Every October the diagnosis codes change, and every October practices discover that the habits they had before the change are the habits they have after it. A coder who defaulted to unspecified codes in September defaults to unspecified codes in October, now with new options to ignore. The code update is a deadline. The audit is what makes the deadline useful.
We recommend a coding audit in June for the same reason we recommend a leakage review in May: the window is old enough to be adjudicated, and there is time left in the year to act. Here is how we structure one for a practice of two to ten providers, what we look for, and how to turn findings into changed behavior rather than a report in a drawer.
Key takeaways
- Twenty encounters per provider from March and April, weighted to the provider's own E/M mix, plus ten procedure encounters where relevant.
- Blind coding: the auditor never sees the billed code first.
- Six error types account for most findings, and three of them are fixed in the EHR, not in the coder.
- Score by provider and by error type. A practice at 90 percent with one provider at 70 percent has one problem, not a general one.
- Correct and refund overpayments within the 60-day rule, re-audit the outliers in September, and use October 1 as the reason.
Sample design
Pull 20 encounters per provider from dates of service in March and April 2026, selected at random from each provider's billed E/M levels in proportion to how often they bill them. If a provider bills 60 percent 99214, then 12 of the 20 should be 99214. Add 10 procedure encounters per provider for specialties that do procedures in the office. That gives you enough to see patterns without spending a week.
The audit is blind: the auditor codes from the documentation without seeing the billed codes, then compares. If you use an outside auditor, that is automatic. If you audit internally, have coders review a different provider's work than they usually code, and give them the notes without the claim. An audit where the reviewer sees the billed 99214 first and then reads the note tends to find that the note supports a 99214.
The six error types that dominate findings
| Error | What it looks like | Typical fix |
|---|---|---|
| E/M level not supported by MDM | 99214 billed; note shows one stable chronic problem and no data or prescription management | Provider education on the three MDM elements; assessment stated explicitly |
| Unspecified diagnosis when specificity was documented | E11.9 billed; note documents diabetic neuropathy (E11.42) | Coder habit; EHR favorites list rebuilt with specific codes |
| Modifier 25 without a separately identifiable E/M | 99213-25 with 20610 when the visit was only the injection | Clear rule: the E/M must address a problem beyond the procedure decision |
| Laterality missing | M17.0 bilateral coded when note says right knee (M17.11) | Templates that force laterality |
| Time-based level without a compliant time statement | 99215 by time; note says "spent time with patient" | Time statement template with total time and activities |
| Chronic conditions coded but not addressed | Six diagnoses on the claim; two addressed in the note | Code what was assessed or treated at the visit |
Three of these (unspecified codes, laterality, time statements) are system problems wearing a coder's clothes. If the favorites list puts E11.9 at the top and E11.42 four clicks down, the practice will code E11.9. Fix the list once and the error disappears for every provider at the same time.
Reading the E/M distribution
Before the audit, pull each provider's E/M level mix for the past 12 months and compare it to the national Medicare distribution for the specialty, which CMS publishes in its utilization data. Family medicine in recent years has billed roughly half of established visits as 99214, a third as 99213, and about one in ten as 99215. A provider at 80 percent 99214 and 15 percent 99215 is not necessarily wrong, but the audit sample should be weighted toward those levels, and the documentation had better support them. A provider at 60 percent 99213 is probably undercoding, which is also a finding; underpayment is leakage too.
Look at the new-patient codes separately. A provider who bills 99204 for every new patient is either seeing an unusually complex panel or has a template that produces a 99204 whether or not the visit earned it. Both are worth knowing.
Scoring: a worked example
Keep the scoring sheet simple: one row per encounter with the billed code, the audited code, the error type, the dollar difference and a one-line note. Practices that build elaborate scoring tools spend the time on the tool instead of the notes. Record each encounter as agree, overcoded, undercoded, or diagnosis error, with the dollar difference for level changes at your largest payer's fee schedule.
Here is what the summary looks like for a three-provider internal medicine practice, 20 encounters each, using approximate Medicare differences of $42 between a 99213 and a 99214 and $53 between a 99214 and a 99215:
| Provider | Agree | Overcoded | Undercoded | Diagnosis errors | Accuracy | Net dollar effect on 20 encounters |
|---|---|---|---|---|---|---|
| Dr. A | 18 | 1 | 0 | 1 | 90% | About $42 over |
| Dr. B | 13 | 5 | 0 | 2 | 65% | About $230 over |
| Dr. C | 16 | 0 | 3 | 1 | 80% | About $126 under |
The practice average is 78 percent, which sounds like a general problem. It is not. Dr. A is fine. Dr. B has four MDM findings and one time statement finding, and at roughly 350 established visits a month the pattern is worth about $4,000 a month in overpayments that a payer audit would want back. Dr. C is leaving about $2,200 a month on the table by billing 99213 for visits that document prescription management of two chronic conditions. Two different conversations, two different fixes, and neither of them is a practice-wide retraining.
Accuracy rates above 95 percent are excellent; below 85 percent needs a plan. Report by provider and by error type, not as a single practice score.
What to do with the results
- One page per provider. Their accuracy, their top two error types, three example encounters with the note excerpt and the corrected code. Providers respond to their own notes; they ignore aggregate slides.
- Fix the system where the system is the cause. Unspecified codes at the top of the favorites list, templates without laterality, an auto-inserted time statement: these are fixed once, in the EHR, and they stop producing errors for everyone.
- Corrected claims where required. Overcoded encounters should be corrected and refunded where a payer was overpaid. Medicare's overpayment rules give you 60 days from identifying an overpayment to report and return it, with a defined period to investigate the scope. Talk to counsel about scope if the pattern is large, because a five-out-of-twenty finding for Dr. B implies a lookback question, not a five-claim refund.
- Re-audit the outliers in September. Ten encounters each for the providers below 85 percent, before the new codes land.
Using October as the reason
The FY 2027 ICD-10-CM update takes effect for dates of service on or after October 1, 2026, and the code files are posted in June. The new codes include more specific options in several chapters, which means the "unspecified when specificity was documented" finding will get more common, not less, unless habits change. Frame the summer audit as preparation: here is what we found, here is what changes on October 1, here is the favorites list we are rebuilding. Providers accept an audit tied to a real date more readily than one that arrives out of nowhere.
Our coding courses are built around this audit structure, and our RCM audit includes a blind coding sample by provider. Practices that want the audit done and then the coding handled can look at medical coding; rates are on the pricing page.
Questions we hear
Is 20 encounters per provider enough?
Enough to find patterns, not enough to estimate an error rate precisely. If the first 20 show a problem, expand to 50 for that provider before drawing conclusions about dollars.
Should providers know the audit is happening?
Yes. Tell them the dates of service and the method in advance. An audit that feels like an ambush produces defensiveness; one that feels like a scheduled check produces better notes in the next quarter, which is the point.
Who should do the audit if we have one coder?
Not the coder who coded the encounters. Use an outside auditor for the first round, or swap audits with a practice you trust in a different specialty. A coder auditing her own work will find what she already believes.
What to do this month
- Pull each provider's E/M distribution for the past 12 months and compare it to the specialty norm.
- Select 20 encounters per provider from March and April, weighted to their mix, plus 10 procedures where relevant.
- Code them blind and score each as agree, over, under or diagnosis error, with the dollar difference.
- Write one page per provider and hold the fifteen-minute conversations.
- Fix the favorites lists, templates and time statement settings in the EHR.
- Book the September re-audit for anyone below 85 percent.
