Every network pharmacy signs a yearly form for its Pharmacy Benefit Manager (PBM) certifying that it completed fraud, waste and abuse (FWA) training, screened staff against the federal exclusion lists, keeps its licenses current, and maintains a written compliance policy. A one-page signature can carry exposure reaching a PBM audit, a termination notice, or a False Claims Act theory, tracing back to the gap between what a pharmacy certified and what its records show.

What the Annual Attestation Certifies

The annual attestation comes from the network agreement between a pharmacy and its PBM, not from a government form, and wording differs by PBM and credentialing vendor. The certifications fall into a consistent set of categories: completed FWA and general compliance training, exclusion-list screening, current professional licenses, and a written compliance policy on file. The training piece traces back to 42 C.F.R. Section 423.504, requiring Medicare Part D plan sponsors to maintain a compliance program reaching their contracted pharmacies. CMS eliminated the regulation's specific training mandate for first-tier, downstream and related entities, which include network pharmacies, in its contract year 2019 final rule, so no federal rule currently requires a pharmacy to complete FWA training on a set schedule. A PBM can still require its own training and attestation as a condition of network participation, which is why this form belongs to the contract, not CMS. The specific form in front of you controls, not a prior year's categories or a form built for a different PBM audit relationship.

The Records That Have to Exist Behind Each Statement

An attestation is only as reliable as the records behind it. Training logs naming each employee and a completion date back up a certification that staff finished FWA training, not a manager's recollection that training gets done every year. Exclusion screening needs the actual search results on file, not an assumption that no employee has ever appeared on a list, and the written compliance policy itself has to be current and producible, not a document drafted once at opening and never revisited. Signing without pulling these records first certifies a belief, not a fact the pharmacy has checked.

Who Should Sign

The attestation calls for a single signature, from the pharmacist-in-charge, the owner, or a designated compliance officer, depending on how the network agreement defines that role. The certification reaches further than the signer's personal knowledge: it speaks for the pharmacy's training records, exclusion screening, and policy file as a whole. The signer should be positioned to confirm the underlying records actually exist, not simply be whoever opened the portal when the form arrived. Verify the training logs and screening results before signing, not after a PBM asks to see the file behind it.

How a Missed or Inaccurate Attestation Surfaces Later

A missed or inaccurate attestation surfaces later than the moment it was signed, inside a PBM audit document request, a network termination notice, or a government inquiry with its own trigger. Once a PBM has the signed attestation, the real question is whether the certification matched the pharmacy's actual records on the date it signed, not whether the pharmacy trained its staff in the abstract, a distinction that can matter to a recoupment or an audit appeal over the same claims period. Because network participation depends on compliance with the agreement, an inaccurate attestation can also support a False Claims Act theory under a false-certification framing, beyond a straightforward audit finding or termination.

A signed attestation stands on its own. The earlier certification remains what the pharmacy actually signed, regardless of any fix made to the underlying records afterward.

Where Attestation Gaps Intersect Other PBM Exposure

An attestation gap can surface alongside other PBM exposure in the same file. A multi-location group must confirm every store's records are current, not just the location signing for the group; see Multi-Location Pharmacy Groups: Audit Exposure Across Stores. A pharmacy already in a Navitus review faces the same documentation standard on its file; see Navitus Audits: What Pharmacies Should Know. And a pharmacy defending an NDC mismatch finding should expect the same check; see NDC Mismatch Findings in a PBM Audit.

Why Early Legal Counsel Is Critical

It is critical for pharmacies to involve experienced healthcare defense counsel before signing an annual PBM attestation, and immediately after receiving a PBM audit notice, a termination notice, or any inquiry referencing a prior attestation. Early legal review can confirm what the specific form asks, identify gaps between the certification and the pharmacy's records while there is time to close them, and help the pharmacy respond without compounding an earlier statement. Addressing a gap before signing is a materially different position than explaining it after the signed form is already in a PBM's file.

How Health Law Alliance Can Help

Health Law Alliance's attorneys have overseen 2,000+ audits and handled 5,000+ matters, with 25+ years of experience.

If your pharmacy is preparing this year's PBM attestation, or has already received a PBM audit, termination notice, or other inquiry that references a prior year's certification, contact Health Law Alliance's PBM audit defense attorneys for a free, confidential consultation.