Medical coding audit tutorial text over a desk with magnifying glass, stethoscope, calculator, and documents.

How to Perform a Medical Coding Audit:Step-by-Step Tutorial for 2026

How to Perform a Medical Coding Audit:Step-by-Step Tutorial for 2026

By Nicole Statley at Healthcare Compliance Pros

A medical coding audit is more than a claim review. Done well, it helps an organization confirm that the clinical record supports the codes billed, identify patterns before they become repayment or denial problems, and give coders and providers practical feedback they can use.

In 2026, a strong audit process should account for current ICD-10-CM guidance, quarterly HCPCS updates, Medicare National Correct Coding Initiative edits, payer-specific coverage rules, and the organization's own risk history. The goal is not to find a certain number of errors. It is to produce a fair, repeatable review that improves documentation, coding accuracy, and revenue integrity.

Quick takeaway: A reliable coding audit follows five steps: plan the audit, build the checklist, select cases, conduct the review, and report and remediate findings.

Understanding Medical Coding Audits: Why They Matter in 2026

A medical coding audit is a structured comparison of the patient record, coding, charge capture, and submitted claim. The reviewer determines whether the documentation supports the diagnosis codes, procedure codes, modifiers, units, medical necessity, and billing requirements for the service.

A coding audit can identify both overpayments and underpayments. It may also uncover documentation gaps, inconsistent provider practices, training needs, edit failures, or workflow issues that lead to preventable denials.

What a coding audit should answer

  • Was the service actually documented?
  • Does the documentation support the level and type of service billed?
  • Are ICD-10-CM diagnosis codes specific, current, and supported by the record?
  • Are CPT and HCPCS codes accurate for the service performed?
  • Were modifiers used appropriately and supported by documentation?
  • Do code combinations comply with applicable CMS National Correct Coding Initiative, or NCCI, edits?
  • Does the claim meet Medicare, Medicaid, commercial payer, and organizational requirements?
  • Is there a pattern that requires education, workflow changes, repayment review, or a larger audit?

CMS states that Medicare payment depends on medical record documentation supporting coverage, coding, and billing requirements. Documentation deficiencies remain a common source of improper payments identified through medical review activity.

Why 2026 requires extra attention

Coding teams should not rely on last year's code references or billing edits. Codes can be added and deleted each year, so it's important to stay current and audit with the correct lens.

CMS also releases HCPCS updates throughout the year. For example, CMS posted January, April, July, and October 2026 HCPCS Level II files, each with its own effective date. Medicare NCCI edits also change periodically, and the NCCI Policy Manual effective January 1, 2026 should be used as a reference for Medicare coding policy.

For compliance leaders, audit planning should also align with the organization's risk assessment. OIG's General Compliance Program Guidance recommends that the compliance work plan include audits based on risks identified through the annual risk assessment, along with routine monitoring of known and emerging risks.

Regulatory context to keep in view

Compliance area

What the coding audit should evaluate

CMS documentation requirements

Whether the medical record supports coverage, coding, billing, and medical necessity

ICD-10-CM updates

Whether diagnosis codes and sequencing follow current official guidance

CPT and HCPCS updates

Whether procedure and supply codes are current for the date of service

NCCI edits

Whether code combinations, units, and modifiers are appropriate

Medicare and Medicaid rules

Whether claims meet federal program requirements and applicable state Medicaid rules

Commercial payer policies

Whether prior authorization, coverage, modifier, and documentation rules are met

HIPAA privacy

Whether auditors have role-based access and use only the PHI necessary for the review

Overpayment obligations

Whether findings are escalated promptly for investigation, quantification, and repayment decisions

HIPAA's minimum necessary standard generally requires covered entities to take reasonable steps to limit PHI access, use, and disclosure to what is needed for the intended purpose. Audit teams should have access controls, secure workspaces, and defined procedures for handling audit files.

Step 1: Plan Your Medical Coding Audit

The best audits begin before the first chart is opened. Planning creates consistency, helps prevent scope creep, and makes the results easier to defend and act on.

Set clear audit objectives

Start by documenting what the audit is intended to accomplish. Common objectives include:

  • Assess coding and documentation compliance
  • Reduce recurring claim denials
  • Validate medical necessity support
  • Review a new provider, coder, service line, or location
  • Test a known risk identified in a compliance risk assessment
  • Examine a high-dollar procedure or high-volume diagnosis
  • Evaluate changes after provider or coder education
  • Investigate a potential overpayment trend

Avoid vague objectives such as "review coding accuracy." Instead, state the specific question.

Example audit objective: "Evaluate whether office visit documentation and code selection for established patient E/M services billed from January through March 2026 support the reported level of service, including any separately reported procedure modifiers."

Choose the audit type

Audit type

When it is useful

Example

Prospective audit

Before claims are submitted

Review high-risk surgical claims before billing

Retrospective audit

After claims are billed or paid

Examine denial trends or potential overpayments

Focused audit

When a known risk exists

Review modifier 25 use with same-day procedures

Random audit

To measure general compliance

Select claims across providers and service lines

Targeted audit

To review high-risk claims

Focus on high-dollar infusions or E/M services

Follow-up audit

To test whether remediation worked

Re-audit charts after training or workflow changes

Define the scope

Write the scope in a short audit charter or work plan. It should include:

  • Audit period and dates of service
  • Providers, locations, departments, or service lines included
  • Claim types and payers included
  • Codes, modifiers, diagnoses, or procedures under review
  • Data sources, such as EHR, charge capture system, billing system, denial reports, and payer portals
  • Sample methodology and planned sample size
  • Reviewer qualifications and independence
  • Reporting recipients
  • Due dates and escalation procedures

Assemble the right team

A coding audit may involve more than coders. Depending on the scope, the team may include:

  • Certified coders or auditors
  • Compliance officer or compliance committee representative
  • HIM or clinical documentation integrity staff
  • Revenue cycle and denial-management personnel
  • Practice administrator or department manager
  • Medical director, provider champion, or specialty subject matter expert
  • Legal counsel, when findings involve potential legal exposure or self-disclosure considerations

Internal teams understand the organization's workflows. An outside reviewer may be helpful when independence, specialty expertise, limited resources, or a fresh perspective is needed.

Healthcare Compliance Pros can support organizations with focused coding audits, documentation review tools, risk-based audit planning, education, and corrective-action support tailored to the current healthcare environment.

Step 2: Develop Your Audit Checklist and Tools

A checklist is the audit team's quality-control tool. It keeps reviews consistent across reviewers and ensures the final report can show exactly how findings were reached.

Build a 2026-ready coding audit checklist

Your checklist should match the specialty, payer mix, service type, and risk area. At minimum, include the following elements.

Checklist category

Questions to ask

Patient and encounter

Is the correct patient, date of service, rendering provider, and place of service reflected?

Documentation

Is the service documented, signed or authenticated as required, and complete?

Diagnosis coding

Do diagnosis codes accurately reflect documented conditions and required specificity?

Procedure coding

Do CPT or HCPCS codes match services actually performed?

E/M services

Does the documentation support the selected code under the applicable rules?

Modifiers

Is each modifier necessary, supported, and correctly applied?

Medical necessity

Does documentation support the reason for the service and any applicable coverage criteria?

Bundling and edits

Does the claim comply with NCCI edits and other applicable coding rules?

Units

Do billed units match the record, dosage, time, or quantity documented?

Payer rules

Does the claim meet applicable LCD, NCD, Medicaid, Medicare Advantage, or commercial payer rules?

Privacy and security

Was PHI accessed, stored, and shared securely during the audit?

Finding classification

Is the issue an overcode, undercode, documentation gap, technical error, or education opportunity?

Keep code sources current

Your checklist should prompt reviewers to verify the code set and policy that applied on the date of service, not only the date of audit.

For 2026, maintain access to:

  • FY 2026 ICD-10-CM Official Guidelines and code files
  • Current CPT resources licensed for organizational use
  • CMS HCPCS Level II updates
  • Current NCCI edits and policy guidance
  • Relevant Medicare Local Coverage Determinations and National Coverage Determinations
  • State Medicaid billing manuals and provider bulletins for each state in which the organization participates
  • Current payer manuals and policy updates

CMS explains that NCCI Procedure-to-Procedure edits are intended to prevent improper payment when incorrect code combinations are reported.

Practical tool: Create a one-page "coding changes log" that records the update, effective date, impacted departments, required system changes, staff education date, and validation results.

Step 3: Sampling and Case Selection

Sampling should be deliberate. Reviewing only easy charts or only obvious problem claims can create a misleading picture of compliance.

Choose a sampling method

Method

Best use

Limitation

Statistical sampling

Estimating an error rate across a defined population

Requires a sound methodology and may require expert support

Judgmental sampling

Investigating known risks or high-risk services

Results generally should not be generalized to the full population without further analysis

For most internal compliance audits, judgmental sampling is useful when there is a specific risk to test. For example, a practice may select claims with modifier 25, high-level E/M codes, high-cost drugs, repeated denials, or medically unlikely units.

Prioritize high-risk encounters

Consider including claims with one or more of these indicators:

  • High-dollar reimbursement
  • High-volume procedures
  • Frequent payer denials or appeals
  • New providers, new coders, or new clinical services
  • Significant changes in coding rules or payer policy
  • Outlier patterns by provider, location, or code
  • Services involving modifiers, time-based codes, or multiple procedures
  • Claims near NCCI edit boundaries
  • Services previously associated with errors or repayment activity

Sample-size guidance

There is no universal sample size that works for every organization. The appropriate number depends on the size of the population, audit objective, risk level, resources, and whether results will be extrapolated.

For a focused internal audit, a practical starting point may be a manageable set of records per provider or risk area. If the audit identifies a meaningful error pattern, expand the sample before drawing conclusions about the broader population.

Document:

  • The full population
  • Inclusion and exclusion criteria
  • Sample selection method
  • Selected claims
  • Reason for targeted selections
  • Any sample expansion
  • Limits on how findings should be interpreted

Step 4: Conduct the Coding Review

Consistency matters. Review every selected encounter in the same sequence and document the evidence supporting each conclusion.

Use a repeatable review workflow

1. Confirm the patient, provider, date of service, payer, and claim details.

2. Review the complete relevant documentation, not only the billing summary.

3. Identify diagnoses, services, supplies, time, and procedures documented.

4. Compare the record with reported ICD-10-CM, CPT, HCPCS, modifier, and unit data.

5. Verify applicable coverage, medical necessity, bundling, and payer requirements.

6. Record the finding, rationale, source, and financial impact when known.

7. Classify the root cause before finalizing the report.

Common coding error types

  • Upcoding: Reporting a higher-level or more complex service than documentation supports.
  • Undercoding: Reporting a lower-level service or failing to capture supported services.
  • Unbundling: Reporting separate codes for services that should be included in a comprehensive code.
  • Incorrect modifier use: Adding a modifier without documentation that supports the distinct circumstance.
  • Unsupported diagnosis coding: Reporting conditions not documented, no longer active, or insufficiently specific.
  • Medical-necessity mismatch: Documentation does not support why the service was needed under the payer's coverage criteria.
  • Incorrect units: Billing more or fewer units than documentation supports.
  • Date-of-service error: Applying a new code, rule, or edit to a claim that predates its effective date.

Real-world audit scenario

A multispecialty practice notices a rise in denials for office visits billed with a same-day minor procedure.

The audit team selects 30 claims with an E/M code and a procedure code reported on the same date of service. The reviewer checks whether the record supports a significant, separately identifiable E/M service in addition to the work inherent in the procedure.

The review finds:

  • 10 claims had documentation supporting both services.
  • 12 claims had a procedure note but limited documentation of a separately identifiable E/M service.
  • 8 claims showed inconsistent modifier selection or unclear charge-entry workflows.

The issue is not automatically "provider upcoding." The findings suggest a combination of documentation inconsistency, modifier education needs, and possible workflow problems. The corrective action should address each root cause rather than treating every error as an individual coding mistake.

Step 5: Reporting, Remediation, and Follow-Up

The value of an audit comes from what happens after the review. A report should be factual, understandable, and action-oriented.

Build an actionable audit report

A clear report generally includes:

  • Audit objective, scope, dates, and methodology
  • Population size and sample selection approach
  • Overall results and error categories
  • Findings by provider, specialty, location, payer, or service type when appropriate
  • Examples that are de-identified for broad education
  • Root-cause analysis
  • Estimated financial impact, if within scope
  • Recommended corrective actions
  • Assigned owners and due dates
  • Follow-up validation plan

Avoid reports that simply list errors. Leadership needs to know what happened, why it happened, what risk it creates, and what the organization will do next.

Match remediation to the root cause

Root cause

Appropriate response

Knowledge gap

Targeted coder or provider education with examples

Unclear documentation template

Revise template, smart phrases, or workflow prompts

Charge-capture issue

Update charge master, billing edit, or charge-entry process

Outdated code reference

Update resources and validate effective dates

Payer-policy gap

Create payer-specific job aid or prebill edit

Repeat individual error

Focused coaching and competency validation

Broader compliance concern

Expand audit scope and involve compliance leadership

OIG's guidance emphasizes risk assessment, auditing and monitoring, training, and responding to detected offenses through corrective action initiatives as parts of an effective compliance program.

Handle potential overpayments promptly

If an audit suggests a potential overpayment, do not treat the audit report as the final repayment determination. Escalate the finding under the organization's established compliance process for validation, population review, quantification, repayment analysis, and documentation.

CMS states that Medicare providers and suppliers generally must report and return an identified overpayment by the later of 60 days after identification or the date any corresponding cost report is due, if applicable. State Medicaid programs may have their own reporting, refund, self-disclosure, and documentation requirements, so organizations should evaluate applicable federal and state requirements with compliance and legal counsel.

Re-audit to verify improvement

Corrective action is incomplete until the organization checks whether it worked.

A follow-up audit should confirm:

  • Education was completed and documented
  • Policies, templates, charge edits, or workflows were updated
  • New coding patterns meet expectations
  • Denials or edit failures decreased where relevant
  • Repeat errors are not continuing
  • New risks have been identified and added to the audit plan

Key Pitfalls and How to Avoid Them

Pitfall: Starting without a defined scope

A broad "coding audit" can quickly become unmanageable and hard to interpret.

Better approach: Define the population, date range, codes, payers, risk question, and intended use of results before selecting claims.

Pitfall: Using outdated coding references

Code updates, edit changes, and payer policies can affect whether an otherwise reasonable claim is payable.

Better approach: Verify the code set, policy, edit, and coverage requirement that applied on the date of service. Maintain a documented update-management process for ICD-10-CM, HCPCS, NCCI, and payer changes.

Pitfall: Treating every error as a coder problem

Many coding issues begin upstream in documentation, template design, clinical workflow, charge capture, or system configuration.

Better approach: Use root-cause analysis. Ask why the error occurred and what change will make correct performance easier the next time.

Pitfall: Ignoring undercoding

Compliance risk is not limited to overpayments. Undercoding may distort data, reduce appropriate reimbursement, create operational inefficiencies, and conceal documentation quality issues.

Better approach: Track undercoding, missed charges, and unsupported denials alongside potential overcoding.

Pitfall: Failing to document the audit itself

An undocumented audit is difficult to reproduce, defend, or use for meaningful improvement.

Better approach: Retain the audit charter, sample methodology, checklist, reviewer notes, findings, education records, corrective-action plan, and follow-up results according to the organization's record-retention practices.

How Healthcare Compliance Pros Makes Auditing Easier

Healthcare Compliance Pros helps healthcare organizations turn audit expectations into a workable process. Support can be tailored to practices, billing companies, specialty groups, and healthcare organizations that need practical guidance without a one-size-fits-all approach.

Our medical coding audit support can include:

  • Risk-based audit planning
  • Customized coding audit checklists
  • Focused documentation and code reviews
  • Specialty-specific audit tools
  • Provider and coder education
  • Corrective-action planning
  • Follow-up audit support
  • Compliance program resources aligned with federal requirements and relevant state considerations
  • Consultation on documentation, coding, revenue integrity, and monitoring workflows

The goal is to help your organization build a process that is practical for daily operations, traceable for compliance purposes, and flexible enough to adapt to changing coding and payer requirements.

Need a starting point? Use a standardized coding audit checklist, select one high-risk area, document the methodology, and schedule a follow-up review before the first audit report is issued.

Medical Coding Audit FAQ for 2026

How often should a medical coding audit be performed?

Frequency should be based on risk, volume, payer mix, prior findings, staffing changes, new services, and regulatory updates. Many organizations include routine coding audits in an annual compliance work plan, then conduct additional focused audits when denial data, complaints, new coding rules, or prior findings indicate elevated risk. OIG recommends scheduling audits based on risks identified through the organization's annual risk assessment while maintaining capacity to audit emerging concerns.

Which teams should be involved in a coding audit?

At minimum, involve qualified coding or auditing personnel and the appropriate operational leader. Depending on the audit, include compliance, HIM, CDI, revenue cycle, practice operations, clinical leadership, IT or EHR support, and legal counsel. Providers should receive focused feedback when documentation practices are part of the finding.

What should be included in a coding audit checklist?

A checklist should cover patient and encounter information, record completeness, diagnosis coding, procedure coding, modifiers, units, E/M selection when applicable, medical necessity, NCCI edits, payer-specific requirements, findings, root cause, corrective action, and follow-up status.

How do I select claims for a coding audit?

Start with the audit objective. Use random sampling to assess a broader population and judgmental sampling to examine known risks. High-risk selections may include high-dollar claims, high-volume codes, modifier use, repeated denials, new providers, new service lines, unusual utilization patterns, and services with recent coding or policy changes.

How do we stay compliant with changing 2026 coding requirements?

Assign ownership for monitoring official CMS, OIG, state Medicaid, Medicare Administrative Contractor, and payer updates. Track effective dates, update systems and audit tools, train affected staff, and test the change through targeted post-implementation auditing.

Does a coding audit guarantee compliance or protect against enforcement?

No. A coding audit is a key compliance and revenue-integrity activity, but it does not guarantee that an organization will avoid denials, repayments, audits, investigations, or enforcement action. Its value comes from identifying risks early, documenting a reasonable review process, correcting validated issues, and monitoring whether remediation works.

Disclaimer

This article is for general educational and informational purposes only. It is not legal advice, coding advice for a particular claim, reimbursement advice, or a substitute for review by qualified legal counsel, coding professionals, compliance personnel, or applicable payer guidance. Requirements vary by payer, program, state, service, and date of service. Always verify current federal, state, and payer-specific requirements before making billing, coding, disclosure, or repayment decisions.

Sources

  • CMS: ICD-10 resources and FY 2026 ICD-10-CM Official Guidelines
  • CMS: Complying with Medical Record Documentation Requirements
  • CMS: HCPCS Quarterly Update
  • HHS OIG: General Compliance Program Guidance
  • HHS: HIPAA Minimum Necessary Requirement
  • CMS: National Correct Coding Initiative (NCCI) and 2026 Policy Manual
  • CMS: Medicare Rep