10 Aug What a 340B Compliance Partner Should Be Accountable For
Covered entities bring in compliance partners for a reasonable reason. The work is continuous, the expertise is specialized, and internal teams are already stretched. What goes wrong is not the decision to bring someone in. It is a scope that never says out loud who is answerable for what. We have walked into programs where three vendors each believed a fourth party was watching the same control. This post is about writing the engagement so that cannot happen.
Who Is Responsible for 340B Compliance?
The covered entity is. That is not a caveat to read past. Registration sits with the entity, recertification sits with the entity, and when HRSA audits, it audits the entity. A compliance partner can do the work, build the controls, run the monitoring, and defend the findings. The partner cannot absorb the responsibility, and any partner who implies otherwise has told you something important about how they operate.
What that means practically is that a good compliance engagement is designed around a named internal owner, not around the vendor. The partner’s job is to make that person effective. If your compliance partner is the only party who understands your configuration, your controls, or your audit evidence, you have outsourced knowledge rather than capacity, and you will feel it the first time the relationship changes.
Inside the entity, responsibility is usually split across pharmacy, finance, compliance, revenue cycle, and IT. None of those departments owns the whole program. Someone has to, and our 340B compliance monitoring engagements are built to sit alongside that person rather than in place of them.
Why the 340B Policy Fight Belongs in Your Scope
The dispute over the program’s reach, contract pharmacy arrangements and manufacturer data demands above all, is its own subject, and we cover it properly in our 2026 state of 340B compliance briefing and in our August post on 340B program management. What matters for this post is what the instability does to the job you are hiring for.
In a stable regulatory environment, a compliance partner is largely a monitoring function. In this one, the partner also has to be a sensing function, tracking manufacturer notices, distribution conditions, state contract pharmacy laws, and data submission requirements, and translating each into whether anything about your operation needs to change. A partner who only reports on last month’s claims is solving half the problem. Our running commentary on why 340B compliance feels harder than it should is largely about this shift.
What a 340B Compliance Partner Should Own
Write the scope as a list of deliverables with owners, not as a description of a service. Five items belong on it.
Independent monitoring. The partner reviews accumulation, replenishment, and dispense data on a defined cadence and reports exceptions, including exceptions that reflect badly on prior work. If the partner also sold you the software producing the data, say out loud how independence is preserved.
Self audit execution and documentation. The partner designs the sample, runs it, and produces evidence a reviewer could follow. Sample design is where competence shows. A sample that only tests easy claims produces comfortable reports and no protection.
Policy maintenance. Policies are living documents that need to track the program’s actual footprint. The partner should be revising them, not filing them.
Regulatory monitoring with a translation step. Not a newsletter. A short written answer to the question of whether a given development changes anything for this entity.
Audit response readiness. The partner should be able to produce the evidence package for any registered site on request, and should have rehearsed doing it.
Write each of those five with a responsible party and an accountable party named, and make sure the accountable party is always someone inside your organization. The exercise takes an afternoon and it surfaces the disagreements early, which is the entire point. Most of the scope disputes we see in year two of a partnership were visible in the first draft of the scope in year one, and nobody wanted to slow the signing down to resolve them.
Two Ways to Split the Work
There are two workable shapes for this relationship and one that fails reliably.
Co-sourced monitoring means the partner runs the analytics and the sampling while your internal owner runs the decisions and the remediation. The partner brings pattern recognition across many programs, and your team keeps the institutional knowledge about why your program is configured the way it is. This is the shape we recommend for most health systems with a functioning pharmacy operation, because it builds capability rather than dependence.
Fully outsourced monitoring means the partner runs the whole compliance function and reports into a governance committee. It suits smaller grantees and entities that genuinely cannot staff the work. It requires more discipline, not less, because your governance committee has to be able to challenge the reports it receives. If nobody in the room can ask a hard question about sample design, the oversight is decorative.
The shape that fails is undefined co-sourcing, where the partner assumed you were reviewing the exceptions and you assumed the partner was closing them. Every finding we have seen produced by a well resourced program with a well regarded vendor traced back to this. Nobody was negligent. The seam between two competent parties simply had no owner.
Scoping the Engagement Before You Sign
Three parts of the scope are worth more attention than they usually get.
Cadence and depth. Monthly exception review and quarterly sampling are different products with different prices. Agree on both, in writing, including sample sizes.
Escalation. Define what happens when the partner finds something material. Who is told, how fast, in what form, and what the partner is expected to recommend. An unescalated finding is worse than no finding, because it establishes that you knew.
Independence from your other vendors. If your compliance partner, your TPA, and your split billing vendor are the same organization or are commercially entangled, the monitoring is not independent. That is not automatically disqualifying, but it has to be named and managed rather than discovered later.
Our comparison of 340B consulting against the alternatives walks through where each model fits, including the cases where building internally beats buying.
Signals the Partnership Is Working
You can tell within two quarters. The partner is producing findings, and the findings are getting closed rather than restated. Your internal owner can explain the program without the partner in the room. Documentation for any site can be assembled in days rather than weeks. And when a manufacturer or a state changes something, you hear about it from your partner with a recommendation attached, rather than from a colleague at another health system.
Ask about the ending as well as the beginning. A good partner will tell you what offboarding looks like, which documentation and analytic logic transfers to you, and in what format. A partner who has never been asked that question will improvise an answer, and the improvisation tells you how much of your program currently lives in their environment rather than yours. We would rather have that conversation in the first month than the last one.
The evidence we point to on our own side is exposure. We have supported 148 HRSA 340B audits, a count published on our own site, and that pattern library across many programs is what a compliance partner is actually selling. Ask any firm you are considering for its equivalent number, and ask what it counts as a success.
Frequently Asked Questions
What is 340B compliance?
340B compliance is the state of being able to demonstrate, with records, that every drug purchased at 340B pricing went to an eligible patient of a properly registered site, that no drug generated both a 340B discount and a Medicaid rebate, and that the entity has met its registration, recertification, and record retention obligations. The demonstration matters as much as the underlying fact. Our 340B compliance best practices post covers what that evidence looks like in practice.
Who are 340B covered entities?
Covered entities are the specific hospital and federal grantee categories Congress made eligible, from disproportionate share and critical access hospitals to federally qualified health centers and Ryan White clinics. Which category an entity falls into matters, because purchasing rules differ by category. The full list, and what each category is permitted to do, is in our primer on 340B program eligibility.
Next Steps
If you are scoping a compliance partner, the most useful hour you can spend is writing down who owns each control today, honestly, before you ask anyone to bid. We are happy to be measured against that list. Evaluate Ponaman as your 340B compliance partner and bring the awkward version of your org chart.
