Medicare Managed Care Manual (Pub. 100-16), Ch. 5 § 30.1.1
HEDIS® Compliance Audit Requirements
30.1.1 - HEDIS® Compliance Audit Requirements
(Rev. 117, Issued: 08-08-14, Effective: 08-08-14, Implementation: 08-08-14)
Because of the critical importance of ensuring accurate data, CMS continues to require an
external audit of the HEDIS® measures before public reporting. MAOs and §1876 cost
contracts are responsible for submitting audited data, according to the audit methodology
outlined in Volume 5: HEDIS® Compliance Audit: Standards, Policies and Procedures.
CMS requires each MAO and §1876 cost contract to contract with an NCQA licensed
organization for an NCQA HEDIS® Compliance Audit. The licensed audit firms are
listed on NCQA’s Web site at http://www.ncqa.org/. CMS requires that the licensed
organizations follow the established standards, policies and procedures in NCQA’s
HEDIS®, Volume 5. All contracts must ensure that the site visit audit team is led by a
NCQA Certified HEDIS® Compliance Auditor. In addition, the plan’s chief executive
officer, president, or other authorized person, such as the medical director, will be
required to provide an electronic attestation to the validity of the plan-generated data in
IDSS.