The Medical Billing Audit Checklist: 47 Items
By MedPrecision Operations Team · Published
A real medical billing audit is not a single dashboard review. It is a structured walk through the entire revenue cycle — front-end eligibility, coding, claim construction, denial patterns, A/R aging, contract loading, compliance posture — looking for the specific failure points where revenue is leaking. This 47-item checklist is the framework used on most first-engagement audits at MedPrecision, organized by revenue cycle stage so the findings map directly to remediation owners. The checklist is the method, and it is published in full below so you can run it yourself. What it is not is an offer: the scope, sample size, turnaround and price of an actual medical billing audit engagement are set in the engagement agreement, not on this page.
What a billing audit covers and what it produces
A complete billing audit reviews 47 specific items across six revenue cycle stages: front-end (eligibility, demographics, prior auth), coding (CPT/ICD-10 accuracy, modifier logic, documentation), claim submission (clean claim rate, scrubber rules, payer mix), payer adjudication (denial pattern, appeal velocity, contract loading), A/R management (aging buckets, days in A/R, write-off discipline), and compliance (HIPAA, OIG work plan items, fraud red flags). The output is a prioritized findings list carrying, for each item, the observed frequency, the direction of the error (under-coded or over-coded) and a named remediation owner. Findings quantify denied dollars, which are observed. They do not forecast recovered dollars, which depend on payer response, appeal outcome and how much filing runway is left.
- 47 items across 6 revenue cycle stages
- Front-end through compliance
- Findings quantify denied dollars, never forecast recovery
- Each finding has a remediation owner
Front-End: Eligibility and Patient Access (Items 1-9)
Item 1: Is real-time eligibility verification (270/271) run at scheduling for every patient? Item 2: Is eligibility re-verified at check-in to catch coverage changes since scheduling? Item 3: Are insurance card images captured and OCR-validated against the eligibility response? Item 4: Are demographics validated against payer records (subscriber name, DOB, ID format)? Item 5: Is the secondary payer identified at registration and the COB order confirmed? Item 6: For Medicare patients, is the MSP questionnaire completed (working spouse, workers' comp, no-fault, ESRD)? Item 7: Are time-of-service collections happening for known copays and outstanding balances? Item 8: Are referral requirements identified for HMO patients before service? Item 9: Are no-show and cancellation policies operationalized to capture documented patient acknowledgment? Front-end gaps are the single largest controllable source of CARC 27, 31, and 22 denials.
Front-End: Prior Authorization (Items 10-13)
Item 10: Is there a documented list of which CPT codes require PA by payer, kept current? Item 11: For PA-required services, is the request submitted within 24 hours of scheduling? Item 12: Is the approved PA number captured into the practice management system attached to the encounter, and is there a scrubber edit that blocks PA-required CPTs from claim submission without an authorization number? Item 13: Are pending PAs tracked in a dashboard with daily follow-up until cleared? CARC 197 denials are almost entirely preventable with discipline at items 10-12; the most common failure is item 12 (PA was approved, but the number didn't get captured to the claim).
Coding: Accuracy and Documentation (Items 14-22)
Item 14: Is there a defined coder review cycle for every claim above a specified complexity threshold (typically all surgical, all level-4/5 E/M, all infusion)? Item 15: Are coders certified (CPC, CCS, CCS-P) and is annual continuing education tracked? Item 16: Is documentation reviewed against the current CPT E/M guidelines — the 2021 revision that dropped history and exam as elements of code selection for office visits in favour of medical decision making or total time, extended to the remaining E/M categories in the 2023 code set? Item 17: Are modifier 25, 59, 76, 77, and 91 applied consistently against NCCI edits? Item 18: For surgical claims, are global period rules (0, 10, 90 day) correctly applied? Item 19: Are diagnosis codes coded to highest specificity supported by documentation (no unspecified codes when specificity exists)? Item 20: Is there a query process when documentation is unclear, and is query response timeliness tracked? Item 21: Is the coder error rate by type tracked monthly? Item 22: Are coder audits performed quarterly with a minimum 25-chart sample? Coding gaps are the second largest revenue leak category and the largest compliance exposure.
Claim Submission and Scrubbing (Items 23-28)
Item 23: What is the documented clean claim rate, and under which definition? HFMA's MAP Keys define Clean Claim Rate (CL-1) as claims passing edits with no manual intervention over claims accepted into the claims processing tool for billing — which is not the same event as clearinghouse acceptance. MAP Keys publish the equation and the inclusions only; they publish no target value, and no free primary source publishes a clean-claim-rate target, so the number to beat is your own trailing baseline. Item 24: Are scrubber edits maintained against payer-specific rules and updated when payer policies change? Item 25: Is charge lag measured and bounded by a written internal SLA? MAP Keys defines Total Charge Lag Days (PB-4) as the days between date of service and the revenue-recognition posting date, averaged across charge codes billed — a definition, with no target attached, so the threshold has to be yours and it has to be written down. Item 26: Are NPI, taxonomy, and tax ID validated on every claim against NPPES and against the payer enrollment file? Item 27: Is place-of-service consistent with the rendering location (POS 11 office, POS 22 hospital outpatient, POS 02 telehealth)? Item 28: Are duplicate claim submissions prevented by the system, and are CARC 18 (duplicate) denials trended? Submission failures are the most measurable category — every gap shows in the CCR number.
Denial Management (Items 29-34)
Item 29: Is the denial rate trended monthly by CARC code, with the top 5 codes broken out separately? Item 30: Is the median time from denial receipt to first appeal action under 14 days? Item 31: Is appeal recovery rate tracked by denial type and by payer? Item 32: Is there a documented escalation path for denials that fail first-level appeal (peer-to-peer, second-level appeal, external review)? Item 33: Are denial root causes traced back to the front-end or coding stage that produced them, with feedback loops to prevent recurrence? Item 34: Are write-off thresholds enforced — no claim written off without documented appeal exhaustion or supervisor approval? Denial management is where most aged A/R sits; an unworked denial queue is the single biggest source of NCR drag.
A/R Management and Reporting (Items 35-39)
Item 35: Is days in A/R computed under a stated formula, and the same one every month? MAP Keys' Net Days in A/R (FM-1) divides net A/R by average daily net patient service revenue; AAFP's method divides total receivables by average daily charges over a chosen period, net of credits. The two are not interchangeable, and switching between them mid-year manufactures a trend that is not there. Item 36: Is the aging bucket distribution (0-30, 31-60, 61-90, 91-120, 121+) reviewed monthly? Item 37: Is A/R over 90 days tracked as a percentage of total A/R against a threshold the practice has set and written down? No free primary source publishes a target for it. AAFP points specifically at the greater-than-120-day bucket, because good overall days in A/R can mask elevated older receivables. Item 38: Is there a defined work queue for each aging bucket, with daily worklist assignment? Item 39: Are bad debt write-offs reviewed and approved at the appropriate authority level, with documented criteria? A/R management is the recovery layer — gaps here turn front-end and coding mistakes into permanent revenue loss rather than recoverable rework.
Contract and Fee Schedule (Items 40-43)
Item 40: Are payer contract allowed amounts loaded into the practice management system, current to the most recent contract amendment? Item 41: Is each payment posted compared to the loaded allowed amount, with underpayments flagged automatically? Item 42: Are fee schedule rates set as a stated multiple of the current Medicare Physician Fee Schedule, with the multiple and its rationale documented? We publish no recommended multiple — the figures in circulation are trade-press convention rather than a sourced benchmark, and the defensible one depends on your payer mix and contracted rates. Item 43: Are renegotiation cycles documented, with major payer contracts reviewed at least every 24 months? Contract loading is one of the largest hidden revenue leak categories — payer underpayments that go undetected because the loaded rate doesn't match the contract rate represent immediate recoverable dollars.
Compliance and Risk (Items 44-47)
Item 44: Is the HIPAA risk assessment current (within 12 months) and documented with mitigations for identified risks? Item 45: Are workforce members with PHI access trained annually, with documentation? Item 46: Is the OIG work plan reviewed annually and findings mapped against the practice's billing patterns (e.g., E/M upcoding scrutiny, modifier 25 utilization, telehealth POS)? Item 47: Are billing-side fraud red flags monitored — duplicate submissions, unusual coding patterns, after-hours billing activity, single-coder claim approval bypasses? Compliance audit findings rarely produce immediate revenue impact but represent the largest tail risk — a False Claims Act exposure can cost more than the entire billing operation in a year.
What a Medical Billing Audit Should Actually Uncover
A thorough billing audit covers five areas: coding accuracy across all providers and service lines, denial root causes broken down by payer and reason code, A/R aging distribution with follow-up activity tracking, payer contract compliance including fee schedule validation against actual reimbursements, and front-end processes like eligibility verification, authorization workflows, and charge capture. Each area should produce specific findings with dollar amounts attached — not vague recommendations. You should know exactly how much revenue is at risk in each category.
Certain findings demand immediate attention: a single payer whose denial rate sits materially outside the rest of your book — AAFP's guidance puts the industry average at 5% to 10% with below 5% more desirable, so the signal is the outlier rather than any absolute threshold; A/R over 90 days materially above your own trailing baseline or concentrated in one payer; consistent underpayments against contracted rates; missing or lapsed provider credentials with active claims; recurring coding errors on the same CPT codes; and authorization denials that could have been prevented with better intake workflows. If your audit does not quantify these issues and rank them by financial impact, it is not actionable.
Illustrative Billing Audit (Sample Findings Report)
> This is an illustrative example demonstrating MedPrecision's reporting methodology. It is not presented as the result of an actual client engagement. Every practice-level figure below is synthetic. No patient, practice, or payer data appears anywhere on this page. Where a public benchmark comparator is shown, it is real and cited.
Example Practice A — the same illustrative practice used across all of our sample deliverables, so the artifacts can be read end to end: a four-physician, two-APP family medicine group in Ohio, roughly 2,050 encounters and $412,000 in gross charges per month. Reporting period: June 2026.
The 47-item checklist above is the instrument. This is what a completed findings report looks like when that instrument is run — the deliverable, not the method.
Scope and method
| Field | Value |
|---|---|
| Records audited | 200 encounters |
| Period sampled | January–March 2026 |
| Sampling method | Stratified by provider and payer class |
| Verified against | CPT accuracy, ICD-10-CM accuracy and linkage, HCPCS modifier use, documentation support |
| Coding accuracy rate | 88.5% (177 of 200 correctly coded) against the 95% internal standard this illustrative practice had set for itself |
Findings, in both directions
An audit that reports only under-coding is a revenue-maximisation exercise. Reporting over-coding is what makes the rest of the numbers credible — and it is the finding that carries actual compliance risk.
| # | Severity | Finding | Frequency | Code at issue | Direction | Est. annual impact |
|---|---|---|---|---|---|---|
| 1 | High | Established-patient visits coded at 99213 where documentation supported 99214 | 14 of 120 | 99213 → 99214 | Under-coded | Revenue understated |
| 2 | High | Same-day E/M billed with a minor procedure without documentation supporting a separately identifiable service | 6 of 62 | Modifier 25 | Over-coded | Repayment exposure |
| 3 | High | Clearinghouse rejections not worked within 48 hours | 74/month | — | Process | 5 claims/month lost to timely filing |
| 4 | Medium | Eligibility not re-verified for recurring patients | 11/month | CO-27 denials | Process | $2,530/month denied |
| 5 | Medium | Diagnosis-to-procedure linkage not checked before submission | 12/month | CO-11 denials | Process | $2,640/month denied |
| 6 | Low | Patient statements issued on day 12 post-EOB against a day-5 target | Systemic | — | Process | Extends patient A/R by ~7 days |
Finding 2 is the one that matters most, and it reduces revenue. Six claims carried a modifier 25 that the documentation does not support. The correct response is a repayment review, not an appeal. An auditor who did not surface this would have produced a more flattering report and a larger liability.
Remediation
| Finding | Corrective action | Owner | Re-audit |
|---|---|---|---|
| 1 | E/M documentation training; prospective review of 99213/99214 selection | Coding lead | 60 days |
| 2 | Repayment review of the 6 identified claims; modifier 25 documentation standard issued | Compliance + coding lead | 30 days |
| 3 | Rejections worked daily; 48-hour SLA with exception reporting | A/R analyst | 30 days |
| 4 | Eligibility re-verified at every visit for recurring patients | Front desk | 30 days |
| 5 | Scrubber rule added for diagnosis-to-procedure linkage | Billing systems | 60 days |
| 6 | Statement cycle moved to day 5 post-EOB | Patient A/R | 60 days |
Why no headline dollar figure. A findings report of this kind can responsibly quantify denied dollars, because those are observed. It cannot responsibly quantify "recovered" dollars in advance, because recovery depends on payer response, appeal outcome and timely-filing runway. Any audit that opens with a single recovery number has estimated it. We would rather show the denied dollars, the error rate, and the direction of each error.
Free Billing Audit · No obligation
Talk Through Your Audit Scope
The 47 items above are the framework we work from. Scope, sample size, turnaround and price are set in the engagement agreement rather than quoted on a page — tell us what you are trying to find and we will tell you what reviewing it involves.
Prefer to talk? Book a 15-minute callRequest received
A billing specialist will review your practice details and reach out within 1 business day. No confirmation email is sent — if you need to reach us sooner, call +1-872-297-2815.
Common Questions
Common questions about medical billing audit checklist (2026): 47 items to review.
Get a Free Billing Audit
Our billing specialists can walk you through this and more.
Get a Free Billing AuditHow often should a practice run a billing audit?
A full external billing audit should occur every 12-18 months at minimum, with internal mini-audits monthly on a rotating subset of items. The full audit produces a complete revenue cycle assessment with remediation recommendations and revenue impact estimates; it is the right cadence for catching structural issues that develop over time. Monthly internal audits should rotate through subsets — coding accuracy on 25 charts in month one, denial pattern analysis in month two, contract underpayment review in month three — to maintain ongoing visibility without the full audit cost. Practices that have just changed billing companies, switched practice management systems, gone through a major payer contract renegotiation, or experienced an unexplained revenue drop should run a full audit immediately rather than wait for the cycle.
What is the difference between a coding audit and a billing audit?
A coding audit reviews documentation against assigned CPT and ICD-10 codes, looking for accuracy, modifier appropriateness, and documentation support — typically a sample of 25-50 charts reviewed by a certified coder (CPC, CCS, CCS-P) against payer policy and NCCI edits. The output is a coder error rate, identified upcoding or downcoding patterns, and recommended documentation training. A billing audit is broader — it includes the coding audit as one component but also reviews eligibility processes, claim submission, scrubber configuration, denial patterns, appeal velocity, A/R aging, contract loading, and compliance posture. The billing audit is operations-focused; the coding audit is documentation-focused — which is why they are scoped as separate engagements, medical billing audit and medical coding audit. A finding in the coding audit might be 'modifier 25 is being used on 30% of E/M visits — review for medical necessity'; a finding in the billing audit might be 'CARC 197 denials represent 18% of total denials — investigate front-end PA workflow.'
How much revenue does a typical audit recover?
We do not publish a figure, and you should be wary of anyone who does. An audit can responsibly quantify what it observes — denied dollars, error rate, underpayment variance against loaded contract rates — but recovery from those findings depends on payer response, appeal outcome and how much filing runway is left on each claim, none of which is knowable in advance. There is also no free primary source that publishes a revenue-leak percentage for physician practices; the ranges in circulation are vendor marketing. What is worth knowing is where recovery tends to sit when it happens: contract underpayments where loaded rates do not match the contract, unworked aged denials, appeals abandoned before exhaustion, and posting errors that overstated contractual write-offs. Some of those produce a one-time catch-up within a couple of months; others (contract loading fixes, scrubber rules) produce no lump sum at all, only a better run rate going forward.
What red flags should a billing audit catch?
Five specific red flag patterns warrant escalation. First, billing patterns that sit well outside your specialty's own distribution on items the OIG Work Plan is actively examining — modifier 25 frequency on E/M visits, the share of E/M coded at the highest level, modifier 59 applied without NCCI documentation, telehealth place-of-service 02 used when the service was rendered face-to-face. The escalation trigger is the deviation and the documentation behind it, not a fixed percentage; the published utilisation thresholds in circulation are convention rather than a rule any authority issues. Second, a single coder approving >50% of claims without secondary review. Third, after-hours billing activity (claims submitted, modifications made) outside normal workflow. Fourth, duplicate submission patterns suggesting intentional double-billing. Fifth, unusual specialty utilization patterns — for example, a primary care practice billing high-complexity G-codes for chronic care management at volumes inconsistent with patient panel composition. These are False Claims Act exposure indicators and require immediate review.
Should I run an audit before switching billing companies?
Yes — a baseline audit before switching is one of the most defensible specific investments available. The audit creates the documented starting point against which the new billing company's performance can be measured at 90 and 180 days, surfaces any pending issues that need to be resolved before the transition (open denials, aged A/R, pending appeals), and produces a credentialing and contract inventory that simplifies the transition itself. Practices that switch without a baseline audit frequently discover post-transition that some revenue loss began before the switch but gets attributed to the new vendor — making it harder to evaluate the actual transition outcome. We publish no audit price or return figure: pricing is set per engagement, and any published return multiple would be a forecast of recovery, which this page argues nobody can responsibly make.
Do I need a CPA for a billing audit?
No — a billing audit is operational, not financial, and is performed by revenue cycle specialists rather than CPAs. CPAs perform financial statement audits under generally accepted auditing standards (GAAS), which review the accuracy of financial reporting but do not examine billing operations, coding accuracy, or revenue cycle KPIs. A billing audit is performed by certified coders (CPC, CCS, CCS-P), revenue cycle analysts, and practice operations consultants who specialize in healthcare billing. The output is operational — findings on coding patterns, denial trends, contract loading, scrubber configuration — not a financial opinion. Some firms offer combined billing-and-financial audits, but the scope and skillset are different and the deliverables address different audiences.
Related Services
Related Specialties
Talk Through Your Audit Scope
The 47 items above are the framework we work from. Scope, sample size, turnaround and price are set in the engagement agreement rather than quoted on a page — tell us what you are trying to find and we will tell you what reviewing it involves.
- No contract
- No setup fees
- Reply within 1 business day