Case Study 2 — The Signature That Wasn't There: A Composite

A composite constructed from documented Medicare medical review findings and published contractor guidance. The regulatory requirements are Tier 1; the practice and its numbers are Tier 3 and constructed, and labeled as such.


Background

Case Study 1 was about documentation that says too much. This one is about documentation that is entirely accurate, clinically excellent, and worth nothing — because of a defect that has no clinical content at all.

Section 4.4 listed the authentication requirements and called missing signatures "the cheapest audit finding there is." That phrase deserves an illustration, because new coders and billers consistently underestimate the category. It has no drama. Nobody upcoded. No patient was harmed. The care was furnished, it was appropriate, and it was documented in detail.

And it is not payable.


The composite

Constructed. Not a real organization.

A four-physician practice adds an in-office diagnostic service — the kind of ancillary that many practices add for legitimate clinical and financial reasons. The workflow is designed by the office manager over a few weeks and it looks entirely sensible:

  1. The physician decides during a visit that the test is indicated and tells the medical assistant.
  2. The medical assistant enters the order in the electronic health record under a shared "orders" workflow.
  3. The test is performed, usually the same day.
  4. The result is routed to the physician, who reviews it and documents the interpretation in a subsequent note.
  5. Billing generates the claim.

Every clinical step is correct. The physician made the decision, the test was indicated, the result was reviewed and acted upon.

The order was never signed by the ordering physician.

The electronic health record recorded it as entered by the medical assistant, under a general authorization that the practice believed was sufficient. Nobody looked at this for two years, because nothing about it produced a denial: the claims paid, routinely, for two years.

Then the practice received a documentation request. Twenty claims, selected by the contractor. The practice assembled the records and sent them — complete notes, clear clinical justification, signed interpretations, everything a clinician would want to see.

Nineteen of the twenty were denied. Not for medical necessity. For the absence of a signed order from the treating physician.

The practice appealed, arguing — correctly — that the physician had unquestionably ordered the tests, that the notes documented the clinical decision, and that the interpretations were signed. The appeal failed at the first level. The requirement is not that the physician decided; it is that the order be documented and authenticated. A clinical decision described in a note is not an order.

And then the arithmetic got worse. The reviewed sample was twenty claims. The practice had billed the service for two years. Chapter 37 §37.6 explains extrapolation; the short version is that a contractor finding a high error rate in a valid statistical sample may project that rate across the universe of similar claims, and demand the projected overpayment rather than the sampled one.

The practice's exposure was not nineteen claims. It was two years of a service line.


What actually happened, step by step

Worth walking, because every step is a place the failure could have been caught and was not.

The workflow was designed by someone who did not know the requirement. Not negligence — the office manager was competent and the workflow was clinically sound. The signature requirement for diagnostic test orders is not intuitive, is not clinical, and is not something an electronic health record will necessarily enforce.

Payment provided false reassurance. This is the mechanism that makes this category so dangerous. Claims paying is not evidence that claims are correct. A payer's front-end adjudication checks codes, eligibility, edits, and medical policy. It does not check whether an order was signed, because it has never seen the record. Two years of clean payment established nothing except that nobody had looked.

There was no internal audit. A single review of ten charts, at any point in those two years, would have found it — because it is not a subtle finding. It is the first thing an auditor checks.

And the defect was uncurable after the fact. The practice could not sign the orders now. Signing them now would be creating documentation after a records request, which converts a payment problem into a very different problem (§4.5). The only honest paths were to accept the finding, appeal what was appealable, and fix the workflow going forward.


What it shows

First, the audit standard is not the clinical standard. Every clinician who looked at those charts would say the care was appropriate and well documented. The reviewer was not asking that question. The reviewer was asking whether a specific required document existed and was authenticated, and it did not.

This is the most important thing for a new professional to absorb about audits generally: the reviewer is applying a checklist, and being right about medicine does not satisfy it.

Second, "the claims are paying" is not a control. It is the most common reason a practice believes its documentation is fine, and it has no evidentiary value whatsoever. Chapter 37 §37.2 builds this into a positive argument for internal audit: the purpose of an internal audit is to find, while it is cheap, exactly what an external reviewer would find when it is not.

Third, the failure compounds silently over time. A coding error found in month one costs one claim. The same error found in year two costs a service line, because the volume accumulated and because extrapolation exists. The cost of a systemic documentation defect is proportional to how long it went unexamined, which means the value of an internal audit is proportional to how early it happens.

Fourth, and this is the one that connects to the whole chapter: the defect was invisible in the clinical record. A coder reading the note would have seen an excellent note. Nothing in the note signals that the order behind it is unsigned. The order is a different document, in a different part of the system, and a coder who only ever reads notes will never see the problem.

That is a real limitation of the coder's role and worth naming honestly. Which is why §4.4's list of signature requirements includes the order as a separate item, and why Chapter 37's internal audit scope includes documents a coder does not routinely open.


The lesson

Authentication is not clinical, and it is checked first.

Three carry-forwards:

Know which services require a signed order — diagnostic tests, therapy, durable medical equipment, home health, and others — and verify that your workflow produces one, authenticated, by the treating provider. This is a five-minute question with a two-year consequence.

Treat "our claims pay" as information about the payer's front-end edits and about nothing else. It is not evidence of documentation adequacy. It cannot be, because the payer has not seen the documentation.

Audit early and audit small. Ten charts, once a quarter, against a checklist that includes the non-clinical requirements. The purpose is not to catch people. It is to find the workflow defect in month two instead of year two, when the remedy is a configuration change rather than a repayment.

Signature and order requirements are set out in the Medicare Program Integrity Manual and in contractor guidance, and they vary by service type and by payer. Verify the requirements for the specific services your organization furnishes.


Discussion questions

  1. The practice's clinical care was correct and its documentation of that care was excellent. Is the denial fair? Argue both sides, then say what a rule that produced a "fairer" outcome would have to look like — and what it would cost.

  2. The case study says paying claims established nothing. Yet almost every practice treats payment as confirmation. Why is that intuition so durable, and what would it take to displace it in an organization you worked for?

  3. Map the responsibility. The office manager designed the workflow, the physician signed the notes, the medical assistant entered the orders, the coder coded from the notes, and the biller submitted the claims. Who should have caught this? Is there an answer that does not amount to "someone should have known a rule nobody in the building knew"?

  4. Chapter 1 §1.8 ranked six leaks by cost and said the cost of a fix rises steeply with how late it is found. Locate this failure on that list — it does not fit neatly into any of the six — and say what that suggests about the list.

  5. Design the ten-chart quarterly audit that would have caught this. What is on the checklist, who runs it, and what happens when it finds something? Be specific about the last part, because it is where most internal audit programs fail.