Platform

Twenty modules. One license.

Everything a Medicare Advantage compliance program does between audits, with the regulation attached to every finding. Built module by module inside a live plan, not from a generic compliance template.

Precision Mandate · regulatory command center

The CMS memo, read and assigned before lunch.

A memo arrives. Mandate reads it, separates the obligations from the background, quotes the memo text behind each action item, names the department, and sets a working due date ahead of CMS's. Each owner gets a morning brief. The officer sees what is late, what is with compliance, and what closed, with the evidence attached.

  • Acknowledgements by name on the memo, with a timeline entry per acknowledgement
  • Correct a department once and the next memo of that kind goes to the right owner
  • Every reassignment, evidence upload, and return is a timeline entry nobody can edit later
Precision Mandate · morning brief
The Precision Mandate morning brief email listing actions that need attention
Scrubber · universe validation

Eighteen tables. The current standards. Nothing kept.

ODAG Tables 1 to 5, CDAG Tables 1 to 7, FA Tables 1 to 4, SNPCC, and CPE. Field rules come from the CMS record layouts. Timeliness comes from the current regulation, which is why the Scrubber tests standard organization determinations at 7 days when the protocol PDF still says 14.

  • Complete universe export with the issue written into the row, plus tabs for timeliness, missing data, and formatting
  • Large files run in a worker so a 70,000 row universe does not lock the screen
  • Validated in memory. Enrollee rows are removed before anything is stored. A de-identified timeliness summary is all that persists
Scrubber · choose the universe table
The Scrubber with the ODAG universe tables ready to check
Audit · internal and FDR audits

Engagement notice to final report, in the CMS format.

Internal program audits on ODAG, CDAG, SNPCC, and provider directory accuracy, and delegated entity audits, on one engine. The notice goes out on your letterhead. The universe request runs on the CMS clock. The data check is the Scrubber. Sampling follows the protocol. Findings become conditions, and the draft and final reports come out in the CMS program audit format with the results workbook beside them.

  • Auditee access with its own sign-in and multi-factor, so a department or a vendor works its own evidence request
  • Protected health information is working material only: samples drawn from validated universes and destroyed at close, with the destruction record on the audit
  • Every finding routes to the Issues Log and, where warranted, opens a CAP
Audit · ODAG internal audit workspace
An internal ODAG audit workspace showing the period under review, engagement date, evidence due date, and authorities
Policy Review Guide and RuleIQ · policies against the rule

A policy checked against the rule that governs it, with the citation next to every flag.

Open a policy for review and the guide has already checked it against the final rule, the CMS memos your plan received, and the duties in your state Medicaid contract. It flags only what it can cite, offers the wording, and stays silent where it is not certain. RuleIQ does the same from the rule's side: it reads a proposed or final rule as duties, matches each duty to the policy that should carry it, and lists the duties no policy cites yet, by department.

  • Certain or silent. A flag without a source is not shown
  • Department owners review and attest in the same screen; the officer signs off
  • Every review is recorded with what changed and why, in one plain sentence
Policy Review Guide · checked against current requirements
The Policy Review Guide showing flagged sections with the regulation quoted beside each
Risk Assessment · the register

The risk register scored the way the compliance committee reads it.

Every risk sits in one of the eight compliance domains or Reputational, with inherent and residual scores, the owner, the controls, and the year over year change. The heat map and the register go to the committee and the board as they are, and the work plan draws its monitoring from what scored highest.

  • Eight domains plus Reputational, nothing invented
  • Inherent and residual scoring with the controls that close the gap
  • Feeds the COA Work Plan, so monitoring follows the risk
Risk Assessment · register
The Risk Assessment register with scored risks and the heat map
Precision Privacy · program and incidents

A privacy incident carried from the first report to the last letter.

Intake, the risk assessment, the sixty day clock from discovery, state rules, the notifications, and the letters to members, HHS, and the covered recipients who reported it. The program itself lives beside the incidents: policies, training, the vendor reviews, and the officer’s record.

  • The clock starts at intake and is visible on every case
  • Assessment written to the HIPAA factors, with the outcome recorded either way
  • Letters generated from the case and kept as sent
Privacy, end to endHIPAA Breach Notification Rule and Privacy Rule
  1. Discovery. The clock starts the day the incident is known, or should have been known. Every case is dated from that day, not from the day it reached the privacy officer.45 CFR 164.404(b)
  2. Assessment. The four factor risk assessment: what was involved, who used or received it, whether it was actually acquired or viewed, and how far the harm was mitigated. The outcome is recorded either way.45 CFR 164.402
  3. Notification. Individuals without unreasonable delay and within sixty days. HHS within sixty days when five hundred or more are affected, otherwise in the annual log. Media when five hundred or more in a state.45 CFR 164.404, 164.406, 164.408
  4. Business associates. Notice from the associate to the plan, the agreement terms that bind it, and the record of both.45 CFR 164.410, 164.504(e)
  5. Mitigation and sanctions. Harmful effects mitigated, workforce sanctions applied and recorded, substance use disorder records handled under their own consent rules.45 CFR 164.530(e), (f) · 42 CFR Part 2
  6. Documentation. The case, the letters, and the decisions kept for six years, ready for an OCR request.45 CFR 164.530(j)
Network Adequacy · 42 CFR 422.116

The roster in, adequacy measured, the HPMS tables out.

The roster is scored against every CMS standard by county and specialty every time it changes. Gaps become findings the network team works. Office attestations run on a cycle so the roster stays true. Drive times are mapped. When a gap cannot be closed, the exception request drafts itself with the rationale and the supporting data.

  • Standards met by county, thin margins flagged before they become gaps
  • Trend across runs for the board
  • Correspondence and attestations on the record
Network Adequacy · overview
Network Adequacy overview with standards met by county and a trend across runs
Every module

Twenty modules, grouped the way a compliance program is organized.

All of them ship on the same license. Department users see only what they own. The compliance officer sees everything.

Regulation and memos
Precision MandateReads every CMS memo, pulls out the action items, assigns each to a department with a due date, and keeps the acknowledgement roster and the evidence.42 CFR 422.503(b)
RuleIQReads a proposed or final rule as duties, editorial changes, and background. Matches each duty to your policies and lists the ones nothing covers yet.42 CFR Parts 422 and 423
Policy Review GuideChecks a policy against the current rule, the CMS memos, and your state Medicaid contract. Flags only what it can cite, with the wording ready to paste.Final rule · HPMS memos · SMAC
Compliance HubEvery obligation and every deadline from every module in one calendar, with the working date a few days ahead of the regulator's.42 CFR 422.503(b)(4)(vi)(B)
Audit and monitoring
ScrubberValidates 18 universe tables across ODAG, CDAG, FA, SNPCC, and CPE against the CMS record layouts and the current timeliness standards, then exports the complete universe with every issue marked.CMS Program Audit Protocols
AuditRuns internal program audits and FDR audits end to end: engagement notice, universe request, data check, sampling, fieldwork, findings, and a report in the CMS program audit format.ODAG · CDAG · SNPCC · PDA
COA Work PlanThe audit and monitoring work plan by area, measure, and month, with benchmarks, results, and charts ready for the compliance committee and the board.42 CFR 422.503(b)(4)(vi)(F)
Universe RequestsRequests universes from FDRs and internal departments on a schedule, tracks the clock, and files what comes back on the audit.CMS universe timelines
ReporterRecounts your Part C and Part D reporting from the source records, shows every miscount with the citation beside it, and writes the HPMS upload file.42 CFR 422.516 · 423.514
Network AdequacyMeasures the provider roster against every CMS standard by county and specialty, works the gaps, maps drive times, and drafts the exception requests.42 CFR 422.116
Issues LogEvery issue and its remediation in one register with an owner, its evidence, and a link back to whatever raised it.42 CFR 422.503(b)(4)(vi)(F)
CAPA corrective action plan from root cause to leadership sign-off, with the closure packet assembled as the work happens.42 CFR 422.503(b)(4)(vi)(G)
Delegation
FDR OversightThe vendor register, contracts read for delegation scope, annual assessments built from what is delegated, attestations, scorecards, monthly exclusion screening, and a vendor portal with its own sign-in.42 CFR 422.504(i)
Governance
Risk AssessmentThe risk register across the eight compliance domains, scored, with the heat map and the year over year change.42 CFR 422.503(b)(4)(vi)(C)
SignoffHubCompliance committee, CEO, and board sign-off with the packet, the minutes, and the approval date written back to the document.Board oversight
Policy ManagementThe policy library with versions, owners, approvals, and attestations.42 CFR 422.503(b)(4)(vi)(A)
WorkstreamFollow-ups that cross modules, with the email kept exactly as sent and every reply landing on the record.Evidence record
Privacy, FWA, and governance
Precision PrivacyThe privacy program and its incidents: intake, risk assessment, the 60 day clock, notifications, and the letters.45 CFR 164.404
SentinelFraud, waste, and abuse intake, triage, and investigation with a case record built for referral.42 CFR 422.503(b)(4)(vi)
Precision Responsible AIA register of the automated tools your plan relies on, each with its risk tier, its assessment, and the committee record.Governance
Deck StudioBoard and committee decks built from the live record in your organization's template.Reporting
Reporter · Part C and Part D reporting

The counts CMS publishes, recounted from your records before you upload.

Twelve Part C sections and eight Part D sections. Drop the file in with the source records behind it. Reporter recounts, shows every miscount and misclassified case with the citation beside it, and writes the HPMS upload file. One section, the D-SNP Enrollee Advisory Committee, runs a layout preflight only until CMS publishes its layout.

Universe Requests · the clock

Universes requested on a schedule, tracked to the day.

Internal departments and delegated entities get the request on the first business day, in your organization's voice, with the CMS timeline attached. What comes back lands on the audit. What does not come back is visible before it becomes a finding.

Security and SOC 2

Built for protected health information from the first line.

A Business Associate Agreement is signed before any work begins. SOC 2 Type 1 examination is in preparation with Thoropass, covering the platform and the Scrubber, with Type 2 to follow. The controls below are running today, independent of the report.

Multi-factor sign-in for everyone

Plan users, department owners, auditees, and vendor portal users. No shared logins.

Append-only audit log

Every action is written to a log that cannot be rewritten later, with 13 month retention on the operational record.

Tenant isolation

One organization's data is never in another's query. Department scoping inside the tenant.

Encryption in transit and at rest

TLS to the browser, encrypted storage, envelope encryption on universe submissions.

Microsoft Azure only, US regions

Every part of the platform runs inside Azure under the same BAA. The platform refuses to start against any other provider.

PHI as working material

Universes validated in memory. Audit samples destroyed at close with the record kept. Detected PHI in the wrong place is removed and compliance is alerted.

The first call

Call (305) 510 0774. Or send one file and get the read.

Tell us what is on your desk: a universe due in two weeks, a memo nobody has read, a vendor you have never assessed, a network gap. We answer on the call, and the memo follows in writing with the citations. If our platform would help, we will show you on your own file.

What happens next

A person answers. If we are on another call, we call back the same day.

The memo arrives as a PDF with every citation. Yours to keep, whether or not we ever work together.

Prefer email? support@PrecisionComplianceGroup.onmicrosoft.com