← Back to Blog
Compliance8 min read

How to Build a Compliance Auditing Program That Actually Protects Your Practice

A compliance audit program isn't just a regulatory checkbox — it's your earliest warning system against the billing patterns that trigger external audits, recoupments, and penalties. Here's how to build one that works.

M
Medbillytics Team
July 2, 2024

Most practices think about compliance auditing the wrong way. They think of it as something that happens to them — an external audit from a payer or the OIG that disrupts operations and potentially costs money. But the practices with the strongest compliance records have flipped that framing. They audit themselves first, continuously, and use what they find to fix problems before a payer ever has the opportunity to find them.

A well-designed internal compliance auditing program isn't a regulatory burden. It's the most cost-effective risk management tool available to a medical practice.

Here's how to build one that actually works.

Why Internal Compliance Auditing Matters More Than Most Practices Realize

External audits — whether from Medicare RAC auditors, commercial payer post-payment reviews, or OIG investigations — are triggered by patterns in billing data. Payers run statistical analyses that compare your billing distribution against peers in your specialty, geography, and provider type. When your patterns are statistical outliers, you get flagged.

The practices that get audited aren't always doing something wrong. But they're often doing something that looks wrong in aggregate — a high rate of top-level E/M codes, unusual modifier patterns, high utilization of a specific procedure code, or a sudden volume spike. An internal audit program identifies those patterns at your level before payers see them at their level.

When you catch it internally, you can fix it: correct the underlying documentation issues, retrain providers, adjust coding policies. When payers catch it externally, the response is recoupment demands, post-payment audits covering multiple years, and potential compliance investigations.

The Four Essential Elements of an Internal Audit Program

1. Defined Scope and Frequency

Your audit program needs to specify what gets audited, how often, and by whom. Vague commitments to "audit periodically" don't produce consistent outcomes.

Recommended baseline:

  • Quarterly E/M level audits for all providers — minimum 10–15 charts per provider per quarter
  • Annual specialty-specific procedure audits covering your highest-volume CPT codes
  • Immediate targeted audits when denial patterns suggest a systemic coding or documentation issue
  • New provider baseline audits — audit 20–30 charts within the first 90 days of a new provider joining the practice

What to audit:

  • E/M code level vs. documentation support (MDM or time)
  • Modifier usage vs. documentation requirements
  • ICD-10 specificity and medical necessity alignment
  • High-risk service lines — E/M billed same-day as procedure, preventive plus problem-focused, prolonged services, high-cost procedures

2. Statistically Valid Sampling

Random sampling produces more defensible audit results than convenience sampling (cherry-picking charts that look fine). For most practices, a random sample of 10–20 charts per provider per audit cycle is statistically sufficient to identify systematic patterns.

The sampling should be truly random — not selected by the provider or the billing team. Use a random number generator or have an independent person pull the charts.

Why randomness matters: If auditors come to you with a post-payment review and you can show documented random-sample internal audits with findings and corrective actions, it demonstrates a good-faith compliance effort. If your internal "audits" consisted of reviewing charts you selected, that carries much less weight.

3. Documented Findings and Corrective Actions

An audit that produces findings but no documented response is worse than no audit at all — it demonstrates that you knew about problems and didn't address them.

Every audit should produce a written report that includes:

  • The date range and charts reviewed
  • The provider(s) included
  • Specific findings: chart number, date of service, billed code, correct code, type of error, dollar impact
  • Error rate by provider and error type
  • Corrective action assigned: specific training, process change, coding policy update
  • Completion date for corrective action
  • Follow-up audit scheduled to verify improvement

This documentation serves two purposes: it drives actual improvement, and it provides evidence of a good-faith compliance program if you're ever subject to an external review.

4. Provider-Specific Feedback

The most effective compliance training is specific, not general. A provider who receives a report showing their five specific charts where documentation didn't support the E/M level billed learns more from that than from a 45-minute annual HIPAA training.

Feedback should be:

  • Chart-specific: "In this encounter on this date, you billed 99215 but the MDM documentation supports 99214 because..."
  • Non-punitive in framing: compliance auditing is education and protection, not discipline
  • Timely: feedback delivered within 2 weeks of the audit is far more effective than feedback delivered 3 months later
  • Actionable: each finding should come with a specific, clear explanation of what documentation or coding change is needed

High-Risk Areas That Warrant Priority Attention

E/M level distribution vs. specialty benchmarks. CMS publishes annual utilization data showing the distribution of E/M codes billed by specialty nationally. If your practice's 99215 rate is materially higher than your specialty average, that's a priority audit target. Understanding why — whether the documentation genuinely supports higher complexity or whether there's a systematic upcoding pattern — is essential before a payer asks the same question.

Same-day E/M and procedure. Modifier 25 allows billing of a separate, identifiable E/M on the same day as a procedure. Payers audit modifier 25 usage specifically because it's frequently used without the documentation to support it. Every claim with modifier 25 should have a note where the E/M service is clearly distinct from the pre-service work of the procedure.

High-cost procedure codes. Procedures with high relative value units (RVUs) and narrow documentation requirements are disproportionately audited. Confirm that your documentation for these procedures includes clinical indication, specific technique, patient response, and any findings.

Diagnosis code specificity. Audits frequently find "unspecified" ICD-10 codes used when the documentation clearly supports a more specific code. This isn't fraud — it's a coding gap — but it weakens medical necessity justification and indicates a training opportunity.

Turning Audit Findings Into a Compliance Culture

The goal of a compliance program isn't to generate paperwork — it's to create a practice environment where accuracy is the standard, not the exception. When providers understand that the purpose of compliance auditing is to protect them personally (from audit exposure, recoupment liability, and license risk) rather than to monitor or punish them, engagement with the program changes dramatically.

Share aggregate compliance metrics with providers quarterly. Celebrate improvements. Frame findings as opportunities rather than violations. When a provider's coding accuracy improves measurably after targeted feedback, acknowledge it.

Compliance isn't built through fear. It's built through understanding — and a good audit program creates that understanding consistently.


Want to establish or strengthen your compliance auditing program? Talk to our compliance team — we conduct independent billing and coding audits for practices of all sizes and help build ongoing compliance programs that protect both revenue and providers.

Need help with your revenue cycle?

Get a free assessment from our team — we'll show you exactly where you're leaving money on the table.

Get a Free Assessment