D.1 RAC Region 2 SOW FINAL.pdf

PDF 755 KB Posted

Attached to
RAC Region 2 Federal contract opportunity
Solicitation number
75FCMC21R0018
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

This statement of work outlines requirements for the Recovery Audit Contractor (RAC) Region 2 contract to identify improper Medicare Fee-for-Service payments made by A/B Medicare Administrative Contractors. The contractor will review claims for inpatient, outpatient, physician/non-physician practitioner, laboratory, ambulance, skilled nursing facility, inpatient rehabilitation facility, critical access hospitals, long term care hospitals, ambulatory surgical center, and other provider types excluding DMEPOS and home health/hospice. The contractor must collaborate with CMS and MACs to adjust claims, recoup overpayments, pay underpayments, support the appeals process, and report on reviews through the RAC Data Warehouse and monthly reports. The contractor must meet requirements for personnel, medical review processes, new issue approvals, websites and portals, communication with other contractors, and other program integrity tasks. The statement of work provides extensive details on the scope of the contract.

View the file

Other files for this federal contract opportunity

Other files attached to RAC Region 2, newest first.
File Type Posted
RFP 75FCMC21R0018 RAC 2 Amendment 2.pdf PDF
E.2 QA RFP 75FCMC21R0018 RAC 2.xlsx XLSX spreadsheet
75FCMC21R0018 RAC Region 2 Amendment 1.pdf PDF
RFP 75FCMC21R0018 RAC Region 2.docx.pdf PDF
E.3 Virus Detection Certification.docx DOCX document
E.2 Q&A Template.xlsx XLSX spreadsheet
D.6 Subcontractor Proposal Checklist.docx DOCX document
D.4 Responsibility Questionnaire.docx DOCX document
D.7 Non Disclosure Statement.docx DOCX document
E.1 Proposed Contingency Fee.xlsx XLSX spreadsheet
D.3 Past Performance Questionnaire.docx DOCX document
D.2 Contractor - Offeror Conflict of Interest.docx DOCX document
D.5 Prime Proposal Checklist.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work (SOW) for the Part A/B Medicare Fee-for-Service Recovery Audit Contractor (RAC) –Region 2

(Version 8/25/2021)

I. PURPOSE

II. BACKGROUND

III. REQUIREMENTS

A. GENERAL REQUIREMENTS

B. STATEMENT ON STANDARDS FOR ATTESTATION ENGAGEMENTS

C. SYSTEM REQUIREMENTS AND DATA ACCESSIBILITY

D. RECEIVING AND TRANSMITTING MEDICAL RECORDS/DOCUMENTATION

E. SYSTEM SECURITY REQUIREMENTS

F. INFORMATION SECURITY REQUIREMENTS

IV. PERSONNEL REQUIREMENTS

A. KEY PERSONNEL

B. MEDICAL REVIEW PERSONNEL

C. OTHER PERSONNEL

V. STATEMENT OF WORK TASKS

TASK 1: INITIAL MEETING WITH CMS

TASK 2: PROJECT PLAN

A. DRAFT PROJECT PLAN

B. SUBSEQUENT PROJECT PLANS

TASK 3: IDENTIFICATION OF IMPROPER PAYMENTS ON POSTPAYMENT REVIEW

A. IMPROPER PAYMENTS INCLUDED IN THIS SOW

C. IMPROPER PAYMENTS EXCLUDED IN THIS SOW

D. UNDERPAYMENTS

E. PROVIDER INQUIRIES (NOT REQUESTED BY RAC)

TASK 4: OBTAINING, STORING, SHARING, AND PAYING FOR MEDICAL RECORDS

A. OBTAINING MEDICAL RECORDS

B. ADDITIONAL DOCUMENTATION REQUEST LIMITS

C. PAYING FOR MEDICAL RECORDS

D. MAINTAINING A CASE FILE

TASK 5: CLAIM REVIEW PROCESS

A. AUTOMATED REVIEW

B. COMPLEX REVIEW

C. EXTRAPOLATION

D. TYPES OF CLAIM REVIEW DETERMINATIONS

E. BASIS OF DETERMINATIONS

TASK 6: NEW ISSUE REVIEW SUBMISSION AND APPROVAL

A. NEW ISSUE PACKAGE SUBMISSION AND APPROVAL PROCESSES

TASK 7: WEBSITE AND PROVIDER PORTAL

A. IT ACCESSIBILITY REQUIREMENTS

B. GENERAL WEBSITE

C. APPROVED REVIEW WEBSITE

D. PROVIDER PORTAL

TASK 8: COMMUNICATION AND COLLABORATION WITH OTHER MEDICARE CONTRACTORS

A. COMMUNICATIONS RELATING TO THE CLAIM ADJUSTMENT

B. COMMUNICATIONS RELATING TO APPEALS

C. COMMUNICATION REGARDING POTENTIAL FRAUD

D. REFERRALS

E. SUPPORT OF OIG AND OTHER AUDITS

F. OTHER SUPPORT CONTRACTORS

TASK 9: ACTIVITIES FOLLOWING REVIEW

A. COMMUNICATION WITH PROVIDERS ABOUT IMPROPER PAYMENT CASES

B. REVIEW RESULTS LETTER

C. ALLOWANCE OF A DISCUSSION PERIOD

D. THE CLAIM ADJUSTMENT PROCESS

E. DEMAND LETTERS

F. RECALLED CLAIMS

G. REWORKED CLAIMS

H. COMPROMISE AND/OR SETTLEMENT OF OVERPAYMENT

I. POTENTIAL QUALITY OF CARE PROBLEMS

TASK 10: UTILIZATIONS OF THE RACDW

A. PREVENTING OVERLAP

B. EXCLUSIONS

C. SUPPRESSIONS

D. RACDW REPORTING OF POSSIBLE/IDENTIFIED IMPROPER PAYMENTS

E. ACCURACY INCENTIVE

F. APPEAL AFFIRMATION INCENTIVE

G. INITIAL CLAIM UPLOAD

TASK 11: REVIEW QUALITY ASSURANCE AND ACCURACY

A. RAC REVIEW QUALITY ASSURANCE

TASK 12: SUPPORTING IDENTIFICATION OF OVERPAYMENT IN THE MEDICARE APPEALS PROCESS

AND/OR IN THE DEBT COLLECTION IMPROVEMENT ACT PROCESS

A. DEFENDING IMPROPER PAYMENT DETERMINATIONS AT ALJ HEARINGS

TASK 13: CONFERENCE CALLS, MEETINGS AND TRAVEL

A. CONFERENCE CALLS

B. MEETINGS/TRAVEL

C. ANNUAL RAC OPERATIONAL MEETING

D. PROGRAM INTEGRITY ANNUAL MEETING (PIAM)

TASK 14: MONTHLY PROGRESS REPORTS

A. MONTHLY ADMINISTRATIVE PROGRESS REPORT

B. MONTHLY APPEALS REPORT

C. MONTHLY NEW ISSUES REPORT

TASK 15: CUSTOMER SERVICE AND PROVIDER OUTREACH

A. CUSTOMER SERVICE

B. PROVIDER OUTREACH

C. PUBLIC COMMUNICATIONS

TASK 16: ADMINISTRATIVE PERIOD (CONTRACT CLOSEOUT AND RECONCILIATION)

A. FINAL REPORT

VI. ADMINISTRATIVE AND MISCELLANEOUS ISSUES

A. CONTRACTOR PERFORMANCE EVALUATIONS (CPE)

B. REMEDIES FOR UNSATISFACTORY PERFORMANCE OR NON-COMPLIANCE

APPENDIX A: SCHEDULE OF DELIVERABLES

APPENDIX B: MAP OF RECOVERY AUDIT PROGRAM REGIONS

APPENDIX C: ACCURACY REVIEW DISPUTE FORM

APPENDIX D: 508 STANDARDS PER THE REVISED SECTION 508 OF THE REHABILITATION ACT

I. Purpose The Recovery Audit Program’s mission is to reduce Medicare improper payments through the efficient detection and correction of improper payments. The purpose of this statement of work (SOW) includes all tasks and responsibilities associated with the review of Medicare Fee-for-Service (FFS) claims submitted to, and paid by, the A/B Medicare Administrative Contractors (MACs) in RAC Region 2 (see map in the Appendices section). This excludes Durable Medical Equipment, Prosthetics, Orthotics, and Supply (DMEPOS) claims, and Home Health/Hospice (HH/H) claims. The RAC shall review all applicable claim types submitted to an A/B MAC through the appropriate review methods and work with the Centers for Medicare & Medicaid Services (CMS) and MACs to effectuate the adjustment of claims, recoupment of overpayments, payment of underpayments, support of the appeals process and reporting the status of all reviews by updating the RAC Data Warehouse (RACDW) and providing monthly reports in a timely, accurate, and efficient manner.

II. Background Section 1893(h) of the Social Security Act authorized a nationwide expansion of the Recovery Audit Program, and required the Secretary of the Department of Health and Human Services to utilize RACs under the Medicare Integrity Program to identify underpayments and overpayments and recoup overpayments associated with services and items for which payment is made under Part A or B of Title XVIII of the Social Security Act. The CMS is required to actively review Medicare payments to determine accuracy and, if errors are identified, to pursue the collection of any payment made in error. To gain additional knowledge, Offerors may research the following documents:

• The CMS IOM Pub. 100-08, Medicare Program Integrity Manual (PIM)

• The Debt Collection Improvement Act of 1996

• SEC. 31001 - (3)(A)(ii)(c)(6) and (7)(A)(B)

• The Federal Claims Collection Act, as amended and related regulations found in 42 CFR

• Title 42 CFR Subpart D – Medicare Integrity Program Contractors

• Title 42 CFR Subpart E – Medicare Administrative Contractors;

• National Coverage Determinations (NCDs) and Local Coverage Determinations (LCDs)

• Comprehensive Error Rate Testing Reports

• Recovery Audit Program Status Documents and Reports to Congress available at CMS.gov

Medicare Fee-for-Service Compliance Programs

• Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), Title 2 -- Preventing Health Care Fraud and Abuse; Administrative Simplification; Medical Liability Reform:

― Subtitle C – Data Collection ― Subtitle F – Administrative Simplification

Throughout this document, the term “improper payment” is used to refer collectively to overpayments and underpayments. Situations where the provider submits a claim containing an error (such as an incorrect code, or incorrect/missing modifier), but the payment amount is not altered by the error, are not considered improper payments for the Medicare FFS Recovery Audit Program.

III. Requirements A. General Requirements The SOW is subject to Sections 504 and 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220). All documentation created by the RAC and submitted to CMS is subject to Sections 504 and 508 Compliance for Communications, as applicable. At the discretion of the CMS RAC COR, 508 compliance may be waived for working documents including draft versions of documents and versions of documents not yet accepted by the CMS RAC COR. For more information, see Appendix D- 508 Standards per the Revised Section 508 of the Rehabilitation Act.

Independently and not as an agent of the Government, the RAC shall furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform all requirements of this SOW.

The primary point of contact for the RAC for all operational tasks in this SOW or any aspect thereof shall be the CMS RAC COR or his/her delegate. The RAC shall not contact anyone in CMS with regard to work being performed under this contract without the written approval of the CMS Contracting Office or the CMS RAC COR. The CMS Contracting Officer (CO) shall be the primary point of contact for all contract issues/questions.

The CMS will provide minimum administrative support, which may include standard system changes when appropriate, help communicating with Medicare contractors, policy interpretations as necessary, and other support deemed necessary by CMS to allow the RAC to perform its tasks accurately and efficiently. The CMS will support changes it determines are necessary but cannot guarantee timeframes or constraints. In changing systems to support greater efficiencies for CMS, the end product could result in additional administrative tasks being placed on the RAC that were not previously present. These administrative tasks shall be within the scope of this contract and shall be applicable to the identification and recovery of improper payments.

B. Statement on Standards for Attestation Engagements Each RAC shall be required to complete an annual Statement on Standards for Attestation Engagements Number 18 (SSAE 18 Type II Audit). Each RAC shall be responsible for contracting with an independent and certified public accounting (CPA) firm to perform the audit in accordance with current CMS standards. The CPA firm will ideally have experience in Medicare operations and must have experience performing SSAE 18 Type II audits.

The CMS control objectives can be found in IOM Pub. 100-06, Chapter 7, along with additional general information concerning a SSAE 18 Type II audit. The CMS will dictate which control objectives will be applicable to the audit. The scope of the audits will be dictated by CMS and will be determined no later than 180 days after contract award. Further, a final report from the CPA firm must be submitted to CMS annually, by the award anniversary date. Any corrective action plan must be submitted to CMS within 45 calendar days of the issuance of the final report.

C. System Requirements and Data Accessibility The RAC shall be responsible for obtaining the appropriate hardware, software, and telecommunications equipment to undertake and fully complete all the tasks within this SOW. It is the responsibility of the RAC to have available the personnel needed to design, build, and maintain a system, in the appropriate environment, meeting CMS standards, without assistance from CMS.

Resources available to the RAC include the CMS Risk Management Handbook (RMH) and the CMS Acceptable Risk Safeguards (ARS) publication. The RAC shall comply with the CMS Security Assessment and Authorization (SA&A) methodology, policies, standards, procedures, and guidelines for contractor facilities and systems. When using or disclosing protected health Information (PHI), the RAC shall comply with the Health Insurance Portability and Accountability Act (HIPAA).

The RAC shall comply with CMS policies and other requirements below, as well as documents referenced within those policies:

• CMS Policy for Information Security (PIS), (as amended) – The high-level CMS policy for the CMS Information Security Program.

• CMS Policy for the Information Security Program (PISP), (as amended) - Sets the ground rules under which CMS shall operate and safeguard its information and information systems to reduce the risk and minimize the effect of security incidents. This document will subsequently reference the contractor-applicable ARS manual and the RMH, Volumes I, II, and/or III Security Standards and Procedures.

• CMS Policy for Investment Management and Governance (as amended) – Establishes the policy for systematic review, selection/reselection, implementation/control, and continual evaluation of IT investments at CMS.

• Cloud Services - All cloud-specific requirements will be as defined in CMS Information Security, Section 1.3, Cloud-based Services. However, for information identified as Personally Identifiable Information (PII), Protected Health Information (PHI), and/or Federal Tax Information (FTI), the additional security and privacy requirements listed in the ARS manual Implementation Standards (as amended), as applicable to PII, PHI, and/or FTI, shall be applied within cloud-based services.

• The CMS Information Security website provides a list of applicable security policies and procedures across the program.

A summary of these requirements is listed in the Applicable Laws and Regulations sections of the above listed CMS policies, as well as in the Applicable Laws and Regulations section of the Health and Human Services (HHS) Office of the Chief Information Officer (OCIO) Policy for Information Systems Security and Privacy.

To access CMS data, the RAC shall acquire a secure line between the RAC and the CMS Data Center. The RAC shall acquire the appropriate software to enter into the CMS Data Center.

IBM/Sterling Commerce Connect:Direct software is currently being utilized for this purpose. There is no other alternative software. The RAC shall incur all costs associated with the establishment and maintenance of the secure line, as well as license costs. The RAC shall be responsible for negotiating its own commercial license and costs with the vendor. These costs are not controlled by CMS and may increase at any time.

The RAC may be required to provide testing to ensure data transfers are secure and successful. After the secure line is established, any testing is completed, and any corrective actions identified as a result of testing have been taken, CMS will provide the RAC with all necessary data files under the terms of this contract for the applicable geographic area. The RAC will receive new data updates on a monthly basis. The data file format, data fields available and user agreements are available upon request.

If any problems arise with the transfer of data files, the RAC shall undertake all necessary steps in troubleshooting the cause of the problem. The RAC shall request assistance from CMS only after all steps have been taken to ensure the problem does not originate from the contractor side. If the problem is found to have been caused by CMS, CMS will take steps to re-send the data correctly.

If a newly awarded RAC requires National Claims History (NCH) historical claims data files, for the awarded RAC region(s), the CMS Office of Technology Solutions (OTS) requires the RAC to submit an external hard drive. The external hard drive shall be submitted to the CMS RAC COR. The hard drive shall be capable of storing a minimum of two terabytes of data. A previously used hard drive can be used, but must be stripped of any previous data. A RAC that has more than one RAC region is required to provide a separate hard drive for each region.

The CMS will provide approximately three years of historical claims data divided by provider type to each RAC region. The historical claims data files will contain all provider types, including inpatient, carrier, skilled nursing facility, home health, and durable medical equipment, as appropriate to the awarded contract. The historical claims data will differ in format from the NCH monthly tap file claims transmissions. The record layouts for the historical claims data files are on the following DESY website www.cms.gov/DESY in folders Version K SAS Copylibs and Version K COBOL Copylibs (The version may be subject to change).

As CMS moves towards utilizing Enterprise Data Centers (EDC), the transmission of data may cease.

The RAC may be required to utilize a CMS system in a CMS Data Center to retrieve extracts of claims.

The RAC shall incur any charges associated with the transfer of data. This includes, but is not limited to, cartridges, data communications equipment, lines, messenger service, mail, etc. The RAC shall pay for all charges associated with the storage and processing of any data necessary to accomplish SOW directives.

D. Receiving and Transmitting Medical Records/Documentation http://www.cms.gov/DESY

Although providers are not mandated to electronically store or transmit medical records, the RAC shall possess the technology to accept documentation via electronic transmission. The RAC shall accept medical records submitted electronically, (e.g., fax, CD, DVD, or transmitted via electronic submission of medical documentation (esMD)). Before additional documentation requests (ADRs) may be sent, the RAC shall have the capability to receive medical records via esMD.

The RAC shall also accept medical records/documents submitted as (paper) hard copies. Hard copy records shall be scanned into the RAC’s secure internal document management system. When scanning, the RAC shall ensure, as much as possible, that the scanned documents maintain appearance, size, form, shading, and fonts of the original documents. After successfully scanning, hard copy records shall be disposed of using appropriate records management procedures.

When transmitting medical records/documentation, the RAC shall use a secure transmittal process.

Secure transmittal means sent in accordance with the CMS business systems security manual (e.g., mailed CD, MDCN line, through a clearinghouse, esMD transmittal).

E. System Security Requirements The RAC shall establish and maintain backup and recovery of systems in accordance with “CMS Information Security (IS) Application Contingency Plan (CP) Procedures,” and “CMS Contingency Planning Tabletop Testing Procedures.” The RAC shall comply with all CMS privacy and security requirements. The RAC shall provide all personal computers, printers, and equipment to accomplish the work described herein throughout the contract term.

The RAC shall conduct or undergo an independent evaluation and test of its systems security program in accordance with the CMS Business Partners System Security Manual, IOM Pub.100-17. The RAC’s first independent evaluation and test of its systems security program shall be completed prior to the RAC commencing claims review under the contract. Any deficiencies noted as a result of the independent evaluation and test of its systems security program shall be corrected prior to the processing of claims.

The RAC shall conduct, at a minimum, annual vulnerability assessments of its systems, programs, and facility in accordance with the CMS Business Partners System Security Manual, IOM Pub.100- 17, Continuous Monitoring:

• The RAC shall support CMS validation and accreditation of RAC systems and facilities in accordance with CMS’ SA&A methodology, through which an organization establishes and demonstrates a sound information security posture for its system.

• The RAC shall provide annual certification, in accordance with SA&A procedures, that certifies it has examined the management, operational, and technical controls for its systems supporting the RAC function and considers these controls adequate to meet CMS security standards and requirements.

• The RAC shall ensure security documents are uploaded and security controls are documented timely in the CMS FISMA Control Tracking System (CFACTS). The RAC shall correct any security deficiency, conditions, weaknesses, findings, or gaps identified by all CMS audits, reviews, evaluations, tests, and assessments within the timeframes requested. The RAC shall begin the process to obtain an Authority to Operate (ATO) within 60 calendar days of contract award.

• While the RAC is working towards obtaining an ATO, the RAC is expected to perform all aspects of the SOW manually, using methods approved by the CMS RAC COR. The quality of the work delivered shall be entirely accurate, complete, and containing no errors. Granting of an ATO is based on the RAC’s system meeting/exceeding the minimum Federal, Health & Human Services (HHS), and CMS Security and Privacy policy and standards. The CMS security requirements, policies, procedures, standards, and guidelines are located at CMS Information Security and Privacy Virtual Handbook.

CMS will take all measures necessary to minimize system security risks, including stopping the transmission of NCH data to the RAC, ceasing reviews, and terminating the RAC contract, if necessary.

F. Information Security Requirements In accordance with the Federal Information Processing Standards Publication Standards for Security Categorization of Federal Information and Information Systems, the contractor shall:

• Provide security for any contractor systems, and information contained therein, connected to a CMS network or operated by the contractor on behalf of CMS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

• Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program and CMS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the contractor is responsible under this contract or to which the contractor may otherwise have access under this contract.

• Obtain the HHS/ CMS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy and the CMS Information Systems Security and Privacy Policy.

• Use any information provided to the contractor by CMS or collected by the contractor on behalf of CMS only for the purpose of carrying out the provisions of this contract. The contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the contractor.

• Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

• Respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/CMS IRT teams within 24 hours or as directed by CMS, whether the response is positive or negative. In the event of a suspected or confirmed incident or breach, the contractor shall follow all security incident response procedures as defined by

CMS.

• Comply with all CMS/HHS directed information security and privacy requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall also follow all CMS/HHS directed policies and requirements.

• Maintain all information in accordance with CMS records retention policies and schedules.

IV. Personnel Requirements The RAC shall ensure that the key personnel and additional personnel listed below will comprise an adequate structure to perform the tasks outlined in the SOW. The CMS RAC COR has the right to waive any of the below requirements at their discretion for the key personnel requirements listed below, in order to benefit the Government.

RAC personnel shall be required to undergo a background investigation commensurate with the Homeland Security Presidential Directive (HSPD) 12 position-sensitivity levels for the Personal Identity Verification (PIV) card required to access, develop, or host and/or maintain a Federal information system(s). All RAC employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract.

Additional information regarding PIV card credentialing shall be communicated by the CMS RAC

COR.

A. Key Personnel At a minimum, the RAC shall designate a Project Manager (PM), Contractor Medical Director (CMD), Chief Information Officer (CIO), and Systems Security Officer (SSO) as key personnel. The RAC may designate additional key personnel at its discretion.

The RAC shall submit a CMS approved contingency plan and designate fully qualified (meets the required experience and education requirements) backups for each key personnel role (including a CMS User ID and access to the RACDW). The designated backup personnel shall ensure, to the greatest extent possible, continuity of operations and minimal interruptions in the event of an unexpected departure of key personnel. All backup positions, while working in the backup capacity, may be a part-time RAC employee, but must work full-time while serving in a key personnel position.

The key personnel specified in this contract are considered essential to work performance. At least 30 calendar days prior to the RAC voluntarily diverting any of the specified individuals to other programs or contracts, the RAC shall notify the CMS RAC COR and Contracting Officer (CO), and shall submit a justification for the diversion or replacement and a request to replace the individual.

The request must identify the proposed replacement and provide an explanation of how the replacement's skills, experience, and credentials meet or exceed the requirements of the contract. If the employee of the RAC is terminated for cause or separates from the RAC voluntarily with less than 30 days’ notice, the RAC shall provide the maximum notice practicable under the circumstances.

The RAC shall not divert, replace, or announce any such change to key personnel without the written consent of the CMS RAC COR. The contract will be modified to add or delete key personnel as necessary to reflect the agreement of the parties.

For this SOW, “fully dedicated” means that the individual identified for the position shall be a Full Time Equivalent (FTE) employee. Fully dedicated key personnel may work on another RAC Region contract, in a backup capacity only. This individual may not perform duties on any Medicare/non- Medicare contract or commercial line of business without approval by the CMS CO.

Project Manager The Project Manager shall be fully dedicated to this contract and shall act as a central point of contact with CMS and other stakeholders. The Project Manager shall be available to the CMS RAC COR during normal business hours (8:00 – 5:00 pm ET). If the Project Manager is not going to be in the office due to vacation, etc., the CMS RAC COR shall be notified at least one day in advance. In such cases, the Project Manager will designate a CMS-approved backup person to serve as the central point of contact with CMS. Anyone serving as a backup for the Project Manager will be required to have the ability to answer questions and/or provide data to the same degree that the Project Manager would be able to provide to CMS.

Project Manager Work Experience The Project Manager shall have 10 or more years of previous work experience, with at least three years’ experience as a project manager, preferably with large, complex projects. The Project Manager shall have knowledge of the Medicare program, with knowledge of CMS FFS Recovery Audit Program requirements and activities being preferable.

Project Manager Education The Project Manager shall possess a bachelor’s degree from an accredited institution, plus a master’s degree from an accredited institution, or substitution of four additional years of related work experience in lieu of the master’s degree.

Contractor Medical Director (CMD) The CMD shall be fully dedicated to this contract. The RAC shall arrange for a CMS-approved alternate CMD when the primary CMD will be unavailable for an extended period. The CMD must be either a Doctor of Medicine or a Doctor of Osteopathy who has relevant work and educational experience to oversee the review of Medicare FFS claims. More than one individual’s time cannot be combined to meet the one FTE minimum. The CMD must be approved by CMS.

Primary duties include:

• Briefing and directing personnel on the correct application of policy during claim adjudication, including through written internal claim review guidelines;

• Keeping abreast of medical practice and technology changes that may result in improper billing or program abuse;

• Serving as a readily available source of medical information to provide guidance in questionable claim review situations;

• Recommending when LCDs, NCDs, provider education, system edits, or other corrective actions are needed or must be revised to address RAC identified vulnerabilities;

• Overseeing the medical review process and providing the clinical expertise and judgment to understand LCDs, NCDs and other Medicare policy;

• Participating in the appeals process.

Other duties include:

• Discussing claim review determinations with providers upon request;

• Interacting with the CMDs of other contractors and/or RACs to share information on potential problem areas;

• Participating in CMD clinical workgroups, as appropriate;

• Upon request, providing input to CMS on national coverage and payment policy;

• Participating in CMS/RAC presentations (approved by the CMS RAC COR) to providers and associations.

Please Note: These tasks mentioned are not administrative therefore, non-medical personnel cannot be substituted for the CMD to oversee or perform any of the tasks that involve medical review.

To prevent conflict of interest, the CMD must provide written notification to CMS within three months after the appointment, election, or membership effective date if the CMD becomes a committee member or is appointed or elected as an officer in any state or national medical societies or other professional organizations. The RAC shall ensure that the CMD does not supervise claims from a provider who was their employer within the previous 12 months.

CMD Work Experience

• A minimum of three years’ experience practicing medicine as a board-certified physician with no previous sanctioning or exclusion from the Medicare program.

• A minimum of two years’ prior work experience in the health insurance industry, utilization review firm or another health care claims processing organization.

• Extensive knowledge of the Medicare program particularly the coverage and payment rules.

• Public relations experience such as working with physician groups, beneficiary organizations or Congressional offices.

• CMD Education and Licensure. The RAC shall periodically verify that the CMD’s license is current.

• Experience practicing medicine as a board-certified Doctor of Medicine or Osteopathy or Doctor who is currently licensed to practice medicine. When recruiting CMDs, the RAC should give preference to physicians who have patient care experience and are actively involved in the practice of medicine.

Chief Information Officer (CIO) The RAC shall appoint a CIO to oversee its compliance with the CMS information security requirements. The CIO may oversee lines of business, other than this contract.

CIO Work Experience The CIO shall possess knowledge of and extensive practical experience in information technology (IT) practices, including security controls, in large organizations and significant managerial or other practical involvement relating to IT management.

Systems Security Officer (SSO) The RAC shall designate a principal (i.e., primary) SSO qualified to manage the Medicare information security program and ensure the implementation of necessary safeguards. The RAC’s Systems Security Officer (SSO) may oversee other lines of business, other than this contract.

The SSO shall be dedicated to assisting the CIO in fulfilling compliance with the CMS information security requirements. The SSO shall be organizationally independent of IT operations. The SSO can be within the CIO organizational domain but cannot have responsibility for operation, maintenance, or development. The SSO shall perform duties in accordance with IOM Pub. 100-17, the CMS Business Partner System Security Manual (BPSSM).

SSO Work Experience The SSO shall possess three years of practical experience in information technology (IT) systems security policies, procedures, and practices to manage security administrative duties in large organizations.

B. Medical Review Personnel Certified Coders Each RAC is required to employ certified coders to perform complex coding validations. Certified coders are those professionals who earn their certification from an accredited association such as the American Association of Professional Coders (AAPC) or American Health Information Management Association (AHIMA). Health care professionals are obligated to stay current in their profession. This includes continuing education in their respective discipline and keeping abreast of current medical coding updates, compliance rules, and government regulations.

Certified coders may also be Registered Health Information Administrators (RHIA) and Registered Health Information Technicians (RHIT) who have been credentialed by AHIMA in their field of health information. These coders must have at least five years direct coding or billing experience in the specific coding field. That is, an RHIT or RHIA who will be reviewing DRG Validation must have experience in coding or billing DRGs for at least five years before performing coding review for the RAC. The CMS reserves the right to review the credentials of certified coders, RHIA and RHIT at any time under this SOW.

Registered Nurses Each RAC is required to employ registered nurses with previous experience in medical record review.

Registered nurses are required to have current licenses in nursing in the United States. The RAC must ensure that the license is current. The CMS reserves the right to review the credentials of registered nurses at any time under this SOW.

Therapists Each RAC is required to employ therapists (e.g., physical therapist, occupational therapist, and speech-language pathologist) with previous experience in medical record review.

Therapists are required to have current therapy licenses in the United States. The RAC must ensure that the license is current. The CMS reserves the right to review the credentials of therapists at any time under this SOW.

Other Clinicians In addition to the required clinicians listed above, the RAC may employ other clinicians to perform medical review. However, only licensed clinicians with previous experience in medical record review may review medical records for medical necessity. The clinician must have an understanding of Medicare policies as well as LCDs and NCDs.

Regardless of license type, all clinicians (including registered nurses, therapists, etc.) must possess three years of previous medical record review experience and at least three years of current and/or relevant clinical experience in a variety of health care settings. Examples include but are not limited to: acute care, sub-acute care, long term care, rehabilitative services, home health, skilled nursing, diagnostic services, and outpatient services/settings.

In addition to the CMD, the RAC is encouraged to utilize the expertise of a panel of board-certified clinical specialists, for consultation when performing medical review.

C. Other Personnel Customer Service Program Manager The Customer Service Program Manager must possess a history of providing effective oversight of customer service staff. The Customer Service Program Manager shall have a focus on handling customer inquiries/questions and the education of these customers. The scope of the education provided is limited to only that of the RAC processes. The RAC is prohibited from providing education on the interpretation of Medicare and/or payment policy.

Systems Analyst The Systems Analyst is primarily responsible for an organization's current computer systems, procedures, and design information systems solutions to help the organization operate more efficiently and effectively. The Systems Analyst may be a part-time position. The professional shall possess a bachelor’s degree in an IT related field from an accredited institution, and at least five years of related work experience. In lieu of a bachelor’s degree, an additional three years of related work experience may substituted.

System Administrator The System Administrator is primarily responsible for the upkeep, configuration, and reliable operation of computer systems. The System Administrator may be a part-time position. The professional shall possess a bachelor’s degree in an IT related field from an accredited institution, and at least five years of related work experience. In lieu of a bachelor’s degree, an additional three years of related work experience may substituted.

Application Developer The Application Developer is primarily responsible for designing, developing, and programming successful software. The Application Developer may be a part-time position. The professional shall possess a bachelor’s degree in an IT related field from an accredited institution, and at least five years of related work experience. In lieu of a bachelor’s degree, an additional three years of related work experience may substituted.

508 Compliance Officer The 508 Compliance Officer shall possess a bachelor’s degree from an accredited institution. In lieu of a bachelor’s degree, on-the-job experience may be substituted for the required education on a year-for-year basis.

Any changes to the RAC’s organizational chart (down to the first line management) shall be submitted to the CMS RAC COR within seven business days of the actual change being made. First line management is RAC specific and refers to any individuals charged with the oversight responsibility of audit reviewers, analysts, customer service representatives, and any other staff essential to Recovery Audit operations. The first line management may include personnel involved in daily communications with the CMS RAC COR. This direction excludes changes to key personnel, which shall be communicated immediately to and approved by CMS before the transition occurs.

V. Statement of Work Tasks

Task 1: Initial Meeting with CMS The RAC’s project staff (including key personnel, the Project Manager, CMD, CIO, and SSO) shall meet at CMS in Baltimore, Maryland with the CMS RAC COR and appropriate CMS staff within two weeks of the date of award to discuss the project plan. During the meeting, the terms and conditions of the Region 2 RAC contract will be discussed. Topics will include: CMS staff and RAC staff roles and responsibilities, invoice procedures, security requirements, other CMS expectations for the work being performed under this contract, and any questions or concerns from the RAC.

The RAC shall submit a list, containing the names and roles, of each RAC staff member who will be in attendance. This list shall be submitted to the CMS RAC COR via email, no less than one week prior to the meeting, unless otherwise directed by the CMS RAC COR.

Task 2: Project Plan The Project Plan outlines the resources and timeframe(s) for completing all work activities associated with this SOW.

A. Draft Project Plan Within two weeks after the initial meeting with CMS, the RAC shall submit a draft project plan. The draft project plan will be for the first year of the contract. The draft project plan and all subsequent project plans must be approved by the CMS RAC COR, prior to implementation.

The draft project plan shall include the following:

• Detailed RAC Organizational Chart, identifying the names and titles of all key personnel, first-line management, and all medical review personnel.

• Contingency plan for dealing with unexpected changes in any key personnel. Contingency plans must be approved by the CMS RAC COR, before implementation.

• Provider Outreach Plan, detailing all potential and planned outreach efforts to associations, individual providers, provider groups, Medicare contractors, and other applicable Medicare stakeholders.

• Customer service component.

B. Subsequent Project Plans The Project Plan is an evolving document that, at a minimum, must be updated quarterly. It is the RAC’s responsibility to update the project plan as new review topics are approved. The subsequent project plans shall include the following:

• Detailed RAC Organizational Chart, identifying the names and titles of all key personnel, first-line management, and all medical review personnel.

• Contingency plan for dealing with unexpected changes in any key personnel. Contingency plans must be approved by the CMS RAC COR, before implementation.

• Proposed quarterly projections by: a) review topics b) type of review (automated, complex, extrapolation); c) type of error (medical necessity, incorrect coding, etc.).

• Joint Operating Agreements (JOAs) review and signature due dates.

• Customer service component.

Task 3: Identification of Improper Payments on Postpayment Review The RAC shall perform postpayment review on all Medicare claim types and provider types to identify improper payments (overpayments or underpayments), which were made under Part A or Part B (excluding HH/H and DMEPOS) of Title XVIII of the Social Security Act. This includes review of claims/providers that have a high propensity for error, based on the Comprehensive Error Rate Testing (CERT) program and other CMS analysis.

The RAC shall comply with Reopening Regulations located at 42 CFR 405.980. Before a RAC makes a decision to reopen a claim, the RAC must have good cause and shall clearly document the good cause in review proposals and correspondence (review results letters, ADRs, etc.) to providers.

Additionally, the RAC shall develop processes to minimize provider burden, to the fullest extent possible, when identifying Medicare improper payments. This may include, but is not limited to, ensuring edit parameters are refined to selecting only those claims with the greatest probability of being improper and that the number of additional documentation requests do not negatively impact the provider’s ability to provide care. The RAC shall perform this analysis prior to requesting records.

The CMS has the authority to create/revise ADR limits at any time. ADR limits will be provided via technical direction or as otherwise instructed by CMS.

At its discretion, CMS may impose minimum percentage review requirements by claim type.

Requirements may be based on improper payment findings in the CERT program or other CMS data analysis. The CMS will perform routine evaluations to ensure the RAC is reviewing all claim types as directed.

To assist the Recovery Audit Program, CMS works closely with the claim processing contractors to establish monthly workload figures. The workload figures are typically modified annually, with the option for further modification, as necessary. Workload limits equate to the number of claims that a claims processing contractor is required to adjust on a monthly basis. Should the RAC demonstrate a backlog of claims for a claims processing contractor, and have projections showing the necessity for a sustained higher monthly workload, CMS will consider increasing future workload limits.

A. Improper payments included in this SOW Unless prohibited by Section B or Section C below, the RAC may attempt to identify improper payments (overpayments or underpayments) that result from any of the following:

• Incorrect payment amounts ― Exception: in cases where CMS issues instructions directing contractors not to pursue certain incorrect payments made

• Non-covered services (including services that are not reasonable and necessary under section

1862(a)(1)(A) of the Social Security Act)

• Incorrectly coded services (including DRG miscoding)

• Duplicate services

• Claims from the following provider types:

― Inpatient hospital ― Outpatient hospital ― Physician/Non-Physician Practitioner ― Laboratory ― Ambulance ― Skilled Nursing Facility ― Inpatient Rehabilitation Facility ― Critical Access Hospitals ― Long Term Care Hospitals ― Ambulatory Surgical Center ― Other (such as Comprehensive Outpatient Rehabilitation Facilities, Rural Health Clinics, and Independent Diagnostic Testing Facilities; excluding DMEPOS, Home Health and Hospice)

The RAC shall review all provider types listed above. The CMS conducts periodic evaluations of the RAC’s performance. If the CMS RAC COR determines the RAC is not effectively reviewing all claim/provider types during these evaluations, CMS will consider official contract action.

C. Improper payments excluded in this SOW The RAC may not attempt to identify improper payments (overpayments and underpayments) arising from any of the following:

• Services provided under a program other than Medicare Fee-For Service – For example, the RAC shall not attempt to identify improper payments in the Medicare Managed Care program or Drug Benefit program.

• Cost report settlement process and Medical Education payments – The RAC shall not attempt to identify underpayments and overpayments that result from Indirect Medical Education (IME) and Graduate Medical Education (GME) payments. The RAC shall not review cost report settlements for overpayment/underpayment identification.

• Claims more than three years past the date of the initial determination – The RAC shall not attempt to identify any overpayment or underpayment more than three years past the date of the initial determination made on the claim. The initial determination date is defined as the claim paid date documented in the Common Working File (CWF). Any overpayment or underpayment inadvertently identified by the RAC after this timeframe shall be set aside. The RAC shall take no further action on these claims except to indicate the appropriate status code in the RACDW. The look back period is conducted starting from the date of the initial determination and ending with the date the RAC issues the medical record request letter (for complex reviews) or the date of the overpayment notification letter (for automated reviews).

• Random selection of claims – The RAC shall adhere to Section 935 of the Medicare Prescription Drug, Improvement and Modernization Act of 2003, which prohibits the use of random claim selection for any purpose other than to establish an error rate. Therefore, the RAC shall not use random review in order to identify cases for which it will request medical records from the provider. Instead, the RAC shall utilize data analysis techniques in order to identify those claims most likely to contain improper payments. This process is called

“targeted review.” The RAC may not target a claim solely because it is a high dollar claim but may target a claim because it is high dollar AND contains other information that leads the RAC to believe it is likely to contain an overpayment.

• Claims identified with a Special Processing Number – Claims containing Special Processing Numbers are involved in a Medicare demonstration or have other special processing rules that apply. These claims are not subject to review by the RAC. The CMS attempts to remove these claims from the data prior to transmission to the RAC.

― For example: Providers/suppliers submitting claims subject to prior authorization must include a valid Unique Tracking Number (UTN). The UTN is available on the face of the claim and is therefore, visible to the RAC in its respective National Claims History (NCH) data. The RAC shall exclude from review claims with the UTN present in order to avoid capturing claims subject to prior authorization.

The CMS reserves the right to limit the number of reviews or the time period available for review by RAC, state, claim type, provider type, or any other reason where CMS believes it is in the best interest of the Medicare program to limit claim review. This notice will be in writing (includes e-mail) and will be effective immediately.

D. Underpayments The RAC shall review claims using automated or complex review to identify potential Medicare underpayments. Upon identification, the RAC shall communicate the underpayment finding to the appropriate MAC. The RAC shall not ask the provider to correct and resubmit the claim. The RAC shall obtain approval of the underpayment notification letter language from the CMS RAC COR before issuing the first letter.

For purposes of the Recovery Audit program, a Medicare underpayment is defined as lines or payment group (e.g., APC) on a claim that was billed at a low level of payment but should have been billed at a higher level of payment. The RAC shall review each claim line or payment group and consider all possible occurrences of an underpayment in that one line or payment group. If the medical documentation supports changes to the diagnosis, procedure, or order in that line or payment group that would create an underpayment, the RAC shall identify an underpayment. Service lines or payment groups that a provider failed to include on a claim are NOT considered underpayments for the purposes of the program.

Examples of an Underpayment:

• The provider billed for 15 minutes of therapy when the medical record clearly indicates 30 minutes of therapy were provided. (Certain HCPCS/CPT codes are measured in 15-minute increments and are called “timed” codes. These services require direct (one-on-one) patient contact. When reporting a 15-minute service, the provider should enter (1) in the field labeled units on the claim form. The provider in this scenario is entitled to (2) units.

• The provider billed for a particular service and the amount the provider was paid was lower than the amount on the CMS physician fee schedule.

• A diagnosis/condition was left off the MDS but appears in the medical record. Had this diagnosis or condition been listed on the MDS, a higher payment group would have been the result.

The following will NOT be considered an Underpayment:

• The medical record indicates that the provider performed additional services such as an EKG, but the provider did not bill for the service. (This provider type is paid based on a fee schedule that has a separate code and payment amount for EKG).

• The provider billed for 15 minutes of therapy when the medical record clearly indicates 30 minutes of therapy were provided; however, the additional minutes do not affect the grouper or the pricer. (This provider type is paid based on a prospective payment system that does not pay more for this much additional therapy.)

• The medical record indicates that the provider implanted a particular device for which a device APC exists (and is separately payable over and above the service APC), but the provider did not bill for the device APC.

E. Provider Inquiries (Not Requested by RAC) The RAC does not have responsibility to randomly accept case files from providers for an underpayment case review. If the RAC receives case files from providers that the RAC did not request, the RAC is under no obligation to respond to the provider, and the case files shall be disposed of…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .