# Citation Verification Statement

*HPI-CT — Healthcare Program Integrity Control Toolkit. Public-source, personal-capacity project maintained by Nicholas Nyarko. Current as of 2026-07-29.*

**Report a bad citation: focusfusionuniverse@gmail.com** — subject line "HPI-CT citation".

This statement says plainly what has been checked against primary sources, what has not, and what the known error rate is. It exists so that a reader can calibrate trust rather than take a blanket disclaimer at face value.

---

## 1. Summary

| Layer | Status |
|---|---|
| Framework numbering — COSO / GAO Green Book 17 principles | **Verified.** Component grouping and P1–P17 numbering confirmed (CE P1–P5 · RA P6–P9 · CA P10–P12 · I&C P13–P15 · Mon P16–P17). |
| COSO-ACFE Fraud Risk Management Guide, 5 principles | **Verified** against the 2nd edition (2023) — confirmed as the current edition. |
| OIG General Compliance Program Guidance, 7 elements | **Verified** against the November 2023 GCPG, including element order (the toolkit tags element numbers, so order is load-bearing). |
| 42 CFR citations in the control library | **Verified** — approximately 42 distinct sections checked against official eCFR / Cornell LII section titles. |
| Control-to-principle *mapping judgment* | **Not verifiable — editorial.** See §4. |
| Enforcement-case coding | **Partially verified.** See §5. |

## 2. Method

Each 42 CFR citation was resolved against the **official eCFR text or Cornell LII**, and the section's official title was compared with the use the toolkit makes of it — a citation "resolves" only if the real section is about what the control claims it is about. Framework numbering was checked against the standard-setters' own publications (COSO, GAO, ACFE, HHS-OIG). Statutory and rule identifiers for the newer controls were checked against congress.gov / govinfo and the Federal Register.

Verification records, with per-citation detail, are in the repository:

- `03_Toolkit/Framework_Citation_Verification_FULL_2026-07-16.md` — the full pass across all modules, the crosswalk, and the exports
- `03_Toolkit/Assessment_v3_Citation_Verification_2026-07-15_DRAFT.md` — Module 00 / v3 anchors
- `03_Toolkit/HPI-CT_New_Controls_Citation_Confirmation_2026-07-24_DRAFT.md` — the controls added after the full pass
- `03_Toolkit/Module_08_Citation_Confirmation_2026-07-22_DRAFT.md` — AI & analytics governance identifiers

## 3. Findings and known error rate

The 2026-07-16 full pass found, across ~42 distinct CFR sections:

- **one** citation requiring a precision refinement — 422.2440 / 423.2440 corrected to **422.2460 / 423.2460** (MLR reporting). Corrected across Module 06, the crosswalk, and the regenerated exports on the same day.
- **one** section flagged for a final eyeball — 410.32 — subsequently confirmed against eCFR.
- **zero** citations found substantively wrong.

**Known error rate at the last full pass: 1 imprecise citation in ~42 sections (~2.4%), 0 substantively incorrect. Both findings are resolved; zero are outstanding.**

**Coverage gap, stated honestly.** The full pass was run when the toolkit held **141 controls and 195 questions**. It now holds **160 controls and 204 questions**. The 19 controls and 9 questions added since are covered by the two later per-batch confirmation records listed above, not by a fresh end-to-end pass. A full re-verification at the current count has **not** been run. Treat the ~2.4% figure as the rate measured on the 141-control set.

## 4. What is *not* a citation-accuracy question

Verifying that 42 CFR 424.57(c) exists and is about DMEPOS supplier standards is a factual check, and it passed. Deciding that a particular assessment question best satisfies **Green Book P10 rather than P12** is an **editorial mapping judgment**. Those judgments are one practitioner's reasoning. They are exactly what subject-matter review is for, and they are not claimed as verified. The same applies to lifecycle-stage assignment, which is partly heuristic and should not be quoted as a precise statistic.

## 5. Enforcement-case coding

Case coding — scheme category, lifecycle stage, COSO/Green Book component, and the control mapped to the failure — follows `04_Evidence_DOJ_Analysis/Case_Base/Coding_Rulebook.md` v1.0.

A full-dataset conformance audit against that rulebook returned **90.6% full-tuple agreement** (stage 94.7% / component 97.1% / module 93.0%), with residuals mostly documented sub-scheme splits — see `Coding_Consistency_Check_2026-07.md`.

**This is a self-consistency measure, not an inter-rater reliability measure.** A blind independent recode of a 50-case sample with Cohen's kappa is planned and **has not been done**. Until it is, single-coder subjectivity remains the project's largest methodological exposure, and case-derived statistics should be read with that in mind.

Because the published case data is de-identified (see [`CORRECTION_POLICY.md`](CORRECTION_POLICY.md) §2), published rows do not carry source URLs. Verification of a specific coding is available on request through the maintainer-held source crosswalk.

## 6. What we ask of you

Citations are the project's credibility. If you find one that is wrong, imprecise, superseded, or that does not support the statement attached to it, **please report it** to focusfusionuniverse@gmail.com. Reports are verified against primary sources and corrected on the same schedule as the [correction policy](CORRECTION_POLICY.md) — acknowledged within 7 days, resolved within 30.

Regulations change. A citation verified in July 2026 may be superseded later; the monthly source-change monitors exist to catch this, and they are not infallible. **Confirm any citation against the primary source before relying on it operationally.**

---

*Everything in this project is a working draft. Not legal advice; not an official or endorsed standard; not a certification of compliance. See [`SCOPE_AND_LIMITATIONS.md`](SCOPE_AND_LIMITATIONS.md).*
