Independent validation. Actionable findings. Greater confidence in your program.
Maintaining a compliant 340B program requires more than internal monitoring.
Thrive340B provides comprehensive annual independent audits designed to evaluate contract pharmacy arrangements, identify potential compliance concerns, validate internal controls, and help covered entities prepare for external scrutiny.
Our annual audit gives leadership an independent assessment of how the program is operating, where potential vulnerabilities exist, and what corrective actions may be needed.
One comprehensive annual review of your compliance controls, contract pharmacy arrangements, and supporting records.
Schedule Your Annual 340B Audit
HRSA Recommends Annual Independent Audits
HRSA recommends that covered entities perform annual independent audits—or more frequently when necessary—of all contract pharmacies they use. HRSA also recommends quarterly internal audits and written policies describing how the covered entity oversees its contract pharmacy arrangements.
HRSA’s contract pharmacy guidance further states that covered entities must provide oversight of their contract pharmacies, use an independent audit firm to audit them at least once each year, maintain auditable records, and report identified noncompliance with an appropriate corrective plan.
Thrive340B helps covered entities incorporate that annual independent review into a structured, documented compliance program.
More Than a Routine Claims Review
An annual independent audit should do more than confirm that a small group of prescriptions appears accurate.
Thrive340B evaluates the systems, relationships, records, and controls supporting your contract pharmacy arrangements.
Our review is designed to determine whether:
- Patient eligibility decisions are adequately supported
- Prescriptions can be connected to qualifying clinical encounters
- Providers have an appropriate relationship with the covered entity
- Contract pharmacies and associated locations are properly registered
- Duplicate-discount safeguards are functioning
- Diversion controls are operating effectively
- Dispensing, purchasing, billing, and replenishment records reconcile
- Provider and location data remain current
- Written policies reflect actual program operations
- Vendors are performing their assigned responsibilities
- Previous findings have been appropriately corrected
- Program records are organized and auditable
What Our Annual Independent Audit Reviews
Contract Pharmacy Arrangements
We evaluate the structure and operation of the covered entity’s contract pharmacy relationships.
The review may include:
- Active contract pharmacy arrangements
- HRSA OPAIS registration
- Written contract pharmacy agreements
- Pharmacy start and termination dates
- Pharmacy and location identifiers
- Third-party administrator configuration
- Accumulator activity
- Prescription capture methodology
- Replenishment processes
- Reversal handling
- Claims exclusions
- Vendor fees and reporting
- Covered entity oversight activities
The audit plan is structured to address all utilized contract pharmacy arrangements while applying appropriate transaction sampling and risk-based review methods.
Patient Eligibility and Patient Definition
We review whether sampled 340B transactions are supported by documentation demonstrating an appropriate relationship between the patient and the covered entity.
Testing may include:
- Patient registration
- Clinical encounter documentation
- Dates of service
- Medical record maintenance
- Covered entity responsibility for care
- Prescription-to-encounter matching
- Referral relationships
- Follow-up care
- Prescriber and location validation
- Consistency across clinical, pharmacy, and claims systems
Provider Relationship Validation
A prescription should not be treated as eligible merely because the prescriber appears on a provider list.
We evaluate the documentation supporting provider relationships, which may include:
- Employment records
- Professional service agreements
- Independent contractor arrangements
- Credentialing records
- Provider start and termination dates
- Authorized service locations
- Prescribing authority
- Provider roster accuracy
- Third-party administrator configuration
- Evidence of covered entity responsibility for the care provided
Diversion Controls
Covered entities are responsible for ensuring that 340B drugs are not transferred to individuals who do not meet applicable program eligibility requirements.
Our review may evaluate:
- Patient eligibility controls
- Prescription qualification logic
- Provider eligibility controls
- Location eligibility
- Claims exclusions
- Referral prescriptions
- Refill qualification
- Data-matching rules
- Manual override procedures
- Exception reporting
- Resolution of identified discrepancies
Duplicate-Discount Prevention
We evaluate processes designed to prevent both a 340B discount and a Medicaid rebate from being applied to the same drug transaction.
The review may include:
- Medicaid Exclusion File information
- Carve-in and carve-out decisions
- Medicaid billing practices
- State-specific Medicaid requirements
- Managed Medicaid activity
- Billing modifiers
- Claims identifiers
- Contract pharmacy Medicaid exclusions
- Third-party administrator settings
- Written duplicate-discount procedures
Transaction Reconciliation
HRSA recommends reconciliation of dispensing, purchasing, and billing records as part of contract pharmacy oversight.
Our transaction testing may include:
- Original prescription records
- Dispensing records
- Payer and billing information
- Accumulator records
- Purchase orders
- Wholesaler activity
- Replenishment transactions
- Reversals and resubmissions
- Inventory movement
- Prescription-to-purchase reconciliation
- Financial settlement records
HRSA OPAIS Accuracy
We compare relevant organizational information with the HRSA Office of Pharmacy Affairs Information System.
This may include:
- Covered entity information
- Parent and child-site records
- Contract pharmacy registrations
- Shipping addresses
- Authorizing official information
- Primary contact information
- Medicaid billing information
- Active and terminated arrangements
- Effective dates
- Duplicate or outdated registrations
Policies and Procedures
Written policies should accurately reflect how the program operates in practice.
We may review policies addressing:
- Patient eligibility
- Provider eligibility
- Contract pharmacy oversight
- Diversion prevention
- Duplicate-discount prevention
- Medicaid billing
- Provider roster management
- HRSA OPAIS maintenance
- Internal auditing
- Independent auditing
- Corrective actions
- Self-disclosure
- Record retention
- Staff responsibilities
- Vendor oversight
We identify situations in which policies are incomplete, outdated, internally inconsistent, or not aligned with actual workflows.
Vendor and Third-Party Administrator Oversight
The covered entity remains responsible for program compliance even when operational functions are delegated to outside vendors.
Our audit may assess:
- Assigned vendor responsibilities
- Contractual obligations
- System configuration
- Data accuracy
- Exception management
- Reporting quality
- Communication processes
- Corrective-action responsiveness
- Pharmacy reconciliation
- Covered entity access to records
- Evidence of active oversight
Risk-Based Transaction Testing
The annual audit uses a documented sampling methodology based on the size, complexity, and risk profile of the covered entity’s program.
Sampling considerations may include:
- Contract pharmacy volume
- High-cost medications
- Specialty prescriptions
- Medicaid activity
- Reversals
- Unmatched prescriptions
- Referral prescriptions
- Newly added providers
- Newly added pharmacies
- New or changed locations
- Manual overrides
- Prior audit findings
- Unusual utilization patterns
The objective is to evaluate both routine program activity and transactions more likely to reveal a weakness in internal controls.
Clear Findings With Defined Risk Levels
At the conclusion of the audit, Thrive340B provides a written report explaining what was reviewed and what was identified.
Findings may be categorized according to risk and urgency, such as:
- Critical findings
- High-risk findings
- Moderate-risk findings
- Lower-risk observations
- Process-improvement opportunities
- Areas demonstrating effective controls
Each finding may include:
- The condition identified
- Relevant supporting documentation
- The potential compliance concern
- The affected pharmacy, provider, location, or transaction
- Root-cause considerations
- Recommended corrective action
- Proposed responsible party
- Recommended completion date
- Follow-up validation requirements
Corrective-Action Planning
The value of an annual audit depends on what happens after findings are issued.
Thrive340B can help the covered entity develop a structured corrective-action plan addressing:
- Immediate transaction corrections
- Provider roster updates
- HRSA OPAIS corrections
- Pharmacy configuration changes
- Vendor-system corrections
- Policy revisions
- Staff education
- Claims reconciliation
- Repayment analysis
- Expanded transaction testing
- Self-disclosure considerations
- Follow-up monitoring
The covered entity and its legal or compliance advisors retain responsibility for determining whether repayment, self-disclosure, or other formal action is required.
Follow-Up Validation
Corrective action should be verified—not merely marked complete.
Depending on the engagement, Thrive340B can conduct follow-up testing to confirm that:
- The identified issue was corrected
- Affected data was updated
- Transactions were properly reconciled
- New controls were implemented
- Staff received necessary education
- Vendor configuration was corrected
- Policies were revised
- The issue has not continued
- Supporting documentation has been retained
Follow-up results can be documented for leadership, compliance committees, governing boards, and future audit preparation.
Annual Audits and Monthly Audits Serve Different Purposes
Monthly Compliance Audits
Monthly audits provide ongoing monitoring of current program activity. They help identify emerging concerns, confirm that routine controls are functioning, and support timely corrective action.
Annual Independent Audits
The annual independent audit provides a deeper and more comprehensive assessment of the contract pharmacy program, internal controls, vendor relationships, written policies, and supporting records.
A strong compliance program may use both:
- Monthly internal or operational monitoring to detect concerns throughout the year
- An annual independent external audit to provide objective validation and satisfy recommended contract pharmacy oversight practices
The annual audit does not replace ongoing covered entity oversight. It provides an additional level of independent assurance.
Preserving Auditor Independence
An external audit must provide an objective assessment of the program.
Before accepting an engagement, Thrive340B evaluates existing consulting, operational, and management relationships for actual or perceived conflicts of interest.
When Thrive340B already performs operational services for an organization, the annual audit engagement may require:
- A separately assigned audit team
- Separation between operational and audit personnel
- Defined information barriers
- Independent review of findings
- Written conflict disclosures
- Additional quality controls
- Coordination with another independent audit firm when appropriate
The final engagement structure will be designed to preserve the integrity and credibility of the audit process.
What You Receive
Depending on the scope of the engagement, annual audit deliverables may include:
- Audit planning document
- Document request list
- Contract pharmacy inventory
- Risk assessment
- Transaction sampling methodology
- Detailed transaction testing
- Provider relationship review
- HRSA OPAIS validation
- Duplicate-discount testing
- Diversion-control testing
- Policy and procedure assessment
- Vendor oversight review
- Written findings report
- Executive summary
- Corrective-action recommendations
- Leadership or board presentation
- Follow-up validation testing
Prepare Before HRSA Selects Your Organization
HRSA conducts both remote and onsite audits of covered entities and reviews records related to program eligibility, diversion, duplicate discounts, and contract pharmacy arrangements. Covered entities are expected to maintain accurate, auditable records demonstrating compliance.
An annual independent audit allows your organization to identify and address potential concerns before they are discovered during an external government or manufacturer review.
Demonstrate Active Covered Entity Oversight
An annual independent audit helps your organization demonstrate that leadership is actively overseeing the 340B program rather than relying entirely on pharmacies, third-party administrators, or other vendors.
The audit provides documented evidence that the covered entity has:
- Evaluated its contract pharmacy arrangements
- Tested supporting transactions
- Reviewed patient and provider eligibility
- Assessed duplicate-discount and diversion controls
- Verified HRSA registration information
- Identified potential weaknesses
- Developed corrective actions
- Monitored the resolution of findings
Independent Review. Practical Recommendations. Stronger Program Integrity.
Your organization should not have to wait for a government audit to discover weaknesses in its 340B program.
Thrive340B provides a structured annual independent audit designed to identify concerns, validate internal controls, strengthen contract pharmacy oversight, and give leadership a clear understanding of program risk.
Know where your program stands before someone else evaluates it.
Schedule Your Annual Independent Audit
