A RAC audit letter shows up in your mailroom on a Monday morning. It gives you 30 or 45 days to produce the complete medical record for 40 claims spanning the last three years, or every one of those claims automatically becomes an overpayment demand. The auditor is paid on contingency. The clock does not stop for you to organize a response. This is the reality of RAC, TPE, and SMRC audit defense in 2026, and it is the reason every hospital compliance officer, home health administrator, DME supplier, hospice medical director, and physician practice manager needs a documented response workflow before the letter arrives, not after.
This is the field guide. What each audit is, what the ADR letter demands, the documentation packet that survives a first-pass review, the appeal ladder that recovers what does not, and the prevention workflow that stops the same denial patterns from recurring next quarter.
1. The letter that ruins your Monday
An ADR letter (Additional Documentation Request) from a RAC, TPE, or SMRC is not a suggestion. It is a request with legal teeth, a hard deadline, and asymmetric consequences. Miss it and the claims become overpayments with no medical necessity review. Respond incompletely and the auditor denies for missing elements before ever looking at clinical merit. Respond thoroughly and on time and you preserve every appeal right in the five-level Medicare appeal ladder.
The pattern most operators fall into: the letter arrives, it gets routed to whoever opens the mail, sits in someone's inbox for four days while the medical records team is on other work, gets escalated on day 7 when someone realizes what it is, and the actual response effort starts with 21 days left on a 30-day clock. That is not a response. That is a scramble. And scrambles lose.
2. RAC, TPE, SMRC, and CERT explained
Four distinct Medicare audit programs, each run by a different contractor, each with different scope, cadence, and consequence. Understanding which one sent the letter is the first thing to determine when it arrives.
3. The ADR letter and the 30-day clock
Every audit sends an Additional Documentation Request (ADR) letter. The letter names the claims under review, specifies exactly what documentation is required, and states the deadline. The deadline varies by program and provider type:
- RAC ADRs: 45 days for hospitals, 30 days for other provider types
- TPE ADRs: 45 days from notification letter
- SMRC ADRs: 45 days standard, 30 days expedited
- CERT ADRs: 75 days initially, 45 days for follow-up
The clock starts on the letter date, not the receipt date. A letter that sits in a mailroom for 7 days before it hits the compliance officer's desk has already burned 15 to 25 percent of the response window. This is a mail-handling problem worth solving before any documentation workflow gets built. Every ADR letter should reach the assigned owner within 24 hours of arrival with a same-day acknowledgement.
4. Who gets audited and how much is at stake
Audit activity concentrates in the categories with the highest historical error rates. The 2024 Medicare improper payment rates by category, from the CMS Improper Payments Report:
If your organization operates in DMEPOS, home health, hospice, or outpatient rehab, RAC and TPE audit activity is not a matter of if but when. Provider organizations in these categories should assume a continuous audit posture, not an episodic one.
5. The audit-ready record packet
Regardless of which audit program sent the letter, the required documentation is the same. A complete audit-ready record packet contains every element below. Missing any one of them is grounds for the auditor to deny the claim without ever reviewing clinical merit.
- The physician order. Signed, dated, and dated before the service was rendered. Verbal orders documented with the signed authentication within the required timeframe.
- The progress note, op note, or ED note. Complete narrative documenting the service, medical necessity, and any complications. Signed and authenticated.
- The history and physical. When applicable (inpatient, surgery). Signed within the required timeframe.
- Diagnostic results. Every lab, imaging, or diagnostic study referenced in the note. Labs must include the specimen collection date. Imaging must include the read, not just the raw image.
- Medication administration records. For every medication administered during the encounter, including PRN doses.
- Discharge summary or discharge instructions. Signed by the discharging provider. Includes discharge diagnosis, medications, follow-up instructions.
- Anesthesia record. For surgical cases. Complete including start and stop times, medications, monitoring.
- Signature attestation. Every entry needs a complete signature (name, credential, date). Illegible signatures need a signature log or attestation statement.
- The claim form and remittance. The CMS-1500 or UB-04 as submitted, the itemized bill, the EOB or 835 remittance.
- Pre-authorization and coverage documentation. If a prior authorization was required, the auth number and approval letter. Coverage verification for the date of service.
6. A five-step audit response workflow
Step 1: Intake and triage within 24 hours of receipt
Every ADR letter is scanned and entered into the audit tracker within 24 hours of physical receipt. Fields recorded: audit type (RAC/TPE/SMRC), contractor, claim count, claim numbers, date range, documentation categories requested, ADR deadline, response method (fax, esMD, mail). Deadline calendared with automatic reminders at day 15, day 7, day 3, and day 1.
Step 2: Record pull and completeness verification
The medical records team pulls every requested claim's complete record within 5 business days. Every record is verified against the 10-element checklist above. Missing elements trigger a physician query or documentation search before the packet is finalized. Missing elements after that trigger a decision: submit with a documented explanation, or hold the claim and file for extension where the program allows.
Step 3: Coder or CDI review before submission
A certified coder or CDI reviewer looks at every packet before it ships. The reviewer confirms the documentation actually supports the billed code, flags any coding that will be indefensible on review, and either recommends a self-audit correction (some overpayments are better self-disclosed) or clears the packet for submission.
Step 4: Submit via the fastest accepted method and confirm receipt
Every Medicare audit program accepts esMD (Electronic Submission of Medical Documentation) via CMS's secure portal. esMD is faster than fax, faster than mail, and produces a receipt confirmation with a tracking number. Use it. Get the receipt in writing. Store it in the audit tracker.
Step 5: Track the finding and prepare the appeal
Every audit response has a decision date. Track it. If the finding is favorable (documentation supported the claim), close the case and log the pattern for prevention. If the finding is a partial or full overpayment demand, the appeal clock starts and you have 120 days to file Redetermination (Level 1). Do not wait 90 days to start the appeal packet. Start it the day the demand arrives.
7. The five levels of Medicare appeal
Every overpayment demand comes with appeal rights. Providers who do not appeal because "it takes too long" or "we probably won't win" are leaving substantial recoverable revenue on the table. Historical ALJ success rates run 40 to 60 percent when providers actually file.
The economic argument for appealing every legitimate denial is simple: on the average RAC overpayment demand at hospital scale of $5,000 to $50,000 per claim, appealing costs a few hundred dollars in staff time and recovers 40 to 60 percent of contested dollars at ALJ. Anything better than a 3 percent recovery rate justifies the appeal work. The success rate is 10-20x that.
8. Denial patterns that repeat across audits
Every audit program has favorite denial reasons. Knowing them lets you fix your documentation upstream before the next audit cycle.
The top 5 auditor denial reasons across programs
- Insufficient documentation of medical necessity. The note does not connect the service to a documented clinical rationale. The most common finding across all programs.
- Signature deficiencies. Illegible, missing, or improperly authenticated. #1 procedural denial reason.
- Missing physician orders. Order was verbal and never authenticated, or was signed after the service.
- Coding does not match documentation. Billed level of service exceeds what the note supports. Big for E/M levels 99214, 99215, 99205.
- Missing supporting documentation. Referenced imaging without the read attached, referenced labs without the results, MAR entries without the underlying order.
9. The prevention playbook
Every audit cycle teaches you something about your documentation weaknesses. The organizations that reduce audit exposure over time treat each audit response as a signal to fix upstream, not just a defensive fire drill.
- Log every audit finding by denial reason. Aggregate by service line, provider, and CPT. The pattern that surfaces in the aggregate is the pattern to fix in the next round of provider education.
- Run internal audits on your highest-risk categories quarterly. Pick 20 claims from DMEPOS, home health, hospice, PT, or high-level E/M and audit them exactly as an outside auditor would. Fix what fails before an ADR letter finds it.
- Feed audit findings back into CDI queries. If auditors are consistently finding weak medical necessity narratives on level 5 E/M, CDI queries should specifically target that pattern in real-time chart review.
- Track your Comparative Billing Report (CBR) status quarterly. CBRs from the CMS Program Integrity Manual show whether your billing pattern is an outlier compared to peers. Outliers get audited first.
- Document your voluntary corrections. Self-disclosed overpayments through the 60-day rule are treated meaningfully better than auditor-discovered ones. If your internal audit finds a real overpayment, disclose it and refund. The alternative is discovery on their timeline with penalties added.
10. Where AI actually helps in audit response
Audit response is one of the highest-leverage AI use cases in the entire revenue cycle. Three specific places:
ADR intake and triage
An AI can read an incoming ADR letter, extract the audit type, contractor, claim numbers, date range, and documentation categories requested, and open a case in the audit tracker with a calendared deadline. What used to take a compliance officer an hour of manual entry runs in seconds.
Documentation packet assembly
For each claim in scope, an AI can pull every referenced element from the EHR (visit note, op note, MAR, anesthesia record, ancillary system outputs, imaging reads), verify against the 10-element checklist, flag missing pieces, and assemble the packet in submission order. The medical records team reviews and ships instead of hunting and gathering.
Appeal drafting for denied claims
For any claim denied on medical necessity, an AI can draft the redetermination letter citing the specific clinical documentation, referencing the Medicare coverage policy that applies, and matching the argument structure that historically wins at redetermination. A human reviewer verifies and submits.
Our AI Biller is what runs these three workflows inside client PM environments. Delivered in 30 days, sits inside the existing audit workflow, and cuts response time per ADR by 60 to 80 percent. Money back if it does not outperform your current process on three metrics you pick.
11. Five metrics to instrument
- Audit intake time. Hours from ADR letter arrival to entry in the audit tracker. Target: under 24 hours. Anything over 72 hours is a mail-handling problem to fix immediately.
- First-pass acceptance rate. Percent of submitted audit responses that survive the auditor's initial review without technical denial. Target: 95 percent or higher. Under 90 percent means signature or completeness issues.
- Overturn rate at Level 1 (Redetermination). Percent of appealed denials overturned at the MAC level. Target: 20 percent or higher.
- Overturn rate at Level 3 (ALJ). Percent of appealed denials overturned at ALJ. Target: 45 percent or higher. Under 30 percent suggests your appeal packets are underdeveloped.
- Repeat finding rate. Percent of new audit findings that match a pattern from a previous audit. Target: under 10 percent. Higher means the prevention feedback loop is broken.
12. Where to start Monday morning
- Audit your audit intake process. How many days does it take from letter arrival to compliance officer's desk? If over 24 hours, this is the first thing to fix. Assign a named owner, a dedicated mailbox, and a same-day acknowledgement standard.
- Pull the last 12 months of audit findings. Aggregate by denial reason, service line, and provider. The top 3 patterns are the top 3 things to fix upstream.
- Run an internal signature audit. Pull 20 random recent charts and verify every entry has a complete signature. If you find any deficiencies, this problem will show up in the next external audit at scale.
- Verify your CBR outlier status. Pull the last two Comparative Billing Reports from CMS. If any of your billing patterns are 2+ standard deviations from peer means, you are near the top of the RAC and TPE targeting list. Fix the pattern or document your legitimate justification for the outlier.
- Score your current audit response workflow against the five-step framework. Any step that is undefined or unassigned is the next thing to close.
Have us build the AI biller that runs your audit response workflow.
The five-step response workflow in this playbook, ADR intake and triage, record pull and completeness verification, coder review, submission and tracking, appeal drafting, is exactly what our AI Biller does. Delivered in 30 days. Lives inside your PM and EHR environment. Money back if it does not outperform your current process on three metrics you pick.
See the AI Biller →13. Frequently asked questions
Want to talk through this for your organization specifically?
A 30-minute call. Bring your top audit categories, your last-quarter ADR volume, and one place you suspect the response workflow is losing time. We will tell you what a first-cycle audit-readiness assessment would surface, what a continuous audit-response workflow would look like for your operation, and whether we are the right partner to build it. No slides, no pitch.
Book a 30-minute consult →