Medicare Fee-for-Service medical reviews, overseen by the Centers for Medicare and Medicaid Services (CMS), are conducted by several distinct contractor types. Three of the most frequently encountered by home health and hospice agencies are Medicare Administrative Contractors (MACs), Recovery Audit Contractors (RACs), and Unified Program Integrity Contractors (UPICs). Each is authorized to issue an Additional Documentation Request (ADR), but the authority, purpose, and consequence of a request differ substantially by contractor type (CMS Additional Documentation Request). A provider who does not know which contractor issued a request, and why, cannot accurately assess the stakes of the review or organize an appropriate response.
The distinction matters because the three contractor types operate under different statutory authority, different review triggers, and different consequences for an unfavorable finding. A routine MAC data-driven probe and a UPIC fraud investigation can arrive as superficially similar-looking letters requesting the same documentation, but they represent fundamentally different levels of regulatory exposure.
This guide covers what each contractor type does, how they are triggered, how they differ in lookback period and financial mechanism, and how a finding from one contractor can escalate into review by another.
For the broader audit landscape and PEPPER-based risk monitoring, refer to the Home Health Medicare Audit Defense and Compliance Guide. For ADR response mechanics specifically, refer to the How to Prepare for and Respond to a Medicare ADR guide.
Key Takeaways
- MACs, RACs, and UPICs are all authorized to issue an Additional Documentation Request, but they operate under different authority and carry different consequences. MAC and RAC reviews are 45-day response windows; UPIC reviews compress to 30 days.
- RACs are paid on a contingency fee basis, a percentage of the improper payment recovered, negotiated at the time of contract award. This financial structure is unique to RACs among the three contractor types and is a key reason RAC reviews often apply statistical extrapolation.
- RAC review is limited to a 3-year lookback period from the date of service. UPIC and MAC reviews are not bound by this same limit, meaning documentation retention planned only around the RAC window leaves an agency exposed to older claims under other contractor types.
- CMS recalculates a provider's RAC Additional Documentation Request limit after every three 45-day ADR cycles, based on the provider's calculated Denial Rate, producing an Adjusted ADR Limit that can increase review volume for providers with high denial rates.
- UPICs operate in five geographical jurisdictions and perform fraud, waste, and abuse detection across Medicare Parts A, B, Durable Medical Equipment, Home Health and Hospice, and Medicaid. UPICs replaced the former Zone Program Integrity Contractor (ZPIC), Program Safeguard Contractor, and Medicaid Integrity Contractor functions.
- Medicare Program Integrity Manual guidance treats MACs, RACs, and UPICs as parallel review authorities rather than a single hierarchy. A provider can be subject to review from more than one of these contractors on overlapping claims or time periods at the same time.
The Three Medicare Review Contractor Types
Medicare Program Integrity Manual guidance groups MACs, RACs, and UPICs together for many procedural purposes, including data analysis and provider suppression rules, but each contractor type has a distinct scope and mandate.
Medicare Administrative Contractors (MACs)
MACs process and pay Medicare Fee-for-Service claims within their assigned jurisdiction and conduct medical review as part of that function, including the Targeted Probe and Educate (TPE) program. MACs initiate provider-specific prepayment or post-payment review based on their own data analysis, or upon referral from a RAC, the CERT program, a UPIC, the Office of Inspector General (OIG), or the Government Accountability Office (GAO) when directed by CMS (CMS Medicare Program Integrity Manual, Chapter 3).
MACs target providers with historically high claim denial rates or billing practices that vary from peer benchmarks. A MAC ADR is typically the entry point into the Medicare review system for most providers, and TPE specifically is structured around education: agencies with acceptable improvement after review are released from that specific review topic, while agencies with continued high denial rates face escalation.
Recovery Audit Contractors (RACs)
RACs conduct post-payment review to identify improper payments, both overpayments and underpayments, on claims already processed and paid. RACs are paid on a contingency fee basis under Section 1893(h) of the Social Security Act, a percentage of the improper payment recovered from or reimbursed to providers, negotiated by each RAC at the time of contract award (CMS Recovery Audit Program). The RAC must return the contingency fee if the determination is overturned at any level of appeal.
The RAC ADR Limit Mechanism
CMS limits how many additional documentation requests a RAC may send a provider at one time. This limit is not static: after every three 45-day ADR cycles, CMS calculates or recalculates the provider's Denial Rate and uses it to set an Adjusted ADR Limit (CMS RAC ADR Limits). A provider with a rising denial rate faces an increasing RAC ADR volume as a direct, mechanical consequence, independent of any single claim's outcome.
The 3-Year Lookback
RAC review is limited to claims paid within the preceding 3 years, consistent with CMS's claims reopening policy. This limit is specific to RACs. Agencies should not treat the RAC 3-year window as a general documentation retention standard, since UPIC and MAC reviews are not bound by the same limit and can reach older claims under different statutory authority.
Red Road Insight: The contingency fee structure is the single most important fact to understand about RAC review. A RAC has a direct financial incentive to identify improper payments, and it must return its fee if overturned on appeal. This does not make RAC findings less legitimate, but it explains why RAC reviews consistently apply statistical extrapolation on complex reviews, since extrapolation converts a sample finding into a much larger recovery demand.
Escalation Level: Short-term : Agencies receiving a RAC ADR should confirm the specific claims under review fall within the 3-year lookback window and should track their own Denial Rate trend, since a rising rate directly increases future RAC ADR volume under the Adjusted ADR Limit mechanism.
Unified Program Integrity Contractors (UPICs)
UPICs perform fraud, waste, and abuse detection, deterrence, and prevention activities across Medicare Parts A, B, Durable Medical Equipment, Home Health and Hospice, Medicaid, and the Medicare-Medicaid data match program. UPICs operate in five geographical jurisdictions nationwide and consolidated functions previously performed by the Zone Program Integrity Contractor (ZPIC), Program Safeguard Contractor (PSC), and Medicaid Integrity Contractor (MIC) (CMS Review Contractor Directory).
A UPIC investigation is a benefit integrity investigation aimed at detecting suspected fraud, waste, or abuse, with findings that can be referred to law enforcement for civil or criminal investigation, not primarily a payment accuracy exercise. The 30-day ADR response window, shorter than the 45 days given to MAC and RAC requests, reflects this elevated regulatory posture.
Providers researching a request under the former ZPIC name should understand that ZPIC functions were consolidated into the UPIC program; a request referencing ZPIC authority today is functionally a UPIC matter.
Red Road Insight: The signal that distinguishes a UPIC request from a routine MAC or RAC review is rarely stated explicitly in the letter itself. It is the scope: a UPIC investigation typically spans multiple claims, patients, or time periods at once, rather than the single-claim or single-episode focus of a routine MAC probe. Providers should read the scope of a documentation request as closely as the deadline.
How a Finding From One Contractor Escalates to Another
The three contractor types are not fully independent of one another. A finding from one can trigger review by another, and understanding this escalation pathway helps a provider recognize when a routine matter is developing into something more serious.
MAC to RAC or UPIC Referral
A MAC that identifies a pattern of high denial rates through TPE can refer a provider for further action, which may include RAC review or UPIC referral, depending on whether the pattern reflects a payment accuracy issue or a potential integrity concern.
RAC Findings and Broader Review
A RAC overpayment determination that reflects a systemic pattern rather than an isolated billing error can prompt a broader program integrity referral. Because RACs operate on a claim-by-claim, post-payment basis, a pattern across multiple RAC findings is a more likely trigger for escalation than a single overturned claim.
UPIC to OIG or DOJ
Where a UPIC investigation develops evidence indicating fraud rather than an unintentional payment error, the matter can move from an administrative documentation review to a referral to the Office of Inspector General (OIG) or the Department of Justice (DOJ) for civil or criminal investigation. This is the most serious escalation pathway among the three contractor types, and it changes the nature of the matter from a billing dispute to a legal one, typically warranting counsel with health care fraud defense experience rather than a standard documentation response.
Escalation Level: Immediate : A provider who has received requests from more than one contractor type on overlapping claims or time periods, or who receives a request referencing findings from a prior review, should treat this as a signal that a broader pattern is already under CMS review and should seek to understand the full scope before responding.
Responding to a Request Once You Know the Contractor Type
Identifying which contractor issued a request should shape how the response is prepared, even though the underlying documentation requirements, physician certification, plan of care, visit notes, coding support, are largely consistent across contractor types.
- Confirm the issuing contractor from the letterhead and any reference numbers, not from assumption based on past experience with a different contractor.
- Calculate the response deadline correctly: 45 calendar days for MAC or RAC requests; 30 calendar days for UPIC requests, from the date printed on the letter.
- For a UPIC request, treat the review as a program integrity matter from the outset rather than a routine documentation exercise, given the shorter deadline and broader scope UPIC investigations typically carry.
- For a RAC request, confirm the claims under review fall within the 3-year lookback period and note whether the request references automated or complex review, since complex review requires the documentation submission this guide addresses.
Why Identifying the Contractor Correctly Matters Beyond the Deadline
The response deadline is the most time-sensitive detail, but it is not the only reason contractor identification matters. A MAC probe is typically resolved through the standard appeals process if the determination is unfavorable. A RAC finding carries the added dimension of potential statistical extrapolation on complex reviews, meaning a sample of claims can produce a repayment demand far larger than the sampled dollar amount. A UPIC investigation carries the possibility of referral beyond the administrative process entirely, to civil or criminal enforcement, which changes what kind of response, and what kind of counsel, is appropriate from the outset.
Agencies that route every documentation request through the same internal workflow, regardless of contractor type, risk under-responding to a UPIC matter that requires a fundamentally more serious posture, or over-escalating a routine MAC probe in a way that consumes resources better directed elsewhere. A brief triage step at intake, confirming the issuing contractor before the response is drafted, is a small process addition that prevents both outcomes.
Red Road Insight: The most common mistake we see is treating every documentation request as procedurally identical because the cover letter format looks similar. A MAC probe, a RAC complex review, and a UPIC investigation each call for a different level of internal escalation, and identifying the contractor correctly in the first hour after receipt is what determines whether that escalation happens on time.
A complete framework for building the response package itself, organized by document type and review sequence, is in the How to Prepare for and Respond to a Medicare ADR guide.
How External Compliance Support Addresses Multi-Contractor Audit Risk
For home health and hospice agencies, the operational challenge is not typically understanding any single contractor's requirements in isolation. It is maintaining documentation practices robust enough to withstand review from any of the three contractor types, at any point relative to the date of service, without having to reconstruct a defense from incomplete records after a request arrives.
A physician certification, a face-to-face encounter note, and visit notes supporting medical necessity do not need to be written differently depending on whether a MAC, a RAC, or a UPIC eventually requests them. The documentation standard is the same. What differs is how quickly an agency can locate, organize, and submit that documentation once a request arrives, and how confidently it can demonstrate the record was contemporaneous rather than reconstructed after the fact.
An external clinical documentation review function that validates documentation at the point of care, rather than only in response to a specific request, produces records that are defensible regardless of which contractor initiates a review or how far back the lookback period extends.
The Bottom Line
MACs, RACs, and UPICs each operate under different authority, different financial incentives, and different consequences for an unfavorable finding, even though the documentation they request often looks similar on the surface. A RAC's contingency fee structure and 3-year lookback, a UPIC's fraud-focused mandate and 30-day deadline, and a MAC's routine claims processing role each require a distinct read on what level of risk a given request represents.
Agencies that maintain documentation defensible against any of the three contractor types carry meaningfully less exposure as CMS shifts review activity across these programs over time, more than agencies building compliance practices around a single audit type they've experienced before.
How Red Road Supports Multi-Contractor Audit Readiness
Red Road's clinical documentation review service validates home health and hospice documentation against current CMS coverage and coding standards before billing, producing records that are defensible under MAC, RAC, or UPIC review regardless of when a request arrives. Registered Nurse clinical reviewers confirm that physician certification, face-to-face documentation, and visit notes support the coded claim, reducing the gap between what was billed and what a reviewer can independently verify.
When a documentation request does arrive, Red Road's team helps assemble the response package against the specific contractor's request, tracks response deadlines by contractor type, and reports findings by contractor and denial category so agencies can identify whether activity from a specific contractor reflects an isolated review or a broader pattern requiring structural correction.
Regulatory Sources
- CMS Additional Documentation Request Overview
- CMS Medicare Program Integrity Manual, Chapter 3 — Contractor Review Procedures
- Section 1893(h), Social Security Act — RAC Contingency Fee Structure
- CMS Recovery Audit Program — RAC Authority and Scope
- CMS RAC Additional Documentation Request Limits — Adjusted ADR Limit Methodology
- CMS Medicare Review Contractor Directory — UPIC Jurisdictions and Consolidated Authority
.webp)




