Revenue at Risk: How AI-Powered Payer Analytics Are Changing the Way Practices Get Audited
Author Jacob Yates at Healthcare Compliance Pros
A practice can submit technically clean claims one at a time
and still develop a billing profile that attracts payer scrutiny. The
difference today is that claims are increasingly assessed as part of a
continuously updated pattern, not just as isolated transactions. And that makes
"revenue at risk" a financial exposure that can be estimated, prioritized, and
reduced.
For practice owners, CFOs, compliance officers, and
revenue-cycle leaders, the question isn't, "Could this claim be denied?" It is:
"What portion of our current and future reimbursement is vulnerable because
our cumulative billing patterns look unusual?" CMS and its
program-integrity partners already use data analytics, statistical outlier
detection, machine learning, and now AI to find potential improper payment
risk. Similarly, commercial payers also have strong incentives to use automated
analytics to focus review resources where patterns indicate a closer look is
needed.
The Shift From Manual Review to Algorithmic Surveillance
Historically, claims review was constrained by human
capacity. A payer could apply claim edits, review select claims against
coverage and coding rules, and conduct post-payment audits based on complaints,
known risk areas, or random samples. Those controls still exist, but they are
no longer the whole picture. In fact, with the rise of AI, they will likely
become less of the picture than ever before.
Claim oversight begins with data. Program-integrity guidance
from CMS describes data analysis as an essential first step in identifying
potential billing or payment problems. It calls for identifying statistical
outliers within a well-defined peer group, and more sophisticated patterns within
individual claims or groups of claims that could indicate improper billing or
payment. CMS's guidance also identifies comparative utilization ratios by code,
Medicare Administrative Contractor jurisdiction, and specialty among the
analytic reports used in program-integrity work.
But why does this matter? It matters because a claim can appear
reasonable in by itself but also look unusual when viewed across thousands of
encounters. Think about it from this perspective. A physician group whose
evaluation and management (E&M) distribution is:
1.)
Materially higher than similar specialty peers,
2.)
Whose modifier use is unusually dense
3.)
Whose procedure volume rises rapidly without
a corresponding change in patient mix, staffing, sites of service, or referral
patterns
None of those observations automatically prove an error, but
together, they create a profile that can justify additional review.
CMS has also made it clear that aggregate analysis is
necessary. In many cases, fraud or abuse can be detected only by reviewing
cumulative claims and billing patterns whereas each individual claim may appear
legitimate when examined by itself. That is the core change in the audit
environment. Healthcare practices are increasingly evaluated as statistical
entities, not just as collections of discrete claims.
For Medicare, CMS's Data Analytics & Systems Group
states that its Fraud Prevention System[1]
uses machine learning to monitor and analyze Medicare fee-for-service activity
in support of Unified Program Integrity Contractors. CMS also provides its
program-integrity partners access to analytic tools and data repositories
designed to identify improper payments and measure results. The government's
use of these tools should not be overstated as proof that every claim decision
is AI-driven. It does, however, establish a direction of travel; these analytics
are being used to triage risk, find patterns, and target limited review
resources more efficiently.
Commercial payers are also responding to this same
operational reality. They process enormous volumes of claims, must manage
payment integrity at scale, and possess years of utilization, coding, network,
and prior-authorization data. Automation enables a payer to identify patterns
faster than a traditional audit cycle would permit. That does not mean
every payer uses the same model or applies AI the same way. It means that a
practice should assume its billing profile can be compared against historical
behavior, internal policy rules, and relevant peer cohorts more quickly than in
the past.
What Payer Analytics Are Measuring
Algorithmic claim reviews are not a single test. It is more
like a portfolio of signals that could be combined into a risk profile. The
precise methods are proprietary and vary by payer, product, geography,
specialty, and line of business. Still, the kinds of data points that matter
are familiar to experienced coding, compliance, and RCM teams.
One high-value signal is E&M distribution. If a
clinician or group bills a significantly greater proportion of high-level
office visits than comparable practitioners treating a similar population, that
does not establish upcoding. The practice may legitimately serve medically
complex patients. But it creates a question that documentation, coding policy,
patient-acuity data, and internal audit results should be able to answer. If
this sounds like your organization, I cannot stress the importance of thorough
and accurate documentation and data.
Modifier patterns are another common signal. Modifier 25,
for example, is appropriate when a significant, separately identifiable E&M
service is performed on the same date as a procedure or other service. However,
it is also susceptible to routine or unsupported use. A practice with a
materially higher modifier-25 rate than its peers may become a candidate for
focused review, especially if the underlying documentation does not
consistently establish the distinct E&M work.
Other relevant measurements can include:
- Procedure
and service code frequency by provider, location, and payer
- Units
billed per encounter, beneficiary, or day
- New
vs. established patient ratios
- Changes
in utilization after a provider joins, a location opens, or a coding
process changes
- Documentation
timing, completion patterns, and signature behavior
- Referral,
ordering, rendering, and supervising-provider relationships
- Specialty-specific
RVU production compared with applicable peer cohorts
- Denial,
appeal, and resubmission patterns by payer and code family
CMS's own program-integrity materials recognize this
approach. They reference comparative billing reports, peer-review reports,
focused medical review information, and analyses designed to identify potential
coding, coverage, and payment problems. CMS's PEPPER program[2]
provides another explanation of the basic concept by comparing
provider-specific Medicare data with national, jurisdictional, and state
benchmarks to identify target areas associated with potential improper payments
and to highlight areas for auditing and monitoring.
This practical lesson is important for all healthcare
providers to understand—Peer comparison is NOT itself an accusation. A
benchmark is a prompt for inquiry. It tells leadership where to ask
whether a pattern reflects legitimate clinical complexity, a documentation gap,
an operational workflow issue, a coding education need, or a potential
overpayment exposure.
The Numbers Behind the Trend
The most defensible evidence of a trend is not a claim that
every denial is generated by AI. Rather, it is the growing institutional
investment in data-driven payment integrity, machine learning, and faster
prior-authorization and claims workflows.
CMS has been building its program-integrity capabilities
around advanced analytics for years. In 2019, CMS described its exploration of AI
and machine learning to review compliance on more claims with less provider
burden and lower cost to taxpayers. CMS also emphasized advanced data analytics
as part of its broader strategy to stop improper payments before they
occur.[3]
More recently, CMS confirmed that the Fraud Prevention
System supports Unified Program Integrity Contractors with
machine-learning-enabled monitoring and analysis of Medicare fee-for-service
activity. CMS also announced the WISeR Model[4],
which is designed to test whether enhanced technologies (including AI) can
support a more efficient prior-authorization process for certain services in
Original Medicare while also safeguarding against wasteful or inappropriate
care.
At the same time, regulators are attempting to improve the
transparency of utilization-management decisions. CMS's Interoperability and
Prior Authorization Final Rule, CMS-0057-F[5],
requires impacted payers to provide a specific reason when they deny a
prior-authorization request. The relevant provisions apply beginning in 2026
for affected payers, including Medicare Advantage organizations, Medicaid, CHIP
fee-for-service programs, Medicaid managed-care plans, and qualified health
plan issuers on the federally facilitated exchanges.
The CMS-0057-F rule is significant for providers because a
usable denial reason improves the ability to correct a submission, resubmit an
authorization request, or pursue an appeal. It does not regulate every claim
denial or eliminate opaque automated processes, but it reflects a broader
policy concern; as payer decision-making becomes more automated and
data-driven, providers need clear and actionable information about why a
request was not approved.
There are also genuine governance concerns. The Office of
Inspector General (OIG) reported in 2026 that three of the largest Medicare
Advantage organizations had denied requests for certain long-term acute-care
hospital and inpatient rehabilitation facility services at some of the highest
rates[6].
The OIG then urged CMS to assess the
reasons for wide variation in denial and overturn rates across organizations
and contractors. The point is not that automated review is inherently improper.
It's that analytics can identify waste, reduce repetitive manual work, and
improve consistency when properly designed and overseen. It's as simple
as this: Healthcare practices need their own controls, evidence, and escalation
processes when a data-driven decision affects reimbursement or patient access.
Why Revenue at Risk Is Quantifiable
"Revenue at risk" often sounds like a vague compliance or
payment phrase, but it shouldn't be. In a modern revenue-cycle and compliance
program, revenue at risk is the estimated dollar value of claims, payments, or
future billing activity that may be vulnerable to denial, recoupment,
prepayment review, delayed payment, appeal cost, or corrective action because
one or more risk signals are present.
It is not the same as saying all flagged revenue is
improper. A well-designed model distinguishes between risk and error. It
quantifies exposure so leadership can decide what deserves attention first.
For example, a practice might classify current activity into
these three practical categories:
|
Risk Category |
What it Means |
Leadership Response |
|
High |
A material coding, documentation, utilization, or modifier
outlier exists; the relevant revenue is substantial; and available evidence
does not yet explain or support the pattern |
Prioritize targeted audit, claim validation, education,
and (where appropriate) repayment or corrective action |
|
Moderate |
A pattern differs from peers or historical norms but may
be explainable by patient mix, specialty, workflow, or payer policy |
Validate the explanation, expand sampling, monitor the
trend, and provide focused education |
|
Little to none |
Available data, documentation, and policy alignment
supports the billing pattern, and no meaningful outlier is present |
Continuing routine monitoring and retaining the evidence
supporting the conclusion |
A practical calculation might start with the dollars
associated with a flagged code family, modifier, provider, location, or payer
over a defined lookback period. The practice can then apply a defensible risk
factor based on internal audit findings. If 20 percent of sampled claims in a
high-risk category lack adequate support, the organization has a basis to
estimate potential exposure. As I've stated already, this is not to assume that
every claim is wrong, but to prioritize the category before an outside reviewer
does.
The financial framing changes the conversation. "Our
modifier use may be high" is a compliance observation. "We have $420,000 in
annualized reimbursement connected to a modifier pattern that has not been
validated against documentation and payer policy" is a leadership issue.
CFOs, owners, boards, compliance officers, and RCM directors can align around
that number because it connects coding behavior to a measurable financial
outcome.
The Case for Provider-Side Analytics
Payers and government contractors have always had data
advantages. They see broad claims populations, peer comparisons, trends across
networks, and historical payment patterns. But providers do not have to wait
passively for an audit letter to begin looking at their own data.
A defensive analytics program applies the same basic
discipline internally by:
- Establishing
the appropriate comparison group. Specialties, site(s) of service, payer
mixes, patient acuity, geography, and clinician roles all matter. A
pediatric subspecialist should not be measured against a general adult
primary care physician.
- Identifying
meaningful outliers. Reviewing E&M distributions, modifier densities,
procedure frequencies, units, RVUs, diagnosis-to-procedure relationships,
denial patterns, and sudden changes in behavior.
- Validating
with records—not statistics alone. An outlier may be justified but the justification
must be confirmed through targeted chart review, coding analysis, and
comparison to the applicable payer and Medicare requirements.
- Converting
findings into risk-ranked dollars. Link the issue to paid claims, pending
claims, or forecasted reimbursement so the practice can prioritize work
according to actual exposure.
- Correcting
the underlying process. Education is necessary but it is not always
sufficient. A reliable response may also require template changes, charge capture
controls, pre-bill edits, documentation workflow redesign, or
payer-specific coding guidance and training.
The goal is not to force every provider toward the
average. Medicine is not an average activity and legitimate variation
is inevitable. The goal is to ensure that a practice can explain and support
variation before a payer, CMS contractor, or auditor asks.
CMS's own use of comparative reports and provider-specific
data makes this approach especially sensible. PEPPER, for instance, is intended
to help providers compare patterns over time, identify possible overpayment and
underpayment areas, and pinpoint issues that may require auditing and
monitoring. Healthcare practices should build an analogous discipline across
their full payer mix rather than treating external scrutiny as something that
begins only with a formal record request.
How HCP's SENTRY Coding Intelligence Applies This Model
HCP's SENTRY Coding Intelligence is built around a simple
premise: the practice should understand its own billing risk before an
outside reviewer defines it.
Rather than treating coding compliance as a periodic,
organization-wide exercise, SENTRY can support a quarterly
analytics-to-audit-to-education cycle. It begins by examining utilization, RVU
patterns, E&M distribution, modifier density, and other specialty-relevant
measures at the provider and group level. The purpose is not to label every
deviation as a problem, but rather to identify where the practice's profile
differs enough from relevant expectations to justify a closer look.
Those findings can then be translated into a Revenue Risk
score that is meaningful for operations and finance:
- High
Revenue Risk: Significant dollars are associated with an outlier
pattern that needs prompt validation through targeted auditing and
documentation review.
- Moderate
Revenue Risk: A pattern warrants monitoring and selective review but
may be supported by clinical complexity, payer mix, or another legitimate
explanation.
- Little
to No Revenue Risk: The practice has evidence that its billing patterns
are appropriately supported and do not present a material current
exposure.
The value of this analysis is not merely the score. It is
the discipline behind it—Identifying patterns, testing them against records and
policy, quantifying the financial significance, educating the affected providers
and workforce members, and measuring whether the pattern changes. This process
is far more efficient than conducting broad and disruptive audits across every
provider and every code family at the same level of intensity.
SENTRY's model also supports a more productive leadership
conversation. Instead of asking coding, compliance, and RCM teams to report
every conceivable risk, it helps them identify the patterns that are both
statistically meaningful and financially consequential. Those are the
areas where a timely audit, targeted education, or workflow correction can
protect reimbursement and reduce the likelihood of a more disruptive and
stressful external review.
Conclusion and Next Steps
AI-enabled and analytics-driven payer oversight is changing
the practical meaning of audit readiness. A practice may no longer receive a
clear warning before its aggregate billing behavior becomes visible as a
potential outlier. The healthcare organizations best positioned to respond are
not the ones that assume every variance is wrong. They are the ones who can
identify, explain, document, and correct meaningful variation before it
becomes a problem.
Every practice leader should be able to answer a few essential
questions about their coding audit program:
- Which
providers, code families, modifiers, and payer relationships create the
largest potential exposure?
- How
does the practice's E&M, RVU, utilization, and modifier profile
compare with a similar specialty cohort?
- Which
unusual patterns are supported by documentation and clinical complexity,
and which have not been validated?
- What
dollar amount is connected to high, moderate, and low or no risk patterns?
- What
education, audit, charge-capture, or workflow controls are in place to
reduce this exposure over the next quarter?
A Revenue Risk Analysis turns those questions into a
structured, actionable view of the practice's current exposure. Request
a SENTRY Revenue Risk Analysis to see where your coding and utilization
patterns may deserve attention before payer analytics (or a CMS
contractor) find them!
Frequently Asked Questions
Are payers using AI to deny every claim?
No. Payer and government review processes vary, but not
every claim decision is made by AI. However, CMS has publicly described its use
of machine learning and advanced analytics in program-integrity activities,
including monitoring Medicare fee-for-service data and helping identify
potential improper-payment risk. The practical concern for practices is that
analytics can identify patterns and prioritize claims or providers for review
at a scale that manual processes cannot match.
What does "Revenue at Risk" mean in healthcare?
Revenue at Risk is the estimated reimbursement that could
be vulnerable to denial, recoupment, audit, payment delay, appeal costs, or
corrective action because a coding, documentation, utilization, or
billing-pattern risk exists. It is an exposure estimate, not a conclusion that
every identified claim was incorrectly billed.
Which billing patterns are most likely to attract
scrutiny?
Common examples include atypical E&M distributions,
unusually high modifier use, procedure or unit patterns that diverge from
relevant peers, abrupt changes in utilization, and documentation that does not consistently
support the billed service. CMS's guidance specifically recognizes the use of
statistical outlier analysis and comparative utilization data to identify
potential billing or payment issues.
Does being an outlier mean the practice has committed
fraud?
No. An outlier is a signal for further review, not
proof of wrongdoing. A legitimate explanation may include higher-acuity
patients, subspecialty practice, unusual referral patterns, a different
site-of-service mix, or an appropriate clinical workflow. The compliance task
is to validate the explanation with documentation, coding rules, and
targeted auditing.
What is CMS-0057-F, and why does it matter?
CMS-0057-F is CMS's Interoperability and Prior Authorization
Final Rule. Beginning in 2026, affected payers must provide a specific reason
when denying a prior-authorization request. This helps providers understand the
decision and (when appropriate) resubmit or appeal. It is an important
transparency measure though it does not eliminate the need for practices to
monitor their own claims and authorization patterns.
How can a practice reduce AI-driven audit risk?
Start with provider-side analytics, such as benchmark utilization and coding patterns against a similar provider/provider group, identify statistically meaningful outliers, conduct focused chart audits, quantify the associated revenue, and correct the underlying education or workflow issue. The objective is not to be like every other practice. It is to ensure that any meaningful variation is clinically appropriate, accurately coded, and well supported in the medical record.
[3] https://www.cms.gov/newsroom/press-releases/fiscal-year-fy-2019-medicare-fee-service-improper-payment-rate-lowest-2010-while-data-points