J.1 Statement of Work (SOW) RAC 3-5.docx
DOCX document 190 KB Posted
- Attached to
- Recovery Audit Contractor (RAC) Regions 3, 4, & 5 Federal contract opportunity
- Solicitation number
- 75FCMC25RJ003
About this file
This document is a Statement of Work (SOW) for the Part A/B Medicare Fee-for-Service (FFS) Recovery Audit Contractor (RAC) and the National DME/HH+H RAC for Regions 3, 4, and 5. The SOW outlines all tasks and responsibilities associated with the review of Medicare FFS claims, including identifying and correcting improper payments, recouping overpayments, paying underpayments, supporting the appeals process, and reporting on all reviews by updating the RAC Data Warehouse (RACDW). Key requirements include complying with CMS policies and procedures, establishing Joint Operating Agreements with Medicare contractors, performing automated and complex claim reviews, submitting and obtaining approval for review topics, maintaining a provider portal, communicating review results to providers, and managing the claim adjustment process. The RAC must also meet specific personnel requirements for key roles such as Project Manager, Contractor Medical Director, Medical Review Manager, and IT security personnel. The SOW is associated with a federal contract opportunity for the Recovery Audit Contractor Regions 3, 4, and 5.
View the file
Other files for this federal contract opportunity
Show all 23
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
State of Work (SOW) for the Part A/B Medicare Fee-for-Service (FFS) Recovery Audit Contractor (RAC) and the National DME/HH+H RAC– Regions 3, 4, and 5
| I. Purpose | 2 |
| II. Background | 2 |
| III. Requirements | 3 |
| A. General Requirements | 3 |
| B. Statement on Standards for Attestation Engagements | 3 |
| C. System Requirements and Data Accessibility | 3 |
| D. Receiving and Transmitting Medical Records/Documentation | 6 |
| E. System Security Requirements | 6 |
| IV. Personnel Requirements | 7 |
| A. Key Personnel | 7 |
| B. Medical Review Personnel | 12 |
| C. Other Personnel | 14 |
| V. Statement of Work Tasks | 15 |
| Task 1: Initial Meeting with CMS | 15 |
| Task 2: Project Plan | 15 |
| Task 3: Identification of Improper Payments on Postpayment Review | 16 |
| Task 5: Claim Review Process | 22 |
| Task 6: Review Topic Submission and Approval | 26 |
| Task 7: Website and Provider Portal | 28 |
| Task 8: Communication and Collaboration with Other Medicare Contractors | 30 |
| Task 9: Activities Following Review | 33 |
| Task 10: Utilizations of the RACDW | 38 |
| Task 11: Quality Assurance and Accuracy Monitoring | 44 |
| Task 12: Supporting Medicare Third Level of Appeal, in the Office of Medicare Hearings and Appeals (OMHA) and/or in the Debt Collection Improvement Act Process | 46 |
| Task 13: Customer Service and Provider Outreach | 48 |
| Task 14: Conference Calls, Meetings and Travel | 50 |
| Task 15: Monthly Progress Reports | 52 |
| Task 16: Administrative Period (Contract Closeout and Reconciliation) | 54 |
| APPENDIX A: SCHEDULE OF DELIVERABLES | 57 |
| APPENDIX B: Section 508 Requirements | 61 |
| APPENDIX C: CMS Security and Privacy Language for Information and Information Technology | 63 |
I. Purpose The Recovery Audit Program’s mission is to reduce Medicare improper payments through the efficient detection and correction of improper payments. This statement of work (SOW) includes all tasks and responsibilities associated with the review of Medicare Fee-for-Service (FFS) claims submitted to, and paid by, the Medicare Administrative Contractors (MACs) in the Recovery Audit Contractor (RAC) Region for which this contractor is awarded. The RAC shall review all claim types using CMS-approved review topics. The RAC shall work with the Centers for Medicare & Medicaid Services (CMS), MACs, and any other CMS contractors to effectuate the adjustment of claims, recoup overpayments, pay underpayments, support the appeals process, report the status of all reviews by updating the RAC Data Warehouse (RACDW), and provide monthly reports. All RAC tasks shall be completed in a timely, accurate, and efficient manner, as defined by the CMS RAC COR.
II. Background Section 1893(h) of the Social Security Act (“the Act”) authorized a nationwide expansion of the Recovery Audit Program, and required the Secretary of the Department of Health and Human Services to utilize RACs under the Medicare Integrity Program to identify underpayments and overpayments and recoup overpayments associated with services and items for which payment is made under Part A or B of Title XVIII of the Act. To gain additional knowledge, RACs shall research the following documents:
· The CMS IOM Pub. 100-08, Medicare Program Integrity Manual (PIM)
· The Debt Collection Improvement Act of 1996
· SEC. 31001 - (3)(A)(ii)(c)(6) and (7)(A)(B)
· The Federal Claims Collection Act, as amended and related regulations found in 42 CFR
· Title 42 CFR Subpart D – Medicare Integrity Program Contractors
· Title 42 CFR Subpart E – Medicare Administrative Contractors
· National Coverage Determinations (NCDs) and Local Coverage Determinations (LCDs)
· Comprehensive Error Rate Testing Reports (CERT)
· Recovery Audit Program Status Documents and Reports to Congress available at CMS.gov Medicare Fee-for-Service Compliance Programs
· Sections 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220)
· Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), Title 2 -- Preventing Health Care Fraud and Abuse; Administrative Simplification; Medical Liability Reform:
· Subtitle C – Data Collection
· Subtitle F – Administrative Simplification
Throughout this document, the term “improper payment” is used to refer collectively to overpayments and underpayments. Situations where the provider submits a claim containing an error (such as an incorrect code, or incorrect/missing modifier), but the payment amount is not altered by the error, are not considered improper payments for the Medicare FFS Recovery Audit Program.
III. Requirements A. General Requirements The primary point of contact (POC) for the RAC for all operational tasks in this SOW or any aspect thereof shall be the CMS RAC COR or their delegate. The CMS Contracting Officer (CO) shall be the primary POC for all contract issues/questions. The RAC shall collaborate with other subject matter experts (SMEs), with CMS RAC COR approval.
Independently and not as an agent of the Government, the RAC shall furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform all requirements of this SOW.
All documentation created by the RAC and submitted to CMS is subject to the Revised Section 508 of the Rehabilitation Act, as applicable. At the discretion of the CMS RAC COR, 508 compliance may be waived for working documents including draft versions of documents and versions of documents not yet accepted by the CMS RAC COR. For more information, see Appendix B- 508 Standards per the Revised Section 508 of the Rehabilitation Act.
B. Statement on Standards for Attestation Engagements Each RAC shall be required to complete an annual Statement on Standards for Attestation Engagements Number 18 (SSAE 18 Type II Audit). Each RAC shall be responsible for contracting with an independent and certified public accounting (CPA) firm to perform the audit in accordance with current CMS standards. The CPA firm will ideally have experience in Medicare operations and must have experience performing SSAE 18 Type II audits.
The CMS control objectives can be found in IOM Pub. 100-06, Chapter 7, along with additional general information concerning an SSAE 18 Type II audit. The CMS will dictate which control objectives will be applicable to the audit. The scope of the audits will be dictated by CMS and will be determined no later than 180 days after contract award. The final annual report from the CPA firm must be submitted to CMS by the award anniversary date. Any corrective action plan must be submitted to CMS within 45 calendar days of the issuance of the final report.
C. System Requirements and Data Accessibility The CMS may make system changes that could result in additional (not previously present) administrative tasks being placed on the RAC. These administrative tasks shall be within the scope of this contract and shall be applicable to the identification and recovery of improper payments. The CMS will provide minimal administrative support for system changes and cannot guarantee implementation timeframes.
The RAC shall be responsible for obtaining the appropriate hardware, software, and telecommunications equipment to undertake and fully complete all the tasks within this SOW. It is the responsibility of the RAC to have available the personnel needed to design, build, and maintain a system, in the appropriate environment, meeting CMS standards, without assistance from CMS. Resources available to the RAC include the CMS Risk Management Handbook (RMH) and the CMS Acceptable Risk Safeguards (ARS) publication. The RAC shall comply with the CMS Security Assessment and Authorization (SA&A) methodology, policies, standards, procedures, and guidelines for contractor facilities and systems. When using or disclosing protected health Information (PHI), the RAC shall comply with the Health Insurance Portability and Accountability Act (HIPAA).
The RAC shall comply with CMS policies and other requirements below, as well as documents referenced within those policies:
1. The CMS Policy for Information Security (PIS), (as amended) – The high-level CMS policy for the CMS Information Security Program.
2. The CMS Policy for the Information Security Program (PISP), (as amended) - Sets the ground rules under which CMS shall operate and safeguard its information and information systems to reduce the risk and minimize the effect of security incidents. This document will subsequently reference the contractor-applicable ARS manual and the RMH, Volumes I, II, and/or III Security Standards and Procedures.
3. The CMS Policy for Investment Management and Governance (as amended) – Establishes the policy for systematic review, selection/reselection, implementation/control, and continual evaluation of IT investments at CMS.
4. Cloud Services - All cloud-specific requirements will be as defined in CMS Information Security, Section 1.3, Cloud-based Services. However, for information identified as Personally Identifiable Information (PII), Protected Health Information (PHI), and/or Federal Tax Information (FTI), the additional security and privacy requirements listed in the ARS manual Implementation Standards (as amended), as applicable to PII, PHI, and/or FTI, shall be applied within cloud-based services.
5. The CMS Information Security website provides a list of applicable security policies and procedures across the program.
A summary of these requirements is listed in the Applicable Laws and Regulations sections of the above listed CMS policies, as well as in the Applicable Laws and Regulations section of the Health and Human Services (HHS) Office of the Chief Information Officer (OCIO) Policy for Information Systems Security and Privacy.
To access CMS data, the RAC shall acquire a secure line between the RAC and the CMS Data Center. The RAC shall acquire the appropriate software to enter into the CMS Data Center. IBM/Sterling Commerce Connect: Direct software is currently being utilized for this purpose. Any alternative CMS software must be approved by the CMS RAC COR. The RAC shall incur all costs associated with the establishment and maintenance of the secure line, as well as license costs. The RAC shall be responsible for negotiating its own commercial license and costs with the vendor. These costs are not controlled by CMS and may increase at any time.
The RAC shall be required to provide testing to ensure data transfers are secure and successful. After the secure line is established, all testing is completed, and any corrective actions identified as a result of testing have been taken, CMS will provide the RAC with all necessary data files under the terms of this contract for the applicable geographic area. The RAC will receive new data updates monthly. The data file format, data fields available and user agreements are available upon request.
If any problems arise with the transfer of data files, the RAC shall undertake all necessary steps in troubleshooting the cause of the problem. The RAC shall request assistance from CMS only after all steps have been taken to ensure the problem does not originate from the contractor side. If the problem is found to have been caused by CMS, CMS will take steps to re-send the data correctly.
If a newly awarded RAC requires access to National Claims History (NCH) historical claims data files, for the awarded RAC region, the CMS Office of Technology Solutions (OTS) requires the RAC to submit an external hard drive. The external hard drive shall be submitted to the CMS RAC COR. The hard drive shall be capable of storing a minimum of two terabytes of data. A previously used hard drive can be used but must be stripped of any previous data. A RAC that has more than one RAC region is required to provide a separate hard drive for each region.
The CMS will provide approximately three years of historical claims data divided by provider type to each RAC region. The historical claims data files will contain all provider types pertinent and appropriate to the awarded contract. The historical claims data will differ in format from the NCH monthly tap file claims transmissions. The record layouts for the historical claims data files are on the following DESY website www.cms.gov/DESY in folders Version K SAS Copylibs and Version K COBOL Copylibs (The version may be subject to change).
As CMS moves towards utilizing Enterprise Data Centers (EDC), the transmission of data may cease. The CMS will work with the RAC to transition from claims data transmission to claims data extraction. For claims data extraction, the RAC shall be required to utilize a CMS system in a CMS Data Center. An example of the CMS system would be the Integrated Data Repository (IDR).
The RAC shall incur any charges associated with the transfer of data. This includes, but is not limited to, cartridges, data communications equipment, lines, messenger service, mail, etc. The RAC shall pay for all charges associated with the storage and processing of any data necessary to accomplish SOW directives.
D. Receiving and Transmitting Medical Records/Documentation Before requesting documentation, the RAC shall have the ability to receive medical records via esMD. In addition to esMD, the RAC shall accept medical records submitted electronically, (e.g., fax, CD, DVD, or transmitted via electronic submission of medical documentation (esMD)), per the CMS Internet Only Manual (IOM), Program Integrity Manual (PIM), Section 3.2.3.5 - Acceptable Submission Methods for Responses to Additional Document Requests (ADRs).
The RAC shall also accept medical records/documents submitted as (paper) hard copies. Hard copy records shall be scanned into the RAC’s secure internal document management system. When scanning, the RAC shall ensure, as much as possible, that the scanned documents maintain appearance, size, form, shading, and fonts of the original documents. After successfully scanning, hard copy records shall be disposed of using CMS records management procedures, as outlined in IOM 100-01 Chapter 7 - Contract Administrative Requirements 30.30.
When transmitting medical records/documentation, the RAC shall use a secure transmittal process. Secure transmittal means sent in accordance with the CMS business systems security manual (e.g., mailed CD, MDCN line, through a clearinghouse, esMD transmittal).
The RAC may use a provider portal designed to accept medical record documentation with CMS Technical Review Board (TRB) approval, see SOW, Task 7, Section C Provider Portal for details.
E. System Security Requirements The RAC shall establish and maintain backup and recovery of systems in accordance with “CMS Information Security (IS) Application Contingency Plan (CP) Procedures,” and “CMS Contingency Planning Tabletop Testing Procedures.” The RAC shall comply with all CMS privacy and security requirements. The RAC shall provide all personal computers, printers, and equipment to accomplish the work described herein throughout the contract term.
The RAC shall conduct or undergo an independent evaluation and test of its systems security program in accordance with the CMS Business Partners System Security Manual, IOM Pub.100-17. The RAC’s first independent evaluation and test of its systems security program shall be completed prior to the RAC commencing claims review under the contract. Any deficiencies noted as a result of the independent evaluation and test of its systems security program shall be corrected prior to the processing of claims.
The RAC shall conduct, at a minimum, annual vulnerability assessments of its systems, programs, and facility in accordance with the CMS Business Partners System Security Manual, IOM Pub.100-17, Continuous Monitoring:
1. The RAC shall support CMS validation and accreditation of RAC systems and facilities in accordance with CMS’ SA&A methodology, through which an organization establishes and demonstrates a sound information security posture for its system.
2. The RAC shall provide annual certification, in accordance with SA&A procedures, that certifies it has examined the management, operational, and technical controls for its systems supporting the RAC function and considers these controls adequate to meet CMS security standards and requirements.
3. The RAC shall ensure security documents are uploaded and security controls are documented timely in the CMS FISMA Control Tracking System (CFACTS). The RAC shall correct any security deficiency, conditions, weaknesses, findings, or gaps identified by all CMS audits, reviews, evaluations, tests, and assessments within the timeframes requested. The RAC shall begin the process to obtain an Authority to Operate (ATO) within 60 calendar days of contract award.
4. While the RAC is working towards obtaining an ATO, the RAC is expected to perform all aspects of the SOW manually, using methods approved by the CMS RAC COR. The quality of the work delivered shall be entirely accurate, complete, and containing no errors. Granting of an ATO is based on the RAC’s system meeting/exceeding the minimum Federal, Health & Human Services (HHS), and CMS Security and Privacy policy and standards. The CMS security requirements, policies, procedures, standards, and guidelines are located at CMS Information Security and Privacy Virtual Handbook.
The CMS will take all measures necessary to minimize system security risks, including but not limited to stopping the transmission of NCH data to the RAC, ceasing reviews, and terminating the RAC contract, if necessary.
IV. Personnel Requirements The RAC shall ensure that the personnel listed below will comprise an adequate structure to perform the tasks outlined in the SOW.
RAC personnel shall be required to undergo a background investigation as outlined with Section III.F.6 of this SOW.
A. Key Personnel At a minimum, the RAC shall designate a Project Manager (PM), Contractor Medical Director (CMD), Medical Review (MR) Manager, Chief Information Officer (CIO), and Systems Security Officer (SSO) as key personnel.
Key Personnel:
For this SOW, “fully dedicated” means that the individual identified for any key personnel position shall be a full time equivalent (FTE) employee. The PM, MR Manager, and CMD may serve as a designated back up, or in an ancillary capacity, on another RAC contract with CMS COR approval; they may not fulfill the role of a primary key personnel on another contract. The primary CIO and SSO may serve in the primary key personnel role, or backup key personnel role, on more than one RAC contract, with CMS COR approval. Key personnel may not perform duties on any Medicare/non-Medicare contract or commercial line of business, other than a RAC contract, without approval by the CO and CMS RAC COR.
Prior to key personnel changes, the RAC shall send a prospective candidate’s resume to CMS reflecting that the candidate meets the requirements of this SOW, along with a proposed transition plan. The key personnel shall be approved by CMS before the transition occurs. All changes to the RAC’s organizational chart shall be submitted to the CMS RAC COR within seven business days of the actual change being made.
Backup Key Personnel:
The RAC shall submit a CMS approved contingency plan and designate fully qualified (meets the experience and education requirements for the respective key personnel position) backups for each key personnel role (including a CMS User ID and access to the RACDW). The designated backup personnel shall ensure, to the greatest extent possible, continuity of operations and minimal interruptions in the event of a permanent or temporary departure of key personnel. All backup positions, while serving in the capacity as primary key personnel, must work full-time and are subject to the same rules as Key Personnel provided for above.
1. Project Manager The PM shall be fully dedicated to this contract and shall act as a central point of contact (POC) with CMS and other stakeholders. The PM shall be available to the CMS RAC COR during normal business hours (9:00 am – 6:00 pm ET). If the PM is not going to be in the office due to vacation, etc., the CMS RAC COR shall be notified, and the PM shall designate a CMS-approved backup person to serve as the central POC with CMS. Anyone serving as a backup for the PM shall be required to answer questions and/or provide data to the same degree that the PM would be able to provide to CMS.
Primary duties shall include but are not limited to:
· Coordinate internal resources for the execution of projects.
· Ensure all projects are delivered on-time and within the scope of the project.
· Manage changes to the project scope, project schedule, and project deliverables.
· Perform risk management analysis and implement risk mitigation.
· Create and maintain comprehensive project documentation.
· Maintain data integrity and notify CMS of failure to meet SOW requirements immediately upon becoming aware.
· Ensure staff possess the appropriate credentials to fulfill the SOW requirements.
· Communicate and disseminate critical project information to CMS and other stakeholders.
· Coordinate provider outreach opportunities (see Task 15).
· Attend conferences and training as required by CMS.
Project Manager Education The PM shall possess a bachelor’s degree in Accounting, Business, Marketing, Public Administration, or other Healthcare relevant field.
Project Manager Work Experience The PM shall have at a minimum 5 years of professional work experience in the healthcare industry supporting either Federal Government agencies or Commercial Healthcare market as a PM, project leader, operations manager, technical project manager, or product manager. The PM shall have extensive knowledge of the Medicare program particularly the coverage and payment rules and , preferably with knowledge of CMS FFS Recovery Audit Program.
2. Contractor Medical Director (CMD) The CMD shall be fully dedicated to this contract. The RAC shall arrange for a CMS-approved alternate CMD when the primary CMD will be unavailable for an extended period, for example 30 calendar days or more. The CMD must be either a Doctor of Medicine or a Doctor of Osteopathy who has Medicare FFS claim experience to oversee medical review. More than one individual’s time cannot be combined to meet the one FTE minimum. The CMD must be approved by CMS.
Primary duties include:
· Briefing and directing personnel on the correct application of policy during claim adjudication, including through written internal claim review guidelines.
· Keeping abreast of medical practice and technology changes that may result in improper billing or program abuse.
· Serving as a readily available source of medical information to provide guidance in questionable claim review situations.
· Recommending when LCDs, NCDs, provider education, system edits, or other corrective actions are needed or must be revised to address RAC identified vulnerabilities.
· Overseeing the medical review process and providing the clinical expertise and judgment to understand LCDs, NCDs and other Medicare policy.
· Participating in the appeals process.
· Participating in operational meetings with CMS and CMS stakeholders.
Other duties include:
· Discussing claim review determinations with providers upon request.
· Interacting with the CMDs of other contractors and/or RACs to share information on potential problem areas.
· Participating in CMD clinical workgroups, as appropriate.
· Upon request, providing input to CMS on national coverage and payment policy.
· Participating in CMS/RAC presentations (pre-approved by the CMS RAC COR) to providers and associations.
Please Note: These tasks mentioned are not administrative therefore, non-medical personnel shall not be substituted for the CMD to oversee or perform any of the tasks that involve medical review.
To prevent conflict of interest, the CMD must provide written notification to CMS within three months after the appointment, election, or membership effective date if the CMD becomes a committee member or is appointed or elected as an officer in any state or national medical societies or other professional organizations. The RAC shall ensure that the CMD does not supervise claims from a provider who was their employer within the previous 12 months.
CMD Work Experience
· Experience practicing medicine as a licensed and board-certified Doctor of Medicine or Osteopathy. When recruiting CMDs, the RAC should give preference to physicians who have patient care experience and are actively involved in the practice of medicine.
· A minimum of three years’ experience practicing medicine as a board-certified physician with no previous sanctioning or exclusion from the Medicare program.
· A minimum of two years’ prior work experience in the health insurance industry, utilization review firm or another health care claims processing organization.
· Extensive knowledge of the Medicare program particularly the coverage and payment rules.
· Public relations experience such as working with physician groups, beneficiary organizations or Congressional offices.
· The RAC shall annually verify that the CMD’s license and board certifications are current.
3. Medical Review (MR) Manager Each RAC is required to employ a Medical Review (MR) Manager. The MR Manager is responsible for the overall medical review and quality assurance of the RAC review staff and associated processes. The MR Manager shall have broad knowledge of the Medicare program and working knowledge of the CMS FFS Recovery Audit Program requirements and activities. The MR Manager shall be responsible for keeping abreast of regulatory, policy, and coding changes as well as clinical practice and technology changes that may result in improper payments.
Primary duties may include but are not limited to:
· Overseeing the medical review process and providing the clinical expertise and judgment to apply indications for coverage as outlined in Federal regulations and policy.
· Educating and directing personnel on the correct application of CMS-issued review guidelines and edit parameters during the review process.
· Serving as a liaison to the CMD related to claim reviews.
· Overseeing the Inter-Rater Reliability (IRR) process.
· Assuring the timely and accurate completion of the review topic QA processes.
· The RAC shall annually verify that the MR Manager’s license is current.
MR Work Experience:
This candidate shall have at least five years of previous medical review experience, with at least three years of management experience.
MR Education and Licensure:
The MR Manager shall have a current Registered Nurse (RN) license in the United States or U.S. Territory. An associate degree in nursing is acceptable.
4. Chief Information Officer (CIO) The RAC shall appoint a CIO to oversee its compliance with the CMS information security requirements. The CIO may be fully dedicated but it is not a requirement of this contract.
CIO Work Experience The CIO shall have 5 years combined work experience with at least 3 of those years being in the healthcare industry supporting either Federal Government agencies or commercial healthcare market as the CIO, information technology manager, chief technology officer, information technology manager, or network administrator. The CIO shall have knowledge of the Medicare program, with knowledge of CMS FFS Recovery Audit Program requirements and activities being preferable.
CIO Education The CIO shall possess an associate degree in information systems, computer science or other related technology field. Relevant work experience in related field of work will be considered in lieu of an associate degree.
Primary duties shall include but are not limited to:
· Learning, documenting, and implementing Federal/CMS security controls.
· Disseminating and implementing IT policy that aligns with CMS requirements.
· Providing interpretation of current policies in response to inquiries or specific incidents.
5. Systems Security Officer (SSO) The RAC shall designate a SSO to manage the Medicare information security program and ensure the implementation of necessary safeguards. The SSO shall be dedicated to assisting the CIO in fulfilling compliance with the CMS information security requirements. The SSO shall be independent of IT operations. The SSO can be within the CIO organizational domain but cannot have responsibility for operation, maintenance, or development.
SSO Work Experience The SSO shall have 5 years combined work experience with at least 3 of those years being in the healthcare industry supporting either Federal Government agencies or Commercial Healthcare market as the SSO, Information technology specialist, Security engineer, Information security analyst, or Information systems technician. The SSO shall have knowledge of the Medicare program, with knowledge of CMS FFS Recovery Audit Program requirements and activities being preferable.
SSO Education The SSO shall possess an associate degree in information systems, Computer Science, or other related technology field. Relevant work experience in related field of work will be considered in lieu of associate degree.
The SSO should earn a minimum of 40 hours in continuing professional education credits each year from a recognized national information systems security organization. The educational sessions conducted at the CMS Security Controls Oversight and Update Training (CSCOUT) can be used toward fulfilling the continuing professional education credits.
Primary duties shall include but are not limited to:
· Complying with CMS system security policies, procedures, and practices.
· Responding to security breaches.
· Providing CMS security system updates.
· Designating appropriate levels of security clearance to employees.
· Reporting any identified security vulnerabilities and risks.
· Perform duties in accordance with IOM Pub. 100-17, the CMS Business Partner System Security Manual (BPSSM).
B. Medical Review Personnel RAC medical reviewers are required to follow CMS coverage instructions, as well as pertinent coding and billing materials. Coverage criteria may be outlined in statute and/or regulation, and may be further defined in National Coverage Determinations (NCDs), Local Coverage Determinations (LCDs) and CMS' Manuals
When performing complex reviews, the RAC shall ensure that coverage and medical necessity determinations are only made by licensed RNs or licensed therapists, who have previous medical review experience. The reviewers shall understand Medicare policies (including LCDs and NCDs). Reviews that have been conducted by unqualified or uncredentialed personnel may result in a reversal of findings and/or a corrective action plan.
The RAC shall code the revised principal, secondary diagnosis, or procedures affecting or potentially affecting the MS-DRG assignment to the highest level of specificity per coding guidelines whether it impacts the MS-DRG or not. Clinical validation[footnoteRef:2] is prohibited in all RAC reviews. [2: Clinical validation is a process that involves a clinical review of the medical record to ascertain whether or not the patient truly possesses the conditions that were documented.
RACs shall ensure that a licensed medical professional will perform medical record reviews for the purpose of determining medical necessity, using their clinical review judgment to evaluate medical record documentation.
The RAC shall maintain and provide documentation upon the provider’s request listing the credentials of the individuals making the medical review determinations. This only includes a reviewer’s credentials. The RAC is not required to share names and personal information.
1. Certified Coders Each RAC is required to employ certified coders to perform complex coding validations. Certified coders are those professionals who earn their certification from an accredited association such as the American Association of Professional Coders (AAPC) or American Health Information Management Association (AHIMA). Certified Coders are obligated to stay current in their profession. This includes continuing education in their respective discipline and keeping abreast of current medical coding updates, compliance rules, and government regulations. Reviews performed by unqualified or uncredentialed personnel[footnoteRef:3] are not payable under this contract. [3: Unqualified or uncredentialed personnel are those persons without active certifications or licensures as required in this SOW.
Certified coders may also be Registered Health Information Administrators (RHIA) and Registered Health Information Technicians (RHIT) who have been credentialed by AHIMA in their field of health information. These coders must have at least five years direct coding or billing experience in the specific coding field. The CMS reserves the right to review the credentials of certified coders, RHIA and RHIT at any time under this SOW.
2. Registered Nurses Each RAC is required to employ registered nurses with previous experience in medical record review. Registered nurses are required to have current licenses in nursing in the United States or US Territory. The RAC must ensure that the license is current. The CMS reserves the right to review the credentials of registered nurses at any time under this SOW.
3. Therapists Each RAC is required to employ licensed therapists (e.g., physical therapist, occupational therapist, and speech-language pathologist) with previous experience in medical record review.
Therapists are required to have current therapy licenses in the United States or US Territory. The RAC must ensure that the license is current. The CMS reserves the right to review the credentials of therapists at any time under this SOW.
4. Other Clinicians In addition to the required clinicians listed above, the RAC may employ other licensed clinicians to perform medical review. However, only clinicians with current licenses in the United States or US Territories with previous experience in medical record review in their respective disciplines may review medical records for medical necessity. The clinician must understand Medicare policies as well as LCDs and NCDs. The CMS reserves the right to review the credentials of these licensed clinicians at any time under this SOW.
Regardless of license type, all clinicians (including registered nurses, licensed therapists, etc.) must possess three years of previous medical record review experience and at least three years of current and/or relevant clinical experience in a variety of health care settings. Examples include but are not limited to acute care, sub-acute care, long term care, rehabilitative services, home health, skilled nursing, diagnostic services, and outpatient services/settings.
In addition to the CMD, the RAC is encouraged to utilize the expertise of a panel of board-certified clinical specialists, for consultation when performing medical review.
Those personnel that are licensed must have licenses issued by the United States or a US Territory regulatory agency.
C. Other Personnel
The Contractor shall ensure adequate staffing levels (i.e. adequate full-time equivalents (FTEs)) and structure, to successfully perform all tasks in the agreed upon timeframes established in this SOW.
V. Statement of Work Tasks Task 1: Initial Meeting with CMS The RAC’s project staff (including key personnel) shall meet with the CMS RAC COR and appropriate CMS staff within two weeks of the date of award. The initial (Kick Off) meeting shall be in person for key personnel with a virtual/remote option to be approved by CMS RAC COR. During the meeting, the terms and conditions of the specified Regional RAC contract will be discussed. Topics will include, but not be limited to, CMS staff and RAC staff roles and responsibilities outlined in the statement of work, invoice procedures, security requirements, project plan, and any questions or concerns from the RAC for the work being performed under this contract.
The RAC shall submit a list, containing the names and roles, of each RAC staff member who will be in attendance. This list shall be submitted to the CMS RAC COR via email, no less than one week prior to the meeting, unless otherwise directed by the CMS RAC COR.
Task 2: Project Plan The Project Plan outlines the resources and timeframe(s) for completing all work activities associated with this SOW.
A. Draft Project Plan Within two weeks after the initial meeting with CMS, the RAC shall submit a draft project plan. The draft project plan will be for the first year of the contract. The draft project plan and all subsequent project plans must be approved by the CMS RAC COR, prior to implementation.
The draft project plan shall include the following:
· Detailed RAC Organizational Chart, identifying the names and titles of all key personnel, first-line management, and all other personnel named within this SOW.
· A list of all clinical certified coders, registered nurses and therapists performing reviews including relevant credentials.
· Contingency plan for dealing with unexpected changes in any key personnel. Contingency plans must be approved by the CMS RAC COR, before implementation.
· Provider Outreach Plan, detailing all potential and planned outreach efforts to associations, individual providers, provider groups, Medicare contractors, and other applicable Medicare stakeholders.
· Customer service plan.
· Appeals Participation Plan, including ALJ hearings.
· Schedule of Deliverables.
· Key Project Milestones:
· ATO implementation and maintenance;
· CFACTS;
· Complying with all CMS System Security and Privacy Requirements;
· Annual Trainings;
· Joint Operating Agreements (JOAs) execution:
· Proposed quarterly projection by:
· Review topics;
· Type of review (automated, complex, extrapolation);
· Type of improper payment (medical necessity, incorrect coding, etc.).
B. Subsequent Project Plans The Project Plan is a living document that, at a minimum, must be included with the monthly progress report (see Task 15). The subsequent project plans shall include the following:
· Detailed RAC Organizational Chart, identifying the names and titles of all personnel named within this SOW.
· Contingency plan for dealing with unexpected changes in any key personnel. Contingency plans must be approved by the CMS RAC COR, before implementation.
· Joint Operating Agreements (JOAs) review and signature due dates.
· Proposed quarterly projections by:
· review topics;
· type of review (automated, complex, extrapolation);
· type of improper payment (medical necessity, incorrect coding, etc.).
· Customer service plan.
· Updated ongoing Provider outreach plans.
· Approved new and closed review topics.
Task 3: Identification of Improper Payments on Postpayment Review The RAC shall perform postpayment review on all Medicare claim types and provider types to identify improper payments, which were made under Part A or Part B. This includes reviews of claims/providers that have a high propensity for error, based on the Comprehensive Error Rate Testing (CERT) program and other CMS analysis.
The RAC shall comply with Reopening Regulations located at 42 CFR 405.980. Before a RAC makes a decision to reopen a claim, the RAC must have ‘good cause’ as defined in 42 CFR 405.986 and shall clearly document the good cause in review proposals and all correspondence related to the review. The RAC shall develop processes to minimize provider burden when identifying Medicare improper payments. The RAC shall ensure edit parameters and claim selection criteria are refined to select only those claims with the greatest probability of being improper and that the number of additional documentation requests do not negatively impact the provider’s ability to provide care. The RAC shall perform this analysis prior to requesting records. The CMS has the authority to develop/revise ADR limits at any time. ADR limits will be provided via technical direction, or as otherwise instructed by CMS. ADR limits shall be applied on an annual basis per calendar year, unless otherwise specified by CMS.
All medical record request letters must adequately describe the good cause for reopening the claim. Good cause for reopening the claim may include but is not limited to OIG report findings, data analysis findings, comparative billing analysis, etc.
The CMS will perform routine evaluations to ensure the RAC is reviewing all claim types as directed. The CMS may impose minimum percentage review requirements by claim type and/or adjust conditional approval limits accordingly. Requirements may be based on improper payment findings in the CERT program or other CMS data analysis.
A. Improper payments included in this SOW Unless prohibited by Section B below, the RAC may review claims and identify improper payments (overpayments or underpayments) that result from any of the following:
· Incorrect payment amounts.
· Exception: in cases where CMS issues instructions directing contractors not to pursue certain incorrect payments made.
· Non-covered services (including services that are not reasonable and necessary under section 1862(a)(1)(A) of the Social Security Act).
· Incorrectly coded services (including DRG miscoding).
· Duplicate services.
· Claims from the following provider types:
· Inpatient hospital;
· Inpatient psychiatric facility;
· Outpatient hospital;
· Professional services;
· Laboratory;
· Ambulance;
· Skilled Nursing Facility;
· Inpatient Rehabilitation Facility;
· Critical Access Hospitals;
· Long Term Care Hospitals;
· Ambulatory Surgical Center;
· Other (such as Comprehensive Outpatient Rehabilitation Facilities, Rural Health Clinics, and Independent Diagnostic Testing Facilities.
For purposes of the Recovery Audit program, a Medicare underpayment is defined as a single code, although there may be multiple lines, or payment group (e.g. Ambulatory Payment Classification (APC) on a claim that was billed at a higher level of payment but should have been billed at a lower level of payment. The RAC shall review a single code or payment group on a claim, unless otherwise directed by CMS. The RAC may only consider multiple lines of the same code on a claim.
A review may consist of a target claim and a reference claim. A target claim represents the improper payment and is the claim that will be sent to the MAC for adjustment. Regions 3 and 4 target claims exclude HH/H and DMEPOS. Region 5 target claims include only HH/H and DMEPOS. The reference claim may be any claim paid under Part A or Part B of Title XVIII of the Social Security Act. These reference claims may address any claim for any region.
The RAC shall review all provider types listed above.
Any proposed uses of advanced technology, such as artificial intelligence (AI) applied under this SOW shall be reviewed, vetted, and subject to approval by the CMS RAC COR.
B. Improper payments excluded in this SOW The RAC shall not attempt to identify improper payments (overpayments and underpayments) arising from any of the following:
· Services provided under a program other than Medicare Fee-For-Service – For example, the RAC shall not attempt to identify improper payments in the Medicare Managed Care program or Drug Benefit program.
· Cost report settlement process and Medical Education payments – The RAC shall not attempt to identify improper payments that result from Indirect Medical Education (IME) and Graduate Medical Education (GME) payments. The RAC shall not review cost report settlements for improper payment identification.
· Claims more than three years past the initial claim paid date – The RAC shall not review claims or identify any improper payment more than three years past the initial claim paid date. The look back period is conducted starting from the date of the initial claim paid date and ending with the date the RAC issues the ADR letter (for complex reviews) or the date of the review results letter (for automated reviews). The RAC shall take no further action on these claims except to indicate the appropriate status code in the RACDW and notify CMS RAC COR.
· Random selection of claims– The RAC shall adhere to Section 935 of the Medicare Prescription Drug, Improvement and Modernization Act of 2003, which prohibits the use of random claim selection for any purpose other than to establish an error rate. Therefore, the RAC shall not use random review in order to identify cases for which it will request medical records from the provider. The RAC shall perform targeted reviews that utilize data analysis techniques in order to identify those claims that most likely contain improper payments. The RAC may not target a claim solely because it is a high dollar claim but may target a claim because it is high dollar AND other data analysis suggest that the claim is likely to contain an improper payment.
· Claims identified with a Special Processing Number – Claims containing Special Processing Numbers are involved in a Medicare demonstration or have other special processing rules that apply. These claims are not subject to review by the RAC. The CMS attempts to remove these claims from the data prior to transmission to the RAC.
· The RAC shall exclude from review claims with a Unique Tracking Number (UTN) to avoid capturing claims subject to prior authorization. For example, providers/suppliers submitting claims subject to prior authorization must include a valid UTN. The UTN is available on the face of the claim and is therefore visible to the RAC in its respective National Claims History (NCH) data.
· National Correct Coding Initiative (NCCI) edits - RACs shall not propose nor conduct any reviews based on (NCCI) edits. In addition, RACs shall not submit any Review Topic proposals that are based on NCCI edits.
The CMS reserves the right to limit the number or time period available for reviews by RAC, state, claim type, provider type, natural disaster, public health emergency (PHE) or any other reason where CMS believes it is in the best interest of the Medicare program to limit claim review. The RAC will be provided written notice containing the effective date of the restrictions outlined.
C. Underpayments The RAC shall review claims using automated or complex review to identify potential Medicare underpayments. Upon identification, the RAC shall communicate the underpayment finding to the appropriate MAC. The RAC shall not ask the provider to correct and resubmit the claim. The RAC shall obtain approval of the underpayment notification letter template from the CMS RAC COR before issuing the first letter.
For purposes of the Recovery Audit program, a Medicare underpayment is defined as a single code on a claim that was billed at a lower level of payment but should have been billed at a higher level of payment. The RAC shall review each claim line or payment group and consider all possible occurrences of an underpayment in that one code or payment group. If the medical documentation supports changes to the diagnosis, procedure, or order in that line or payment group that would create an underpayment, the RAC shall identify an underpayment. Service lines or payment groups that a provider failed to include on a claim are NOT considered underpayments for the purposes of the program.
1. Examples of an Underpayment:
· The provider submitted a claim for 15 minutes of therapy when the medical record clearly indicates 30 minutes of therapy were provided. Certain HCPCS/CPT codes are measured in 15-minute increments and are called “timed” codes. These services require direct (one-on-one) patient contact. When reporting a 15-minute service, the provider should enter (1) in the field labeled units on the claim form. The provider in this scenario is entitled to (2) units.
· The provider submitted a claim for a particular service and the amount the provider was paid was lower than the amount on the CMS physician fee schedule.
2. The following will NOT be considered an Underpayment:
· The medical record indicates that the provider performed additional services such as an EKG, but the provider did not submit a claim for the service. (This provider type is paid based on a fee schedule that has a separate code and payment amount for EKG).
· The provider submitted a claim for 15 minutes of therapy when the medical record clearly indicates 30 minutes of therapy were provided; however, the additional minutes do not affect the grouper or the pricer. (This provider type is paid based on a prospective payment system that does not pay more for this much additional therapy.)
· The medical record indicates that the provider implanted a particular device for which a device APC exists (and is separately payable over and above the service APC), but the provider did not submit a claim for the device APC.
Task 4: Obtaining, Storing, Sharing, and Paying for Medical Records A. Obtaining medical records The RAC shall not perform onsite visits to review medical records. Medical records shall be obtained through the ADR (Additional Documentation Request) process. The RAC shall accept medical records submitted electronically, (e.g., fax, CD, DVD, or transmitted via electronic submission of medical documentation (esMD), RAC Provider Portal, and submitted as (paper) hard copies). The RAC must have the capability to receive medical records via esMD, prior to sending ADR letters. Although providers are not mandated to electronically store or transmit medical records, the RAC shall possess the technology to accept documents via electronic transmission. The documentation received following the issuance of an ADR or received during a discussion period, shall be stored maintaining as much as possible the document’s original appearance including the size, form, color and fonts. The RAC shall comply with all CMS business system security requirements when entering into arrangements regarding the transmission and storage of medical records and other documentation.
Should the RAC receive medical records and/or correspondence in a language other than English, the RAC shall possess the necessary software required to translate the documentation or be required to close the review.
Provider Inquiries (Not Requested by RAC) The RAC does not have responsibility to randomly accept case files from providers for…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .