Medical billing audit services are structured reviews of a practice’s coding, documentation, claim submission, and payment data, performed to find revenue the practice is not collecting and compliance exposure it has not noticed. An audit compares what was documented against what was coded, what was coded against what was billed, and what was billed against what was actually paid. The output is a set of specific, evidence-backed findings — not an impression.
Practices usually commission an audit for one of two reasons. Either the numbers feel wrong — collections are flat while volume is up, or A/R keeps aging — or something has raised a compliance concern, such as a payer request for records, a probe review, or a coding pattern that looks unusual relative to peers. Both are legitimate. The second is more urgent.
What do medical billing audit services examine?
A credible audit works across the full revenue cycle rather than sampling charts in isolation. Documentation review alone tells you whether coding is defensible; it does not tell you whether correctly coded claims are being paid correctly.
| Audit area | What gets reviewed | What it typically reveals |
|---|---|---|
| Documentation and coding | A sample of encounters compared against the codes submitted | Under-coding, over-coding, unsupported modifiers, missing diagnoses |
| Charge capture | Scheduled and completed encounters compared against charges entered | Visits that never became claims; unbilled ancillary services |
| Claim submission | Clearinghouse rejections and front-end edits | Repeating demographic, eligibility, and registration errors |
| Denials | Denial reason codes grouped by root cause and payer | Denials being reworked repeatedly instead of prevented |
| Payment posting | Payments compared against contracted allowables | Systematic underpayments accepted as correct |
| A/R and write-offs | Aging by payer and adjustment codes used | Timely-filing write-offs; balances abandoned without appeal |
| Credentialing | Provider enrollment status by payer | Claims denied for enrollment rather than clinical reasons |
The denial and underpayment portions are where audits most often pay for themselves, because both problems repeat silently. A denial reason that appears three hundred times in a year is not three hundred separate incidents; it is one unfixed process.
What do auditors usually find?
The pattern is consistent enough that it is worth naming: most audit findings trace back to documentation, not to intent. Medicare’s own error data makes the point. In fiscal year 2025, the Medicare Fee-for-Service improper payment rate was 6.55%, representing roughly $28.8 billion, according to the CMS Fiscal Year 2025 Improper Payments Fact Sheet. When CMS breaks those improper payments down by error category, the distribution looks like this:
| Error category | Percent of 2025 Medicare FFS improper payments |
|---|---|
| Insufficient documentation | 53.0% |
| Medical necessity | 15.3% |
| No documentation | 12.0% |
| Incorrect coding | 11.1% |
| Other | 8.5% |
Source: CMS, 2025 Medicare Fee-for-Service Supplemental Improper Payment Data, Table A3. These are Medicare figures and do not describe commercial payer behavior, but they describe the failure mode well: the chart usually did not support what was billed, rather than the code being flatly wrong.
That has a practical consequence. A practice that responds to audit findings by changing codes without changing documentation has not fixed anything. It has moved the exposure.
Where does revenue leak?
In small and mid-sized practices, the recurring leaks tend to be unglamorous:
- Under-documented office visits. Evaluation and management services carry most of the volume in an office setting. For established patients, the choice among 99212, 99213, 99214, and 99215 is driven by medical decision making or time, and practices frequently default to a habitual level rather than the level the encounter supports — in both directions.
- Add-on and care management services never billed. Chronic care management, billed with 99490, and the Medicare visit complexity add-on G2211 are commonly performed and rarely captured.
- Preventive services folded into problem visits. Medicare annual wellness visits, billed with G0438 for the initial visit and G0439 for subsequent visits, are often absorbed into a problem-focused encounter and never separately billed.
- Modifier misuse. Modifier 25 and modifier 59 are among the most-scrutinized modifiers in claims review. Applying them by habit is a compliance risk; omitting them when they are supported is a revenue loss.
- Underpayments posted as correct. If nobody compares remittance amounts to the contracted fee schedule, a payer paying below contract will keep doing so indefinitely.
- Timely-filing write-offs. These rarely appear in a denial report because the claim was never appealed. They show up as adjustments.
Procedure-heavy specialties stack their own leaks on top of these. Component splitting and device-monitoring windows set the pattern in cardiology billing services, while endoscopic bundling edits drive it in urology billing services. A general audit that ignores the specialty rulebook will miss both.
How often should a practice audit its billing?
An annual external review is a reasonable baseline for a stable practice, and our guide to preparing for a medical billing audit covers the data pull and chart sample to have ready. Certain events should trigger one sooner:
- A new provider joins, or an existing provider changes scope
- You add a service line or a new place of service
- A payer sends a records request, initiates a probe review, or notifies you of a post-payment review
- Collections diverge from volume for more than a quarter
- You change practice management or EHR systems
- You change billing staff or billing companies
Between formal audits, ongoing internal monitoring matters more than audit frequency. Reviewing your monthly medical billing KPIs — particularly days in A/R, clean claim rate, and first-pass resolution rate — will surface most problems long before an annual audit would.
Internal review or external audit?
Both have a place, and they answer different questions.
| Internal review | External audit | |
|---|---|---|
| Best for | Ongoing monitoring, provider-level feedback | Independent baseline, compliance documentation |
| Frequency | Monthly or quarterly | Annually, or event-driven |
| Main limitation | Reviews the same assumptions that created the problem | Point-in-time; requires follow-through to matter |
| Credibility with payers | Limited | Stronger, because it is independent |
If your billing is outsourced, an audit performed by that same billing company is still useful for finding operational issues, but it is not independent. When the question is compliance exposure rather than performance, independence matters.
What happens after the audit?
Findings are the easy part. The value is in what follows, and a report that stops at a list of errors has not finished the job. A usable audit closes with:
- Prioritized findings — separated by dollar impact and by compliance risk, because those are not the same ranking.
- Root cause for each — process, documentation, system configuration, or training.
- Specific corrective actions with an owner and a date.
- Provider-level education where documentation is the driver, delivered as coaching rather than as a scorecard.
- A re-measurement plan so you can confirm the fix held.
Denials in particular should be reworked through a defined process rather than case by case; our denial management and appeal workflow outlines what that looks like. If the audit points toward changing billing partners, our guide on how to evaluate a medical billing company covers what to verify before you move.
One caution on overpayments. If an audit identifies money the practice was not entitled to keep, that finding carries obligations. Handle it with your compliance counsel rather than quietly adjusting future claims.
Frequently asked questions
How large a sample does a billing audit need?
It depends on what you are testing. A focused review of one provider’s use of a single code family needs a much smaller sample than a practice-wide baseline across several specialties and payers. The sample should be large enough that a finding represents a pattern rather than one unusual chart, and it should be selected on a defined basis rather than chosen by whoever pulls the records.
Will an audit disrupt our billing?
It should not. Most of the work happens on exported data and copies of documentation, and providers are typically only involved for a short education session at the end. The disruptive scenario is the one where you skip the audit and a payer conducts its own review instead.
What if the audit finds we have been over-coding?
Better that you find it than a payer does. The response is documentation and education, plus a decision — made with counsel — about any repayment obligation. Practices that self-identify and correct are in a materially different position than practices that are discovered.
Can an audit help if we already outsource billing?
Yes, and it is often more useful in that situation, because it gives you an independent read on work you are not performing yourself. It also gives you concrete material for your next review with the billing company: specific claims, specific denial reasons, specific dates.
Verify current CPT, ICD-10, and payer requirements before billing.
Get an independent read on your billing
AMS Solutions has worked with physician practices since 1992. We are physician-founded, our staff is entirely U.S.-based, our coders are AAPC-certified, and we operate under HIPAA-compliant processes. We treat billing as a long-term partnership, which means the point of an audit is the corrective work that follows it, not the report itself. If you suspect you are leaving money on the table or you want a clear picture of your compliance exposure, start with a free medical billing audit, or contact us through our form to discuss a wider review. You can also reach us at 866-973-2221.