A medical billing audit is a structured review of how clinical and administrative data becomes a claim, a payment, an adjustment, or an outstanding balance. The goal is not to hunt for a single dramatic number. It is to establish which reports can be trusted, where work breaks down, why it breaks down, and which corrections deserve priority.
This checklist is designed for practice administrators, owners, finance leaders, and revenue-cycle teams evaluating billing performance or an outside revenue cycle consulting engagement. It covers operational performance and compliance touchpoints, but it is not legal advice and does not replace a qualified coding or compliance review.
Audit blueprint
A defensible audit moves from reconciled evidence to owned corrective action.
1. Define the Audit Scope Before Pulling Reports
Start with a decision, not a spreadsheet. A useful audit question is specific enough to test: Why did cardiology denials increase after the payer edit change? Are old balances concentrated in a particular location? Do posted payments reconcile to bank deposits? A broad instruction such as "find more revenue" invites inconsistent analysis.
Write down these scope decisions
- Objective: performance diagnostic, compliance review, vendor transition, or focused root-cause analysis.
- Period: a representative window that captures payer cycles, seasonality, and recent workflow changes.
- Population: locations, providers, specialties, payers, service lines, and patient-balance classes included or excluded.
- Systems of record: EHR, practice management, clearinghouse, payer portals, bank deposits, and general ledger.
- Decision owners: who validates findings, approves changes, and accepts residual risk.
Freeze KPI definitions at the beginning of the review. Two teams can report different denial rates from the same data when they use different dates, dollar-versus-claim denominators, or denial-status rules.
2. Gather the Data and Prove It Reconciles
Dashboard totals are clues, not evidence. Before interpreting a trend, trace summary reports back to transactions and confirm that the same period, posting logic, reversals, refunds, and adjustments are included. Reconciliation prevents a reporting artifact from becoming an expensive operational project.
Core evidence set
- Charge, claim, payment, adjustment, refund, write-off, and open-AR transaction detail.
- 837 claim files, 999 and 277CA acknowledgments, clearinghouse rejection reports, and 835/ERA files.
- Payer contracts, fee schedules, authorization records, remittance details, and appeal outcomes.
- Provider documentation, coding and charge-capture audit trails, and claim edit history for sampled accounts.
- Bank deposits and ledger totals used to reconcile posted collections.
- User access, adjustment approval, refund, and write-off controls relevant to the audit objective.
CMS explains that electronic claims pass through format, implementation-guide, coverage, and payment-policy edits, with different responses for batch and individual-claim failures. That makes acknowledgments and edit responses essential audit evidence, not background paperwork. See the CMS electronic claims workflow.
Evidence chain
Each recommendation should be traceable back to operational evidence.
3. Medical Billing Audit Checklist by Operating Area
Review the revenue cycle as a connected system. A denial may appear in the back office while its root cause sits in registration, authorization, documentation, or charge capture. The table below keeps evidence and risk connected.
| Audit area | Evidence to test | Risk surfaced |
|---|---|---|
| Scope and governance | Audit question, period, systems, owners, definitions | Unclear scope or conflicting KPI definitions |
| Patient access | Registration, eligibility, referrals, authorizations | Front-end rejections and avoidable denials |
| Documentation and coding | Notes, codes, modifiers, charge capture, edit history | Unsupported, delayed, or missed charges |
| Claims | 837 files, clearinghouse reports, acknowledgments, payer edits | Rejected claims, submission lag, filing risk |
| Payments | 835/ERA, EOB, deposits, adjustments, refunds | Posting errors and unexplained variances |
| Denials and AR | CARC/RARC, work queues, appeals, aging, write-offs | Recurring leakage and weak follow-up |
| Compliance | Policies, access, audit logs, exclusions, refund controls | Payment, privacy, and documentation exposure |
| Reporting | KPI logic, source lineage, segmentation, cadence | Decisions based on incomplete or inconsistent data |
Patient access and authorization
Sample eligibility, subscriber data, referrals, and prior authorizations against the final claim. Segment failures by payer, location, service, and staff workflow. For recurring denial patterns, connect this work to the denial management service and the existing guide on reducing medical claim denials.
Documentation, coding, and charge capture
Trace the appointment or service through signed documentation, code assignment, modifier use, charge entry, edits, and claim submission. CMS states that medical review can test coverage, coding, billing, documentation, and medical necessity requirements. Use applicable payer policy and the date-of-service rules rather than a generic checklist. Review the CMS medical review framework.
Claims, payments, denials, and AR
Separate clearinghouse rejection, payer rejection, initial denial, final denial, and contractual adjustment states. Then trace payments and adjustments through remittance and deposit evidence. Analyze aged accounts by payer, provider, service, balance class, denial reason, and last action instead of relying on one total AR figure. The AR days guide explains how aging and workflow discipline interact.
Compliance and control environment
Operational gains are not valid if they depend on unsupported coding, weak documentation, inappropriate adjustments, or uncontrolled access. The HHS Office of Inspector General describes internal monitoring and auditing as part of a broader compliance infrastructure and makes clear that its general guidance is voluntary and nonbinding. Use the current OIG General Compliance Program Guidance with qualified advice for the organization and issue being reviewed.
4. Define KPIs Before Comparing Benchmarks
A benchmark is useful only when the practice and comparison source calculate the metric the same way. Store the definition beside the result: numerator, denominator, date basis, exclusions, source system, refresh cadence, and owner. HFMA describes its MAP Keys as standardized revenue-cycle KPIs with consistent definitions and data sources across several healthcare settings. See HFMA MAP Keys.
Clean-claim rate
Claims accepted on initial submission / claims submitted
Define acceptance point and resubmission treatment.
Initial denial rate
Initially denied claims / adjudicated claims
State whether the measure uses claim count or dollars.
Net collection rate
Payments / contractually collectible amount
Document adjustments, refunds, and time lag.
Days in AR
Ending receivables / average daily charges
Define charge period and credit-balance treatment.
Payment-posting lag
Payment date to posting date
Segment manual and automated posting.
Write-off rate
Approved write-offs / defined revenue base
Separate contractual, bad debt, and administrative loss.
Do not force one benchmark across every specialty or payer mix. Compare like with like, disclose the source and period, and treat a variance as a question to investigate. Our revenue cycle analytics guide covers dashboard design in depth; this audit should focus on whether each number is reproducible and decision-useful.
5. Model ROI Without Turning Assumptions Into Promises
Separate identified leakage from addressable leakage, realistically recoverable value, and realized cash. Some defects can be prevented prospectively but not recovered retrospectively. Others may require payer appeals, staffing, system changes, or contract work before value appears.
- Establish a reconciled baseline using the same definitions that will be used after implementation.
- Quantify the affected claim or dollar population and remove duplicates or timing artifacts.
- Classify what is preventable, recoverable, contractually allowed, or compliance-sensitive.
- Model conservative capture assumptions and include one-time and ongoing costs.
- Set a validation period and compare realized results with the baseline and a suitable control.
Interactive model
Audit opportunity scenario
- Gross opportunity
- $45,000
- Modeled total cost
- $42,000
- Net modeled value
- $3,000
- Simple break-even
- 9.6 months
Illustrative scenario only, not a forecast or guarantee. Use validated practice data and distinguish identified leakage from realistically recoverable value. Do not enter PHI.
A positive modeled value is not proof of ROI. It is a scenario for deciding whether deeper validation is worth the effort. Record every assumption and replace it with observed data as implementation proceeds.
6. What a Credible Audit Deliverable Should Contain
Management should be able to act on the report without reverse-engineering the analysis. Each finding needs evidence, impact logic, an accountable owner, and a way to confirm whether the correction worked.
Evidence register
Source, period, reconciliation status, sample logic, and limitations.
Finding register
Condition, root cause, risk, affected population, and confidence level.
Action roadmap
Priority, owner, effort, dependency, due date, and validation metric.
Prioritize findings with four questions
- How strong is the evidence and how large is the affected population?
- What financial, compliance, patient, or operational risk does the issue create?
- What can the practice control, and what depends on a payer, vendor, contract, or regulation?
- Which metric will prove that the correction is working without creating a new problem elsewhere?
For a broader view of how these controls fit together, read What Is Revenue Cycle Management?. Practices evaluating whether to keep work internal or use an outside team can also compare in-house and outsourced medical billing before changing operating models.
Questions to Ask a Medical Billing Consultant
- Which questions will the audit answer, and which questions are outside scope?
- How will reports be reconciled to transactions and deposits?
- How are samples selected, and what limitations will be disclosed?
- Which benchmarks are licensed, current, and calculated comparably?
- How are coding, compliance, security, and payer-policy issues escalated?
- How will opportunity estimates separate prevention, recovery, and timing effects?
- Who owns implementation, and how will results be independently validated?
Primary Sources Used
This guide uses public guidance for audit structure and terminology. Practice-specific decisions must be checked against applicable payer contracts, coverage rules, coding guidance, law, and professional advice.