Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
The six red flags that pull grant auditors into a treatment center
Grant scrutiny at a behavioral health facility is typically triggered by six fraud, waste, and abuse (FWA) red flags: unallowable cost allocations under 2 CFR 200 Subpart E, ghost personnel or time-and-effort discrepancies, duplicative billing between grant funds and Medicaid, subrecipient monitoring failures, inadequate cost-share documentation, and single-audit findings under 2 CFR 200 Subpart F. Operators who segregate grant revenue in the general ledger, document allocations at the transaction level, and run quarterly internal audits materially reduce their exposure to the HHS Office of Inspector General (OIG) and state pass-through auditors.
The Oroville case out of California, where a treatment provider drew oversight after alleged misuse of roughly $1.5M in public funds, is not an outlier. It is the pattern. Federal enforcement is scaling. The Fall 2024 Semiannual Report to Congress highlights over $7 billion in expected recoveries and receivables resulting from HHS-OIG investigations and audits conducted during fiscal year (FY) 2024. In FY 2024, HHS-OIG reported 1,548 criminal and civil enforcement actions against individuals and entities suspected of engaging in crimes targeting HHS programs and the people they serve, and excluded 3,234 individuals and entities from participation in Federal health care programs.
Christi Grimm, HHS Inspector General, put the posture plainly in the Spring 2024 report: “To hold wrongdoers accountable, OIG doggedly pursues criminals whose schemes put federal funds at risk and endanger the public.” If your organization touches a State Opioid Response (SOR) dollar, an MHBG allocation, a SUBG pass-through, or an HRSA rural opioid award, that posture applies to you.
Why grant dollars are the next enforcement frontier for SUD and mental health operators
The money at stake is enormous, and auditors follow the money. Since fiscal year 2018, the Substance Abuse and Mental Health Services Administration (SAMHSA) has awarded about $8.1 billion in SOR grants and $307.5 million in TOR grants nationwide. SAMHSA allocated more than $1.5 billion in FY25 continuation funding awards for the State Opioid Response (SOR) and Tribal Opioid Response (TOR) grants. Add the Community Mental Health Services Block Grant (MHBG) and the Substance Use Prevention, Treatment, and Recovery Services Block Grant (SUBG), and most multi-state operators are handling federal dollars at a scale that puts them squarely inside 2 CFR Part 200.
The single-audit trigger has changed. Operators who used the old $750,000 figure are working from stale guidance. For decades, any non-federal entity that expended $750,000 or more in federal awards during its fiscal year was required to have a Single Audit. OMB raised that threshold to $1,000,000 for audits covering fiscal years beginning on or after October 1, 2024. A mid-sized SUD operator running SOR pass-throughs in Texas or Florida, plus an HRSA rural opioid subaward, can clear that line without noticing.
GAO has already flagged SAMHSA oversight gaps that make individual grantees more exposed to downstream audit findings, not less. When the funder’s own controls are under GAO review, the recipient becomes the easier target.
What OIG and state auditors actually pull when they knock
The document requests are predictable. I have watched them land at facilities in Florida, Ohio, and Arizona, and the list barely changes.
- Time and effort certifications. Signed, dated, matched to payroll journals, and reconciled to the effort actually charged to the grant. Ghost personnel and after-the-fact allocations are the fastest way to a finding.
- Cost allocation methodology. Written, approved, applied consistently. If your CFO cannot walk an auditor through how a shared clinical director’s salary splits between an SOR-funded IOP cohort and a Medicaid PHP census, you have a problem.
- Procurement files. Sole-source justifications, competitive quotes, conflict-of-interest disclosures. Under the 2024 revisions, a requirement was added that recipient and sub-recipient internal controls include cybersecurity and other measures to safeguard information.
- Subrecipient monitoring evidence. Risk assessments, site visits, review of subrecipient single audits. Regardless of whether audit requirements apply, pass-through entities should monitor subrecipients consistent with requirements in 2 C.F.R. Part 200.
- Duplicative billing crosswalks. Proof that services paid by SOR were not also billed to Medicaid or a commercial payer. This is where FWA cases get built.
- Schedule of Expenditures of Federal Awards (SEFA). Complete, tied to the general ledger, reconciled to draw-downs in the Payment Management System.
If your team cannot produce these inside 10 business days, you are not audit-ready. You are hoping.
The internal controls that keep operators out of a False Claims Act file
The False Claims Act (31 U.S.C. §§ 3729 to 3733) is the enforcement tool that turns a documentation gap into a treble-damages settlement. Grant funds, Medicaid claims, and cost-share representations are all “claims” under the statute. A duplicative bill between an SOR-funded MOUD induction and a Medicaid E/M code is not a paperwork error to the DOJ. It is a false claim.
Operators who have survived post-award monitoring cleanly do a few things consistently. Their CFOs segregate every federal award into its own project code in the general ledger, so that a query returns grant-specific expenditures without reconstruction. Their compliance officers reconcile time and effort monthly, not annually. Their clinical leaders sign off on service logs before the billing team codes anything. Their executive teams treat the GAO Green Book (Standards for Internal Control in the Federal Government) as an operating checklist, not a theoretical document.
One accounting reference frames the mechanics well: the organizations that struggle the most are the ones that comingle federal and non-federal money in a single program code, then try to reconstruct grant-specific expenditures after the fact. The ones who pass cleanly built tracking discipline into their accounting from day one.
At Atlantic Health Strategies, when we run an operational audit against grant compliance, we are looking for the disconnects between four systems: the general ledger, the payroll allocation, the EMR service record, and the claim submitted to Medicaid. If those four do not tie out, the FWA risk is already there. The auditor just has not arrived yet. The recent Joint Commission accreditation our team helped earn across five facilities in three states, covering three different levels of care, came out of that same four-system discipline. Grant readiness and accreditation readiness live in the same file.
Frequently asked questions
What documentation do federal grant auditors expect from a behavioral health facility during post-award monitoring?
Expect requests for the executed Notice of Award, approved budget and any rebudget approvals, the Schedule of Expenditures of Federal Awards, general ledger detail by project code, time and effort certifications, procurement files with sole-source justifications, subrecipient monitoring records, cost allocation plans, and any indirect cost rate agreement. Under 2 CFR 200 Subpart E, every charge to the grant must be allowable, allocable, reasonable, and adequately documented.
How should operators segregate grant revenue from Medicaid and commercial payer revenue in the general ledger?
Assign each federal award its own project or class code. Post revenue and expense to that code only. Never let a shared cost hit the grant without a written allocation methodology that ties to time studies, square footage, or census. When your CFO runs a report for Award No. 2025-XYZ, the expenditures should pull in minutes with source documentation attached to every line.
When does a behavioral health provider trigger a single audit under 2 CFR 200 Subpart F?
Under 2 CFR 200.501, a non-federal entity that expends $1,000,000 or more in federal awards during a fiscal year beginning on or after October 1, 2024 must have a single audit or permitted program-specific audit. The test is expenditures, not receipts, and it aggregates every federal source including pass-throughs from state agencies.
What are the most common unallowable costs charged to SAMHSA block grants?
Lobbying, entertainment, alcohol, fundraising, bad debt, fines and penalties, and executive compensation above the statutory cap. We also see misclassified marketing spend, staff bonuses tied to census rather than performance, and shared administrative costs pushed to the grant without a documented allocation base. Each of these is a repeat finding in OIG audits of SAMHSA recipients.
How should a PE buyer diligence grant compliance risk in a target treatment center?
Pull three years of single audits from the Federal Audit Clearinghouse. Read every finding and every corrective action plan. Request the target’s Notice of Award files, indirect cost rate agreement, and time and effort methodology. Reconcile SOR and block grant draw-downs to the general ledger. If the target has ever received a management decision letter from a pass-through state agency, read it. Grant compliance liability transfers, and the FCA statute of limitations reaches back six years.
References
- HHS-OIG Fall 2024 Semiannual Report to Congress: $7.13 Billion in Expected Recoveries
- HHS-OIG Spring 2024 Semiannual Report to Congress
- SAMHSA: HHS Provides More Than $1.5 Billion in FY25 State and Tribal Opioid Response Grants
- GAO-25-106944: Opioid Use Disorder Grants Oversight Report
- 2 CFR Part 200 Subpart F, Audit Requirements (eCFR)
- Single Audit Resource Center: 2024 Threshold Change to $1,000,000
- HHS OIG Semiannual Reports to Congress (Archive)