Best Medical Billing

Compliance & Audits

Billing Compliance and Payer Audits

HIPAA, the No Surprises Act, documentation retention, and surviving a review.

Compliance is the part of billing that costs nothing until it costs everything. A single audit with extrapolated findings can outweigh a year of denial recovery, and the exposure is created by ordinary documentation habits rather than by fraud.

The obligations fall into a few groups. Privacy and security under HIPAA, including business associate agreements and breach notification. Billing integrity: coding to documentation, medical necessity, and the rules against unbundling and upcoding. Patient-facing transparency under the No Surprises Act, including good faith estimates and balance-billing limits. And record retention, which varies by payer and state.

Audits arrive in several forms — RAC, TPE, UPIC, and commercial payer reviews — each with its own trigger, sample size, and response deadline. The practices that come out well are the ones with a documentation standard already in place and someone who owns the response calendar.

These pages cover what each program looks for, how to respond to a records request, how to handle an identified overpayment, when self-disclosure is the right move, and the internal audit cadence that catches problems before a payer does.

Frequently asked questions

What triggers a payer audit?
Statistical outliers most often: E/M level distributions well above peers, unusual modifier frequency, high units per encounter, or a specific code that CMS has flagged for review. Patient complaints and prior findings also trigger reviews.
How long should I keep billing records?
Six years is the common federal floor for HIPAA documentation and many payer contracts, but several states require seven or ten years for medical records. Retain to the longest applicable requirement.
What do I do if I find an overpayment?
Federal rules require reporting and returning an identified overpayment within 60 days. Document the analysis, quantify the period, and use the payer's refund or self-report process rather than waiting for a recoupment.
Does the No Surprises Act affect my billing?
Yes. It limits balance billing for out-of-network emergency and certain non-emergency services, requires good faith estimates for uninsured and self-pay patients, and provides an independent dispute resolution process.
How often should we run an internal audit?
Quarterly sampling of 10 to 20 charts per provider is a workable baseline, with focused reviews whenever a new service line, code set, or provider is introduced.

More on compliance

HIPAA, documentation standards and audit response, written for practices rather than for lawyers.

Read the guides