Who audits, and why it matters operationally
Medicare's integrity infrastructure — Recovery Audit Contractors reviewing post-payment claims and Unified Program Integrity Contractors investigating fraud, waste and abuse — plus commercial payer special investigation units all work the same raw material: your claim data. They select populations by statistical signal: providers whose E/M level distribution deviates from peers, modifier usage that clusters oddly, or codes with elevated error rates nationally.
The practical implication: outliers attract audits. Consistent, documented patterns — even conservative ones — are safer than irregular, unexplained ones. A provider billing nothing but 99215s is as visible as one billing nothing but 99213s, and both invite review.
The four populations auditors target first
Across contractor audits, the same four claim families dominate findings. Each maps to a documentation discipline:
- E/M leveling: does the medical decision making documented support the level billed? The 2021+ guidelines shifted the test from checklist history to complexity — and auditors read the MDM section closely
- Modifier use: modifier 25 on same-day E/M with procedures requires a significant, separately identifiable service; modifier 59/XS requires genuinely distinct services. Empty or templated modifier support is the most common denial finding
- Medical necessity: diagnosis codes, frequency and treatment history must justify the service, especially for repetitive services (injections, therapies, diagnostics)
- Code combinations and units: NCCI Procedure-to-Procedure edits and Medically Unlikely Edits define what can bill together and in what quantity — claims that bypass them are automatically suspect
“48% of leaders named denials and appeals their practice's largest source of revenue leakage, compared with 23% who cited front-end issues.”
Extrapolation: why small error rates get expensive
In post-payment audits, a sample of paid claims is reviewed, an error rate is computed, and — where contracts permit — that error rate is extrapolated across the entire claim population for the review period. A 4% error rate on a code billed 8,000 times per year is not a 320-claim problem; it is a repayment demand on a multiplier of them.
This is why audit defense is not a documents-to-gather exercise when the letter arrives. The only durable defense is systemic: an error rate low enough that the extrapolated number is a nuisance instead of a crisis, verified by your own scrubbing layer on every claim, not a spot-checked sample.
The documentation discipline that withstands review
Auditors ask one question: can a reviewer reconstruct the billed service from the note alone, without the provider explaining it later? Build every encounter to that test:
- MDM elements match the billed level — problems addressed, data reviewed, risk managed
- Modifier 25 same-day services have a distinct interval note or clearly separate problem discussion
- Surgical and procedural notes document findings, technique, specimens and dispositions
- Time-based codes carry start/stop times and total minutes
- Medical necessity narrative answers "why this service, for this patient, now"
- Diagnoses link logically to procedures — no diagnosis "support" that inverts causality
Self-audit before the payer does
The strongest audit posture is a practice that reviews itself: sample each provider's high-volume codes quarterly, score them against the same criteria auditors use, and fix documentation templates before patterns harden. When findings are corrected prospectively, the extrapolation math never has a period to attach to.
EntireRCM builds this in: our coding reviews run against AAPC standards on every claim, level distributions are reported per provider monthly, and our compliance team flags documentation patterns that trend toward the audit populations above. It is easier to answer a letter when you found the issue first — see our billing and charge capture service or request the free audit for a baseline.