← Back to blog

First 72 Hours That Win Audits: Audit Readiness Steps for Small Practices

September 29, 2026
First 72 Hours That Win Audits: Audit Readiness Steps for Small Practices

The moment a records request lands, five actions determine everything that follows: assign a coordinator, preserve the original records, pull a sample of claims and reconcile each one against the chart, build a claim crosswalk for the submission package, and hit the deadline. Practices that treat OIG's compliance-program model as a continuous habit, not a fire drill, walk into an audit with proof already in hand.


TL;DR:

  • Practices should assign a single audit coordinator and maintain a detailed log to respond swiftly and accurately to records requests within 72 hours.
  • Sampling claims should include both random and risk-based selections, with reconciliation focused on codes, modifiers, signatures, and supporting documentation.
  • Organize submission packages with a clear crosswalk, ordered by request, and keep records legible and secure to avoid delays or penalties.
  • Regularly run internal audits with measurable benchmarks and follow-up sampling to identify and fix vulnerabilities before an external review occurs.
  • Most audit risks stem from small process gaps, such as unclear ownership and inadequate record preservation, rather than complex coding disputes.

Himshield
Strengthen Your Audit Readiness
HIMShield identifies coding, documentation, and charge capture risks before they become denials or audits, with clear guidance for practices.
Explore HIMShield

Table of Contents

Quick step-by-step audit readiness checklist

You don't need a compliance department to get audit-ready. You need a short list, executed in order, with someone accountable for each line.

  1. Name one audit coordinator and write down who backs them up when they're out.
  2. Preserve original records the moment a request or internal flag appears, and log who touched them and when.
  3. Pick a sampling plan, mixing random claims with risk-based picks from your highest-denial code families.
  4. Reconcile each sampled claim against the chart: codes, modifiers, units, signatures, and orders.
  5. Sort findings into exception categories (documentation gap, coding error, charge-capture miss) and assign a fix and a due date to each.
  6. Put the next review on the calendar before you close this one out.

Skipping the calendar step is the most common failure. A one-time review protects you for a quarter. A scheduled cadence, tied to the physician practice audit survival checklist most practices already use informally, protects you year over year.

Pro Tip: Keep a single spreadsheet with request date, due date, coordinator, and status for every open item. It turns a scramble into a five-minute status check.

Assigning governance: OIG's seven components in a small practice

OIG built its compliance framework for organizations of every size, but a five-physician practice can't staff seven committees. It can assign seven owners.

  • Written standards and policies: one short document per high-risk area (coding, documentation, billing), owned by the administrator.
  • Compliance contact: a single named person, often the administrator, who fields questions and escalations.
  • Training: a recurring session, even 30 minutes quarterly, tied to your own audit findings.
  • Internal monitoring and auditing: the sampling routine described above, run on a fixed schedule.
  • Response and corrective action: a documented fix for every exception, with a follow-up date.
  • Open communication: a way for staff to flag concerns without fear of blame.
  • Disciplinary standards: a written, evenly applied consequence for repeat or willful errors.

Reviewers look for evidence these components exist on paper, not just in intention. A folder of monitoring logs, training sign-in sheets, and closed corrective-action items does more to demonstrate an effective compliance program than any policy statement alone.

Sampling and chart reconciliation: pick claims, test them against the record

A good sample catches problems before a payer does. Mix random selection, which protects against blind spots, with risk-based targeting aimed at your highest-volume codes, newest providers, or recent denial trends.

  • Pull claims across providers, payers, and code families rather than clustering on one physician.
  • Check medical necessity, CPT and ICD selection, modifiers, units billed, signatures, and supporting orders against the chart.
  • Confirm the charge capture matches what was actually documented and performed.
  • Log every exception with a severity rating, from a minor documentation gap to a coding error that changes reimbursement.

Contractors reviewing Medicare claims commonly use probe samples of roughly 20 to 40 claims to decide whether a provider-specific problem exists before scaling up. Running your own sample at a similar size gives you an early read on what a contractor would find, using the same logic they apply. For documentation examples that hold up under this kind of scrutiny, the medical necessity documentation guide walks through what a reconciled chart should look like.

Responding to a records request: the first 72 hours matter most

The first response shapes everything that follows. A slow or disorganized reply reads as a red flag even when the underlying claims are clean.

  1. Acknowledge receipt in writing immediately, and log the request type, date received, and due date.
  2. Preserve the original records and assign your coordinator to own the response from start to finish.
  3. Map every requested item to a claim ID, date of service, provider, and source system before you touch the response.
  4. Request an extension early if you need more time. Waiting until the deadline is close makes the ask look evasive.
  5. Loop in the treating physician, a coder, and legal counsel when the dollar exposure or pattern of findings is material.

Pro Tip: Never edit the original record to fix a gap once a request has arrived. Add a dated addendum through your EHR's amendment process instead, so the original entry and the audit trail both stay intact.

Medicare response windows vary by contractor and request type, and CMS guidance commonly gives around 45 days for many MAC and RAC requests. Missing that window can turn a routine review into an automatic denial. The step-by-step record request response breaks this protocol down further for practices building it for the first time.

Assembling the submission package: crosswalk, order, and proof of transmission

A reviewer moves faster through an organized package, and a faster review tends to go better for the practice that sent it.

  • Build a claim crosswalk that maps each requested field (claim ID, date of service, code, modifier) to its location in the submitted documents.
  • Order the package to match the request itself, not your internal filing system.
  • Keep every page legible, and redact only what the request specifically permits.
  • Submit electronically where the payer allows it, and save the transmission confirmation with a timestamp.
  • Keep a copy of the full package and a chain-of-custody log showing who assembled and sent it.

The Medicare record maintenance guidance warns that failing to produce requested records on time can put Medicare enrollment itself at risk, which is reason enough to treat the crosswalk step as non-negotiable rather than optional polish.

Appeals strategy: when to push back and what to cite

Not every adverse finding deserves an appeal. Decide first whether the dollar value and the strength of your evidence justify the administrative cost.

  • Cite the payer contract's own language, CPT coding guidance, applicable CMS guidance, and the medical record itself, not just your disagreement with the outcome.
  • Skip the appeal when the finding is accurate and the record genuinely doesn't support the original claim.
  • Resubmit the complete record with a short cover sheet pointing directly to the evidence the reviewer missed.
  • Calendar every appeal deadline the moment a determination arrives, since most windows are short and non-negotiable.

Payer audits sometimes extrapolate a small sample of errors into a much larger recoupment demand, which is why the AMA's appeals guidance recommends building appeals around the same complete, well-indexed package used in the original response. The overpayment demand response guide covers the follow-up steps once a determination is final.

Continuous monitoring: turning readiness into routine

A single clean audit doesn't prove much. A pattern of clean audits does.

  • Run a baseline audit now, even if no request has arrived, so you know where you stand before a payer tells you.
  • Set measurable benchmarks (denial rate, documentation gap rate) and track them over time.
  • Schedule follow-up sampling after every corrective action to confirm the fix actually worked, not just that it was written down.
  • Tie training directly to what your own audits find, and keep a change log of policies and their outcomes.

Pro Tip: Retest the exact issue you corrected within 60 to 90 days. A corrective action that isn't verified is just a promise.

The annual coding review guide and the benchmark audit explainer both walk through how to set a cadence that fits a small practice's staffing, without turning compliance into a full-time job for someone who already has one.

What administrators consistently get wrong

What administrators consistently get wrong — overview diagram

Most audit exposure doesn't come from complex coding disputes. It comes from small, repeatable process gaps: no single owner for the response, records that get touched before anyone thinks to preserve them, or a sample that's too small to mean anything. Fixing those three things protects a practice more than any amount of policy language.

The payer audit preparation guide and the risk-based audit explainer both come out of the same operational lens this article uses: what actually reduces exposure, not what looks thorough on paper. Practices that want a second set of eyes on their current exposure don't need to wait for a request to arrive before finding out where they stand.

— Elena

How HIMShield helps you get audit-ready without adding staff

Building the checklist above by hand takes time most administrators don't have between patient scheduling and billing follow-up. HIMShield's free 30-day Revenue Leakage Audit does the sampling and reconciliation work for you, scanning your EHR data to quantify coding, documentation, and charge-capture gaps by provider and payer before a payer ever asks for a chart.

Himshield

  • Get a per-provider, per-payer report showing exactly where reimbursement is at risk.
  • Receive automated compliance alerts and one-click physician e-signature on corrections, with no new software training required.
  • Move into ongoing audit defense support once the initial audit identifies your exposure.

The audit is free for 30 days. Start with the Revenue Leakage Audit or visit HIMShield to see how the compliance engagement works for practices your size.

Sources

These are the primary sources behind the steps above: OIG's compliance guidance for governance, CMS's PIM transmittal for probe sampling and deadlines, CMS's record maintenance guidance for record access rules, and the AMA's payor audit checklist for response and appeal protocol.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

FAQ

What are the first steps to take when an audit notice arrives?

Assign a single coordinator, preserve the original records without editing them, and log the request date and deadline immediately. Map every requested item to its claim ID and date of service before you begin assembling a response, following the same protocol in CMS's medical record guidance.

How many claims should a small practice sample during a self-audit?

There's no single fixed number, but Medicare contractors commonly use probe samples of roughly 20 to 40 claims to test for provider-specific problems before expanding a review. Running an internal sample at a similar size gives a practice an early, comparable read on its own exposure.

Can I correct an error in the medical record before submitting it?

You should never alter the original entry. Add a dated addendum through your EHR's amendment process so the original record and its audit trail stay intact, since backdated or unsigned changes can trigger a separate fraud inquiry.

When should a practice appeal a payer's audit finding instead of accepting it?

Appeal when the record genuinely supports the original claim and the dollar value justifies the administrative effort, citing the payer contract, CPT guidance, and CMS rules alongside the record itself. Skip the appeal when the finding is accurate, since AMA guidance recommends weighing cost against the strength of the evidence before filing.

How often should a practice run its own compliance audit?

A baseline audit followed by scheduled follow-up sampling, often quarterly or tied to your highest-risk code families, works for most independent practices. The cadence matters more than the exact frequency, since OIG's model treats monitoring as continuous rather than a once-a-year event.