Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
2
3
4
6
7
8
9
10
11
13
14
15
16
17
7:30 AM - HLTH 2025
18
19
20
22
23
24
25
26
27
28
29
30
31
1
2
12:00 AM - NextGen UGM 2025
TigerConnect + eVideon Unite Healthcare Communications
2025-09-30    
10:00 am
TigerConnect’s acquisition of eVideon represents a significant step forward in our mission to unify healthcare communications. By combining smart room technology with advanced clinical collaboration [...]
Pathology Visions 2025
2025-10-05 - 2025-10-07    
8:00 am - 5:00 pm
Elevate Patient Care: Discover the Power of DP & AI Pathology Visions unites 800+ digital pathology experts and peers tackling today's challenges and shaping tomorrow's [...]
AHIMA25  Conference
2025-10-12 - 2025-10-14    
9:00 am - 10:00 pm
Register for AHIMA25  Conference Today! HI professionals—Minneapolis is calling! Join us October 12-14 for AHIMA25 Conference, the must-attend HI event of the year. In a city known for its booming [...]
HLTH 2025
2025-10-17 - 2025-10-22    
7:30 am - 12:00 pm
One of the top healthcare innovation events that brings together healthcare startups, investors, and other healthcare innovators. This is comparable to say an investor and [...]
Federal EHR Annual Summit
2025-10-21 - 2025-10-23    
9:00 am - 10:00 pm
The Federal Electronic Health Record Modernization (FEHRM) office brings together clinical staff from the Department of Defense, Department of Veterans Affairs, Department of Homeland Security’s [...]
NextGen UGM 2025
2025-11-02 - 2025-11-05    
12:00 am
NextGen UGM 2025 is set to take place in Nashville, TN, from November 2 to 5 at the Gaylord Opryland Resort & Convention Center. This [...]
Events on 2025-10-05
Events on 2025-10-12
AHIMA25  Conference
12 Oct 25
Minnesota
Events on 2025-10-17
HLTH 2025
17 Oct 25
Nevada
Events on 2025-10-21
Events on 2025-11-02
NextGen UGM 2025
2 Nov 25
TN
Articles

Apr 25: EHR Incentive Audits-Common Questions on Timelines and Risk Profile

ehr incentive audits

By Jim Tate, EMR Advocate and Meaningful Use Audit Expert
Twitter: @JimTate
eMail: audits@emradvocate.com
Website: www.meaningfuluseaudits.com

In recent conversations with Eligible Hospitals (EHs) two questions seem to be coming up more and more concerning CMS EHR incentive audits. Let’s take them on one at a time.

How long can my CMS EHR incentive attestation be subject to an audit?

CMS is pretty clear that documentation used in support of an attestation should be saved for 6 years. “Documentation to support attestation data for Stage 2 meaningful use objectives and clinical quality measures should be retained for six years post‐attestation. Documentation to support payment calculations (such as cost report data) should continue to follow the current documentation retention processes.” Sounds to me that you could possibly be audited for up to 6 years after an individual attestation. Case closed.

If an audit is failed, does that make me more likely to be audited again in future years?

Ah, this is a good one and gets into the shady area of “risk profile”. CMS, for obvious reasons, is keeping their cards close to their chest on what makes up the “risk profile”.  There is another angle to this that touches not on risk of audits for future attestations but also on past attestations. Case in point, I was contacted last week about such a “look back” audit situation. The initial audit was performed on a 2012 attestation and notification was received of a Negative Determination in August 2013 based on one measure. They were then the subject of an audit based on an earlier (2011) attestation and were notified of failure in March 2014 on the exact same measure. It only makes sense that during an audit if it becomes obvious that there is evidence of a “problematic” attestation the same issue might exist in earlier attestations. Now I have no insider info on what makes up the “risk profile” but I can usually do a little reading between the lines. If you went through an 2014 meaningful use audit, and didn’t have a Security Risk Assessment, I would think there would be a chance you couldn’t provide it for prior attestations either. I’m expecting we will see more and more of these “look back” audits based on what is revealed during an initial audit. Just make sense to me.

Side note: At HIMSS in February I spoke with Elizabeth Holland (director CMS’ Health IT Initiatives Group) and Robert Anthony (deputy director of CMS’ Health IT Initiatives Group) at HIMSS this year and here’s what they told me: The majority of failed audits occur either for lack of having documentation of the MU measures or the Security Risk Analysis.   To address this critical documentation issue, we’ve now added a review of the Security Risk Assessment to our Mock Audit Services.  If you are interested in learning more about conducting a mock audit for your organization, please contact me at audits@emradvocate.com.

Source