← Back to Blog
Compliance9 min read

Medical Auditing: What Every Practice Owner Needs to Know to Stay Compliant and Protect Revenue

Medical auditing isn't just about regulatory compliance — it's a management discipline that protects revenue, identifies operational gaps, and keeps your practice defensible if an external auditor ever comes looking.

M
Medbillytics Team
July 1, 2024

Medical auditing is one of those topics that most practice owners know they should be doing more seriously — and most aren't. The reasons are predictable: it's time-intensive, it requires expertise most practices don't have in-house, and it occasionally surfaces uncomfortable findings about billing practices that have been in place for years.

But the alternative is worse. External auditors — RAC contractors, commercial payer post-payment reviews, and in serious cases, OIG investigations — are doing the audit your practice isn't doing internally. And when they find what your internal audit would have found, the consequences are substantially more costly than correcting the problem yourself.

Here's what medical auditing actually encompasses, how to do it effectively, and how to turn findings into operational improvements.

The Two Categories of Medical Auditing

Medical auditing splits into two primary categories that serve different but complementary purposes:

Billing and coding audits review the accuracy of claim submissions — whether the codes billed match the documentation, whether modifiers are used correctly, whether the documentation supports the billed service level. These audits identify revenue lost to undercoding and compliance risk created by overcoding. They're the foundation of a compliance program and the most directly actionable for revenue improvement.

Clinical documentation audits review the quality, completeness, and accuracy of clinical documentation itself — independent of the billing. A billing audit asks "does this code match the note?" A clinical documentation audit asks "is this note accurate, specific, and complete?" Both matter for compliance, but documentation audits are also a quality improvement tool — poor documentation creates clinical risk, not just billing risk.

Most practices that do internal auditing focus on billing and coding. The most comprehensive compliance programs include both.

What a Billing and Coding Audit Actually Examines

A complete billing and coding audit for a medical practice covers:

E/M code selection. Under current AMA guidelines (effective 2021), E/M code level is based on MDM or total time. The audit compares the billed E/M level against what the documentation actually supports. Undercoding findings identify recoverable revenue. Overcoding findings identify compliance risk.

Modifier accuracy. Each modifier used in the practice's billing is reviewed for appropriate application and supporting documentation. High-value modifiers — 25, 59, 26/TC, 51 — require specific documentation to justify. Modifier audits identify both missing modifiers (denials) and unsupported modifiers (compliance risk).

Diagnosis code specificity. ICD-10 specificity is reviewed — are codes as specific as the documentation supports? Are combination codes used when appropriate? Are laterality and manifestation codes applied correctly?

NCCI compliance. Are any procedure codes being billed in combinations that violate National Correct Coding Initiative edits? Are bundled services being billed separately?

Medical necessity. Do the diagnosis codes on the claim support the medical necessity of the services billed? This is the question payers ask when they conduct post-payment reviews — your internal audit should ask it first.

Procedure documentation. For procedure claims, does the procedure note include the required elements: clinical indication, technique, patient response, findings, complications?

Designing an Audit That Produces Actionable Results

The difference between an audit that produces useful information and one that produces a binder nobody reads is in the design.

Sample selection: Random sampling across all providers and date ranges within the audit period. Not cherry-picked charts. Not charts selected by the provider or billing team. Statistically valid random sampling produces results that are both more accurate and more defensible.

Scoring criteria: Explicit, documented criteria that match current coding guidelines and payer-specific requirements. The audit scoring should be replicable — a different auditor using the same criteria should reach the same conclusions.

Categorization of findings: Findings should be categorized by type (coding error, documentation gap, modifier issue, diagnosis specificity) and by potential financial impact (overcoding, undercoding, denial risk, compliance risk). This categorization drives prioritization of corrective actions.

Provider-specific reporting: Aggregate results are informative for program management. Provider-specific results are what drives behavioral change. Each provider should receive their own audit results — not as a punitive measure, but as specific, actionable feedback on their coding patterns.

Dollar impact quantification: For undercoding findings, calculate the estimated revenue impact of the identified pattern. This serves two purposes: it demonstrates the revenue recovery opportunity, and it creates urgency around corrective action.

The Corrective Action Process

An audit finding is only valuable if it generates a corrective action that prevents recurrence. Every finding should result in one of three corrective actions:

Training: When a finding indicates that a provider or coder doesn't understand the correct approach — how MDM works, when modifier 25 is appropriate, what level of diagnosis specificity is required — the corrective action is education. Chart-specific training (using de-identified examples from the audit) is consistently more effective than general compliance training.

Process change: When a finding indicates a systematic workflow failure — claims being coded without access to sufficient documentation, modifiers being applied automatically without documentation review, authorization requirements not being checked before scheduling — the corrective action is a process change.

Policy update: When a finding indicates that a payer's requirements have changed and your billing policies haven't caught up, the corrective action is a policy document update and team communication.

Every corrective action should have a responsible owner and a completion date. A follow-up audit scheduled for the next quarter should specifically verify whether the corrected patterns have improved.

The Legal Protection Value of a Documented Compliance Program

When an external audit does occur — and eventually, for most practices, it will — having a documented internal compliance program with consistent audit findings and corrective actions is a significant legal and financial protection.

The OIG's compliance program guidance specifically identifies self-disclosure (identifying and correcting billing errors proactively, before an external audit) as a factor that substantially reduces penalty exposure. A practice with documented internal audits showing that a pattern was identified, corrected, and improved can demonstrate good-faith compliance effort. A practice with no audit history cannot.

More practically: when a payer post-payment review requests charts and finds that your billing exactly matches what your most recent internal audit identified and corrected, the conversation is very different than when they find a pattern you were unaware of.

Outsourcing Medical Auditing: When It Makes Sense

For small practices without in-house coding expertise, conducting meaningful billing and coding audits is genuinely difficult. Coding accuracy requires current knowledge of CPT and ICD-10 guidelines, payer-specific requirements, and specialty-specific billing rules that most practice administrators don't have.

An independent audit by a professional billing and coding specialist has specific advantages over in-house auditing:

Independence: An outside auditor isn't influenced by internal dynamics or relationships with the providers being audited. Their findings are objective.

Expertise: Professional auditors bring current, specialty-specific knowledge of coding guidelines and payer requirements.

Credibility: A documented third-party audit carries more credibility in an external audit response than an internal review by someone without billing credentials.

Outsourced auditing works best as a supplement to an internal compliance program, not a substitute for it. Internal audits should happen quarterly. An independent external audit should happen at least annually, or whenever a specific concern arises.


Want an independent billing and coding audit for your practice? Talk to our team — we conduct comprehensive billing audits for practices across all major specialties and provide actionable findings with provider-level feedback.

Need help with your revenue cycle?

Get a free assessment from our team — we'll show you exactly where you're leaving money on the table.

Get a Free Assessment