← Back to Blog
Compliance8 min read

Healthcare Auditing Explained: What It Is, Why It Happens, and How to Be Ready

A healthcare audit can cover billing accuracy, clinical documentation, compliance, or all three simultaneously. Understanding what auditors look for — and how to be prepared — is the difference between a clean outcome and a costly one.

M
Medbillytics Team
July 1, 2024

"Audit" is a word that generates immediate anxiety in most medical practices. It shouldn't — at least not when your billing is accurate and your documentation is solid. But for practices that haven't thought carefully about audit preparedness, the anxiety is warranted. An external audit that reveals systematic billing errors can result in recoupment demands covering multiple years of overpayments, compliance penalties, and in serious cases, exclusion from Medicare and Medicaid.

Understanding what healthcare audits actually are, who conducts them, what they look for, and how to ensure your practice can withstand scrutiny is essential for any practice owner or administrator.

Types of Healthcare Audits

There isn't one type of healthcare audit — there are several, with different scopes, triggers, and conducting authorities.

Medicare RAC Audits (Recovery Audit Contractors). RAC auditors are contracted by CMS to identify improper Medicare payments. They review claims on a post-payment basis — meaning they're looking at claims that have already been paid and determining whether those payments were appropriate. RAC auditors are paid a percentage of the improper payments they identify, which means they have a financial incentive to find errors. They focus on areas with known high error rates: complex E/M services, specific procedure codes with narrow documentation requirements, and high-cost services.

ZPIC / UPIC Audits (Zone Program Integrity Contractors / Unified Program Integrity Contractors). These contractors investigate suspected Medicare and Medicaid fraud. Unlike RAC auditors who look for billing errors, ZPIC/UPIC investigations are triggered by fraud indicators — unusual billing patterns, statistical outliers, whistleblower complaints, or referrals from other contractors. These are more serious than RAC audits because they're investigating potential fraud, not just overpayments.

MAC Audits (Medicare Administrative Contractors). MACs process Medicare claims and conduct targeted prepayment and post-payment reviews in specific areas. They issue local coverage determinations (LCDs) that define what documentation and clinical criteria must be met for specific services to be covered. Claims that don't meet LCD requirements are denied.

Commercial Payer Audits. Commercial insurers conduct their own post-payment audits, typically targeting high-cost claims, high-volume providers, or providers whose billing patterns are outliers compared to peers. The process is similar to Medicare RAC audits but governed by your payer contract rather than federal regulations.

OIG Investigations. The Office of Inspector General investigates healthcare fraud. OIG investigations are the most serious — they can result in criminal charges, civil monetary penalties, exclusion from federal healthcare programs, and personal liability for physicians and practice owners.

What Auditors Are Looking For

External auditors review claims against specific criteria. Understanding those criteria is the foundation of audit preparedness.

Documentation that supports the billed code. For E/M services, the documentation must support the level of Medical Decision Making or the time documented. For procedures, the note must document the clinical indication, technique, and findings. For any service, the documentation must demonstrate that the service was medically necessary for this patient at this time.

Correct code selection. Auditors verify that the CPT and ICD-10 codes on the claim accurately represent the service rendered and the diagnosis documented. Upcoding (billing a higher level than the documentation supports) and unbundling (billing component services separately when they should be billed together) are the most common coding errors found in audits.

Modifier accuracy. Modifiers change how a code is paid. Auditors specifically target high-value modifiers — modifier 25, modifier 59, modifier 26/TC — because these are commonly misused and the financial impact is significant.

Authorization compliance. Services that required prior authorization must have authorization documentation on file. Authorization obtained for one service doesn't cover a different service. Services rendered outside the authorization period aren't covered by that authorization.

Duplicate billing. Submitting the same claim twice, or billing for a service that was already included in a different billed code, is a common finding in both RAC audits and commercial payer reviews.

The Internal Audit: Your Most Effective Defense

The most effective audit defense is a strong internal audit program that identifies the same issues before external auditors do.

A practice with documented, consistent internal audits that produce corrective actions is in a fundamentally different position than one without them. If an external auditor identifies a billing pattern that your internal audits also identified — and that you corrected — the narrative is "we found this issue, we fixed it, here is the documentation." That's a very different outcome than "we had no idea this was a problem."

An effective internal audit program includes:

Regular random sampling. Minimum quarterly, covering at least 10–15 charts per provider per cycle. Random selection is important — cherry-picked charts don't produce defensible audit data.

Scoring against current guidelines. E/M coding scores against current AMA MDM criteria. Procedure coding scores against NCCI edits and payer LCDs. Modifier usage scores against payer-specific requirements.

Written findings and corrective actions. Every audit produces a written report. Every finding generates a documented corrective action with a completion date. Follow-up audits verify that corrections were made.

Provider feedback. Findings are shared with individual providers in a constructive, specific format — not just as aggregate statistics.

How to Respond to an Audit Request

Receiving an audit request — whether from Medicare, a commercial payer, or a government contractor — requires a careful, systematic response.

Respond on time. Audit requests specify a deadline for document submission. Missing that deadline is treated as uncooperative and can accelerate the scope of the investigation. If you need additional time, request an extension in writing before the deadline.

Review the requested documentation before submitting. Don't submit charts blindly. Review each requested record for completeness and accuracy. Incomplete documentation submitted in response to an audit becomes exhibit A for the auditor's findings.

Don't submit more than requested. The audit request specifies what's being reviewed. Submitting additional records outside the scope of the request can inadvertently expand the audit's reach.

Understand your appeal rights. If an auditor issues findings or demands recoupment, you have appeal rights. The appeal process for Medicare claims involves multiple levels and has specific deadlines. A finding that results in a significant recoupment demand warrants professional support — the financial exposure justifies it.

Keep copies of everything. Maintain copies of every document submitted in response to an audit, every communication with the auditor, and every piece of correspondence. Audit processes can extend over months and sometimes years.

Preparing Before an Audit Request Arrives

Audit preparedness isn't something to think about when you receive an audit letter. By then, the preparation window has passed.

Proactive audit preparedness includes:

  • Maintaining current, complete documentation for every patient encounter
  • Conducting regular internal billing and coding audits
  • Reviewing your billing patterns against specialty benchmarks quarterly
  • Maintaining a compliance policy and designating a compliance officer
  • Training staff on billing and documentation accuracy annually
  • Keeping a compliance hotline or reporting mechanism for staff to flag potential issues

Practices that treat compliance as an ongoing operational priority — not a response to external pressure — consistently have better audit outcomes than those that treat it as a check-the-box exercise.


Concerned about your practice's audit readiness? Talk to our compliance team — we conduct independent billing and documentation audits and help practices build ongoing compliance programs that withstand external scrutiny.

Need help with your revenue cycle?

Get a free assessment from our team — we'll show you exactly where you're leaving money on the table.

Get a Free Assessment