In 2025, external payer audit activity accelerated sharply: at-risk amounts and audit cases per customer rose 30%, the average amount at risk per claim increased 18%, and outpatient coding-related denials climbed 26% year over year after a 126% spike the prior year. Those figures, reported by ICD10monitor on payer audit activity, change the operating question for specialty groups. Medical coding audits aren't occasional chart reviews that happen after a problem appears. They're part of a continuous revenue protection operation that connects documentation, claim quality, payer behavior, underpayment recovery, and, where applicable, No Surprises Act Independent Dispute Resolution.
Why Medical Coding Audits Changed in 2026
The old audit model was retrospective. A compliance team selected charts, reviewed codes, issued findings, and assigned education. That model still has value, but it doesn't match a payer environment built around recurring requests, automated claim edits, targeted denials, and small, repeated reviews of specific code families or specialties.
The 2025 data points to a more persistent operating burden. External payer audit activity rose sharply, with total at-risk amounts and audit cases per customer up 30% and the average amount at risk per claim up 18%. At the same time, outpatient coding-related denials increased 26% year over year, following a 126% spike the prior year. These figures come from ICD10monitor's report on accelerating payer audits.

The specialty impact
Anesthesia, ambulatory surgery centers, imaging, and multi-specialty platforms are particularly exposed because their claims combine technical rules, procedure-specific documentation, payer variation, and frequent outpatient volume. A retrospective sample may identify a pattern, but it won't stop the next claim from carrying the same vulnerability.
The practical response is continuous micro-auditing. Instead of waiting for a quarterly or annual review, teams monitor high-risk services, payer-specific edits, provider-level variation, documentation gaps, and denial patterns as operating signals. A flagged trend should trigger a focused review, a provider or coder intervention, and a follow-up check that confirms whether the correction held.
Operational rule: Treat each payer request as intelligence about the next audit, not as an isolated administrative task.
This approach also changes ownership. Coding, clinical documentation improvement, billing, denial management, contracting, and legal or dispute-resolution teams need a shared view of risk. A code that looks accurate in isolation may still produce a denial if the note doesn't support medical necessity, the claim lacks required detail, or the payer repeatedly interprets the service differently.
What Medical Coding Audits Actually Do
A medical coding audit functions like a continuous inspection line. Claims enter with clinical documentation, code assignments, modifiers, provider details, and payer rules. Automated checks identify exceptions, trained reviewers examine the context, and the resulting findings return to the people who created the claim.

The purpose isn't only to produce an accuracy score. A useful audit answers four operational questions:
- Can the record support the assigned codes? The reviewer tests whether the diagnosis, procedure, level of service, modifiers, and medical necessity are supported by the actual note.
- Can the claim survive payer review? The team checks whether documentation and coding align with payer requirements, authorization conditions, and known denial behavior.
- Can the practice correct the cause? A finding should identify whether the issue arose from documentation, code selection, workflow design, training, or an unresolved query.
- Can the organization defend payment? The record, audit rationale, query history, and payer correspondence should remain organized for an appeal or dispute.
Consider a missing modifier. The problem may begin in coding, but the financial consequence appears later as a claim edit, downcoding, denial, delayed payment, or underpayment. An audit that only records the incorrect code misses the process failure. An audit that traces the missing modifier to the note template, coder workflow, or payer rule creates a fix.
Preventive and corrective control
Pre-bill review prevents a vulnerable claim from leaving the organization. Post-pay review identifies historical exposure and recovery opportunities. Concurrent review helps teams correct active encounters while documentation and coding decisions remain current.
The strongest programs combine these controls with a feedback loop. The reviewer documents the finding, the responsible owner responds, the policy or workflow changes, and the team tests subsequent claims. Spreadsheet-only tracking often makes that loop difficult to manage because reviewers may use inconsistent definitions or lose the connection between a finding and its corrective action.
Types of Coding Audits Compared
Audit type should follow the risk, not team habit. A gastroenterology practice preparing high-volume outpatient claims may need targeted pre-bill checks for procedure documentation, while an orthopedic group facing payer recoupment may need a post-pay review tied to a specific denial pattern. A multi-state platform may require all of these approaches, coordinated through one governance process.
| Audit Type | Timing | Owner | Common Trigger |
|---|---|---|---|
| Pre-bill audit | Before claim submission | Internal coding, compliance, or external audit team | High-risk code, new payer rule, unusual modifier, or incomplete documentation |
| Concurrent audit | During active encounter or near real time | Coding, CDI, clinical operations, or specialty lead | Documentation uncertainty while the encounter is still open |
| Post-pay audit | After payment or adjudication | Compliance, revenue integrity, payer-contracting, or recovery team | Denial trend, recoupment notice, underpayment pattern, or historical exposure |
| Internal audit | Scheduled or continuous | Provider organization or delegated auditor | Compliance monitoring, provider variation, education need, or recurring error |
| External payer audit | After payer selection or request | Payer, contractor, or government-related reviewer | Medical necessity concern, coding variance, records request, or payment review |
Choosing the right review
Pre-bill audits are preventive but can slow claim release if reviewers apply broad manual checks to every encounter. Use them selectively for services where a small documentation issue creates a meaningful payment or compliance risk.
Concurrent audits support faster correction, but they require clinical and coding staff to respond while work is still moving. They fit specialties with complex documentation and active query needs, though they can create friction if reviewers treat every question as a compliance escalation.
Post-pay audits provide visibility into actual payer behavior. They can uncover underpayments that a coding-only review misses, but they also arrive after cash has been delayed or lost. External audits deserve a separate response protocol because deadlines, record production, appeal language, and payer interpretation can affect the outcome.
Internal and external reviews should not compete. An internal audit should identify and correct vulnerabilities before a payer finds them. When an external audit arrives, the internal record should show what was reviewed, what changed, who approved the response, and why the organization believes the claim is supported.
Audit Methods and Sampling Benchmarks
A medical coding audit can produce a misleading result if the team doesn't define what “accurate” means. Counting individual codes and counting complete records answer different questions, so the audit report should name the method rather than present a single unexplained percentage.
The AHIMA guidance on compatible coding audit benchmarks identifies two main approaches:
- Code-over-code accuracy measures the share of individual codes assigned correctly. It can reveal whether a particular diagnosis family, procedure group, or modifier is producing repeated errors.
- Record-over-record accuracy measures the share of whole charts coded correctly. It gives management a stricter view of whether a complete claim is defensible from beginning to end.
Industry guidance notes that many organizations target about 94% to 96% accuracy, while an error rate of 5% or lower is often treated as acceptable in audit contexts. Those benchmarks should guide interpretation, not replace it. A high overall score can conceal concentrated risk in one provider, payer, service line, or code family.

Build a defensible sample
A practical sample starts with a defined population. Separate claims by specialty, payer, provider, place of service, code family, denial reason, and payment status. Then select a mix of routine claims and risk-based exceptions.
Risk-based sampling should favor encounters with one or more of these characteristics:
- A payer has started requesting records or denying a service.
- The claim includes complex modifiers, multiple procedures, or unusual diagnosis combinations.
- The provider or location shows unexplained variation.
- The service involves medical necessity, telehealth, clinical validation, or risk-adjustment exposure.
- The claim carries a meaningful underpayment or dispute opportunity.
Document the selection rule, reviewer qualifications, coding guidelines used, and treatment of disagreements. If two reviewers reach different conclusions, retain the rationale and establish an adjudication process. Consistency is part of defensibility.
Key Metrics and Audit Dashboards
A continuous audit program needs more than an accuracy rate. Leaders need to know where errors occur, what they cost, how quickly teams respond, and whether payer behavior is changing. A dashboard should turn review activity into decisions, not create another report that nobody owns.

Accuracy and impact
Accuracy belongs at the top of the dashboard, but it needs segmentation. Show the overall rate alongside error by specialty, provider, location, payer, and code family. A single enterprise score can look stable while one anesthesia group, imaging location, or telehealth workflow carries the actual exposure.
Impact measures connect findings to cash. Track denial reason mix, underpayment patterns, clean-claim performance, recoupment exposure, and the amount at risk per claim. Separate preventable coding issues from medical necessity disputes and documentation requests. Those categories require different owners and different responses.
Efficiency and trend signals
Query turnaround is a leading indicator. If providers don't answer questions promptly, coders may submit unsupported claims, billing may release incomplete records, and denial staff may lack evidence for an appeal. Audit cycle time also matters, but speed shouldn't come from skipping review standards.
A useful dashboard can include:
- Accuracy: Overall accuracy, error by specialty, repeat finding rate.
- Impact: Denial reason mix, underpayment value, amount at risk per claim, and dispute eligibility.
- Efficiency: Query turnaround, audit cycle time, appeal response time, and unresolved finding age.
- Payer intelligence: Requests for information, medical necessity activity, telehealth denials, and recurring code edits.
For a broader framework for organizing operational measures, teams can reference revenue cycle management metrics. The dashboard should assign an owner to every red signal. A trend without a decision rule is just historical information.
Common Findings and Specialty Hotspots
Documentation is often the control point. One training source reports that about half of coding errors stem from insufficient provider documentation, while about one-third result from providers not responding to repeated auditor requests. Those figures are documented in the medical coding training material on audit error drivers.
That changes how a revenue protection lead should respond to an error. Sending a coder back for retraining may be appropriate, but it won't solve a note that never states the clinical facts needed to support the code. Likewise, creating another query template won't help if providers receive questions without clear ownership, deadlines, or escalation.
Where exposure concentrates
Anesthesia claims can involve procedure details, time documentation, modifiers, and payer-specific interpretations. ASC and outpatient claims often move through fast workflows where a missing detail becomes visible only after adjudication. Imaging teams face medical necessity and order-related scrutiny, while multi-specialty platforms must manage variation across providers, locations, and acquired practices.
Clinical-validation risk deserves separate attention. Copy-forward documentation can create inconsistencies between the current encounter and the historical narrative. Risk-score anomalies may prompt questions about whether the record supports the reported condition. Telehealth encounters can generate documentation gaps when templates don't capture the required context or when virtual workflows differ from in-person processes.
The most useful finding report identifies the root cause instead of labeling everything a “coding error”:
- Documentation deficiency: The provider note doesn't support the service or diagnosis.
- Query failure: The question was sent, but no usable response returned.
- Code-selection issue: The documentation supports a different code or modifier.
- Workflow defect: A system, template, or handoff caused the omission.
- Payer interpretation: The record supports the claim, but the payer applies a disputed policy position.
A finding isn't remediated until the team can explain why it happened and demonstrate that the same pathway no longer produces it.
Remediation and Training Workflows
Remediation should begin with ownership. Assign each finding to the person who can change the cause, not merely the person who discovered it. A coder can correct code selection, a provider can improve the clinical narrative, an operations leader can revise the workflow, and a denial specialist can preserve evidence for an appeal.
Start with the record. Identify the exact missing or conflicting element, distinguish a documentation query from a coding correction, and confirm that the proposed change follows applicable coding and payer requirements. Avoid retrospective alterations that aren't supported by the original encounter. The audit file should preserve the source note, review rationale, query history, response, corrected claim action, and final outcome.
Make queries operational
A query process needs a clear owner, escalation path, and response expectation. The team should monitor open queries by provider, specialty, age, and subject. If a provider repeatedly receives the same question, the solution may be a template change, targeted education, or a redesigned intake process rather than another isolated reminder.
Training works best when it follows a pattern. Use actual de-identified findings, explain the documentation element that mattered, show the downstream denial or payment consequence, and give the provider or coder a practical replacement behavior. A short specialty-specific session is usually more useful than generic annual education.
Teams building a broader documentation program can review clinical documentation improvement services as one model for connecting provider documentation, coding support, and audit findings.
Preserve dispute readiness
Don't wait for a payer request to assemble evidence. Store the relevant medical record, coding rationale, payer correspondence, authorization details, contract language where applicable, and internal review history in a controlled case file. That package supports appeals, underpayment review, and NSA IDR preparation without forcing staff to reconstruct the claim months later.
Audits Inside Revenue Cycle and IDR
Medical coding audits sit in the middle of the revenue lifecycle. Eligibility and authorization affect whether the service can be billed, documentation and coding determine whether the claim is supportable, adjudication reveals payer behavior, and denial or underpayment work determines whether the organization accepts the result.
A coding team that only measures accuracy may miss a payer consistently underpaying a correctly documented service. A denial team that only contests payment may miss a recurring documentation weakness that makes every dispute harder. Revenue integrity connects both views.
Link the operating views
For continuous micro-audits, I recommend three working views:
- Payer denial trend: Group denials by payer, reason, service, specialty, and documentation request. This distinguishes a broad coding issue from a payer-specific pattern.
- Specialty error heatmap: Display findings by provider, location, code family, and encounter type. Use it to prioritize education and pre-bill review.
- Case-age workbook: Track open audits, appeals, underpayments, record requests, deadlines, evidence status, and next action. Aging should be visible to operations and finance, not just the denial team.
Medical coding audits can also identify claims that deserve underpayment prioritization. The question isn't “Can we appeal everything?” It's “Which disputed claims have strong documentation, a clear payment variance, a meaningful recovery opportunity, and a viable dispute path?” That decision should account for payer behavior, case age, administrative effort, and the risk of allowing a recurring underpayment pattern to become normal.
Under the No Surprises Act, eligible disputes may proceed through Independent Dispute Resolution. Coding accuracy alone doesn't win an IDR case, but it strengthens the evidence chain by showing that the service, diagnosis, documentation, and billed claim align. A connected workflow can carry audit findings into Independent Dispute Resolution under the No Surprises Act while preserving the underlying record and payer history.
RevGuard is one option for organizations that want specialty-specific revenue cycle operations connected to NSA IDR support, including coding and documentation review, payer-behavior analytics, evidence assembly, case filing, and enforcement workflows. The practical value of any platform depends on whether it gives coders, denial staff, finance leaders, and dispute teams a shared, actionable record.
RevGuard helps specialty groups connect medical coding audits, revenue cycle management, payer-behavior analytics, and NSA IDR workflows so documentation problems are corrected upstream and defensible underpayments are prioritized downstream. Visit RevGuard to discuss how your organization can build a continuous revenue protection process around its specialty, payer mix, and audit exposure.