What Does the OIG Actually Look For When Auditing Physician Practices?
"Whenever we hear about OIG investigations, it sounds like they only happen to providers committing obvious fraud. But most physician practices are just trying to follow the rules and keep up with changing regulations. What is the OIG actually looking for when it reviews physician practices, and what types of issues attract scrutiny?"
Practices assume OIG audits only target bad actors. In reality, the OIG uses data analytics, billing trends, whistleblower complaints, and audit priorities to identify areas that may pose risk to Medicare and Medicaid programs.
Many audits begin because a practice’s billing patterns differ from peers, documentation doesn’t fully support services billed, or a particular service becomes an enforcement priority. In many cases, the issue isn’t intentional misconduct—it’s a lack of awareness, inconsistent processes, or outdated workflows.
The good news is that understanding what the OIG looks for can help you proactively reduce risk. Practices with strong documentation, ongoing compliance training, regular internal audits, and awareness of OIG priorities are often better prepared to withstand scrutiny.
The OIG Focuses on Fraud, Waste, and Abuse
The OIG’s mission is to protect federal healthcare programs from fraud, waste, and abuse. The agency conducts audits, investigations, and reviews designed to identify improper payments and compliance concerns.
That doesn’t mean every audit involves criminal activity. Many reviews focus on whether:
- Services were medically necessary
- Documentation supports billing
- Claims meet Medicare requirements
- Coding is accurate
- Compliance processes are functioning properly
Think of the OIG as looking for risk indicators rather than simply looking for criminals.
Billing Outliers Often Get Attention
One of the most important takeaways from recent enforcement activity is that government agencies are increasingly using data analytics to identify providers whose billing patterns differ significantly from their peers.
For example, a practice might attract scrutiny if it:
- Bills significantly more high-level E/M services than similar practices
- Uses certain modifiers at unusually high rates
- Performs significantly more procedures than specialty benchmarks
- Bills services in patterns that appear unusual
When most practices think about audits, they focus on individual claims. The government often focuses on patterns.
Instead of asking: “Is this claim correct?”
Ask: “Would our billing patterns look reasonable compared to similar practices?”
That’s often the type of analysis government agencies are conducting behind the scenes. Being different doesn’t automatically mean you’re doing something wrong. But it may mean you’ll be asked to explain why.
Documentation Is Still the Foundation
If I had to identify one issue that appears repeatedly in audits, investigations, and enforcement actions, it would be documentation. The OIG wants to see that the medical record supports:
- The services performed
- The level of service billed
- Medical necessity
- Clinical decision-making
- Compliance with billing requirements
A claim may be coded correctly, but if the documentation doesn’t support it, the practice may still face denials, recoupments, or audit findings.
Medical Necessity Is a Major Focus
One of the most common themes throughout recent OIG and DOJ enforcement actions is medical necessity. The government continues to pursue cases involving allegations that procedures, tests, or services were performed without sufficient clinical justification.
When reviewing medical necessity, auditors often ask:
- Why was the service needed?
- Did the documentation support the decision?
- Was the service reasonable for the patient’s condition?
- Were alternative treatments considered?
Strong clinical reasoning documented in the medical record remains one of the best defenses.
Modifier 25 Continues to Be Under the Microscope
If your practice uses Modifier 25, this should be on your radar.
The OIG has conducted multiple audits involving Modifier 25 across specialties including dermatology, podiatry, and ophthalmology. These reviews identified high error rates and significant estimated overpayments.
The key issue is whether the E/M service was: Significant and separately identifiable from the procedure performed.
Practices should regularly audit Modifier 25 usage and ensure documentation clearly supports the additional work performed.
Telehealth and Virtual Services Remain Active Review Areas
The OIG has also reviewed virtual check-ins, e-visits, and telehealth services, identifying improper payments where billing requirements were not met.
Common documentation issues include:
- Missing patient consent
- Incorrect codes
- Failure to document time
- Missing provider or patient location information
- Insufficient support for the service billed
As telehealth rules continue to evolve, practices should review documentation requirements regularly.
The OIG Pays Attention to Financial Relationships
The government also reviews arrangements involving:
- Referral relationships
- Compensation agreements
- Ancillary services
- Management service organizations
- Physician ownership interests
The goal is to identify potential violations of the Anti-Kickback Statute and Stark Law. Financial arrangements that appear tied to referral patterns often receive increased scrutiny.
Real Practice Example
An orthopedic practice believed it was operating compliantly because it had never experienced a significant audit.
During an internal review, leadership discovered that providers were using Modifier 25 differently, documentation standards varied significantly, and telehealth visits were being documented inconsistently.
None of these issues involved intentional wrongdoing. However, each created potential audit risk.
The practice implemented quarterly audits, standardized documentation expectations, and provider education sessions. Within six months, coding consistency improved and leadership felt much more confident about its compliance posture.
Does receiving an audit request mean our practice did something wrong?
Not necessarily.
Many audits are driven by data, billing patterns, specialty reviews, or broader enforcement initiatives. An audit request doesn’t automatically mean wrongdoing occurred.
However, every audit request should be taken seriously and viewed as an opportunity to evaluate your compliance processes.
One of the biggest mistakes I see is assuming compliance reviews are only necessary after receiving an audit notice. By then, the claims have already been submitted.
The most successful practices audit themselves before someone else does. They regularly review:
- Documentation
- Coding
- Modifier usage
- Telehealth claims
- Denial trends
- OIG priorities
That’s where problems are most often identified early.
What Your Practice Should Review Before an Auditor Does
✅ Review your top billed CPT codes.
✅ Audit recent Modifier 25 claims.
✅ Review telehealth documentation.
✅ Evaluate medical necessity support.
✅ Compare billing patterns to specialty benchmarks.
✅ Check current OIG Work Plan topics.
The goal isn’t perfection. The goal is awareness.
Bottom Line
The OIG is not just looking for obvious fraud. Today’s audits often focus on documentation, medical necessity, coding accuracy, billing patterns, telehealth services, Modifier 25 usage, and financial relationships. Practices that understand these priorities and conduct proactive internal reviews are far better positioned to reduce risk and confidently respond to government scrutiny.
Key Takeaways
- OIG audits are often data-driven.
- Billing outliers can attract attention.
- Documentation remains one of the biggest risk areas.
- Medical necessity is a common audit focus.
- Modifier 25 continues to receive significant scrutiny.
- Telehealth and virtual services remain active review areas.
- Internal audits can help identify problems before regulators do.
Stay Ahead of OIG Audit PrioritiesGovernment enforcement is becoming increasingly data-driven, and physician practices need to stay informed about emerging risks. Healthcare Training Leader’s All-Access Training Pass provides year-round access to expert-led training on OIG audit priorities, healthcare fraud prevention, documentation, coding compliance, medical necessity, telehealth billing, Modifier 25, and other high-risk areas. Instead of reacting to audit findings after they occur, your team can proactively strengthen compliance and reduce risk throughout the year. Learn more about Healthcare Training Leader’s All-Access Training Pass and give your providers, coders, billers, and compliance staff the education they need to stay ahead of changing enforcement priorities. |
Meet Your Expert
Hillary Stemple
Hillary focuses her practice on advising a wide range of health care practices on complex health care regulatory matters such as compliance with health care fraud and abuse laws, with an emphasis on the Anti-Kickback Statute, Stark Law, and the False Claims Act.
Hillary also counsels clients on all aspects of overpayment issues and making voluntary self-disclosures, including the drafting and submission of self-disclosures to the OIG Self-Disclosure Protocol and the CMS Self-Referral Disclosure Protocol.
She also regularly coordinates with the firm’s Government Relations group on federal advocacy efforts before Congress and the US Department of Health and Human Services on behalf of health care practices.
Additional Resources
-
How Can a Medical Practice Tell If an Arrangement Could Violate the Stark Law?
A routine physician contract, lease, ownership interest, or compensation arrangement can create Stark Law concerns when referrals are involved. Understand how to screen financial relationships, identify designated health...
-
Respond to Payer Audits with Confidence & Reduce Recoupments
A payer audit notification can strike fear into the hearts of medical practices — but it doesn't have to. Discover how to respond effectively thanks to expert tips...
-
6 Ways to Improve Medical Coding and Billing Accuracy and Protect Your Revenue
Strong documentation is only half the battle when it comes to getting your practice paid correctly. Your codes must accurately reflect what the provider documented and the services...

