← Back to Blog
Compliance9 min read

Preventing Healthcare Audits Through RCM Optimization and Coding Accuracy

Most audits aren't random. They're triggered by billing patterns that deviate from peer benchmarks. Here's how to optimize your revenue cycle and eliminate the coding errors that put practices on auditors' radar.

M
Medbillytics Team
July 2, 2024

Healthcare audits — whether from Medicare's Recovery Audit Contractors, commercial payer post-payment review programs, or OIG investigations — aren't random. Auditors use data analytics to identify providers whose billing patterns deviate significantly from their peers. High E/M code levels, unusual procedure volumes, modifier misuse patterns, and billing spikes all appear in the data before an auditor ever requests a chart.

This means most audits are predictable — which means they're largely preventable. The practice that conducts rigorous internal audits, monitors its own billing patterns against benchmarks, and catches coding problems proactively is the practice that external auditors typically find nothing worth pursuing.

Here's what triggers audits, what coding errors invite the most scrutiny, and how a well-optimized revenue cycle minimizes audit risk without sacrificing the revenue you've legitimately earned.

How Auditors Find You: The Data Behind Audit Selection

Understanding the audit selection process is the first step in prevention.

CMS data analytics: Medicare publishes the annual Part B Public Use File, which contains specialty-level utilization data for every provider billing Medicare. CMS uses statistical analysis to identify outliers — providers billing specific codes at rates significantly higher than their specialty peers. Providers in the top decile for high-level E/M codes, high-cost procedures, or certain modifier combinations receive disproportionate attention.

RAC (Recovery Audit Contractor) selection: RAC contractors are paid a percentage of what they recover, giving them a financial incentive to target high-value claims. They use predictive analytics to identify billing patterns most likely to yield a successful overpayment determination. Common RAC targets include: inpatient medical necessity claims, high-level E/M billing, implant billing, and certain high-cost outpatient procedures.

Commercial payer post-payment review: Commercial payers run similar analyses on their own claims data. A provider billing modifier 25 on 70% of all visit-with-procedure encounters (when the specialty average is 15%) will appear in a commercial payer's anomaly report. These reviews often start with targeted record requests rather than announced audits.

Complaint-driven investigations: OIG and state medical board investigations frequently begin with complaints — from a patient, a former employee, or a competing provider. These are harder to predict but are often prevented by the same strong compliance practices that prevent data-driven audit selection.

The Coding Errors That Most Reliably Trigger Audits

E/M upcoding patterns. Billing consistently at the highest E/M level (99215 for established patients) isn't inherently a violation — some practices genuinely see a complex patient population. But a solo primary care provider with a 99215 rate of 65% when the national average for their specialty is 18% will receive scrutiny. The critical question isn't the code level — it's whether the documentation consistently supports the billed level. Upcoding becomes fraud when the documentation doesn't support the code and the pattern is systematic.

Modifier 25 overuse. Modifier 25 — used to bill a separate E/M on the same day as a procedure — is legitimate and valuable. It's also one of the most commonly misused modifiers in outpatient billing. When modifier 25 is applied to every procedure visit regardless of whether a separately identifiable E/M was actually performed, auditors find a pattern. The fix: apply modifier 25 only when the documentation explicitly supports a separate evaluation with distinct findings and decision-making.

Unbundling. Billing separately for components of a service that CMS defines as a bundle is both a billing error and a compliance violation. NCCI (National Correct Coding Initiative) edits define which procedure codes are bundled. Billing unbundled codes when the CCI rules require a bundle generates automatic rejections when the scrubber is current — but can pay incorrectly when the scrubber is outdated, creating post-payment audit targets.

Duplicate billing. Submitting the same claim twice — even accidentally — creates an immediate flag. Billing the same service to two different payers for the same patient on the same date is a more serious violation. Billing systems with claim status tracking and clearinghouse acknowledgment workflows prevent most duplicate billing, but practices that manage multiple billing systems or that don't reconcile clearinghouse rejections systematically create the conditions for accidental duplicates.

Medical necessity documentation failures. A procedure is covered when it's medically necessary. The documentation must establish necessity — the patient's condition, the clinical indication, and why the service was appropriate. When the ICD-10 codes on the claim don't connect clearly to the procedure, or when the note describes a procedure but doesn't explain why it was needed, medical necessity denials and audit findings follow.

RCM Optimization Strategies That Reduce Audit Risk

Implement routine internal audits. Proactive internal auditing is the single most effective audit prevention strategy. Quarterly chart-level audits that sample a statistically meaningful number of claims per provider identify coding accuracy problems before external auditors do. When problems are found internally, corrective action can be documented — which substantially reduces penalty exposure if an external audit occurs later.

The audit process should include:

  • Random sampling (not cherry-picked charts)
  • Explicit scoring criteria aligned to current coding guidelines
  • Provider-level reporting with specific findings
  • Dollar quantification of both overcoding and undercoding findings
  • Corrective action tracking with completion dates

Monitor E/M distribution against benchmarks. Pull your E/M level distribution monthly — the percentage of office visits billed at each code level (99202 through 99205 for new patients, 99211 through 99215 for established patients). Compare this distribution against CMS specialty benchmark data. Significant deviations in either direction warrant investigation: overcoding has compliance implications, undercoding has revenue implications.

Maintain current NCCI compliance. NCCI edits update quarterly. Your claim scrubber's edit library must be kept current — an outdated scrubber that doesn't catch current bundling violations is worse than no scrubber, because it creates false confidence that claims are clean.

Document corrective actions. When an internal audit finds a coding error, the value of the finding is only realized if the error is corrected and the correction is documented. A corrective action log showing that a pattern was identified, a root cause was established, training was provided, and the pattern was subsequently verified as corrected is your best protection in an external audit. It demonstrates good-faith compliance effort that external auditors and OIG investigators weigh favorably.

Train staff on coding updates annually. CPT codes, ICD-10 codes, and payer billing guidelines update every year. Billing staff and coders who aren't trained on current guidelines are coding from outdated knowledge — which produces both compliance errors and missed revenue from codes they don't know exist.

If an Audit Happens

Even with strong prevention practices, audits occur. Having a documented compliance program is your best defense:

Respond promptly and professionally. Record requests have response deadlines. Missing them creates additional complications. Assign a specific staff member to coordinate the response.

Provide complete, organized records. Disorganized responses suggest disorganized practice. Compile the requested records completely and professionally.

Review before submitting. Before sending records to an auditor, review them internally. If there are documentation gaps, document your understanding of what the record does and doesn't show. Never alter records — but understand what you're submitting.

Engage a healthcare attorney for significant audits. For RAC audits, OIG investigations, or any audit involving a significant dollar amount, involve healthcare legal counsel early. The process and your rights as a provider are complex.

Appeal adverse determinations. Medicare and commercial payer adverse audit determinations have appeal processes. First-level appeals are often successful, particularly when additional clinical documentation is provided. Don't accept an overpayment determination without reviewing the basis and evaluating the appeal merits.

Prevention is always less expensive than response. The goal of a strong RCM compliance program is making sure that when an auditor runs your data through their analytics, nothing unusual appears — because nothing unusual is happening.


Want an independent review of your billing patterns and compliance exposure? Talk to our team — we conduct compliance-focused billing audits for practices across all specialties and help you identify and address risks before they become audit findings.

Need help with your revenue cycle?

Get a free assessment from our team — we'll show you exactly where you're leaving money on the table.

Get a Free Assessment