...

STOP Credentialing Delays from HOLDING UP YOUR REVENUE Learn More

Internal CMS Audits: Find Your Medicare Compliance Risks Before an Auditor Does

Share: Share on Facebook Share on Twitter Share on LinkedIn

Internal CMS Audits: Find Your Medicare Compliance Risks Before an Auditor Does

Share: Share on Facebook Share on Twitter Share on LinkedIn

Waiting until you receive an audit request to find out whether your Medicare documentation and billing processes will hold up is a risky strategy.

CMS has significantly expanded its Medicare Advantage audit efforts, increased the use of technology to identify unsupported diagnoses, and dramatically expanded the number of medical coders reviewing records. At the same time, documentation continues to play a major role in Medicare improper payments.

For your practice, the message is clear: you need to know what an auditor could find before the auditor finds it.

A well-designed internal CMS audit can help you uncover weak documentation, questionable coding patterns, unsupported diagnoses, recurring modifier problems, and other compliance vulnerabilities while you still have an opportunity to correct your processes.

Why Your Practice Should Be Auditing Before CMS Comes Calling

CMS announced in May 2025 that it would dramatically expand Medicare Advantage Risk Adjustment Data Validation (RADV) audits. Instead of auditing approximately 60 Medicare Advantage plans per year, CMS said it would audit all eligible contracts in newly initiated audits—approximately 550 plans. CMS also announced plans to increase its team of medical coders from 40 to approximately 2,000.

That does not mean CMS is directly conducting RADV audits of 550 individual physician practices. RADV audits are directed at Medicare Advantage organizations and are designed to determine whether diagnoses submitted for risk-adjustment payments are supported by patients’ medical records.

But your documentation can be part of that equation.

If you treat Medicare Advantage patients, health plans may rely on documentation from your practice to substantiate diagnosis information. That makes accurate, complete medical records increasingly important.

Your goal should be to find vulnerabilities internally before they contribute to a denial, repayment demand, payer audit, RADV record request, or other compliance problem.

Go Beyond Routine Claim Reviews

Reviewing individual claims for coding errors is important, but don’t mistake that process for a comprehensive compliance audit.

A billing review may tell you that a modifier was used incorrectly or that a diagnosis code was missing. An internal compliance audit should go further by looking for patterns.

For example, are the same documentation problems appearing across multiple providers? Is one modifier being used far more frequently than expected? Are diagnoses being reported without sufficient documentation? Are your providers consistently supporting the level and medical necessity of the services billed?

Those patterns can expose much larger problems than one incorrectly coded claim.

Expert advice: Don’t design your audit simply to answer, “Was this claim coded correctly?” Ask, “What would this claim tell an outside reviewer about the way our practice operates?”

That change in perspective can help you identify systemic risks instead of repeatedly correcting isolated errors.

Start With Medical Necessity and the Reason for the Encounter

One of the first places to look is the documentation explaining why the patient needed the service.

Generic descriptions such as “follow-up” or “med check” may not tell the complete story. Your documentation should clearly communicate the patient’s condition, what was evaluated or managed, and why the services performed were medically necessary.

During an internal audit, select a sample of encounters and ask:

  • Can you quickly determine why the patient was seen?
  • Does the documentation support the diagnoses reported?
  • Does the assessment and plan demonstrate how the condition was evaluated or managed?
  • Does the documentation support the services and level of care billed?
  • Would an auditor who knows nothing about the patient understand why the service was medically necessary?

If you have to make assumptions to connect the pieces, an outside reviewer may have the same problem.

All Access Pass

Pay Special Attention to Diagnosis Documentation

Diagnosis documentation deserves additional attention as Medicare Advantage RADV scrutiny increases.

CMS uses RADV audits to confirm that diagnoses submitted by Medicare Advantage organizations for risk-adjustment purposes are actually supported by patients’ medical records. Unsupported diagnoses can result in CMS recovering overpayments from Medicare Advantage organizations.

CMS reported an estimated $23.67 billion in Medicare Part C improper payments for FY 2025, representing an estimated improper payment rate of 6.09%. According to the agency, most Part C improper payments involved situations where supporting documentation failed to substantiate beneficiary diagnosis data submitted for payment.

CMS’s Medicare Part C improper-payment data further explains that an overpayment can occur when there is insufficient documentation to make a payment determination or when medical records don’t support the CMS-HCCs for which the Medicare Advantage organization received payment.

This is why your audit shouldn’t simply confirm that a diagnosis code appears on the claim. Verify that the medical record supports it.

Expert advice: Consider periodically auditing high-risk, chronic, and risk-adjusting diagnoses separately from your general coding audit. Look for diagnoses that continue to appear on claims even though the current encounter documentation does not clearly support their status, assessment, or management.

Look for Billing Patterns That Could Attract Attention

Individual claims rarely tell the whole story. Patterns do.

Use your billing data to identify unusual trends that deserve a closer look. Depending on your specialty, this could include high utilization of certain E/M levels, frequent modifier use, repeated combinations of services, unusually high procedure volume, or substantial differences between providers performing similar work.

A pattern doesn’t automatically mean you’re doing something wrong. It tells you where to investigate.

For example, if one provider uses Modifier 25 significantly more often than other providers in the practice, review a sample of those claims. Determine whether the documentation consistently supports a significant, separately identifiable E/M service in addition to the procedure performed that day.

Your internal audit should help you answer the questions an auditor might ask before those questions are directed at you.

Use CMS Audit Resources to Strengthen Your Internal Process

You don’t have to guess what CMS considers important.

CMS publicly provides information about Medicare Advantage and Part D program audits, including audit protocols, audit submission checklists, program audit reports, data collection specifications, and other resources.

CMS also publishes RADV guidance, audit methods and instructions, audit schedules, questions and answers, and other documents related specifically to Medicare Advantage RADV audits.

Your physician practice is not necessarily subject to the same audit protocols as a Medicare Advantage organization. However, reviewing CMS audit materials can help your compliance team understand the level of organization, documentation, data integrity, and corrective action federal reviewers expect.

In fact, CMS has previously encouraged Medicare organizations to use its program audit protocols and tools to conduct mock audits because doing so can help identify operational vulnerabilities and areas of noncompliance before an actual program audit.

Your internal audit file should document what you reviewed, how you selected the sample, what you found, what corrective action was taken, and how you determined whether the correction worked.

Don’t Stop When You Find an Error

Finding the problem is only the beginning.

Suppose your audit finds that several providers are consistently documenting a particular service incorrectly. Correcting the sampled claims doesn’t solve the underlying problem. If the same documentation practice continues tomorrow, your compliance risk continues too.

Instead, determine why the error happened.

Was your team trained incorrectly? Is your EHR template contributing to the problem? Does your written policy conflict with current requirements? Is a provider misunderstanding a coding rule? Does your billing team need a second review before certain claims are submitted?

Once you identify the cause, create a documented corrective action plan.

Your plan should identify the problem, who is responsible for correcting it, what education or process change is required, when the correction should occur, and when you will re-audit the issue.

Expert advice: Always include a follow-up audit date. An education session or policy change doesn’t prove the problem was corrected. Your follow-up sample does.

Have a Process for Potential Medicare Overpayments

Your internal audit may uncover more than a documentation weakness. It could identify a potential overpayment.

That requires prompt attention.

Federal Medicare overpayment requirements make it especially important to have a formal process for identifying, investigating, reporting, and returning applicable overpayments. Don’t allow a potential overpayment uncovered during an audit to sit unresolved in someone’s inbox or on a billing report.

Your practice should have a written process for escalating potential overpayments immediately to the appropriate compliance, billing, legal, or leadership personnel so the issue can be investigated and handled within applicable federal requirements.

Create an Internal CMS Audit Checklist

Consistency makes your internal audit program stronger. Instead of reinventing the process each time, develop a standard checklist your compliance or billing team can use.

Your checklist should address areas such as:

  • Medical necessity and reason-for-visit documentation
  • Diagnosis-to-documentation support
  • E/M level selection
  • Modifier utilization
  • Procedure documentation
  • Provider signatures and authentication
  • High-risk diagnosis codes
  • Unusual billing and utilization patterns
  • Overpayment identification and escalation
  • Staff and provider training
  • Corrective action documentation
  • Follow-up auditing

You may also want to create specialty-specific sections based on your highest-risk services.

The point isn’t to make your audit as complicated as possible. It’s to create a repeatable process that helps you identify problems early and prove that your practice takes compliance seriously.

Turn Audit Findings Into Staff Training

Your audit results can also tell you exactly where your training dollars and staff time should go.

Instead of providing generic annual education and hoping it addresses your biggest problems, use actual audit findings to determine what your providers, coders, billers, and administrative staff need to learn.

If you uncover repeated Modifier 25 errors, train on Modifier 25. If diagnoses aren’t adequately supported, address documentation. If overpayment procedures aren’t being followed, make sure everyone involved understands when and how to escalate a potential problem.

This makes compliance training relevant to the work your employees actually perform—and gives you a documented response to identified risk.

Make Internal Audits Part of Your Compliance Routine

You can’t eliminate every possibility of a Medicare audit. You can control how prepared your practice is when scrutiny occurs.

Don’t wait for an audit letter, payer request, repayment demand, or compliance complaint to discover whether your documentation and billing processes are defensible. Periodic internal audits give you an opportunity to identify weak points, educate your team, correct recurring problems, and verify that your changes actually worked.

The strongest audit defense isn’t scrambling to fix your records after someone requests them. It’s building processes that help your team get the documentation, coding, and billing right before the claim ever leaves your practice.

Keep Your Entire Team Ready for Changing Medicare Requirements

CMS rules, documentation expectations, coding requirements, payer policies, and compliance risks don’t stand still—and neither can your team’s training. With Healthcare Training Leader’s Annual All-Access Pass, your entire practice gets access to expert-led medical office training covering billing, coding, Medicare, compliance, credentialing, reimbursement, practice management, and more.

Instead of purchasing training every time a new issue arises, you can give your staff the resources they need throughout the year to identify problems earlier, implement changes correctly, and protect your practice’s revenue. Give your entire team year-round access to the practical training they need to stay compliant, get paid correctly, and be ready when an audit comes your way.