A Unified Program Integrity Contractor (UPIC) benefit integrity review increasingly reaches past paper copies of a chart and asks for the electronic health record (EHR) system itself: read-only remote access, the audit trail for a specific patient's chart, or the metadata showing when an entry was created, edited, or backdated. An open grant of system access can hand a UPIC far more than the claims under review, and how a practice responds shapes what the contractor finds and how it characterizes what it finds.
Scope Negotiation for EHR Access Requests
A provider or supplier that orders, certifies, refers, or prescribes Part A or Part B services must maintain the related documentation and provide access to it under 42 CFR 424.516(f), in the manner CMS or its contractor requests. CMS's own guidance draws a line between sufficient and deficient access: sufficient access is documentation specific to the dates of service, patients, or claims actually named in the request, while deficient access includes producing records the contractor did not ask for. A UPIC request for standing, read-only access to the whole EHR platform reaches past named patients and named dates of service in the same way, and a practice can hold the request to what it actually covers before granting any access.
Producing a Defensible Export Instead of Open Access
A login credential handed to a UPIC reviewer, or to a contractor's outside consultant, keeps working after the specific review closes unless someone remembers to revoke it, and it exposes every patient in the system, not only the ones under review. The alternative most practices can offer instead is a defensible export: the complete record for the named patients and dates, produced with the underlying audit trail for those specific charts attached, rather than standing credentials to the platform itself. That export is also where a practice's own documentation, comparable to the authorship record a signature log keeps for a dispensed prescription, becomes part of the answer rather than an afterthought produced only if asked.
Late Entries, Addenda, and the Audit Trail
When UPIC staff reviews documentation for benefit integrity purposes, its focus differs from a routine coverage determination. CMS's Medicare Program Integrity Manual, Chapter 3 directs UPIC reviewers to look for evidence of alteration, including obliterated sections, missing or inserted pages, white-out, and excessive late entries. The same chapter also addresses the routine case, where documentation is sometimes properly amended, corrected, or entered after the service was rendered, and when that happens, the date and author of the change should be identifiable and the addendum clearly and permanently denoted. An audit trail and its metadata are what let a reviewer tell the two situations apart. When a UPIC's findings cross the criminal-referral threshold, the contractor refers the matter to HHS-OIG, the DOJ Civil Division, or U.S. Attorneys, and that referral is how a records request can turn into the kind of federal inquiry that ends with a target letter.
Records Stranded in a Legacy System After an EHR Migration
A practice that changed EHR platforms since the dates of service under review often finds that the original audit trail did not travel with the record. The new system may show only a migration date, or display entries in a format that no longer matches how they looked when made. None of that relieves the obligation to maintain and produce the underlying documentation for the period a UPIC has named. Where the legacy system is still reachable, even in a read-only archive, its own logs are usually the more complete answer than whatever the current platform shows for a record it inherited rather than created.
A UPIC reviewer cannot tell an audit trail's silence from a provider's alteration. That distinction has to come from what the practice produces.
Why Early Legal Counsel Is Critical
It is critical that providers promptly retain experienced healthcare defense counsel before responding to a UPIC's request for EHR access, audit trail data, or metadata. Early legal intervention can shape the scope of what is produced, ensure a defensible export is offered in place of open system access, and prevent an innocent late entry from being read as an alteration for want of context. Delaying representation until after access has already been granted can close off options that were available only before the contractor was in the system.
How Health Law Alliance Can Help
Health Law Alliance has overseen 2,000+ audits, including UPIC benefit integrity reviews. If your practice has received a request for system access, an audit trail, or chart metadata, contact Health Law Alliance's UPIC audit defense attorneys for a free, confidential consultation before you respond.





