How to Perform a Medical Coding Audit:Step-by-Step Tutorial for 2026
By Nicole Statley at Healthcare Compliance Pros
A medical coding audit is more than a claim review. Done
well, it helps an organization confirm that the clinical record supports the
codes billed, identify patterns before they become repayment or denial
problems, and give coders and providers practical feedback they can use.
In 2026, a strong audit process should account for current
ICD-10-CM guidance, quarterly HCPCS updates, Medicare National Correct Coding
Initiative edits, payer-specific coverage rules, and the organization's own
risk history. The goal is not to find a certain number of errors. It is to
produce a fair, repeatable review that improves documentation, coding accuracy,
and revenue integrity.
Quick takeaway: A
reliable coding audit follows five steps: plan the audit, build the checklist,
select cases, conduct the review, and report and remediate findings.
Understanding Medical Coding Audits: Why They Matter in 2026
A medical coding audit is a structured comparison of the
patient record, coding, charge capture, and submitted claim. The reviewer
determines whether the documentation supports the diagnosis codes, procedure
codes, modifiers, units, medical necessity, and billing requirements for the
service.
A coding audit can identify both overpayments and
underpayments. It may also uncover documentation gaps, inconsistent provider
practices, training needs, edit failures, or workflow issues that lead to
preventable denials.
What a coding audit should answer
- Was the service actually documented?
- Does the documentation support the level and type of service billed?
- Are ICD-10-CM diagnosis codes specific, current, and supported by the record?
- Are CPT and HCPCS codes accurate for the service performed?
- Were modifiers used appropriately and supported by documentation?
- Do code combinations comply with applicable CMS National Correct Coding Initiative, or NCCI, edits?
- Does the claim meet Medicare, Medicaid, commercial payer, and organizational requirements?
- Is there a pattern that requires education, workflow changes, repayment review, or a larger audit?
CMS states that Medicare payment depends on medical record
documentation supporting coverage, coding, and billing requirements.
Documentation deficiencies remain a common source of improper payments
identified through medical review activity.
Why 2026 requires extra attention
Coding teams should not rely on last year's code references
or billing edits. Codes can be added and deleted each year, so it's important
to stay current and audit with the correct lens.
CMS also releases HCPCS updates throughout the year. For
example, CMS posted January, April, July, and October 2026 HCPCS Level II
files, each with its own effective date. Medicare NCCI edits also change
periodically, and the NCCI Policy Manual effective January 1, 2026 should be
used as a reference for Medicare coding policy.
For compliance leaders, audit planning should also align
with the organization's risk assessment. OIG's General Compliance Program
Guidance recommends that the compliance work plan include audits based on risks
identified through the annual risk assessment, along with routine monitoring of
known and emerging risks.
Regulatory context to keep in view
|
Compliance
area |
What
the coding audit should evaluate |
|
CMS documentation requirements |
Whether the medical record supports coverage, coding,
billing, and medical necessity |
|
ICD-10-CM updates |
Whether diagnosis codes and sequencing follow current
official guidance |
|
CPT and HCPCS updates |
Whether procedure and supply codes are current for the date
of service |
|
NCCI edits |
Whether code combinations, units, and modifiers are
appropriate |
|
Medicare and Medicaid rules |
Whether claims meet federal program requirements and
applicable state Medicaid rules |
|
Commercial payer policies |
Whether prior authorization, coverage, modifier, and
documentation rules are met |
|
HIPAA privacy |
Whether auditors have role-based access and use only the
PHI necessary for the review |
|
Overpayment obligations |
Whether findings are escalated promptly for investigation, quantification, and repayment decisions |
HIPAA's minimum necessary standard generally requires
covered entities to take reasonable steps to limit PHI access, use, and
disclosure to what is needed for the intended purpose. Audit teams should have
access controls, secure workspaces, and defined procedures for handling audit
files.
Step 1: Plan Your Medical Coding Audit
The best audits begin before the first chart is opened.
Planning creates consistency, helps prevent scope creep, and makes the results
easier to defend and act on.
Set clear audit objectives
Start by documenting what the audit is intended to
accomplish. Common objectives include:
- Assess coding and documentation compliance
- Reduce recurring claim denials
- Validate medical necessity support
- Review a new provider, coder, service line, or location
- Test a known risk identified in a compliance risk assessment
- Examine a high-dollar procedure or high-volume diagnosis
- Evaluate changes after provider or coder education
- Investigate a potential overpayment trend
Avoid vague objectives such as "review coding accuracy."
Instead, state the specific question.
Example audit objective: "Evaluate whether office visit
documentation and code selection for established patient E/M services billed
from January through March 2026 support the reported level of service,
including any separately reported procedure modifiers."
Choose the audit type
|
Audit
type |
When
it is useful |
Example |
|
Prospective audit |
Before claims are submitted |
Review high-risk surgical claims before billing |
|
Retrospective audit |
After claims are billed or paid |
Examine denial trends or potential overpayments |
|
Focused audit |
When a known risk exists |
Review modifier 25 use with same-day procedures |
|
Random audit |
To measure general compliance |
Select claims across providers and service lines |
|
Targeted audit |
To review high-risk claims |
Focus on high-dollar infusions or E/M services |
|
Follow-up audit |
To test whether remediation worked |
Re-audit charts after training or workflow changes |
Define the scope
Write the scope in a short audit charter or work plan. It should include:
- Audit period and dates of service
- Providers, locations, departments, or service lines included
- Claim types and payers included
- Codes, modifiers, diagnoses, or procedures under review
- Data sources, such as EHR, charge capture system, billing system, denial reports, and payer portals
- Sample methodology and planned sample size
- Reviewer qualifications and independence
- Reporting recipients
- Due dates and escalation procedures
Assemble the right team
A coding audit may involve more than coders. Depending on
the scope, the team may include:
- Certified coders or auditors
- Compliance officer or compliance committee representative
- HIM or clinical documentation integrity staff
- Revenue cycle and denial-management personnel
- Practice administrator or department manager
- Medical director, provider champion, or specialty subject matter expert
- Legal counsel, when findings involve potential legal exposure or self-disclosure considerations
Internal teams understand the organization's workflows. An
outside reviewer may be helpful when independence, specialty expertise, limited
resources, or a fresh perspective is needed.
Healthcare Compliance Pros can support organizations with
focused coding audits, documentation review tools, risk-based audit planning,
education, and corrective-action support tailored to the current healthcare
environment.
Step 2: Develop Your Audit Checklist and Tools
A checklist is the audit team's quality-control tool. It
keeps reviews consistent across reviewers and ensures the final report can show
exactly how findings were reached.
Build a 2026-ready coding audit checklist
Your checklist should match the specialty, payer mix,
service type, and risk area. At minimum, include the following elements.
|
Checklist
category |
Questions
to ask |
|
Patient and encounter |
Is the correct patient, date of service, rendering
provider, and place of service reflected? |
|
Documentation |
Is the service documented, signed or authenticated as
required, and complete? |
|
Diagnosis coding |
Do diagnosis codes accurately reflect documented conditions
and required specificity? |
|
Procedure coding |
Do CPT or HCPCS codes match services actually performed? |
|
E/M services |
Does the documentation support the selected code under the
applicable rules? |
|
Modifiers |
Is each modifier necessary, supported, and correctly
applied? |
|
Medical necessity |
Does documentation support the reason for the service and
any applicable coverage criteria? |
|
Bundling and edits |
Does the claim comply with NCCI edits and other applicable
coding rules? |
|
Units |
Do billed units match the record, dosage, time, or quantity
documented? |
|
Payer rules |
Does the claim meet applicable LCD, NCD, Medicaid, Medicare
Advantage, or commercial payer rules? |
|
Privacy and security |
Was PHI accessed, stored, and shared securely during the
audit? |
|
Finding classification |
Is the issue an overcode, undercode, documentation gap, technical error, or education opportunity? |
Keep code sources current
Your checklist should prompt reviewers to verify the code
set and policy that applied on the date of service, not only the date of audit.
For 2026, maintain access to:
- FY 2026 ICD-10-CM Official Guidelines and code files
- Current CPT resources licensed for organizational use
- CMS HCPCS Level II updates
- Current NCCI edits and policy guidance
- Relevant Medicare Local Coverage Determinations and National Coverage Determinations
- State Medicaid billing manuals and provider bulletins for each state in which the organization participates
- Current payer manuals and policy updates
CMS explains that NCCI Procedure-to-Procedure edits are
intended to prevent improper payment when incorrect code combinations are
reported.
Practical tool: Create a one-page "coding changes log" that
records the update, effective date, impacted departments, required system
changes, staff education date, and validation results.
Step 3: Sampling and Case Selection
Sampling should be deliberate. Reviewing only easy charts or
only obvious problem claims can create a misleading picture of compliance.
Choose a sampling method
|
Method |
Best
use |
Limitation |
|
Statistical sampling |
Estimating an error rate across a defined population |
Requires a sound methodology and may require expert support |
|
Judgmental sampling |
Investigating known risks or high-risk services |
Results generally should not be generalized to the full population without further analysis |
For most internal compliance audits, judgmental sampling is
useful when there is a specific risk to test. For example, a practice may
select claims with modifier 25, high-level E/M codes, high-cost drugs, repeated
denials, or medically unlikely units.
Prioritize high-risk encounters
Consider including claims with one or more of these
indicators:
- High-dollar reimbursement
- High-volume procedures
- Frequent payer denials or appeals
- New providers, new coders, or new clinical services
- Significant changes in coding rules or payer policy
- Outlier patterns by provider, location, or code
- Services involving modifiers, time-based codes, or multiple procedures
- Claims near NCCI edit boundaries
- Services previously associated with errors or repayment activity
Sample-size guidance
There is no universal sample size that works for every
organization. The appropriate number depends on the size of the population,
audit objective, risk level, resources, and whether results will be
extrapolated.
For a focused internal audit, a practical starting point may
be a manageable set of records per provider or risk area. If the audit
identifies a meaningful error pattern, expand the sample before drawing
conclusions about the broader population.
Document:
- The full population
- Inclusion and exclusion criteria
- Sample selection method
- Selected claims
- Reason for targeted selections
- Any sample expansion
- Limits on how findings should be interpreted
Step 4: Conduct the Coding Review
Consistency matters. Review every selected encounter in the
same sequence and document the evidence supporting each conclusion.
Use a repeatable review workflow
1. Confirm the patient, provider, date of service,
payer, and claim details.
2. Review the complete relevant documentation, not
only the billing summary.
3. Identify diagnoses, services, supplies, time,
and procedures documented.
4. Compare the record with reported ICD-10-CM, CPT,
HCPCS, modifier, and unit data.
5. Verify applicable coverage, medical necessity,
bundling, and payer requirements.
6. Record the finding, rationale, source, and
financial impact when known.
7. Classify the root cause before finalizing the
report.
Common coding error types
- Upcoding: Reporting a higher-level or more complex service than documentation supports.
- Undercoding: Reporting a lower-level service or failing to capture supported services.
- Unbundling: Reporting separate codes for services that should be included in a comprehensive code.
- Incorrect modifier use: Adding a modifier without documentation that supports the distinct circumstance.
- Unsupported diagnosis coding: Reporting conditions not documented, no longer active, or insufficiently specific.
- Medical-necessity mismatch: Documentation does not support why the service was needed under the payer's coverage criteria.
- Incorrect units: Billing more or fewer units than documentation supports.
- Date-of-service error: Applying a new code, rule, or edit to a claim that predates its effective date.
Real-world audit scenario
A multispecialty practice notices a rise in denials for
office visits billed with a same-day minor procedure.
The audit team selects 30 claims with an E/M code and a
procedure code reported on the same date of service. The reviewer checks
whether the record supports a significant, separately identifiable E/M service
in addition to the work inherent in the procedure.
The review finds:
- 10 claims had documentation supporting both services.
- 12 claims had a procedure note but limited documentation of a separately identifiable E/M service.
- 8 claims showed inconsistent modifier selection or unclear charge-entry workflows.
The issue is not automatically "provider upcoding." The
findings suggest a combination of documentation inconsistency, modifier
education needs, and possible workflow problems. The corrective action should
address each root cause rather than treating every error as an individual
coding mistake.
Step 5: Reporting, Remediation, and Follow-Up
The value of an audit comes from what happens after the
review. A report should be factual, understandable, and action-oriented.
Build an actionable audit report
A clear report generally includes:
- Audit objective, scope, dates, and methodology
- Population size and sample selection approach
- Overall results and error categories
- Findings by provider, specialty, location, payer, or service type when appropriate
- Examples that are de-identified for broad education
- Root-cause analysis
- Estimated financial impact, if within scope
- Recommended corrective actions
- Assigned owners and due dates
- Follow-up validation plan
Avoid reports that simply list errors. Leadership needs to
know what happened, why it happened, what risk it creates, and what the
organization will do next.
Match remediation to the root cause
|
Root
cause |
Appropriate
response |
|
Knowledge gap |
Targeted coder or provider education with examples |
|
Unclear documentation template |
Revise template, smart phrases, or workflow prompts |
|
Charge-capture issue |
Update charge master, billing edit, or charge-entry process |
|
Outdated code reference |
Update resources and validate effective dates |
|
Payer-policy gap |
Create payer-specific job aid or prebill edit |
|
Repeat individual error |
Focused coaching and competency validation |
|
Broader compliance concern |
Expand audit scope and involve compliance leadership |
OIG's guidance emphasizes risk assessment, auditing and
monitoring, training, and responding to detected offenses through corrective
action initiatives as parts of an effective compliance program.
Handle potential overpayments promptly
If an audit suggests a potential overpayment, do not treat
the audit report as the final repayment determination. Escalate the finding
under the organization's established compliance process for validation,
population review, quantification, repayment analysis, and documentation.
CMS states that Medicare providers and suppliers generally
must report and return an identified overpayment by the later of 60 days after
identification or the date any corresponding cost report is due, if
applicable. State Medicaid programs may
have their own reporting, refund, self-disclosure, and documentation
requirements, so organizations should evaluate applicable federal and state
requirements with compliance and legal counsel.
Re-audit to verify improvement
Corrective action is incomplete until the organization
checks whether it worked.
A follow-up audit should confirm:
- Education was completed and documented
- Policies, templates, charge edits, or workflows were updated
- New coding patterns meet expectations
- Denials or edit failures decreased where relevant
- Repeat errors are not continuing
- New risks have been identified and added to the audit plan
Key Pitfalls and How to Avoid Them
Pitfall: Starting without a defined scope
A broad "coding audit" can quickly become unmanageable and
hard to interpret.
Better approach: Define the population, date range, codes,
payers, risk question, and intended use of results before selecting claims.
Pitfall: Using outdated coding references
Code updates, edit changes, and payer policies can affect
whether an otherwise reasonable claim is payable.
Better approach: Verify the code set, policy, edit, and
coverage requirement that applied on the date of service. Maintain a documented
update-management process for ICD-10-CM, HCPCS, NCCI, and payer changes.
Pitfall: Treating every error as a coder problem
Many coding issues begin upstream in documentation, template
design, clinical workflow, charge capture, or system configuration.
Better approach: Use root-cause analysis. Ask why the error
occurred and what change will make correct performance easier the next time.
Pitfall: Ignoring undercoding
Compliance risk is not limited to overpayments. Undercoding
may distort data, reduce appropriate reimbursement, create operational
inefficiencies, and conceal documentation quality issues.
Better approach: Track undercoding, missed charges, and
unsupported denials alongside potential overcoding.
Pitfall: Failing to document the audit itself
An undocumented audit is difficult to reproduce, defend, or
use for meaningful improvement.
Better approach: Retain the audit charter, sample
methodology, checklist, reviewer notes, findings, education records,
corrective-action plan, and follow-up results according to the organization's
record-retention practices.
How Healthcare Compliance Pros Makes Auditing Easier
Healthcare Compliance Pros helps healthcare organizations
turn audit expectations into a workable process. Support can be tailored to
practices, billing companies, specialty groups, and healthcare organizations
that need practical guidance without a one-size-fits-all approach.
Our medical coding audit support can include:
- Risk-based audit planning
- Customized coding audit checklists
- Focused documentation and code reviews
- Specialty-specific audit tools
- Provider and coder education
- Corrective-action planning
- Follow-up audit support
- Compliance program resources aligned with federal requirements and relevant state considerations
- Consultation on documentation, coding, revenue integrity, and monitoring workflows
The goal is to help your organization build a process that
is practical for daily operations, traceable for compliance purposes, and
flexible enough to adapt to changing coding and payer requirements.
Need a starting point?
Use a standardized coding audit checklist, select one high-risk area,
document the methodology, and schedule a follow-up review before the first
audit report is issued.
Medical Coding Audit FAQ for 2026
How often should a medical coding audit be performed?
Frequency should be based on risk, volume, payer mix, prior
findings, staffing changes, new services, and regulatory updates. Many
organizations include routine coding audits in an annual compliance work plan,
then conduct additional focused audits when denial data, complaints, new coding
rules, or prior findings indicate elevated risk. OIG recommends scheduling
audits based on risks identified through the organization's annual risk
assessment while maintaining capacity to audit emerging concerns.
Which teams should be involved in a coding audit?
At minimum, involve qualified coding or auditing personnel
and the appropriate operational leader. Depending on the audit, include
compliance, HIM, CDI, revenue cycle, practice operations, clinical leadership,
IT or EHR support, and legal counsel. Providers should receive focused feedback
when documentation practices are part of the finding.
What should be included in a coding audit checklist?
A checklist should cover patient and encounter information,
record completeness, diagnosis coding, procedure coding, modifiers, units, E/M
selection when applicable, medical necessity, NCCI edits, payer-specific
requirements, findings, root cause, corrective action, and follow-up status.
How do I select claims for a coding audit?
Start with the audit objective. Use random sampling to
assess a broader population and judgmental sampling to examine known risks.
High-risk selections may include high-dollar claims, high-volume codes,
modifier use, repeated denials, new providers, new service lines, unusual
utilization patterns, and services with recent coding or policy changes.
How do we stay compliant with changing 2026 coding requirements?
Assign ownership for monitoring official CMS, OIG, state
Medicaid, Medicare Administrative Contractor, and payer updates. Track
effective dates, update systems and audit tools, train affected staff, and test
the change through targeted post-implementation auditing.
Does a coding audit guarantee compliance or protect against enforcement?
No. A coding audit is a key compliance and revenue-integrity
activity, but it does not guarantee that an organization will avoid denials,
repayments, audits, investigations, or enforcement action. Its value comes from
identifying risks early, documenting a reasonable review process, correcting
validated issues, and monitoring whether remediation works.
Disclaimer
This article is for
general educational and informational purposes only. It is not legal advice,
coding advice for a particular claim, reimbursement advice, or a substitute for
review by qualified legal counsel, coding professionals, compliance personnel,
or applicable payer guidance. Requirements vary by payer, program, state,
service, and date of service. Always verify current federal, state, and
payer-specific requirements before making billing, coding, disclosure, or
repayment decisions.
Sources
- CMS: ICD-10 resources and FY 2026 ICD-10-CM Official Guidelines
- CMS: Complying with Medical Record Documentation Requirements
- CMS: HCPCS Quarterly Update
- HHS OIG: General Compliance Program Guidance
- HHS: HIPAA Minimum Necessary Requirement
- CMS: National Correct Coding Initiative (NCCI) and 2026 Policy Manual
- CMS: Medicare Rep