Medicare Advantage compliance

What would CMS find in your plan today? Find out for free.

Send us one file: a universe, a CMS memo, a vendor contract, a policy, a provider or facility roster, a Part C or Part D reporting file, or an impermissible use or disclosure you are working through. Within two business days you get back what an auditor would write about it, with the regulation beside every line. We sign the HIPAA Business Associate Agreement first and do the work before you owe us anything. That is how we earn your trust, and how a partnership starts.

Mario Botana, founder of Precision Compliance Group

I read your file myself, and I take the call.

Mario Botana, JM, CHC, CIPP/USFounder

(305) 510 0774
In production at Solis Health Plans 18 universe tables checked against the regulation in force One price per plan, quoted on the first call
What we do

The whole compliance program, on one platform, with the people who built it.

Precision Compliance Group runs Medicare Advantage compliance end to end. CMS memos read and assigned. Universes checked before submission. Program audits run the CMS way. Corrective action plans through closure. Vendor and delegate oversight from the contract itself. Network adequacy measured the day the roster changes. Part C and D reporting recounted before upload. Policies checked against the rule. Risk, privacy, and the board record. Twenty modules on one license, built inside a health plan, in production at Solis Health Plans.

When a plan needs a person as well, the same team does the work: mock audits, CAPs, vendor assessments, exception requests, policy rewrites, incident response.

Call (305) 510 0774. A demo runs on your own work, under a signed BAA, in thirty minutes.

The platform

Twenty modules on one license, one sign-in, and one audit trail. These are the ones most plans start with.

Precision Mandate · CMS memos

Every HPMS memo read, assigned, and due before the regulator's date.

Drop the memo in or let it arrive. Mandate pulls out the action items, quotes the memo text behind each one, names the department, sets the working due date ahead of CMS's, and sends each owner a morning brief. Acknowledgements, evidence, and the officer's review live on the memo.

  • Every quote checked against the memo text before it reaches a department
  • Working due date a few days ahead of the external one
  • One mention email, a per person activity highlight, and a full timeline
Precision Mandate · memo briefing
A Precision Mandate memo briefing with the action items and due date
Scrubber · universe validation

Eighteen universe tables graded against the regulation, not the PDF.

ODAG, CDAG, FA, SNPCC, and CPE. Field rules from the CMS record layouts, timeliness from the regulation in force, and a complete universe export with every issue marked in the row where CMS will look for it. Files are checked in memory and the enrollee rows are never written to disk.

  • Roughly 350 field rules and 33 timeliness scenarios across the tables
  • Complete universe export, issue tabs, timeliness summary
  • The same checks run inside Audit before an engagement starts
Scrubber · choose the universe table
The Scrubber with the ODAG universe tables ready to check
Audit · internal and delegated entity audits

Your own program audit, run the way CMS runs it, before CMS does.

Pick the area, ODAG, CDAG, SNPCC, or provider directory accuracy. The engagement notice goes out on your letterhead. The universe comes in on the CMS clock and is checked before testing starts. Samples are drawn by the protocol. Findings become conditions, and the report comes out in the CMS program audit format with the results workbook beside it.

  • Auditees and vendors work their own evidence requests through a separate sign-in
  • Protected health information is working material: drawn from validated universes, destroyed at close, destruction recorded
  • Every finding lands in the Issues Log and, where warranted, opens a CAP
Audit · ODAG internal audit workspace
An internal ODAG audit workspace showing the period under review, engagement date, evidence due date, and authorities
Risk Assessment · the register

The risk register scored the way the compliance committee reads it.

Every risk sits in one of the eight compliance domains or Reputational, with inherent and residual scores, the owner, the controls, and the year over year change. The heat map and the register go to the committee and the board as they are, and the work plan draws its monitoring from what scored highest.

  • Eight domains plus Reputational, nothing invented
  • Inherent and residual scoring with the controls that close the gap
  • Feeds the COA Work Plan, so monitoring follows the risk
Risk Assessment · register
The Risk Assessment register with scored risks and the heat map
Precision Privacy · program and incidents

A privacy incident carried from the first report to the last letter.

Intake, the risk assessment, the sixty day clock from discovery, state rules, the notifications, and the letters to members, HHS, and the covered recipients who reported it. The program itself lives beside the incidents: policies, training, the vendor reviews, and the officer’s record.

  • The clock starts at intake and is visible on every case
  • Assessment written to the HIPAA factors, with the outcome recorded either way
  • Letters generated from the case and kept as sent
Privacy, end to endHIPAA Breach Notification Rule and Privacy Rule
  1. Discovery. The clock starts the day the incident is known, or should have been known. Every case is dated from that day, not from the day it reached the privacy officer.45 CFR 164.404(b)
  2. Assessment. The four factor risk assessment: what was involved, who used or received it, whether it was actually acquired or viewed, and how far the harm was mitigated. The outcome is recorded either way.45 CFR 164.402
  3. Notification. Individuals without unreasonable delay and within sixty days. HHS within sixty days when five hundred or more are affected, otherwise in the annual log. Media when five hundred or more in a state.45 CFR 164.404, 164.406, 164.408
  4. Business associates. Notice from the associate to the plan, the agreement terms that bind it, and the record of both.45 CFR 164.410, 164.504(e)
  5. Mitigation and sanctions. Harmful effects mitigated, workforce sanctions applied and recorded, substance use disorder records handled under their own consent rules.45 CFR 164.530(e), (f) · 42 CFR Part 2
  6. Documentation. The case, the letters, and the decisions kept for six years, ready for an OCR request.45 CFR 164.530(j)
FDR Oversight · delegation

The vendor file CMS expects, built from the contract itself.

Contracts are read for what is actually delegated. The annual assessment assembles from that scope, goes to the vendor through a portal with its own sign-in, comes back scored, and every email in between is kept exactly as sent. Monthly exclusion screening writes its own evidence row.

  • Delegation scope register, verbatim from the contract and its addenda
  • Annual assessments, attestations, scorecards, and correspondence per vendor
  • Findings and CAPs on the vendor, with the audit trail underneath
Delegation oversight, end to endMedicare Advantage first tier, downstream, and related entities
  1. The written agreement. Every required provision present, and the delegated functions taken from the contract and its addenda, not from memory.42 CFR 422.504(i)(3), (i)(4)
  2. Before delegation. The entity can perform the work, and no one performing it is excluded. Screened against the OIG exclusion list and SAM.gov before the first day.42 CFR 1001.1901 · 422.503(b)(4)(vi)(F)
  3. Ongoing monitoring. Exclusion screening every month with the evidence row, performance measured against the delegated functions, and a scorecard per vendor.42 CFR 422.503(b)(4)(vi)(F)
  4. Annual assessment. An audit each year on the tools that match what is delegated, sent to the vendor, returned scored, with every message kept as sent.42 CFR 422.504(i)(4)
  5. Findings and correction. Findings to the vendor, a corrective action plan with dates, and revocation of the delegation where the plan has to.42 CFR 422.504(i)(4)
  6. Records. Contracts, screenings, assessments, and correspondence available to CMS for ten years.42 CFR 422.504(d), (e)
Network Adequacy · 42 CFR 422.116

Every county, every standard, measured the day the roster changes.

Upload the provider roster and the platform scores it against every CMS standard by county and specialty. Gaps become findings the network team can work. Drive times are mapped. When a gap cannot be closed, the exception request drafts with the rationale and the data.

  • Roster attestations on a cycle, so the roster stays true
  • Findings queue, drive time map, HPMS tables out
  • Trend across runs, so the board sees direction, not a snapshot
Network Adequacy · overview
Network Adequacy overview with standards met by county and a trend across runs
See all twenty modules Policy review, RuleIQ, Reporter, Risk, COA Work Plan, Privacy, SignoffHub, and more.
Before you renew

Six questions to ask your current vendor. Then ask us.

Every one of these has a yes or no answer. Write down what you hear.

1
Does it grade my universes against the regulation in force today, or against the protocol PDF?
PCG: The regulation. When the protocol document and the CFR disagree, the platform follows the CFR and the finding says so, with the citation.
2
Does every finding show me the regulation line behind it?
PCG: Yes. A finding without a citation is not shown. The policy reviewer, the memo reader, and the rule reader all quote the source next to the flag.
3
Where do my enrollee rows go after a universe is checked?
PCG: Nowhere. Universes are validated in memory. The enrollee rows are removed before anything is stored. What persists is a de-identified timeliness summary.
4
Does the price change when I add a user, a file, a vendor portal, or an analysis?
PCG: No. One annual price for the plan, set by enrolled membership. Every module, every user, every vendor portal, every analysis. We quote the number on the first call.
5
Can the person who built it get on the phone this week?
PCG: Yes. The people who built the platform answer the support mailbox and take the calls. There is no tier between you and them.
6
Will you tell me what CMS would find in my plan before I sign anything?
PCG: Yes. Send one file. The read comes back in two business days, free, with the regulation beside every line. Then decide.
In production Solis Health Plans A Florida Medicare Advantage and Dual Eligible Special Needs Plan organization runs its compliance program on the platform: CMS memos, universe validation, audits, FDR oversight, policies, and board reporting.
20
modules on one license and one sign-in
18
universe tables validated across ODAG, CDAG, FA, SNPCC, and CPE
20
Part C and Part D reporting sections recounted from source records
1
business day to a reply from a person
Trust

How your data is handled.

Business Associate Agreement first

Signed before any work involving protected health information begins. No exceptions for demos.

United States only

Hosted on Microsoft Azure in US regions. Nothing about your plan leaves that boundary, and no other provider ever sees it.

SOC 2 Type 1 in process

Examination in preparation with Thoropass, covering the platform and the Scrubber. The controls are running today: multi-factor sign-in, append-only audit log, tenant isolation, encryption in transit and at rest.

The first call

Call (305) 510 0774. Or send one file and get the read.

Tell us what is on your desk: a universe due in two weeks, a memo nobody has read, a vendor you have never assessed, a network gap. We answer on the call, and the memo follows in writing with the citations. If our platform would help, we will show you on your own file.

What happens next

A person answers. If we are on another call, we call back the same day.

The memo arrives as a PDF with every citation. Yours to keep, whether or not we ever work together.

Prefer email? support@PrecisionComplianceGroup.onmicrosoft.com