Medical Billing Audit Checklist

If you have ever watched a clean-looking claim get denied for a reason nobody flagged during the visit, you already understand why audits exist. Billing errors rarely announce themselves. They hide inside a missing modifier, a stale fee schedule, an eligibility check that never ran, or a note that does not quite support the code that was billed. By the time the denial letter or the payer audit notice arrives, the damage is already done.

A medical billing audit checklist is the tool that catches these problems before a payer does. Used correctly, it is not a compliance chore you run once a year and forget. It is a recurring discipline that protects revenue, keeps your practice out of the Office of Inspector General’s (OIG) crosshairs, and gives your billing team a shared standard to work from instead of relying on memory or habit.

This guide walks through a complete, practice-ready audit checklist built from decades of hands-on revenue cycle management work: what to check, in what order, how often, and what separates a checklist that actually finds problems from one that just looks good in a binder.

Why Medical Billing Audits Matter More in 2026

Payers are not getting more forgiving. According to CMS’s Comprehensive Error Rate Testing (CERT) program, the Medicare Fee-for-Service improper payment rate for fiscal year 2025 came in at 6.55 percent, representing roughly $28.8 billion in improper payments nationwide. Most of that was not fraud. CMS itself notes that improper payments are usually the result of a missed administrative step, insufficient documentation, or a coding mismatch rather than deliberate abuse.

That distinction matters, because it means the majority of these errors are preventable with a consistent audit process. Medicaid told a similar story: more than three-quarters of Medicaid improper payments in the most recent reporting cycle traced back to insufficient documentation, not intentional overbilling. In other words, practices are leaving money on the table (or exposing themselves to recoupment) not because they are trying to cut corners, but because nobody is checking the work before it goes out the door.

An internal audit closes that gap. It gives you the chance to find your own mistakes on your own timeline, while the correction window is still open, instead of discovering them months later through a payer takeback or an OIG inquiry.

What a Medical Billing Audit Actually Checks

A medical billing audit is a structured review of the documentation, coding, and claims for a sample of patient encounters, done to confirm that what was billed matches what was documented and that the claim follows payer and regulatory rules. It touches four connected stages of the revenue cycle:

  • Front-end accuracy: patient demographics, insurance verification, and authorization
  • Clinical documentation: whether the note actually supports the service billed
  • Coding and charge capture: CPT, HCPCS, ICD-10, modifiers, and units
  • Claims and payment integrity: submission timeliness, denial patterns, and payment posting

Skipping any one of these turns your audit into a partial picture. A practice that only reviews coding, for example, will miss the eligibility failures that caused half its denials in the first place. That is why the checklist below is organized to follow the same path a claim actually travels, from the front desk to the remittance advice.

Internal vs. External Audits: Know the Difference First

Before running through the checklist, it helps to be clear on which type of audit you are doing, since the goal changes the scope.

Audit TypeWho Runs ItPrimary Goal
Prospective (pre-bill)Internal team or auditorCatch errors before claims go out
Retrospective (post-payment)Internal team or auditorFind patterns in already-submitted claims
Payer auditInsurance companyVerify claims paid were billed correctly
OIG / CMS auditFederal regulatorConfirm compliance, investigate fraud risk

Internal audits, whether prospective or retrospective, are the ones you control. Running them regularly is also the best preparation for the external audits you do not control, since a practice that already knows its weak spots walks into a payer or OIG review with far less risk.

The Complete Medical Billing Audit Checklist

1. Patient Registration and Insurance Verification

Most billing problems start here, long before a code is ever selected. A downstream denial almost always has an upstream cause, and that cause is often something as small as a mistyped subscriber ID or a policy that lapsed between visits.

  • Confirm patient name, date of birth, and address match the insurance card and the medical record exactly
  • Verify the correct payer, plan, group number, and subscriber ID were entered
  • Re-check eligibility and active coverage on the date of service, not just at intake
  • Confirm copay, deductible, and coinsurance amounts were captured accurately
  • Verify referral and prior authorization requirements were met before the visit, where applicable
  • Confirm guarantor and responsible-party information is correct for minors or dependents
  • Check for duplicate patient records that could split a patient’s history across two accounts

Front-end accuracy is a large enough problem on its own to deserve its own review. If your practice struggles here, our insurance eligibility verification guide and patient registration process guide walk through how to tighten this stage before it ever reaches billing.

2. Clinical Documentation and Medical Necessity

Every code on a claim needs a note that justifies it. Auditors, whether internal or from CMS, work from one simple rule: if it is not documented, it is not billable.

  • Confirm the note supports the level of service billed (history, exam, and medical decision-making for E/M codes)
  • Verify diagnosis codes are supported by clinical findings, not just carried forward from a prior visit
  • Check that signatures, credentials, and dates are present and legible
  • Confirm orders exist for any tests, imaging, or procedures billed
  • Verify time-based codes include the documented time and required elements
  • Flag templated or copy-forward notes that do not reflect what actually happened at that visit

3. Coding Accuracy: CPT, HCPCS, ICD-10, and Modifiers

This is where most audit checklists stop, but it is only one piece of the picture. Still, it deserves careful attention because coding errors are the fastest way to trigger both denials and compliance risk.

  • Confirm CPT and HCPCS codes match the documented service and current code year
  • Verify ICD-10 codes reflect the highest specificity supported by the documentation
  • Check modifier use against National Correct Coding Initiative (NCCI) edits and bundling rules
  • Confirm units billed match what was actually performed or dispensed
  • Review E/M code selection for upcoding or downcoding patterns
  • Check for unbundling of services that should be billed together
  • Verify place-of-service and telehealth indicators match how the visit occurred

4. Charge Capture and Claim Scrubbing

Even accurate coding can fail if the charge never makes it onto the claim cleanly, or if it goes out with a formatting error a clearinghouse will reject.

  • Compare charges against the encounter form or EHR to catch missed or duplicate charges
  • Confirm fee schedules are current and match the correct payer contract
  • Run claims through scrubbing software before submission to catch missing NPI numbers, invalid codes, or formatting errors
  • Cross-check same-patient, same-date claims for duplicate billing
  • Verify bundled services are not being billed separately in error

If your practice is still catching these errors manually after submission, it is worth reviewing whether your current system is doing enough of this work automatically. Our medical billing software guide breaks down what a modern claim-scrubbing setup should catch before a claim ever leaves your office.

5. Claims Submission Timeliness and Compliance

A perfectly coded claim submitted late is still a lost claim. Timely filing limits vary by payer, and missing them is one of the few billing mistakes that usually cannot be appealed.

  • Confirm claims are submitted within each payer’s timely filing window
  • Verify clean claim rate (the percentage accepted without manual correction)
  • Check that HIPAA-compliant transmission standards are followed for electronic claims
  • Confirm claims reflect current CMS and payer-specific billing rules, including any recent regulatory updates
  • Review whether staff are trained on current compliance requirements, not just current codes

Compliance rules shift often enough that a checklist built two years ago is already out of date in places. Our medical billing compliance guide is worth cross-referencing here to confirm your process reflects the current regulatory landscape.

6. Denial Management and Appeals

Denials are not the end of the story, they are data. A good audit treats every denial as a signal about where the process upstream broke down.

  • Track denial rate by payer, code, and denial reason
  • Confirm denied claims are being corrected and resubmitted within the appeal window
  • Identify repeat denial patterns that point to a systemic issue rather than a one-off mistake
  • Review whether write-offs are being applied correctly, versus being used to avoid the work of an appeal
  • Confirm appeal letters include the documentation needed to support reversal

A high or rising denial rate is usually the clearest early warning sign that something upstream needs attention. If this is where your numbers are weakest, our claim denial management guide covers how to build a structured appeals process instead of handling denials one at a time as they come in.

7. Payment Posting and Contractual Adjustments

The audit is not finished at submission. What actually gets paid, and what gets written off, needs its own review.

  • Confirm payments posted match the amount allowed under the payer contract
  • Verify contractual adjustments are calculated correctly, not applied as a flat estimate
  • Check for underpayments that were posted without a follow-up flag
  • Confirm secondary and tertiary payer balances are billed correctly after primary payment
  • Review aging accounts receivable (AR) for balances stuck past 60 or 90 days

8. Common Billing Mistakes Worth a Dedicated Look

Some errors show up often enough across specialties that they deserve a specific check rather than getting buried inside the categories above: mismatched patient identifiers, expired authorizations, incorrect provider NPI on a claim, and services billed under the wrong rendering provider. Our medical billing mistakes guide goes deeper into the patterns that show up most often in real practice audits, if you want to build a specialty-specific watchlist.

How Often Should You Run a Medical Billing Audit?

Frequency matters more than most practices assume. The value of an audit comes from how early it catches a pattern, not how thorough a single review looks.

  • Monthly spot checks: A small random sample (10 to 20 claims) reviewed monthly catches problems while the correction window is still open
  • Quarterly focused audits: A deeper review of a specific area, such as a high-denial payer or a new code set, once per quarter
  • Annual comprehensive audit: A full review across all categories above, ideally by someone outside the day-to-day billing team
  • Trigger-based audits: Immediately after adding a new provider, switching billing software, expanding into a new payer, or noticing a sudden change in denial rate

A pattern that starts in week one and goes unnoticed until quarter-end has already cost you months of claims that are past the point where correction is realistic. Consistency catches far more revenue than intensity does.

What Increases Your Risk of an External Audit

Certain patterns tend to draw payer or OIG attention faster than others. Being aware of them does not mean avoiding legitimate billing, it means knowing which claims deserve extra internal scrutiny before they go out:

  • Consistent use of high-level E/M codes across most patients
  • Billing patterns that differ sharply from peers in the same specialty
  • High volumes of a single high-reimbursement code
  • Frequent use of modifier 25 or 59 without clear documentation support
  • A sudden spike in billing volume or average charge per visit
  • Prior audit findings that were never remediated

Internal Audit or Outsourced Review: Which Makes Sense?

An internal audit, run by your own billing staff, is a good starting point and should happen regularly regardless of practice size. But there is a real limitation worth naming honestly: the people who create the errors are often the same people reviewing the work, and unconscious blind spots are hard to self-detect.

An outsourced or third-party audit brings a few advantages that are hard to replicate internally: an outside set of eyes with no stake in defending past decisions, current knowledge of payer-specific edit logic across many practices rather than just one, and the bandwidth to sample more claims than an internal team usually has time for.

Many practices land on a hybrid model: monthly internal spot checks handled in-house, paired with a quarterly or annual deeper audit from an outside partner. If your team is stretched thin or your denial rate has been climbing without a clear cause, a full revenue cycle management review or dedicated medical billing services partner can usually surface issues faster than adding the work onto an already-busy front desk or billing staff. Practices with aging AR often benefit specifically from a focused AR follow-up review alongside the coding and documentation audit.

Building Your Audit Sample: A Practical Approach

You do not need to review every claim to get a reliable picture. A sample of 15 to 30 claims per provider, per quarter, is generally enough to surface real patterns without consuming the entire billing team’s week. Pull a mix that includes:

  • A random selection across different payers
  • Your highest-denial CPT or diagnosis codes from the prior quarter
  • Claims from any new provider or staff member still ramping up
  • A handful of your highest-dollar claims, since a single error there costs more than several small ones combined

Document every finding, even the ones that turn out fine. A clean finding still tells you the process is working, and having that record on hand matters if a payer or the OIG ever asks to see your compliance efforts.

Frequently Asked Questions

What is the difference between a medical billing audit and a coding audit? A coding audit reviews only whether the CPT, HCPCS, and ICD-10 codes match documentation. A medical billing audit is broader and reviews the entire claim lifecycle, including registration, eligibility, coding, submission timeliness, denials, and payment posting.

How many claims should a medical billing audit review? Most practices review a random sample of 15 to 30 claims per provider each quarter, supplemented with targeted reviews of high-denial codes or high-dollar claims. Larger practices facing an OIG inquiry may need a statistically valid sample sized by a compliance specialist.

What triggers a payer or OIG medical billing audit? Common triggers include billing patterns that deviate from specialty peers, heavy use of high-level E/M codes, frequent modifier 25 or 59 use without documentation support, sudden volume spikes, and prior unresolved audit findings.

How long should audit records be kept? Most compliance guidance recommends retaining medical billing audit documentation, along with the underlying claims and medical records, for a minimum of six to ten years, though state-specific retention rules can extend this further.

Can a small practice run its own medical billing audit checklist without outside help? Yes, a small practice can run internal spot checks using the categories in this checklist. The tradeoff is that internal reviewers may miss their own blind spots, so pairing internal monthly checks with an outside audit once or twice a year is generally the more reliable approach.

Turning This Checklist Into a Habit

A checklist only works if someone owns it. Assign a specific person or team to run the audit on a set schedule, document findings in the same format every time, and close the loop by actually fixing what the audit finds rather than filing the report away. Revenue does not usually disappear all at once. It leaks quietly, claim by claim, through errors nobody was specifically looking for. A consistent audit habit is what turns that invisible leak into something you can see, measure, and stop.

If your last audit turned up more findings than you expected, or you have not run one at all this year, The Billing Advisors team can walk through your claims with you and help build an audit process that fits your practice size and specialty.

Write a Reply or Comment

Your email address will not be published. Required fields are marked *