Medical Billing Audit Checklist

Medical Billing Audit Checklist — illustration

A billing audit is a systematic review of how claims are created, submitted, followed up, and paid. Done well, it finds the exact places where revenue leaks — miscoded claims, unworked denials, underpaid contracts, documentation gaps — and turns them into a fix list with owners and deadlines.

This checklist follows the same structure a professional auditor uses, written so a practice can self-assess. If you would rather have an outside review, our medical billing audit service works through these same steps.

1. Claim submission review

Start at the beginning: are clean, complete claims actually leaving the building?

  • [ ] Pull a representative sample of submitted claims. Cover all major payers, all providers, and a recent date range. Include both paid and unpaid claims — auditing only paid claims hides the problems.
  • [ ] Verify patient demographics and eligibility on each sampled claim. Name, date of birth, member ID, and coverage effective on the date of service. Demographic and eligibility errors are among the most preventable denial sources.
  • [ ] Check timely filing. Confirm each claim was submitted within the payer’s filing limit, and flag any that missed it — along with the reason why.
  • [ ] Review claim scrubber edits. Look at which edits fired, whether they were resolved or overridden, and whether the overrides were justified. Routinely overridden edits are a process failure wearing a disguise.
  • [ ] Trace several claims end to end. From encounter documentation to submitted claim to remittance advice — every handoff is a place where data degrades. The trace shows you where.

2. Coding accuracy sampling

Coding is where small errors become expensive patterns. For a deeper dive devoted entirely to coding, see our medical coding audit checklist and our medical coding services page.

  • [ ] Compare coded claims against the clinical documentation. Every CPT and ICD-10 code on the claim should be supported by the note. If the note does not say it, the claim should not code it.
  • [ ] Review E/M level selection. Confirm the documented history, exam, and medical decision-making support the level billed — or that documented time supports time-based coding.
  • [ ] Check diagnosis–procedure linkage. Each procedure should link to a diagnosis that justifies medical necessity for it.
  • [ ] Sample across providers and coders. Coding habits vary by person. A sample drawn from one provider does not represent the practice.
  • [ ] Categorize every finding. Upcoding, downcoding, unbundling, missing codes, modifier errors — categorized findings turn into targeted training instead of vague feedback.

3. Denial pattern analysis

Denials are data. This section turns them into decisions.

  • [ ] List the top denial reasons by volume and dollars. A handful of reason codes usually drive most of the damage. Rank them both ways — high-volume small-dollar denials and low-volume large-dollar denials need different responses.
  • [ ] Break denials down by payer. The same denial reason may need a completely different fix for each payer, because payer rules and edits differ.
  • [ ] Separate preventable from unpreventable denials. Eligibility, authorization, and demographic errors are preventable — that is where corrective action pays off fastest.
  • [ ] Measure rework rate and appeal success. What share of denied claims actually gets reworked, how quickly, and what share of appeals succeed? Denials that are never touched are write-offs by neglect.
  • [ ] Check write-off discipline. Confirm contractual adjustments and write-offs follow a written policy with approval thresholds — not individual judgment call by call.

4. A/R aging review

Aging tells you how long money has been waiting and whether anyone is chasing it.

  • [ ] Review aging buckets by payer and provider. Know where the money sits, how long it has sat there, and who is responsible for moving it.
  • [ ] Scrutinize balances over 120 days. Every aged balance needs an action plan: appeal, rebill, move to patient responsibility, or document a write-off. “Monitoring” is not an action plan.
  • [ ] Check for timely filing exposure. Flag claims approaching their filing limits and give them priority — a missed filing deadline turns a collectible claim into a guaranteed write-off.
  • [ ] Verify credit balances. Unapplied credits should be refunded or applied promptly, not left to accumulate. Lingering credit balances are a compliance risk as well as sloppy accounting.

5. Payer contract compliance

You cannot collect what the contract promises if you never check the contract.

  • [ ] Confirm fee schedules on file are current. Outdated fee schedules hide systematic underpayments for months.
  • [ ] Compare paid amounts against contracted rates. Sample paid claims per payer and flag underpayments. One underpaid code across thousands of claims is real money.
  • [ ] Check credentialing and enrollment status. Claims denied for provider enrollment issues point back to credentialing gaps, not billing errors — fix the root cause.

6. Documentation gaps

Weak documentation undermines everything downstream — coding, medical necessity, and audit defense.

  • [ ] Look for unsigned or late documentation. Unsigned notes can stall or invalidate claims, and late documentation suggests encounters are being reconstructed from memory.
  • [ ] Flag copy-paste and cloned documentation. Identical notes across encounters invite payer scrutiny and audit risk, even when the care itself was appropriate.
  • [ ] Confirm medical necessity is documented. The note should explain why the service was needed, not just record that it happened.

7. Compliance red flags

This section protects the practice, not just the revenue.

  • [ ] Scan for upcoding patterns. Consistently high E/M levels relative to the documented complexity deserve a second look — intentional or not, the pattern is what auditors notice.
  • [ ] Review modifier usage. Modifiers such as 25 and 59 must be supported by documentation and consistent with payer policy. Modifier misuse is a frequent audit target.
  • [ ] Check advance beneficiary notice (ABN) usage where applicable. ABNs must be properly executed before billing Medicare patients for services expected not to be covered.
  • [ ] Confirm a business associate agreement is in place with every vendor that touches protected health information, and that data is handled under HIPAA safeguards throughout the revenue cycle.

Frequently asked questions

How often should a practice audit its billing?
At least annually for the full cycle. Between full audits, run quarterly focused reviews — one payer, one denial category, one provider — and audit promptly after an EHR change, a clearinghouse switch, or significant staff turnover. Our medical billing consulting page covers how practices structure ongoing reviews.

What is a good sample size for a billing audit?
Large enough to fairly represent each major payer, each provider, and each service type you bill. There is no single magic number that fits every practice — define the sample before you start, document how you chose it, and keep it consistent so repeat audits are comparable.

Can we audit our own billing?
Yes, for process findings — your team knows the workflows and can spot breakdowns quickly. An outside auditor adds independence and sees habits your team has gone blind to. Many practices do both: internal reviews quarterly, independent audit annually.

What should we do with audit findings?
Prioritize by dollars at risk and compliance risk, assign each finding an owner and a deadline, fix the underlying process (not just the individual claims), and then re-audit to confirm the fix worked. Findings without follow-up are just paperwork.

How long does a billing audit take?
It depends on practice size and scope. A focused review — one payer or one denial category — can take days. A full-cycle audit of a multi-provider practice takes weeks. Scope and timeline are defined up front, before the work starts.

An audit is only useful if someone acts on it. Get a Free Billing Audit. Medical Billing Services Group — Medical Billing & Revenue Cycle Management — is a remote company serving practices in all 50 states. Call +1 (307) 396-4107 or email contact@medicalbillingservicesgroup.com.

General educational information, not legal advice or a guarantee of reimbursement. Requirements vary by payer, plan, setting and date of service. CPT is a registered trademark of the American Medical Association.

Leave a Comment