What HRSA actually examines in a 340B audit.
HRSA audits roughly 200 covered entities each year — a small fraction of the total. Adverse findings, however, have historically appeared in between half and two-thirds of completed audits, depending on the year.
At a glance
- 01Audits per year
- ~200
- 02Share of entities
- < 1%
- 03Adverse finding rate
- Historically 49–70%
- 04Also audited
- Manufacturers
How an audit unfolds
HRSA selects entities for audit through a mix of risk-based targeting and random selection. Manufacturers may also request an audit of a covered entity where they have a reasonable basis to believe a violation has occurred.
The process typically begins with a notification letter and an engagement call, followed by a document request covering policies, registration records, purchasing history, claims data and contract pharmacy arrangements. Field work may be conducted remotely or on site.
Findings are issued in a draft report. The entity has an opportunity to respond and to submit a corrective action plan. Once the corrective action plan is accepted and implemented, the audit is closed — but the findings, and the entity, remain part of the public record.
The most common adverse findings
01Diversion
- What it typically looks like
- 340B drugs provided to individuals who do not meet the entity's patient definition — frequently referral prescriptions with inadequate documentation
- Preventable by
- Testing the patient definition against real encounters, and documenting the referral relationship
02Duplicate discounts
- What it typically looks like
- Medicaid Exclusion File status inconsistent with actual billing, or managed care claims not handled per state rules
- Preventable by
- Annual review of MEF status against billing practice, per state
03Eligibility documentation
- What it typically looks like
- Child sites registered without cost report evidence, or sites operating before registration was effective
- Preventable by
- Cost report linkage verified before submission, and a registration calendar
04Inaccurate OPAIS record
- What it typically looks like
- Closed sites still listed, operating sites not listed, lapsed authorizing official
- Preventable by
- An annual record accuracy audit against the actual footprint
05Contract pharmacy oversight
- What it typically looks like
- No documented oversight, reconciliation not evidenced, agreements missing or outdated
- Preventable by
- Location-level oversight documentation on a fixed cadence
06GPO prohibition violation
- What it typically looks like
- A DSH, children's or free-standing cancer hospital purchasing covered outpatient drugs through a GPO
- Preventable by
- Purchasing pathway audit — this is the highest-severity finding category
What happens after a finding
Outcomes vary considerably with the nature and scale of the finding. Isolated documentation errors are treated very differently from systemic diversion or a GPO prohibition violation.
- A corrective action plan is required, with defined actions and timelines
- Repayment to affected manufacturers may be required where a discount was improperly obtained
- Systemic violations can result in removal from the program
- Findings become part of the public record associated with your entity
- Reputational consequences can extend to your board, your payers and your community
- Follow-up review typically confirms whether the corrective action was actually implemented
HRSA audits — common questions
01How are entities selected for audit?
Through a combination of risk-based targeting and random selection. Manufacturers may also request an audit where they have a reasonable basis to believe a violation has occurred. Risk factors commonly include program size, contract pharmacy volume and prior findings.
02How long does an audit take?
From notification to closure is typically several months. Document production is the phase entities most often underestimate — assembling evidence that was never systematically maintained is slow, and the timeline does not accommodate it.
03Can we self-disclose a problem we found ourselves?
Yes, and self-disclosure is generally viewed more favorably than the same issue being discovered at audit. Whether to disclose, and how to frame it, is a decision that usually warrants both consulting and legal input.
04Does a finding mean we lose 340B?
Not usually. Most findings result in a corrective action plan and, where applicable, repayment. Removal from the program is reserved for systemic or egregious violations — but the risk is real, particularly for GPO prohibition violations.
05Should we run a mock audit even if we have never been selected?
Yes. HRSA expects covered entities to audit themselves regardless of whether it audits them, and mock audits generate exactly the evidence of self-auditing that HRSA looks for. Fewer than one percent of entities are audited in any given year, which means most programs go a long time without any external test.
Marked up with FAQPage schema for search and AI-answer eligibility.
Next step
The best time to find a finding is before HRSA does.
A mock audit tests the same areas, against your real data, while remediation is still cheap and private.