Audit-Proof Your Agency: Build a 2026 Compliance Checklist
Audit-Proof Your Agency: Build a 2026 Compliance Checklist

An audit should be a controlled review: not a fire drill.
For home care and behavioral health agencies, 2026 brings focused scrutiny around billing patterns, prior authorization decisions, documentation, cybersecurity, and corrective action. State surveyors, CMS contractors, and the OIG increasingly rely on data to identify agencies that look different from their peers.
That makes agency audit preparation more than a last-minute file search. It is an operating discipline that protects reimbursement, reduces disruption, and gives your organization room to grow.
Use this checklist to build a practical 2026 audit-readiness program.
Important: Requirements vary by state, payer, provider type, and contract. Use this checklist as an operational guide, not legal advice.
1. Organize Your Documentation. Prove Your Services. Close Your Gaps.
Auditors do not evaluate what your agency intended to do. They evaluate what your records demonstrate.
Create a centralized, secure audit file: physical, electronic, or both: with consistent naming conventions and access controls. Your team should be able to locate a complete record without searching across personal inboxes, desktops, and disconnected systems.
Documentation readiness checklist
- Current policies and procedures are approved, dated, and version-controlled.
- Policies reflect your actual workflows: not an outdated model from your startup period.
- Governing body, quality improvement, and compliance meeting minutes are complete.
- Employee training records include dates, topics, attendees, and follow-up actions.
- Client or patient records include assessments, plans of care, progress notes, orders, and required signatures.
- Records clearly connect the service delivered to the service authorized.
- Corrections to records follow proper late-entry and amendment procedures.
- Incident reports, complaints, grievances, and investigations are tracked through resolution.
- Internal audit findings include an owner, deadline, corrective action, and validation step.
- Retention schedules are documented and consistently followed.
For behavioral health agencies, pay close attention to medical necessity, treatment-plan updates, service authorization, clinical supervision, and timely documentation.
For home care agencies, confirm that the record supports eligibility, orders, care planning, visit delivery, aide supervision, and changes in condition.

2. Test Your Billing. Validate Your Coding. Protect Your Revenue.
Billing risk often begins with a small inconsistency: a missing order, an unsupported code, a mismatched date, or documentation that does not support the level of reimbursement submitted.
In 2026, home health agencies should give special attention to institutional admission source coding.
The OIG’s 2026 Work Plan review is examining Medicare home health claims billed with occurrence codes 61 or 62. These codes indicate that an institutional stay occurred within 14 days of the home health admission. Institutional admissions can receive higher reimbursement than community admissions.
The risk is straightforward: an emergency room visit or observation stay may not qualify as an inpatient stay. If the claim does not have the right supporting documentation, the higher payment may not be defensible.
Billing and coding checklist
- Pull a report of all claims using occurrence codes 61 and 62.
- Review current and prior-year claims: not only recent submissions.
- Confirm that each claim has a qualifying institutional stay within the required timeframe.
- Match the claim to supporting inpatient documentation and the appropriate Medicare claim.
- Verify that an emergency room or observation visit was not incorrectly treated as an inpatient admission.
- Confirm that admission source coding matches the clinical record and billing data.
- Review diagnosis codes, modifiers, units, visit counts, and authorization numbers.
- Compare submitted services with schedules, time records, and progress notes.
- Sample denied, adjusted, and high-dollar claims for recurring patterns.
- Correct identified errors through appropriate rebilling, refunds, or overpayment procedures.
- Document staff retraining and monitor whether the error recurs.
CMS and its contractors also use predictive data analytics, comparative billing data, and outlier tools to prioritize reviews. PEPPER, the Program for Evaluating Payment Patterns Electronic Report, compares provider billing patterns with peer organizations and highlights areas associated with improper payment risk.
PEPPER is not an audit and does not prove fraud. But a persistent deviation from regional or national norms can increase audit attention. Review your most recent PEPPER, identify high-risk target areas, and document the action you took.

3. Review Prior Authorization. Meet Deadlines. Explain Denials.
Behavioral health agencies should treat prior authorization as both a clinical process and a compliance process.
In a June 2026 report, the OIG found that none of 100 sampled behavioral health prior authorization denials fully met applicable requirements. The review identified delayed decisions, notices sent to incorrect addresses, and unclear denial language.
The OIG also highlighted a 21-day decision window. Agencies and managed care organizations need a reliable process for identifying requests that may be considered approved when a decision notice is not sent within the required timeframe.
For impacted payers, the CMS Interoperability and Prior Authorization Final Rule generally requires decisions within seven calendar days for standard requests and 72 hours for expedited requests beginning in 2026. Specific requirements depend on the payer and line of business.
Prior authorization checklist
- Document the date and time every request is received.
- Track standard, expedited, reconsideration, and appeal deadlines separately.
- Configure alerts before each deadline: not after it has passed.
- Verify the member’s address and contact information before sending notices.
- Use denial templates approved for the applicable payer and program.
- State the specific clinical or administrative reason for the denial.
- Identify the criteria used to make the decision.
- Explain appeal rights and how to request relevant records.
- Distinguish a complete denial from a recommendation for an alternate service.
- Review a sample of authorization decisions every quarter.
- Track late decisions, returned mail, unclear notices, and appeal outcomes.
A denial workflow should be easy to audit. If your team cannot show when a request arrived, who reviewed it, what criteria were applied, and when the notice was sent, the process is not yet controlled.
4. Verify Credentialing. Confirm Eligibility. Maintain the File.
Credentialing gaps can undermine an otherwise strong clinical operation. Auditors may ask whether the person who delivered services was qualified, enrolled, screened, supervised, and authorized to work in the role assigned.
Credentialing and personnel file checklist
- Current license, certification, registration, or other required credential.
- Primary-source verification completed and documented.
- National Provider Identifier and payer enrollment information confirmed.
- Exclusion screening completed at hire and on a recurring schedule.
- Background checks and required state screenings documented.
- Job description matches the services actually performed.
- Orientation and annual training requirements are complete.
- Competency evaluations are current.
- Clinical supervision records are signed and dated.
- CPR, first aid, infection control, and safety training are current when required.
- Expiration dates are tracked with advance reminders.
- Contractors and temporary staff follow the same verification process.
Create one credentialing dashboard with a clear owner. A spreadsheet can work if it is controlled, regularly reviewed, and protected. The goal is not a sophisticated platform. The goal is no surprises.
5. Test Your Security. Document Your Controls. Escalate Quickly.
Cybersecurity is now part of agency audit preparation. A compliance file that protects billing but ignores ePHI is incomplete.
A necessary 2026 clarification: HIPAA’s current Breach Notification Rule still generally requires notice without unreasonable delay and no later than 60 days after discovery of a breach. HHS has proposed stronger Security Rule requirements, including documented annual penetration testing and vulnerability scanning at least every six months, but those provisions should not be represented as a final rule unless formally enacted.
Your agency should still prepare to that higher standard.
HIPAA security checklist
- Current security risk analysis is documented.
- Risk treatment plan assigns owners and deadlines.
- Annual penetration testing is completed and documented.
- Vulnerability scans are scheduled at least every six months: or more frequently based on risk.
- Findings are prioritized, remediated, and retested.
- Business associate agreements are current.
- Access is removed promptly when staff leave or change roles.
- Multifactor authentication is used where appropriate.
- Backups are tested and protected from unauthorized access.
- Incident response roles are assigned.
- Suspected ePHI compromises trigger an internal 72-hour escalation target.
- Breach notification requirements are mapped across HIPAA, state law, payer contracts, and insurance policies.
The 72-hour internal target is a practical control. It gives leadership and counsel time to investigate while preserving the ability to meet the legally required notification window.
6. Run a Mock Survey. Interview Your Team. Correct the Record.
A mock survey reveals the difference between having policies and following them.
Assign an internal reviewer or outside compliance partner to evaluate your agency as a surveyor would. Select a sample of records, personnel files, billing claims, incidents, and authorization decisions.

Mock survey checklist
- Review the physical environment and posted emergency procedures.
- Trace a client or patient from intake through discharge.
- Compare the plan of care with actual services billed.
- Pull random and high-risk records.
- Interview staff without giving them scripted answers.
- Ask staff where to find key policies.
- Test after-hours contact and escalation procedures.
- Review complaint and incident investigations.
- Examine credentialing and exclusion-screening files.
- Confirm that quality improvement projects show measurable follow-up.
- Issue a written findings report.
- Re-test corrections after implementation.
Train staff to answer clearly and honestly. “I do not know, but I know where to find the answer” is safer than guessing.
7. Build the Response Protocol. Assign Ownership. Meet the Clock.
When a Statement of Deficiencies arrives, the response clock starts immediately.
For many CMS survey processes, a Plan of Correction is generally due within 10 calendar days of receiving the CMS-2567 Statement of Deficiencies. Confirm the deadline and submission instructions for your specific program and surveying authority.
Response protocol checklist
- Designate one executive point of contact.
- Preserve all records related to the review.
- Log the date the findings were received.
- Notify compliance, operations, clinical leadership, and counsel as appropriate.
- Assign an owner to each deficiency.
- Describe the immediate correction.
- Explain the system change that prevents recurrence.
- Set a realistic completion date.
- Define how compliance will be monitored.
- Attach supporting evidence when appropriate.
- Draft internally by day five to seven.
- Submit the final response before the deadline.
- Continue monitoring after submission.
A strong Plan of Correction does not simply promise improvement. It shows who will act, what will change, how completion will be measured, and how leadership will know the fix lasted.
Turn Audit Readiness Into Growth Readiness
Compliance should not live in a binder that only opens when an auditor arrives. It should support better billing, clearer accountability, stronger staff performance, and more confident expansion.
Are your agency’s records, systems, and response protocols ready for the next review: or are you still relying on a last-minute fire drill?
Book a consultation with EmpoThrive for practical support with compliance, billing, credentialing, accreditation, audit preparation, and sustainable agency growth. From setup to scale, EmpoThrive is your end-to-end partner for building a healthcare organization that is prepared, compliant, and built to last.
Sources
- OIG: Nationwide Medicare Compliance Audit of Home Health Claims Billed With an Institutional Admission Source
- OIG: Community Behavioral Health Did Not Comply With Requirements When Denying Prior Authorization Requests
- CMS: Interoperability and Prior Authorization Final Rule
- CMS: Statement of Deficiencies and Plan of Correction guidance
- HHS: HIPAA Security Rule Notice of Proposed Rulemaking fact sheet
- EmpoThrive Services