Amendment 000002 J.1 Unified_Program_Integrity_Contract_USOW.docx
DOCX document 251 KB Posted
- Attached to
- Unified Program Integrity Contract (UPIC) Federal contract opportunity
- Solicitation number
- HHSM-500-2015-RFP-0122
About this file
J.1 Unified Program Integrity Contract (UPIC) Umbrella Statement of Work (USOW) Amendment 000002
View the file
Other files for this federal contract opportunity
Show all 50
Unified Program Integrity Contract (UPIC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HHSM-500-2015-RFP-0122 Attachment J.1
Unified Program Integrity Contractor (UPIC)
Umbrella Statement of Work (USOW)
ATTACHMENT J.1
Version ________
06/04/2015
This page was intentionally left blank
Table of Contents
| 1. | Scope | 6 |
| 1.1 Purpose of Contract | 7 | |
| 1.2 Background | 8 | |
| 1.3 UPIC Jurisdictions | 8 | |
| 1.4 Medicare | 8 | |
| 1.5 Medicaid | 9 | |
| 1.6 Roles and Responsibilities | 10 | |
| 1.6.1The Centers for Medicare & Medicaid Services | 10 | |
| 1.6.2 State Medicaid Agency | 11 | |
| 1.6.3 Law Enforcement | 12 | |
| 1.6.4 Unified Program Integrity Contractor | 12 | |
| 2. | Applicable Statutes, Regulations, and Documents | 14 |
| 2.1 The Medicare Integrity Program | 14 | |
| 2.2 The Medicare-Medicaid Data Match Program | 14 | |
| 2.3 The Medicaid Integrity Program | 14 | |
| 2.4 The Patient Protection and Affordable Care Act | 14 | |
| 2.5 The Medicare Prescription Drug, Improvement and Modernization Act of 2003 (MMA) | 15 | |
| 2.6 Healthcare Fraud Prevention Partnership | 15 | |
| 3. | Program Goals | 15 |
| 4. | Transition and Implementation Requirements | 16 |
| 5. | UPIC Functional Requirements | 22 |
| 5.1 Identification of Vulnerabilities | 22 | |
| 5.1.1. | Regional Steering Committee | 23 |
| 5.1.1.1 Initial Meeting | 23 | |
| 5.1.1.2 Timing and Purpose | 23 | |
| 5.1.2 Annual Program Integrity Mission | 23 | |
| 5.1.3 All Other Conferences | 24 | |
| 5.2 Data Analysis and Matching Requirements | 24 | |
| 5.2.1 Data Analysis Planning | 24 | |
| 5.2.2. Data Analysis Expectations & Responsibilities | 25 | |
| 5.2.3. Collaboration with States – Data Analysis | 26 | |
| 5.2.4 Functional Data Analysis & Management Activities | 26 | |
| 5.2.5. Data Analysis & Management Reporting | 30 | |
| 5.3. | Lead Management | 31 |
| 5.3.1 Workload Categories | 31 | |
| 5.3.2 Sources of Leads | 32 | |
| 5.3.3 Lead Management Protocol | 33 | |
| 5.3.4 Lead Prioritization | 33 | |
| 5.3.5 Tracking | 35 | |
| 5.4 Investigation Requirements | 35 | |
| 5.4.1 Planning Requirements | 36 | |
| 5.4.2 Executing Requirements | 37 | |
| 5.4.3 Referring Requirements | 37 | |
| 5.4.3.1 Referral to CMS | 37 | |
| 5.4.3.2 Referral to State Medicaid | 37 | |
| 5.4.3.3 Referral for Quality of Care Issues | 37 | |
| 5.4.3.4 Referral to HHS OIG | 38 | |
| 5.4.3.5 Referral to the MAC | 38 | |
| 5.4.3.6 Referral to Law Enforcement | 38 | |
| 5.4.4 Appeals | 38 | |
| 5.4.5 Closing Investigations | 38 | |
| 5.5 Cost Report Audits and Reviews | 39 | |
| 5.5.1 Cost Report Audits for Medicaid providers | 39 | |
| 5.5.2 Cost Report Review for Medicare providers | 39 | |
| 5.5.3 Coordination with CMS | 39 | |
| 5.5.4 Findings and Recommendations | 39 | |
| 5.6 Medical Review Requirements | 39 | |
| 5.7 Edits | 41 | |
| 5.7.1 Program Integrity Edits | 41 | |
| 5.7.2 Shared Systems | 41 | |
| 5.7.3 Evaluating Edit Effectiveness | 41 | |
| 5.7.4 Edit Implementation | 42 | |
| 5.8 Support to CMS | 42 | |
| 5.8.1 Healthcare Fraud Prevention Partnership (HFPP) | 42 | |
| 5.8.2 Command Center | 43 | |
| 5.8.2.1 Command Center Activities | 43 | |
| 5.8.3 Program Integrity Projects | 44 | |
| 5.9 Support to States | 45 | |
| 5.10 Support to Law Enforcement | 46 | |
| 5.10.1 Requests from Law Enforcement Entities | 46 | |
| 5.10.2 UPIC Role in Support to Law Enforcement | 46 | |
| 5.10.2.1 Constraints, Assumptions, and Other Issues | 46 | |
| 5.10.3 Reporting/Monitoring | 47 | |
| 5.11 Education Requirements | 47 | |
| 5.11.1 Educating the Providers | 47 | |
| 5.11.2 Educating the Stakeholders | 48 | |
| 5.11.3 Educating the States | 48 | |
| 5.11.4 Documentation of Provider Education Regarding Improper Actions | 48 | |
| 6. Expected Outcomes | 48 | |
| 6.1 Recommending Administrative Actions | 49 | |
| 6.2 Prepayment Review | 49 | |
| 6.3 Identify Medicare and Medicaid Overpayments | 50 | |
| 6.4 Referrals to Law Enforcement | 50 | |
| 6.5 Coordination | 50 | |
| 6.6 Tracking and Reporting | 51 | |
| 7. Administrative Requirements | 51 | |
| 7.1 Meetings, Workgroup, and Conferences | 51 | |
| 7.1.1. Kickoff Meeting with CMS | 51 | |
| 7.1.2 Command Center Missions | 52 | |
| 7.1.3 Jurisdictional Fraud, Waste, and Abuse Workgroup | 52 | |
| 7.2 Joint Operating Agreements (JOAs) | 52 | |
| 7.3 Key Personnel Requirements | 52 | |
| 7.3.1 Jurisdiction Program Director | 53 | |
| 7.3.2 Medicare Operations Lead | 54 | |
| 7.3.3 Medicaid Operations Lead | 54 | |
| 7.3.4 Medical Director | 54 | |
| 7.3.5 Program Integrity Manager | 55 | |
| 7.3.6 Medical Review Manager | 55 | |
| 7.3.7 Data Manager | 55 | |
| 7.3.8 Chief Legal Counsel | 56 | |
| 7.3.9 Chief Statistician | 56 | |
| 7.4 Stakeholder Coordination and Communication Requirements | 56 | |
| 7.4.1 Appropriate CMS Staff | 56 | |
| 7.4.2 Medicaid State Agency and Medicaid Fiscal Agents | 57 | |
| 7.4.3 Medicare Administrative Contractors | 57 | |
| 7.4.4 Medicaid Fraud Control Units (MFCUs) | 57 | |
| 7.4.5 One Program Integrity (OnePI) and the Integrated Data Repository (IDR) | 57 | |
| 7.4.6 Other Unified Program Integrity Contractors | 58 | |
| 7.4.7 Working with Other Medicare Organizations | 58 | |
| 7.4.8 Office of Inspector General | 58 | |
| 7.4.9 Department of Justice | 58 | |
| 7.4.10 Federal Bureau of Investigation | 59 | |
| 7.4.11 State Agencies for Survey and Certification | 59 | |
| 7.4.12 Law Enforcement Health Care Task Forces | 59 | |
| 7.4.13 State Licensure Agencies | 59 | |
| 7.4.14 State Licensure of Agents and Brokers | 59 | |
| 7.4.15 State and Local Licensure and Enforcement Agencies | 59 | |
| 7.4.16 Professional Societies | 59 | |
| 7.4.17 Quality Improvement Organizations | 60 | |
| 7.4.18 Managed Care Organizations | 60 | |
| 7.4.19 Private Health Plans | 60 | |
| 7.4.20 Other Contractors | 60 | |
| 7.4.21 Other Federal and State Agencies | 60 | |
| 7.4.22 Data Analysis Coordination | 60 | |
| 7.4.23 Coordination with Other Contractors | 61 | |
| 7.5 Information Technology and Security | 61 | |
| 7.5.1 CMS Provided Datasets and Systems | 61 | |
| 7.5.1.1 Integrated Data Repository (IDR) | 61 | |
| 7.5.1.2 One Program Integrity (One PI) | 61 | |
| 7.5.1.3 Fraud Prevention System | 62 | |
| 7.5.1.4 Medicare Fee-for-Service (FFS) Claims Processing Shared Systems | 62 | |
| 7.5.1.5 Medicaid Data | 63 | |
| 7.5.1.6 Unified Case Management System (UCM) | 64 | |
| 7.5.1.7 Electronic Submission of Medical Documentation System (eSMD) | 64 | |
| 7.5.1.8 Other UPIC Proposed Resources | 65 | |
| 7.5.1.9 Other CMS Provided Systems | 65 | |
| 7.5.2 UPIC-Provided Functions | 65 | |
| 7.5.3 Access to CMS Systems | 66 | |
| 7.5.3.1 Data Use Agreement | 66 | |
| 7.5.3.2 Other Systems Access Requirements | 66 | |
| 7.5.4 Hardware and Software Testing | 66 | |
| 7.5.4.1 Test Plan Guidelines | 66 | |
| 7.5.4.2 Telecommunications | 67 | |
| 7.5.4.3General Requirements | 67 | |
| 7.5.5 Security | 67 | |
| 7.5.5.1 Physical and Operational Security | 69 | |
| 7.5.5.2 System Security | 69 | |
| 7.5.5.3 Certification for Compliance with CMS Systems Security | 70 | |
| 7.5.5.4 Authority to Operate | 70 | |
| 7.5.5.5 Administer Security Program | 70 | |
| 7.5.5.6 Correct Deficiencies | 71 | |
| 7.5.5.7 Corrective Action Attestation | 72 | |
| 7.5.5.8 Security Review and Verification | 72 | |
| 7.6 Unified Case Management (UCM) System Requirements | 73 | |
| 7.6.1 Introduction/Overview | 73 | |
| 7.6.1.1 System Activities | 73 | |
| 7.6.2 Planning | 74 | |
| 7.6.3 Executing/Reporting | 74 | |
| 7.6.4 Managing and Monitoring | 75 | |
| 7.7 Quality Assurance Program Requirements | 75 | |
| 7.7.1 Cooperation/Coordination | 75 | |
| 7.7.2 ISO-9000 Certification | 75 | |
| 7.7.3 Quality Control Plan | 76 | |
| 7.7.4 Quality Evaluations | 76 | |
| 7.7.5 Continuous Improvement Program | 77 | |
| 7.7.6 Data Matching Quality Assessment | 77 | |
| 7.7.7 Innovation and Technology | 77 | |
| 8. Other UPIC Projects / Efforts | 78 | |
| List of Appendices | 79 |
1. Scope The Unified Program Integrity Contractor (UPIC), acting as an independent Contractor and not as an agent of the government, shall furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the government, as needed to perform the work described in this Statement of Work (SOW).
For purposes of this contract, when differences or conflicts occur, the order of precedence shall be the Task Order SOW followed by this SOW and then Internet-Only-Manuals (IOMs) unless otherwise specified. The UPIC shall immediately contact the Contracting Officer’s Representative (COR) and/or the Contracting Officer (CO) if discrepancies are identified. The UPIC shall identify any budgetary concerns that may occur as a result of any conflict. The UPIC is advised that any and all references in the SOW (including manuals, IOMs) to “RO-Regional Office” shall also include CPI field offices unless otherwise specified in this SOW. Appendix C contains definitions of abbreviations used throughout this SOW.
1.1 Purpose of Contract
The purpose of this contract is to obtain a Unified Program Integrity Contractor (hereinafter, referred to as “Contractor” or “UPIC”) to detect, prevent, and proactively deter fraud, waste, and abuse in the Medicare and Medicaid programs. UPIC contractors shall perform their responsibilities under the direction of the Centers for Medicare & Medicaid Services (CMS).
Under this contract, the UPICs shall perform numerous functions to detect, prevent, and deter specific risks and broader vulnerabilities to the integrity of the Medicare and Medicaid programs including those that may result from historic billing approaches, as well as those resulting from payment reforms and health care innovations such as the use of electronic health records (EHRs). The UPICs shall operate in a geographic area or “jurisdiction” defined by individual Task Orders. The UPICs shall perform the requirements of this contract in accordance with applicable federal and state laws, regulations, Medicare and Medicaid manuals, and CMS requirements to assure the integrity of the Medicare and Medicaid programs. Internet-Only-Manuals can be found at the following location: http://www.cms.hhs.gov/Manuals/IOM/list.asp#TopOfPage).
The UPICs shall use or interact with certain CMS-required systems in the performance of its functions. Further, the UPICs shall coordinate its activities not only with CMS, but also with agencies at the federal, state, and local levels of government as well as other CMS partners and Contractors.
CMS’ goals for unifying this work are to achieve enhanced detection and prevention of fraud, waste and abuse across the Medicare and Medicaid programs by:
· Consolidating Medicare and Medicaid program integrity activities currently handled by separate contractors;
· Sharing and coordinating information among Medicare and Medicaid partners;
· Emphasizing timely administrative actions; and,
· Strengthening data matching across the Medicare and Medicaid programs to expand the view of provider/supplier billing patterns.
CMS anticipates that this integrated and data-driven approach will lay the groundwork for fostering further program integrity coordination with other private and governmental payers across the entire health care industry. Ultimately, it is through partnership and increased awareness across a variety of programs that health care fraud, waste, and abuse can be reduced thus benefiting all Medicare beneficiaries and/or Medicaid recipients.
1.2 Background
CMS currently relies on a network of Contractors to carryout program integrity work in Medicare and Medicaid. The Zone Program Integrity Contractors (ZPICs) and Program Safeguard Contractors (PSCs) are under contract to perform specific Medicare program integrity functions. The Medicare-Medicaid Data Match (Medi-Medi) program is incorporated as a separate task order under the current ZPIC scope of work. The ZPICs are under contract to conduct Medi-Medi activities including matching Medicare and Medicaid data and investigating potential instances of fraud, waste, and abuse. The Medicaid Integrity Contractors (MICs) are under contract to perform specific Medicaid program integrity functions, including provider/supplier audits. The UPIC will combine and integrate these existing functions into a single contractor in a defined geographic area performing Medicare and Medicaid program integrity work on behalf of CMS.
1.3 UPIC Jurisdictions
The UPIC shall operate in CMS defined geographic areas, or jurisdictions, as found in the map in Appendix B. At a minimum, the UPIC shall have the majority of its offices and staff located in the jurisdiction. See Section 87.3 on Key Personnel for additional requirements.
1.4 Medicare
Medicare is the federal health insurance program for people who are 65 or older, certain younger people with disabilities, and people with End-Stage Renal Disease (permanent kidney failure requiring dialysis or a transplant, also referred to as ESRD).Nearly all Medicare beneficiaries access the majority of their insurance benefits through one of two health care delivery systems – traditional Medicare, also known as Medicare Fee-for-Service (FFS), or Medicare Advantage (MA).
Medicare FFS (Medicare Parts A and B) The Medicare FFS program consists of two distinct parts: (1) Medicare Hospital Insurance (HI) often referred to as “Medicare Part A” and (2) Supplementary Medical Insurance (SMI), or “Medicare Part B”. Services covered under Part A are: hospital inpatient services, skilled nursing facility (SNF) inpatient services, and swing bed services (SNF level in a rural hospital having less than 50 beds), hospice services, and some Home Health services. Services covered under Part B include, the professional medical services of physicians and certain other licensed practitioners and/or certified practitioners, a variety of other services and items such as ambulance, durable medical equipment (DME), prosthetics, orthotics and supplies, and certain institutional services. These include hospital outpatient services, SNF outpatient services, all specialty facility services, such as dialysis for End Stage Renal Disease beneficiaries, outpatient rehabilitation services, regardless of the type of institution, and some Home Health services.
Benefits under Medicare FFS are largely provided under an indemnity insurance model. That is, the beneficiary chooses his/her health care providers/suppliers, the providers/suppliers bill the appropriate Medicare claims administrator for their services, and the claims administrator pays the provider/supplier based on Medicare eligibility, coverage, and payment rules. The CMS relies on a network of contractors to process Medicare FFS claims, enroll health care providers/suppliers and educate them on Medicare billing requirements, handle claims appeals, answer beneficiary and provider/supplier inquiries and detect Medicare fraud, waste and abuse.
Medicare Advantage (Part C) In the Medicare Advantage Program, or Part C, beneficiaries have the option to enroll in any private insurance plan that contracts with CMS to provide all the benefits available under Medicare Part A and B. These private Medicare plans may organize themselves in keeping with one of several health care delivery and payment models (e.g., health maintenance organizations, preferred provider organizations). Medicare Advantage plans are required to cover the same basic benefits that the traditional Medicare program offers, but they are given fairly broad responsibility and latitude to set up their internal requirements and processes as they see fit.
Medicare Drug Coverage (Part D) CMS contracts with licensed risk-bearing entities to administer the prescription drug benefit (Medicare Part D). These Part D plans are referred to as stand-alone, risk-bearing Prescription Drug Plans (PDPs). Many Medicare Advantage plans have added a Part D benefit to their existing program. These plans are known as Medicare Advantage Prescription Drug Plans (MA-PDs). All Part D plans must offer a standard drug benefit, but may also vary the benefit offering within defined parameters.
1.5 Medicaid
Medicaid is a joint federal-state funded health insurance program that is the primary source of medical assistance for millions of low-income, disabled, and elderly Americans. The federal government establishes minimum requirements for the program and states design, implement, administer, and oversee their own Medicaid programs. In general, states pay for the health benefits provided, and the federal government, in turn, matches qualified state expenditures based on the Federal medical assistance percentage (FMAP), which can be no lower than 50 percent.
All states participate in the Medicaid program and as a requirement for receipt of federal matching payments must cover individuals who meet certain minimum financial eligibility standards. Additionally, the states must cover certain medical services, such as physician, hospital and nursing home care, and are provided the flexibility to offer a large number of optional benefits to beneficiaries[footnoteRef:2]. States also have the option to expand their Medicaid programs to cover additional beneficiaries who have income above the minimum financial threshold, up to statutory limits on income levels. State governments have a great deal of programmatic flexibility within which to tailor their Medicaid programs to their unique political, budgetary, and economic environments. [2: (http://www.medicaid.gov/Medicaid-CHIP-Program-Information/By-Topics/Benefits/Medicaid-Benefits.html). ]
| 1.6 Roles And Responsibilities | ||
| 1.6.1 | The Centers for Medicare & Medicaid Services |
The CMS Center for Program Integrity (CPI) oversees Medicare and Medicaid fraud, waste and abuse activities. Program integrity encompasses all causes of improper payments, and covers fraud, waste, and abuse. The Affordable Care Act of 2010 (ACA) strengthened program integrity efforts across Medicare and Medicaid and established requirements for proactive detection and prevention of fraud, waste, and abuse, as well as robust program management, performance measurement, and reporting.
The ultimate objective of strengthening Medicare and Medicaid program integrity is achieved when claims are submitted and paid correctly for covered services that are appropriately provided. In pursuing this objective, CPI strives to have positive impact on the costs and appropriateness of the care provided to Medicare and Medicaid beneficiaries by adhering to principles of operational excellence, leadership and coordination. For the UPIC program, CPI exhibits these principles by:
· Setting national goals and priorities that assure local and regional program integrity activities are consistent with CPI’s national-level strategy, while allowing for swift response to local or regional trends in fraud, waste, and abuse.
· Integrating critical Medicare and Medicaid program integrity activities, including provider/supplier investigations, to support a truly holistic and coordinated Medicare and Medicaid program integrity strategy.
· Leveraging CPI’s centralized fraud detection mechanisms and other tools, for example the Fraud Prevention System and OnePI/IDR.
· Adopting a data driven approach to management of contractors’ work and measurement of their performance using timely and accurate information about their workload and activities through a centralized case management system.
· Requiring contractors to share information (e.g. leads, vulnerabilities, concepts, approaches) with each other whenever that would promote the goals of the program and the efficiency of operations at other contracts.
CPI manages the work of contractors engaged in program integrity activities by issuing guidance in communications such as manual updates describing changes in policy and operations; evaluation of the performance of those contractors based on the work it engages them to do, and activities such as periodic conferences on topics of general interest and targeted sessions with selected subsets of the contractors.
Within CMS, specialists on various Medicare and Medicaid topics will serve as Business Function Leads (BFLs) to assist the Contracting Officer’s Representative (COR) and the Contracting Officer in administering the contract. These BFLs will provide technical guidance to the UPIC on matters within each BFL’s area of responsibility. The BFLs are not authorized to direct changes to contract work.
1.6.2 State Medicaid Agency
Both federal and state governments are accountable for the effective oversight of the Medicaid program. States establish and administer their own Medicaid programs; they determine the type, amount, duration, and scope of benefits within broad federal guidelines. While all state Medicaid programs have financial responsibility for any improper payments identified through program integrity activities, the scope and execution of program integrity activities varies by state. State entities that may be involved in the program integrity oversight include State Medicaid Agencies (SMAs), State Medicaid Inspectors General, Medicaid Fraud Control Units (MFCUs), Medicaid Fiscal Agents (MFAs), State Attorneys General, or Agencies for Program Integrity.
States are critical partners in stewardship of the public trust and are strongly committed to ensuring the accuracy of Medicaid payments and detection/prevention of fraud, waste, and abuse. States promote coordinated efforts to Medicaid program integrity while balancing their existing program integrity efforts, meeting new requirements, and coordinating with federal program integrity efforts.
The States’ roles and responsibilities in the new UPIC environment may include:
a) Learning about, as well as using federal data to support state efforts to identify, deter, prevent, and reduce fraud, waste and abuse, as well as allowing access to state databases to support further state, regional, and national coordination.
b) Assisting the UPIC in identifying and prioritizing the specific risks and broad vulnerabilities to program integrity in their respective Medicaid programs.
c) Educating the UPIC about their state-specific policies, program characteristics, organizational structures, and identifying state-specific priorities and vulnerabilities so that program integrity activities can be tailored to fit an individual state.
d) Identifying more sophisticated tools for data mining and technology deployment that the state may need to assist them in their program integrity efforts or educating others in those tools that the state may already possess that they are using successfully.
e) Collaborating with the UPIC to reduce overlap, inefficiency, and confusion with program integrity efforts, while improving communication and sharing.
f) Assisting in creation of a pathway to leverage the best data sources possible, as well as Medicare’s data analytics, predictive modeling and other resources.
g) Identifying and proposing solutions to remedy barriers to conducting effective program integrity activities.
h) Defining and communicating the states’ vision and expectations for a high performing Medicaid integrity program.
In addition, States have a vital role in responding to emerging program integrity challenges and issues, and assisting in rapid course‐correction to reduce or prevent ineffective approaches and programs. States are important partners in the development of reasonable and useable program integrity policies and functional data exchange systems between local and federal Medicare and Medicaid processes.
1.6.3 Law Enforcement
Some causes of improper payments are potential fraud, and to address those issues, CMS must work closely with a number of law enforcement partners. There must be close collaboration between a variety of partners, including CMS, other program integrity contractors, state agencies, law enforcement agencies, and other entities. Subject to the requirements in the IOM Pub.100-08, the UPIC shall provide support to law enforcement agencies for investigations of potential fraud and abuse.
Law enforcement agencies are important stakeholders in the program integrity process. Each UPIC’s local interactions with law enforcement must remain aligned with CMS’ agency-level approach to such interactions. It is crucial that each UPIC provide CMS with ongoing and sufficient information about its law enforcement interactions so that it is assured that they are in alignment with CMS’ overall approach. Referrals from the UPIC to law enforcement are discussed in the “Investigations” section of this SOW.
1.6.4 Unified Program Integrity Contractor
The CMS currently fulfills its duty to detect, prevent, and deter threats to the integrity of the Medicare and Medicaid programs by engaging separate Medicare and Medicaid integrity contractors. To improve its capacity to swiftly anticipate and adapt to the ever changing and dynamic nature of those involved in health care fraud, waste, and abuse, CMS will engage contractors to perform work across the Medicare and Medicaid program integrity continuum. The UPICs will integrate the program integrity functions for audits and investigations across Medicare and Medicaid, and assure that CMS’ national priorities for both Medicare and Medicaid are executed and supported locally. Through its expertise in proactive data analysis, ability to harmonize Medicare, Medicaid and private sector data and its knowledge of Medicare and Medicaid-related law enforcement processes and actions, each jurisdictional UPIC will also advise CMS regarding possible national strategies, as well as recommend locally or regionally targeted variations and additions in its own jurisdiction to support CMS’ national-level program integrity strategy.
The program integrity requirements that the UPICs will perform, including the expected outcomes, are set out more fully in this document and may be further defined in subsequent Task Orders.
The UPIC shall perform activities that identify and reduce fraud, waste, and abuse by individuals and entities furnishing items and services under Medicare and Medicaid. At the direction of CPI, the UPIC shall perform general and specific activities as indicated by the nature and severity of the issue for each health care provider/supplier under review and the policies, rules, and guidelines set forth in the Medicare and Medicaid programs. The UPIC shall provide detailed documentation in the UCM to support all activities, including any referrals of analytic results or research provided to appropriate entities, as well as completion of the feedback loop with respect to these referrals. The UPIC may be asked, and will be required to respond to requests for information from CMS at any time. All activities undertaken by the UPIC shall be aligned with the national-level and regional program integrity priorities identified and approved by CMS.
To promote open, cooperative, and transparent relationships between Contractors and with CMS, the government shall have rights in data, including items such as models, concepts, approaches, and software in accordance with FAR clause 52.227-17 Rights in Data - Special Works. UPICs are expected and required to share leads, vulnerabilities, conclusions, concepts, approaches, processes, policies, desk references and other intellectual property that is based on the UPIC data and operations whenever that property could promote the goals of the program and the efficiency of operations on behalf of CMS.
2. Applicable Statutes, Regulations, And Documents As a result of combining work across the Medicare and Medicaid continuum, the UPIC shall operate under multiple legislative authorities (refer to Appendix J, Statutes and Regulations, for more information). This is not an exhaustive list:
2.1 The Medicare Integrity Program
The Medicare program integrity responsibilities of the UPICs are authorized by Section 1893 of the Social Security Act (which established the Medicare Integrity Program).
2.2 The Medicare-Medicaid Data Match Program
The Medicare-Medicaid data match responsibilities of the UPICs are authorized by Section 1893(g) of the Social Security Act (enacted in Section 6034(d) of the Deficit Reduction Act of 2005).
2.3 The Medicaid Integrity Program
The Medicaid program integrity responsibilities of the UPICs are authorized by Section 1936 of the Social Security Act (which established the Medicaid Integrity Program).
2.4 The Patient Protection and Affordable Care Act
CMS intends to use UPICs to implement the augmented program integrity authorities found in the Patient Protection and Affordable Care Act of 2010 (more commonly known as the Affordable Care Act or ACA). There are four principal ways that the ACA seeks to improve Program Integrity efforts:
a. Providing additional funding to prevent and fight fraud,
b. Improving provider/supplier screening and compliance,
c. Providing new penalties and allowing for enhanced administrative actions, and
d. Enabling improved data sharing.
CMS is using these authorities to move the Medicare and Medicaid program integrity environment beyond the “pay and chase” model and on a continued path toward a “prevention and detection” model. (More details on these legislative authorities can be found in the attachment section of this SOW.)
2.5 The Medicare Prescription Drug, Improvement And Modernization Act Of 2003 (MMA) The Medicare Prescription Drug, Improvement and Modernization Act of 2003 (MMA) (P.L. 108-173) was signed into law on December 8, 2003. Title I of the MMA established a new voluntary outpatient prescription drug benefit under Part D of Title XVIII of the Social Security Act (the Act). The prescription drug benefit, referred to as Medicare Part D, as well as an employer subsidy for qualified retiree health plans, began on January 1, 2006.
Title II of the MMA modified and renamed the Medicare+Choice (M+C) program established under Part C of Title XVIII of the Act. The program is now called the Medicare Advantage (MA) program. The MMA also introduced a new process for determining beneficiary premiums and benefits for 2006 and future years under which MA organizations will submit a “bid” reflecting their revenue needs for covering the benefits they plan to offer. This new process applied to all MA plans beginning in 2006.
2.6 Healthcare Fraud Prevention Partnership
Section 1128C (a) (2) of the Social Security Act provides authority for the Secretary of HHS and the Attorney General, in carrying out the Fraud and Abuse Control Program established by section 1128C(a)(l), to consult with, and arrange for the sharing of data with representatives of health plans, including Medicaid as well as private plans. CMS has established the Healthcare Fraud Prevention Partnership (HFPP), an ongoing partnership to fight fraud, waste, and abuse across the health care system. The (HFPP) currently has 35 partner organizations from the public and private sectors, law enforcement, and other organizations combatting fraud, waste, and abuse. The partnership is sharing data to assist payers in evaluating trends, recognizing patterns consistent with potential fraud, waste, and abuse, and potentially uncovering schemes or bad actors they could not otherwise identify using only their own information.
3. Program Goals This SOW supports the mission of the Centers for Medicare & Medicaid Services to detect, prevent, and deter fraud, waste, and abuse in the Medicare and Medicaid programs. Specifically, the UPIC program is designed to:
a. Integrate Medicare and Medicaid program integrity activities to support a holistic and coordinated Medicare and Medicaid program integrity strategy;
b. Set national goals and priorities to assure that local or regional program integrity activities are consistent with the CPI’s national-level strategy, while still allowing for regional program integrity activities to respond to local or regional trends in fraud, waste and abuse;
c. Further enable cooperation, communication and sharing of information and best practices between the program integrity Contractors to assure a truly national approach to providers/suppliers or trends that cut across jurisdictions;
d. Adopt a data-driven approach to CMS’ national-level direction of the UPICs’ work by using timely and accurate information about the UPICs’ workload and activities;
e. Leverage CPI’s evolving centralized fraud detection mechanisms and other tools, for example the Fraud Prevention System predictive analytics tool (“FPS”) and the Healthcare Fraud Prevention Partnership (“HFPP”), across the entire nation;
f. Reduce improper payments caused by fraud, waste and abuse.
4. Transition and Implementation Requirements The UPIC shall perform the tasks required to successfully implement program integrity operations, including transition of operations from outgoing program integrity contractor(s). In a successful transition:
· There is minimal disruption to program integrity partner operations (e.g. MACs, States, and Law Enforcement), providers/suppliers, physicians and suppliers.
· There is minimal disruption of ongoing investigations, administrative actions (e.g. payment suspension actions, revocations underway) and active LE cases.
· All appropriate data, files and information are transferred and made accessible to the incoming program integrity contractor.
· All interested parties are kept informed of the transition’s status and progress
· Transition resources are effectively and efficiently used and transition activities are completed on schedule.
4.1. Transition And Implementation Requirements
The UPIC shall perform the activities necessary to establish and operate a program integrity operation per the requirements of this SOW, including the orderly transfer of all Medicare and Medicaid data, records, and operations from all outgoing ZPICs, PSCs, and MICs within its jurisdiction. The UPIC shall develop a Jurisdiction Implementation Project Plan as described in 4.12 of the SOW. The UPIC shall establish and maintain through the course of the implementation and transition an experienced implementation and transition management team.
4.1.1. Implementation Period
The start of any implementation period will be defined in individual Task Orders and shall include, at a minimum, the following tasks:
| a. | Transition of workload from one or more outgoing contractors. The transition period timeframe shall be prescribed in the Task Order SOW. |
| b. | Coordination with stakeholders. |
| c. | Working with the entities listed in Section 7.2 on establishing Joint Operating Agreements (JOAs). |
| d. | Establishing connectivity to CMS and other appropriate systems and testing this access, including establishing Data Use Agreements (DUAs). The UPIC shall establish DUAs early in the implementation period so that it has access to systems and can begin processing work in the required timeframes (see Appendix Q, Data Use Agreement). Systems and applications to which the UPIC must establish connection, gain access and test include: |
· Connection to CMSNet
· Access to the CMS Enterprise Portal
· Access to One PI and One PI Business Intelligence Tools
· Access to the CMS Unified Case Management System
| e. | Hiring and training staff. |
| 4.1.2. | Jurisdiction Implementation Project Plan |
The UPIC shall develop, execute, and maintain a Jurisdiction Implementation Project Plan for accomplishing the activities necessary to establish and operate a program integrity operation per the requirements of this SOW. The plan shall be consistent with the UPIC’s proposed implementation efforts. The Plan shall include a detailed description of all activities required to transfer all operations, including but not limited to:
| a. | Open, Closed, and Pending Investigations |
| b. | Open, Closed, and Pending Referrals |
| c. | Open, Closed, and Pending Audits |
| d. | Open, Closed, and Pending Administrative and Enforcement Actions |
| i. | Payment Suspensions |
| ii. | Revocations |
| iii. | Prepayment Review |
| iv. | Post-payment Review |
| v. | CMS Civil Monetary Penalties |
| vii. | Recalcitrant Providers |
| viii. | Other administrative or enforcement actions specific to the outgoing contractor(s) |
| e. | Open, Closed, and Pending Requests for Information |
| f. | IT Implementation and Test activities |
| g. | Medical Records |
| h. | Stakeholder Contacts |
The UPIC shall define a work breakdown structure (WBS) that addresses the milestones, resources, and constraints of the project, including those for transitioning the program integrity workload from the outgoing contractor(s). The Jurisdiction Implementation Project Plan shall be submitted in accordance with the Deliverables Schedule, Appendix A.
4.1.3. Risk Management Plan
The UPIC shall develop, execute, and maintain a Risk Management Plan. The Risk Management Plan shall include jurisdiction-wide risks and a periodic assessment of new risks as well as mitigation and contingency planning where appropriate. The Risk Management Plan shall serve as a project management tool for the UPIC to successfully implement the program and for CMS to effectively oversee the transition and implementation.
| 4.1.4 | Information Technology Systems Plan |
| The UPIC shall develop an IT Plan that shall include, at a minimum, the following: |
· Description of the UPIC’s data access plan, including the UPIC’s plan for, at a minimum, establishing read-only access to the appropriate Medicare and Medicaid claims processing shared system(s), configuring the applicable data (i.e. Medicare Parts A, B, C, D, DME, HH+H and Medicaid), and obtaining denial data.
· Description of assumptions and constraints under which each type of analysis shall be performed.
· A list and description of data files necessary to conduct the data analysis.
· A list and description of data the UPIC would be required to access from either CMS or the MAC(s) or plan sponsors.
· Schedule of how often new or updated data would be needed.
· Description of the software systems, products, and tools that are being proposed for use, including the licensing restrictions.
· Certification that the hardware and software being proposed have the capacity to manipulate the anticipated volume of data.
· Description of how the UPIC plans to use the hardware and software products.
· Description of how the UPIC will assure compliance with The Privacy Act of 1974 and any subsequent statutory revisions, such as HIPAA.
· Other items as identified by the UPIC.
The IT Systems Plan shall be submitted in accordance with the Deliverables Schedule, Appendix A.
4.1.5 Implementation Period Reporting
The UPIC shall regularly report on the status of the implementation, to include the following basic work elements:
Project Management - This element includes organizing project staff and workgroups, preparing the various plans required by CMS, conducting meetings, monitoring and reporting progress, issue/problem resolution, managing costs, and managing risk.
Communications - Activities include communicating with program integrity partners such as MACs, States and Law Enforcement, providers/suppliers, beneficiaries, medical/specialty groups, trading partners, and all other participants and stakeholders in the project.
Program Integrity Operations - This element involves activities associated with preparing, maintaining, or closing down the business environment. Tasks include preparing operational activities, due diligence, asset inventory, and interaction with other organizations involved in the transition.
Resources/Infrastructure - Activities include personnel activities, training, and the preparation of facilities and associated infrastructure.
Financial - This element includes banking arrangements, accounts receivable review, CMS required reporting activities and cost reporting.
Cutover/Workload Transfer - This area includes file preparation, storage, and the activities associated with the actual cutover of program integrity operations and transfer of files.
The UPIC shall consult with the COR to establish the submission schedule for this report.
| 4.2. | Fully Operational Requirements | |
| 4.2.1. | Fully Operational Period |
After the implementation period, the UPIC shall assume full responsibility for all activities prescribed in the SOW and subsequent Task Order SOWs.
4.2.2 Monthly Status Report
The monthly status report shall be submitted for the prior month’s activities into the CMS ART system. The CORs and the UPIC shall agree upon the content of the Monthly Status Report if information is required other than described below. The Monthly Status Report shall include, at a minimum:
· Any FPS issues
· Report on any JOA issues
· Medicare and Medicaid Overpayments referred
· Administrative actions referred to the State
· State vulnerability coordination efforts
· Summaries of meetings and areas of concentration for the upcoming month
· Issues of concern that require the Centers for Medicare & Medicaid Services’ action
· Updates with regard to quality assurance activities and ISO registrations
· Any unresolved issues from the prior month
· Appeals information
· Any innovations implemented.
· Quality of care referrals
· A list of all compromised numbers identified in the previous month
| 4.3. | Outgoing Transition Activities (End Of Contract) | |
| 4.3.1. | Workload Closeout Project Plan |
The UPIC shall price all regional task orders based on the transition out beginning three months prior to the end date of the final period of performance. The UPIC will be expected during this time to maintain operations while also meeting the below transition out activities. For other types of task orders the timeframes for transition out and the applicability of USOW sections 4.3.1, 4.3.2, & 4.3.3 will be defined at the order level. At the end of jurisdiction contract period of performance the UPIC is required to develop, maintain, update, and follow a Workload Closeout Project Plan to provide for the transfer of functions and operations at contract end and report its status. The UPIC will confer with the CMS COR regarding the submission timeframe for the plan.
The outgoing contractor’s plan shall provide detailed tasks reflecting the activities necessary for the outgoing contractor to provide data to the incoming UPIC, and to maintain operational standards during the workload closeout period, and shall include all the tasks required for the transition of program integrity activities.
The outgoing contractor shall also provide the incoming UPIC with its Workload Closeout Project Plan and shall coordinate the plan with the incoming UPIC’s implementation plan.
4.3.2. Workload Closeout Meetings
At the end of a contract period of performance the UPIC is required to attend meetings and provide appropriate staff to participate in the various functional workgroups that may be established during the workload closeout period, including:
| a. | Kickoff meeting organized by the incoming UPIC; | ||
| b. | Weekly transition workgroup teleconferences or meetings; | ||
| c. | Biweekly transition status teleconferences or meetings with the incoming UPIC; | ||
| d. | Lessons-learned conference that will be held by the new contractor; and | ||
| e. | Ad hoc meetings as necessary. | ||
| 4.3.3. | Workload Closeout Risk Management Plan |
At the end of a contract period of performance the UPIC is required to develop, execute, and maintain a Workload Closeout Risk Management Plan. The Workload Closeout Risk Management Plan shall include a monthly assessment of new risks and mitigation and contingency planning where appropriate for the transition of its operations and the transfer of Medicare and Medicaid data or through identification of patterns of behavior reports by beneficiaries, employees, or other individuals, or by analysis of the payment systems for potential weaknesses. Timeframes for submission of the plan will be provided by the CMS COR.
5. UPIC Functional Requirements This section describes the program integrity functional requirements the UPIC shall perform. The UPIC program integrity activities will be highly focused on activities leading to timely and successful implementation of administrative actions.
5.1 Identification of Vulnerabilities
A vulnerability is an instance of potential Medicare or Medicaid fraud, waste, or abuse identified though the analysis and management of provider, supplier, and beneficiary data or through identification of pattern of behavior reports by beneficiaries, employees, or other individuals, or by analysis of the payment systems for potential weaknesses. The UPIC and its partners (e.g. MACs, Law Enforcement, and State Medicaid Agencies) shall work together and communicate frequently in order to keep each other appraised of potential areas of vulnerability and to avoid duplication of efforts.
In consultation with CMS, the UPIC shall review and analyze a variety of data to identify vulnerabilities and specific providers/suppliers for review and investigation within its jurisdiction. Central to this analysis is the Fraud Prevention System (see Section 5.2.2. d.). The UPIC shall provide CMS with recommendations for possible controls, audits, or policy changes to reduce the vulnerability. Further, the UPIC shall be proactive and innovative, using many different sources and techniques for analyzing data in order to reduce any of its risks within this SOW.
The UPIC shall work with and coordinate with, entities and partners including, but not limited to, CMS, State Medicaid Agencies, MACs, Federal stakeholders, the HFPP entities and partners, and Law Enforcement representatives.
The UPIC shall submit identified program vulnerabilities at CPIVulnerabilityIntake@cms.hhs.gov unless otherwise directed by CMS. As part of the vulnerability submission, the UPIC shall provide recommended corrective actions to address the vulnerability identified. For example, the UPIC may recommend Local Coverage Determinations (LCDs), National Coverage Determinations (NCDs), state policy changes, model development, provider education, system edits or other actions needed to address the vulnerability.
5.1.1 Regional Steering Committee
The UPIC shall support CMS and State program integrity efforts by convening program partners and to provide opportunities for collaboration, guidance, and information sharing on program vulnerabilities and analysis results. The UPIC shall serve as the organizer of the steering committee and conduct the administrative work of facilitating steering committee meetings. With input from CMS, States, and other participants, the UPIC shall also customize a charter for the steering committee.
Participating State Medicaid Agencies will be asked to assign a person to act as a member of the regional steering committee (this person shall be identified in JOAs with State Medicaid Agencies).
5.1.1.1 Initial Meeting
The UPIC is responsible for the logistics of setting up the first meeting of the steering committee. This includes locating a venue, notifying participants of the date, drafting the agenda, and obtaining input from the co-chairs and maintaining minutes.
5.1.1.2 Timing and Purpose
The initial steering committee meeting should occur during the implementation period of the program. Its purposes include:
a. Briefing members on the UPIC’s purpose and function.
b. Providing an update to the partners on the progress of implementation.
c. Drafting the steering committee’s charter.
d. Discussing and defining the members’ roles and responsibilities.
e. Brainstorming potential vulnerabilities for the UPIC to consider as it develops its analysis strategy.
f. Arranging for ongoing vulnerability identification, analysis, and mitigation activities to occur between meetings.
g. Planning for future meetings.
5.1.2 Annual Program Integrity Mission
CMS shall facilitate a national mission with representatives from each UPIC for data sharing exercises. The Annual Program Integrity Mission provides a forum for education and information sharing. The conference will focus on two main areas. The first is the sharing of standard information on Medicare and Medicaid policy and data. This allows new staff to get a basic understanding of the two programs and provides updated information on the changes that are occurring. The second area of focus is contractor information sharing. This includes challenges and lessons learned relating to issues with connectivity, data matching, and investigation development as well as success stories relating to the discovery of program vulnerabilities, and development of leads, investigations, and potential fraud cases. The UPIC shall be prepared to attend and share pertinent program integrity activities in their jurisdiction.
5.1.3 All Other Conferences
On an annual basis, by task order, the UPIC shall submit a list of preferred conferences to the COR for approval that are relevant and necessary as part of the work outlined in a specific task order. Annual request for travel attendance should be consistent with the UPIC’s original cost submission and shall not be construed as permission to incur costs over an agreed to cost ceiling or established price. Actual attendance shall be at the discretion of CMS.
5.2 Data Analysis and Matching Requirements
CPI is committed to driving continuous improvements in program integrity performance and believes that accurate data and relevant, efficient data analysis is integral to strong program integrity efforts. The knowledge of data and experience with a wide range of analytical tools is integral to the work performed by the UPIC.
In performing this work, the UPIC shall be prepared to work in CMS systems, with CMS as the owner of the data, algorithms, statistical methods, and results. Results of data analysis, including leads, shall be documented by the UPIC and maintained in the Unified Case Management System or an alternative system as directed by CMS. Additional details regarding data analysis is given in IOM Pub. 100-08 and the Medicaid Program Integrity Coordination Policies and Procedure Manual (PPM). The PPM is available in Appendix G.
5.2.1 Data Analysis Planning
Work phases involving data, data analysis, and data matching include:
a) During the Implementation Phase, the UPIC shall participate in meetings with outgoing contractors and CMS regarding the transfer of data and information. The UPIC shall collaborate with participating stakeholders and submit a Data Analysis Project Management Plan that describes current status, as well as future plans for the data. The Data Analysis Project Management Plan shall be submitted in accordance with the Deliverables Schedule, Appendix A.
b) During the Fully Operational Phase, the UPIC shall use data and tools to perform comprehensive research, data analysis, and trending activities. The planned source for the majority of the data and tools to be used will be in the OnePI/IDR. While awaiting data sources that may not be fully available in the IDR, the UPIC shall collaborate with CMS to determine innovative approaches so that the most complete and accurate data possible becomes available to perform data analysis work in pursuit of strong program integrity.(For more information on implementation activities, please Section 45, Implementation Requirements)
5.2.2 Data Analysis Expectations & Responsibilities
a) The UPIC shall perform a range of fraud, waste, and abuse data analysis and matching activities on Medicare-only claims, Medicaid-only claims, and Medicare-Medicaid (Medi-Medi) claims as well as any other claim information or datasets identified in specific Task Orders to perform activities that shall include,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .