Select Page
Laura Ferrara is a healthcare executive with 30+ years of experience in post-acute and PACE care. As Chief Population Health Officer at Intus Care, she leads efforts to improve outcomes through data-driven, compliant, and compassionate care models.

Update (February 23rd, 2026)

Last week, CMS finalized the PACE Audit Protocol, confirming many of the directional changes outlined when the draft was released.

The Overview and Protocol Package are available on the CMS PACE Audits webpage.

The final version reinforces a more standardized audit structure, greater emphasis on data accuracy and documentation, and clearer expectations for root cause analysis and corrective action. While the core regulatory requirements themselves have not fundamentally changed, the way CMS operationalizes and audits those requirements is now more defined and consistent for audits beginning in 2026.

Original post (September 18th, 2025)

CMS is updating the PACE Audit Protocol. Finalization of the draft is expected by year’s end. The updates will apply to audits beginning in 2026.

CMS has integrated 2024 regulations and lessons from past audits, creating a process that is both more streamlined and more rigorous.

The message is clear: the bar is rising on compliance in PACE.

The good news? Preparing now will help your PACE program stay ahead and make your next audit far less stressful. With the right approach and the right tools, your organization will pass an audit with confidence.

The new rules of the audit road

The new PACE audit protocol reflects the new regulatory requirements that became effective in June 2024. These changes directly impacted PACE organization operations, including:

  • Personnel Requirements: PACE programs must now meet enhanced medical clearance and immunization requirements for staff with direct participant contact.
  • Service Timeframes: New rules set maximum timeframes for reviewing recommended services, scheduling and delivering care, and coordinating services.
  • Participant Rights: The rules update and clarify participant rights, strengthening protections.
  • Grievance Procedures: New definitions with specific timeframes for resolution are now in place.

The protocol introduces significant updates that all PACE organizations should be aware of. Here’s what’s new:

A more standardized, streamlined (and stricter) approach

To make audits more consistent, CMS has standardized nearly every step of the process. The changes mean fewer surprises for PACE organizations, but they also leave less room for error.

  • Templates for everything: The audit process is now defined by a suite of new and revised documents. To ensure consistency, CMS has introduced specific templates for Request for Additional Information (RAI) responses and Corrective Action Plans (CAPs). This means organizations must use these specific documents to respond to CMS.
  • Case file cover sheets: Auditors expect a clear path through your digital files. A new cover sheet is now required for each sample case file submitted for review, which is designed to make it easier for auditors to find the necessary documentation.
  • Seven new impact analysis templates: PACE programs must now formally demonstrate the scope of each issue. When non-compliance is identified, CMS may request an Impact Analysis (IA), and the protocol now includes seven new templates to help organizations submit this information accurately. CMS expects a clearer demonstration of how deficiencies were analyzed and remediated.
  • Reduced administrative burden: While some requirements are stricter, CMS listened to feedback about the burden on PACE organizations. They are eliminating some data collection requirements that were part of previous protocols, including certain monitoring reports.

A new focus on data accuracy and accountability

CMS is also doubling down on data accuracy and accountability, meaning PACE organizations must raise the bar on their data management practices. With the new PACE audit protocol, CMS places a much greater emphasis on the accuracy and integrity of the data that PACE organizations submit.

  • Three strikes and you’re out: For data universe submissions, CMS has implemented a new, stricter policy. CMS now limits PACE organizations to three attempts to submit a usable universe; if the third attempt is rejected, it will be noted in the final audit report as a finding of non-compliance.
  • The “Why” matters: A surface-level explanation will not suffice. The protocol emphasizes that a Root Cause Analysis (RCA) must do more than just restate the circumstances of non-compliance. Programs must conduct a thorough investigation to determine all contributing factors that led to the non-compliance. RCAs are considered “critical” to helping a PO develop effective Corrective Action Plans (CAPs) that prevent future non-compliance.

PACE audit protocol readiness

A successful audit starts long before the engagement letter arrives. Here are the key steps your organization should be taking right now to make sure you are prepared:

  1. First, master the new audit tools: Given the new, standardized audit templates, your team should become proficient with the new documents for responding to CMS. Conduct mock audits to practice using the new forms for responding to requests for additional information and submitting corrective action plans to ensure a seamless process during the audit itself.
  2. Next, prioritize data accuracy and integrity: With the new emphasis on data integrity, your organization must shift its focus from merely submitting data to ensuring its accuracy from the start. Implement internal validation processes for all data universes to minimize errors and avoid rejected submissions.
  3. Then, get obsessed with the ‘why’: The protocol’s focus on a thorough investigation of non-compliance means a prepared organization will have a process in place to determine all contributing factors. By perfecting your “why” in a Root Cause Analysis, you can more effectively develop and implement corrective actions that prevent future issues.
  4. Finally, let your EMR do the heavy lifting: In a world where audits are increasingly data-driven, your EMR is your best asset. It can be the difference between scrambling to pull information from disparate systems and demonstrating a seamless, compliant process from the beginning.

Your partner in compliance: The CareHub advantage

CareHub EMR is built with this in mind, giving your organization a compliance co-pilot and audit advantage. Here’s how it helps ensure you are audit-ready:

  • Compliance built-in, not bolted on: CareHub embeds compliance into every workflow — from enrollments to assessments and care planning — reducing the risk of findings before they happen. Smart content checklists and contextual documentation guide your team to consistently meet CMS requirements.
  • Seamless data management: When the engagement letters arrive under the new audit protocol, you’ll be ready. Generate accurate, CMS-ready data sets for service requests, grievances, appeals, and medical records with ease. This speeds up audit prep, reduces rejected submissions, and keeps your team focused on care.
  • Total data control: With CareHub, you own your data. CareHub gives you nightly exports of your complete data set, so you always have an up-to-date copy ready for review. Our upcoming DataHub add-on will make it even easier to consolidate and manage your data in one place, so you can respond to auditor requests with confidence and speed.

The bottom line

Audit prep under the new PACE audit protocol doesn’t have to be stressful. By focusing on streamlined processes, disciplined documentation, and partnering with an EMR built for compliance, your PACE program can stay audit-ready and continue improving day-to-day operations

 

 

See how you can transform your PACE organization

Schedule a demo with our team to learn more about how IntusCare can optimize your organization, streamline communication, and enable better quality and compliance.