In This Analysis
- Errors vs. Misconduct: Why the Distinction Matters for ECCP
- Manufacturer Name Normalization: The Error That's Invisible Until It Isn't
- Royalty and Promotional Spend, Conflated
- Cross-Manufacturer Aggregation Gaps
- Name of Study Mismatches in Research Payment Data
- Zero-Dollar and Negative-Amount Anomalies
- Late or Unresolved Disputes During Pre-Publication Review
- Remediation: Aligning Your Correction Process With ECCP
Most CMS Open Payments discrepancies aren't the product of concealment. They're the product of a data-handling error that nobody caught before submission, the kind that's easy to make at scale and expensive to unwind after the fact. Even qordata's own three-year analysis of the CMS public-use files, built with a chunked, resumable processing pipeline specifically to avoid this class of mistake, hit one: the file initially staged as the 2025 General Payments extract was actually the 2025 Research Payments file, a 252-column layout mistaken for a 91-column one. It was caught and corrected before publication, but it's a useful reminder that data-handling errors happen even to processes built to prevent them. The question is whether yours are caught before CMS finds them.
For the full audit process and CMS's legal authority to request supporting records, see qordata's CMS Open Payments Audit: Resources & FAQs. This piece focuses on the specific data-quality errors that generate discrepancy notices in the first place.
Errors vs. Misconduct: Why the Distinction Matters for ECCP
DOJ's Evaluation of Corporate Compliance Programs (ECCP) guidance asks three questions of any compliance function under review: is the program well designed, is it being applied earnestly and in good faith, and does it actually work in practice. A reporting error doesn't answer any of those questions on its own. What answers them is what happens next: whether the error was systemic or isolated, whether your process caught it before or after CMS did, and whether the fix addressed the pattern or just the one flagged record. The five error types below are the ones most likely to generate a CMS discrepancy notice, and each one maps to a different piece of that ECCP test.
Manufacturer Name Normalization: The Error That's Invisible Until It Isn't
CMS's own data-quality process has to normalize manufacturer names to merge case and punctuation variants, "ABBVIE INC." and "AbbVie Inc." resolving to the same entity, before any meaningful trend analysis is possible. If CMS's own published files need that normalization, a reporting entity submitting under multiple subsidiary names, legal-entity variants, or historical naming conventions carries the same risk internally. An unreconciled name variant doesn't just create a cosmetic inconsistency; it can understate a manufacturer's true aggregate spend in any benchmarking exercise, including CMS's own, and create exactly the kind of discrepancy a covered recipient notices when their own records don't match what a fragmented submission shows.
Royalty and Promotional Spend, Conflated
Royalty and license payments are governed by a different economic logic than a consulting fee or a speaker honorarium: they compensate licensed intellectual property, not a service rendered. Reported as one blended total alongside promotional spend, they can distort a manufacturer's own benchmarking, sometimes dramatically.
One manufacturer ranks first in total three-year General Payment spend at $1.085 billion, almost entirely royalty income; excluding royalties, its promotional spend is $0.9 million, and it falls to last among the same top-10 pool. A different manufacturer leads true promotional, consulting, and speaker spend once royalties are excluded, at $473.3 million. Reporting and certifying spend in a single blended figure, rather than in the three views CMS's own data structure supports, including royalties, excluding royalties, and royalties only, is one of the more common ways an accurate filing ends up looking wrong to anyone benchmarking it externally.
Cross-Manufacturer Aggregation Gaps
No single manufacturer's submission shows what a recipient earns across the industry. In 2025, 162,679 recipients were paid by 10 or more distinct manufacturers, and 12,458 by 25 or more. That's not itself an error; it's a structural feature of how Open Payments works. The error occurs when a reporting entity's own internal fair-market-value review treats a recipient's cumulative exposure as bounded by what that one company paid, missing that the same physician's industry-wide total may sit well inside a top-tier concentration band once every manufacturer's submission is combined. CMS, and any journalist or plaintiff's attorney with access to the public data, can see that aggregate picture even when an individual reporting entity's own systems can't.
Name of Study Mismatches in Research Payment Data
Research Payment records carry a Name of Study field and, where applicable, a ClinicalTrials.gov identifier, so CMS can confirm a reported payment ties back to a real, publicly registered study. An internal shorthand title, a drifted name that no longer matches the official ClinicalTrials.gov listing, or a blank identifier field breaks that reconciliation, and CMS has been actively reaching out to reporting entities to correct these mismatches, including on prior Program Years' data, not only the current cycle. Because CMS can audit any Program Year within the five-year retention window, a mismatch flagged on a recent submission often prompts a look back at older Research Payment records for the same naming habit.
Zero-Dollar and Negative-Amount Anomalies
Payment-amount parsing sounds like the kind of thing that either works or doesn't, but CMS's own PY2023-2025 files show the edge cases worth checking for in your own submission pipeline: a small number of zero-dollar rows in the earliest year of the analysis, and no negative amounts in any year once the data was fully validated. A zero-dollar or negative record in your own staged submission is rarely intentional; it's usually a currency-conversion error, a voided transaction that wasn't fully removed from the export, or a rounding artifact from an upstream system. None of these are hard to catch with a validation pass before submission. All of them are conspicuous, and slow to explain, once CMS or a covered recipient spots one in the published data instead.
Late or Unresolved Disputes During Pre-Publication Review
Every dispute a covered recipient files during the annual pre-publication review window, typically April 1 through May 15, extended through May 30, is a data-quality signal arriving with the recipient's own explanation attached. CMS does not mediate these disputes; the reporting entity is expected to resolve them directly. A dispute still outstanding when the window closes publishes as disputed, a visible flag to anyone reviewing the public data, including CMS itself. Treating the dispute window as a compliance-calendar afterthought, rather than an early-warning system, converts a fixable data-quality issue into a permanent, visible mark on the published record.
Remediation: Aligning Your Correction Process With ECCP
Fixing the flagged record is the minimum bar. ECCP's "does it work in practice" test looks for something more: whether the correction process finds and fixes the same error pattern elsewhere in your data, current and prior Program Years, rather than closing the single ticket CMS opened. When CMS flags a specific Name of Study mismatch or a discrepant record, the defensible response requests the exact Record IDs and Program Year at issue, corrects those first, and then reviews every comparable entry on file for the same pattern, whether or not CMS asked for that broader review.
Expense Monitoring & Auditing (EMA) applies continuous, AI-driven review to 100% of expense and payment records rather than a sample, so manufacturer-name variants, royalty misclassification, and other data-quality errors surface before submission instead of in a discrepancy notice. Risk Assessment & Management (RAM) structures the program-design side of that response against OIG-recognized, COSO- and ISO 31000-aligned risk frameworks, which is exactly the kind of documented, defensible design ECCP's first question is asking about. Compliance Central keeps every corrected record linked back to its source documentation, so a remediation effort produces an audit trail of its own.