review at a time.

The Connecticut audit's finding is blunt and stated right in its title: Connecticut did not always ensure selected nursing homes complied with federal and state background check requirements. That's not a subtle finding, and it lines up with what the earlier state audits in the series turned up.

So what does a facility in a state that hasn't been individually reviewed do with that? Historically, OIG recommendations from one state's audit have shaped CMS guidance and state survey agency priorities well beyond that state's own borders. The Connecticut and New York findings are relevant reading for operators everywhere, not just in those two states.

The fix isn't complicated to describe, even if it takes real diligence to run consistently. Pre-employment screening has to cover both federal and state disqualifying offenses, background check results have to be kept and retrievable on demand, and the process has to apply the same way to contractors with direct resident contact as it does to employees on payroll.

Medicare Advantage prior authorization denials: the revenue and access problem OIG is quantifying in real time

Diagram: The MA Prior Authorization Denial Funnel: Denials, Appeals, Reversals. Visualizes: Show the dramatic funnel of Medicare Advantage SNF prior authorization outcomes from three data points in the article: of all SNF admission requests…

This may be the most consequential item on the current Work Plan for SNF operators, because it hits revenue and resident access at the same time. Series SRS-E-26-004, announced June 17, 2024 and with projects active through mid-2026, examines how often Medicare Advantage Organizations denied requests for post-acute care in SNFs, long-term acute care hospitals, and inpatient rehab facilities, and what happened when those denials got appealed.

Two OIG reports give the numbers real weight: "Medicare Advantage Organizations Overturned Nearly All Appealed Prior Authorization Denials for Skilled Nursing Facility Admission, Raising Concerns About Initial Denials" (OEI-09-24-00331), and a companion report on the three largest MAOs and their denial rates for long-term acute care and inpatient rehab (OEI-09-24-00330). Across the 19 MAOs reviewed, 12 percent of SNF admission requests were denied collectively, though the range across individual organizations ran from 0.4 percent up to 23 percent. A spread that wide means denial practice varies by plan, not by any shared clinical standard, and that alone should raise questions about how "medical necessity" is even being defined across the industry.

Only 18 percent of those SNF denials were ever appealed. When they were, MAOs overturned 95 percent of them in the enrollee's favor. If 95 out of every 100 appealed denials get reversed, that raises serious questions about the vast majority of denials nobody challenged. OIG itself raised concerns that a portion of initial denials likely involved medically necessary care, and the real problem is the volume of denials that residents or their representatives never appealed.

The contractor naviHealth shows up in this data too. It processed roughly half of all SNF admission requests reviewed and denied 14 percent of them, a higher rate than MAOs handling authorization internally (11 percent) or other contractors in the review (9 percent). Outsourced utilization review, at least here, denied more often than the payers doing it themselves.

Enforcement is catching up to the data. Enforcement pressure on Medicare Advantage is its first stated priority: coordinated enforcement, not passive monitoring. A second track runs alongside it. CMS's move to the V28 risk adjustment model in 2024 was projected to save $7.6 billion, and OIG will check MA coding patterns to see whether those savings actually showed up. That puts risk adjustment coding under the same lens as prior authorization denials.

For SNFs, the practical response is documentation discipline. Log every MA prior authorization denial, track whether residents and their representatives were told about appeal rights, and check that facility processes aren't quietly discouraging residents from filing appeals they're entitled to file.

Quality of care metrics: falls and antipsychotic medication use as audit triggers, not just survey flags

Two clinical areas sit on OIG's active Work Plan for reasons that go beyond resident safety alone: falls prevalence and antipsychotic medication prevalence. The antipsychotic review has been running since 2023; the falls review was announced in 2024. Both remain active into the 2025 and 2026 cycles. OIG flagged these two areas as high risk because they cause serious injury, drive up cost, and involve documentation practices that can obscure what's actually happening from regulatory view.

That last part deserves close attention, because it changes what a finding here actually means. OIG's stated concern isn't only clinical outcomes, but the possibility of records being shaped to dodge regulatory review. An audit finding in this space isn't just "this facility had more falls than its peers." It can mean the facility's documentation doesn't match its actual outcomes, which is a data integrity problem layered on top of a clinical one, and the second problem is usually harder to fix than the first.

CMS already requires every SNF to run a QAPI program, and the November 2024 ICPG goes further, calling for compliance and quality functions to work together instead of sitting in separate silos. Under that guidance, the compliance committee should review resident outcome data, including falls rates and antipsychotic or restraint use, as routine business, not an annual exercise done once and shelved. Surveyors assessing QAPI programs under the ICPG framework check for more than a program's mere existence. They check committee composition, how often it meets, how it prioritizes issues, whether policies actually get reviewed and updated, what corrective action follows a finding, and whether outcomes improve afterward.

So what should a facility do with its own QAPI numbers? Treat elevated falls rates or above-benchmark antipsychotic use as a self-generated audit flag to act on before the next meeting. OIG's entire review posture here is built around finding the gap between what the outcome data shows and what the documentation claims, and a facility that closes that gap internally, before an external reviewer finds it, has already done most of the work OIG's audit is designed to force.

Reading the Work Plan as an operational compliance calendar, not a legal warning

Everything above, taken together, makes one argument: compliance has to be something a facility actually does, day to day, not something it writes down once and files away. The ICPG says this directly, and every section here backs it up the same way: surveyors and auditors interview staff to check that written policy matches daily practice. A policy manual with no operational counterpart is a liability with a table of contents, nothing more.

Treating the Work Plan as background noise carries a real cost, because every item covered here, PDPM billing, related-party cost allocation, medical director PBJ data, background checks, MA prior authorization denials, falls and antipsychotic documentation, was posted publicly before OIG did any of the underlying fieldwork. That's the mechanism this piece has traced start to finish. Providers who read the list when items go up get a genuine head start. Providers who wait to hear about a problem through an audit letter have already lost that time, and no amount of after-the-fact diligence buys it back.

Cantinieri's guidance in Skilled Nursing News points at the same conclusion from a different angle: third-party reviewers work from a facility's own records, so a facility that finds its own system-wide issues before OIG does has already cut its exposure across surveys, audits, and reimbursement reviews at once. That's not a one-time project, and treating it like one is probably the single biggest mistake a compliance office makes here. The ICPG frames risk assessment as something that has to stay current with actual facility operations and reimbursement exposure, adjusting as regulations and enforcement trends shift underneath it. An annual risk assessment done once and filed away doesn't meet that bar, no matter how thorough it looked the day it was written.

Financial statement audits and day-to-day compliance work overlap here in a way that's easy to miss. A well-run annual audit doesn't just satisfy a lender covenant or a HUD reporting requirement. It surfaces related-party cost allocation problems, revenue recognition questions, and documentation gaps in the exact same places OIG's Work Plan items are already looking. Read that way, the Work Plan stops being a list of things to worry about. It becomes closer to a calendar, one that tells providers, with real specificity, where and when the next round of scrutiny is likely to land.

Sources

  1. Skilled Nursing Facility Reimbursement
  2. Inside New and High-Risk Compliance Issues Arising from OIG Recommendations and CMS Regulations
  3. Background Checks for Nursing Home Employees
  4. OIG launches PDPM audits and wants first nursing home it reviewed to repay $31M - McKnight's Long-Term Care News
  5. Nursing home hit in first PDPM audit sues over OIG effort to ‘rewrite history’ with $31M recoupment
  6. leadingage.org
  7. maynardnexsen.com
  8. oig.hhs.gov

More in Healthcare Audit Readiness