Running an Internal Billing Audit
An internal billing audit is the review a practice runs on its own claims before anyone else runs one on them. Instead of waiting for a payer's records request or a Medicare contractor's demand letter, the practice takes a sample of its own billing, compares each claim against the documentation and the rules behind it, and finds the errors while they are still corrections rather than findings. It is one of the most ordinary and most protective things a billing operation can do — the point where the abstract duty to bill accurately becomes a concrete, repeatable check. The work is not mysterious, but it is easy to do badly: an audit of the wrong claims, against the wrong standard, or with no follow-through, produces a comforting report and changes nothing.
Updated 17 min read
On this page
Key takeaways
- An internal billing audit is a practice auditing itself — a planned, documented review of a sample of its own claims, coding, and documentation — rather than waiting to be audited by a payer or a Medicare contractor. It is the compliance program's auditing-and-monitoring element in action.
- Monitoring and auditing are related but different. Monitoring is the ongoing checking built into daily work; an audit is a more formal, point-in-time review of a sample of claims against the records behind them, ideally performed by someone independent of the work being reviewed.
- A prospective (pre-bill) audit reviews claims before they are submitted, so an error is fixed before it ever reaches a payer; a retrospective (post-payment) audit reviews claims already paid, which can surface an overpayment the practice then has its own duty to return.
- Audit by risk, not at random. The claims worth reviewing are where the practice is most exposed — high-volume or high-dollar services, new codes or rules, modifier-heavy billing, and areas that have produced denials or that regulators have flagged.
- Measure a claim against what actually governs it: the documentation in the record, the code's own rules and edits, and the payer's coverage policy — not an invented benchmark or an industry “average,” which vary and do not decide any individual claim.
- A finding only matters if it is acted on. A good audit ends in a corrective action plan — root cause, the fix, who owns it, and a follow-up re-audit — and routes an identified overpayment to its return duty and any potential fraud to the compliance program and counsel.
What an internal billing audit is
An internal billing audit is a structured, planned review a practice performs on its own claims — pulling a sample, comparing each claim against the medical record and the rules that govern it, and recording what it finds. The word that matters is “internal”: this is the practice looking at its own work on purpose, as opposed to the Medicare contractor audits and payer reviews it may face from the outside. Both examine the same thing — whether a claim was accurate and supported — but an internal audit is the one a practice controls, schedules, and learns from before the stakes rise.
It sits inside the practice's compliance program, as the working end of the element that combines risk assessment, auditing, and monitoring. The compliance program is where a practice decides that it will look for problems on purpose; the internal billing audit is how it actually looks. That is why this is a compliance article and not only a coding one: the audit is a control, and its real product is not a score but the corrections and the changes it drives.
Monitoring and auditing are not the same activity
Why a practice audits its own billing
The plainest reason to audit is that it is far cheaper to find an error yourself than to have a payer find it. A claim caught before or shortly after it goes out is a correction; the same claim found in a post-payment audit two years later is an overpayment with interest, a demand letter, and a question about how many other claims look the same. But the deeper reason is about the standard a practice is held to when something goes wrong.
The False Claims Act does not require anyone to have intended to cheat. Its “knowing” standard reaches actual knowledge, but also deliberate ignorance and reckless disregard of whether a claim is true — with no proof of specific intent to defraud. That is exactly the posture an unaudited practice can drift into: a credible signal arrives — a run of identical denials, a coder's flagged concern, a rule that changed — and nothing looks at it. An internal audit is the opposite of that drift. It is the mechanism by which a practice investigates its own signals and writes down what it found, which is both the fix for the error and the record that the practice was not looking away.
Finding your own overpayment is a feature, not a failure
Prospective and retrospective audits
Internal audits split into two kinds by their timing relative to the claim, and the two do different jobs. Neither is a legal term — they are operational descriptions — but the distinction shapes what an audit can accomplish.
- Prospective (pre-bill) audit
- A prospective audit reviews claims before they are submitted. The reviewer checks the coding and documentation while the claim is still held, so an error is corrected before it ever reaches the payer and no incorrect claim — and no overpayment — is created. Its cost is speed: holding claims for review slows the cash a little. Its value is prevention, which is why it fits a new practice, a newly hired coder, a new service line, or any situation where the risk of a systematic error is highest and catching it before submission is worth the delay.
- Retrospective (post-payment) audit
- A retrospective audit reviews claims that have already been submitted and paid. Because the outcome is known, it can measure what actually happened — how the payer adjudicated the claim, whether the payment matched the documentation — and it is the only way to see patterns across a body of finished work. Its trade-off is the mirror of the prospective audit's: it cannot prevent the error it finds, and a finding may be an overpayment that now has to be returned. It is the standard tool for an established practice testing whether its billing is holding up.
Most practices use both, matched to risk. A prospective audit guards the areas where an unspotted error would be systematic and expensive; a retrospective audit periodically tests the rest of the book to confirm it is sound and to catch what monitoring missed. The choice is not ideological — it is about whether the greater value, for a given kind of claim, is preventing the error or measuring it.
Deciding what to audit: risk, not random
The most common way to waste an audit is to pull claims at random. A random sample of a whole practice's billing tells you a little about everything and not enough about anything, and it spends the scarce hours of a qualified reviewer on claims that were never likely to be wrong. A useful internal audit starts from risk: it looks where the practice is most exposed, because that is where an error is both most likely and most costly.
Two sources tell a practice where its risk is. The first is its own data — the services it bills most often, the highest-dollar codes, the areas that generate denials or appeals, the modifiers it uses heavily, and anything that recently changed: a new provider, a new code, a new payer policy, a new service line. The second is the risk areas others have already identified and published, which a practice can map onto its own billing.
- Your highest-volume and highest-dollar services. An error repeated across a common service, or sitting inside a large payment, is where the exposure concentrates — a small mistake multiplied by volume, or a single large claim that does not hold up.
- Anything new. New codes, new coverage rules, a newly hired coder or provider, and a new service line are where errors cluster, because the practice has the least experience billing them correctly.
- Your own denial and appeal patterns. A code or a payer that keeps generating denials is telling the practice where its claims are already failing a check — the cheapest risk assessment there is.
- Modifier-heavy and medical-necessity-dependent billing. Services whose payment turns on a modifier, on documentation of medical necessity, or on the difference between two levels are where the record and the claim most often drift apart.
- Published risk areas. The government publishes where it is looking. The HHS Office of Inspector General's Work Plan, the results of the Medicare error-rate programs, and the topics external auditors are pursuing are all signals a practice can use to audit the same areas on its own terms first.
The audit's scope is a risk decision, and it should be written down
Auditing against the right standard
Once the claims are chosen, an audit is only as good as the standard it measures them against — and this is where a practice must resist the pull of invented benchmarks. A claim is not “correct” because it matches an industry average, a peer's rate, or a number from a webinar. It is correct because it reflects what was documented and what the rules that govern it require. The standard is specific to each claim, and the reviewer's job is to find it, not to assume it.
The documentation in the record
The first and most important comparison is between the claim and the medical record behind it. Did the service billed actually happen, and does the documentation support the code, the units, and the level billed? A claim that outruns its documentation is the single most common finding, and the record — not the claim — is the source of truth.The code's own rules and edits
Codes carry rules about how they may be reported together, whether one is bundled into another, and what an add-on requires. National correct-coding edits and medically-unlikely-edit limits are published and knowable; auditing against them catches the unbundling and the impossible unit counts that an external review would flag.The payer's coverage and medical policy
Whether a service was covered and reasonable and necessary is answered by the payer's own coverage policy — a Medicare national or local coverage determination, or a commercial payer's published medical policy — not by the practice's assumption. The applicable policy is found in the payer's own materials and the provider manual, and it is where a medical-necessity question is actually decided.
There is no universal “right number” — find the one that applies
How much, how often, and who performs it
The question a practice asks first — how many claims, how often — is the one with no universal answer, and being honest about that is part of doing it well. There is no legally required sample size or audit schedule for a physician practice's internal review. The Office of Inspector General's compliance guidance is voluntary and deliberately non-prescriptive: it describes auditing and monitoring as something an effective program does and expects it to be scaled to the practice, rather than fixing a number every practice must hit. Where older OIG guidance offered a small baseline sample, it did so as an example of a starting point in voluntary guidance, not as a mandate.
What a practice can hold onto instead is a defensible method. A common and sound approach is a baseline audit that establishes where the practice stands, followed by periodic audits that test whether it is staying there and re-check the areas a baseline flagged. The size and frequency follow the risk: a high-risk or newly changed area is audited more, and more often, than a stable one. And if a practice ever projects the results of a sample across a larger body of claims — to estimate a total rather than review every claim — that projection is not a guess; statistical sampling and extrapolation have a defined methodology, and a defensible internal estimate follows it rather than inventing a figure.
Independence is what makes the result trustworthy
Acting on what you find
An audit that produces a report and nothing else is worse than no audit, because it creates a record that the practice knew about a problem and did not fix it. The value of the whole exercise is in the follow-through, and the follow-through has a name: a corrective action plan.
A corrective action plan turns a finding into a change. It names the problem and — this is the part that matters — its root cause, because fixing the one claim without fixing the training gap, the unclear policy, or the system default that produced it just means the error returns under a new claim number. It records the specific fix, who owns it and by when, and a follow-up re-audit to confirm the correction held. Writing it down is not bureaucracy; it is how the fix actually happens and how the practice shows it took its own finding seriously.
Some findings carry their own downstream duties, and the plan is where those get sequenced rather than forgotten.
- An identified overpayment gets returned. If the audit finds the practice was overpaid, returning the money on time is part of the corrective action, under the 60-day overpayment rule — not a separate task to get to later.
- A potential-fraud finding leaves the billing desk. If a finding suggests something beyond error — a pattern that looks intentional, a possible kickback, conduct that could be a false claim — it goes to the compliance program and counsel, and the OIG Self-Disclosure Protocol may be the route to resolve it. A practice that comes forward promptly and cooperates is treated more favorably than one that is caught, which is one more reason to audit and disclose rather than wait.
- The person who raised it is protected. Findings often start with a staff concern. Treating the person who surfaced it as an asset, not a threat, is both right and practical — the False Claims Act protects whistleblowers from retaliation, and a concern handled internally is a case that never has to be filed.
What a billing operation should actually do
An internal audit program does not have to be elaborate to work. It has to be real, risk-based, and followed through — a few disciplined habits repeated on a schedule.
Decide what to audit from your own risk
Start from the practice's highest-volume and highest-dollar services, its denial patterns, its recently changed billing, and the areas regulators have published as risks — and write down why each was chosen. Auditing your risk areas, and being able to show you did, is the point.Measure each claim against its real standard
Compare the claim to the documentation, the coding rules and edits, and the payer's coverage policy — not to an industry average or a target number. The standard is specific to the claim, and finding it is the reviewer's job.Use a defensible method and an independent reviewer
Set a sample and a cadence proportionate to the risk, keep them consistent, and document them; have someone a step removed from the work perform the review. Route a sensitive audit through counsel from the start.Turn every finding into a corrective action plan
Fix the root cause, not just the claim; assign an owner and a date; re-audit to confirm it held; return any identified overpayment on time; and escalate anything that looks like more than an error to the compliance program and counsel.
Done this way, an internal billing audit is not an event a practice dreads but a habit that quietly lowers its risk across the whole of compliance and regulations — the routine by which ordinary billing errors get caught and corrected before anyone outside the practice ever has cause to look.
Educational, not legal advice
Common questions
What is an internal billing audit?
It is a practice's own planned review of a sample of its claims, coding, and documentation — the practice auditing itself, rather than waiting to be audited by a payer or a Medicare contractor. The reviewer compares each claim against the medical record and the rules that govern it and records what they find, so errors are caught while they are still corrections. It is the working end of a compliance program's auditing-and-monitoring element.
What is the difference between a prospective and a retrospective audit?
Timing. A prospective (pre-bill) audit reviews claims before they are submitted, so an error is fixed before it reaches the payer and no incorrect claim is created — it prevents. A retrospective (post-payment) audit reviews claims that have already been paid, so it can measure what actually happened and spot patterns across finished work — but it cannot prevent the error it finds, and a finding may be an overpayment the practice then has to return. Most practices use both, matched to where the risk is.
How many claims should we audit, and how often?
There is no universal number. No law fixes a required sample size or audit schedule for a practice's internal review, and OIG's compliance guidance is voluntary and deliberately non-prescriptive — it expects auditing to be scaled to the practice rather than set at a fixed figure. A sound approach is a baseline audit to establish where the practice stands, then periodic audits sized and timed to the risk of each area, using a consistent, documented method. If results are ever projected across a larger set of claims, that uses a defined statistical methodology, not a made-up number. This article does not state a specific figure for that reason.
What do we do if an internal audit finds an overpayment?
Return it, on time, as part of the corrective action — do not set it aside. A retained, identified overpayment is what turns an accounting error into exposure, so an audit that finds one and returns it under the 60-day overpayment rule is the audit working as intended. Document what was found, correct the root cause so it does not recur, and if the overpayment is tied to something that looks like more than an error, involve the compliance program and counsel before acting.
Who should perform an internal billing audit?
Someone a step removed from the work being reviewed, and qualified to read the documentation and the coding rules — a different coder, a dedicated internal auditor, or an outside firm. A person auditing their own claims tends to repeat the reasoning that produced the error. For a sensitive audit, where the findings might implicate potential fraud, many practices run the audit through counsel from the outset so the work is protected and the response is planned. Independence is what makes the result trustworthy.
Key terms in this article
Defined once, on their own pages.
Continue learning
The program the audit belongs to, the outside audits it gets ahead of, and the duties a finding can trigger.
The Seven Elements of an Effective Compliance Program
Where auditing and monitoring live as one of the seven elements — the program that decides a practice will look for problems on purpose, of which the internal audit is the working end.
The Types of Medicare Audits
The audits a practice faces from CMS's contractors — MAC review and TPE, the Recovery Audit program, CERT, UPICs, and the SMRC — the outside reviews an internal audit is meant to get ahead of.
The 60-Day Overpayment Rule
The duty an internal audit can trigger: an identified overpayment must be reported and returned by its deadline, or a retained overpayment becomes a False Claims Act obligation.
The False Claims Act in Medical Billing
The statute whose “knowing” standard reaches reckless disregard and deliberate ignorance — the reason acting on a credible signal, rather than looking away, is what an audit is for.
Authoritative sources
- HHS Office of Inspector General — General Compliance Program Guidance (November 2023) (opens in a new tab)
U.S. Department of Health and Human Services, Office of Inspector General. OIG's consolidated, voluntary guidance describing the elements of an effective compliance program, including risk assessment, auditing, and monitoring, and responding to detected problems with corrective action — framed as non-binding and expected to be scaled to the size and resources of the entity rather than prescribing a fixed audit size or schedule.
- HHS OIG — Compliance Program Guidance for Individual and Small Group Physician Practices, 65 FR 59434 (Oct. 5, 2000) (opens in a new tab)
U.S. Department of Health and Human Services, Office of Inspector General. The physician-practice compliance guidance describing auditing and monitoring, including a baseline audit to establish a starting point followed by periodic audits, and the review of claims and coding against the documentation — presented as voluntary guidance and examples, not mandates.
- 42 U.S.C. § 1320a-7k(d) — Reporting and returning of overpayments (opens in a new tab)
The requirement that a person who has received an overpayment report and return it by the later of 60 days after the overpayment was identified or the date a corresponding cost report is due, and that an overpayment retained after that deadline is an “obligation” for purposes of the civil False Claims Act — the duty an internal audit's finding can trigger.
- 31 U.S.C. § 3729(b)(1) — False Claims Act; “knowing” and “knowingly” (opens in a new tab)
The civil False Claims Act's definition of the knowing standard: actual knowledge, deliberate ignorance of the truth or falsity of the information, or reckless disregard of it — and no proof of specific intent to defraud — which is why investigating and acting on a credible billing signal, rather than ignoring it, is what an internal audit is for.
- 42 U.S.C. § 1395ddd(f)(3) — Statistical sampling and extrapolation (opens in a new tab)
The Medicare statute limiting when a contractor may use extrapolation to determine an overpayment; together with the CMS Program Integrity Manual, it reflects that statistical sampling and projection follow a defined methodology — support for the point that a practice's own audit estimate should rest on a defensible method rather than an invented number.
