Medical groups encounter two broad categories of HIM audits: internal audits driven by your own compliance and quality programs, and external audits initiated by government agencies or commercial payers. Within those two categories, the specific audit types include coding and billing audits, clinical documentation improvement (CDI) audits, quantitative and qualitative record reviews, chart abstraction audits, privacy and security audits, and quality improvement audits tied to programs such as MACRA and HEDIS. Government programs alone span RAC, TPE, UPIC, and CERT audits, each with distinct scopes and recoupment authority. Understanding where each type fits, what triggers it, and how to respond is the foundation of any credible compliance program.
Here is a quick-reference breakdown of the main categories:
- Internal audits: Quantitative, qualitative, clinical, coding/billing, CDI, concurrent, retrospective
- External government audits: RAC, TPE, UPIC, CERT, Medicare, Medicaid
- Commercial payer audits: Triggered by billing irregularities; focused on coding accuracy and medical necessity
- Quality improvement audits: MACRA performance measures, HEDIS data validation
- Privacy and security audits: HIPAA Privacy Rule, Security Rule, Breach Notification Rule compliance
Each type carries different objectives: compliance verification, financial accuracy, care quality, or data privacy. Audit outcomes range from corrective education plans to significant recoupments.
Table of Contents
- 1. What external government audits mean for your medical group
- 2. How commercial payer audits differ from government reviews
- 3. Internal HIM audits and quality improvement in medical groups
- 4. How audit sampling methodology affects your results
- 5. What chart abstraction audits actually review
- Protect your revenue before the next audit finds you first
- Key Takeaways
1. What external government audits mean for your medical group
Government audits are the highest-stakes category for most medical groups. They are initiated by CMS, HHS-OIG, or their contractors, and they carry real recoupment authority. Understanding each program helps you prioritize where your documentation must be airtight.
The four primary federal audit programs are:
- Recovery Audit Contractors (RAC): RAC auditors review paid Medicare claims for improper payments, both overpayments and underpayments. They work on contingency, so they are motivated to find errors. Common targets include high-dollar DRGs, evaluation and management (E/M) upcoding, and medical necessity gaps.
- Targeted Probe and Educate (TPE): CMS Medicare Administrative Contractors (MACs) run TPE reviews, selecting providers with aberrant billing patterns for focused record review. Up to three rounds of review occur before escalation, with education offered between rounds.
- Unified Program Integrity Contractors (UPIC): UPICs investigate fraud, waste, and abuse across Medicare and Medicaid simultaneously. Their scope is broader than RAC, and referrals can escalate to HHS-OIG investigations.
- Comprehensive Error Rate Testing (CERT): CERT measures the Medicare fee-for-service improper payment rate by reviewing a statistically valid random sample of claims. A CERT finding does not automatically trigger recoupment, but it informs MAC and RAC targeting.
Medicaid audits add another layer. State Medicaid agencies and their contractors conduct their own reviews, often mirroring CMS frameworks but with state-specific coverage policies that create additional documentation requirements.
Common triggers across all government audit types include:
- Billing rates significantly above specialty peers
- High frequency of the same CPT code across encounters
- Missing or incomplete medical necessity documentation
- Patterns of modifier misuse (e.g., modifier 25 or 59)
- Claims for services not supported by the documented diagnosis
Non-compliance consequences range from claim-level recoupments to prepayment review holds and, in UPIC cases, potential exclusion from federal programs. HHS-OIG's General Compliance Program Guidance emphasizes that corrective action plans must include follow-up monitoring, not just a one-time fix.
2. How commercial payer audits differ from government reviews
Commercial payer audits share the same surface-level focus as government audits, but the rules of engagement are different. Payers like UnitedHealthcare, Aetna, and BCBS each maintain their own audit protocols, appeal timelines, and coverage policies, which means a documentation standard that satisfies Medicare may not satisfy a commercial contract.
Commercial audits are typically triggered by:
- Billing patterns that deviate from peer norms in the payer's own data
- High denial rates followed by successful appeals (a signal that claims are being pushed through)
- Specific CPT codes flagged under the payer's internal edit logic
- Credentialing or contract compliance reviews
The audit focus lands on three areas: coding accuracy (are CPT and ICD-10 codes supported by documentation?), medical necessity (does the clinical record justify the service?), and documentation completeness (are all required elements present per the payer's coverage policy?).
One practical difference from government audits: commercial payer appeal processes are governed by your contract, not federal regulation. Appeal windows are often shorter, and the burden of proof rests entirely on your documentation. Preparing for a payer audit means having clean, complete records before the request arrives, not assembling them after.
Best practices for commercial audit readiness:
- Maintain payer-specific coverage policy files and update them when contracts renew
- Flag high-volume CPT codes for periodic internal review against each payer's LCD equivalent
- Document medical necessity in the body of the note, not just in the diagnosis field
- Track denial patterns by payer to identify coding or documentation gaps early
3. Internal HIM audits and quality improvement in medical groups
Internal audits are your first line of defense. They catch coding and documentation problems before an external auditor does, and they generate the data your compliance program needs to improve. The audit process in healthcare at the internal level breaks into several distinct types.
Quantitative audits check for the presence of required documentation elements: signatures, dates, authentication, and completeness of each record section. Qualitative audits go deeper, assessing whether the content actually supports the diagnosis, treatment plan, and billed services. Both are necessary; one without the other leaves blind spots.

Concurrent audits review records while the patient is still receiving care, allowing real-time corrections. Retrospective audits review closed records, which is the more common approach in outpatient medical groups. Clinical audits evaluate whether care delivered meets established clinical standards, while coding audits focus specifically on CPT, ICD-10, and HCPCS accuracy.
CDI audits deserve their own mention. Clinical documentation improvement reviews target the gap between what a provider documents and what the coding staff can accurately capture. A CDI audit often reveals that a physician's note supports a higher-specificity diagnosis code that was never assigned, leaving reimbursement on the table.
Internal audit team structure matters. Multidisciplinary teams that include providers as subject matter experts produce more credible findings and get better provider buy-in during education sessions. A coder reviewing records in isolation misses the clinical context that only a provider can validate.
Quality improvement audits tied to MACRA and HEDIS extend beyond billing. MACRA's Merit-based Incentive Payment System (MIPS) tracks performance measures that directly affect your Medicare payment adjustments. HEDIS audits validate the clinical data submitted to health plans for quality ratings. Both require accurate, complete documentation at the point of care.
Recommended internal audit cycle:
- Conduct quarterly record reviews across all E/M service levels
- Pull a minimum of three records per provider per service category, expanding the sample and triggering improvement plans if discrepancies affect one-third or more of records, with a 60-day follow-up period.
4. How audit sampling methodology affects your results
Sampling strategy determines whether your audit findings are actionable or misleading. Two approaches dominate: random sampling and targeted (risk-based) sampling.
Random sampling gives you a statistically representative picture of your coding accuracy across all records. It is useful for baseline assessments and annual compliance reporting. Targeted sampling, by contrast, uses existing system data — DRG accuracy reports, length-of-stay norms, financial edit flags — to pre-select high-risk records. Targeted sampling uncovers problematic patterns faster and uses fewer resources than pulling records at random.

The audit methodology you choose also shapes the numbers you report. The per-code method evaluates each individual code assignment, so a record with five codes and one error scores 80% accuracy. The per-record method counts any reimbursement error as a full record failure, producing a stricter accuracy rate. Per-record audits tend to yield lower accuracy scores and drive more aggressive corrective action, which is why your choice of method should be documented and consistently applied.
| Sampling Method | Best Use Case | Limitation |
|---|---|---|
| Random | Baseline compliance assessment | May miss concentrated risk areas |
| Targeted/Risk-based | High-risk code or provider review | Requires reliable source data |
| Concurrent | Real-time CDI correction | Resource-intensive |
| Retrospective | Closed-record compliance review | Cannot correct already-billed claims |
Pro Tip: Use your EHR's built-in reporting to generate a DRG accuracy or E/M distribution report before selecting your audit sample. Records that fall outside expected norms for your specialty are your highest-value targets.
Continuous auditing integrated into your compliance program, rather than treated as an annual event, reduces external audit risk and builds a documented track record of proactive self-correction. That track record carries weight if you ever face a government audit.
For healthcare labs, the same principle applies: lab compliance audits benefit from continuous monitoring frameworks that mirror the best practices used in physician group HIM programs.
5. What chart abstraction audits actually review
Chart abstraction audits extract specific data elements from clinical records to evaluate care quality, coding accuracy, or regulatory compliance. They are distinct from standard coding audits because the focus is on pulling structured data points from unstructured documentation, not just verifying that a code matches a diagnosis.
In a medical group context, chart abstraction is most commonly used for HEDIS measure validation, risk adjustment accuracy under Medicare Advantage, and clinical quality reporting. An abstractor reviews the full clinical record and pulls discrete data: dates of service, diagnoses confirmed during the encounter, lab values, medication lists, and documented clinical decisions. The accuracy of that abstraction directly affects your quality scores and, in risk adjustment programs, your reimbursement.
Common abstraction targets include:
- HCC (Hierarchical Condition Category) validation: Confirming that chronic conditions documented in the record are coded and submitted for risk adjustment
- Preventive care measure compliance: Verifying that screenings, immunizations, and counseling documented in the chart are captured in quality reporting
- Clinical decision support adherence: Checking whether documented treatment decisions align with evidence-based guidelines
Chart abstraction audits require abstractors with both clinical knowledge and coding expertise. An abstractor who misreads a clinical note can either inflate or deflate your quality scores, with direct financial consequences under value-based contracts. Regular chart audit workflows that include abstraction quality checks are a practical safeguard.
Protect your revenue before the next audit finds you first
Most medical groups discover coding and documentation gaps only after a payer requests records or a RAC audit lands in the inbox. Himshield flips that sequence.

Himshield scans your existing EHR data to identify coding risks, documentation gaps, and charge-capture misses before they become denials or audit findings. The platform flags HCC gaps, E/M level inconsistencies, and missing medical necessity documentation, then delivers physician-friendly guidance your providers can act on immediately. No waiting for an annual coding review. No scrambling to reconstruct documentation after a TPE request arrives.
Independent practices using Himshield recover significant amounts in at-risk reimbursement by catching what manual spot-checks miss. If you are managing HIM compliance for a medical group and want a continuous audit defense rather than a reactive one, see how Himshield works and connect your EHR today.
Key Takeaways
Medical groups face a layered audit environment where internal proactive reviews are the most effective defense against external government and payer audits.
| Point | Details |
|---|---|
| Internal vs. external audits | Internal audits catch coding and documentation gaps before government or payer auditors do. |
| Government audit programs | RAC, TPE, UPIC, and CERT each have distinct scopes; non-compliance can trigger recoupments or exclusion. |
| Sampling methodology matters | Per-record audits produce stricter accuracy rates than per-code methods; document your chosen approach consistently. |
| Continuous auditing reduces risk | Conducting quarterly record reviews with a minimum three-record baseline and 60-day corrective action follow-up demonstrates ongoing compliance monitoring. |
| Himshield for proactive defense | Himshield identifies coding, documentation, and charge-capture risks before they become denials or audit findings. |
