Overview
A medical coding audit is a structured review of a sample of claims and their supporting clinical documentation to verify that coding is accurate, compliant, and supports the billed services. Audits are foundational to any compliance program and serve three purposes: detecting revenue leakage from under-coding, detecting compliance risk from over-coding, and providing educational feedback to coders and providers.
Audits fall into two broad categories. Internal audits are performed by the organization's own compliance, coding, or HIM teams (or by engaged external consultants) on a routine basis — typically monthly or quarterly — sampling claims across specialties, payers, and coders. External audits are initiated by payers (through prepayment or postpayment review), MACs (through Targeted Probe and Educate programs), OIG (through Work Plan audits), Recovery Audit Contractors (through claim sampling for overpayments), or ZPICs/UPICs (for program integrity review). Each external audit has its own scope and remediation mechanics.
Audit methodology typically combines sampling and scoring. A random or stratified sample of claims is pulled (by CPT category, coder, provider, payer, or diagnosis). For each claim, the auditor reviews the supporting documentation and scores the coding against a rubric — correct primary diagnosis, correct procedure codes, correct modifiers, appropriate E/M level, accurate diagnosis-procedure linking. Results are aggregated to an accuracy rate (typically 95%+ is best-in-class) and individual coder performance scores.
Audit findings drive corrective action. Coders with consistent error patterns receive targeted education. Providers with documentation gaps get CDI-style queries or education. System-level patterns (e.g., specific CPT with repeated modifier errors) may prompt edit rule additions or charge master changes. Refunds are required for over-coded claims; under-coded claims may be re-billed within timely filing. Major patterns may escalate to compliance disclosure.
For external audits, responses are procedurally demanding. RAC and MAC audits require documentation submission within 45 days; missing the deadline forfeits the case. OIG audits often include document requests, interviews, and formal responses. Mature compliance programs maintain audit-response playbooks, designated liaisons, and pre-staged documentation retrieval workflows to handle external audits without disrupting operations.
Compliance programs treat Medical Coding Audit as a recurring audit trigger rather than a one-time policy exercise. The practical approach is a quarterly Medical Coding Audit self-audit tied into the broader compliance calendar, with findings tracked against coding compliance and upcoding so a Medical Coding Audit gap cannot silently persist from one audit cycle to the next. Reviewers on this site pair every Medical Coding Audit reference with the corresponding regulatory citation so the policy owner can trace the requirement back to its authoritative source.
Medical Coding Audit is one of the compliance areas where documentation discipline determines audit outcomes more than policy sophistication. Practices that invest in clean Medical Coding Audit records, consistent coding compliance workflows, and auditable upcoding evidence come out of OIG, RAC, and MAC audits with materially smaller recoupment exposure than practices with equivalent policies but weaker paper trails.
Industry benchmark
OIG Work Plan audit targets published annually. AAPC/AHIMA coder accuracy benchmark: 95%+ is best-in-class. Internal audit frequency: monthly-to-quarterly for mature programs. RAC automated review rate on Medicare claims: 1–3%.
Worked example
A 40-physician multispecialty group's compliance team runs a quarterly coding audit. A stratified sample of 200 claims across 4 specialties returns 94% accuracy with three identified patterns: surgery underutilizing modifier 59 (down-coded, $12K identified for rebilling), E/M coding in one clinic consistently over-leveled (4 claims over-coded, $1,400 in refunds issued), and radiology modifier 26 omissions in cross-covered reads (down-coded, $4K for rebilling). Targeted education and an edit rule update close the patterns.
Frequently asked questions — Medical Coding Audit
How often should we audit our coding?
Quarterly minimum for a mature compliance program, monthly for higher-risk specialties (surgery, cardiology, E/M-heavy practices). New coders and new providers typically have focused audit during onboarding. External audit prep may drive additional ad-hoc internal audits.
What accuracy rate should we target?
95%+ is industry best-in-class; 98–99% is achievable in mature operations. Below 90% indicates training or process gaps that need immediate attention. Individual coder scores, specialty scores, and trend lines matter as much as the overall average.
Do external auditors use different rules than internal?
Same coding rules (AMA CPT, CMS NCCI, payer medical policies) but different sampling, deadlines, and remediation. External auditors may use specific payer policies that internal audits don't emphasize. Consistency requires using the same or equivalent rubrics.
What triggers an external audit?
Claim pattern outliers (E/M leveling vs peer, modifier 59 usage, specific CPT frequency), CERT-detected error rates, whistleblower allegations, OIG Work Plan topics, and random sampling by RACs. Patterns detected internally can often be corrected before they surface externally.
Disclaimer
This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.