Quick answer: A CMS Open Payments audit is CMS checking that the Sunshine Act payment data your organization submitted actually matches what happened, not a routine formality, and not tied to a fixed annual cycle. CMS can request records at any time, reporting entities are expected to respond within a proposed 30-day window, and supporting documentation must stay retrievable for 5 years. The sections below walk through who's covered, what CMS asks for, how to prepare, and answer 19 of the most common compliance-team questions in plain language.
On This Page
- What Is a CMS Open Payments Audit?
- Who Must Comply: Reporting Entities & Covered Recipients
- Key Open Payments Terms to Know
-
Frequently Asked Questions
- What Triggers a CMS Open Payments Audit?
- What Legal Authority Does CMS Use to Conduct Open Payments Audits?
- What Records Does CMS Request During an Open Payments Audit?
- How Long Does a Reporting Entity Have to Respond to a CMS Audit Request?
- What Are the Penalties for Open Payments Non-Compliance?
- What Is the CMS Open Payments Reporting Deadline for CY2025 Data?
- How Long Must Reporting Entities Retain Open Payments Records?
- What Is the Difference Between a CMS Open Payments Audit and an Internal Compliance Audit?
- How Often Should Compliance Teams Audit Expense Reports Before CMS Does?
- What Does "Dispute Resolution" Mean in the Open Payments Context, and Does It Affect Audit Risk?
- What Is CMS Proposing to Change About Open Payments Audit Enforcement in 2026?
- Who Is Considered a Covered Recipient Under Open Payments?
- What Is a Program Year in CMS Open Payments Reporting?
- What Is the Difference Between General Payments, Research Payments, and Ownership Interests?
- Why Do Name of Study Entries in Research Payment Data Draw CMS Scrutiny?
- How Should Reporting Entities Correct Name of Study Errors, Including Prior Program Years?
- How Does the Open Payments Dispute and Correction Process Work?
- What Happens During the Pre-Publication Review Period?
- Are Physician Assistants and Nurse Practitioners Covered Recipients?
- 7-Step CMS Open Payments Audit Readiness Checklist
- CMS Audit vs. Internal Audit at a Glance
- 2025 Open Payments Data at a Glance
- Official Resources
- Free Compliance Resources
- How qordata Supports Open Payments Audit Readiness
- FAQ Summary
What is a CMS Open Payments audit?
A CMS Open Payments audit is a formal review initiated by the Centers for Medicare and Medicaid Services to verify that applicable manufacturers and group purchasing organizations have accurately reported transfers of value to covered recipients under the Physician Payments Sunshine Act. CMS holds audit authority under 42 C.F.R. § 403.912(e)(2), which authorizes the agency to request records, documentation, and attestations from reporting entities. Failure to respond or to produce accurate records can result in civil monetary penalties.
Open Payments was created under Section 6002 of the Affordable Care Act, commonly known as the Physician Payments Sunshine Act. Since its public database launched in 2014, CMS has used the program to give patients, researchers, and regulators visibility into the financial relationships between drug and device manufacturers and the clinicians and hospitals that prescribe, use, or purchase their products. An audit is CMS's mechanism for confirming that the data a reporting entity submits each Program Year reflects what actually happened, not simply that a submission was filed on time.
Key Takeaway: An audit request isn't itself a penalty: it's CMS checking your work. The real risk is a discrepancy between what you submitted and what your records actually show, which is why the response depends entirely on documentation you should already have on hand.
Who Must Comply: Reporting Entities & Covered Recipients
Two types of organizations are required to report to Open Payments each Program Year: applicable manufacturers of covered drugs, devices, biologicals, or medical supplies, and applicable group purchasing organizations (GPOs). Both must register with CMS, submit payment and ownership data annually, and be able to substantiate that data if CMS requests supporting records.
Reporting Entities
- Applicable manufacturers that produce, prepare, propagate, compound, or convert a covered drug, device, biological, or medical supply
- Applicable group purchasing organizations (GPOs) that negotiate purchasing arrangements or contracts on behalf of health care providers
Covered Recipients
- Physicians and teaching hospitals, covered recipients since the program's inception
- Physician assistants, nurse practitioners, and clinical nurse specialists
- Certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives
The six additional non-physician practitioner types were added as covered recipients starting with Program Year 2021 data collection, expanding the population of providers whose payment relationships with industry are publicly reported. Reporting entities that engage any of these practitioner types must track and report payments to them using the same standards applied to physicians and teaching hospitals. Learn more from CMS.
Key Takeaway: If your organization reports to Open Payments at all, every practitioner type listed above is in audit scope, not just physicians. Teams that only track physician payments closely are the most likely to have gaps in the other six categories.
Key Open Payments Terms to Know
CMS audit requests reference specific regulatory terminology. Compliance teams should be fluent in the following terms before a request arrives, not while responding to one.
Program Year
The calendar year (January 1 through December 31) during which a reportable payment or transfer of value occurred. Data for a given Program Year is collected the following spring, reviewed by covered recipients, and published mid-year.
General Payments
Payments or transfers of value not connected to a research agreement or protocol: consulting fees, meals, travel, and speaker compensation, for example. This is the category most relevant to day-to-day HCP engagement compliance.
Research Payments
Payments made in connection with a research agreement, protocol, or clinical study. CMS collects and publishes these separately from General Payments.
Ownership and Investment Interests
Ownership or investment interests held by physicians, or their immediate family members, in an applicable manufacturer or GPO. Reported as its own data category, separate from General and Research Payments.
Nature of Payment
The CMS-defined category that classifies each transfer of value, such as food and beverage, royalty or license, consulting fee, or compensation for services other than consulting.
Civil Monetary Penalty (CMP)
A financial penalty CMS can assess against a reporting entity for failing to report, knowingly failing to report, or, under proposed 2026 rulemaking, failing to respond to an audit request within the required window.
Pre-Publication Review
The annual window (typically April 1 through May 15, with an extended resolution period through May 30) during which covered recipients review submitted records and reporting entities resolve disputes before CMS publishes the data.
Key Takeaway: Of these seven terms, Program Year, Nature of Payment, and CMP are the three most likely to appear verbatim in an actual CMS audit request: worth having your team fluent in first.
7-Step CMS Open Payments Audit Readiness Checklist
Compliance teams that treat audit readiness as a continuous discipline, rather than an annual scramble, respond faster and with more confidence when a CMS request arrives. These are the practices qordata recommends to life sciences compliance teams preparing for a CMS Open Payments audit.
Centralize Your Audit Trail Documentation
Keep contracts, expense receipts, FMV assessments, attendance records, and approval workflows in one system so every submitted record can be traced back to its source document within minutes, not days.
Reconcile Continuously, Not Just Before Submission
Match source-system data (expense platforms, CRM, speaker program logs) against what was actually submitted to CMS throughout the Program Year, not only in the weeks before the reporting deadline.
Give Low-Dollar, High-Volume Categories the Same Scrutiny as High-Dollar Ones
Food and beverage records make up the large majority of most reporting entities' transaction volume. A high error rate in a low-dollar category can still represent significant aggregate exposure.
Build a 30-Day Audit Response Protocol
Document who owns each step of an audit response (records retrieval, legal review, submission) so your organization can meet the response window proposed under CMS's 2026 rulemaking without scrambling to assemble a team.
Treat the Pre-Publication Review Period as a Data-Quality Checkpoint
Use the annual dispute window (April 1 through May 30) to catch and correct errors before they become part of the public record, and analyze disputed records for patterns that reveal upstream process gaps.
Maintain the Full Five-Year Retention Window
Confirm that document retention policies and systems keep supporting records retrievable, not just archived, for the entire period CMS can request them.
Audit 100% of Records, Continuously
Replace periodic sampling with continuous, automated review of expense and payment records so no category, and no Program Year, is left unexamined heading into an audit.
Key Takeaway: The teams that clear a CMS audit fastest are the ones already reconciling continuously (Step 2), not the ones scrambling to assemble records after a request arrives.
CMS Audit vs. Internal Audit at a Glance
The two review types work together, but they differ in who initiates them, what authority backs them, and what happens when they turn up a problem.
| Aspect | CMS Open Payments Audit | Internal Compliance Audit |
|---|---|---|
| Who initiates it | CMS, at any time | The reporting entity itself |
| Legal authority | 42 C.F.R. § 403.912(e)(2) | None: a voluntary compliance practice |
| Primary purpose | Verify accuracy of submitted Sunshine Act data | Identify and correct data issues before CMS review |
| Response obligation | Defined response window (30 days proposed) | No external deadline |
| Consequence of findings | Civil monetary penalties for inaccurate or missing records | Internal corrective action; reduced future audit risk |
| Recommended frequency | Can occur at any time, for any Program Year within the retention window | Continuous, ideally covering 100% of records |
2025 Open Payments Data at a Glance
On June 30, 2026, CMS published the Program Year 2025 Open Payments data: more than 16.13 million individual General Payments records, totaling $3.92 billion, from 1,854 reporting manufacturers and GPOs. Where the money goes tells two very different stories, and both matter for audit readiness.
Source: qordata analysis of CMS Program Year 2025 Open Payments data. Read the full breakdown in 2025 Open Payments Data: Key Facts.
Royalty or License payments were the single largest General Payments category by dollar value (30.7% of all General Payments dollars) but came from only 15,496 records, an average of roughly $77,700 per record. Food and Beverage told the opposite story: 91.5% of all records but only 11.3% of dollars. For audit purposes, that split matters: a compliance program built only around dollar thresholds will miss the category most likely to contain volume-driven errors, which is exactly the kind of gap a CMS audit is designed to find.
Official Resources
Open Payments Program Homepage
CMS's central hub for Open Payments program overview, data publication timelines, and resources for reporting entities and covered recipients: cms.gov/priorities/key-initiatives/open-payments
CMS Open Payments Frequently Asked Questions
CMS maintains an official FAQ page covering reporting requirements, submission procedures, and program guidance: cms.gov/priorities/key-initiatives/open-payments/frequently-asked-questions
Explore the Public Open Payments Data
CMS's public data platform, where anyone can search, filter, and download Open Payments records by reporting entity, covered recipient, or Program Year: openpaymentsdata.cms.gov
Dispute and Correction Guidance
CMS's guidance for reporting entities on resolving disputed records and submitting corrections during and after the pre-publication review period: cms.gov/openpayments/program-participants/reporting-entities/dispute-and-correction
Regulatory Authority
42 C.F.R. § 403.912(e)(2) establishes CMS's authority to audit applicable manufacturers and GPOs and to require production of supporting records.
2026 Proposed Rulemaking
CMS's proposed enforcement mechanism for audit non-response (30-day response window, CMP exposure) was open for public comment through June 15, 2026. Compliance teams should monitor the final rule publication for effective dates and implementation requirements.
Free Compliance Resources
CMS Open Payments Audits: Why and How to Be Audit Ready
A practical guide to understanding CMS audit triggers, building a defensible audit trail, and preparing your compliance program before a request arrives.
Download the WhitepaperPreparing for a CMS Open Payments Audit
Watch qordata's on-demand webinar for a walkthrough of audit readiness best practices, common pitfalls, and how leading compliance teams stay prepared.
Watch the WebinarOpen Payments: Audit Best Practices (CMS, 2026)
CMS's own resource guide on what to expect during an audit: document types requested, preparation strategies, and answers to the questions reporting entities ask most.
Download the CMS GuideHow qordata Supports Open Payments Audit Readiness
qordata's Expense Monitoring and Auditing solution audits 100% of expense records using AI-driven review rather than sampling, so compliance teams have a complete, defensible audit trail before CMS requests one. Compliance Central centralizes documentation, surfaces potential risks in real time, and maintains the record linkage that CMS audit requests require.
- 100% Expense Record Review: AI-driven review of every expense record, not a statistical sample, so nothing enters your Open Payments submission unverified.
- Centralized Audit Trail: Compliance Central links every submitted record back to its contract, receipt, or approval, ready to produce if CMS requests it.
- Real-Time Risk Surfacing: Potential FMV, duplicate, or documentation gaps are flagged as they occur, not discovered during Program Year close-out.
- Dispute & Correction Support: Track disputed records through the pre-publication review window without losing visibility into resolution status.
To see how Compliance Central supports your audit preparation, contact the team at sales@qordata.com or schedule a demo at qordata.com.
FAQ Summary
What is a CMS Open Payments audit?
A formal review under 42 C.F.R. § 403.912(e)(2) in which CMS requests records and documentation from applicable manufacturers or GPOs to verify the accuracy of their Sunshine Act submissions. Non-response or inaccurate records can result in civil monetary penalties.
What triggers a CMS Open Payments audit?
CMS can initiate an audit at any time. Common triggers include data discrepancies, disputed records, late submissions, and prior enforcement history. CMS issued 9 CMPs in FY2022, up from 3 in FY2021.
What records does CMS request during an Open Payments audit?
CMS typically requests contracts, expense reports, receipts, FMV assessments, attendance records, approval workflows, and reconciliation files that connect submitted records to source documentation.
What are the penalties for Open Payments non-compliance?
Penalties range from $1,000 to $10,000 per unreported payment (up to $150,000 annually) and from $10,000 to $100,000 per knowing failure to report (up to $1,000,000 annually). Proposed 2026 rulemaking would add CMP exposure for failing to respond to an audit request within 30 days.
How long must reporting entities keep Open Payments records?
CMS requires a five-year retention period from the date of submission for all records supporting Open Payments data.
What is the difference between an internal compliance audit and a CMS audit?
A CMS audit is externally initiated, carries legal authority, and has defined response obligations. An internal audit is self-initiated and serves as the primary mechanism for identifying and correcting data quality issues before CMS review.
How does continuous expense monitoring reduce Open Payments audit risk?
Continuous monitoring of 100% of expense records ensures that inaccurate or unsupported records are identified and corrected before submission. This produces a more accurate dataset and a more complete audit trail, both of which reduce exposure during a CMS review.
Who is considered a covered recipient under Open Payments?
Physicians and teaching hospitals, plus six additional practitioner types added starting with Program Year 2021: physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives.
What is a Program Year in Open Payments reporting?
The calendar year (January 1 through December 31) in which a reportable payment occurred. Data is submitted the following spring and published mid-year, and CMS can audit any Program Year within the five-year retention window.
What's the difference between General Payments, Research Payments, and Ownership Interests?
General Payments cover non-research transfers of value like consulting fees and meals; Research Payments cover research-agreement payments; Ownership and Investment Interests cover physician ownership stakes in a manufacturer or GPO. Each is reported and published separately.
Why is CMS flagging Name of Study entries in research payment data?
CMS checks the Name of Study field and ClinicalTrials.gov identifier on Research Payment records against the public registry; a shorthand title, a drifted name, or a missing identifier creates a mismatch, on current or prior Program Year data.
How should reporting entities correct Name of Study errors?
Request the exact Record IDs and Program Year CMS flagged and correct those first, then review every Name of Study entry on file, current and prior years, against ClinicalTrials.gov and correct any additional mismatches found.
How does the Open Payments dispute and correction process work?
Covered recipients dispute records directly with the reporting entity during the pre-publication review period; CMS does not mediate. Unresolved disputes by the close of the extended window are published as disputed.
What happens during the pre-publication review period?
Covered recipients review submitted records, typically from April 1 through May 15 (extended through May 30), and can flag disputes before CMS publishes the data. New disputes can be filed through December 31.
Are physician assistants and nurse practitioners covered recipients?
Yes, since Program Year 2021, along with clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives.