Chapter 37 — Key Takeaways

The whole chapter in one line

An audit is a reading of your work by somebody who was not there, has no stake in your interpretation, and will not give you the benefit of the doubt. The reading is going to happen. The only choice is who does it first.


Why audit

  1. An error found early is a correction; found late it is a repayment. Account 31-2245: forty-two claims, one macro, \$25,720.80. Nothing about the coding got worse over eighteen months. Only the arithmetic did.
  2. An unmeasured function is indefensible. Production counts itself; quality does not.
  3. Errors run both directions and only one announces itself. The audit is the only routine activity that looks where nothing else looks.

And an audit that finds nothing quarter after quarter is evidence about the method, not the claims.


Scope: universe, sample, standard

  • Audit universe = a query with a date range, payer, provider, code set, and filter — written as a sentence ending in a count.
  • Probe audit = 10–30 items, to decide whether a real audit is needed. Never a basis for a rate or a projection.
  • Standard stack: the record → the code set → the Official Guidelines and CPT guidelines → the NCCI edits and Policy Manual → the coverage policy (NCD/LCD/commercial) → the contract or manual.
  • THE DATE RULE: a claim is scored against the rules in force on its date of service. ICD-10-CM changes October 1 · CPT January 1 · HCPCS Level II and NCCI edits quarterly.

Three legs, not one:

Leg Finds Misses
Charts unsupported codes, wrong codes, linkage anything the configuration does to every chart
Configurations an assertion nobody chose how often the assertion is wrong
Distributions what is only wrong in aggregate anything inside a single record

Treat a favorable trend as a question. A number with a story attached stops being a question.


Scoring

   1  NOT SUPPORTED ......... the code comes off
   2  WRONG CODE ............ the service happened; the description is wrong
   3  SEQUENCING / LINKAGE .. right codes, wrong order, pointer, or unit
   4  SUPPORTED BUT FRAGILE . nothing changes on the claim - and this is the
                              category that predicts next year's category 1
  • Report accuracy with its denominator: code-level · chart-level · financial · directional.
  • External reviewers score the claim, not the code — and in an extrapolation the sampling unit is usually the claim, so one bad line makes the whole unit an error.
  • A correct outcome is not evidence of a correct process.
  • A finding that does not name its authority is an opinion. Every finding gets a written rebuttal before it is final.

Prepayment vs. postpayment

Prepayment Postpayment
When before adjudication after payment
What it creates a suspension and an ADR an overpayment
What it costs calendar, cash cycle, labor money you already have
Non-response denial for insufficient documentation, scored as an error an overpayment on a claim your records would have supported

You do not appeal your way off prepayment review. Answer every ADR on time · read the denials for pattern · fix upstream and show the date · talk to them.


The external alphabet

  MAC    processes AND reviews; governed by the Program Integrity Manual
         (Pub. 100-08); effects most recoveries
  TPE    a MAC PROGRAM: small provider-specific probe + 1:1 education,
         defined rounds. The cheapest audit you will ever receive.
  RAC    CONTINGENCY FEE; mostly postpayment; automated / semi-automated /
         complex; must find UNDERPAYMENTS too; issues published in advance
  SMRC   reviews what CMS assigns; DOES NOT RECOVER - refers to the MAC
  CERT   a MEASUREMENT, not an audit of you - but your sampled claim is
         still a claim, and a non-response still costs it
  UPIC   BENEFIT INTEGRITY: fraud, not error. Payment suspension, site
         visits, law-enforcement referral. COUNSEL BEFORE YOU RESPOND.

Commercial SIUs operate under YOUR CONTRACT, not under the Program Integrity Manual. Also in the landscape: the OIG (audits, the Work Plan, exclusion, self-disclosure) and RADV for risk adjustment.


Extrapolation

   UNIVERSE (N)  ->  PROBABILITY SAMPLE (n)  ->  MEAN  ->  POINT ESTIMATE
                                                        ->  LOWER BOUND
                                                        ->  DEMAND

Account 31-2245 was a CENSUS, not a projection: 42 × \$612.40 = **\$25,720.80**, because 42 was the whole population. The same error on 380 claims, sampled at 42:

   point estimate      380 x $612.40   =  $232,712.00
   demand (lower bound, 90% two-sided) =  $204,489.40

The demand is a function of how many claims EXIST, not how many were read.

Why consistency makes it worse — four reasons: it shrinks the confidence interval (\$23,092.60 in this chapter's example) · it satisfies the sustained or high level of payment error precondition · the sample defends itself, so "this claim was different" has no purchase · and the consistent error is the disciplined one — a rule, followed carefully, by people doing their jobs.

Medicare's constraints: not automatic (SSA §1893(f)(3)) · the design must be disclosed · the demand is a lower bound, not the point estimate · statistical validity is appealable · overturned sampled claims can change the projection · RAT-STATS is public — quantify your own exposure with it.

And 11 of 42 were defensible and unprovable — \$6,736.40, which would have made the demand \$18,984.40. The defense is contemporaneous documentation and it cannot be built retroactively.


Records request and response

  LOG IT the day it arrives  ->  IDENTIFY THE PROGRAM  ->  CALENDAR BACKWARD
  ->  DEFINE "THE RECORD" per claim  ->  CHECK THE SIGNATURE FIRST
  ->  COMPLETE FOR WHAT WAS ASKED, BOUNDED TO IT  ->  BUILD IT AS A DOCUMENT
  ->  KEEP AN EXACT COPY + PROOF  ->  CONFIRM RECEIPT
  • What you produce is defined by policy, not by convenience (Ch. 4 §4.8).
  • Never amend a record in response to a request. Send what you have (Ch. 4 §4.5).
  • The response letter: agree · agree in part · disagree, finding by finding. Concede fast — it is what makes the rest believable. Cite the authority the reviewer cited. Quote your record; never characterize it. Never explain what the provider meant. Attach the corrective action.

The two collected answers

THE COMMERCIAL-PURPOSE PATTERN. Four findings in this book arrived because somebody read payer or practice materials for a commercial purpose — due diligence, negotiation, renewal, an ownership review. Schedule the reading without waiting for the transaction: an annual contract read, a payer policy calendar, a fee-schedule reload check, a rotating outside read. The buyer is not smarter. The buyer is the first person in six years with a reason to read.

And its mirror: an organization with zero internal reports does not have zero problems. Count the reports. It is the only compliance number that goes up when things are going well.

Is "build better controls" sufficient? No — necessary, not sufficient. A control can only be built for a failure already imagined; controls decay silently; and a control tests conformance while an adversarial reading tests the premise. Build the controls and buy the reading.


Self-disclosure and the sixty-day clock

Identified = knowing AND quantifying. A timely good-faith investigation is contemplated; not looking is not a defense. Retention past the deadline creates an obligation — the False Claims Act's reverse false claim. Verify the current regulatory text and timeframes; they have been revised more than once.

What you found Where it goes
Quantified billing/coding error, no intent issue Refund — Ch. 31 §31.9's workflow
Conduct implicating civil monetary penalty authorities (false billing, an excluded person, kickbacks) OIG Self-Disclosure Protocol
Actual or potential physician self-referral (Stark) violation CMS Voluntary Self-Referral Disclosure Protocol
Possibly knowing conduct · a UPIC · a subpoena Counsel first

A coder escalates in writing and does not decide which door. Not legal advice — verify with counsel and your compliance officer.


The corrective action plan

Six fields: finding · root cause · the change · an owner by name · a date · a test and a re-audit. Missing the last two, it is an intention.

  1  MAKE THE ERROR IMPOSSIBLE ............. changes what the system permits
  2  VISIBLE BEFORE THE CLAIM LEAVES ....... scrubber edit, pre-bill hold
  3  VISIBLE AFTER, WITH A NAMED READER .... a report is not a control;
                                              a person who reads one is
  4  TELL PEOPLE ........................... necessary; decays with turnover

  Most CAPs stop at 4. Most findings recur.

A manual workaround is not a correction. A workaround that mostly works becomes institutional knowledge, and a team keeping up with a problem prevents anyone from noticing the problem.


THE ASSERTION REGISTER — the one control

An inventory of every place an assertion can be made about a claim or an encounter by something other than a person deciding about that claim.

Five fields: what it is · what it asserts, in plain language · where it lands and in whose voice (the practice's · the physician's, in the legal record · the patient's signature · the payer's, which you cannot change and still answer for) · an owner by name · an evidence test run against a real transmitted claim.

Two hard triggers for off-cycle review: a payer policy or edit change · a system migration, upgrade, or vendor change.

It reaches a billing macro, a note template, a pre-printed form, a transmission mapping, a posting rule, a payer's software, and a script handed to a person — because it is defined by assertion, not by system.

AN ASSERTION NOBODY CHOSE IS AN ASSERTION NOBODY AUDITS.

Its three published limits: it cannot find an assertion nobody thought to inventory (build it from configuration exports and change logs, not memory) · it cannot say how often an assertion is wrong — that still takes the sample · and it cannot see an error visible only in aggregate.


The person who could not have known

A person noticing is not a control — but the absence of a place to say something IS a control failure. And some errors are not detectable from any seat inside the organization at all.

  1. A channel that does not require the reporter to know whether it is a coding, billing, clinical, contract, or system question.
  2. An owner with authority and a written response obligation within a stated number of business days — including "we looked, it is working as intended, here is why."
  3. The outside-in audit: the distributions a reviewer computes with no chart — E/M levels by provider, modifier 25 and 59 rates, units against descriptors, discharge status, liability-modifier share — against a peer comparison, plus the fields nobody adjudicates, plus "what would a stranger with only our public record conclude?"

Compute what they compute, before they do. None of this makes a person a control. It makes the absence of a person survivable.


Account 10-4471, audited

   CODE-LEVEL ACCURACY .... 4 of 4 supported ............ 100%
   FINANCIAL VARIANCE ..... $0.00
   DOCUMENTATION FINDINGS . 2 (category 4; no code change)

Survives: 99214 on medical decision making (Ch. 15 §15.13) · modifier 25 on four elements, three of which have nothing to do with the knee (Ch. 14 §14.4, from Figure 4.2) · 20610's 000-day package, with the lidocaine correctly off the claim for three independent reasons · J1030's dose and units · 36415 pointed at the A1c, not the knee (Ch. 25 §25.5) · M25.561 and E11.9, both correct for March 14.

The finding: the note never states the decision to inject was made at this visit — the second of the gaps in Chapter 4 §4.10's note. Chapter 30's appeal had to construct the argument rather than quote a sentence. The fix is a template change to future notes; this one is not amended.

And the same record scores differently depending on which audit you are in. A coding audit, a medical necessity review, and a RADV review ask three different questions of the same paragraphs. "Is this chart clean?" is not a well-formed question until somebody says clean for what.

The claim that scores 100% is the claim that was denied. The denial was policy, not a coding error. An audit measures defensibility; it does not predict what a payer will do. (Whether the denial could have been prevented belongs to Chapter 40.)


Monday morning

You should be able to: write an audit universe as a sentence ending in a count · draw and defend a sample · score a chart in four categories, each finding on cited authority, with the denominator and the direction stated · explain what prepayment review does to cash and what it takes to come off it · identify which contractor sent the letter and who writes the response · work an extrapolation from universe to demand and say why consistency costs more · run a records request as a product on a deadline · write a response that concedes fast and argues narrow · recognize the day a pattern becomes a sixty-day obligation and escalate it in writing · and build one corrective action plan with an owner, a date, and a test that somebody will actually run.