Medical Coding Audit Guide: 2026 Process and Checklist

Medical Coding Audit Guide for Healthcare Providers in 2026

Category: Medical Coding

Posted By: Andrew Christian

Posted Date: Sep 26, 2025

A medical coding audit compares clinical documentation against the codes billed on a claim. The review covers CPT, ICD-10-CM, HCPCS Level II, modifiers, units, medical necessity, and payer rules. It flags unsupported coding, missed coding, and documentation gaps that create payment risk. Practices use it for quality improvement and compliance monitoring, not error counting for its own sake.

Practice leaders need specific answers, not a general accuracy score. Does the documentation support the claim? Do the codes reflect what happened during the encounter?

Are the errors isolated to one coder or provider, or do they repeat across the practice? Do the findings change payment, denial rates, or overpayment exposure? A coding audit answers those questions with evidence. That evidence is what protects a practice when a payer or regulator asks questions later.

This guide walks through the full process: defining scope and objectives, picking an audit type, sizing a defensible sample, running the 10-step review, calculating accuracy, grading severity, and turning findings into corrective action. Five points matter before you start.

  • No single chart count makes every audit representative. The right sample depends on your objective and population.
  • Documentation has to support each diagnosis, procedure, modifier, and unit you bill. Supporting the visit as a whole isn't enough.
  • Internal quality reviews and a response to a payer or government audit follow different workflows and different rules.
  • A finding without a corrective action, an owner, and a re-audit date is a list of mistakes.
  • Code sets and edit files have to match the date of service, not the date you happen to be reviewing the chart.

What Is a Medical Coding Audit?

A medical coding audit is a structured review of clinical documentation against the diagnosis codes, procedure codes, and modifiers submitted on a claim. It checks whether ICD-10-CM, CPT, and HCPCS Level II codes accurately represent the documented encounter, and whether the claim would hold up if a payer asked to see the record behind it.

What a Medical Coding Audit Reviews

A reviewer works through the encounter in a consistent order:

  • Clinical documentation supporting the visit
  • ICD-10-CM diagnosis assignment
  • CPT procedure and professional-service assignment
  • HCPCS Level II supplies, drugs, and services
  • Modifiers
  • Units of service
  • Place of service
  • Medical necessity
  • Applicable payer edits and coverage rules

The full step-by-step process, including how each of these gets checked in practice, is covered later in this guide.

What an Audit Can and Cannot Establish

An audit can identify discrepancies between the note and the claim, measure a defined type of accuracy, surface documentation and workflow patterns, and estimate financial exposure when the sampling method supports it. Those findings feed directly into corrective action.

An audit cannot guarantee compliance, prove intent, eliminate future denials, or replace legal advice. It also cannot make every payer interpret a rule the same way twice. Treat any claim of full compliance assurance or guaranteed accuracy as a marketing statement, not an audit finding.

Medical Coding Audit vs. Clinical Coding Audit

"Clinical coding audit" and "medical coding audit" usually describe the same underlying work: checking coded clinical information against the medical record. Hospitals, health information management departments, and international settings tend to use "clinical coding audit" more often. In U.S. physician billing, "medical coding audit" is the more common search and service term.

Clinical validation goes one layer deeper. It asks whether the documented clinical indicators support a reported diagnosis, not only whether the diagnosis code was technically assigned in a way that matches the note. A clinical validation audit and a standard coding audit can reach different conclusions about the same chart.

Review Area

Audit Question

Possible Finding

Diagnosis coding

Does ICD-10-CM match the documented condition and its specificity?

Unsupported or non-specific diagnosis

Procedure coding

Does CPT or HCPCS match the documented service?

Wrong code, missing add-on, incorrect units

Modifiers

Does the modifier reflect what the documentation shows?

Missing, misused, or unsupported modifier

Medical necessity

Does the record justify the service under payer policy?

Necessity denial risk

Payer edits

Does the code combination clear NCCI, MUE, and LCD or NCD checks?

Bundling or coverage conflict

AMA CPT resources maintain the official Current Procedural Terminology code set referenced throughout this process. For diagnosis coding, CMS ICD-10 files currently distinguish FY2026 files, used for dates of service through September 30, 2026, from FY2027 files, which apply to encounters beginning October 1, 2026. HCPCS Level II updates follow their own schedule through the CMS HCPCS updates page.

Medical Coding Audit vs. Medical Billing, Claims, and Documentation Audits

How the Four Audits Differ

Audit

Primary Focus

Typical Records

Main Output

Medical coding audit

Code and documentation alignment

Notes, code assignments, claim lines

Coding findings and accuracy rate

Medical documentation audit

Completeness and support in the record

Clinical notes and supporting records

Documentation findings

Medical claim audit

Accuracy and context of the submitted claim

Claims, records, remittances

Claim-level discrepancies

Medical billing audit

The full billing and collections workflow

Registration through payment

Revenue-cycle findings

A medical coding audit and a medical claim audit sound interchangeable and are not. A coding audit asks whether the codes match the note. A claim audit asks whether the claim itself, including the form, the payer rules, and the coverage policy, was built correctly.

A claim can carry perfectly accurate codes and still fail because the place-of-service field was wrong or an LCD requirement wasn't met.

When a Practice Needs More Than a Coding Audit

A coding review alone will not catch every problem in the revenue cycle. Eligibility issues, prior authorization gaps, claim formatting errors, clearinghouse rejections, payment-posting mistakes, underpayments, denial follow-up, and aging accounts receivable all sit outside a coding audit's scope. Finding a clean set of codes on a chart tells you nothing about whether that same claim got paid correctly.

When findings extend past documentation and coding into how claims move through the system, the review that answers those questions is a revenue cycle management services review rather than a coding audit. MedSole RCM's revenue cycle page covers registration through payment posting, alongside its current billing and credentialing pricing.

Why Medical Coding Audits Matter in 2026

Compliance and Overpayment Risk

Documentation has to support the diagnosis and the service represented on a claim. Implying it isn't enough. An unsupported diagnosis code can create both payment exposure and risk-adjustment exposure if the plan is a Medicare Advantage plan.

Procedure codes need to align with the place of service and the surrounding claim context. Errors that repeat across multiple charts usually point to a workflow, template, or training gap rather than a one-off mistake.

Revenue and Denial Risk

Coding errors cut both ways. Overcoding creates overpayment and recoupment risk. Undercoding causes reimbursement a practice earned but never collected. Errors in modifiers, diagnosis specificity, NCCI edits, units, or place of service can trigger rejections, denials, or unexplained payment variance, and none of that shows up clearly unless audit findings get connected to actual claim and denial data.

When coding review starts turning up claim-level and denial-level problems as well, that's usually a sign the practice needs outsourced medical billing services rather than another isolated fix, since claims, denials, payment posting, and reporting all sit under one connected process.

What Recent OIG Findings Show

Two 2026 reports from the HHS Office of Inspector General illustrate how documentation, diagnosis validity, and claim context interact. Neither example means every provider faces the same exposure. Both show what OIG scrutiny looks for.

In June 2026, OIG's acute-stroke audit sampled 97 Medicare Advantage enrollees whose plans had submitted acute-stroke diagnosis codes. None of the 97 records supported the diagnosis, and OIG estimated CMS made $462 million in potential net overpayments to MA organizations for 2021 as a result.

The figure is a potential estimate, not a confirmed recovery amount, and OIG did not recommend recouping it. Its recommendation was prepayment prevention.

In March 2026, a separate OIG emergency-department review found more than $15 million in improper and potentially improper Medicare payments tied to emergency-department procedure codes billed with a non-emergency place of service or revenue center code. Physician claims alone accounted for over $922,000 of that total.

For context on where OIG expects providers to focus internally, its OIG compliance guidance describes its General Compliance Program Guidance as voluntary and nonbinding, not a mandatory checklist.

Types of Medical Coding Audits

Internal vs. External Audits

An internal audit is run by a practice's own qualified staff. It works well for routine monitoring, staff education, and ongoing quality improvement, but internal reviewers can miss issues they've grown used to seeing.

An external audit is run by an independent reviewer and adds objectivity, specialty expertise, and a useful benchmark against other practices. Neither model automatically produces a more accurate result on its own.

Who should conduct an external coding audit? An external coding audit should be led by a reviewer with relevant coding, auditing, payer-policy, and specialty experience who is independent from the coding work under review. Credentials help establish competence, but a practice should still evaluate the reviewer's methodology, independence, and report quality before hiring.

Prospective vs. Retrospective Audits

A prospective audit, sometimes called a pre-bill audit, happens before claim submission. It suits new providers, new coders, high-risk services, and active education, and it can reduce preventable errors, though it can't eliminate every denial. A retrospective audit happens after submission or payment and works best for trend analysis, payment-variance review, denial patterns, and historical exposure.

Practices building out a prospective review often pair it with medical claim submission services, since catching an error before the claim goes out depends on the submission workflow being tight in the first place.

Focused, Random, and Risk-Based Audits

A focused audit narrows in on one provider, coder, code, service, modifier, or known problem. A random audit selects records without targeting any specific concern, which makes it useful for a general accuracy snapshot.

A risk-based coding audit selects charts because of financial, compliance, denial, utilization, or documentation risk. That makes it the right tool when you already suspect where the exposure sits.

Payer and Government Reviews

Several government and payer review programs sit outside a practice's own audit process: Medicare Administrative Contractor medical review, CMS Targeted Probe and Educate, Recovery Audit Contractor review, Unified Program Integrity Contractor review, and commercial payer audits.

CMS describes a traditional TPE round as generally covering 20 to 40 claims, though current program variations, including a low-volume track, can use smaller samples. That figure belongs to TPE specifically, not a general rule for internal audit sample size. Appeal steps for these government reviews are covered later in this guide.

When Should a Practice Conduct a Medical Coding Audit?

Scheduled Review Triggers

Risk-based scheduling makes more sense than a fixed calendar. Common triggers include new providers, new coders, high-volume services, high-dollar procedures, time-based services, frequent modifier use, new locations, and newly introduced service lines.

Event-Based Review Triggers

Certain events should prompt a review regardless of when the last one happened: a denial spike, a shift in coding distribution, an EHR or practice-management migration, the annual CPT or ICD-10-CM update, a payer-policy change, repeated documentation questions from staff, a payer medical-record request, a merger or acquisition, findings from a prior audit, or unexplained write-offs and payment variance.

Risk-Based Frequency Matrix

Situation

Suggested Response

Stable, low-risk environment

Periodic representative review

New coder or provider

Early focused review, then a recheck

High-risk code family

More frequent focused audit

Payer-rule change

Targeted review after implementation

Previous material finding

Re-audit after corrective action

External audit notice

Separate response workflow

How often should a medical coding audit happen? There's no single correct interval. Frequency should reflect risk, claim volume, recent changes to staff or coding, and prior findings. It isn't a fixed monthly or annual rule applied the same way everywhere.

Providers who want a sense of where federal attention is currently concentrated can check the current OIG Work Plan, which changes throughout the year rather than staying fixed to one published list.

How to Set Audit Objectives, Scope, and Ownership

Select One Primary Audit Objective

Objective

Main Question

Coding accuracy

Do the assigned codes match the documentation?

Compliance

Are the codes supported by applicable rules and policies?

Revenue

Are supported services being missed or undervalued?

Denial reduction

Which coding patterns cause payer rejection?

Education

Which providers or coders need targeted support?

Audit response

What records and claims fall within the external request?

An audit can carry secondary goals, but it needs one defined primary objective before anyone pulls a chart. Trying to answer every question at once is how audits turn into unfocused chart reviews that don't hold up under scrutiny.

Define the Audit Scope

Scope should specify the providers, coders, locations, specialties, payers, date range, code families, claim status, service settings, risk categories, and excluded records under review. A vague scope produces vague findings, and vague findings don't survive a payer's follow-up questions.

Assign Roles and Decision Rights

Every audit needs an audit sponsor, an auditor, a coding lead, a clinical reviewer where clinical validation applies, a compliance lead, data or EHR support, an education owner, and a corrective-action owner. Someone also needs to be named in advance to resolve disagreements between the auditor and the provider being reviewed, before that disagreement happens.

What should be defined before beginning an audit? Objective and scope come first. They determine everything downstream: how the sample gets built, what counts as a finding, how the report is structured, and what corrective action follows.

How Many Charts Should a Medical Coding Audit Review?

There is no universal number of charts that makes every medical coding audit representative. The right sample depends on the audit objective, the population under review, the expected error risk, and the provider and payer mix.

Whether findings will be projected across a larger claim population changes things too. A small focused sample can support education. Financial extrapolation needs a properly designed statistical method.

Match the Sample to the Audit Objective

Objective

Sampling Approach

Routine quality snapshot

Random representative selection

New-provider review

Provider-specific focused sample

Modifier concern

Modifier-focused sample

Denial investigation

Denial-based targeted sample

High-dollar exposure

Risk-based coding audit

Overall financial estimation

Statistically designed sample

External audit response

The requested population, as defined

Why Fixed Chart Counts Can Mislead

Ten charts might reveal a real issue, but they can't measure organization-wide accuracy on their own. A larger sample isn't automatically unbiased either, and selecting only the charts you already suspect are problems can't support any claim about overall performance.

The sampling unit, frame, selection method, and projection method all need documentation. The final error count on its own isn't enough. TPE's 20 to 40 claims per round, mentioned earlier, is a CMS program rule built for a specific purpose, never a general internal-audit standard.

When Statistical Expertise Is Needed

Bring in statistical support when you're extrapolating overpayments, estimating organization-wide error rates, building confidence intervals, reviewing a large claim population, or responding to a matter with potential legal or repayment consequences.

OIG RAT-STATS is a free statistical package OIG makes available to providers for claims-review sampling, and it's also the primary tool OIG's own Office of Audit Services uses. Using it doesn't automatically make a sample statistically valid. The sample design still has to be sound.

How to Conduct a Medical Coding Audit: 10-Step Process

How do you audit medical coding? The process runs in a fixed sequence, from confirming scope through assigning corrective action. Skipping steps is usually where audits lose defensibility.

Step 1. Confirm the Objective and Scope

Reference the objective, population, date range, payer mix, and providers or services already defined during planning. There's no need to redo that work here. Confirm it before pulling a single chart.

Step 2. Select and Document the Sample

Record the sampling method, sampling frame, selection date, sample size, inclusion criteria, exclusion criteria, and the reason for choosing that method. Don't call a sample statistically representative unless it was designed to be one.

Step 3. Collect the Complete Record and Claim Data

Gather the progress notes, orders, test results, operative reports, time records, claims, remittance data, charge-entry data, prior authorization material, and payer correspondence tied to each encounter in the sample.

Step 4. Verify Record Completeness and Authentication

Confirm patient identity, date of service, provider identity, signature or electronic authentication, addenda, required orders, supporting reports, and encounter status before reviewing anything else.

Step 5. Validate ICD-10-CM Diagnoses

Check the documented condition, specificity, laterality, encounter status, whether the condition is acute or history, diagnosis sequencing, and whether each diagnosis links to the service billed.

Step 6. Validate CPT and HCPCS Services

Confirm the service was performed, the code selected describes it, required components are documented, units and add-on codes are appropriate, and the code was valid for the date of service.

Step 7. Review E/M Levels, Time, and Modifiers

Check medical decision-making or time as the basis for the E/M level, total time where it's used, modifier 25, modifier 59 or the X modifiers, professional and technical component splits, repeat-service modifiers, and global-period modifiers. This step isn't a complete modifier reference on its own.

Step 8. Apply NCCI, MUE, Coverage, and Payer Rules

Review National Correct Coding Initiative Procedure-to-Procedure edits, Medically Unlikely Edits, Local Coverage Determinations, National Coverage Determinations, payer-specific medical policies, and frequency and unit limits. CMS confirms that its CMS NCCI edits and quarterly update files are published through its official NCCI resources, and that replacement files can be issued outside the normal quarterly schedule when needed.

Place-of-service accuracy belongs in this step too, since place-of-service coding errors can trigger the same kind of automatic rejection as a bundling conflict, even when the procedure code itself is correct.

Reference the CMS Place of Service codes set and, where a coverage question is involved, the Medicare Coverage Database for the applicable LCD or NCD.

Step 9. Classify Findings and Identify Root Causes

Record whether each finding traces back to code selection, documentation, a modifier, units, medical necessity, payer policy, workflow, a template, training, or claim construction. Save the accuracy math and severity grading for after every chart in the sample has been reviewed.

Step 10. Report Findings and Assign Next Actions

Every finding handed to leadership should include the finding itself, the supporting rule, a responsible owner, a due date, whether education is needed, whether a claim correction is needed, whether a financial review is needed, and a re-audit date.

Providers who work through these 10 steps and find that errors extend past coding into how claims get submitted often need a broader fix than a coding correction alone. Clean claim submission support addresses that gap directly, since a correctly coded chart still needs a correctly built claim behind it.

Complete Medical Coding Audit Checklist

A medical coding audit checklist turns the 10-step process into something a reviewer can work from, chart by chart. Use it as the backbone of the review whether you're covering 10 charts or 10,000.

Pre-Audit Setup Checklist

Record these before pulling a single chart:

  • Primary objective
  • Audit type
  • Audit population
  • Providers and coders included
  • Specialty and payers
  • Date-of-service range and claim-status range
  • Sampling method and sample size
  • Inclusion and exclusion criteria
  • Applicable coding year
  • Auditor name and qualifications
  • Planned report date and re-audit date
  • Whether results will be projected beyond the sample, and if so, the statistical methodology behind that projection

What Makes Documentation Audit-Ready?

Audit-ready documentation is complete, authenticated, dated, and specific to the encounter. It stays consistent across the record, states medical necessity clearly, and supports the diagnosis and procedure codes billed.

It also documents time where time is the basis for the code, ties back to orders and results where those are required, skips contradictory copied-forward content, and is retrievable within whatever response window a payer or auditor sets.

Encounter-Level Review Checklist

Work through each encounter in this order.

Record completeness: correct patient, correct date of service, correct rendering provider, a signed or authenticated note, available orders and reports, clearly dated addenda, and time records where needed.

Diagnosis review: the condition is documented, the ICD-10-CM code is supported at the right specificity and laterality, the encounter character (acute, chronic, history, or status) is correct, the diagnosis links to the service, and sequencing follows guidelines.

Service review: the CPT or HCPCS service was performed, documentation supports the reported service and E/M level, time is documented where used, units and add-on codes are correct, place of service is correct, and any modifier is supported.

Compliance review: medical necessity is supported, NCCI edits and MUEs are checked, the applicable LCD or NCD is reviewed where relevant, payer policy and frequency limits are checked, and authorization requirements are noted where they apply.

Post-Review Handoff Checklist

Every reviewed chart should leave the auditor's desk with a finding category, a severity level, the supporting rule, the correct code or action, financial variance, root cause, education needs, whether a claim correction or refund review is needed, an owner, a due date, and a re-audit date.

Common Errors Found During Medical Coding Audits

Diagnosis Coding Errors

The most common diagnosis-level findings include an unsupported diagnosis, insufficient specificity, incorrect laterality, the wrong encounter character, an active condition documented as history (or the reverse), a diagnosis that never links to the service billed, incorrect sequencing, and an unsupported risk-adjustment diagnosis.

Each one traces back to a specific cause, whether that's a rushed note, a copied-forward template, or a coder guessing at intent. Each carries its own claim or compliance risk.

CPT and HCPCS Errors

Procedure-level findings include a service the documentation doesn't support, the wrong procedure code, a deleted or inactive code, a missing service that was performed, incorrect units, an incorrect add-on code, incorrect component billing, and the wrong place of service. Not every incorrect code points to fraud. Intent, knowledge, and context all matter before anyone draws that conclusion.

E/M and Time Documentation Errors

Watch for unsupported medical decision-making, missing total time, time entries that include activities that don't count toward the code, a pattern of consistently high E/M levels without matching support, template language that doesn't reflect the actual encounter, and incomplete documentation on split or shared services where those apply.

Modifier, Bundling, and Edit Errors

Modifier 25 used without a separately identifiable E/M service. Modifier 59 or an X modifier applied without support for a distinct service. A missing professional or technical component modifier. The wrong global-period modifier. Unbundling. Units that exceed what the documentation supports. An edit bypassed without anything in the chart to justify it.

Finding

Immediate Outcome

Longer-Term Risk

Missing modifier

Rejection or reduced payment

Recurring denial pattern

Unsupported modifier

Incorrect payment

Recoupment exposure

Missing diagnosis specificity

Medical-necessity denial

Delayed accounts receivable

Undercoding

Lower reimbursement

Revenue leakage

Unsupported code

Overpayment

Refund or audit exposure

Coding errors only tell half the story until they're traced into the denials they caused. That's the job of denial management services, which connects a coding finding to the specific denial category it produced and corrects the workflow behind it, not the one claim alone.

Modifier problems deserve extra attention because they drive a disproportionate share of denials. If modifier 59 or the X modifiers keep showing up in your findings, modifier-related CO-4 denials is worth a closer read, since CO-4 is the specific reason code payers use when a modifier and procedure code don't match.

When the same coding issue shows up across multiple denials, the fix is correcting the workflow that's generating the error, not reworking each denied claim as if it were unrelated to the last one.

How to Calculate Coding Accuracy and Financial Impact

There's no single accuracy formula that fits every audit. Before calculating anything, the report needs to define what unit is being measured, what counts as an error, whether multiple errors can exist within one chart, whether documentation findings and coding findings are being reported separately, and whether financial impact is measured or projected.

Chart-Level Accuracy

Chart-level accuracy = charts with no reportable findings, divided by total charts reviewed, times 100.

Hypothetical example: 50 charts reviewed, 42 with no reportable findings, gives a chart-level accuracy of 84%.

A chart with one minor finding and a chart with several material findings both count as inaccurate under this formula, so severity needs its own separate report. Chart-level accuracy alone can't tell leadership which failing charts matter most.

Code-Element Accuracy

Code-element accuracy = correct code elements, divided by total code elements reviewed, times 100. Code elements can include diagnosis codes, CPT codes, HCPCS codes, modifiers, units, and place of service. Define the unit before calculating the percentage, or the number won't mean anything to whoever reads the report next.

Error Rate

Error rate = audited units with errors, divided by total audited units, times 100. Don't compare two organizations' error rates unless both used the same denominator and the same definition of what counts as an error.

Financial Impact

Calculate underpayment and overpayment separately.

Potential underpayment opportunity = supported allowed amount minus actual allowed or paid amount.

Potential overpayment exposure = actual allowed or paid amount minus supported allowed amount.

A financial result from a targeted sample shouldn't get extrapolated across the full claim population unless the sampling and projection methodology supports that conclusion. That distinction matters more than the dollar figure itself.

Recommended Audit Dashboard

A useful dashboard tracks chart-level accuracy, code-element accuracy, findings by severity, findings by provider, findings by coder, findings by code family, estimated underpayment, estimated overpayment, the connection to denial data, corrective actions completed, and re-audit outcomes.

Findings that point to a supported underpayment or a claim stuck in review often need follow-up beyond the coding fix itself. That's where accounts receivable follow-up picks up, chasing the claim until it's resolved instead of leaving it in the queue.

How to Classify Medical Coding Audit Findings by Severity

Five-Level Finding Framework

Level

Definition

Typical Response

Critical

Potential unsupported payment, material compliance exposure, or a systemic high-risk issue

Escalate immediately

High

Coding or modifier error with meaningful payment or denial impact

Correct promptly and educate

Moderate

Documentation or process weakness that may affect support or payment

Assign corrective action

Low

Technical inconsistency with limited immediate impact

Monitor and correct

Opportunity

A supported service or specificity that wasn't captured

Review for compliant revenue improvement

Severity Is Not the Same as Frequency

A rare, high-dollar unsupported service can be critical on its own. A frequent, low-dollar technical issue can still be operationally significant because of how often it repeats. Severity, frequency, financial impact, and recurrence deserve separate reporting lines, not one blended score. An opportunity finding is a chance to review for compliant revenue improvement, not a promise of recoverable revenue.

Required Finding Fields

Every finding should carry a category, severity, frequency, financial impact, supporting rule, root cause, required action, owner, due date, and a re-audit criterion. Severity grades the finding. It doesn't establish intent, and the report should say so.

What Should a Medical Coding Audit Report Include?

Executive Summary

Leadership should be able to read the executive summary alone and understand the main result: the audit objective, scope, review period, providers and locations, payers, sample method and size, the primary result, the highest-risk findings, estimated financial impact, and immediate recommendations.

Methodology

Document the audit population, sampling frame, selection method, inclusion and exclusion criteria, the coding and payer references used, how accuracy and error were defined, the projection method if one was used, auditor and reviewer roles, and the audit's limitations.

Detailed Findings Table

A defensible findings table includes the encounter ID, date of service, provider, specialty, payer, billed diagnosis, recommended diagnosis, billed CPT or HCPCS, recommended CPT or HCPCS, modifier, documentation finding, medical necessity finding, edit or payer-policy finding, severity, financial variance, root cause, corrective action, owner, due date, and re-audit result.

Recommendations and Action Plan

Group recommendations by immediate claim correction, provider education, coder education, EHR template changes, policy updates, payer-rule updates, workflow correction, additional focused audits, and re-audit.

Downloadable Report Assets

A complete audit program typically produces a blank Excel worksheet, a blank audit-report template, a completed and anonymized example report, and a printable PDF checklist. None of these should ever include real PHI, identifiable provider information, or actual patient data.

Audit findings only stay useful if someone tracks them against what's happening in the revenue cycle. RCM reporting services connect audit results to denial trends, collections, and claim outcomes, so a finding doesn't sit in a report nobody revisits.

Corrective Action and the 30, 60, 90-Day Re-Audit Plan

Immediate Response: Days 0 to 10

Validate the finding, confirm the applicable rule, and stop any active workflow defect from generating more of the same error. Identify affected claims, assign a responsible owner, determine whether compliance or legal review is needed, and preserve the supporting documentation. Don't rebill, refund, or appeal before the finding and the applicable payer process are both confirmed.

First 30 Days

Complete root-cause analysis, correct affected templates, and update coding instructions. Educate the providers and coders involved, review the related denial categories, check whether the issue extends beyond the original sample, and set the baseline you'll measure against later.

Days 31 to 60

Monitor newly submitted claims, track whether the finding is repeating, confirm education was completed, review the financial corrections made, check how denial numbers are moving, and test the updated templates and workflows under real conditions.

Days 61 to 90

Run a focused re-audit using the same criteria defined at the start. Compare the new results against the baseline, close out corrected findings, escalate anything still unresolved, and set the next monitoring date before closing the file.

Confirmed Medicare Overpayments

When an audit identifies a potential Medicare overpayment, validate and quantify the issue first, and involve qualified compliance or legal support where the situation calls for it. CMS states that a self-identified overpayment generally must be reported and returned within 60 days of identification, or by the applicable cost-report due date if that's later.

This isn't individualized legal advice, and it doesn't apply automatically to every commercial payer. Payer rules and circumstances vary.

Specialty-Specific Medical Coding Audit Risks

Specialty Risk Matrix

Specialty

Recommended Audit Focus

Primary care

E/M levels, preventive services, modifier 25, chronic-condition documentation

Behavioral health

Time-based codes, psychotherapy add-ons, telehealth documentation, group versus individual services

Cardiology

Diagnostic components, add-on codes, device services, supervision, medical necessity

Orthopedics

Laterality, injections, global periods, surgical modifiers, imaging

Podiatry

Q modifiers for routine foot care, laterality and toe modifiers, class-finding documentation, wound and debridement coding, global-period surgical modifiers

Pain management

Procedure indications, levels and sites, sedation, drug codes, NCCI relationships

Radiology

Orders, interpretation, professional and technical components, place of service

Surgery

Global surgery rules, assistant-at-surgery, unbundling, multiple-procedure modifiers

PT, OT, and SLP

Timed units, plan of care, progress documentation, therapy modifiers

Infusion services

Drug units, wastage modifiers, administration hierarchy, orders

Hospital inpatient

Principal diagnosis, secondary diagnoses, present-on-admission status, DRG effect

Risk adjustment

Face-to-face support, active condition status, diagnosis validity

Home health

Orders, certification, plan-of-care documentation, episode timing

How to Use the Matrix

Select the specialty-specific risks that apply to your practice rather than auditing every row with equal frequency. Combine specialty risk with payer mix, volume, denial history, and financial exposure, and verify anything you find against current payer and date-of-service rules instead of applying one coding rule across every setting.

Podiatry carries its own documentation pressure points beyond the routine foot care rules covered here. For nail, callus, wound, and Q-modifier detail specific to that specialty, MedSole's podiatry CPT codes and billing guide covers the code-level and modifier-level requirements a general coding audit checklist won't spell out.

2026 Risk-Adjustment Evidence

A 2026 OIG audit of Priority Health's risk-adjustment submissions found that medical records failed to support the diagnosis codes for 252 of 300 sampled enrollee-years. OIG estimated the plan received at least $4.4 million in net overpayments for the years reviewed.

That result supports a focused look at diagnosis validity and record support anywhere risk-adjustment coding is part of the audit scope.

Internal Risk-Adjustment Mock Audit

A risk-adjustment mock audit generally works through these steps: define the member and date-of-service population, select the diagnoses submitted for risk adjustment, retrieve the complete qualifying medical record, confirm patient, provider, date, and encounter validity, and verify that the diagnosis was documented and addressed.

From there, check whether clinical indicators support the condition where clinical validation applies, confirm code specificity, identify unsupported additions or conditions that should come off the claim, record education needs for the coder and provider involved, and re-audit after corrective action.

None of this should be used to justify adding diagnoses to raise a risk score. That's the exact pattern OIG audits are built to catch.

For practices weighing whether a specialty carries enough risk to need dedicated coverage, specialty medical billing services breaks down billing and coding support across the specialties MedSole RCM already works with.

Medical Coding Audit Tools, Software, and AI-Assisted Auditing

What Is a Medical Coding Audit Tool?

A medical coding audit tool supports the review process itself: selecting claims and charts, importing claims and coding data, comparing coding patterns, flagging outliers, tracking findings, storing coding-rule references, calculating error rates, generating reports, assigning corrective actions, and tracking re-audit results.

An audit tracking tool, a coding encoder, a claim-editing tool, a documentation review tool, an AI-assisted coding platform, and a revenue-integrity analytics platform solve different problems. Treating them as interchangeable is how practices end up with a tool that does none of these jobs particularly well.

What Medical Coding Audit Software Should Evaluate

Capability

Audit Purpose

ICD-10-CM validation

Diagnosis accuracy and specificity

CPT and HCPCS review

Procedure and service validation

Modifier checks

Modifier support and edit relationships

NCCI and MUE logic

Bundling and units review

Documentation comparison

Support for billed services

Payer-rule library

Payer-specific compliance

Denial integration

Rejected and downcoded claim patterns

Financial variance

Underpayment and overpayment review

Finding management

Severity, owner, due date, and status

Audit trail

Documentation of reviewer actions

How to Audit Auto-Coding Logic to Prevent Misclassification

Define the expected coding outcome before testing anything, then build a validation dataset that includes common cases and known high-risk ones. Compare the automated output against qualified human review, and record every false positive and false negative you find. Test code specificity, modifiers, units, and medical necessity, and review how the tool handles payer-specific logic.

Retest against new annual code-set updates, restrict automation in any area where confidence is low, and revalidate the whole process after any model, rule, or template change. The provider stays responsible for the claim even when software recommends or assigns the code. That responsibility doesn't shift to the software because it made the first pass.

How AI-Assisted Coding Audits Identify Undercoding and Revenue Leakage

AI-assisted review tends to be useful for spotting missing charge patterns, coding distributions that run lower than expected, services that were documented but never billed, missed add-on codes, missing diagnosis specificity, and repeated downcoding.

It's also useful for spotting gaps between providers who otherwise have similar service mixes. None of this proves recoverable revenue on its own. It surfaces patterns a human reviewer still has to validate.

How AI Supports Denial Prevention

AI tools can identify high-risk claim patterns, compare current claims against past denial data, flag payer-specific problems, catch missing or inconsistent information, and prioritize charts for human review. What they shouldn't do is generate provider documentation, bypass payer rules, assign final codes without human governance, or treat a statistical correlation as proof of medical necessity.

E/M Audit Tools and MDM Evaluation Matrices

An E/M-focused audit tool or matrix should walk through the problems addressed, the data reviewed and analyzed, the risk of patient management, time where it applies, the final E/M level, the auditor's rationale, and any documentation gap identified. Keep that matrix scoped to audit use. It isn't a substitute for a full E/M coding reference.

Practices weighing whether their internal coding team has the bandwidth for this level of review often find that capacity, not the audit tool, is the real constraint. Acting on what the tool finds takes staff time the coding team doesn't always have.

Private practice RCM support and full-service medical billing both exist for that gap, and provider enrollment services keep credentialing from becoming the reason a clean claim still can't be billed.

Internal Teams, External Audit Services, and MedSole Pricing

An internal team can usually handle routine monitoring and day-to-day education without outside help, especially once a practice has a defined objective, a repeatable sampling method, and a reviewer with real bandwidth to run it.

The gap shows up when volume, specialty complexity, a payer audit, or a compliance concern outpaces what that internal team can cover without falling behind on regular coding work.

External support makes sense for high-volume specialty coding, a first risk-adjustment review, preparation for a payer or government audit, or a finding serious enough that an independent second opinion matters. Whichever direction a practice chooses, the same evaluation questions apply to any partner being considered.

Before signing on with an external coding audit partner or a broader billing partner, confirm their coding and auditing credentials, their specialty experience, and their independence from any billing work they're also performing for you.

Confirm their sampling and projection methodology too, and ask what a finished report from them looks like before you need one. You'll learn more from one sample report than from any sales sheet.

Pricing is part of that evaluation, and MedSole RCM keeps its structure simple: full-service medical billing is priced at 2.99% of payer collections, and provider enrollment and credentialing is priced separately at $99 per insurance.

Coding review, claim submission, denial management, accounts receivable follow-up, payment posting, and reporting are all handled within that billing workflow. If a coding audit is the only service a practice needs right now, confirm the scope in writing before assuming it's bundled into a broader engagement.

Medical Coding Audit FAQs and Next Steps

What is a medical coding audit?
A medical coding audit compares clinical documentation against the CPT, ICD-10-CM, HCPCS, and modifier codes billed on a claim. It identifies unsupported or missed coding and documentation gaps, and it exists for quality improvement and compliance monitoring as much as error counting. The full breakdown is in the definition section above.

How often should a practice conduct a coding audit?
Frequency should be risk-based rather than fixed to a calendar. Provider or coder changes, service-line changes, denial trends, payer updates, and prior audit findings all factor in, along with whether a code family carries known high risk. There's no single interval that fits every practice.

How many charts should be reviewed?
There's no universal chart count. A small, focused sample can support coder or provider education. Extrapolating findings across a larger claim population, especially for financial estimates, needs a statistically designed sample, not a bigger stack of charts.

Who should perform an external coding audit?
Look for independence from the coding work under review, specialty experience, coding and payer-policy expertise, a defined sampling and reporting methodology, and relevant credentials. Credentials alone don't confirm quality. Ask to see how the reviewer documents and reports findings.

What should a medical coding audit checklist include?
A complete checklist covers scope and sampling, documentation completeness, diagnosis and procedure code validation, modifiers, units, medical necessity, payer-policy checks, findings classification, corrective action, and a re-audit date. The full working checklist is in the section above.

How is coding accuracy calculated?
Start by defining the denominator. Chart-level accuracy measures the share of charts with no reportable findings. Code-element accuracy measures the share of individual code elements, like diagnoses, procedures, or modifiers, that are correct. Neither number means much without that definition stated up front.

What happens after errors are found?
Validate the finding, grade its severity, assess the financial impact, identify the root cause, and assign a corrective action with an owner and a due date. Education and claim correction usually follow, along with a re-audit to confirm the fix held.

Can I download a medical coding audit template?
A complete audit program includes a PDF checklist, an Excel worksheet, a blank report template, and an anonymized completed example. Request a coding review to get the current set from MedSole RCM.

How much do MedSole's services cost?
MedSole RCM's full-service medical billing is priced at 2.99% of payer collections, and provider enrollment and credentialing is priced separately at $99 per insurance. If you only need the coding-audit piece, confirm the scope before assuming it's included in a broader engagement.

Find the Coding and Revenue Risks Behind Your Claims

A coding audit should surface more than a handful of isolated errors. MedSole RCM connects what an audit finds to the claims, denials, payments, accounts receivable, and reporting around it, and the practice keeps access to its own data and findings throughout.

The first step is a focused conversation about your specialty, payer mix, and audit objective, not a generic sales pitch.

Request a coding review to start that conversation.

About the Author
Andrew Christian

Andrew Christian

Billing Manager

Andrew Christian is the Billing Manager at MedSole RCM, bringing 12+ years of experience in medical billing, coding, and revenue cycle management across multiple specialties. He is highly skilled in claims submission, denial management, payment posting, and payer follow-up, ensuring maximum reimbursement for providers. Andrew works closely with Medicare, Medicaid, and commercial payers, supporting hundreds of providers nationwide. His proven billing approach minimizes claim rejections, accelerates cash flow, and drives stronger financial performance from day one.