DRL (Data Request List)
Definition
The Data Request List (DRL) is one of the first documents a covered entity receives when selected for an HRSA audit. It specifies the categories of documentation and data the auditor needs to review, typically including eligibility and registration records, policies and procedures, purchasing and dispensing data, contract pharmacy agreements, Medicaid billing information, and evidence of diversion and duplicate discount prevention controls.
The DRL defines the scope of the audit and the documentation the covered entity must organize and produce within the specified timeframe. Covered entities that are audit-ready can respond to a DRL efficiently; those that are not may struggle to gather required documentation within the response window.
The DRL is a practical tool for understanding what HRSA expects to see during an audit. Covered entities can use HRSA’s published DRL templates to assess their own audit readiness by evaluating whether they could respond to each item on the list.
Frequently Asked Questions
Why DRL (Data Request List) Matters
The DRL defines what a covered entity must produce in an HRSA audit. Knowing what the DRL typically includes allows covered entities to proactively organize their documentation and assess audit readiness before an official audit notice arrives.
How Virtue 340B Uses It
Virtue 340B uses HRSA's DRL structure as a framework for our mock audits and audit readiness assessments, ensuring that covered entities are prepared to respond to each category of documentation request.