A medical coding audit is a structured review of a sample of your own paid claims against the clinical documentation that sits behind them, asking one question: does the note support the code? The short answer on scope is five to ten records per physician, or five or more records per federal payer, reviewed at least once a year. Those figures come from the Office of Inspector General’s compliance program guidance for individual and small group physician practices, and they have been the working benchmark for physician practices since 2000.
What has changed is why the work matters. In fiscal year 2025 the Medicare fee-for-service improper payment rate was 6.55 percent, or $28.83 billion, measured by the Comprehensive Error Rate Testing program. Roughly 53 percent of those improper payments were traced to insufficient documentation, with medical necessity at about 15 percent and missing documentation at about 12 percent. Most of the money a medical coding audit puts at risk is money that was genuinely earned and simply not written down well enough to survive a reviewer.
That is the useful frame for a practice owner. A medical coding audit is not primarily a fraud check. It is a test of whether your notes can defend your revenue, and it is one of the few compliance exercises that can pay for itself.
What a medical coding audit actually checks
The OIG guidance describes the self-audit in plain terms. A practice reviews its own claims to determine whether bills are accurately coded and accurately reflect the services provided as documented in the medical records, whether documentation is being completed correctly, whether the services provided are reasonable and necessary, and whether any incentives for unnecessary services exist.
Read that list again and notice the order. Coding accuracy comes first, but three of the four tests are really about documentation and clinical judgment. A chart can carry a perfectly defensible code and still fail an audit because the note does not establish why the service was needed. This is the single most common finding in practice, and it maps directly onto the CERT data: insufficient documentation, not miscoding, is the largest category of improper payment.
A medical coding audit therefore has to be run against the note, not against the claim. If you open the claim first and then go looking for support, you will find it, because you already know what you are looking for. Read the encounter note cold, decide what you would have coded, and only then compare it to what went out the door.
How many charts should a medical coding audit review?
The OIG’s answer is deliberately unfussy. There is no set formula for how many medical records should be reviewed, but a basic guide is five or more medical records per federal payer, meaning Medicare and Medicaid, or five to ten medical records per physician. The guidance adds the obvious caveat that the larger the sample, the more comfort it buys, and it encourages practices to look at claims from every federal payer they bill.
For a three-physician practice that is fifteen to thirty charts. That is a half day of work for one reviewer, and it is a realistic starting point for a first medical coding audit. Practices that try to open with a hundred-chart review usually never finish the first one.
Two refinements are worth making once you have run a cycle. First, weight the sample toward high-volume and high-dollar codes, because that is where a small error rate turns into real money. Second, add a small focused sample around any code you have a specific worry about, such as your higher-level office visits or anything touched by the incident to billing rules, where the compliance question is about supervision and documentation rather than code selection.
Where the benchmark comes from, and what its status is now
This part is worth knowing before you cite the numbers in a board meeting, because most articles on the subject present them as current federal guidance without qualification.
The five-to-ten benchmark comes from the Compliance Program Guidance for Individual and Small Group Physician Practices, published at 65 Federal Register 59434 on October 5, 2000. That document is explicitly voluntary. It describes seven components of a compliance program (internal monitoring and auditing, compliance standards, a designated compliance contact, training, responding to detected offenses with corrective action, open lines of communication, and consistent disciplinary standards) and it says outright that, unlike the OIG’s other guidance documents, it does not expect physician practices to implement all seven at once.
As of August 2026, the OIG’s own compliance guidance index lists that physician practice document under archived guidance. The current general document is the General Compliance Program Guidance, published November 6, 2023, and the OIG is replacing the old industry documents one subsector at a time. Only two industry segment-specific guidances have been issued so far: nursing facilities in November 2024 and Medicare Advantage in February 2026. There is no physician practice replacement yet.
The practical reading: the five-to-ten sample size remains the most widely used benchmark and is still a sensible place to start, but treat it as an established convention rather than a live federal standard, and expect the reference to move when the OIG publishes a physician segment guidance. If your compliance plan cites the 2000 document by name, note its archived status in the plan so nobody is surprised later.

A seven-step medical coding audit process
1. Decide what question the audit answers
A baseline audit and a focused audit are different exercises. The OIG describes a baseline audit as an examination of the whole claim development and submission process, from patient intake through claim submission and payment, and recommends examining claims submitted and paid during the initial three months after a training program goes in. Its purpose is to set a benchmark you can measure against later. A focused audit looks at one code, one provider, or one payer because something specific prompted it. Decide which medical coding audit you are running before you pull a single chart.
2. Pull the sample without looking at it first
Define the universe (a date range, a payer, a code set), then select records randomly inside it. The temptation in a first medical coding audit is to hand-pick charts you already feel good about. That produces a comfortable number and no information. Document the selection method in writing, because a consistent methodology is what lets you compare this audit to the next one.
3. Choose a reviewer who did not code the charts
The OIG suggests the review involve someone with coding knowledge and a medically trained person, with physicians able to rotate through that role. In a small practice this usually means your coder audits the providers and an outside reviewer audits the coder, or physicians review each other’s notes. Whatever the arrangement, the person who assigned the code should not be the person grading it. A medical coding audit graded by its own author measures nothing.
4. Score the note, then the code, then the claim
Work in that order. Read the note and record what it supports. Compare that to the code submitted. Then check the claim mechanics: modifiers, units, place of service, linked diagnoses, and whether the payer required something procedural before the visit, which is where a broken prior authorization process shows up as an avoidable write-off. Record every discrepancy in both directions. Undercoding is a finding too, and in most practices it is more common than the reverse.
5. Quantify the money and the pattern
Convert each discrepancy into a dollar figure and a cause. A medical coding audit that produces a percentage and nothing else cannot be acted on. What you want at the end is a short list of causes ranked by dollars, because that ranking tells you what to fix first. Practices that already track claim denial patterns usually find the audit findings and the denial buckets pointing at the same two or three root causes.
6. Fix the cause, not the chart
Correcting the individual records is the smallest part of the work. The OIG frames the important step as an appropriate response taken as soon as possible after the problem is identified, and it points practices toward examining claim denial history and repeated overpayments to find and correct the most frequent sources. If four of your findings trace to one provider’s discharge documentation, the fix is a template change and a training session, not four corrected claims.
7. Re-audit the same thing
Six to twelve weeks after the corrective action, pull a fresh sample of the same code or provider. This is the step practices skip, and skipping it is what turns a medical coding audit into an annual ritual with no measurable effect. The re-audit is the only evidence that the fix worked.
What to do when the audit finds an overpayment
This is the part that makes practice owners hesitate to look, so it is worth being precise about it.
Federal law requires a Medicare or Medicaid overpayment to be reported and returned within 60 days of the date it is identified. CMS changed the identification standard effective January 1, 2025: an overpayment is identified when a person knowingly receives or retains it, which incorporates actual knowledge, deliberate ignorance, and reckless disregard. The same rule codified a suspension of up to 180 days while a practice conducts a timely, good-faith investigation into whether related overpayments exist. In other words, finding one problem does not start a 60-day sprint to quantify everything connected to it, provided the investigation is genuine and prompt.
The OIG’s own framing is less alarming than most practices assume. Its guidance states that absent a violation of civil, criminal, or administrative law, erroneous claims result only in the return of funds claimed in error, without penalties. The risk that should worry you is not the honest error you found and returned. It is the pattern you were told about and did nothing with, which is exactly what a reckless disregard standard is written to capture. Deciding not to run a medical coding audit does not make the exposure smaller.
How often should you run a medical coding audit?
The OIG’s general recommendation is that periodic audits be conducted at least once each year to confirm the compliance program is being followed, and that a more focused review be run more frequently when the audit identifies a problem. Annual is the floor, not the target.
A workable cadence for most independent practices is a small quarterly sample per provider plus one broader annual review, with an immediate focused audit triggered by any of the following: a new provider’s first ninety days, a code set change that touches your top codes, a payer pre-payment review letter, a sharp move in your coding distribution against your specialty peers, or a new service line. The quarterly rhythm matters more than the sample size. A medical coding audit run four times a year on ten charts teaches a practice more than one annual review of forty.
Organizationally, a medical coding audit belongs inside internal monitoring and auditing, the first of the seven elements described in our guide to building a medical practice compliance program. The audit is not a standalone project. It is the element that produces the evidence the rest of the program acts on.
Four mistakes that make a medical coding audit useless
Auditing the claim instead of the note. Reading the submitted code first anchors the reviewer, and the review becomes a search for justification. Read the documentation cold.
Reporting only an accuracy percentage. A 94 percent accuracy rate is not actionable. Dollars by cause is actionable, and it is what tells you whether the finding is worth a template change.
Treating undercoding as a happy result. Systematically billing below what the documentation supports is a revenue problem and a documentation problem at the same time, and it distorts your coding profile against peers just as visibly as the opposite error.
Never re-auditing. Without the second look, a medical coding audit measures a problem and never demonstrates a fix. If you can only do two things this year, do a small audit and its re-audit rather than one large audit.
If your practice is weighing whether to keep this work in house or hand it to a billing partner, the scope questions in our guide to evaluating a billing vendor include whether coding audits are inside the fee or billed separately. It is a common gap in vendor contracts and an expensive one to discover late.
Frequently asked questions
Who should perform a medical coding audit, an employee or an outside reviewer?
Both, at different intervals. Internal reviewers know your specialty, your templates, and your payers, and they can run a quarterly medical coding audit cheaply. An independent reviewer once a year catches the assumptions your team shares, which is the category of error an internal audit structurally cannot find.
Is a medical coding audit required by law?
The OIG compliance program guidance for physician practices is voluntary, and the sample sizes in it are described as a basic guide rather than a rule. The obligations that do bind are separate: claims submitted must be true and accurate, and identified overpayments must be reported and returned within 60 days. Auditing is how a practice satisfies those obligations rather than an obligation in itself. Some payer contracts and participation agreements impose their own audit expectations, so read those terms as well.
What accuracy rate should we be aiming for?
Set the target internally rather than importing a number. What matters more than the headline percentage is the trend across audits and whether the dollar value of findings is falling in the categories you took corrective action on. A stable 95 percent with three unresolved repeat findings is a worse position than 90 percent with a clean re-audit.
How long should a medical coding audit take?
A focused quarterly sample of five to ten charts per provider is typically a half day of reviewer time plus an hour to write up findings. A baseline audit that traces the whole process from intake to payment takes longer, usually a week of part-time work, because it examines the workflow rather than only the records.
Getting the first cycle done
Most practices do not need a bigger audit. They need a smaller one that actually finishes, produces a ranked list of causes, and gets re-run. Pull ten charts per provider from the last quarter, read the notes before the codes, and write down what you find in dollars. That is a complete medical coding audit, and it is a better starting position than a plan for a thorough one you never run.
If you want a structured readiness review, a sampling methodology you can reuse, and a corrective plan you can hand to your team, our practice consulting and compliance support is built around this work, informed by running the billing operation of our own musculoskeletal and regenerative medicine clinic. Reach us at contact@practicemanagementconsultancy.com or (706) 909-3271.
This article summarizes federal guidance and published CMS data as of August 2026 and is general information, not legal, compliance, or billing advice. Verify current requirements against the source documents and your payer agreements before acting.






