Part of our work on healthcare
Healthcare
The DME Documentation Process, and Why Audits Find the Same Gap
Big Sky Consulting Group · October 5, 2026 · 7 min read
The finding you have seen before
Your last audit letter and the one before it said roughly the same thing. Insufficient documentation. The item was delivered, the patient needed it, the claim was coded correctly, and the payment came back anyway.
Then the team did what teams do. Someone rebuilt the intake checklist. Someone bought a compliance course. Someone reminded the referral coordinators, again, to check for the face-to-face note. And the next audit found the same gap.
That repetition is the signal. When a finding survives three rounds of retraining, the problem is not that people are careless. It is that the process is built so that the document the audit cares about most is the one you control least.
How big the gap actually is
The scale is not a matter of opinion. CMS's 2024 Medicare Fee-for-Service supplemental improper payment data put the DMEPOS improper payment rate at 21.41 percent, about 1.92 billion dollars. That is roughly one dollar in five, across the whole supplier category.
The cause is not fraud and it is mostly not ineligible equipment. CMS attributes the root of the DMEPOS error rate to insufficient documentation: orders, records, and certifications that were missing or inadequate. Put plainly, most of the money is lost on paperwork about equipment that was probably appropriate.
That should change how you read your own audit results. If the national error is overwhelmingly a documentation error, then your audit outcomes are a measurement of your documentation process, not of your clinical judgment or your billing team's coding.
Two jobs wearing one folder
Here is the pattern we see underneath almost every recurring DME finding.
The documentation packet is assembled to get a claim paid. It is audited to verify a clinical story. Those are different jobs, done by different parties, on different timelines, and the packet only looks like one thing because it lives in one folder.
The claim job is the supplier's. Get the standard written order, confirm the item and the HCPCS code, deliver, capture proof of delivery, bill. Suppliers are usually good at this, because it is their process and they see the result in their cash.
The clinical story job belongs to somebody else. The treating practitioner examines the patient, writes the note, and decides what goes into the medical record. CMS's standard documentation requirements for DME MAC claims are explicit that medical necessity has to be supported by the beneficiary's medical record. An attestation or a supplier-prepared form does not substitute for it.
So the auditor opens your packet and reads the one document you did not write. If the physician's note says "patient would benefit from" instead of describing the functional limitation the policy requires, the claim fails. Your intake checklist confirmed the note existed. It could not confirm the note said the right thing, because nobody on your side was in the exam room.
This is why we call it a control failure rather than a diligence failure. A diligence failure goes away when people try harder. A control failure is structural: the outcome depends on an input you cannot directly govern. You cannot checklist your way out of depending on a document someone else writes.
Why the checklist industry does not fix it
Search for DME audit readiness and the first page is checklists, compliance consultancies, and billing services. Most of the advice is accurate. Very little of it is useful for the recurring finding, because it treats the packet as a single object that can be made complete by inspection.
A checklist answers "is the document here?" The audit asks "does the document say enough?" Those questions need different people. The first can be answered by an intake coordinator in thirty seconds. The second needs someone who knows the local coverage determination for that product category and is willing to send a note back to a referring practice that sends you half your volume.
That last part is where the process actually breaks. Pushing back on a referral source is commercially awkward. Intake staff are measured on how fast orders move, not on how many claims survive review a year later. So the incentive points toward accepting the thin note, and the audit catches it eighteen months after anyone could have fixed it.
If that sounds familiar, it is the same shape as a problem we have written about in eligibility verification: the people creating the error never see its consequence, so the error recurs no matter how often they are trained.
This is the general shape of the problem. Which parts apply to your process depends on answers only your systems can give.
Put us on it, from $5,000Proof of delivery is the quiet one
The physician note gets the attention because it is the hard part. Proof of delivery is the finding that should embarrass suppliers most, because it is entirely in their control.
The rule is not subtle. Suppliers must keep proof of delivery for seven years from the date of service, and the DME MACs treat a POD you cannot produce in an audit as though the delivery never happened. CGS's supplier documentation manual spells out the required elements: beneficiary name, delivery address, a description of the items detailed enough to verify coding, quantity, the date, and a signature.
When POD fails, it is rarely because the driver skipped the signature. It is because the signature is in a system nobody can search, attached to the wrong order, missing the item description, or sitting in a courier portal whose retention is shorter than seven years. That is not a clinical problem. It is a records problem, and a records problem is the one kind of documentation gap that is genuinely automatable.
Which brings us to the part vendors will want to talk about.
What automation can and cannot do here
Documentation automation for DME is a real category, and some of it is good. It is worth being precise about which half of the problem it addresses.
It is well suited to the claim job. Capturing POD with the right fields, linking it to the order, retaining it for the full period, flagging an order that arrives without a face-to-face date, checking that the written order has the elements the policy requires. These are rules, the rules are published, and software applies them more consistently than a tired coordinator at 4:45 on a Friday.
It is poorly suited to the clinical story job. Some products now read the physician's note and score it against the coverage criteria. That can help triage. But a model that flags a weak note has not fixed the note. Someone still has to go back to the referring practice and ask for an addendum, and that conversation is exactly the one your process currently avoids.
The trap is buying the second kind of tool and expecting it to solve the first kind of problem. A supplier that automates packet assembly without changing who is accountable for note quality will produce complete-looking packets faster, and fail audits on the same grounds. We made a related argument about prior authorization automation: automating the submission without fixing what gets submitted just produces the wrong outcome at higher speed.
In short, the tool can tell you the paper is thin. It cannot make the paper thicker. (Someone had to say it.)
The questions that decide the outcome
We will not pretend there is a universal fix, because the right one depends on your product mix, your referral concentration, and which MAC jurisdictions you bill. But the questions that separate a supplier that keeps failing audits from one that stops are consistent.
Do you know where your findings concentrate? Not your overall error rate. Which product categories, which referring practices, and which document type. In most suppliers we would expect a small number of referral sources to account for a disproportionate share of thin notes. You cannot know that without sorting your own audit and pre-payment review results, and most suppliers have never sorted them.
Who owns note quality before the claim drops? If the honest answer is "the intake coordinator, informally," then nobody owns it. Somebody with the authority to hold an order and the knowledge to explain why has to sit at that point.
Is your proof of delivery retrievable, or just retained? Pick a date of service from five years ago and time how long it takes to produce a complete POD. That number tells you more about your audit exposure than any readiness score.
What does a denial on a thin note actually cost you? Not the claim value. The rework, the appeal, the time a person spends assembling records from a practice that has since changed EHRs. We have written about what a denial really costs in rework, and the mechanism is the same for suppliers: the cost is real, it sits in salaries, and it is invisible on any report you already run.
Answering those four is an afternoon of uncomfortable data pulls. Acting on them is where the process design, the referral conversations, and the tooling decisions get made.
Where this leaves you
A recurring DME audit finding is not evidence that your team is careless. It is evidence that your process depends on a document you do not control and has no mechanism to push back on it before the claim goes out. Better checklists measure the gap more precisely. They do not close it.
If your audit letters keep naming the same gap, that is the problem we work on. Talk to us about where your findings concentrate and which half of the documentation problem is actually yours to fix.
