← All posts

Navigating 340B Compliance: Essential Guidelines for July 2025

Compliance in 340B is not a checklist exercise. It is an operational discipline. The organizations that pass HRSA audits without breaking a sweat are not the ones with the thickest policy binders. They are the ones where compliance is embedded in how the pharmacy actually runs, every day.

Know What HRSA Is Actually Looking For

HRSA audits focus on five core areas: patient eligibility, duplicate discounts, diversion, contract pharmacy oversight, and the entity maintaining an auditable trail for all of it. If you can demonstrate clean data in those five areas, you will clear an audit. If you cannot, no amount of narrative explanation will save you.

The most common finding in HRSA audits is not fraud. It is sloppy eligibility documentation. A patient fills a prescription, the covered entity claims it at 340B pricing, and when the auditor asks for proof that the patient had a qualifying relationship with the entity at the time of the dispense, the documentation is incomplete or missing. That is a repayment finding. And it is entirely preventable.

Eligibility Determination Is Where Programs Fail

Your 340B eligibility policy needs to be specific enough that a new employee can apply it without interpretation. "Patient of the entity" is a regulatory definition, not a clinical judgment call. The patient must be registered, must have a provider relationship with the covered entity, and the prescription must arise from a healthcare encounter at the entity or an associated site listed on the OPAIS database.

Where this breaks down in practice is referrals and telehealth. A provider at your FQHC refers a patient to an outside specialist. The specialist writes a prescription. Is that prescription 340B-eligible? It depends on whether the referring provider maintains the prescribing relationship or whether care was transferred. If your staff cannot answer that question consistently, your eligibility process has a gap.

Duplicate Discount Prevention

The duplicate discount prohibition is simple in concept and complicated in execution. You cannot claim both a 340B discount and a Medicaid rebate on the same drug unit. For in-house pharmacies using Medicaid carve-out, this is usually handled at the point of sale. For contract pharmacies, it requires active coordination between your TPA, the contract pharmacy, and your Medicaid billing team.

The risk area is fee-for-service Medicaid claims that slip through without being carved out. If your state uses a carve-in model for 340B, you need a reconciliation process that catches these within 30 days. Quarterly reconciliation is too slow. By the time you find the error, the rebate invoice has already gone to the manufacturer.

Contract Pharmacy Oversight

Having a contract pharmacy agreement on file is necessary but not sufficient. HRSA expects the covered entity to exercise meaningful oversight of every contract pharmacy arrangement. That means reviewing dispensing data, monitoring for diversion indicators, and confirming that the contract pharmacy is following your policies on patient eligibility and inventory management.

If your oversight of contract pharmacies consists of receiving a monthly report that nobody reads, you have a compliance exposure. Assign a staff member to review contract pharmacy data quarterly and document the review. That documentation is what the auditor will ask for.

Build It Into Operations, Not On Top of Them

The best compliance programs I have seen do not feel like compliance programs. They feel like normal pharmacy operations that happen to produce clean audit trails. The eligibility check happens automatically at intake. The duplicate discount prevention runs at the point of sale. The contract pharmacy review is a standing item on the monthly pharmacy operations meeting agenda.

That is the goal. Not a compliance department that polices the pharmacy. A pharmacy operation that is inherently compliant because the workflows were designed that way from the start.