IconIcon

Diversion and Duplicate Discounts Rarely Start as Mistakes

September 3, 2026

When diversion shows up in a 340B program, it's almost never intentional. It's usually the result of eligibility logic inside a TPA that's quietly broader than the covered entity realizes. The fix isn't a values problem. It's a monitoring problem, and it's one that needs to be built into policy, not treated as a background assumption.

What Diversion Actually Looks Like

The most common pattern is a provider who is eligible at one registered location, while the TPA is capturing 340B-eligible prescriptions from every location that provider works at, without fully validating that each one involved a qualifying encounter. This shows up especially often in contract pharmacy arrangements, where the connection between a claim and an actual patient encounter is a step removed from the point of dispensing.

Testing claims back to an actual encounter date is what catches this. It confirms that the eligibility logic your TPA is applying actually matches what your policy defines as an eligible encounter, rather than assuming the software is doing that work correctly on its own.

For mixed-use settings, the risk looks a little different. The most common issue is inpatient and outpatient activity that isn't cleanly separated, or patient status changes, reversals, returns, and inventory adjustments that don't flow through the system the way they're supposed to. Routine monitoring built specifically around these transitions is what catches the gap before it becomes a pattern.

What Duplicate Discount Risk Looks Like

Duplicate discounts are a more complicated risk to manage, largely because Medicaid billing requirements vary by state. Understanding the specific requirements in every state where you bill Medicaid, and confirming your carve-in and carve-out elections are accurate and consistent across every system, including billing, pharmacy, and TPA platforms, is the starting point.

In a contract pharmacy environment, this typically means validating your Medicaid Exclusion File, reviewing claims that could have been billed to Medicaid, and reconciling dispensing data against billing records. The goal isn't to eliminate every possible risk. It's to build a process that identifies risk early, and gives your team a clear, repeatable way to review, document, and correct it when it appears.

Building a Monitoring Process That Holds Up

A few practices make diversion and duplicate discount monitoring something you can actually point to during an audit, rather than something you describe in general terms.

Trace claims to actual encounters, not just system flags. Don't rely on the TPA's eligibility determination as the final word. Periodically confirm it against the underlying encounter data.

Separate inpatient and outpatient logic explicitly in mixed-use settings. Build monitoring specifically around status changes, reversals, and returns, since these are where mixed-use tracking tends to break down.

Document your state-by-state Medicaid position. Know which states you bill Medicaid in, what each one requires, and confirm your carve-in and carve-out elections are identical across every system that touches a claim.

Write the review process into policy. Monitoring that exists informally, without a documented cadence or method, is difficult to defend during an audit even when it's genuinely happening.

How RxTrail Handles It

We help covered entities build monitoring processes that connect TPA eligibility logic back to actual encounter data, and that account for the state-by-state variation in Medicaid billing requirements. The covered entity's job is running the program day to day. Ours is making sure the monitoring behind it is structured well enough to catch problems while they're still small.

Diversion and duplicate discount risk are two of the areas where the gap between a well-intentioned program and a compliant one tends to show up. A documented, consistently applied monitoring process is what closes that gap.

Related Content