CMS Open Payments Audit: Resources & FAQs
What is a CMS Open Payments audit?
A CMS Open Payments audit is a formal review initiated by the Centers for Medicare and Medicaid Services to verify that applicable manufacturers and group purchasing organizations have accurately reported transfers of value to covered recipients under the Physician Payments Sunshine Act. CMS holds audit authority under 42 C.F.R. § 403.912(e)(2), which authorizes the agency to request records, documentation, and attestations from reporting entities. Failure to respond or to produce accurate records can result in civil monetary penalties.
Open Payments was created under Section 6002 of the Affordable Care Act, commonly known as the Physician Payments Sunshine Act. Since its public database launched in 2014, CMS has used the program to give patients, researchers, and regulators visibility into the financial relationships between drug and device manufacturers and the clinicians and hospitals that prescribe, use, or purchase their products. An audit is CMS's mechanism for confirming that the data a reporting entity submits each Program Year reflects what actually happened — not simply that a submission was filed on time.
Who Must Comply: Reporting Entities & Covered Recipients
Two types of organizations are required to report to Open Payments each Program Year: applicable manufacturers of covered drugs, devices, biologicals, or medical supplies, and applicable group purchasing organizations (GPOs). Both must register with CMS, submit payment and ownership data annually, and be able to substantiate that data if CMS requests supporting records.
Reporting Entities
- Applicable manufacturers that produce, prepare, propagate, compound, or convert a covered drug, device, biological, or medical supply
- Applicable group purchasing organizations (GPOs) that negotiate purchasing arrangements or contracts on behalf of health care providers
Covered Recipients
- Physicians and teaching hospitals — covered recipients since the program's inception
- Physician assistants, nurse practitioners, and clinical nurse specialists
- Certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives
The six additional non-physician practitioner types were added as covered recipients starting with Program Year 2021 data collection, expanding the population of providers whose payment relationships with industry are publicly reported. Reporting entities that engage any of these practitioner types must track and report payments to them using the same standards applied to physicians and teaching hospitals. Learn more from CMS.
Key Open Payments Terms to Know
CMS audit requests reference specific regulatory terminology. Compliance teams should be fluent in the following terms before a request arrives, not while responding to one.
Program Year
The calendar year (January 1 through December 31) during which a reportable payment or transfer of value occurred. Data for a given Program Year is collected the following spring, reviewed by covered recipients, and published mid-year.
General Payments
Payments or transfers of value not connected to a research agreement or protocol — consulting fees, meals, travel, and speaker compensation, for example. This is the category most relevant to day-to-day HCP engagement compliance.
Research Payments
Payments made in connection with a research agreement, protocol, or clinical study. CMS collects and publishes these separately from General Payments.
Ownership and Investment Interests
Ownership or investment interests held by physicians, or their immediate family members, in an applicable manufacturer or GPO. Reported as its own data category, separate from General and Research Payments.
Nature of Payment
The CMS-defined category that classifies each transfer of value, such as food and beverage, royalty or license, consulting fee, or compensation for services other than consulting.
Civil Monetary Penalty (CMP)
A financial penalty CMS can assess against a reporting entity for failing to report, knowingly failing to report, or — under proposed 2026 rulemaking — failing to respond to an audit request within the required window.
Pre-Publication Review
The annual window (typically April 1 through May 15, with an extended resolution period through May 30) during which covered recipients review submitted records and reporting entities resolve disputes before CMS publishes the data.
Frequently Asked Questions
What Triggers a CMS Open Payments Audit?
CMS can initiate an audit at any time. Common triggers include discrepancies between submitted data and third-party sources, late or incomplete submissions, patterns of disputed records, and prior enforcement history.
CMS has also added Sunshine Act-specific audit guidance to its official FAQ documentation, a signal that audit activity is an ongoing enforcement priority rather than a periodic one. CMP issuance has increased in recent fiscal years: 7 penalties in FY2020, 3 in FY2021, and 9 in FY2022. Combined with new proposed rulemaking, that pattern indicates compliance teams should treat audit readiness as a continuous operational requirement, not an annual exercise.
What Legal Authority Does CMS Use to Conduct Open Payments Audits?
CMS audit authority is established under 42 C.F.R. § 403.912(e)(2). This provision requires applicable manufacturers and applicable GPOs to maintain records supporting their submitted data and to make those records available to CMS upon request. The underlying statutory framework is Section 6002 of the Affordable Care Act, which codifies the Sunshine Act.
What Records Does CMS Request During an Open Payments Audit?
CMS requests documentation that substantiates each reported transfer of value. Compliance teams should be prepared to produce:
- Contracts and consulting agreements with covered recipients
- Expense reports and receipts tied to specific payment records
- Fair market value (FMV) assessments for services rendered
- Attendance records for meals, events, and speaker programs
- Internal approval workflows and sign-off documentation
- Reconciliation records showing how data moved from source systems into the Open Payments submission
The audit trail must connect each submitted record back to a source document. Gaps in that chain, particularly in high-volume, low-dollar categories like food and beverage, represent meaningful exposure.
How Long Does a Reporting Entity Have to Respond to a CMS Audit Request?
Under current CMS proposed rulemaking (public comments due June 15, 2026), failing to respond to an audit request within 30 days would constitute grounds for civil monetary penalties. This is a forward-looking regulatory signal, not yet a final rule, but compliance teams should treat 30 days as the working standard for response readiness.
Documentation cannot be assembled reactively. Records, reconciliation files, and supporting evidence must be organized and accessible before an audit request arrives.
What Are the Penalties for Open Payments Non-Compliance?
CMS can impose civil monetary penalties across several categories:
- Failure to report: $1,000 to $10,000 per payment not reported, up to an annual cap of $150,000.
- Knowing failure to report: $10,000 to $100,000 per payment, up to an annual cap of $1,000,000.
- Failure to respond to an audit: Under the proposed 2026 rulemaking, non-response within 30 days would trigger additional CMPs.
These figures apply per record, not per submission. For organizations with high transaction volumes, even a small percentage of inaccurate or missing records can produce material penalty exposure.
What Is the CMS Open Payments Reporting Deadline for CY2025 Data?
The reporting deadline for CY2025 data was March 31, 2026. Applicable manufacturers and GPOs were required to submit all general payments, research payments, and ownership and investment interests to CMS by that date. The dispute resolution window and final publication timeline follow the submission deadline.
Amending or missing records after submission does not eliminate audit exposure. CMS retains the right to audit any program year's data within the applicable records retention window.
How Long Must Reporting Entities Retain Open Payments Records?
CMS requires applicable manufacturers and GPOs to retain records supporting their Open Payments submissions for five years from the date of submission. This applies to all supporting documentation, not just the submitted data itself. Compliance teams should confirm that document retention policies cover the full five-year window and that records remain retrievable, not just stored.
What Is the Difference Between a CMS Open Payments Audit and an Internal Compliance Audit?
A CMS audit is an external, regulatory review initiated by the agency. It carries legal authority, defined response obligations, and penalty risk. An internal compliance audit is self-initiated and serves as the primary mechanism for identifying and correcting data quality issues before CMS review.
The two processes are complementary. Compliance teams that continuously audit their own expense reports, payment records, and submission data are better positioned to respond to a CMS request quickly and accurately. Internal audits reduce the likelihood that a CMS review will surface material discrepancies.
How Often Should Compliance Teams Audit Expense Reports Before CMS Does?
There is no regulatory minimum for internal audit frequency, but the practical standard is continuous monitoring rather than periodic sampling. CMS audits can cover any record in a submitted dataset. A compliance program that reviews only a sample of expense reports leaves the remaining records unexamined and potentially inaccurate.
Compliance teams with high HCP engagement volumes, multiple field sales teams, or complex speaker program activity carry the greatest exposure from incomplete internal review. Continuous, automated auditing of 100% of expense records is the most defensible posture ahead of a CMS audit.
What Does "Dispute Resolution" Mean in the Open Payments Context, and Does It Affect Audit Risk?
CMS allows covered recipients, including physicians, teaching hospitals, and certain other practitioners, to dispute records submitted about them during a defined dispute resolution window. If a covered recipient disputes a record and the applicable manufacturer cannot substantiate it, that record may require correction or deletion.
Unresolved disputes, or disputes that reveal data quality problems in the original submission, can draw CMS attention. Compliance teams should treat the dispute resolution period as a data quality checkpoint, not just an administrative step.
What Is CMS Proposing to Change About Open Payments Audit Enforcement in 2026?
CMS published proposed rulemaking in 2026 that would formalize the audit response timeline. The key proposal: failing to respond to a CMS audit request within 30 days would constitute a basis for civil monetary penalties. The public comment period closed June 15, 2026.
If finalized, this rule would set a hard deadline that compliance teams must meet regardless of internal resource constraints. Organizations that rely on manual record retrieval or decentralized documentation are most at risk of missing that window.
Who Is Considered a Covered Recipient Under Open Payments?
Covered recipients include physicians and teaching hospitals, the two categories included since the program began, along with six additional practitioner types added starting with Program Year 2021 data collection: physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives.
Reporting entities need a process for identifying which category a given recipient falls into, since payments to non-covered individuals (such as pure researchers with no clinical license, in certain contexts) are handled differently than payments to a listed covered recipient type.
What Is a Program Year in CMS Open Payments Reporting?
A Program Year runs from January 1 through December 31 and represents the calendar year in which a reportable payment or transfer of value took place. Reporting entities collect data throughout the Program Year, submit it to CMS the following spring, and CMS publishes the data later that year once the pre-publication review period closes.
For example, Program Year 2025 covers payments made between January 1 and December 31, 2025. That data was due for submission by March 31, 2026, and published on June 30, 2026. Because CMS can audit any Program Year within the five-year retention window, compliance teams should keep several years of records organized and accessible at once, not just the most recent submission.
What Is the Difference Between General Payments, Research Payments, and Ownership Interests?
CMS collects Open Payments data across three separate categories. General Payments cover transfers of value unrelated to research — consulting fees, meals, travel, and speaker compensation, among others — and represent the category most relevant to day-to-day HCP engagement compliance. Research Payments cover payments made in connection with a research agreement, protocol, or clinical study. Ownership and Investment Interests cover ownership or investment stakes that physicians, or their immediate family members, hold in an applicable manufacturer or GPO.
Each category is reported, reviewed, and published separately, and CMS's combined "total Open Payments" figure for a given Program Year adds all three together. Most audit activity for pharmaceutical and device compliance teams centers on General Payments, since that category carries the highest transaction volume.
How Does the Open Payments Dispute and Correction Process Work?
Covered recipients can review the records submitted about them and, if something looks inaccurate, file a dispute directly in the Open Payments system. Reporting entities are notified and are expected to work directly with the covered recipient to resolve the discrepancy — CMS does not mediate disputes. If the reporting entity updates a record in response, it must resubmit and re-attest the corrected data.
Disputes are meant to be resolved during the annual pre-publication review period. Any dispute still outstanding when that window closes is published as disputed rather than resolved, which is a visible flag to anyone reviewing the public data — including CMS. See CMS's dispute and correction guidance.
What Happens During the Pre-Publication Review Period?
Each year, before CMS publishes Open Payments data, covered recipients have a defined window — typically April 1 through May 15 — to review the records submitted about them and flag anything inaccurate. An extended resolution period runs May 16 through May 30 for outstanding disputes; any records still unresolved by May 30 are published as disputed. Covered recipients can also file disputes on newly submitted data through December 31 of the publication year, outside the standard window.
Compliance teams should treat this window as an early-warning system, not just an administrative step. Unresolved disputes, and the data-quality issues they expose, often mirror the kinds of records CMS is most likely to scrutinize in a later audit. See CMS's review and dispute guidance.
Are Physician Assistants and Nurse Practitioners Covered Recipients?
Yes. Physician assistants and nurse practitioners, along with clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives, became covered recipients starting with Program Year 2021 data collection. Reporting entities that engage these practitioner types must track and report payments to them using the same standards, categories, and documentation applied to physicians and teaching hospitals.
This expansion meaningfully increased the population of providers a typical field team interacts with that now falls under Open Payments reporting, which is one reason continuous, automated expense monitoring has become more important than periodic manual review.
7-Step CMS Open Payments Audit Readiness Checklist
Compliance teams that treat audit readiness as a continuous discipline, rather than an annual scramble, respond faster and with more confidence when a CMS request arrives. These are the practices qordata recommends to life sciences compliance teams preparing for a CMS Open Payments audit.
Centralize Your Audit Trail Documentation
Keep contracts, expense receipts, FMV assessments, attendance records, and approval workflows in one system so every submitted record can be traced back to its source document within minutes, not days.
Reconcile Continuously, Not Just Before Submission
Match source-system data (expense platforms, CRM, speaker program logs) against what was actually submitted to CMS throughout the Program Year, not only in the weeks before the reporting deadline.
Give Low-Dollar, High-Volume Categories the Same Scrutiny as High-Dollar Ones
Food and beverage records make up the large majority of most reporting entities' transaction volume. A high error rate in a low-dollar category can still represent significant aggregate exposure.
Build a 30-Day Audit Response Protocol
Document who owns each step of an audit response — records retrieval, legal review, submission — so your organization can meet the response window proposed under CMS's 2026 rulemaking without scrambling to assemble a team.
Treat the Pre-Publication Review Period as a Data-Quality Checkpoint
Use the annual dispute window (April 1 through May 30) to catch and correct errors before they become part of the public record, and analyze disputed records for patterns that reveal upstream process gaps.
Maintain the Full Five-Year Retention Window
Confirm that document retention policies and systems keep supporting records retrievable, not just archived, for the entire period CMS can request them.
Audit 100% of Records, Continuously
Replace periodic sampling with continuous, automated review of expense and payment records so no category — and no Program Year — is left unexamined heading into an audit.
CMS Audit vs. Internal Audit at a Glance
The two review types work together, but they differ in who initiates them, what authority backs them, and what happens when they turn up a problem.
| Aspect | CMS Open Payments Audit | Internal Compliance Audit |
|---|---|---|
| Who initiates it | CMS, at any time | The reporting entity itself |
| Legal authority | 42 C.F.R. § 403.912(e)(2) | None — a voluntary compliance practice |
| Primary purpose | Verify accuracy of submitted Sunshine Act data | Identify and correct data issues before CMS review |
| Response obligation | Defined response window (30 days proposed) | No external deadline |
| Consequence of findings | Civil monetary penalties for inaccurate or missing records | Internal corrective action; reduced future audit risk |
| Recommended frequency | Can occur at any time, for any Program Year within the retention window | Continuous, ideally covering 100% of records |
2025 Open Payments Data at a Glance
On June 30, 2026, CMS published the Program Year 2025 Open Payments data: more than 16.13 million individual General Payments records, totaling $3.92 billion, from 1,854 reporting manufacturers and GPOs. Where the money goes tells two very different stories, and both matter for audit readiness.
Source: qordata analysis of CMS Program Year 2025 Open Payments data. Read the full breakdown in 2025 Open Payments Data: Key Facts.
Royalty or License payments were the single largest General Payments category by dollar value — 30.7% of all General Payments dollars — but came from only 15,496 records, an average of roughly $77,700 per record. Food and Beverage told the opposite story: 91.5% of all records but only 11.3% of dollars. For audit purposes, that split matters: a compliance program built only around dollar thresholds will miss the category most likely to contain volume-driven errors, which is exactly the kind of gap a CMS audit is designed to find.
Official Resources
Open Payments Program Homepage
CMS's central hub for Open Payments program overview, data publication timelines, and resources for reporting entities and covered recipients: cms.gov/priorities/key-initiatives/open-payments
CMS Open Payments Frequently Asked Questions
CMS maintains an official FAQ page covering reporting requirements, submission procedures, and program guidance: cms.gov/priorities/key-initiatives/open-payments/frequently-asked-questions
Explore the Public Open Payments Data
CMS's public data platform, where anyone can search, filter, and download Open Payments records by reporting entity, covered recipient, or Program Year: openpaymentsdata.cms.gov
Dispute and Correction Guidance
CMS's guidance for reporting entities on resolving disputed records and submitting corrections during and after the pre-publication review period: cms.gov/openpayments/program-participants/reporting-entities/dispute-and-correction
Regulatory Authority
42 C.F.R. § 403.912(e)(2) establishes CMS's authority to audit applicable manufacturers and GPOs and to require production of supporting records.
2026 Proposed Rulemaking
CMS's proposed enforcement mechanism for audit non-response (30-day response window, CMP exposure) was open for public comment through June 15, 2026. Compliance teams should monitor the final rule publication for effective dates and implementation requirements.
Free Compliance Resources
CMS Open Payments Audits: Why and How to Be Audit Ready
A practical guide to understanding CMS audit triggers, building a defensible audit trail, and preparing your compliance program before a request arrives.
Download the WhitepaperPreparing for a CMS Open Payments Audit
Watch qordata's on-demand webinar for a walkthrough of audit readiness best practices, common pitfalls, and how leading compliance teams stay prepared.
Watch the WebinarHow qordata Supports Open Payments Audit Readiness
qordata's Expense Monitoring and Auditing solution audits 100% of expense records using AI-driven review rather than sampling, so compliance teams have a complete, defensible audit trail before CMS requests one. Compliance Central centralizes documentation, surfaces potential risks in real time, and maintains the record linkage that CMS audit requests require.
- 100% Expense Record Review — AI-driven review of every expense record, not a statistical sample, so nothing enters your Open Payments submission unverified.
- Centralized Audit Trail — Compliance Central links every submitted record back to its contract, receipt, or approval, ready to produce if CMS requests it.
- Real-Time Risk Surfacing — Potential FMV, duplicate, or documentation gaps are flagged as they occur, not discovered during Program Year close-out.
- Dispute & Correction Support — Track disputed records through the pre-publication review window without losing visibility into resolution status.
To see how Compliance Central supports your audit preparation, contact the team at sales@qordata.com or schedule a demo at qordata.com.
FAQ Summary
What is a CMS Open Payments audit?
A formal review under 42 C.F.R. § 403.912(e)(2) in which CMS requests records and documentation from applicable manufacturers or GPOs to verify the accuracy of their Sunshine Act submissions. Non-response or inaccurate records can result in civil monetary penalties.
What triggers a CMS Open Payments audit?
CMS can initiate an audit at any time. Common triggers include data discrepancies, disputed records, late submissions, and prior enforcement history. CMS issued 9 CMPs in FY2022, up from 3 in FY2021.
What records does CMS request during an Open Payments audit?
CMS typically requests contracts, expense reports, receipts, FMV assessments, attendance records, approval workflows, and reconciliation files that connect submitted records to source documentation.
What are the penalties for Open Payments non-compliance?
Penalties range from $1,000 to $10,000 per unreported payment (up to $150,000 annually) and from $10,000 to $100,000 per knowing failure to report (up to $1,000,000 annually). Proposed 2026 rulemaking would add CMP exposure for failing to respond to an audit request within 30 days.
How long must reporting entities keep Open Payments records?
CMS requires a five-year retention period from the date of submission for all records supporting Open Payments data.
What is the difference between an internal compliance audit and a CMS audit?
A CMS audit is externally initiated, carries legal authority, and has defined response obligations. An internal audit is self-initiated and serves as the primary mechanism for identifying and correcting data quality issues before CMS review.
How does continuous expense monitoring reduce Open Payments audit risk?
Continuous monitoring of 100% of expense records ensures that inaccurate or unsupported records are identified and corrected before submission. This produces a more accurate dataset and a more complete audit trail, both of which reduce exposure during a CMS review.
Who is considered a covered recipient under Open Payments?
Physicians and teaching hospitals, plus six additional practitioner types added starting with Program Year 2021: physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives.
What is a Program Year in Open Payments reporting?
The calendar year (January 1 through December 31) in which a reportable payment occurred. Data is submitted the following spring and published mid-year, and CMS can audit any Program Year within the five-year retention window.
What's the difference between General Payments, Research Payments, and Ownership Interests?
General Payments cover non-research transfers of value like consulting fees and meals; Research Payments cover research-agreement payments; Ownership and Investment Interests cover physician ownership stakes in a manufacturer or GPO. Each is reported and published separately.
How does the Open Payments dispute and correction process work?
Covered recipients dispute records directly with the reporting entity during the pre-publication review period; CMS does not mediate. Unresolved disputes by the close of the extended window are published as disputed.
What happens during the pre-publication review period?
Covered recipients review submitted records, typically from April 1 through May 15 (extended through May 30), and can flag disputes before CMS publishes the data. New disputes can be filed through December 31.
Are physician assistants and nurse practitioners covered recipients?
Yes, since Program Year 2021, along with clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants, and certified nurse-midwives.