...

STOP Credentialing Delays from HOLDING UP YOUR REVENUE Learn More

What Happens After a Practice Receives an Audit Request?

Share:

Medical Question

"One of my biggest concerns is receiving an audit letter and not knowing what to do next. If our practice receives a request for records from a payer, Medicare contractor, or government agency, what should we expect, and what steps should we take immediately to protect the practice?"

Medical Answer

Few things create more anxiety in a physician practice than receiving an audit letter. Practice managers immediately assume the worst:

  • “Are we being investigated?”
  • “Did we do something wrong?”
  • “Are we going to owe money?”

The reality is that many audits occur for reasons that have nothing to do with fraud or intentional misconduct.

Audit requests can come from Medicare contractors, commercial payers, Medicaid programs, Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs), or government agencies. Audits may be triggered by:

  • Routine oversight activities
  • Billing trends
  • Specialty-specific reviews
  • High utilization patterns
  • Random sampling
  • New enforcement initiatives

The key is not to panic. The key is to respond strategically.

Many audits are routine, data-driven, or focused on specific services rather than suspected fraud. The most important first steps are to carefully review the request, understand what records are being requested, meet all deadlines, preserve documentation, and coordinate a consistent response process.

Practices that remain organized and proactive are typically better positioned to navigate audits successfully.

Step 1: Read the Audit Request Carefully

One of the biggest mistakes practices make is reacting before fully understanding the request. Start by determining:

  • Who sent the request?
  • What type of audit is involved?
  • What records are being requested?
  • What dates are included?
  • What is the response deadline?

Not all audits are the same. The response process often depends on the organization conducting the review.

Step 2: Determine the Scope of the Audit

Some audits involve:

  • A single claim
  • A small sample of records
  • A specific provider
  • A specific service line
  • Multiple years of claims

Understanding the scope helps you assess the potential impact on the practice. The earlier you understand the scope, the better prepared you’ll be.

Step 3: Preserve Documentation

Once an audit request arrives, it’s important to preserve the original medical record and supporting documentation. This may include:

  • Medical records
  • Billing records
  • Coding documentation
  • Policies and procedures
  • Training records
  • Internal audit findings

Documentation should never be altered after an audit request is received. If additional information is needed, it should be clearly identified as supplemental documentation.

Step 4: Assign a Point Person

One of the smartest things a practice can do is designate a single individual to coordinate the response. This may be:

  • Practice manager
  • Compliance officer
  • Revenue cycle manager
  • Administrator
  • Outside consultant

Without a central point of contact, practices often struggle with:

  • Duplicate efforts
  • Missed deadlines
  • Inconsistent communication
  • Incomplete submissions

Centralized coordination improves efficiency and accuracy.

Step 5: Review the Records Before Submission

Before sending records, conduct an internal review. Ask questions like:

  • Is the documentation complete?
  • Are all requested records included?
  • Does the documentation support the services billed?
  • Are there any obvious concerns?

This review helps identify potential issues before the auditor does.

Step 6: Look for Patterns

Even if the audit only requests a small sample of claims, practices should ask: “Could this issue affect other claims?”

For example:

  • Documentation gaps
  • Modifier 25 concerns
  • Medical necessity issues
  • Telehealth billing problems
  • Coding inconsistencies

An audit request often provides valuable insight into areas that deserve additional review.

Step 7: Meet Every Deadline

Missing a deadline can create additional problems. Many practices spend so much time reviewing records that they lose track of response requirements.

Create a timeline that includes:

  • Record collection
  • Internal review
  • Leadership review
  • Submission deadlines

Staying organized is critical.

Real Practice Example

A multi-specialty physician practice received a request for records involving several high-level E/M visits.

Leadership initially focused only on gathering the requested documentation. During an internal review, however, they discovered that providers documented medical decision making differently across the organization.

The audit itself involved only a handful of claims. The underlying issue affected dozens.

The practice responded to the audit request while simultaneously implementing provider education and documentation standardization efforts. The audit became an opportunity for improvement rather than simply a compliance event.

Should we contact an attorney immediately after receiving an audit request?

Not necessarily.

Many audits are routine and can be managed through normal compliance and administrative processes. However, practices should consider professional guidance if:

  • Significant financial exposure exists
  • Fraud allegations are involved
  • A government investigation is underway
  • Legal concerns are identified

The level of response should match the complexity of the audit.

Turn Every Audit Into a Learning Opportunity

One of the biggest mistakes is treating an audit request as an isolated event. Many practices gather records, submit them, and move on.

The most successful practices ask: “Why was this claim selected?”

That question often uncovers opportunities to improve documentation, coding, training, and compliance processes.

Here are some steps you can take today:

✅ Review your audit response process.

✅ Identify who would coordinate an audit response.

✅ Verify where records are stored.

✅ Review documentation retention policies.

✅ Conduct a mock audit exercise.

✅ Identify potential documentation vulnerabilities.

Preparation before an audit is always easier than preparation during an audit.

Bottom Line

Receiving an audit request can be stressful, but it does not automatically indicate wrongdoing. Practices that respond methodically, preserve documentation, meet deadlines, and evaluate underlying processes are often best positioned for successful outcomes. Every audit request is an opportunity not only to respond but also to strengthen compliance, documentation, and operational performance.

Key Takeaways

  • An audit request does not automatically indicate wrongdoing.
  • Read the request carefully before taking action.
  • Understand exactly what records are being requested.
  • Meet all deadlines.
  • Preserve original documentation.
  • Coordinate responses through a designated individual.
  • Use the audit as an opportunity to identify improvement areas.

Be Ready Before the Audit Letter Arrives

The best time to prepare for an audit is before you receive one. Healthcare Training Leader’s All-Access Training Pass provides year-round access to expert-led education on audit readiness, OIG priorities, documentation, coding compliance, medical necessity, Modifier 25, payer audits, and healthcare fraud prevention.

By helping your team understand what auditors review and how to respond effectively, you can reduce stress, improve compliance, and strengthen your practice’s ability to navigate regulatory scrutiny.

 

 

All Access Pass

Meet Your Expert

Hillary Stemple

JD
Partner, ARENTFOX SCHIFF LLP

Hillary focuses her practice on advising a wide range of health care practices on complex health care regulatory matters such as compliance with health care fraud and abuse laws, with an emphasis on the Anti-Kickback Statute, Stark Law, and the False Claims Act.

Hillary also counsels clients on all aspects of overpayment issues and making voluntary self-disclosures, including the drafting and submission of self-disclosures to the OIG Self-Disclosure Protocol and the CMS Self-Referral Disclosure Protocol.

She also regularly coordinates with the firm’s Government Relations group on federal advocacy efforts before Congress and the US Department of Health and Human Services on behalf of health care practices.

Additional Resources