September 24, 2026

The Complete Guide to Medical Billing Audits: How to Ensure Compliance and Protect Your Practice Revenue

Emily Foster

RCM Expert | Content Strategist in Healthcare | Swiftcare Billing

Common Medical Billing Errors That Are Quietly Killing Your Revenue

Faster Cash Flow. Fewer Denials. More Revenue.

Denial of your claims reduced by up to 99% through professional billing that will see you paid promptly, every time.
Reading Time: 6 minutes

Let me say it straight. In 2026, if you haven’t been audited yet, you will be.

Payers aren’t sending letters because they’re curious. They’re using AI to scan every claim you submit. CMS expanded RAC. The OIG drops a new Work Plan every year targeting one specialty. One chart request can turn into a 3-year lookback and a letter demanding $80,000 back.

So what do you do?

You audit yourself first.

A medical billing audit is simple. You pull charts. You compare what you documented to what you billed. You find the leaks and the landmines before a payer does.

In Revenue Cycle Management, this is the line between practices that survive and practices that get crushed by clawbacks.

Here’s what’s at stake:

  • Money: FCA fines start at $13,946 per claim. RACs take their cut and then some. Interest adds up fast.
  • Operations: Payments get suspended. You go on pre-payment review. Your staff spends all day on appeals instead of patients.
  • Reputation: Once you’re flagged as an outlier, every payer watches you.

I’ve spent 15 years doing this for practices. Internal audits. External audits. Defending against OIG. This guide is the exact process I use. No theory. Just what works.

Understanding Healthcare & Billing Audits

If you don’t know what kind of audit you’re facing, you can’t prepare for it.

1.1 Internal vs. External Audits

Internal Audits: You Find It First

This is you checking your own work. A medical practice billing audit every quarter.

Why do it? Because finding a $20,000 coding error in March is better than getting a demand letter for it in November.

Who does it: The practice owner, office manager, or compliance consultant. Goal is simple: find revenue you missed and risk you created.

External Audits: They Found You

This is when someone outside sends the letter. And you have 30-45 days to respond.

The usual suspects:

  • Commercial Payers: United, Aetna, BCBS. They target providers who bill differently than their peers. Too many 90837s. Too many modifier 25s.
  • CMS / MACs: TPE audits. Probe audits. They’ll take 20-40 charts and if your error rate is over 50%, you go to round 2, 3, and 4.
  • RAC – Recovery Audit Contractors: They get paid a percentage of what they take back. Their job is to find overpayments from 3 years ago.
  • OIG – Office of Inspector General: This is serious. They’re looking for fraud, waste, and abuse. This can end in exclusion.

Rule of thumb: Internal audits are for improvement. External audits are for survival.

1.2 The 3 Questions Every Healthcare Billing Audit Must Answer

Every billing compliance audit comes down to this:

  1. Are we leaving money on the table?

    Underbilling happens constantly. Example: Therapist does a 55-minute session but bills 90834 because “that’s what we always bill.” That’s $40 lost per session.
  2. Are we creating legal risk?

    Upcoding, unbundling, billing without documentation. This is how you get a False Claims Act case.
  3. Can we prove it?

    CMS and payers only pay for what’s in the chart. If your note doesn’t support the code, the claim is not defensible. Period.

The Core Elements of a Billing Compliance Audit

You can’t wing this. If OIG or a payer asks how you audit, you need to point to a process.

2.1 Legal & Regulatory Alignment

Base everything on the OIG’s 7 Core Elements. This is what they expect to see:

  1. Written Policies: How do you code 90834 vs 90837? What’s your policy on modifier 25? Write it down.
  2. Compliance Officer: Someone has to own this. Even if it’s the practice manager for 2 hours a week.
  3. Training: Annual HIPAA training isn’t enough. Train on coding changes, documentation, and billing rules. Log it.
  4. Reporting: Staff need a way to say “I think this is wrong” without getting fired.
  5. Enforcement: If someone keeps upcoding, there are consequences.
  6. Auditing: You must audit yourself regularly. Quarterly is the standard.
  7. Response: When you find an error, what do you do? Retrain? Refund? Document it.

Also know these 3 laws cold:

  • False Claims Act: Submit a claim you know is wrong = $13,946 to $27,894 per claim, plus triple damages.
  • Anti-Kickback Statute: No paying for referrals. No “marketing fees” to PCPs.
  • HIPAA: If you pull charts for an audit, use minimum necessary. Have a BAA if a vendor helps.

2.2 Red Flags That Get You Audited

Payers run reports every month. These patterns light them up:

  • Outlier Billing: You bill 90837 85% of the time. The national average is 35%. You’ll get a letter.
  • Modifier Abuse: Modifier 25 on 70% of your E/M visits. Modifier 59 to bypass edits on every claim.
  • High Denials: If 20% of your claims deny for “medical necessity,” a payer assumes the problem is you, not them.
  • Unbundling: Billing for the parts instead of the whole. 36415 + 80053 instead of just the panel.
  • Volume Spikes: You went from 200 claims a month to 400 with no new provider. That’s a trigger.

See any of these in your reports? Fix them now.

Performing a Targeted Medical Coding Audit

This is where the money is. A medical coding audit is not reading every word. It’s checking 3 things.

3.1 The 3 Things Reviewers Check

  1. Was the right code picked?

    You billed 99214. Does the note support 2 of 3: History, Exam, MDM? Or 30-39 minutes? If not, it’s wrong.
  2. Was the diagnosis specific enough?

    “Z13.30 Screening for mental disorder” won’t support a 90837. “F41.1 Generalized Anxiety Disorder, Severe” will. Specificity drives medical necessity.
  3. Was it medically necessary?

    CMS standard: “Reasonable and necessary.” For therapy, that means you documented symptoms, functional impairment, and a treatment plan. For E/M, that means you documented why the patient needed to be seen at that level.

3.2 The 3 Mistakes I See in 80% of Audits

  1. Upcoding

    Billing 99215 when the note supports 99213.

    Real example: Provider copies and pastes the same 5-review ROS for every patient. Auditor sees it and downcodes every chart.

    Fix: Train providers on MDM and time. Kill copy-paste.
  2. Unbundling

    Billing 93000 and 93010 separately. The global code already includes both.

    Fix: Run claims through an NCCI edit checker before submission.
  3. Modifier Misuse

    Modifier 25 on every visit with a vaccine. Modifier 59 on every claim to “make it pay.”
    Fix: Require the provider to document why the modifier is needed in the note.

Step-by-Step Medical Practice Billing Audit Process

Do this every 90 days. It takes 4-6 hours for a small practice.

Step 1: Planning & Scope

Don’t try to audit everything. You’ll quit.

  • Pick a focus: This quarter do E/M levels. Next quarter do therapy codes.
  • Pick a sample: 10-20 charts per provider. Random. Not just the ones you think are clean.
  • Define success: Are we looking for lost revenue or compliance risk?

Step 2: Pull the Charts

Get everything in one folder:

  • The EHR note with signature and timestamp
  • The superbill or encounter
  • The claim that went out
  • The ERA/EOB showing what paid
  • The prior auth if there was one

If you can’t find it in 2 minutes, your documentation is already a problem.

Step 3: Audit the Chart

Side by side. Claim vs Note.

Ask:

  1. Does the diagnosis match the procedure?
  2. Does the note support the CPT code?
  3. Is there a signature, date, and medical necessity?
  4. Was the claim scrubbed? Correct POS? Correct NPI?
  5. Was auth required and on file?

Mark every “no.” That’s an error.

Step 4: Do the Math

Error Rate = Errors ÷ Charts Audited

Financial Risk = Error Rate × Annual Revenue

Example: 4 errors in 20 charts = 20% error rate. If you bill $1M a year, your risk is $200,000.

Also break it down: 3 coding errors, 1 eligibility error. Now you know where to train.

Step 5: Fix It – The CAP

This is the part most practices skip.

For every error:

  • Retrain: If 3 providers are upcoding, do a 30-min lunch and learn.
  • Change the process: Add a hard stop in the EHR. Update your scrubber.
  • Check it: Re-audit the same thing in 60 days.
  • Refund: Found an overpayment? You have 60 days to return it under the 60-Day Rule or you risk FCA penalties.

Specialty Examples – Where Audits Hit Hardest

Audits aren’t the same for everyone. Here’s what I see by specialty:

Primary Care

Biggest risk: E/M leveling and modifier 25.

Example: Provider sees patient for follow-up and does a flu shot. Bills 99214 + 25 + vaccine. Auditor says the 99214 wasn’t significant and separate. Downcodes to 99213.

Fix: Document separate work for the E/M.

Behavioral Health

Biggest risk: Timed codes and medical necessity.

Example: Billing 90837 for 45 minutes. Auditor asks for start/stop time. You don’t have it. Denied.

Fix: Template in EHR for time. Document functional impairment in every note.

Surgery

Biggest risk: Unbundling and global periods.

Example: Billing post-op visit separately during 90-day global.

Fix: Train front desk to check global days before posting charges.

Medical Billing Audit Checklist

Print this. Use it before you submit claims.

A. Patient & Eligibility

  • Eligibility checked in last 48 hours
  • Name, DOB, Member ID match
  • Auth on file if needed

B. Documentation

  • Signature and date on note
  • CC, HPI, Assessment, Plan all there
  • Medical necessity stated
  • Time documented for timed codes

C. Coding & Scrubbing

  • CPT matches what was done
  • ICD-10 to highest specificity
  • Correct POS. Telehealth = 02 or 10 + 95
  • Modifiers have documentation
  • Passed NCCI edits

D. A/R & Denials

  • Denials logged with reason
  • Follow-up started by day 15
  • Appeals sent on time
  • Denial rate tracked monthly

Conclusion

Here’s the truth. You have two choices.

You can wait for a payer to audit you. Then you’re stressed, reactive, and writing big checks.

Or you can audit yourself. Find the problems. Fix them. Get paid correctly and sleep at night.

Practices that do quarterly audits recover 3-5% in missed revenue. They also avoid the six-figure clawbacks.

Stop waiting.

Next step: Schedule your first internal medical billing audit this month. Pull 10 charts per provider. Use the checklist above.

If you’ve already received an audit letter from a payer, RAC, or OIG, don’t respond alone. Talk to a certified billing compliance consultant in the first 48 hours. What you say in that first response matters.

In this business, the practices that audit themselves stay open. The ones that don’t, get audited out of business.

Emily Foster

RCM Expert | Content Strategist in Healthcare | Swiftcare Billing

RCM professional and healthcare content strategist having experience in US medical billing of 12 years. I am located in New Jersey and transform complicated billing and reimbursement processes into high-converting and understandable material. Dedicated to compliance-adjusted storytelling that promotes expansion throughout the revenue cycle.

Have Questions?
Let’s Discuss

Fill out this form, tell us about your practice’s unique needs, and get a tailored solution!
Contact Us Form