Internal Controls (340B)
Definition
Internal controls are the operational safeguards that protect a covered entity’s 340B program from compliance failures. They include both preventive controls (designed to stop violations before they occur) and detective controls (designed to identify violations after they have occurred so they can be corrected).
Examples of internal controls include: patient eligibility screening in split-billing software before each transaction; regular reconciliation of purchasing data against dispensing records; periodic review of contract pharmacy transaction data; Medicaid billing designation reviews; staff training and competency assessments; and periodic internal audits of program operations.
Strong internal controls are the difference between a compliant program and an audit-ready program. A compliant program avoids violations. An audit-ready program can also demonstrate that it has systems in place to prevent and detect violations—which is what HRSA expects to see.
Frequently Asked Questions
Why Internal Controls (340B) Matters
HRSA auditors evaluate not just whether violations occurred, but whether the covered entity had adequate controls to prevent them. Weak internal controls are a finding in themselves, even if no specific violations are identified.
How Virtue 340B Uses It
Virtue 340B assesses the design and effectiveness of internal controls as part of every audit engagement. We identify control gaps, evaluate whether existing controls are operating as intended, and recommend improvements that strengthen the entity's compliance posture.