Medicare Cost Report Pre-Audit QA API Reference

Beta. Pre-audits one hospital cost report (Form CMS-2552-10): the ECR file against the record specifications and level 1 edits in CMS Pub. 15-2, chapter 40, section 4095; the ties between Worksheets S, A, B, C, D and E; Worksheet S-10 line by line; the Exhibit 2A, 3B and 3C listings against the amounts claimed and 42 CFR 413.89; and the deadline in 42 CFR 413.24(f)(2). A math check: it does not judge allowability. Product page and free test form.

Endpoint

PaidPOST https://www.spreadrun.com/api/v1/hcris-preaudit-qa, API key required, $200.00 per completed pre-audit
DemoPOST https://www.spreadrun.com/api/demo/hcris-preaudit-qa, no key, 10 runs per day. Runs the two published sample packages only (clean, with errors), byte for byte. Their listing dates are shifted back 1,000 days, so send periodStart=2021-09-05&periodEnd=2022-09-04; add asOf=2025-10-15 to see the deadline as it stood before it passed.
BodyA .zip with the ECR file and the listings, or the ECR file alone, up to 4 MB. The check stops after about 20 seconds with a plain message and no charge.
Checked againstCMS Pub. 15-2, chapter 40, Transmittal 26 (June 30, 2026), ECR specification 2026181. Printed in every report as checkedAgainst.

Parameters

periodStartRequired. YYYY-MM-DD, the first day of the cost reporting period, shifted by the same number of days as the listing dates. Refused if it is the real date (the listings would not be shifted).
periodEndRequired. YYYY-MM-DD, the last day of the period, shifted the same way. The two must be as far apart as the real period in the ECR file.
asOfOptional. YYYY-MM-DD to measure the deadline from, a real date. Default: today (UTC). The deadline is the last day of the fifth month after the real period end in the ECR file, or 150 days after it when it is not a month end.

Any other parameter is refused, so a typo never changes the result quietly.

The package

Files are recognized by content, not by name. Listings are .xlsx in the CMS template layout, or .csv laid out in the same grid (the exhibit identifier in A1 and B1, the header labels in column A with values in column B, then the column labels and the column number row). Sheets without the identifier are ignored, as MCReF ignores them.

ECR fileExactly one. Found by its first record (type 1, record number 1), whatever its name. A body that is not a .zip is read as the ECR file alone.
Exhibit 2A"Supporting Exhibit" in A1 and "Medicare Bad Debt Listing" in B1. One listing for inpatient and one for outpatient (header IP or OP), per CCN.
Exhibit 3B"Supporting Exhibit" in A1 and "Charity Care Charges" in B1. One per CCN; Component CCN blank for the hospital.
Exhibit 3C"Supporting Exhibit" in A1 and "Total Bad Debt" in B1. One per CCN; Component CCN blank for the hospital.
Prior-year listingsAny of the above with an FYE before periodStart, shifted by the same number of days. Used only to find accounts claimed again.

Which listings are required comes from the cost report: Exhibit 2A when Worksheet E, Part A, line 64, Part B, line 34 or S-10, line 27.01 claims Medicare bad debts; Exhibit 3B when S-10, line 20 claims charity care; Exhibit 3C when S-10, line 26 reports bad debts. A sole community hospital whose Worksheet E, Part A, line 48 is greater than line 47 does not need 3B or 3C.

Patient data

The pre-audit does not accept PHI. Before upload, in your own copy of the listings: replace every account number with a pseudonymous row ID, the same for the same account across listings and years; delete the patient name and MBI columns (columns 1, 2 and, on Exhibit 2A, 6), or leave them blank; put Y in Exhibit 2A column 7 instead of a Medicaid number; and shift every date, including the FYB and FYE header cells, by one number of days of your choosing. Send the period shifted by the same number. The ECR file goes as it is.

Every listing check counts days between dates, so a uniform shift leaves the findings unchanged. The real period comes from the ECR file and is used for the format checks and the deadline only. The engine compares it with the shifted period for two things and nothing else: a listing period equal to the real one is refused as not shifted, and a period whose length differs is refused as not shifted as a block. The offset is never worked out, kept or reported.

Refused before any check, with the file, row and column and no charge: an MBI pattern, a HICN, a Social Security number, an account or Medicaid number pattern (8 or more digits in a row), text that reads like a patient name (Last, First; Mr. or Mrs. and a name; DOB, SSN or MRN labels; two words as an account ID), anything in the name or MBI columns, and a Medicaid number other than Y. The value itself is never repeated. If no write-off date falls inside the period entered, one LIST-SHIFT warning says the period and the listings were probably shifted by different numbers.

Reports contain no dates. Listing findings give the row number and your row ID, and state positions in days (for example, 63 days after the first bill, or 9 days after the period ends).

Report

FieldMeaning
status, summaryFAIL if any error, WARN if only warnings, otherwise PASS. A PASS is not MAC acceptance and does not determine allowability or payment.
checkedAgainstThe transmittal and ECR specification the run was checked against.
fileCCN, the ECR specification date in the file, and record counts.
periodDaysThe length of the cost reporting period in days.
deadlinedaysLeft (negative when late), measuredFrom (today or the asOf date you sent), status (on-time, late, or unknown when the ECR file has no readable period) and the rule. No dates.
checksecrFormat, crossTies, s10, listings and deadline, each pass, warn, fail or na.
listingsfound (exhibit, file, IP or OP, component, rows), required, status per exhibit, priorClaimCheck and priorYearListings.
tiesCheckedHow many amounts were recomputed or compared.
findingsErrors first, up to 400.
notChecked, sources, scope, input, inputSha256What the report does not cover, where the rules come from, what the verdict means, and a fingerprint of the package.

Each finding

severityerror or warning. Any error makes the report FAIL; warnings alone make it WARN.
ruleIdOne of the rule IDs below.
groupecrFormat, crossTies, s10, listings or deadline: the check it counts toward.
worksheet, line, columnWorksheet findings: for example S-10, Part I, line 30, column 1.
exhibit, file, row, columnListing findings: the exhibit, the file name in the package, the spreadsheet row and the exhibit column number. A finding about an account names its row ID.
record, positionsECR format findings: the record number in the file and the character positions.
expected, actualAmounts, where the finding compares two. Expected is what the rule or the other worksheet says; actual is what was filed.
messageWhat is wrong, in plain words. Never repeats text from the files other than your row IDs, and never a date.
sourceA key in sources.

Rule IDs

RuleSeverityMeaning
ECR-10000 to ECR-11000errorThe level 1 edits of Table 6 with the same number: record type, length, upper case, line feeds, CCN, Julian dates, period, record identifiers, numeric line numbers, labels.
ECR-MCR-VERSIONerrorRecord 1, position 37 is not 1, so the file is not a Form CMS-2552-10 file.
ECR-S2-PERIODerrorThe period in record 1 and on Worksheet S-2, line 20 do not agree.
ECR-SPEC-DATEwarningThe ECR specification date is not an approved one, or is older than the one in effect for the period end.
ECR-TYPE4warningThe three type 4 records (encryption and time stamp) are missing.
TIE-A-B, TIE-B-TOTAL, TIE-B-CerrorWorksheet A to B, the B step-down total, B column 26 to C column 1.
TIE-C-FOOT, TIE-C-202, TIE-C-CHARGESerrorWorksheet C, Part I totals, line 202, and total charges as inpatient plus outpatient.
TIE-D-EerrorWorksheet D, Part V, line 202, columns 6 and 7 to Worksheet E, Part B, line 1.
TIE-E-BADDEBT, TIE-E-DUALerrorWorksheet E bad debts: the 65 percent line, and dual eligible within the total.
S10-CCRerrorS-10 line 1 is not the Worksheet C cost-to-charge ratio (Part II without the excluded units).
S10-LINEerrorAn S-10 line that does not recompute from the lines it is built from.
S10-E-TIEerrorS-10 lines 27 and 27.01 against Worksheet E and the other bad debt worksheets.
S10-14000S to S10-14020S, S10-PART2-SUBSETerrorThe S-10 edits of Table 6, and Part II amounts above Part I.
LIST-MISSINGerrorA listing the cost report calls for is not in the package (42 CFR 413.24(f)(5)).
LIST-HEADER, LIST-FORMATerrorA listing header with the wrong CCN or period, or a date or amount that cannot be read.
LIST-S2-12warningWorksheet S-2, Part II, line 12 says bad debts are claimed but none are.
LIST-SHIFTwarningNo write-off date falls inside the period entered: the period was probably not shifted like the listings.
BD-TIE, CC-TIE, TBD-TIEerrorA listing that does not add up to the worksheet line it supports.
BD-DUPLICATE, CC-DUPLICATE, TBD-DUPLICATEerrorThe same account and dates of service listed twice.
BD-PRIOR, CC-PRIOR, TBD-PRIORerrorAn account already on last year's listing.
BD-WRITEOFF-PERIOD, CC-WRITEOFF-PERIOD, TBD-WRITEOFF-PERIODerrorA write-off date outside the cost reporting period.
BD-120-DAYSerrorWritten off less than 120 days after the first bill (42 CFR 413.89(e)(2)(i)(A)(5)).
BD-BILL-120errorFirst bill more than 120 days after the remittance advice (42 CFR 413.89(e)(2)(i)(A)(3)).
BD-CAPerrorAllowable bad debt above the deductible and coinsurance less payments and recoveries.
BD-REQUIRED, BD-DATES, BD-DUALerrorA required Exhibit 2A column is empty, write-off dates are out of order, or a dual eligible row has no Medicaid remittance date.
BD-RECOVERY, BD-INDIGENT, BD-HEADER-TOTALwarningA recovery not entered as a negative, an indigent beneficiary with a responsibility amount, or a header total that does not match the rows.
CC-SUM, CC-STATUS, CC-DEDUCTIBLE, CC-CHARGES, CC-REQUIREDerrorExhibit 3B rows: column 20 as 17 plus 18 plus 19, the columns each insurance status uses, column 19 within column 11, charity within charges net of physician charges and payments.
TBD-CAP, TBD-STATUS, TBD-REQUIREDerrorExhibit 3C rows: column 17 within the prorated cap, valid status and service indicator, required columns.
DEADLINE-LATEwarningPast the due date (42 CFR 413.24(f)(2)).

Source keys, as returned in every report:

413.24(f)(2)42 CFR 413.24(f)(2), due dates for cost reports
413.24(f)(5)42 CFR 413.24(f)(5)(i)(B) and (D), cost report rejected without the bad debt and charity care listings that correspond to the amounts claimed
413.24(f)(5)(ii)42 CFR 413.24(f)(5)(ii), the ECR file must conform to the ECR Specifications Manual
413.8942 CFR 413.89(e) and (f), criteria for allowable Medicare bad debt and the period of write-off
ecr-t1CMS Pub. 15-2, chapter 40, section 4095, Table 1, record specifications
ecr-t6CMS Pub. 15-2, chapter 40, section 4095, Table 6, edits
s10CMS Pub. 15-2, chapter 40, section 4012.1, Worksheet S-10 line instructions
ex2aCMS Pub. 15-2, chapter 40, section 4004.2, Exhibit 2A, and the CMS Exhibit 2A specification
ex3bCMS Pub. 15-2, chapter 40, section 4012.2, Exhibit 3B, and the CMS Exhibit 3B specification
ex3cCMS Pub. 15-2, chapter 40, section 4012.2, Exhibit 3C, and the CMS Exhibit 3C specification
wbCMS Pub. 15-2, chapter 40, section 4020, Worksheet B, Part I
wcCMS Pub. 15-2, chapter 40, section 4023.1, Worksheet C, Part I
weCMS Pub. 15-2, chapter 40, sections 4030.1 and 4030.2, Worksheet E, Parts A and B

Not checked

  • Whether any cost, bad debt or charity care amount is allowable, or what Medicare will pay. That is the MAC's judgment, and a PASS does not decide it.
  • Cost finding choices: statistics, allocation bases, reclassifications and adjustments are taken as filed.
  • Collection effort documentation, indigence determinations, Medicaid remittance advices and the bad debt collection policy. Only the dates and amounts in the listings are checked.
  • Whether the listings match your patient accounting system.
  • The type 4 encryption code. Only approved vendor software can produce it; the check confirms the records are there.
  • Listings for components other than the hospital (subprovider, SNF and other CCNs) are checked row by row but not tied to their worksheets.
  • Worksheets and edits outside this list: the full set of level 1 and level 2 edits runs in your vendor software and again at the MAC.

Example responses

A paid pre-audit of the clean sample, and the findings from a demo run of the sample with errors. Both generated by running the real endpoint code.

{
  "requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
  "api": "hcris-preaudit-qa",
  "mode": "paid",
  "charged": true,
  "priceCents": 20000,
  "balanceCents": 30000,
  "report": {
    "schemaVersion": 1,
    "status": "PASS",
    "summary": "The ECR file is in the CMS format, the worksheets tie, S-10 recomputes and the listings support the amounts claimed. Ready to file, as far as these checks go.",
    "checkedAgainst": {
      "transmittal": "CMS Pub. 15-2, chapter 40, Transmittal 26 (June 30, 2026)",
      "ecrSpecification": "ECR specification dated 2026181, valid for cost reporting periods ending on or after June 30, 2026, with the record layouts and edits in section 4095",
      "specDate": "2026181"
    },
    "file": {
      "ccn": "999208",
      "ecrSpecDate": "2024275",
      "records": 2567,
      "dataRecords": 2473,
      "labelRecords": 89,
      "type4Records": 3
    },
    "periodDays": 365,
    "deadline": {
      "daysLeft": 16,
      "measuredFrom": "the asOf date you sent",
      "status": "on-time",
      "rule": "The last day of the fifth month after the period ends, or 150 days after a period that ends mid-month (42 CFR 413.24(f)(2))."
    },
    "checks": {
      "ecrFormat": "pass",
      "crossTies": "pass",
      "s10": "pass",
      "listings": "pass",
      "deadline": "pass"
    },
    "listings": {
      "found": [
        {
          "exhibit": "2A",
          "file": "MedicareBD_IP_999208.xlsx",
          "kind": "IP",
          "component": false,
          "rows": 14
        },
        {
          "exhibit": "2A",
          "file": "MedicareBD_OP_999208.xlsx",
          "kind": "OP",
          "component": false,
          "rows": 8
        },
        {
          "exhibit": "3B",
          "file": "Charity_999208.xlsx",
          "kind": null,
          "component": false,
          "rows": 9
        },
        {
          "exhibit": "3B",
          "file": "Charity_component_999208.xlsx",
          "kind": null,
          "component": true,
          "rows": 2
        },
        {
          "exhibit": "3C",
          "file": "TotalBD_999208.xlsx",
          "kind": null,
          "component": false,
          "rows": 297
        },
        {
          "exhibit": "3C",
          "file": "TotalBD_component_999208.xlsx",
          "kind": null,
          "component": true,
          "rows": 1
        }
      ],
      "required": {
        "2A": true,
        "3B": true,
        "3C": true
      },
      "status": {
        "2A": "pass",
        "3B": "pass",
        "3C": "pass"
      },
      "priorYearListings": 0,
      "priorClaimCheck": {
        "2A": "not run: add last year's listing to the package",
        "3B": "not run: add last year's listing to the package",
        "3C": "not run: add last year's listing to the package"
      },
      "schExemptFromS10Listings": false,
      "unrecognizedFiles": 0
    },
    "tiesChecked": 823,
    "ruleCounts": {},
    "findingCount": 0,
    "findingCounts": {
      "error": 0,
      "warning": 0
    },
    "findings": [],
    "findingsTruncated": false,
    "scope": "A pre-audit math check: is the ECR file in the CMS format, do Worksheets S, A, B, C, D and E tie, does Worksheet S-10 recompute, and do the listings support what is claimed. A PASS is not MAC acceptance and does not determine allowability or payment.",
    "input": {
      "format": "zip",
      "bytes": 52765,
      "files": 7
    },
    "inputSha256": "38ba820af5f22bbe8f4ba3a2710764d438d0cb08cc31288f0770fc37bd15fa57"
  }
}
[
  {
    "severity": "error",
    "ruleId": "TIE-A-B",
    "message": "Worksheet B, Part I, column 0 must carry the total direct cost from Worksheet A, column 7, for the same line.",
    "source": "wb",
    "worksheet": "B, Part I",
    "line": "60",
    "column": "0",
    "expected": 1436978,
    "actual": 1441978,
    "group": "crossTies"
  },
  {
    "severity": "error",
    "ruleId": "BD-120-DAYS",
    "message": "Written off 60 days after the first bill. Collection effort must last at least 120 days after the first bill before the account is written off (42 CFR 413.89(e)(2)(i)(A)(5)).",
    "source": "413.89",
    "exhibit": "2A",
    "file": "MedicareBD_IP_999208.xlsx",
    "row": "23",
    "column": "17",
    "expected": "120 days or more",
    "actual": "60 days",
    "group": "listings"
  },
  {
    "severity": "error",
    "ruleId": "BD-BILL-120",
    "message": "The first bill went out 287 days after the later remittance advice. The beneficiary must be billed within 120 days of it (42 CFR 413.89(e)(2)(i)(A)(3)).",
    "source": "413.89",
    "exhibit": "2A",
    "file": "MedicareBD_IP_999208.xlsx",
    "row": "23",
    "column": "13",
    "expected": "120 days or fewer",
    "actual": "287 days",
    "group": "listings"
  },
  {
    "severity": "error",
    "ruleId": "BD-CAP",
    "message": "The allowable bad debt (column 23) is more than the deductible and coinsurance (columns 20 and 21) less recoveries and payments (columns 18 and 22). Medicare bad debt can only come from unpaid deductible and coinsurance.",
    "source": "413.89",
    "exhibit": "2A",
    "file": "MedicareBD_IP_999208.xlsx",
    "row": "29",
    "column": "23",
    "expected": "at most 1126.45",
    "actual": 1276.45,
    "group": "listings"
  },
  {
    "severity": "error",
    "ruleId": "LIST-MISSING",
    "message": "Worksheet S-10, line 20 claims charity care but no Exhibit 3B listing is in the package. A cost report is rejected without the listing that supports the charity care claimed (42 CFR 413.24(f)(5)(i)(D)).",
    "source": "413.24(f)(5)",
    "exhibit": "3B",
    "group": "listings"
  },
  {
    "severity": "error",
    "ruleId": "TBD-DUPLICATE",
    "message": "Account B0000005 is listed twice for the same dates of service (rows 18 and 19). Claim each account once.",
    "source": "ex3c",
    "exhibit": "3C",
    "file": "TotalBD_999208.xlsx",
    "row": "19",
    "column": "5",
    "actual": "account B0000005",
    "group": "listings"
  },
  {
    "severity": "error",
    "ruleId": "S10-LINE",
    "message": "Line 30 (cost of uncompensated care) must be line 23, column 3 plus line 29.",
    "source": "s10",
    "worksheet": "S-10, Part I",
    "line": "30",
    "column": "1",
    "expected": 453134,
    "actual": 465134,
    "group": "s10"
  }
]

Errors

See the shared error table. Rejected and not charged: a body that is not an ECR file or a .zip with one, a package over 4 MB (HTTP 413), more than one ECR file, a missing or malformed period, a period beginning before October 1, 2022, an unknown parameter, a listing with PHI patterns, a listing period that is not shifted or not shifted as a block, an .xls listing, a package too large to finish in time, and on the demo endpoint anything other than a sample package. Example, a PDF (HTTP 400):

{
  "error": {
    "code": "input_error",
    "message": "This is a PDF. Send the ECR file (the text file your cost report software exports for MCReF), or a .zip with the ECR file and the listings. Nothing was charged.",
    "requestId": "7f3c2a1e-5b8d-4c6f-9e0a-1d2b3c4d5e6f",
    "charged": false
  }
}

Code samples

curl -X POST "https://www.spreadrun.com/api/v1/hcris-preaudit-qa?periodStart=2022-10-04&periodEnd=2023-10-03" \
  -H "Authorization: Bearer $SPREADRUN_API_KEY" \
  -H "Content-Type: application/zip" \
  --data-binary @package.zip