Last Updated: September 25, 2026
A 340B prescriber roster audit for contract pharmacies is the process of reconciling every provider who writes prescriptions against the prescriber list configured in the third-party administrator's system. When that list drifts from reality, claims get rejected, and the covered entity absorbs the loss.
Drift happens for four reasons:
A 340B TPA configuration audit compares three sources side by side: the TPA's prescriber list, the EHR provider records, and the pharmacy claim detail. Most entities check only the first two.
Run the audit in five steps, in this order. Skipping ahead creates rework, and the corrective action step is the one most entities skip entirely.

Export every claim in the lookback period with the rendering provider NPI attached. Use the rendering NPI, not the billing or supervising NPI.
Check that the report includes:
Look up every NPI in NPPES and confirm the provider is active, in the right specialty, and tied to the correct practice location. Then compare that verified list to the TPA config.
This is the step most entities skip. Pull the contract pharmacy claim detail for the same lookback period and match the adjudicated rendering NPI on each claim to your verified list.
| Reconciliation outcome | What it means | Action |
|---|---|---|
| NPI on claim, on TPA config, in NPPES | Clean | None |
| NPI on claim, missing from TPA config | Revenue at risk | Add to config, request retroactive review |
| NPI on TPA config, no claims | Stale entry | Remove or confirm still active |
| NPI on claim, inactive in NPPES | Compliance exposure | Remove, review affected claims |
| Mid-level rendering under supervising NPI | Hidden rendering provider | List under both NPIs |
Correct the EHR provider record first. If the EHR still holds the wrong NPI, the next config update will reintroduce the error.
A discrepancy without a written corrective action plan (CAP) is an audit finding waiting to happen. HRSA auditors want to see that you found the gap, fixed the root cause, and can prove it.
A workable CAP has five fields:
A 340B prescriber reconciliation template turns the audit into a repeatable file. Build it once, then reuse it every cycle.
| Field | Source | What to Record |
|---|---|---|
| Provider name | EHR | Legal name as billed |
| Rendering NPI | EHR claims report | The NPI on the claim |
| Supervising NPI | EHR | If the provider is supervised |
| NPPES status | NPPES lookup | Active or inactive |
| TPA config status | TPA list | Present or missing |
| Claim volume | EHR claims report | Count in lookback period |
| Discrepancy type | Your review | Missing, wrong NPI, or non-prescriber |
| Action taken | Your review | EHR fix, config update, or removal |
| Date resolved | Your review | Completion date |
| Confirmation on file | TPA | Yes or no |
Most roster gaps become audit findings for the same handful of reasons. None of them are exotic.
Quarterly is the right cadence for most covered entities. Annual is too slow, and monthly is more work than the drift justifies.
Most entities start manual and stay manual longer than they should. Both approaches work, but they fail in different ways.
| Approach | Strength | Failure mode |
|---|---|---|
| Manual quarterly reconciliation | Catches structural drift, forces a human review of every NPI | Misses mid-cycle changes, depends on one owner staying on it |
| Automated roster monitoring | Flags new NPIs on claims within days, catches covering providers fast | Only as good as the EHR feed, silent if the feed breaks |
| Hybrid (recommended) | Automated alerts plus a quarterly human reconciliation | Requires someone to own the alert queue |
Do not wait for the quarterly date if any of these happen. Run a targeted reconciliation within two weeks:
Between cycles, do three things:
Assign one owner. In our experience, roster maintenance fails when it belongs to everyone and no one.
Configs drift because the EHR provider record and the TPA prescriber roster are maintained by different people on different schedules. Mid-levels render under a supervising NPI, covering providers rotate through without an EHR update, and non-prescriber staff get added by mistake. In our experience one audit found roughly a third of active rendering providers missing from the TPA config, including the practice owner, because athena carried the wrong NPI. Reconcile the TPA config against an EHR claims report by rendering NPI every quarter.
Quarterly is the working cadence for most covered entities. It lines up with typical TPA reconciliation cycles and gives you a clean lookback period for each review. Run a full prescriber roster audit for contract pharmacies every quarter, and do an off-cycle pass any time a provider joins, leaves, changes supervising NPI, or switches EHR templates. Waiting until the February recertification window to start is the most common reason files come up short.
Claims written by that NPI at the contract pharmacy can be treated as ineligible, and HRSA can require repayment to the manufacturer. The exposure compounds quietly because the pharmacy keeps dispensing and the claims keep adjudicating. Missing rendering NPIs on a roster also weaken your audit trail, since the claim detail will not tie back to a credentialed prescriber. Fix the EHR provider record, resend the config, and document the correction date.
Pull an EHR claims report by rendering provider NPI for the lookback period, verify each NPI in NPPES, then compare that list line by line against the TPA prescriber config and the pharmacy claim detail. List supervised providers under both the supervising and rendering NPIs. Use a 340B prescriber reconciliation template with columns for name, NPI, NPPES status, TPA status, EHR status and action taken. Send the updated config to the TPA and log the date.
The rendering NPI is the prescriber who actually wrote the prescription, and it is the identifier HRSA and manufacturers use to tie a claim back to an eligible provider at the covered entity. If the rendering NPI is not on the TPA config, the claim can be flagged as ineligible even when the patient and the drug qualify. That is why NPI validation in NPPES and a clean match between the EHR record and the TPA config matter more than almost anything else in the file.
Bring us your patient acquisition, 340B program, or compliance bottleneck. We will show you what a 30-day launch looks like for your clinic — in English or Spanish, month to month, no long contract.