US · guidance
CMS Pub. 100-16, ch. 5, § 30.1.1
HEDIS® Compliance Audit Requirements
Because of the critical importance of ensuring accurate data, CMS continues to require an
external audit of the HEDIS® measures before public reporting. MAOs and §1876 cost
contracts are responsible for submitting audited data, according to the audit methodology
outlined in Volume 5: HEDIS® Compliance Audit: Standards, Policies and Procedures.
CMS requires each MAO and §1876 cost contract to contract with an NCQA licensed
organization for an NCQA HEDIS® Compliance Audit. The licensed audit firms are
listed on NCQA’s Web site at http://www.ncqa.org/. CMS requires that the licensed
organizations follow the established standards, policies and procedures in NCQA’s
HEDIS®, Volume 5. All contracts must ensure that the site visit audit team is led by a
NCQA Certified HEDIS® Compliance Auditor. In addition, the plan’s chief executive
officer, president, or other authorized person, such as the medical director, will be
required to provide an electronic attestation to the validity of the plan-generated data in
IDSS.
History
(Rev. 117, Issued: 08-08-14, Effective: 08-08-14, Implementation: 08-08-14)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
e7f6821e21e28970881ae6aaab71f9d2cd34e53bf3d36b501f89353c6e2b4698
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.