What Is a Billing Compliance Audit?

Introduction

The letter arrives on a Tuesday, official letterhead, a request for records within 30 days. For most practice owners, that's the moment a billing compliance audit stops being an abstract compliance-manual concept and becomes a real, ticking deadline.

The stakes are rising too. In MGMA's March 2024 poll of medical-group leaders, 60% reported higher claim denial rates in 2024 than the same time in 2023, with the industry's aggregate first-submission denial rate holding around 8%. Add in financial penalties, repayment demands, and reputational damage, and audit-readiness isn't optional.

This guide breaks down what a billing compliance audit actually is, the types you might face, what auditors look for, and how behavioral health and general medical practices can prepare before that letter shows up.

Key Takeaways

  • Billing compliance audits confirm your coding, documentation, and claims match payer contracts and federal rules.
  • Unresolved compliance gaps can trigger repayment demands, penalties, or Medicare exclusion.
  • Internal, external, and government audits each carry different risks and need different prep.
  • Regular self-audits and certified coding review catch errors before payers or regulators do.

What Is a Billing Compliance Audit?

A billing compliance audit is a systematic review of a provider's billing, coding, and documentation practices. It checks whether your claims align with payer contracts, federal and state regulations like HIPAA and the ACA, and coding standards under CPT and ICD-10.

Here's the part many practices misunderstand: a compliance audit isn't automatically a punishment. Its real purpose is to catch discrepancies, whether that's overbilling, underbilling, or outright fraud, before they turn into legal or financial liabilities. Think of it as a pressure test for your revenue cycle, not a courtroom.

A compliance audit also differs from a routine billing audit. A standard billing review checks whether claims were coded and submitted correctly. A compliance audit goes further, testing whether your entire process holds up against regulatory and contractual obligations, not just claim accuracy.

Key Areas a Billing Compliance Audit Typically Reviews

Auditors tend to focus on five recurring areas:

  • Claims accuracy and coding compliance — correct CPT/ICD-10 use, no upcoding or unbundling
  • Documentation quality — records that clearly support medical necessity for every billed service
  • Regulatory adherence — HIPAA, ACA, and specific payer contract terms
  • Denial management controls — internal processes that catch errors and prevent fraud before submission
  • Reimbursement accuracy — payments matching contracted payer rates, not inflated or shorted amounts

Miss any one of these, and you've created an opening for a denial, a repayment demand, or worse.

Five key areas reviewed during a billing compliance audit process

Why Billing Compliance Audits Matter for Your Practice

Skipping regular audits doesn't just risk a few denied claims. It exposes your practice to False Claims Act liability, including treble damages on top of repayment.

The scale is hard to ignore: the Department of Justice reported more than $6.8 billion in FCA settlements and judgments in fiscal year 2025, with over $5.7 billion tied specifically to healthcare.

That figure doesn't even count state Medicaid recoveries. And a large share of these cases start as whistleblower lawsuits, not government-initiated audits. DOJ logged 1,297 new qui tam suits in FY2025 alone.

Legal risk is only part of the story. Consistent auditing also strengthens day-to-day operations:

  • Catch coding errors before submission for cleaner first-pass claims and fewer denials
  • Build stronger payer relationships through consistently accurate billing
  • Protect patient trust with transparent bills that avoid disputes and complaints
  • Stabilize cash flow by reducing surprises and clawbacks over time

Practices that audit regularly protect revenue they have already earned and lower the odds of costly repayments later.

Types of Billing Compliance Audits

Billing compliance audits fall into three categories: internal reviews your team runs, external audits from payers or independent firms, and government audits from agencies such as the OIG and CMS. How much weight each carries for your practice depends on your size, specialty, and risk exposure.

Internal Billing Audits

These are conducted by in-house staff or a designated compliance officer, ideally on a recurring schedule. High-risk service lines such as behavioral health psychotherapy codes and TMS therapy billing warrant quarterly review at minimum.

The advantage is speed. Internal audits catch and fix errors before they ever reach a payer or regulator, which means no repayment demand, no denial, no scrutiny.

External and Third-Party Payer Audits

External audits come from independent auditors, private insurers like UnitedHealthcare, Aetna, or Blue Cross Blue Shield, or specialized billing and RCM firms. The goal is removing internal bias—staff auditing their own work often miss what a fresh set of eyes would catch.

Private payer audits carry real teeth even without government involvement. Aetna's provider manual, for example, permits denial, reduction, or recoupment following a review. Some Medicaid plans go further: UnitedHealthcare's 2026 North Carolina Medicaid manual describes formal prepayment review status, requiring three consecutive months at a 70% clean-claim rate before a provider can exit that status.

Government Audits (OIG, RAC, MAC)

When Medicare or Medicaid dollars are involved, the auditor and the stakes both change. Government-level audits carry the steepest consequences—from repayment demands to Medicare exclusion or, in fraud cases, criminal referral.

Auditor Focus Trigger
OIG Program-wide integrity, outlier billing patterns Risk-based Work Plan priorities
RAC Medicare overpayments, contingency-based review Data analytics flagging billing anomalies
MAC (TPE) Routine claims-level checks, education-first approach High error rates, unusual billing, or high-error-rate services

CMS's Targeted Probe and Educate program typically reviews 20-40 claims per round. Keep failing those rounds, and you're looking at 100% prepayment review or a RAC referral.

Comparison of internal external and government billing compliance audit types

How to Prepare for a Billing Compliance Audit

Preparation isn't a one-time project. It's a program, and it needs structure.

  1. Build a formal compliance program. Written policies, a designated compliance officer, and a defined audit schedule are the baseline, not the finish line.
  2. Train staff continuously. Coding updates, documentation standards, and payer rules shift constantly. Annual training isn't enough for high-risk service lines.
  3. Run simulated internal audits. Mirror the government audit process, pull a sample of charts, check documentation against billed codes, and find the gaps before an actual auditor does.
  4. Use billing compliance software or a specialized RCM partner. Practices without in-house audit expertise benefit from real-time error flagging and specialty coding review before claims go out.

That support matters most in high-scrutiny specialties. Persistex's CPC-, CPB-, RHIT-, and CCS-certified team reviews psychotherapy codes (90832-90838) and psychiatric evaluations (90791/90792) against current documentation standards so gaps surface in-house—not during a payer or government audit.

Quick-reference audit checklist:

  • Claims match documentation exactly
  • Medical necessity is clearly supported in the chart
  • Filing deadlines are met for every payer
  • Payer contract terms are reviewed at least annually

Common Compliance Violations and Their Consequences

Most violations aren't dramatic fraud schemes. They're avoidable mistakes that compound over time.

Frequent violations include:

  • Lack of documented medical necessity
  • Incorrect or upcoded coding
  • Insufficient or missing documentation
  • Duplicate billing for the same service

The consequences scale with severity. A single coding error might trigger a repayment demand. A pattern of errors can bring civil monetary penalties, prepayment review status, or Medicare/Medicaid exclusion.

In one 2021 case, an ENT practice paid $750,000 to resolve upcoding allegations tied to evaluation-and-management services, with no formal admission of liability.

Intent matters less than most practices expect. Even unintentional errors can trigger repayment demands, penalties, or exclusion—so catching patterns early through routine audits costs far less than fixing them after a payer notice.

Frequently Asked Questions

What is an example of a compliance audit?

A common example is an OIG or RAC review of a practice's evaluation-and-management coding levels, checking whether documentation actually supports the billed service. Behavioral health and psychotherapy claims are increasingly reviewed the same way, comparing CPT codes against session notes.

How do I prepare for a compliance audit?

Maintain organized, medical-necessity-supported documentation, run regular self-audits, and keep staff current on coding and regulatory changes. A quarterly internal review for high-risk services catches most issues before they escalate.

Who can perform a compliance audit?

Audits can be internal, run by practice staff or a compliance officer, or external, performed by independent auditors, payers, or specialized RCM firms like Persistex that bring certified coding expertise to the review.

How often should billing compliance audits be conducted?

Both OIG guidance and AAPC recommend quarterly internal reviews for high-risk service lines, plus at least one comprehensive annual audit covering every service line.

What triggers a billing compliance audit?

Common triggers include aberrant billing patterns, statistical outliers compared to peer providers, patient or employee complaints, and whistleblower reports. CMS also flags providers with unusually high claim-error rates.

What happens if a practice fails a compliance audit?

Outcomes range from repayment demands and civil penalties to prepayment review status. In severe cases involving intentional fraud, practices can face exclusion from federal healthcare programs or criminal prosecution.