Medical Coding Audit Checklist

Medical Coding Audit Checklist — illustration

A coding audit tests one thing precisely: do the codes on your claims match the clinical documentation, and do they comply with payer rules? It is narrower than a full billing audit — which also covers submission, denials, A/R, and contracts — but it is where compliance risk and revenue accuracy live side by side.

Use this checklist to run a coding audit internally or to understand what an external review covers. Our medical billing audit service includes coding review as a core component, and our medical coding services page describes ongoing coding support.

1. Documentation completeness

Every code must be traceable to the note. Start by confirming the notes themselves are audit-ready.

  • [ ] Confirm every audited encounter has a complete, signed, and dated note. Unsigned or undated documentation cannot support the codes billed from it.
  • [ ] Verify the note identifies the rendering provider. The person documented as performing the service must match the provider on the claim.
  • [ ] Check that required note elements are present. Chief complaint, history, exam, assessment, and plan should appear where the code set requires them — requirements differ between E/M, procedure, and specialty coding.
  • [ ] Flag late entries and addenda. Late documentation should be clearly labeled as such, not silently edited into the original note.

2. E/M level support

Evaluation and management coding is the most audited area in outpatient billing. Give it proportional attention.

  • [ ] Reconstruct the E/M level from the documentation alone — without looking at the billed code first. Then compare. Doing it blind prevents the billed code from anchoring your judgment.
  • [ ] Confirm medical decision-making complexity supports the level billed. Number and complexity of problems addressed, data reviewed, and risk of complications should all point to the same level.
  • [ ] For time-based coding, verify total time is documented and that it meets the threshold for the code selected. Time statements should be specific, not boilerplate.
  • [ ] Watch for level creep. Notes that always land one level higher than the documentation supports — across providers or within one provider’s patterns — are exactly what payer auditors look for.

3. Diagnosis–procedure linkage

Each service on the claim needs a clinical reason for existing.

  • [ ] Confirm each procedure code links to a diagnosis code on the claim. A procedure floating without a supporting diagnosis is a medical-necessity denial waiting to happen.
  • [ ] Verify diagnoses are coded to the highest specificity documented. If the note documents a specific condition, the claim should reflect it — not a vaguer code from the same family.
  • [ ] Check that the diagnosis supports medical necessity for the procedure performed. The linkage has to make clinical sense, not just exist on paper.
  • [ ] Flag symptom codes used where a definitive diagnosis was documented. Coding the symptom when the note establishes the diagnosis understates the case and can trigger medical-necessity reviews.

4. Modifier use

Modifiers change how a code is interpreted and paid. They are also one of the most common sources of audit findings, so review them with care and against each payer’s own published guidance — payers differ.

  • [ ] Review modifier 25 usage. Confirm the documentation describes a significant, separately identifiable E/M service on the same day as a procedure — and that the E/M work goes meaningfully beyond the procedure’s usual pre- and post-work.
  • [ ] Review modifier 59 usage. Confirm the documentation supports a distinct procedural service, and check whether a more specific modifier (such as XE, XP, XS, or XU) described the situation more accurately.
  • [ ] Check other common modifiers against documentation and payer policy — including 24 (unrelated E/M during a postoperative period), 76 and 77 (repeat procedures), and LT/RT or other anatomical modifiers.
  • [ ] Confirm modifier choices match the payer’s published guidance. A modifier combination one payer accepts routinely may be exactly what another payer’s edits target.

5. NCCI awareness

The National Correct Coding Initiative edits define which code combinations payers will not pay together without appropriate justification.

  • [ ] Check sampled claims against current NCCI procedure-to-procedure edits for unbundled code pairs that should have been reported as a single comprehensive code.
  • [ ] Verify medically unlikely edit (MUE) limits are respected — units of service that exceed what is medically reasonable for a single date of service.
  • [ ] Confirm any bypassed edits have documentation support and a compliant modifier. Bypassing an edit is legitimate when the clinical circumstances genuinely warrant it and the documentation proves it.
  • [ ] Note the review date. NCCI edits are updated quarterly, so any coding audit should record which edit version was applied. The NCCI guidance referenced in this checklist was last reviewed 2026-10-08.

6. Error-rate tracking methodology

An audit that does not measure is just an opinion. Track findings rigorously — but describe them honestly, without inventing benchmarks.

  • [ ] Define what counts as an error before you start. Wrong code selected, valid code missing, E/M level unsupported by documentation, modifier misused — write the definitions down so every reviewer applies them the same way.
  • [ ] Track error rates by category, provider, and coder — not just as a single practice-wide number. Averages hide the providers and categories that need training.
  • [ ] Distinguish errors that change payment from errors that create compliance risk. Both matter, for different reasons, and they drive different corrective actions.
  • [ ] Re-audit after education. The point of measuring is to see whether findings actually changed behavior. Schedule the follow-up audit before the first one is even finished.
  • [ ] Set internal targets from your own baseline trend. There is no single published error rate that fits every specialty, payer mix, and practice size — so define improvement against your own starting point and track it over time rather than chasing an invented industry number.

Frequently asked questions

What is the difference between a coding audit and a billing audit?
A coding audit tests whether the codes on claims match the clinical documentation and comply with coding rules. A billing audit is broader — it covers the full revenue cycle including claim submission, denial management, A/R aging, and payer contract compliance. Coding accuracy is one section of a billing audit and the entire subject of a coding audit.

How often should coding be audited?
At least annually, and more often when circumstances change: new providers joining, new service lines, new EHR templates, or payer policy updates affecting your top codes. High-risk areas like E/M leveling deserve focused review between full audits.

Who should perform a coding audit?
Someone independent of the original coding decisions. Internal auditors know the workflows; external auditors bring objectivity and see habits the team has gone blind to. Either way, the reviewer needs genuine coding expertise in your specialty — a generalist review of specialty coding misses the nuances that matter.

What error rate is acceptable?
There is no universal benchmark, so be skeptical of anyone quoting one as a standard. Track your own error rate by category and provider, define internal targets based on your baseline, and measure improvement over time. The trend matters more than any single number.

What happens if the audit finds upcoding?
Correct the affected claims according to each payer’s guidance, educate the providers and coders involved, document the corrective action, and re-audit to confirm the pattern stopped. For significant or repeated findings, involve healthcare compliance counsel before deciding on further steps.

Do we need to audit coding if our claims are getting paid?
Yes. Payment is not proof of accuracy — payers pay first and audit later, sometimes years later. Clean payment history with miscoded claims is deferred risk, not a clean bill of health.

Coding accuracy is the foundation everything else in the revenue cycle stands on. Get a Free Billing Audit. Medical Billing Services Group — Medical Billing & Revenue Cycle Management — is a remote company serving practices in all 50 states. Call +1 (307) 396-4107 or email contact@medicalbillingservicesgroup.com.

General educational information, not legal advice or a guarantee of reimbursement. Requirements vary by payer, plan, setting and date of service. CPT is a registered trademark of the American Medical Association.

Leave a Comment