Medical Coding Audit Checklist: Accuracy, Compliance & Documentation Review
A medical coding audit should reveal why a claim is defensible, where revenue is leaking, and which errors could become compliance liabilities. Reviewing code accuracy alone misses documentation, medical necessity, modifier use, payer policy, and recurring workflow failures. Whether you are building medical coding audit skills, improving professional-fee coding, investigating denial patterns, or strengthening CPT coding accuracy, the checklist below turns an audit into a repeatable compliance and revenue-control process.
1. Define the Audit Scope Before Reviewing a Single Claim
A useful coding audit begins with a specific question. “Check coding accuracy” is too broad. Decide whether you are testing E/M leveling, modifiers, diagnosis specificity, NCCI edits, medical necessity, high-risk procedures, one provider, one coder, one payer, one specialty, or a denial pattern. This makes the audit substantially more actionable for teams managing medical coding productivity, insurance denials, claim adjustment reason codes, and electronic claim submission.
Use both random and targeted sampling. Random cases help estimate ordinary performance. Targeted cases expose known risk: unusually high-level E/M utilization, repeated modifier use, unusually high units, one coder's elevated denial rate, services frequently bundled under NCCI, or claims from a provider with documentation problems. OIG compliance guidance treats internal monitoring and auditing as a core compliance-program function, making regular review far more valuable than an audit performed only after a payer asks questions.
Before review, lock the date-specific rule set. Use the CPT/HCPCS and ICD-10-CM rules applicable to the date of service, the payer's policy, current or applicable NCCI edits, coverage requirements, and the documentation actually available for that encounter. CMS's 2026 NCCI manual is effective January 1, 2026, while NCCI edit files can also receive quarterly updates. This matters for anyone practicing CPC coding, preparing for coding interview tests, working in higher-paying coding specialties, or moving into medical coding auditing.
| Audit Checkpoint | What to Verify | Common Failure | Audit Action |
|---|---|---|---|
| 1. Patient and DOS | Record matches billed patient and service date | Wrong chart or encounter | Stop review until reconciled |
| 2. Rendering provider | Provider matches service documentation | Incorrect rendering clinician | Verify enrollment and claim data |
| 3. Place of service | POS reflects actual setting | Office/facility mismatch | Compare encounter location |
| 4. Primary diagnosis | Diagnosis reflects reason for service | Unrelated or unsupported diagnosis | Recode from documentation |
| 5. Diagnosis specificity | Laterality, stage, acuity, type and detail | Unspecified code despite available detail | Capture supported specificity |
| 6. Diagnosis validity | Code valid for date of service | Deleted or invalid code | Check date-specific code set |
| 7. CPT/HCPCS selection | Code matches service performed | Wrong procedure family | Compare code descriptor with record |
| 8. E/M level | MDM or time supports selected level | Upcoding or downcoding | Recalculate level independently |
| 9. Time-based coding | Required time documented and attributable | Insufficient or overlapping time | Recalculate reportable time |
| 10. Modifier 25 | Separate E/M work supported | Routine procedure work billed as E/M | Remove inherent procedure work mentally |
| 11. Modifier 59/X modifiers | True procedural distinction documented | Modifier added only to bypass edit | Identify exact distinct circumstance |
| 12. Anatomical modifiers | Site/laterality matches record | Wrong side or missing site modifier | Map claim line to documentation |
| 13. NCCI PTP edits | Code pair and modifier indicator | Improper unbundling | Review applicable edit and policy |
| 14. MUEs | Units comply with applicable edit logic | Excess units without support | Validate units and documentation |
| 15. Global surgery | Related services treated correctly | Separate billing for included care | Review global-period rules |
| 16. Add-on codes | Valid primary procedure reported | Orphan add-on code | Verify primary/add-on relationship |
| 17. Units billed | Units match dose, time, quantity or sessions | Calculation error | Reperform unit calculation |
| 18. Medical necessity | Condition supports billed service | Technically coded service lacks coverage basis | Compare policy and patient facts |
| 19. NCD/LCD requirements | Coverage criteria met | Missing required indication | Map record to policy criteria |
| 20. Documentation completeness | Assessment, plan, service details and relevant findings present | Claim exceeds documented work | Score documentation gap |
| 21. Signature/authentication | Record properly authenticated | Missing or invalid signature | Apply payer documentation rules |
| 22. Cloned documentation | Record reflects current patient encounter | Copied-forward contradictions | Compare surrounding visits |
| 23. Diagnosis-procedure relationship | Diagnosis supports service billed | Diagnosis attached for payment convenience | Trace service to assessment |
| 24. Authorization | Service, units, dates and provider match approval | Authorization mismatch | Reconcile approval to claim |
| 25. Payer-specific policy | Claim meets payer rules | Medicare logic used for all payers | Check governing payer policy |
| 26. Duplicate billing | Service was not previously paid or submitted incorrectly | True duplicate | Review claim history |
| 27. Charge capture | All documented billable services captured once | Missed or duplicate charge | Reconcile note to charge lines |
| 28. Under-coding | Documentation supports greater specificity/value | Revenue left unbilled | Record lost-revenue finding separately |
| 29. Over-coding | Billed service does not exceed documentation | Overpayment/compliance exposure | Prioritize corrective review |
| 30. Error recurrence | Same defect appears across claims | Systemic rather than isolated failure | Escalate to root-cause correction |
2. Audit Coding Accuracy Line by Line, Not Just at the Claim Level
A claim can be “mostly correct” and still contain a financially or legally significant error. Review each diagnosis, procedure, modifier, unit, and claim relationship independently. Start with diagnosis coding: confirm that every reported condition is supported, specific enough, valid for the date of service, and relevant under applicable reporting rules. This is fundamental for coders sharpening medical terminology, working through CCS practice questions, building CPC exam skills, or entering risk-adjustment coding.
Then independently verify every CPT or HCPCS service against the note. A procedure name that sounds similar to a code descriptor is insufficient. Look at technique, anatomy, number of lesions or units, approach, laterality, time, and whether another reported code already includes the work. CMS explains that NCCI edits are designed to promote correct coding and prevent inappropriate payment, while providers remain responsible for correct code combinations even when an automated edit does not exist. That principle should guide CPT coding reviews, professional-fee coding audits, coding interview preparation, and denial investigations.
Modifiers deserve their own audit pass. Ask what factual circumstance each modifier communicates and locate that fact in the record. Modifier 25 requires defensible separate E/M work; modifier 59 and the X{EPSU} family require a valid procedural distinction; anatomical modifiers must agree with documented site and laterality. A modifier that merely makes an edit disappear creates a major compliance warning.
Finally, compare under-coding and over-coding separately. Over-coding creates repayment and compliance exposure. Under-coding hides revenue and may reveal coder fear, inadequate education, or faulty internal edits. A high-quality medical coding auditor identifies both rather than treating an audit as a search only for overbilling.
3. Test Documentation and Medical Necessity Against the Service Actually Billed
Documentation review should answer a simple question: Could another qualified reviewer reconstruct why this service was coded and billed this way using the record alone?
CMS's current E/M guidance says documentation should identify the reason for the encounter, relevant history and findings, assessment or diagnosis, plan of care, rationale for diagnostic or ancillary services, and other information supporting the codes reported. CMS also emphasizes that documentation volume does not determine the E/M level and that medical necessity remains central to payment. This is essential for teams working on E/M-heavy professional coding, coding productivity, denial prevention, and coding-auditor careers.
Separate documentation sufficiency from medical necessity. A beautifully documented service can still fail a coverage requirement. A medically reasonable service can also fail because the note does not establish that reason clearly enough. Compare the record with applicable NCDs, LCDs, payer medical policies, authorization terms, and code-specific rules. Medicare's medical review program expressly evaluates whether claims satisfy coverage, coding, billing, and medical-necessity requirements, and contractors may recover improper payments after review.
Pay particular attention to cloned notes, copied-forward diagnoses, templated examinations, conflicting laterality, impossible timestamps, unsigned documentation, and plans that do not match the diagnosis billed. These defects frequently explain patterns later seen in CARC denials, electronic claim failures, medical coding stress, and payer recoupment work.
4. Score Audit Findings by Accuracy, Financial Impact, and Compliance Risk
A single “accuracy percentage” hides too much.
Suppose 95 of 100 claims are technically accurate. One of the five errors is a low-dollar diagnosis-specificity issue. Another systematically upcodes a high-volume E/M service. Those errors should never carry the same risk weight. Organizations using medical coding audit programs, denial management, physician reimbursement analysis, and claim adjustment analysis should classify findings more precisely.
Track at least four dimensions:
Coding accuracy: Did the submitted codes, modifiers, units, and sequence agree with the record and applicable rules?
Documentation support: Did the medical record establish every material element needed to defend the claim?
Financial variance: Did the error produce overpayment, underpayment, denial risk, or missed revenue?
Compliance severity: Is the error isolated, repeated, systemic, intentional-looking, or connected to a known high-risk billing pattern?
Then calculate error rates by provider, coder, code family, payer, modifier, location, specialty, and root cause. A blended 96% accuracy rate may conceal one coder at 99% and another at 81%, or one physician generating nearly every unsupported high-level service. That granularity gives much stronger direction for coder training, coding interview development, coding resume skill development, and movement into advanced coding specialties.
Also separate technical error rate from claim-level accuracy. A claim containing five codes and one incorrect modifier might be one inaccurate claim but only one incorrect coding element. Both measurements can be useful; they answer different questions.
5. Turn Audit Findings Into Corrective Action and Re-Audit the Risk
An audit creates value only when it changes behavior.
For every material finding, identify the root cause, owner, corrective action, deadline, and re-audit date. “Coder error” is rarely deep enough. The underlying cause may be outdated reference material, confusing payer policy, inadequate documentation, faulty software edits, productivity pressure, incomplete training, poor charge configuration, or a provider repeatedly choosing codes without sufficient support. This distinction matters for organizations dealing with coding productivity pressure, medical coding stress, outsourcing concerns, and remote coding performance.
Match the intervention to the failure. Repeated modifier mistakes may require case-based coder training and edit redesign. Unsupported E/M levels may require provider education. Incorrect units may indicate charge-master or calculation problems. Diagnosis specificity failures may point toward documentation improvement. Payer-specific denials may require better electronic claims logic, stronger denial workflows, closer CARC tracking, or better billing-system controls.
For overpayments, escalate findings through the organization's compliance and repayment process rather than treating the issue as an educational footnote. OIG's compliance guidance places auditing, corrective action, communication, training, and enforcement within the broader compliance framework.
Then re-audit the same risk, rather than immediately switching topics. If modifier 25 accuracy was 72%, educate the relevant group and sample modifier-25 claims again. If the new score is 91%, investigate the remaining 9%. A correction that is never tested is only an assumption.
The strongest audit program gradually connects coding accuracy, reimbursement performance, denial prevention, and auditor career-level analysis into one feedback loop.
6. FAQs About Medical Coding Audits
-
A strong checklist should review patient and provider information, ICD-10-CM diagnoses, CPT/HCPCS codes, modifiers, units, E/M levels, NCCI edits, medical necessity, documentation, signatures, coverage rules, place of service, authorization, and payer requirements. The audit should also distinguish under-coding from over-coding. This approach combines CPT coding knowledge, medical billing concepts, denial analysis, and coding audit skills.
-
There is no single sample size that fits every audit objective. The appropriate number depends on claim volume, risk, error history, specialty, payer mix, and whether the audit is exploratory, routine, statistically valid, or targeted. A small targeted audit can uncover a specific modifier issue, while broader compliance work may require a much larger sample. Organizations should define the sampling methodology before review and preserve it with the audit record, particularly when investigating coding productivity, payer denials, coding specialties, or professional-fee coding.
-
Rather than relying on one universal percentage, establish thresholds appropriate to the organization and monitor both overall accuracy and high-risk error categories. A 97% score can still conceal a systematic modifier or E/M problem. Track accuracy by coder, provider, code family, payer, dollar impact, and compliance severity. This creates better information for coder training, medical coding resumes, coding interviews, and auditing advancement.
-
A coding audit determines whether diagnoses, procedures, modifiers, units, sequencing, and other reported data are correct. A documentation audit focuses more closely on whether the medical record establishes the services and clinical facts needed to support those codes. The two overlap heavily because CMS requires documentation to support the diagnosis and treatment codes reported on the claim. Coders working in professional coding, risk adjustment, denial management, and medical coding auditing need both perspectives.
-
Determine whether the E/M family is correct, then independently establish the level using the applicable MDM or time rules rather than accepting the billed level. Confirm that medical necessity supports the service and that documentation reflects the work performed. CMS's May 2026 E/M booklet specifically cautions against using documentation volume to determine the level of service. This makes E/M review a high-value skill for CPC candidates, professional coders, coding interview candidates, and auditors.
-
For modifier 25, identify the E/M work beyond the usual work associated with the same-day procedure. For modifier 59 or an X{EPSU} modifier, identify the specific documented reason the procedures qualify as distinct. Never treat modifier use as correct merely because the claim paid. Review the underlying NCCI relationship and payer rule. CMS states that correct coding remains the provider's responsibility even when an edit is absent. This analysis connects directly with CPT coding, denial management, coding audits, and coding assessment preparation.