90 min read

> "Everything you write will eventually be read by somebody who was not there, has no stake in your

Prerequisites

  • 5
  • 21
  • 26
  • 31

Learning Objectives

  • State the three reasons an organization audits its own coding, and why the strongest of them is not the compliance requirement.
  • Design an internal audit: define the universe, draw a defensible sample, and name the written standard every finding will cite.
  • Score a chart, distinguish the four kinds of error a scoring sheet must separate, and report accuracy with its denominator attached.
  • Explain what prepayment review does to accounts receivable, and what it takes to come off it.
  • Identify what each external review program — MAC, RAC, UPIC, SMRC, CERT, TPE — is looking for, what it can do, and what it means when its letter arrives.
  • Work an extrapolation from sample to demand: the universe, the point estimate, the lower bound, and the provider's options.
  • Respond to a records request and write an audit response letter that concedes what is wrong and defends what is right, on cited authority.
  • Say when an error pattern becomes a reportable overpayment, what 'identified' means, and which disclosure route belongs to which kind of problem.
  • Write a corrective action plan whose success is testable, and build the one control that catches an assertion nobody chose.

Chapter 37: Auditing and Compliance: Internal Audits, External Audits, and Protecting Your Organization

"Everything you write will eventually be read by somebody who was not there, has no stake in your interpretation, and will not give you the benefit of the doubt." — constructed

Overview

Thirty-six chapters of this book have been about producing a claim. This one is about a stranger reading it.

That is the whole subject, and it explains the chapter's structure. An audit is not a punishment and it is not an accusation. It is a reading: somebody takes a sample of finished work, holds it against a written standard, and records where the two disagree. The reader might be your own organization's auditor, a payer's special investigations unit, one of six federal contractor programs with different mandates, or — at the far end — a prosecutor's expert. What they all do is the same act. They read what you wrote and ask whether the code follows from it.

The practitioner's question that opens the chapter, then, is not "how do I survive an audit?" It is this: the reading is going to happen; who do you want to do it first? Everything in the internal half of this chapter follows from answering "us." Everything in the external half follows from understanding that when you answer "them," the reading arrives with a deadline, a methodology you did not choose, and — if the pattern is consistent enough — a multiplier.

This chapter also does something no other chapter in this book does. It is a collector. For thirty-six chapters, case study after case study has ended with a question left deliberately open: what single control would have caught these? Is "build better controls" a sufficient answer? Why does a consistent error cost more than a sloppy one? What do you do when the only person who could have noticed a problem was structurally incapable of seeing it? Those questions were not rhetorical. They were deferred here, because none of them can be answered before you know how an audit actually works. They are answered in §37.2, §37.6, §37.8, and §37.10.

In this chapter, you will learn to:

  • Say why an organization audits itself, in a sentence a practice owner will accept
  • Scope an internal audit: universe, sample, standard
  • Score a chart, and defend the score to the person whose work it was
  • Explain prepayment review's effect on cash and on the calendar
  • Name the external review programs and what each one does
  • Work the extrapolation arithmetic, forward and backward
  • Respond to a records request and write the response letter
  • Recognize when a pattern becomes a sixty-day obligation, and route it correctly
  • Write a corrective action plan with an owner, a date, and a test

37.1 Why audit at all

Start with the decision on the desk. You are the practice manager at Northgate Family Medicine — five physicians, roughly nineteen thousand encounters a year, one coder, one biller. Your coder wants eight hours a quarter to pull forty charts at random and read them against the notes. Those eight hours come out of production. What, exactly, do you get for them?

The wrong answer, and the one usually given, is "we have to." It is true, and it is the weakest of the three real reasons.

Reason one: an error found early is a correction; an error found late is a repayment. This is the whole economics of the activity and it is the same argument Chapter 24 §24.1 made about the front end, moved downstream. A miscoded claim caught before submission is a keystroke. Caught after payment, it is a refund plus a root-cause investigation. Caught by a payer eighteen months later, across every claim that carried the same pattern, it is Account 31-2245 — forty-two claims, one macro, and a demand for \$25,720.80 (Chapter 17 §17.9). Nothing about the coding got worse over those eighteen months. Only the arithmetic did.

Reason two: an audit is the only instrument that measures the thing you are actually selling. Chapter 6 §6.9 introduced the productivity and quality standards a coder is held to. Production counts itself — charts per day, lines per hour, days to bill. Quality is not counted at all unless somebody counts it, and Chapter 24's Case Study 2 supplies the sentence this book has carried since: an unmeasured function is indefensible. When a practice decides whether to outsource coding, cut a position, or overrule a coder's judgment, the department that can produce twelve quarters of measured accuracy is in a different conversation from the one that can only say it works hard.

Reason three, and the one people find surprising: errors run in both directions, and the downward ones are invisible. An overpayment announces itself eventually — a payer finds it. An underpayment does not. Chapter 28 §28.8 built the method and led with the reason it is hard: an underpayment does not deny, does not reject, appears on no exception report, arrives as a payment, and raises the net collection rate. Chapter 33 §33.3 named the facility version. Chapter 5 §5.8 established the principle: upcoding and downcoding are both errors, and coding low is not the conservative option. An audit is the only routine activity in a revenue cycle that looks in the direction nothing else looks.

The compliance requirement, stated honestly

Chapter 5 §5.6 gave the seven elements of an effective compliance program, and auditing and monitoring is one of them. The Office of Inspector General (OIG) of the Department of Health and Human Services has published compliance program guidance for physician practices, hospitals, and billing companies for decades, and every version says the same thing: a program that does not periodically test its own claims is not a program.

But be precise about what that means. An audit that finds nothing, quarter after quarter, is not evidence of excellence — it is evidence of a sample too small, a standard too vague, or an auditor who is not independent. And it is not legal insurance. What it is, in an enforcement posture, is evidence about intent: Chapter 5 §5.2's line between error and fraud runs through intent and pattern, and an organization that can show it looked, found, fixed, and re-tested argues from a different position than one that cannot show it ever looked.

The uncomfortable observation this book has been accumulating

Count how many failures in this book were found by a control — an edit, a report, a reconciliation, a scheduled review — and how many by a person who happened to notice. The person column wins, and it is not close: a new biller who asked why a convention existed, a physician reading his own production report, a front-desk manager who refused a summary and pulled forty claims herself, a returned envelope in a mailroom. Twice the finder was not even inside the organization — a due-diligence team, and a patient's family member.

Chapter 19's Case Study 2 supplied the corollary this chapter inherits: a person noticing is not a control — but the absence of a place to say something IS a control failure.

And Chapter 26's Case Study 1 raised the ceiling. A unit clerk of eleven years entered discharge status codes accurately by her own lights; those codes triggered the transfer rule (Chapter 33 §33.8) in a payment system she had no visibility into and no reason to know existed. She could not have detected the error even in principle. That case ends the comfortable version of "if you see something, say something," and §37.10 has to answer it with something operational.

⚠️ Where Claims Die

The audit that was scheduled and never ran. It is the most common failure in this chapter and it almost never appears in a case study, because nothing happens. A practice adopts a compliance plan with a quarterly audit in it, runs the first one, finds three problems, gets busy, and does not run the second. Two years later the plan is still in the binder and the binder is the only artifact.

Why it matters more than it looks: the plan is now a written statement that the organization knew this testing was necessary. In an enforcement posture, a documented control that was never operated is worse than no documented control, because it establishes what the organization understood its own obligation to be.

What the disciplined organization does: makes the audit smaller and makes it survive. Ten charts a month that actually happen beat forty a quarter that do not. Put a named owner on it, put it on a calendar with a date rather than a season, and report the result — including "no findings" — to somebody who will notice its absence. That is Chapter 27's Case Study 1 in preventive form: a report is not a control; a person who reads a report is a control.


37.2 The internal audit: scope, sample, standard

Three questions get answered before a single chart is pulled, and an audit that skips any of them produces a number nobody can act on.

The audit universe is the complete, defined set of items the audit is about — every claim, line, chart, or encounter that meets the stated criteria for a stated period. The universe is not "our claims." It is a query with a date range, a payer, a provider, a code set, and a filter, that returns a countable number.

Everything downstream depends on that count. A sample means nothing without the population it came from; an error rate means nothing without a denominator (Chapter 29 §29.7's discipline, which applies to audit findings exactly as it applies to denial rates); and an extrapolation — §37.6 — is arithmetic performed on the universe. If you learn one habit from this section, learn to write the universe down as a sentence with a number at the end of it.

Choosing the scope

Four honest ways to choose what to audit; rotate through them rather than pick one.

Risk-driven. Audit what is likely to be wrong or likely to be looked at. The two best free sources are your own denial log (Chapter 29 §29.7 — the categories with the highest preventable share) and the OIG Work Plan.

The OIG Work Plan is the Office of Inspector General's published, continuously updated list of the audits and evaluations it has active or planned, each with a stated issue and an expected report date. It is free, it is public, and it is the closest thing this field has to a forecast of what is about to be scrutinized. Chapter 3 §3.10 put it in your lookup list; this is what to do with it.

Reading it takes twenty minutes a quarter, and items relevant to a family practice appear regularly. An organization that audits an item the month it appears on the Work Plan is auditing on the same schedule as the government.

Volume-driven. Audit what you do most of. A one-percent error rate on a code billed four thousand times a year is a bigger number than a fifty-percent error rate on a code billed twice.

Provider-driven. Every provider on a cycle, including the ones nobody worries about, because the comparison across providers is where a leveling outlier becomes visible. It works only when it is routine: everyone, every year, same sample size, published schedule.

Event-driven. A new provider, a new service line, a new payer contract, a system upgrade, a configuration change, a coder's first ninety days — each a moment when something that was true stops being true. §37.10 makes two of them hard triggers.

The sample

A probe audit — the term covers both an internal first look and, in §37.5, what a Medicare contractor does — is a small, deliberately limited review, ten to thirty charts, whose purpose is to decide whether a larger review is needed. It answers "is there a problem here at all?", not "how big."

Two rules keep a probe honest. Draw it randomly, or say plainly that you did not — a convenience sample off the top of the queue is a legitimate first look and an illegitimate error rate. And never extrapolate from a probe; §37.6 explains why, and the same mathematics that limits your inference limits a contractor's.

For a measured audit, size trades precision against cost. Two anchors: the OIG's long-standing compliance program guidance for physician practices has suggested a baseline of five or more records per federal payer, or roughly five to ten per physician, as a starting point for a practice with no audit history — verify the current guidance. And an audit meant to measure a provider rather than probe one generally starts around twenty to thirty charts per provider per cycle, below which the sampling noise exceeds the differences anyone wants to act on.

The standard

You cannot score a chart against "correct." Every finding must name the authority it rests on, in a form the person being audited can go and read:

THE STANDARD STACK — what a finding must be able to cite         [reference]

   1  THE RECORD ITSELF ............... the note, the order, the signature.
                                        Most findings live here and go no
                                        further: the code is not supported.
   2  THE CODE SET .................... CPT, ICD-10-CM, HCPCS Level II
                                        descriptors and their conventions.
   3  THE OFFICIAL GUIDELINES ......... ICD-10-CM Official Guidelines;
                                        CPT section and subsection guidelines
                                        and parenthetical notes (Ch. 13 §13.4).
   4  THE EDIT FILES .................. NCCI procedure-to-procedure edits and
                                        MUEs; the NCCI Policy Manual (Ch. 21).
   5  THE COVERAGE POLICY ............. NCD, LCD, the local coverage article,
                                        or the commercial medical policy
                                        (Ch. 22 §22.3-§22.5, §22.10).
   6  THE CONTRACT / MANUAL ........... the payer's provider manual, the
                                        Medicare Claims Processing Manual,
                                        the Program Integrity Manual.

   AND THE DATE RULE, which governs all six:
   a claim is scored against the rules in force on its DATE OF SERVICE,
   never against today's.

That last line is the one new auditors get wrong, and it matters because everything in this field is revised on a schedule: ICD-10-CM every October 1, CPT every January 1, HCPCS Level II quarterly, NCCI edits and medically unlikely edit values quarterly, coverage determinations continuously. A claim from March cannot be an error because a code changed in October. Chapter 6 §6.7 taught the update cycle as a survival skill; in an audit it is a defense, and it works in both directions — a contractor scoring your 2023 claims against the 2025 Policy Manual has made a finding you can rebut on a single sentence.

Three legs, because charts alone miss two whole classes of error

Here is the scoping decision that separates an audit program that works from one that keeps missing the same species of error. An audit universe has three legs: charts, configurations, and distributions. Most programs have only the first.

The second leg: the configurations. Across this book, a dozen failures at least, in every part, share one mechanism: a configuration made an assertion nobody chose.

THE SAME MECHANISM, ACROSS EVERY PART OF THIS BOOK
                                        [a dozen instances, at least]

  IN THE BILLING SYSTEM
    seven scrubber rules nobody owned, six of them silently
      altering claim content ............................... Ch. 6
    modifiers appended by a billing rule .................... Ch. 14
    a modifier-59 macro on every 29822 ...... Account 31-2245 / Ch. 21
    a fracture-care macro reporting a 090-day global ........ Ch. 17
    claim lines built in performed order, not by value ...... Ch. 18
    an automatic KX modifier once a threshold is crossed .... Ch. 19
    a place-of-service default that survived a conversion ... Ch. 23
    a posting rule: "any CO -> contractual adjustment" ...... Ch. 28
    a condition code applied by default ..................... Ch. 34

  IN THE CLINICAL RECORD, OVER A PHYSICIAN'S SIGNATURE
    a prefilled total-time default in an E/M template ....... Ch. 15
    leveling logic reimplemented from observed behavior ..... Ch. 16
    a standing order asserting medical necessity monthly,
      for four years ....................................... Ch. 19
    a template auto-inserting a modifier-25 attestation ..... Ch. 29

  IN A FORM THE PATIENT SIGNS
    a routine ABN producing GA on every claim ............... Ch. 22

  IN A TRANSMISSION NOBODY COULD SEE
    an eleven-year-old local 837 mapping .................... Ch. 27

  IN THE PAYER'S SYSTEM, WITH THE PROVIDER'S EXPOSURE
    a remittance asserting that secondary billing
      was proper ........................................... Ch. 31

  IN A SCRIPT HANDED TO A PERSON
    "this patient can pay and should be asked again" ........ Ch. 31

They have almost nothing else in common — different modules, different departments, different decades, different directions of error. Several were correct when configured and stopped being correct later. Two were invisible on any claim anybody in the building could look at. One was not even the provider's configuration: Chapter 31's Case Study 1 turns on a payer's software asserting on every affected remittance that secondary billing was proper, and the provider still certified the claims and still owned the obligation. And the last group is not software at all — a collection script is a configuration whose runtime is a human being.

What they share is that none was ever a decision a person made about a specific claim. Somebody configured each one, once, often years earlier, usually for a good reason. Thereafter the configuration made the assertion, on every claim, silently, in the voice of the practice.

And a chart audit cannot find them. Pull ten charts touched by a modifier-59 macro and the modifier is on all ten: the sample is internally consistent and tells you nothing, because you are auditing the configuration's output with a method that reads only output. Chapter 17's Case Study 1 asked students to write the one control that catches all of these; it is a corrective instrument rather than a diagnostic one, so this book writes it out in §37.10.

The third leg: the distributions. Chapter 15's Case Study 2 stated the limit that makes this leg necessary, and it is worth memorizing: anything that is only wrong in aggregate cannot be found by sampling. A prefilled time default is defensible on any single chart you pull and indefensible when you sum the documented minutes for one physician on one Tuesday. What finds it is a distribution — a count computed from your own claims data with no record opened at all:

ANALYSES THAT NEED NO CHART                 [computable from claims data]

  · E/M level distribution by provider, against the group
  · modifier 25 and modifier 59 rates, by provider and code pair
  · units per line against the descriptor's unit (Ch. 20 §20.3)
  · total documented E/M time per provider per date
  · share of claims carrying GA, KX, or any liability modifier
  · patient discharge status distribution (Ch. 26 §26.7)

They take minutes, they require no chart review, and they find things no claim-level control ever will — the promise Chapter 12's Case Study 2 made to this section back in Part II. §37.10 returns to the list for a harder reason.

So: charts, configurations, distributions. If you have only ever audited the first, two of the three largest classes of failure in this book are invisible to your program.

Treat a favorable trend as a question

One monitoring habit belongs in the plan itself, because this book has produced four cases in which a number moved the flattering way for a bad reason: a denial rate that improved because rejected claims never reach adjudication (Chapter 27's Case Study 1); a collection ratio that rose because underpayments shrank the denominator (Chapter 23's Case Study 2); contractual adjustments that grew because bundling denials were posting as write-offs (Chapter 28's Case Study 1); and modifier-25 denials that fell because a template began asserting the modifier's justification automatically (Chapter 29's Case Study 2). In every one the number was reported accurately by somebody who had done good work, and Chapter 28's case supplies the sentence: a number with a story attached stops being a question.

So put favorable movement on the audit plan. A metric that improves more than expected gets the same one-page investigation an adverse one gets: what changed, in what month, and what else would have to be true.

📋 Read the Chart

text FIGURE 37.1 — "The audit plan, one page" [constructed teaching example] THE DOCUMENT A one-page internal audit plan for Q2, signed by the practice manager and the compliance contact. Northgate Family Medicine (constructed). THE CONTEXT The practice's second quarterly audit. Q1 was a probe; it found two modifier-25 charts the coder and the auditor read differently, which is why Q2 is a measured audit rather than another probe. WHAT IT SHOWS UNIVERSE All professional claims, dates of service Jan 1 - Mar 31, any payer, containing a 99213-99215 with modifier 25 on the same date as a procedure with a 000-day global. Count: 412 claims, 5 providers. SAMPLE 25 charts, randomly drawn, stratified 5 per provider so no provider's rate rests on 2 charts. Draw method and seed recorded. STANDARD CPT E/M guidelines; the modifier 25 definition; NCCI Policy Manual Ch. 1; each payer's published policy where one exists. Every finding cites one of these. SCORING Per line and per chart. Both reported. AUDITOR The practice's coder does not audit her own work; a contracted credentialed auditor reads all 25. Findings returned to the coder for written rebuttal before they are final. WHAT IT DOESN'T It does not measure the practice. It measures one code combination for one quarter. It says nothing about diagnosis coding, nothing about the front end, and nothing about the four configurations running in the charge-capture module. THE DECISION Run it. Calendar the Q3 plan on the day this one closes, so the schedule survives a busy June. THE LESSON A plan that fits on one page is a plan that gets run. The three lines that make it an audit rather than a look are the UNIVERSE COUNT, the DRAW METHOD, and the named STANDARD. Everything else is logistics.

Who audits, and the rebuttal

Independence is a spectrum, not a state. A coder auditing her own work is not an audit. A coder auditing a colleague's is a real audit with a real limitation — she shares the training, the templates, and the assumptions, so she will miss exactly the errors built into the shared assumptions. An external auditor costs money and finds the things the building agrees about. A mature program uses all three at different frequencies and is explicit about which one produced which number.

And every finding gets a rebuttal before it is final. The person whose work was scored reads it, sees the cited authority, and answers in writing. That is not politeness; it is the fastest way to discover that the auditor was wrong — which happens, and which is far more damaging to a program than an error, because a program that cannot be wrong is a program nobody will cooperate with.

🧮 Run the Numbers

The audit that paid for itself, and the reason this section exists. [constructed teaching figures — the shape is Chapter 14's Case Study 2, where a reporting convention was wrong for two payers for four years and the organization LOST money rather than owing it.]

A focused audit of one code pairing across twelve months at a mid-size practice finds that a reporting convention correct for the practice's largest payer was applied to a payer whose contract requires the service reported differently. The claims paid. Nothing denied. Nothing rejected. They simply paid \$62.40 less than the contract allows, every time.

```text claims carrying the convention, 12 months .... 214 underpayment per claim ........................ $62.40

IDENTIFIED 214 x $62.40 = $13,353.60 the size of the error

RECOVERABLE 97 x $62.40 = $6,052.80 only the 97 claims still inside the payer's 180-day reconsideration window NOT RECOVERABLE 117 x $62.40 = $7,300.80 found too late

PROSPECTIVE 214 x $62.40 = $13,353.60 per year, every year, once the convention is fixed ```

Checks: 214 × 62.40 = 13,353.60 ✓ · 97 × 62.40 = 6,052.80 ✓ · 117 × 62.40 = 7,300.80 ✓ · 6,052.80 + 7,300.80 = 13,353.60 ✓ · 97 + 117 = 214 ✓

Three things to take from this.

First, the reversal — and the symmetry underneath it. Almost every audit story in this book is about money owed; this one is money lost, and it is the strongest argument the internal audit function has, because it is the version that survives a practice owner who is not frightened of compliance. The same thing hides both kinds of error: the absence of a financial signal. An overpayment produces no denial, no rejection, no exception report — and neither does an underpayment. Chapter 14's Case Study 2 is the underpayment version: a bilateral reporting convention wrong for two payers for four years, every claim paying normally, found by a newly hired biller who noticed the same procedure paying differently across payers than contract variation could explain. The same silence conceals errors in both directions, and only one of them comes with a deadline (§37.9). Chapter 28 §28.8 supplies the method — expected allowed, actual allowed, variance, threshold, classify — and an audit program that never runs it is auditing one direction.

Second, the cost of delay is real and computable. \$7,300.80 of a \$13,353.60 finding was gone before anyone looked, and it was gone because of a contract clause rather than because of the error. Underpayment review is one of very few revenue-cycle activities with a genuine price on waiting.

Third, the prospective number is the one that matters and the one nobody puts in the report. The recovery is a windfall. The fixed convention is an annuity.


37.3 Scoring a chart, and what counts as an error

An audit produces one artifact: a scored chart with a written finding on each disagreement. Everything else — the rate, the report, the corrective action plan — is built on that artifact, so the definitions underneath it have to be exact.

Four kinds of error, and why they must not be pooled

THE FOUR FINDINGS A SCORING SHEET MUST SEPARATE

  1  NOT SUPPORTED       The record does not contain what the code
                         requires. The code comes off. This is the
                         only category that is unambiguously an error
                         in every audit anyone will ever run.

  2  WRONG CODE          The record supports a service; a different
                         code describes it. Includes the modifier that
                         should not be there and the one that should.
                         The service happened; the description is wrong.

  3  SEQUENCING /        Right codes, wrong order, wrong pointer, wrong
     LINKAGE             unit. The claim asserts a relationship the
                         record does not (Ch. 25 §25.5).

  4  SUPPORTED, BUT      The code stands. Something about HOW the record
     THE RECORD IS       supports it will not survive the next reader:
     FRAGILE             the support is in the wrong section, an element
                         is implied rather than stated, a required
                         negative is absent.

  Categories 1-3 change the claim. Category 4 does not - and it is the
  category that predicts next year's category 1.

Category 4 is the one most scoring sheets do not have, and it is the reason this book insists on it. Chapter 14 §14.4 found that Account 10-4471's note never states the decision to inject was made during this visit — strongly implied, clinically obvious, absent as a sentence. Chapter 33 §33.10 found the facility twin: a record that documents "hypoxic" where "acute respiratory failure with hypoxia" was true is not wrong; it is unwritten. Neither finding removes a code. Both findings are the most valuable things in their respective audits, because they are the only findings that are cheap to fix — a template change and a sentence — and expensive to leave.

An audit that reports only categories 1 through 3 reports only the errors that already cost money. An audit with category 4 reports the ones that are about to.

The denominator, again

Chapter 29 §29.7 established that "denial rate" is not one number. "Accuracy" is worse. The same audit of the same twenty-five charts can honestly report any of these:

Measure What it counts On a chart with 4 lines and 1 bad modifier
Code-level accuracy correct codes ÷ codes reviewed 3 of 4 = 75%
Chart-level accuracy charts with zero findings ÷ charts 0 of 1 = 0%
Financial accuracy net dollar variance ÷ dollars reviewed depends entirely on which line
Directional overstated vs. understated, reported separately 1 overstated, 0 understated

None is wrong. All four are used. A quality standard of "95%" that does not say which one it means is not a standard, and a coder held to chart-level accuracy is held to a materially harder number than a colleague held to code-level accuracy on the same work. Chapter 6 §6.9 introduced the standards; this is where you find out what they measure.

And know which one the outside world uses. Chapter 6 §6.9 called per-chart accuracy the harsh measure and the one closest to how an external auditor scores you. Here is the reason: an external reviewer's finding is about the claim, not about the individual codes on it. In an extrapolation (§37.6) the sampling unit is very often the claim, so one unsupported line makes the whole unit an error and the whole unit's overpayment the number that gets projected. An internal program reporting only code-level accuracy will look systematically better than the same work looks from outside.

And report direction always. A 4% error rate that is entirely understatement is a revenue problem. The same 4% in the other direction is a compliance problem with a sixty-day clock attached (§37.9). The pooled number describes neither.

🔢 Code It

The chart in front of the auditor (constructed teaching example). An established patient presents for right shoulder pain of three weeks. The note documents an HPI focused entirely on the shoulder, a musculoskeletal examination of the shoulder, an assessment reading "right shoulder pain, likely subacromial bursitis," and a plan reading "subacromial injection performed today; follow up in three weeks." A subacromial injection of a major joint or bursa is documented in a procedure note. No other problem is mentioned anywhere in the note. Billed: 99213-25 and 20610-RT.

The finding. 20610 stands: the procedure is documented, the joint size is right, no imaging guidance is claimed. The E/M line does not. Modifier 25 asserts a significant, separately identifiable evaluation and management service above and beyond the usual pre- and post-procedure work included in the procedure's package (Chapter 14 §14.4; Chapter 17 §17.1). This record documents one problem, evaluated once, resulting in one procedure. The history and the examination are the pre-procedure evaluation, and the surgical package already pays for them (Chapter 17 §17.2). Finding: category 1 — not supported. Remove line 1. Authority cited: the CPT modifier 25 definition and the surgical package guidelines.

The plausible wrong answer, and it is the one a nervous auditor gives: "downcode it to 99212." No. The question is not which level; it is whether a separately identifiable E/M service occurred at all. It did not. Billing a lower-level E/M that the record equally fails to support is still billing a service that did not separately happen — Chapter 5 §5.8's symmetry, applied against the instinct that a smaller wrong code is a safer one. It is not safer. It is a smaller false statement.

And the contrast worth holding. This chart is the exact photographic negative of Account 10-4471, where the same two codes appear with the same modifier and the finding goes the other way — because on March 14 three chronic conditions were separately assessed with plans, three medications were reviewed, and two laboratory tests were ordered with stated reasons, none of which has anything to do with the knee (the four elements Chapter 14 §14.4 draws out of Figure 4.2). Same codes, same modifier, opposite findings, and the entire difference is in the note. §37.11 audits that chart in full.

📋 Read the Chart

```text FIGURE 37.2 — "The scoring sheet" [constructed teaching example] THE DOCUMENT One row of an internal audit worksheet, as returned to the coder for rebuttal before the finding is final. THE CONTEXT Q2 audit, chart 11 of 25. The chart in the Code It callout above. WHAT IT SHOWS CHART 11 | DOS 02/09 | PROVIDER C | 2 LINES REVIEWED

               LINE 1  99213-25   FINDING: category 1, not supported
                       AUTHORITY: CPT modifier 25 definition; CPT
                       surgery guidelines, the surgical package.
                       BASIS: the note documents one problem, one
                       evaluation, one procedure. No separately
                       identifiable service is documented.
                       ACTION: remove the line. Financial effect
                       recorded as overstatement.

               LINE 2  20610-RT   FINDING: supported.
                       NOTE (category 4): the procedure note does
                       not state the laterality in words; RT is
                       supported only by the HPI and the exam.
                       Not an error. Fix the template.

               CHART SCORE  code-level 1 of 2 = 50%
                            chart-level  0 of 1 =  0%
                            direction    overstated

               CODER'S REBUTTAL  [ ] agree  [ ] disagree - basis:

WHAT IT DOESN'T It does not say the coder was careless, and it does not say anyone billed fraudulently. A scoring sheet records a disagreement with a cited standard. Intent is not on this form and does not belong on it. THE DECISION Return it, take the rebuttal seriously, and record the category 4 note separately from the error - it goes to the corrective action plan, not to the error rate. THE LESSON A finding that does not name its authority is an opinion. A finding that names its authority is a finding, and the person being audited can check it. ```

The auditor's own discipline

Three habits that make findings survive contact with the people they are about.

Read the whole record before scoring any line. The support for line 1 is frequently in the section that belongs to line 3. Chapter 25's Case Study 1 lesson applies: the instinct is to check the codes first, and the codes are usually fine.

Score what is there, not what you would have written. If two credentialed coders can read the record and reach different defensible codes, the finding is a variance, not an error — record it as one and escalate it to whoever owns the practice's convention.

And carry Chapter 27's Case Study 2 sentence into every clean result: a correct outcome is not evidence of a correct process. A chart can score 100% and have been produced by a macro that will get the next chart wrong, by a coder who guessed and happened to be right, or by a configuration silently normalized downstream. The score measures the artifact, not the machine that made it — which is why §37.10's controls are a separate instrument.

🎓 Exam Watch

Auditing has its own credential — the Certified Professional Medical Auditor (CPMA) from AAPC, described at Chapter 39 §39.3. It is not entry-level and not a substitute for coding fluency; it tests scoring somebody else's work against a cited standard, which is a different skill from producing the code.

On the coding exams, audit material shows up in three reliable shapes. (1) A stem giving you documentation and a billed code, asking what the auditor should do — the trap answer is "query the provider" when the question is about scoring, or "downcode" when the service is not separately supported at any level. (2) Which authority governs a given finding: coverage to the NCD/LCD, bundling to NCCI and its Policy Manual, documentation content to the record and the CPT guidelines. (3) The date rule — a claim is scored against the rules in force on the date of service.


37.4 Prepayment review and what it does to cash

Two words divide the entire external landscape, and getting them straight is worth money.

Postpayment review happens after the claim has been adjudicated and paid. The reviewer requests records, reads them, and — where it disagrees — creates an overpayment: a debt, recovered by demand or by offsetting future payments.

Prepayment review happens before adjudication. Claims matching a defined criterion are suspended on arrival, records are requested, and the claim is paid, reduced, or denied on the strength of the documentation. There is nothing to recover because nothing was paid.

Everyone's instinct is that prepayment review is the gentler of the two. It is not. Postpayment review takes money you have. Prepayment review takes your calendar, your staff, and your cash cycle, all at once, and it does not end on a date you control.

What it actually does

A claim under prepayment review does not deny; it suspends. The payer issues an additional documentation request (ADR) — the letter that asks for the records supporting a specific claim, with a specific deadline. Under Medicare, an ADR commonly allows 45 calendar days for the response, and a non-response is not a neutral event: the claim is denied for insufficient documentation, and it counts against you as an error. Verify the deadline printed on the letter you received, because it governs and it varies by program.

Now trace it through the machinery this book has already built:

  • The claim was filed on time, so timely filing (Chapter 27 §27.7) is not the exposure. The ADR deadline is a different clock, with a different owner and no relationship to the filing rules.
  • Accounts receivable ages. Chapter 31 §31.2's buckets fill and §31.3's days in AR climbs, for a reason no aging report will explain — which is why the work queue needs a status that says "under review" rather than "no response from payer."
  • The denial rate moves misleadingly. Claims denied for non-response are documentation denials, and a root-cause list with no row for "records not produced" will post them somewhere else — Chapter 29's Case Study 1 exactly: a measurement system with a missing category does not report "unknown"; it reports the nearest available answer.
  • And the labor is new work that did not exist last month, per claim, with no offsetting reduction anywhere else.

🧮 Run the Numbers

A code family goes on 100% prepayment review. [constructed teaching figures] A specialty practice bills a code family generating \$26,400.00 per month in expected allowed amounts. Its normal cycle from submission to remittance is 17 days. Under prepayment review, with records requested and adjudicated, the cycle runs 62 days.

```text THE CASH EFFECT added days in the cycle 62 - 17 = 45 days monthly allowed under review = $26,400.00 additional receivable held 45/30 x 26,400 = $39,600.00

THE DENIAL EFFECT documentation error rate found on review = 12% monthly amount denied 26,400 x 0.12 = $3,168.00 annualized, if nothing changes x 12 = $38,016.00

THE LABOR EFFECT (in minutes; this book prices staff time in minutes rather than dollars - see Ch. 27 §27.7) claims requiring an ADR response per month = 60 minutes per response, clerical + coder = 40 to 90 monthly range 60 x 40 = 2,400 min = 40 hrs 60 x 90 = 5,400 min = 90 hrs ```

Checks: 26,400.00 × 1.5 = 39,600.00 ✓ · 26,400.00 × 0.12 = 3,168.00 ✓ · 3,168.00 × 12 = 38,016.00 ✓ · 2,400 ÷ 60 = 40 ✓ · 5,400 ÷ 60 = 90 ✓

The interpretation is the part to carry. The \$39,600.00 is not lost — it is held, and it comes back if the documentation holds. But a practice on a thin cash margin can be seriously injured by a receivable that grows by a month and a half of one service line's revenue while payroll stays weekly. A review that costs a practice nothing in denials can still be the reason it borrows. And the forty to ninety hours a month comes from somewhere: in a small practice it comes from the coder, which means the audit that would have prevented the review is the first thing that stops happening.

Getting off it

The intuition here is wrong, and correcting it is why the section earns its place. You do not appeal your way off prepayment review. Winning individual claims is necessary and insufficient; the reviewer put you on review because of a measured error rate, and only a measured error rate that has fallen takes you off. So: answer every ADR, on time — a non-response is scored as an error, so an unanswered request extends the review the response would have shortened. Read the denials for pattern, not for grievance — if eleven of fourteen say the same thing, the reviewer has written your corrective action plan for free. Fix it upstream and be able to show the date, because a dated corrective action plan (§37.10) with a re-audit attached is the artifact that supports a request for release. And talk to them: Medicare contractors publish provider outreach contacts and run one-on-one education as a formal part of Targeted Probe and Educate (§37.5).

⚠️ Where Claims Die

The records request that went to an address nobody reads. The most expensive administrative failure in this chapter, and it has appeared in this book twice in different clothes: Chapter 27's Case Study 1, where a daily acknowledgment report was delivered faithfully for fourteen months to a departed supervisor's mailbox, and Chapter 24's Case Study 1, where the only evidence of a problem was a returned envelope in a mailroom.

An ADR that is not answered is a 100% error rate on the claims it covers, and it is scored that way. The claim denies for insufficient documentation. On postpayment review, the same non-response creates an overpayment on a claim whose records would have supported it entirely.

The controls are unglamorous and they work. One named person opens every payer envelope and portal notification. Every ADR is logged the day it arrives, with its deadline, where others can see it. The address of record with each payer and contractor is verified annually and after any move, merger, or billing-vendor change. And somebody reads the log weekly — which is, once again, a report is not a control; a person who reads a report is a control.


37.5 The external alphabet: MAC, RAC, UPIC, SMRC, CERT, TPE

Medicare's review apparatus is a set of contractors with different mandates, different funding models, and very different meanings when their letters arrive. Confusing them is common and consequential: a CERT letter and a UPIC letter require completely different responses, and only one of them is a routine administrative event.

Read the table, then the notes.

THE MEDICARE REVIEW LANDSCAPE                    [structure; verify current
                                                  program parameters at CMS]

  PROGRAM   WHO / WHAT IT IS          LOOKING FOR        WHEN     CAN DO
  -------   ---------------------     ---------------    ------   ------------
  MAC       Medicare Administrative   improper payment   pre or   deny, recover,
            Contractor - your claims  by error; local    post     place on
            processor (Ch. 3 §3.3)    policy compliance           review, educate

  TPE       Targeted Probe and        one specific       pre      up to 3 rounds
            Educate - a MAC PROGRAM,  error, provider-   (usual)  + 1:1 education;
            not a separate entity     specific                    referral to CMS
                                                                  if it persists

  RAC       Recovery Audit            improper payments  post     identify over-
            Contractor - paid a       already made,      (mostly) AND underpay-
            CONTINGENCY FEE on what   over and under              ments; MAC does
            it finds                                              the recovery

  SMRC      Supplemental Medical      whatever CMS       usually  findings ->
            Review Contractor -       DIRECTS it to      post     referred to the
            national, project-based   review                      MAC to act on

  CERT      Comprehensive Error       a STATISTIC: the   post     the sampled
            Rate Testing              national improper           claim itself
                                      payment rate               can be recovered

  UPIC      Unified Program           FRAUD, waste,      either   payment
            Integrity Contractor      abuse - benefit             suspension,
                                      integrity, not              revocation
                                      error                       referral, law
                                                                  enforcement

The MAC already processes your Medicare claims (Chapter 3 §3.3). Its medical review work is governed by the Medicare Program Integrity Manual (CMS Publication 100-08), which is free and is the single most useful document in this section. A MAC can review before or after payment and is the contractor that effects most recoveries, including those other contractors identify.

Targeted Probe and Educate (TPE) is the MAC's structured program and the friendliest thing in the table, which readers routinely fail to believe. It is provider-specific and issue-specific: the MAC identifies one item where your data stands out, requests a small probe sample — on the order of twenty to forty claims — reviews them, and then provides one-on-one education about what it found. Providers who correct move on; providers who do not are re-probed, up to a defined number of rounds, and those still showing high error rates after the final round are referred to CMS, which can lead to extrapolation, prepayment review, or referral elsewhere. Verify the current round count and sample sizes; the parameters have been adjusted.

Treat a TPE letter as the cheapest audit you will ever receive. Small sample, specific feedback, education included — a genuine external audit of a real exposure for the cost of copying charts.

The Recovery Audit Contractor (RAC) is the one with the reputation, and the reputation has a documented history Case Study 1 tells properly. Two structural facts matter operationally. First, RACs are paid a contingency fee on what they find — a design decision with real consequences in both directions, and the reason the program has been contentious since it began as a demonstration under the Medicare Modernization Act of 2003 and was made permanent and national by the Tax Relief and Health Care Act of 2006. Second, RACs perform automated review (a data-only determination requiring no records — a duplicate, a units-versus-descriptor conflict, an edit violation), semi-automated review (data plus an opportunity to submit records), and complex review (a human reads records). The program is statutorily required to identify underpayments as well as overpayments, its issues must be approved by CMS and posted publicly before review begins, and record-request volumes are capped by rules tied to provider size. Read the approved-issues list for your RAC region — it is a published list of what is about to be reviewed, and almost nobody reads it.

The Supplemental Medical Review Contractor (SMRC) performs nationwide medical review on topics CMS assigns, frequently arising from OIG or Government Accountability Office reports, CERT data, or comparative billing analysis. The distinguishing operational fact: the SMRC does not recover money. It reviews and refers findings to the MAC, which acts — so an SMRC letter has a second act, and your response is read by whoever decides whether there is one.

Comprehensive Error Rate Testing (CERT) is not an audit of you. It is a measurement program: a random national sample of Medicare fee-for-service claims, reviewed to produce the published improper payment rate. Three things follow. The sample is random, so being selected means nothing about you. The resulting rate is an error rate, not a fraud rate — the largest documented contributor to it has persistently been insufficient documentation rather than incorrect coding, and a claim that was clinically appropriate and correctly coded counts as improper if the records do not establish it. And — the part people miss — your sampled claim is still a claim. Fail to respond and it is scored as an error and the payment can be recovered. A CERT request is low-stakes for your organization and high-stakes for the national number, which is exactly backward from how they are usually treated.

The Unified Program Integrity Contractor (UPIC) is a different category of event. UPICs consolidated the earlier zone- and region-based program integrity contractors into unified entities covering Medicare and Medicaid, and their mandate is benefit integrity: fraud, waste, and abuse, not billing error. A UPIC can conduct prepayment and postpayment review, request records, interview staff, make unannounced site visits, recommend payment suspension, and refer to law enforcement and to the OIG.

A UPIC contact is the point at which counsel is involved, before the response is written. That is not a dramatic recommendation; it is the ordinary standard of care. §37.9 develops the reasoning.

The rest of the landscape

Three more reviewers belong in the picture precisely because they are not Medicare contractors.

The OIG conducts audits and evaluations rather than claim-by-claim review, and its results become industry-wide expectations. Its Work Plan (§37.2) is your forecast; it also administers exclusion (Chapter 5 §5.5) and the self-disclosure route in §37.9.

Commercial payers run their own review, under your contract, not under federal rules. A commercial payer's special investigations unit (SIU) derives its authority — record-request rights, lookback period, recoupment mechanism, appeal path, and whether it may extrapolate at all — from the participation agreement the practice signed, plus state law. The Program Integrity Manual does not govern it. Account 31-2245 was reviewed by exactly this kind of unit, and §37.6 shows why the distinction is worth real money.

And risk adjustment has its own audit. Medicare Advantage plans and their contracted providers are subject to risk adjustment data validation (RADV) audits, in which a sample of the diagnoses submitted for payment is checked against the medical record. Chapter 36 §36.8 owns chart review; what belongs here is that a diagnosis reported for risk adjustment must be supported by a record from the date it was reported, and RADV is where that is tested.

⚖️ Compliance Check

Everything in this section changes. Contractor names, jurisdictions, sample-size limits, round counts, lookback periods, and approved-issue lists are all revised — some annually, some continuously, some by contract award. The structure transfers; the parameters do not. Verify each at CMS, in the current Medicare Program Integrity Manual, and on your own MAC's and RAC's websites.

Identify the sender before you respond. A CERT request, a TPE probe, a RAC complex review, an SMRC project, and a UPIC investigation call for four different documents and one phone call to counsel. The letterhead tells you which. If you cannot tell, call and ask what program the request is under, and write down the answer.

And this chapter is not legal advice, as no chapter of this book is. Program integrity is governed by federal statute and regulation, by state law where a commercial payer or Medicaid is involved, and by payer contracts that vary and change without notice. Your compliance officer and your counsel are the authorities on what your organization should do; this chapter is the vocabulary that lets you have the conversation.


37.6 Extrapolation, and the arithmetic that turns 42 claims into a number

Here is the mechanism that makes an audit finding into a business event, and the reason this book has been pointing at it since Chapter 17.

Extrapolation is the practice of reviewing a probability sample of claims from a defined universe, computing an overpayment rate or amount from the sample, and projecting that result across the whole universe to produce a demand. The reviewer does not read every claim. It reads enough of them to make a defensible statistical statement about all of them.

Statistical sampling is the discipline that makes the projection defensible: the universe is defined, the sampling frame is enumerated, units are drawn by a documented random method, and the estimate is reported with a stated precision.

The samples are small, and that is the whole point. Chapter 15 §15.12 already told you the range — a reviewer commonly pulls ten to thirty encounters — and Chapter 5 §5.5's illustration is a twenty-claim sample. Nothing about a small sample limits the size of the demand, because the demand is not a function of how many claims were read. It is a function of how many claims exist. A twenty-chart audit and a two-hundred-chart audit of the same universe produce roughly the same estimate; the larger one produces a tighter one, which — as the arithmetic below shows — moves the demand up, not down. Anyone comforted by "they only looked at twenty" has the relationship backward.

What actually happened on Account 31-2245

Return to Ridgeview Orthopedic Surgery (constructed), an eight-surgeon group. A shoulder arthroscopy with rotator cuff repair, billed as three lines, with 29822 carrying modifier 59 appended by a billing macro rather than by a coder reading an operative report (Chapter 17 §17.9; Chapter 21 §21.9). A commercial payer's special investigations unit reviewed 42 claims over 18 months with the identical pattern and demanded:

   42 claims  x  $612.40 average overpayment  =  $25,720.80     [Account 31-2245]

That is not an extrapolation. It is a census. The unit reviewed every claim carrying the pattern — all forty-two of them — and demanded the actual overpayment on each. Nothing was projected onto anything.

Say that out loud, because the reason it matters is the whole section: the demand on Account 31-2245 is small because the practice is small. Forty-two claims was the entire population. Change nothing about the error — the same macro, the same modifier, the same operative notes, the same \$612.40 — and make the group larger, and the payer stops reading every claim and starts sampling.

The same error at scale

🧮 Run the Numbers

The counterfactual. [constructed extension of Account 31-2245 — the universe size, the standard deviation, and the confidence level are teaching figures. The 42 claims and the \$612.40 average are the file's frozen facts.] Suppose Ridgeview Orthopedic had been a forty-surgeon multi-site group and the same macro had run on 380 claims over the same eighteen months. The special investigations unit does not read 380 operative notes. It draws a random sample of 42 — the same number it actually read — and projects.

```text THE UNIVERSE N = 380 claims containing 29827 with 29822-59, same date, dates of service inside an 18-month window

THE SAMPLE n = 42 claims, drawn at random from the enumerated frame mean overpayment per sampled claim .............. $612.40 sample standard deviation ....................... $286.00

THE POINT ESTIMATE 380 x $612.40 = $232,712.00

THE PRECISION standard error 286.00 / sqrt(42) = 286.00 / 6.4807 = $44.13 t, 41 degrees of freedom, 90% two-sided ............ ~ 1.683 margin of error 1.683 x 44.13 .................... $74.27

THE LOWER BOUND (what is actually demanded) lower limit of the mean 612.40 - 74.27 = $538.13 DEMAND 380 x $538.13 = $204,489.40 ```

Checks: 612.40 × 380 = 232,712.00 ✓ · 286.00 ÷ 6.4807 ≈ 44.13 ✓ · 1.683 × 44.13 = 74.27 ✓ · 612.40 − 74.27 = 538.13 ✓ · 538.13 × 380 = 204,489.40 ✓ · 232,712.00 − 204,489.40 = 28,222.60, which is 380 × 74.27 ✓

Read the last two lines together. The payer's best estimate of what it overpaid is \$232,712.00**. What it demands is **\$204,489.40 — the lower end of a confidence interval, because the uncertainty introduced by sampling is resolved in the provider's favor rather than the payer's. That is a genuine concession and it is written into the methodology.

And it is still roughly eight times the actual demand on Account 31-2245. Same macro, same error, same average, same forty-two claims read by a human being. The difference is volume, and volume is the multiplier extrapolation exists to apply.

(A refinement, named for honesty and left out of the arithmetic above: when the sample is a meaningful fraction of the universe — here 42 of 380, about 11% — a finite population correction narrows the interval slightly, which raises the lower bound and increases the demand. The correction works against the provider. Its effect at this ratio is small; at a 50% sampling fraction it is not.)

The rules, and who they bind

For Medicare, extrapolation is governed by statute and by the Medicare Program Integrity Manual, and the constraints are real:

  • It is not automatic. Section 1893(f)(3) of the Social Security Act permits extrapolation only where there is a determination of a sustained or high level of payment error, or where documented educational intervention has failed. That precondition is the first thing a response should test.
  • The design must be documented and you are entitled to it — the universe definition, the sampling frame, the sample-size determination, the random selection method, and the estimation formula. Ask for all of them in writing.
  • The demand is a lower bound at a stated confidence level, not the point estimate. CMS's methodology directs contractors to a standard level — the lower limit of a two-sided 90 percent interval in the ordinary case. Verify the current text; this methodology was substantially revised in recent years and can be again.
  • Statistical validity is appealable at every level of the Medicare appeal process (Chapter 30 §30.6), not merely the individual claim determinations, and administrative law judges do adjust extrapolations.
  • Winning claims in the sample can change the projection. Ask for recalculation explicitly; it is not always automatic.
  • The government's own sampling software is public. The OIG publishes RAT-STATS free — a provider can use the same tool to quantify its own exposure, which matters enormously in §37.9.

For a commercial payer, none of that necessarily applies. The SIU's authority to extrapolate, the confidence level, the lookback, and the dispute process come from the participation agreement and from state law, some of which now regulates payer audits and extrapolation directly. Read your contract before you need to — the operational conclusion of §37.8, arrived at here from a different direction.

📋 Read the Chart

text FIGURE 37.3 — "The methodology page" [Account 31-2245 - constructed; the counterfactual universe] THE DOCUMENT Page 3 of a payer's audit findings letter: the sampling and estimation methodology, which is where every meaningful challenge lives. THE CONTEXT Postpayment review by a commercial payer's special investigations unit. Pages 1-2 described the coding issue; page 4 states the demand and the appeal rights. WHAT IT SHOWS UNIVERSE claims paid to TIN xx-xxxxxxx with procedure 29827 and procedure 29822 with modifier 59 on the same date of service, DOS 18-month window. N = 380 FRAME claim-level, one unit per claim, enumerated from the payer's paid-claims file SAMPLE n = 42, simple random sample without replacement, selection performed [date] ESTIMATOR mean per unit; overpayment projected as N x lower limit of a two-sided 90% CI RESULT point estimate $232,712.00 demand (lower limit) $204,489.40 WHAT IT DOESN'T It does not show the SEED or the selection list, so the draw cannot be reproduced. It does not say whether claims with a documented distinct anatomic site were excluded from the universe or left in it - which decides whether the universe is "claims with the pattern" or "claims with the CODES." It does not state the contract provision authorizing extrapolation. Every one of those is a written question. THE DECISION Do not argue the coding first. Ask, in writing, for the selection list, the frame, the sample-size rationale, the contract provision, and the definition of the universe. Then argue the coding. THE LESSON The methodology page is the highest-leverage page in the letter, and it is the page nobody reads. An error in the universe definition moves every dollar in the demand; an error in one chart moves $612.40.

Why consistency makes it worse

Chapter 26's Case Study 1 ended by asking students why a consistent error is more expensive than an inconsistent one. It is one of the least intuitive facts in the revenue cycle, and there are four reasons, three of them arithmetic.

First, consistency shrinks the confidence interval, and the interval was your discount. The margin of error in the arithmetic above is driven by the sample's standard deviation. Run the same universe, the same 42-claim sample, and the same \$612.40 average — but produced by a macro so uniform that the overpayments barely vary:

   THE SAME AUDIT, TWO ERROR PATTERNS          [constructed teaching figures]

                          messy error        consistent error
   sample std deviation      $286.00               $52.00
   standard error             $44.13                $8.02
   margin (1.683 x SE)        $74.27               $13.50
   lower limit of the mean   $538.13              $598.90
   DEMAND (x 380)        $204,489.40          $227,582.00

   the price of being consistent   227,582.00 - 204,489.40  =  $23,092.60

Checks: 52.00 ÷ 6.4807 ≈ 8.02 ✓ · 1.683 × 8.02 = 13.50 ✓ · 612.40 − 13.50 = 598.90 ✓ · 598.90 × 380 = 227,582.00 ✓ · 227,582.00 − 204,489.40 = 23,092.60 ✓

\$23,092.60 more, for the same average error, because the error was reliable. Statistical uncertainty is the only thing standing between the point estimate and the demand, and a consistent error removes it.

Second, consistency satisfies the precondition. Extrapolation under Medicare requires a sustained or high level of payment error. An error that appears on forty-two consecutive claims is the textbook demonstration of "sustained." An error that appears on nine of forty-two, sporadically, is a much harder case for the contractor to make before it may project anything at all.

Third, the sample defends itself. With a consistent error, every reviewed claim shows the same finding, so "this claim was different" has no purchase. With a scattered error, the provider has a real argument that the universe is heterogeneous, that the design should have been stratified, and that a single mean is the wrong estimator — and that argument can win.

Fourth, and this is the part worth sitting with: the consistent error is the disciplined one. Sloppiness produces variance. What produces uniformity is a rule, followed carefully, by people doing their jobs — a macro, a template, a standing instruction, a convention everyone was taught in orientation. Every configuration in §37.2's collection produced a perfectly consistent assertion, which is exactly why each of them extrapolates cleanly. The organization most careful about doing things the same way every time is the organization whose one wrong thing is worth the most. That is not an argument for inconsistency. It is an argument for auditing the rule as well as the work, which is what §37.10 is about.

The provider's options, and the one that could not be exercised

When a demand arrives, there are five real responses and they are not exclusive. Pay it, and put the corrective action in place — sometimes correct. Challenge the methodology, per Figure 37.3. Appeal the individual claims — under Medicare through the five levels of Chapter 30 §30.6, under a commercial contract through whatever the agreement provides — and request recalculation of the projection on the survivors. Offer a full-population review in lieu of the extrapolation, which is sometimes available and sometimes worth it: if you genuinely believe a substantial share of the universe is defensible, reading all 380 charts may cost less than the projection, though the reviewer is not obliged to accept. And manage the cash — Medicare offers extended repayment schedules; commercial recoupment is governed by the contract and by state prompt-pay and offset law, and Chapter 31 §31.9 owns the mechanics.

And now the sentence this file exists to teach. The practice's own internal review found that 11 of the 42 claims were separately documented and defensible — the debridement really had been performed in a different anatomic region. Option 3 was available, correct on the merits, and worth 11 × \$612.40 = **\$6,736.40, which would have reduced the demand to \$18,984.40** (Chapter 17 §17.9).

They could not prove it. The operative notes said "debridement performed" and did not establish a distinct anatomic site, and nothing written eighteen months later could make them say so. The surgeons remembered. Memory is not documentation.

Scale that to the counterfactual and the loss is not \$6,736.40 — it is eleven forty-seconds of a two-hundred-thousand-dollar demand, unrecoverable for want of one clause in a dictated sentence. The defense against an extrapolation is not built when the letter arrives. It is built one note at a time, years earlier, by people who have no idea they are building it.


37.7 Responding to a records request

The records request is where most organizations lose audits they would have won, and the reason is almost never the coding. It is that the response was treated as an errand rather than as a product.

A records response is a document you are producing for a hostile reader on a deadline. Everything below follows from that sentence — and two rules from Chapter 4 govern before the first page is copied.

What you produce for an audit is defined by policy, not by convenience. Chapter 4 §4.8 built the legal health record and the designated record set precisely so this question would have an answer that exists before anyone asks it. A practice that decides, on the day the letter arrives, what counts as "the record" is making a disclosure decision under time pressure, and it will make a different decision next time.

And never amend a record in response to a records request. Send what you have. Chapter 4 §4.5 governs amendments, addenda, and late entries, and every one of its requirements — identify the author, date the entry, preserve the original, state that it is an addendum — is designed to keep an amendment honest. An amendment dated after a request has arrived is presumptively about the request, regardless of what it actually says, and it converts a documentation finding into a credibility problem. If the note is thin, the note is thin. Concede it (§37.8) and fix the template going forward.

The nine steps

RESPONDING TO A RECORDS REQUEST                    [operational checklist]

  1  LOG IT THE DAY IT ARRIVES.  Central log, visible to more than one
     person: date received, sender, program, claims listed, DEADLINE,
     owner. The deadline is calculated from the letter's date, not
     from the day somebody found it.

  2  IDENTIFY THE PROGRAM.  MAC / TPE / RAC / SMRC / CERT / UPIC /
     commercial SIU. The program decides who writes the response, what
     rights you have, and whether counsel is involved before you answer.

  3  CALENDAR IT BACKWARD.  Ship date, then internal completion date,
     then physician-signature date if an attestation is needed. Never
     plan to finish on the deadline.

  4  DEFINE "THE RECORD" FOR EACH CLAIM.  Not just the office note:
     the order, the results, the procedure note, the consent, the
     signature, the itemized statement where relevant, and anything
     the code itself requires (Ch. 4 §4.8, the legal health record
     and the designated record set).

  5  CHECK THE SIGNATURE FIRST.  An unsigned or illegible authenticating
     signature is the most common technical denial in medical review and
     it has nothing to do with coding (Ch. 4 §4.4). Where a signature is
     present but illegible, a signature log or an attestation statement
     is generally accepted. Where a signature is ABSENT, it is not.

  6  SEND WHAT WAS ASKED FOR, COMPLETELY, AND NOTHING ELSE.  Complete
     for the claims requested; not the whole chart for unrelated years.
     This is a permitted disclosure for payment operations, and the
     minimum-necessary discipline still applies (Ch. 5 §5.7).

  7  BUILD IT AS A DOCUMENT.  Cover sheet listing the claims and what
     is enclosed per claim, page numbers, tabs or bookmarks, in the
     order the reviewer will read it. Reviewers work under time
     standards too.

  8  KEEP AN EXACT COPY OF WHAT YOU SENT, and the proof of sending.
     Tracking number, portal confirmation, or electronic submission
     receipt. The copy is the evidence in any later dispute about what
     the reviewer had.

  9  CONFIRM RECEIPT, then diary the response due date.

Three of those nine deserve a sentence of their own.

Step 4 is where audits are lost quietly. A claim for an injection is supported by the procedure note and by the order, the drug and dose, the site, and the consent. A claim for a laboratory test is supported by the order and the treating provider's documentation of why. Chapter 22 §22.6's diagnosis linkage is a documentation requirement, not merely a claim field, and a packet containing the service but not the reason for it hands the reviewer a "not medically necessary" finding for free.

Step 6 is a genuine judgment call and both errors are real. Send too little and the reviewer denies for insufficient documentation. Send indiscriminately and you have made an unnecessary disclosure of protected health information about encounters nobody asked about — and handed a reviewer material it did not request and may act on. The rule is complete for what was asked, bounded to what was asked.

And step 8's copy is not bureaucratic. Chapter 27's Case Study 2 turned on exactly this: the practice's copy of a claim and the payer's copy were accurate records of different files, and the finding came from retrieving what had actually been transmitted. A correct outcome is not evidence of a correct process, and the only way to know what a reviewer read is to keep what you sent.

📞 On the Phone

Calling the contractor's provider line, day 31 of a 45-day window.

You: "I'm calling about an additional documentation request, letter dated the second, twelve claims. I want to confirm three things: the submission address or portal you want these in, whether you accept electronic submission for this request, and whether the deadline runs from the letter date or from receipt."

The representative: "It runs from the date on the letter. You can send them through the portal or by mail to the address in the letter; the portal gives you a confirmation number."

You: "One of the twelve is a claim where the rendering physician left the practice in March. The note is signed but the signature is a scanned image and it's not legible. Do you want a signature log, an attestation, or both?"

The representative: "Send the signature log with the packet. If it's still a question, we'll ask."

What made that call worth three minutes. Nothing in it was about coding. It established the clock's start date — which people routinely assume runs from receipt and it usually does not — confirmed the channel, and pre-empted the most common technical denial in medical review before it happened.

The failure mode to expect: the representative cannot answer, answers a different question, or gives an answer the letter contradicts. The letter governs. Write down the name, the reference number, the date, and what was said — and follow the letter. A phone call is evidence of diligence; it is not authority.


37.8 The audit response letter

The findings arrive. Somebody has to answer them, in writing, by a date. This is the most consequential piece of writing most revenue cycle professionals ever do, and the craft of it is learnable — because you have already learned it. An audit response is Chapter 30 §30.3's appeal letter pointed the other direction. The appeal argues that a payer's determination does not survive your documentation; the response argues that a reviewer's finding does not survive it. Same evidence hierarchy, same discipline about quoting rather than characterizing, same refusal to argue anything the record does not carry. The only structural difference is that an appeal answers one determination and a response answers a table of them at once.

Three postures, and the one that destroys credibility

Every finding gets exactly one of three answers: agree, agree in part, or disagree — and the response letter is organized finding by finding so a reviewer can see which is which without reading prose.

Disagreeing with everything is the mistake. It is understandable — the letter feels like an accusation and the instinct is to defend — and it is self-defeating, because a reviewer reading a blanket denial learns that your assessments carry no information. Conceding a finding you cannot defend is not a loss. It is what makes the rest of the letter believable, and it is also, separately, the honest thing to do.

The response's spine:

THE AUDIT RESPONSE LETTER                             [structure]

  COVER LETTER  (one page)
    - what you received and when; the claims at issue
    - the summary result: agreed on N, disagreed on M, and the
      resulting dollar position, stated plainly
    - what is enclosed, and how it is organized
    - the corrective action already taken, with dates
    - who to contact

  THE FINDINGS TABLE  (one row per claim)
    claim | DOS | finding as stated | our position | authority | exhibit

  THE ARGUMENT  (one short section per DISAGREED finding)
    - the finding, restated in the reviewer's own words
    - the authority WE rely on, quoted, with a citation the
      reviewer can look up
    - the record language that satisfies it, QUOTED, with an
      exhibit and page reference
    - one sentence of conclusion. No adjectives.

  THE METHODOLOGY SECTION  (only where extrapolation is applied)
    - the questions from Figure 37.3, in writing

  EXHIBITS
    - the records, paginated, tabbed, in the table's order

Four principles decide whether it works.

Cite the authority the reviewer cited. If the finding rests on the NCCI Policy Manual, answer from the NCCI Policy Manual. Arguing coverage policy against a bundling finding, or clinical appropriateness against a documentation finding, reads as a change of subject even when it is true. Chapter 30 §30.4's evidence hierarchy for appeals is the same instrument turned around.

Quote your own record; do not characterize it. "The operative note documents debridement in a distinct anatomic region" is an assertion. "The operative note at Exhibit 4, page 2, states: 'Debridement was performed in the subacromial space, anatomically distinct from the repaired supraspinatus insertion'" is evidence. If you cannot produce the quotation, you do not have the argument — which is precisely why eleven of Account 31-2245's forty-two claims were paid back.

Never explain what the provider meant. Chapter 4 §4.7's line is absolute and it does not soften in a response letter. The record says what it says. If the record is silent, the correct response is to concede the finding and state the prospective correction — not to reconstruct intent, and under no circumstances to amend the note now. Chapter 4 §4.5 governs amendments, addenda, and late entries, and a late entry created after a records request is the worst document in the file.

And show the correction. A response letter that answers the findings and stops has answered half the question. Attach the corrective action plan (§37.10): what changed, on what date, who owns it, and when you will re-audit. An unmeasured function is indefensible — Chapter 24's Case Study 2 — and a response letter is the moment that becomes concrete. An organization that can attach twelve quarters of its own audit results is in a different conversation than one that cannot.

📋 Read the Chart

```text FIGURE 37.4 — "Two paragraphs of a response" [Account 31-2245 - constructed teaching example] THE DOCUMENT Two entries from the argument section of the practice's response to the special investigations unit's findings letter. THE CONTEXT 42 claims at issue. The practice agrees on 31 and disagrees on 11 - the eleven its own review found defensible. WHAT IT SHOWS CLAIM 07 - AGREED. "The finding is correct. Procedure 29822 was reported with modifier 59 on the same date as 29827. The operative note at Exhibit 7, page 2, does not identify an anatomic site for the debridement distinct from the repaired structure. Under the NCCI Policy Manual and the modifier 59 definition, the modifier is not supported. We do not contest the overpayment on this claim."

CLAIM 19 - DISAGREED.  "The operative note at Exhibit 19, page 3,
  states: 'Extensive debridement of the glenohumeral joint was
  performed prior to addressing the subacromial space.' We
  submit this documents a distinct anatomic region. We note that
  the finding letter does not address this sentence."

THE METHODOLOGY REQUEST.  "We request the sample selection list,
  the enumerated frame, the sample-size determination, and the
  contract provision under which extrapolation is applied."

WHAT IT DOESN'T Neither entry argues that the practice meant well, that the macro was a vendor's fault, or that the surgeons recall the cases. All three are true. None is evidence, and including them would weaken the eleven arguments that ARE evidence. THE DECISION Concede 31 in the first paragraph of the cover letter. Spend the letter on the 11. THE LESSON The response that concedes fast is the response that gets read carefully. And the difference between claim 07 and claim 19 is not the surgery - it is whether somebody wrote a sentence eighteen months earlier. ```

The commercial-purpose pattern

Now a pattern this book has produced four times and never named. Four case-study findings — genuinely consequential ones, running for years — arrived because somebody read payer or practice materials for a commercial purpose:

Case The commercial event What the reading found
Ch. 23 CS2 acquisition due diligence a measurement failure in which nothing on any claim was wrong
Ch. 24 CS2 contract negotiation an unmeasured function nobody could defend
Ch. 25 CS2 contract renewal a workaround that had become institutional knowledge
Ch. 26 CS2 an ownership-structure review a billing rule that had been wrong since the entity changed shape

In not one of those cases did a control find the problem. In not one was anybody looking for it. In every one, the finding arrived because a transaction created a reason for somebody to read a document carefully — and, crucially, somebody with no history with the document and different incentives from the people who wrote it.

Name the pattern plainly: the only time most organizations read their own agreements and their payers' policies is when money is being negotiated.

The operational conclusion is one sentence: schedule the reading without waiting for the transaction. Concretely, and cheaply: an annual contract read — one payer a month, the whole agreement, by somebody who did not negotiate it, producing a written list of every provision that imposes an operational obligation (filing deadlines, reconsideration windows, records-request rights, recoupment and offset terms, audit and extrapolation provisions, the amendment mechanism); a payer policy calendar, each major payer's update bulletin read on publication by a named person; a fee schedule reload check, which is Chapter 28's Case Study 2 turned into a standing question — "which fee schedule year did you load?"; and a rotating outside read, an external audit or an auditor borrowed from another site. The value of the last one is not superior expertise. It is the absence of history.

The report that never arrived

Turn the pattern around and it produces the most useful diagnostic in this chapter.

If the only readings your organization gets are the ones a transaction pays for, then the readings your own staff could have given you are not arriving. Chapter 21 §21.10 drew the contrast in its plainest form: an unbundling problem has two possible stories — one in which a pattern ran for eighteen months and a payer found it, and one in which a coder found something, reported it internally, and it got fixed. Everything here is about making the second story the likely one, and it depends almost entirely on what happened to the first report anyone ever made.

An organization with zero internal reports does not have zero problems. State it that flatly, because the inference people draw is the opposite one. A compliance log with no entries reads as evidence of a clean operation; it is evidence about a channel, and a channel with no traffic is unknown, untrusted, or unanswered. Case after case in this book had somebody who noticed — Chapter 14's new biller, Chapter 19's coder who had known for months, Chapter 29's front-desk manager who was being blamed by the data. Several times the noticing came years before the finding, and the gap was not perception. There was nowhere to put it.

So count the reports and treat the count as a metric. Not the number of problems — the number of times somebody said something and got a written answer. It is the most reliable indicator of a compliance program's actual health available to a practice, it costs nothing to measure, and it is the only compliance number that goes up when things are going well. A report count of zero is a problem with the channel, not evidence about the claims — and §37.10 designs the channel.

The internal report and the outside reading are the same instrument aimed from opposite ends. One is somebody inside with knowledge and no standing; the other is somebody outside with standing and no history. An organization that has neither is relying on a payer to audit it, which is the most expensive reading available.

"Build better controls" — is that a sufficient answer?

Chapter 23's Case Study 2 ended by asking flatly whether "build better controls" is a sufficient response to findings like these. It has been unanswered for fourteen chapters. The book's position is no — necessary, and not sufficient — in three parts.

One: a control can only be built for a failure that has been imagined. Every control is a statement about a known failure mode; Chapter 21's edit checks catch bundling because somebody knew bundling existed. Each of the four commercial-purpose findings was a failure mode nobody in the organization had named — which is why it ran for years. You cannot write a control for a question nobody asked. Control-building is inherently retrospective: excellent at preventing the recurrence of what you have already survived, structurally blind to what you have not.

Two: controls decay, and the decay produces no signal. Chapter 28's Case Study 1 is the cleanest instance in the book — a posting rule, "any CO becomes a contractual adjustment," correct when written, correctly implemented, and no longer correct after a payer changed its edits. Nothing inside the practice happened on the day it stopped being right. A control is a claim about a world, and the world is revised on a schedule this book has been reciting since Chapter 6.

Three, and decisively: a control tests conformance; an adversarial reading tests the premise. A control asks are we doing what we decided? Every one of the four findings was an organization doing exactly what it had decided, competently, for years. The question that found them was was what we decided right? — and only a reader with no stake in the previous answer reliably asks it. That is not a control. It is a scheduled adversarial reading, and it is a separate line item.

So: build the controls, and separately buy the reading. They catch different things and neither substitutes for the other. And the deflating truth underneath the pattern is worth stating without flinching: the reason due diligence finds things is not that the buyer is smarter. It is that the buyer is the first person in six years with a reason to read.

Which is also, precisely, what an audit is — and why the internal audit function in §37.2 is worth its eight hours a quarter. An audit is an adversarial reading an organization schedules for itself instead of waiting for someone to buy it.


37.9 Self-disclosure and the sixty-day clock

An audit found a pattern. Not one claim — a pattern, across a period, with money attached. Somebody now has to decide what the organization is obliged to do about it, and this section is that decision layer.

Be exact about what belongs to whom. Chapter 5 owns the legal frame — the False Claims Act, the theory of a false certification, the difference between error and fraud, and the sixty-day overpayment provision as law. Chapter 31 §31.9 owns the operational workflow — how an identified overpayment is quantified, refunded, recouped, and posted. This section owns the part between them: when a pattern becomes a reportable obligation, and which door you walk through.

The clock, and what starts it

The Affordable Care Act added a provision to the Social Security Act requiring that a person who has received an overpayment from Medicare or Medicaid report and return it within 60 days of the date on which the overpayment was identified, or the date any corresponding cost report is due, whichever is later. Chapter 5 §5.1 stated the consequence in one sentence — retaining a known overpayment is itself a violation — and Chapter 5 §5.3 supplied the mechanism: the False Claims Act reaches not only false claims for payment but the knowing concealment or improper avoidance of an obligation to pay money to the government. A retained overpayment past the deadline is that obligation, and the theory has a name worth knowing: the reverse false claim. Nothing was submitted; money was kept.

The operative word is identified, and it does not mean "suspected."

  • Identification generally requires two things: knowing an overpayment was received, and quantifying it. A credible indication that something may be wrong is not an identified overpayment. A quantified conclusion is.
  • But you do not get to not look. The standard contemplates a timely, good-faith investigation of credible information. An organization that receives a credible indication and does nothing does not avoid identification — it creates a much worse fact pattern, because the failure to investigate is itself what an enforcement authority will describe.
  • The investigation window is where quantification happens, and where §37.6's sampling belongs: a provider may use statistically valid sampling to quantify its own overpayment across a period, with the same public tools a contractor uses.
  • A lookback period applies, and both it and the identification standard have been revised by rulemaking more than once. Verify the current regulatory text and timeframes — a book that printed today's number as permanent would be wrong within a rulemaking cycle.

The practical translation: the day your investigation produces a number, the clock is running, and sixty days is not enough time to also decide what kind of problem you have. Which is why the decision below is made before the number exists, not after.

The decision: four doors

WHICH DOOR                                    [structure - not legal advice]

  WHAT YOU FOUND                          WHERE IT GOES
  ------------------------------------    --------------------------------
  A billing or coding ERROR, quantified,  REFUND to the payer / MAC through
  no indication of intent, no kickback    the voluntary refund or self-
  or self-referral issue                  reported overpayment process.
                                          Ch. 31 §31.9's workflow. This is
                                          the overwhelming majority of
                                          findings and it is not a
                                          "disclosure" in the special sense.

  Conduct that may violate a federal       OIG SELF-DISCLOSURE PROTOCOL
  law for which CIVIL MONETARY PENALTIES   (SDP). Published, with defined
  are authorized: false or fraudulent      content requirements and minimum
  billing, employing an EXCLUDED person,   settlement amounts. Ch. 5 §5.5
  Anti-Kickback Statute conduct            owns exclusion and CMPs.

  An actual or potential violation of      CMS VOLUNTARY SELF-REFERRAL
  the PHYSICIAN SELF-REFERRAL LAW          DISCLOSURE PROTOCOL (SRDP).
  (Stark) and nothing else                 Stark ONLY. Ch. 5 §5.4.

  Conduct that may have been KNOWING       COUNSEL FIRST, and counsel
  and willful; a UPIC contact; a           decides the route, which may
  subpoena; a whistleblower               involve the Department of Justice.

Three things make that table usable.

Stark is strict liability, and that is why it has its own protocol. A financial relationship can violate the physician self-referral law without anyone intending anything, which means "we did not mean to" is not a defense and an ordinary refund is not a resolution. The SRDP exists because the ordinary route does not fit.

The OIG's protocol carries real, documented benefits, and they are the reason to use it rather than hope. The published protocol describes a lower multiplier of single damages than a litigated case typically produces, a general presumption against requiring a corporate integrity agreement for disclosing parties, and — operationally most important — the sixty-day obligation is tolled from the date of an acceptable submission while the matter is resolved. It also has minimum settlement amounts and specific content requirements, including a description of the conduct, the corrective action, and a damages estimate computed by a described methodology. Verify the current terms; they are published and they are revised.

And the routing decision is not a coder's to make. Chapter 5 §5.9 covered what to do when you are told to code something you cannot defend. The corollary here is narrower and just as firm: a coder or auditor who finds a pattern escalates it, in writing, with the evidence and the quantification, to the compliance officer or the practice's designated compliance contact. They do not call the payer, they do not characterize the conduct, and they do not decide which door. Writing down what you found and when you found it is the whole of your obligation and it is not a small one — Chapter 29 §29.9's discipline for a declined analysis applies exactly.

When counsel is involved, and why "early" is the answer

Three triggers, none of them dramatic: any indication that conduct may have been knowing — someone who raised it and was overruled, someone who benefited, a pattern that continued after somebody said it should not; any contact from a program integrity contractor, law enforcement, or a subpoena, which puts a UPIC letter (§37.5) in this category by definition; and before any disclosure is submitted and before the investigation goes far, because how an internal investigation is structured determines whether its work product is privileged, and that cannot be decided retroactively.

The reason to involve counsel early is not that lawyers make the problem go away. It is that the investigation is itself a set of documents, and those documents will exist regardless. The choice is not whether to create a record. It is whether the record is created deliberately.

⚖️ Compliance Check

This section describes structure. It is not legal advice and cannot be used as any. The sixty-day provision, the identification standard, the lookback period, and the disclosure protocols are governed by federal statute and regulation that have been amended repeatedly; state law and Medicaid rules add requirements; and a commercial payer's overpayment terms come from a contract, not from any of this. Verify the current text at CMS and the OIG, and involve your compliance officer and counsel before you act.

Three things that do not change.

A refund is not an admission of fraud, and a self-disclosure is not a confession. Both are mechanisms the system provides on purpose. Treating an ordinary quantified overpayment as a catastrophe produces the worst outcome available: paralysis, then retention, then an obligation.

The direction of an error decides which chapter applies. An underpayment is Chapter 28 §28.8 and a reconsideration window. An overpayment is Chapter 31 §31.9 and a clock. The same audit produces both, and they are tracked separately — never netted against each other.

And do not investigate a compliance question by asking the payer. A provider-services representative gives a spoken opinion with no authority behind it, creates a record you do not control, and answers nothing. Written payer policy, the manual, the regulation, and your compliance officer are the sources.


37.10 The corrective action plan that actually corrects something

A finding without a corrective action plan (CAP) is a complaint. Most CAPs are complaints with a training slide attached.

A corrective action plan is a written commitment that names a finding, its root cause, the specific change that will prevent recurrence, the person responsible, the date, the test that will demonstrate whether the change worked, and the re-audit that runs the test.

Six fields. A CAP missing the last two is an intention.

The durability ladder

Most organizations reach for the weakest intervention first, and it is the one that decays fastest.

CORRECTIVE ACTIONS, RANKED BY DURABILITY        [strongest at the top]

  1  MAKE THE ERROR IMPOSSIBLE
     Remove the option. Turn off the macro. Change the configuration
     so the assertion cannot be made without a person making it.
     Survives turnover, training gaps, and busy Fridays.

  2  MAKE IT VISIBLE BEFORE THE CLAIM LEAVES
     A scrubber edit, a pre-bill hold, a required field, a second
     read on a defined population (Ch. 6 §6.5). Costs throughput;
     buys certainty.

  3  MAKE IT VISIBLE AFTER THE CLAIM LEAVES
     A report - WITH A NAMED READER AND A RESPONSE OBLIGATION.
     Ch. 27 CS1: a report is not a control; a person who reads a
     report is a control.

  4  TELL PEOPLE
     Education, a memo, a huddle, a policy. Necessary. Decays with
     turnover, volume, and time. NEVER the whole plan.

  Most CAPs stop at 4. Most findings recur.

The distinction underneath the ladder: education changes what a person knows; a control changes what the system permits. Both are needed. Only one is still working in eighteen months, after the person who attended the training has moved to a different practice.

Two warnings the ladder does not show. A stronger control is not always the right control — turning off a macro that is right 96% of the time creates ninety-six new manual decisions to buy four corrections, and manual decisions have their own error rate. The question is not "what is the strongest intervention?" but "what is the strongest intervention whose cost is smaller than the error's?"

And watch for effort absorbing the defect. Chapter 25's Case Study 2 gave this book two sentences that belong in every CAP review: "a workaround that mostly works becomes institutional knowledge," and "a team keeping up with a problem prevents anyone from noticing the problem." If your corrective action is a person checking something manually every day, you have not corrected anything — you have hired the defect a caretaker, and the day that person is out, the defect ships. Worse, the caretaker's competence is exactly what stops anyone from escalating it.

The one control that catches an assertion nobody chose

Chapter 17's Case Study 1 asked students to write the single control that would have caught the whole family of configurations §37.2 collects, and to say whether one control can do it. Here is the book's answer — and then, because every rule in this book gets its limits in the same breath, what it does not reach.

The assertion register.

An inventory of every place an assertion can be made about a claim or an encounter by something other than a person deciding about that claim — each entry naming what it asserts, where the assertion lands, whose voice it speaks in, a named owner, and an evidence test run against a real claim the configuration touched.

Five fields per entry, and each of them is doing work:

THE ASSERTION REGISTER - one row per assertion-maker

  WHAT IT IS        a macro, template, default, standing order,
                    crosswalk, mapping, posting rule, favorites list,
                    auto-appended modifier, auto-inserted sentence,
                    pre-printed form, or SCRIPT GIVEN TO A PERSON

  WHAT IT ASSERTS   in plain language, as a claim about the world:
                    "a valid ABN is on file" - "this service was
                    distinct" - "medical necessity is documented" -
                    "this adjustment is contractual" - "the provider
                    performed a significant separate evaluation" -
                    "this patient can pay and should be asked again"

  WHERE IT LANDS    the field, line, note section, or conversation it
                    writes to, and WHOSE VOICE IT SPEAKS IN:
                      the practice's ........ correctable on a claim
                      the PHYSICIAN'S ....... in the legal record,
                                              amendable but never
                                              un-assertable
                      the PATIENT'S ......... a signature obtained
                      the PAYER'S ........... not yours to change,
                                              still your exposure

  OWNER             a person, by name. Not a department.

  EVIDENCE TEST     what would have to be true, on a specific claim,
                    for the assertion to be true - and the date the
                    owner last checked a real claim against it

Four design decisions make the register work rather than become another binder.

It is tested against output, not against configuration. The owner does not read the setup screen; the owner pulls a claim the configuration touched — ideally the claim as transmitted — and asks whether the assertion it carries is true on that claim. Chapter 27's Case Study 2 is the proof: an eleven-year-old local mapping produced a malformed element on every claim, the clearinghouse silently normalized it, and the practice's copy and the payer's copy were accurate records of different files. Nothing on the configuration screen would have shown it. The transmitted claim did.

Two events force an off-cycle review. A payer policy or edit change, because Chapter 28's Case Study 1 configuration was correct when written and decayed with no internal event to signal it; and a system migration, upgrade, or vendor change, because that is when silent normalization stops and the accumulated drift arrives at once.

The "where it lands" column decides how expensive an entry is to be wrong about. An assertion in a claim field is corrected by correcting the claim. An assertion in a clinical note over a physician's signature is in the legal health record — Chapter 29's Case Study 2 put a templated sentence about a significant, separately identifiable service into two years of signed notes, and a note can be amended (Chapter 4 §4.5) but never un-asserted. An assertion carried by a form the patient signs is Chapter 22's routine ABN, where a signature certified something the form was not valid to certify. Rank the register by that column, not by volume.

And it reaches assertions that are not software at all. Chapter 31's Case Study 1 is a payer's configuration asserting on every affected remittance that a course of secondary billing was proper — not yours to change, and your obligation anyway, because the claim carries your certification (Chapter 5 §5.1) and the sixty-day clock (§37.9) runs against you rather than against the vendor who was wrong. The register entry is not the payer's software; it is the fact that a process of yours relies on an assertion made by somebody else's system, with an owner and a test. And Chapter 31's Case Study 2 is a script given to human beings, asserting in every conversation that this patient can pay and should be asked again — a configuration whose runtime is a person, on the register for the same reason a macro is: it makes the same assertion every time, and nobody decided it in the individual case.

Why one control does catch them all. These instances share no module, no department, no decade, and no direction of error — billing system, clinical record, transmission mapping, posting rule, a form a patient signs, a payer's software, a sentence a person is told to say. No chart audit reaches them; no scrubber edit reaches them. What they have in common is only the mechanism, and a register is an inventory of the mechanism rather than of a technology. That is the answer to Chapter 17's question, and it is why the register is defined by assertion and not by system. The shape of the idea fits in one sentence: an assertion nobody chose is an assertion nobody audits.

What the register does not reach

Three limits, stated plainly, because a control sold as complete is the next chapter of this same story.

It does not find an assertion nobody thought to inventory. A list is written by people with the imagination they have. Chapter 6's Case Study 2 found seven scrubber rules accumulated over eleven years, six of them silently altering claim content, and nobody had inventoried them because nobody knew the module could do that. The mitigation is not cleverness: build the register from the system's own configuration exports and change logs rather than from memory, and make "who can change this, and where is that recorded?" a question every vendor must answer.

It does not reach an assertion that is true. Every configuration in §37.2's collection made a correct assertion most of the time — that is why they survived. Chapter 29's template sentence was true on most encounters; Chapter 25's workaround succeeded about two-thirds of the time. A register tells you an assertion is being made and by whom; it cannot tell you how often it is wrong. That takes the sample, which is §37.2 — the register and the chart audit are not substitutes, and an organization that builds one and calls the problem solved has built half a control.

And it does not reach an error visible only in aggregate. §37.2's third leg exists for that, and neither of the first two replaces it.

Say those out loud in the meeting where the register is proposed. A control whose limits are published gets used correctly; a control sold as complete becomes the thing everyone points at afterward.

The channel, and the person who could not have known

Now the thread this chapter has to close. §37.1 counted the findings in this book that came from a person rather than a control — roughly seven, two of them from outside the organization entirely. Chapter 19's Case Study 2 gave the corollary: a person noticing is not a control, but the absence of a place to say something is a control failure. And Chapter 26's Case Study 1 raised the ceiling by producing a person who could not have detected the error even in principle.

Those three facts have one operational answer with three parts.

One: a channel, defined by what it does not require. One named place where anybody in the building — front desk, medical assistant, biller, coder, scribe — can report "this looks wrong" or "why do we do it this way?" without having to know whether it is a coding, billing, clinical, contract, or system question. That last clause is the entire design requirement and it is the one usually missing. Most organizations have four specialized channels and no general one, so a person who does not know which specialty owns their observation has nowhere to put it. That is the control failure Chapter 19's case study named.

Two: an owner with authority, and a response obligation. A named person receives every report, and every report gets a written disposition within a stated number of business days — including "we looked, it is working as intended, and here is why." The response obligation is not courtesy; it is the mechanism's power supply. A channel with no response obligation goes silent within a quarter and then stands as documentary evidence that the organization built a way to hear and did not listen.

Three — and this is what Chapter 26's case study forces — the outside-in audit, run on purpose. §37.2 made distributions the audit universe's third leg; here is the harder reason they belong there. Some errors are not detectable from any seat inside the organization, so an audit program must include at least one analysis using only what the payer can see — no charts, no interviews, no institutional knowledge. Take §37.2's list and add three moves that only an outsider would make:

THE OUTSIDE-IN VIEW - three moves only an outsider would make

  · every distribution in §37.2, computed against a PEER
    comparison rather than against your own last quarter
  · the fields nobody adjudicates, read as data:
    patient discharge status (Ch. 26 §26.7), the remarks field,
    the referring- and ordering-provider fields
  · "what would a stranger with only our public record conclude?"
    - claims data, the price transparency file (Ch. 32 §32.5),
      the financial assistance policy, a court docket

None of it requires a medical record, and all of it is where a Recovery Audit Contractor's automated review, a comparative billing report, or an SIU actually starts. Chapter 26's unit clerk could not have found her error. A discharge-status distribution would have found it in an afternoon — the auditor found it exactly that way, comparing the hospital against peer facilities — which is why the organization was detectable from outside before it was detectable from inside, and why the comparison it could have run on itself at any time and never did is that case study's real finding.

The third bullet is not rhetorical either. Chapter 32's Case Study 2 argued that an internal audit function which never asks "what would a journalist with our court docket conclude?" is missing a real audit procedure. It is a real audit procedure — an afternoon, using only public documents, and the only one on the list that can see a problem which is not a coding problem at all.

And Chapter 26's quiet detail deserves repeating, because it is the most hopeful fact in this chapter: FL 80 contained the answer. On a number of the misclassified transfers somebody had written down, in the remarks field, what had actually happened — in the one field nobody adjudicates. The information was in the building the whole time. Nobody had a reason to read it.

Compute what they compute, before they do. The outside-in analysis is free, needs no chart access, takes a few hours a quarter, and is the only part of an audit program that can see what the people doing the work cannot.

Does any of this make a person a control? No. It makes the absence of a person survivable — a lower and more achievable claim, and the honest end of a thread this book has been pulling since Chapter 14.

🔍 Check Your Understanding

  1. An audit finds that a charge-capture rule has been appending a modifier to a code family for three years. The practice's corrective action is a memo to staff and a training session. Where does that sit on the durability ladder, and what would move it up two levels?
  2. A CAP's owner reports that the fix is working: "we check every one of those claims before it goes out, and we catch them all." What are the two things wrong with that, and which case study in this book supplies each?
  3. Your practice has never had a compliance report from anyone below the coder level. Is that evidence that nothing is wrong?

Answers: (1) Rung 4 — the weakest, and it decays with turnover. Rung 2 would be a scrubber edit or a pre-bill hold on the affected combination; rung 1 would be turning the rule off, or requiring a person to affirm it per claim. (2) It is a manual workaround absorbing a defect that still exists — Chapter 25's Case Study 2, twice over: "a workaround that mostly works becomes institutional knowledge," and "a team keeping up with a problem prevents anyone from noticing the problem." The day the checker is out, the defect ships. (3) No. It is evidence about the channel, not about the claims — and per §37.1 and Chapter 19's Case Study 2, the absence of a place to say something is itself a control failure. Check whether a general channel exists, whether anyone knows about it, and whether the last report received a written answer.


37.11 🗂️ The Encounter — auditing Account 10-4471

Thirty-seven chapters have built this claim. Now read it the way a stranger would.

The exercise. You are an external auditor with no relationship to Northgate Family Medicine, no access to anyone who was in the room, and no interest in the practice's interpretation. You have the claim, the remittance, and the record. Score it.

What this chapter contributes to the file: the audit finding — the first document in the file that is an outside reading rather than an inside decision.

The claim, and the standard each line is scored against

ACCOUNT 10-4471 - AUDIT WORKSHEET                    [constructed; DOS Mar 14]

  LINE  CODE      MOD  PTR   CHG      SCORED AGAINST
  ----  --------  ---  ----  -------  ------------------------------------
   1    99214      25  ABCD  $185.00  CPT E/M guidelines (MDM); the
                                      modifier 25 definition; the payer's
                                      published policy
   2    20610      RT  A     $150.00  CPT descriptor (major joint, no
                                      ultrasound guidance); the surgical
                                      package guidelines
   3    J1030      --  A      $18.00  the HCPCS descriptor's dose (40 mg)
                                      and the units reported
   4    36415      --  B      $14.00  the CPT descriptor; the order and
                                      the reason for it

  DIAGNOSES  A = M25.561 (right knee pain) · B = E11.9 · C = I10 · D = E78.5
  TOTAL CHARGES $367.00 · ALLOWED $216.28

What survives

Line 1 — 99214, supported. The visit is leveled on medical decision making, not time; the note states that time was not used for level selection, and §15.13 froze the leveling: three chronic conditions, stable, plus one new problem with an uncertain prognosis; data limited; risk moderate — two of three elements at moderate, which is what a level 4 established-patient visit requires. An auditor re-deriving it from the note reaches the same place. Supported.

Modifier 25 — supported, on four elements, and the reason is worth stating precisely. Chapter 14 §14.4 closed this question and the four supporting elements are frozen: (1) three chronic conditions each separately assessed with a plan; (2) prescription drug management — three medications reviewed and continued; (3) two laboratory tests ordered with stated clinical reasons; (4) a new problem with its own history, examination, and independent management decision. Elements 1 through 3 have nothing to do with the knee. That is the entire argument and it is what distinguishes this chart from the one in §37.3's Code It callout, where the same two codes and the same modifier produced the opposite finding. 20610 carries a 000-day global, which is also why 25 is the correct modifier here and 57 is not (Chapter 17 §17.2).

Line 2 — 20610-RT, supported. The knee is a major joint. The procedure note documents the approach, the needle, the drug and dose, and two documented negatives"no aspirate obtained" and "no imaging guidance used" — which are the affirmative reason 20611 is not the code (Chapter 17 §17.7). Those negatives are not padding; they are the load-bearing sentences that defend the chosen code against the more highly valued one. An auditor notices absent negatives. This record has them.

And the lidocaine is correctly absent from the claim. Three milliliters of 1% lidocaine appear in the procedure note and on no line, because the local anesthetic is inside 20610's surgical package (Chapter 17 §17.1, §17.2), because it is a usual supply (Chapter 20 §20.10), and because separately reporting it would violate the standards of medical and surgical practice (Chapter 21 §21.6). Three independent reasons, one correct claim. Nothing is missing here — something is correctly not there, and that is a harder thing for an auditor to see.

Line 3 — J1030, supported. Methylprednisolone acetate 40 mg; the descriptor's dose is 40 mg; one unit. Note, descriptor, and claim agree.

Line 4 — 36415, supported, and the pointer is the finding that is not a finding. The venipuncture points at B (E11.9), not at A, because the blood was drawn for the hemoglobin A1c; pointing it at the knee would assert that a venipuncture treats knee pain (Chapter 25 §25.5). That detail distinguishes a claim built by somebody paying attention from one built by a default, and diagnosis linkage is exactly what a reviewer checks.

Diagnoses — supported for this date of service. M25.561 and not M17.11, because the March 14 assessment states that no definitive diagnosis was established that day and no prior imaging of the knee was available (Chapter 22 closed this as Q5: imaging later supports osteoarthritis, and the March 14 code was correct for March 14). E11.9 rather than a diabetes-with-CKD combination, because Section IV reports conditions addressed at the encounter and the assessment does not address the kidney disease (Chapter 9 §9.7). Neither is an error.

The signature — supported. Signed electronically on the date of service at 6:42 p.m. with an attestation, so §37.7's step 5 passes on the first attempt.

The finding

One finding, category 4: supported, but the record is fragile.

The note never states that the decision to inject was made during this visit. It is strongly implied — "discussed management options … patient elected injection today" — and it is clinically obvious, and it is not a sentence. That is the second of the gaps in Chapter 4 §4.10's note, named at Chapter 14 §14.4 and carried since.

The consequence was not hypothetical. When the payer denied line 1 on day 17 with CO-97 and RARC N19, Chapter 30's appeal had to construct the argument from surrounding evidence rather than quote a sentence — assembling the four elements, the policy language, and the NCCI Policy Manual text into a demonstration, because there was nothing to quote. The appeal won. It won on a constructed argument, which is a materially weaker instrument than a quotation, and the next one might not.

The prospective correction, and its limits. The fix is a template change: the plan section of a procedure-day note should state, in the physician's own words, that the decision to perform the procedure was made at this encounter. That is a change to future notes. It is not an amendment to this one — Chapter 4 §4.5 governs amendments, addenda, and late entries, and a note altered after a payer has denied the claim is the single worst document a file can contain. The record documents a decision that was really made; the correction is that future records say so at the time. Nothing about that recommendation asks anyone to write something that did not happen.

The three documented gaps, from an auditor's chair

The March 14 note printed in full at Chapter 4 §4.10 carries three documented gaps. They are not equally interesting to a reviewer, and knowing why is the transferable skill.

Gap What an auditor does with it
1. Conservative therapy's failure is documented in the HPI, not in the assessment Not an error — an organization problem. Six weeks of intermittent ibuprofen with partial relief is in the record. A reviewer scoring medical necessity for the injection may read the assessment and never reach the HPI (Chapter 22 §22.6). Score it supported; flag it category 4. An auditor who scores it as an error is wrong; an auditor who does not flag it is not doing the job.
2. The note does not state the decision to inject was made at this visit The finding. See above.
3. No diabetes–CKD linkage Nothing at all — to this audit. For this claim, on this date, E11.9 is correct because the kidney disease was not addressed. To a risk adjustment data validation reviewer asking a different question about a different payment system, the same record reads differently, and that question belongs to Chapter 36 §36.11.

Gap 3 is the most valuable thing in the section, and it generalizes. The same record, unchanged, scores differently depending on which audit you are in. A fee-for-service coding audit, a medical necessity review, a RADV audit, and a quality-measure abstraction ask four different questions of the same paragraphs. "Is this chart clean?" is not a well-formed question until somebody says clean for what.

The score

ACCOUNT 10-4471 - AUDIT RESULT                          [constructed]

   CODE-LEVEL ACCURACY ....... 4 of 4 lines supported ........ 100%
   CHART-LEVEL ACCURACY ...... 0 findings requiring a change .. pass
   FINANCIAL VARIANCE ........ $0.00 against $367.00 charged
                                     and $216.28 allowed
   DIRECTION ................. neither overstated nor understated

   DOCUMENTATION FINDINGS .... 2 (category 4; no code change)
                               - decision-to-inject not stated
                               - conservative therapy in the wrong
                                 section of the note

What that settles. The claim is defensible. Every line survives an outside reading against a cited standard, and the two findings are about how the record is built, not about what was billed.

What it does not settle, and this is the sentence to carry out of the chapter: the claim that scores 100% is the claim that was denied. Line 1 was refused on day 17 by a payer edit and paid only after an appeal. Chapter 14 established that fact as canon and it has held for twenty-three chapters: the denial was the payer's policy, not a coding error. An audit measures whether your work is defensible. It does not predict what a payer will do, and a practice that expects a clean audit to prevent denials has confused two different machines.

The open questions. Five of the file's six are closed — Q1 (modifier 25, Chapter 14), Q2 (the diabetes code, Chapter 9, with Chapter 36 retaining whether it is sufficient), Q3 (no ABN, Chapter 22), Q5 (the knee, Chapter 22), Q6 (the \$185.00 charge, Chapter 23). Q4 — could the denial have been prevented? — remains open and belongs to Chapter 40. This chapter deliberately does not touch it. Scoring a claim's defensibility and deciding what a denial was worth are different questions, and only one of them is an audit.


Summary

An audit is a reading of your work by someone who was not there. The only choice is who does it first. Audit because an early error is a correction while a late one is a repayment; because quality is invisible unless somebody measures it and an unmeasured function is indefensible; and because errors run in both directions while only one direction announces itself.

Scope an audit in three moves: universe, sample, standard. Write the universe as a sentence ending in a count. Use a probe — ten to thirty charts — to decide whether a real audit is needed, and never extrapolate from one. Score every finding against a cited authority — the record, the code set, the guidelines, the edits, the coverage policy, the manual — as those stood on the date of service, because ICD-10-CM changes every October 1, CPT every January 1, and HCPCS Level II and the NCCI edits quarterly.

An audit universe has three legs: charts, configurations, and distributions. A dozen failures in this book at least, in every part, share one mechanism — a configuration made an assertion nobody chose — and a chart audit cannot find them, because it reads the configuration's output with a method that reads only output. And anything only wrong in aggregate cannot be found by sampling at all, which is why the third leg is a distribution computed with no chart opened. Treat a favorable trend as a question: a number with a story attached stops being a question.

A scoring sheet separates four findings: not supported, wrong code, sequencing or linkage, and supported but fragile — the fourth being the one most sheets omit and the one that predicts next year's errors. Report accuracy with its denominator, always report direction, and remember that a clean score proves less than it looks: a correct outcome is not evidence of a correct process.

Prepayment review suspends claims rather than denying them; it costs a calendar rather than a payment. A non-response to an ADR is scored as an error and denies the claim. You do not appeal your way off — you answer every request on time, fix the measured error rate, and show a dated corrective action plan.

The external programs are not interchangeable. The MAC processes and reviews; TPE is its provider-specific probe-and-educate program and the cheapest external audit you will ever get; the RAC is contingency-fee-funded, works mostly postpayment, and publishes its approved issues; the SMRC reviews what CMS assigns and refers findings to the MAC; CERT is a national measurement whose sampled claims are still real claims; a UPIC is a benefit-integrity investigation and the point at which counsel is involved before the response is written. Commercial special investigations units operate under your contract, not under the Program Integrity Manual.

Extrapolation projects a sample onto a universe, and volume is its multiplier. Account 31-2245's \$25,720.80 was a census of forty-two claims, not a projection. The same error at scale — 380 claims, a 42-claim sample, the same \$612.40 average — produces a point estimate of \$232,712.00 and a demand of \$204,489.40 at the lower limit of a 90 percent interval. Consistency makes it worse: it narrows the interval (\$23,092.60 here), satisfies the "sustained or high level of payment error" precondition, and leaves no argument that a sampled claim was different. The disciplined organization is the one whose single wrong rule extrapolates most cleanly.

A records response is a product for a hostile reader on a deadline — logged the day it arrives, calendared backward, complete for the claims requested and bounded to them, indexed, copied, confirmed. And the response letter concedes fast and argues narrow, citing the authority the reviewer cited and quoting your own record rather than characterizing it. Never explain what the provider meant; never amend a note after a request; attach the corrective action.

Four of this book's findings arrived because somebody read materials for a commercial purpose — due diligence, a negotiation, a renewal, an ownership review — because organizations read their own agreements only when money is being negotiated. Schedule the reading without waiting for the transaction. Its mirror image is the report that never arrived: an organization with zero internal reports does not have zero problems, and the report count is the only compliance number that goes up when things are going well. And no, "build better controls" is not sufficient: a control can only be built for a failure already imagined, controls decay silently, and a control tests conformance while an adversarial reading tests the premise. Build the controls and buy the reading.

The sixty-day clock starts on identification, and identification means knowing and quantifying. A timely good-faith investigation is contemplated; not looking is not a defense. Ordinary quantified overpayments go back through Chapter 31 §31.9's workflow; conduct implicating civil monetary penalty authorities goes to the OIG Self-Disclosure Protocol; Stark goes to the CMS Voluntary Self-Referral Disclosure Protocol; anything that may have been knowing goes to counsel first. A coder escalates in writing and does not decide which door.

A corrective action plan needs six fields — finding, root cause, change, owner, date, test and re-audit — and interventions rank by durability: make it impossible, make it visible before the claim leaves, make it visible after with a named reader, tell people. Most plans stop at the last one. A manual workaround is not a correction: a workaround that mostly works becomes institutional knowledge, and a team keeping up with a problem prevents anyone from noticing the problem.

Two controls close this book's oldest threads. The assertion register inventories every place an assertion can be made about a claim or an encounter by something other than a person deciding about that claim — what it asserts, where it lands and in whose voice, a named owner, and an evidence test run against a real transmitted claim. Defined by assertion rather than by system, it reaches a billing macro, a note template signed by a physician, a form the patient signs, a payer's software you cannot change but still answer for, and a script handed to a person. An assertion nobody chose is an assertion nobody audits. Its three limits are published with it: it cannot find an assertion nobody thought to inventory, it cannot say how often an assertion is wrong — that still takes the sample — and it cannot see an error visible only in aggregate. And for the findings that came from people rather than controls: a general channel that does not require the reporter to know which specialty owns their observation, an owner with a written response obligation, and an outside-in audit of the distributions a reviewer computes without a chart. Compute what they compute, before they do. None of it makes a person a control; it makes the absence of a person survivable.

And Account 10-4471 scores 100% — four of four lines supported, no financial variance, two documentation findings that change nothing on the claim. It is also the claim that was denied. An audit measures whether the work is defensible; it does not predict what a payer will do.


Key Terms

Audit — a structured, independent re-reading of a defined sample of completed work against a written standard, producing a scored result and a documented finding on each disagreement. (Ch.37)

Audit universe — the complete, countable set of items an audit is about: a query with a date range, a payer, a provider, a code set, and a filter, returning a specific number. Every rate and every extrapolation is computed against it. (Ch.37)

Statistical sampling — the discipline that makes a projection from a sample defensible: a defined universe, an enumerated sampling frame, units drawn by a documented random method, and an estimate reported with its precision. (Ch.37)

Probe audit — a small, deliberately limited first review (roughly ten to thirty items) whose purpose is to decide whether a fuller review is warranted. Never a basis for an error rate or a projection. (Ch.37)

Prepayment review — review that occurs before adjudication: matching claims suspend, records are requested, and the claim is paid, reduced, or denied on the documentation. It costs calendar and labor rather than creating a debt. (Ch.37)

Postpayment review — review of claims already paid; where the reviewer disagrees, the result is an overpayment recovered by demand or by offset. (Ch.37)

Additional documentation request (ADR) — the letter that requests the records supporting specified claims, with a stated deadline; a non-response is scored as an error and denies the claim. (Ch.37)

Extrapolation — projecting an overpayment measured on a probability sample across the whole universe to produce a demand; under Medicare it requires a sustained or high level of payment error and is demanded at the lower limit of a stated confidence interval. (Ch.37)

Recovery Audit Contractor (RAC) — a contingency-fee contractor that identifies Medicare overpayments and underpayments already made, through automated, semi-automated, and complex review, with its issues approved and published in advance. (Ch.37)

Targeted Probe and Educate (TPE) — the MAC's provider-specific, issue-specific program: a small probe sample followed by one-on-one education, repeated for a defined number of rounds, with referral to CMS if the error rate persists. (Ch.37)

Supplemental Medical Review Contractor (SMRC) — a national contractor performing medical review on topics CMS assigns; it does not recover money, but refers its findings to the MAC. (Ch.37)

Comprehensive Error Rate Testing (CERT) — the program that measures Medicare fee-for-service's improper payment rate from a random national claim sample. Selection means nothing about the provider; non-response still costs the claim. (Ch.37)

Unified Program Integrity Contractor (UPIC) — the benefit-integrity contractor covering Medicare and Medicaid: fraud, waste, and abuse rather than error, with authority to suspend payment, conduct site visits, and refer to law enforcement. (Ch.37)

OIG Work Plan — the Office of Inspector General's published, continuously updated list of active and planned audits and evaluations; free, public, and the closest thing the field has to a forecast of what will be scrutinized. (Ch.37)

Self-disclosure — voluntarily reporting identified conduct to the government: the OIG Self- Disclosure Protocol for conduct implicating civil monetary penalty authorities, and the CMS Voluntary Self-Referral Disclosure Protocol for the physician self-referral law. Distinct from an ordinary refund of a quantified overpayment. (Ch.37)

Corrective action plan (CAP) — a written commitment naming a finding, its root cause, the specific change, a person, a date, a test, and the re-audit that runs the test. Missing the last two fields, it is an intention. (Ch.37)

Assertion register — an inventory of every configuration that can make an assertion on a claim or in the record, each with what it asserts, where it lands, a named owner, and an evidence test run against a real transmitted claim. (Ch.37)


Spaced Review

  1. Define the audit universe for this question and then answer it: a practice wants to know whether its modifier 25 use is defensible. Write the universe as a sentence ending in a count, name the sample you would draw and how, and name the three authorities every finding will cite.

  2. A payer reviews a random sample of 42 claims from a universe of 380, finds an average overpayment of \$612.40 per sampled claim, and reports a sample standard deviation of \$286.00. Compute the point estimate. Then explain, without computing it, what happens to the demand if the standard deviation had been \$52.00 instead — and why the second organization is probably the more careful one.

  3. (Chapter 36) A diagnosis was reported for risk adjustment in a year the condition appears only on a problem list. State what MEAT criteria require of the record, and explain why the same chart can pass a fee-for-service coding audit and fail a risk adjustment data validation review.

  4. (Chapter 5) An internal audit quantifies an overpayment pattern across eleven months. Using Chapter 5's framework, state what distinguishes this from fraud, what the False Claims Act's reverse-false-claim theory adds once the amount is quantified, and which of the seven elements of an effective compliance program the audit itself satisfies.

  5. (Chapter 21) Account 31-2245's modifier 59 was appended by a macro. Name the NCCI mechanism that made 29822 bundle into 29827, state what the modifier indicator would have had to be for an override to be possible at all, and explain what documentation had to exist at the time for the override to survive the review that came eighteen months later.


Next: Chapter 38. The same work, done by software. Clinical documentation integrity, the compliant query and the leading one, computer-assisted coding, and the question this chapter's category-4 finding has been circling: if an engine can read a note and propose a code, what exactly is the human in the loop still for?