Most 340B programs can produce a binder in three weeks. Very few can explain what their controls were doing in the eleven months before the letter arrived.

That gap is the whole subject of this article, and it is where 340B audit readiness either exists or does not. Everything below is drawn from an operator running it across dozens of covered entities.

What is 340B audit readiness?

340B audit readiness is the condition of a covered entity’s control systems during an ordinary month when no audit is expected. It is measured by whether eligibility, diversion controls, duplicate discount controls, and corrective actions are being tested continuously, not by how quickly documents can be assembled after an HRSA notice arrives.

That definition matters because it separates two activities most teams treat as one.

The distinction is not academic. Audit preparation starts when the letter arrives. It is collecting files, pulling reports, and getting people ready for audit day. Audit readiness is what the operation was already doing.

Dr. Darra M. Edwards, who oversees 340B compliance across covered entities in a health system spanning 15 states and more than 50 hospitals, put the distinction into one sentence on the latest episode of 340B Pulse: if the audit letter request changes the way you are practicing, then more than likely you are not audit ready.

Her standard for a program that has it right is equally short. “You’re not trying to get ready; you are ready.”

How do you test whether your program is actually ready?

Run the letter test. Imagine the HRSA notice arriving tomorrow and ask what would change in your team’s daily behaviour. If the honest answer is that meetings get scheduled, spreadsheets get rebuilt, and documentation gets chased, the program has audit preparation but not 340B audit readiness.

If nothing changes except that you begin collecting evidence that already exists, the systems are doing their job.

There is a second test that surfaces the problem earlier. Ask how often the team is caught unawares.

“If you’re constantly finding out various issues or various exceptions that come up in the data that you find are not being evaluated routinely,” Edwards said, “but several months down the line, you find that, oh, this has been happening for the past several months,” that is the signal. A program that discovers a three-month-old pattern is not monitoring; it is reacting, and 340B audit readiness cannot survive on reaction.

Which controls belong in a monthly 340B operating review?

The trap in compliance work is that everything feels equally urgent. If every report, every transaction, every site, and every exception is treated the same, a team can spend the entire month reviewing data and end it no more confident than it started.

Strong 340B audit readiness starts by ranking risk, then designing the review around the top of that list.

ControlCadenceWhat it answers
Modifier application on processed claimsDailyDid yesterday’s claims carry the correct modifiers?
Neutral inventory balanceDailyDid an invoice push the balance negative, and why?
Medicaid carve-in and carve-out alignmentMonthlyAre modifiers applied correctly across every site type?
Provider list reconciliationMonthlyWhat changed since last month — new providers, resigned providers?
Organizational change reviewMonthlyNew freestanding ED, new business entity, new qualifying area?
Purchasing documentation across vendorsMonthlyAre manually entered vendors reaching the TPA at all?
Exception ageingMonthlyHow long have open exceptions been sitting unresolved?

Two things in that table are worth pulling out.

The first is that some controls do not belong on a monthly cycle at all. “Something as simple as whether or not the claims that you processed from the day before that actually went out, did they have the modifiers applied?” Daily questions get daily answers.

The second is the provider list. Edwards frames the monthly review around a single opening question: what changed from last month to this month? New business entities, a new freestanding emergency department, new providers, resigned providers, changes to hospital infrastructure, or a legislative or judicial change in how the 340B program is interpreted. Each of those can silently start qualifying claims that should not qualify, or stop qualifying claims that should. Catching them inside the month is what 340B audit readiness looks like in practice.

Why is a clean TPA report not enough for 340B audit readiness?

Because the TPA report is the end of the evidence chain, not the source of it. A covered entity remains accountable to HRSA for eligibility regardless of which vendor produced the determination.

This is the part of 340B audit readiness that separates mature programs from confident ones.

“One of the areas where we could see potential gaps is when we rely solely on what the TPA told us is a qualified claim,” Edwards said. “Then we are missing the bigger picture of where that data even comes from.”

Every system should be telling the same story about a given claim. That means the TPA report, the wholesaler purchasing data, the active provider list, and the EMR documentation all have to agree. When one of them cannot be explained, the program has a visibility problem even if the final report looks complete.

Her framing is the most quotable line in the episode: “It’s more than just what is the final report. You really need to go back and understand your data source, and make sure that if your TPA says this was eligible because, for example, it’s saying this was an outpatient, does your EMR tell that same story?”

What breaks an eligibility decision months after it looked correct?

A patient class change. This is the specific failure mode most programs have never deliberately tested, and it is worth building into your 340B audit readiness review this quarter.

Under Medicare observation rules, a patient who qualified as an outpatient at the moment of dispense can be reclassified to inpatient on the back end, days later, by someone who has never heard of 340B. The TPA qualified the claim correctly against the information available. The EMR now tells a different story.

Two questions follow, and both belong in writing before an auditor asks them.

Do your policies and procedures state whether that claim remains eligible? And can you produce an audit trail demonstrating that the claim was eligible per those policies at the time it was made?

This matters more than it might appear, because of how HRSA findings actually work. “Most of the time, they’re finding deficiencies or recommendations for improvement based on whether or not your practice aligns with your policy.” The finding is rarely that a claim was wrong in the abstract. It is that the organisation did not do what its own policy said it would do. That is why 340B audit readiness is measured against your own documentation before anyone else’s standard.

Does the rebate model change what 340B audit readiness means?

It extends it rather than replacing it. Under the revised rebate model pilot, approved manufacturer plans are scheduled to take effect on 1 January 2027 for a limited set of drugs, which adds a timing component to work most programs are already doing.

“They really aren’t two different things,” Edwards said. “It’s really more of an expansion of what you’re already doing.”

Three capabilities are worth testing before the workflow becomes operational.

  1. Claims-level data completeness. Confirm your EMR already produces every required data element, and that IT can generate those reports on a daily basis rather than as a special request. Incomplete submissions create denial risk that simply did not exist under an upfront discount.
  2. TPA transmission support. Establish whether your TPA can carry claims-level data transmission on your behalf, and what remains yours.
  3. Financial reconciliation and visibility. Rebates and expenditures frequently flow through different systems. Somebody has to reconcile them, and the CFO needs to see both.

That third point carries the real organisational risk. Edwards was direct about the consequence of getting it wrong: “we don’t want our CFOs or hospital executives perceiving that now their programs are operating at a loss that is unsustainable because we’re unable to track our rebates and denials.”

A programme that funds community services can be judged as underperforming purely because the money came back through a system nobody was watching. Reconciliation visibility is now part of 340B audit readiness, not a finance afterthought.

What is the one metric that beats total savings?

Exception ageing. Asked which single number tells you more about program control than total savings or claim value, Edwards did not hesitate: “Perhaps how long some exceptions have gone without being resolved.”

She reasons that unresolved exceptions are the visible symptom of a missing system. “If you are looking at things that have been sitting around for a long time, that’s a big indicator that a broader system infrastructure is not in place to ensure that there’s a prompt resolution of exceptions when they do occur.”

Exception ageing belongs on every 340B audit readiness dashboard for that reason. There is a companion signal worth tracking alongside it. An exception that recurs after a correction has been applied is not an exception at all. “If you’re seeing that it’s happening repeatedly, and even if you put in a correction, but it continues to happen, it’s a system problem, and you need to investigate more thoroughly.”

Where does automation genuinely help 340B audit readiness?

In the reconciliation work, not the judgment work. The manual activity Edwards would remove first is the random transaction review and the spreadsheet labour underneath it: running the reports, building the tabs, running XLOOKUP comparisons to line up where the data is.

The argument for automating it is not headcount savings. It is coverage.

“You miss so much with a manual audit,” she said, “but if you have electronic or digital tools that can support you in that, you can probably get a better grasp of how your program is performing by viewing all of your claims versus a small subset of your claims.”

That shift from sampling toward 100 percent transaction review is the single biggest available upgrade to 340B audit readiness in most programs today. And the reason it has to be technology rather than people is arithmetic: “you can’t add enough people to cover the volume of data that really needs to be evaluated.”

Human judgment stays where it belongs. Once the rules have been evaluated at scale, analysts investigate what the exceptions actually mean: a system error, a purchasing error, a wholesaler change, a gap in specialty care documentation, or a genuine compliance problem.

Looking three to five years out, Edwards wants analysts freed for something larger than error-hunting. “The savings are meant to improve the services that we deliver to our communities.” Her ambition is a 340B analyst team “not just looking at numbers, but also reviewing the impact of those numbers.”

Frequently asked questions about 340B audit readiness

What is the difference between 340B audit readiness and audit preparation? Audit preparation is the work performed after an HRSA notice arrives: collecting files, assembling reports, briefing the team. 340B audit readiness is the state of the control system beforehand. The practical test is whether the letter changes how your team practices.

How often should a covered entity review its 340B controls? It varies by control. Modifier application and neutral inventory balances can be checked daily. Provider list reconciliation, Medicaid alignment, and organizational change reviews suit a monthly cycle. Full self-audits remain annual. What matters is that the cadence is driven by risk, not habit.

Can a covered entity rely on its TPA for 340B compliance? No. TPAs and data sources provide information, but the covered entity remains accountable to HRSA for eligibility. Strong 340B audit readiness means being able to independently explain how the TPA reached its determination and validate it against EMR, purchasing, and provider data.

What data should a 340B program be able to produce months after a transaction? The full evidence chain: patient, encounter, provider, prescription or administration, payer, eligibility decision, accumulation logic, purchase, and increasingly the financial outcome. If any link cannot be explained, the program has a visibility gap.

How does the 2027 rebate model affect 340B audit readiness? It adds a timing dimension and raises the cost of incomplete data. Claims-level submissions must be complete and on time, denials must be reconciled, and finance needs visibility into rebates received against claims submitted.

What should we test first before the rebate workflow goes live? Run a gap analysis. Compare what your systems produce today against what the rebate model requires, and bring IT and finance into that conversation early, because IT changes can take months.

Building a program that is already ready

The through-line of this conversation is that 340B audit readiness is an operating discipline, not a document. It lives in what your controls do on an ordinary Tuesday, in whether your systems agree about a single claim, and in how long an exception is allowed to sit.

NorthArc Health works with covered entities on exactly this layer: risk-targeted monthly controls, evidence chains that survive a revisit months later, and custom agentic AI built around the reconciliation work that currently consumes analyst time. For the underlying program rules, HRSA 340B Program Requirements remains the authoritative source.

Ready to find out where your evidence chain breaks? NorthArc Health is a 340B consulting and technology company that builds custom agentic AI for covered entity operations.

Book a Consultation with NorthArc

Listen to the full conversation with Dr. Darra M. Edwards on 340B Pulse.