Types of Audits: Internal, External, Retrospective, and Prospective
Key Takeaways
- Internal audits are proactive, educational reviews conducted by practice staff or compliance teams to identify risk, whereas external audits are conducted by payers, government entities, or third parties for enforcement, recoupment, or independent verification.
- Retrospective audits analyze historical paid claims to identify pattern errors and financial liabilities, while prospective (pre-bill) audits review documentation prior to claim submission to eliminate overpayment risk.
- Statistical random sampling allows auditors to infer findings across a large population, whereas targeted (judgmental) sampling focuses exclusively on known high-risk providers, specific CPT codes, or billing anomalies.
- Government enforcement audits utilize specialized entities including RACs (contingency-based recoupment), CERT (measuring improper payment rates), and UPICs (investigating suspected fraud).
- The audit lifecycle follows a strict sequence: scope definition, sampling, chart abstraction, error calculation, reporting, provider education, Corrective Action Plan (CAP) execution, and re-auditing.
Types of Audits: Internal, External, Retrospective, and Prospective
Executive Summary: Healthcare audits vary significantly based on their origin, timing, scope, and objective. A Certified Professional Medical Auditor must master the operational nuances of internal self-audits versus external regulatory investigations, prospective (pre-bill) reviews versus retrospective (post-payment) evaluations, and statistical random sampling versus targeted risk audits. Selecting the correct auditing methodology ensures organizational resources are deployed effectively to mitigate compliance risks and protect practice revenues.
The CPMA examination heavily tests audit classification, sampling design, government oversight programs, and the end-to-end audit lifecycle. Mastering these topics is essential for structuring defensible auditing programs in clinical practice.
1. Internal Audits vs. External Audits
The distinction between internal and external audits centers on who initiates the audit, the underlying objective, and the degree of legal or financial exposure involved.
┌──────────────────────────────┐
│ HEALTHCARE AUDITS │
└──────────────┬───────────────┘
│
┌───────────────────────┴───────────────────────┐
▼ ▼
┌─────────────────────┐ ┌─────────────────────┐
│ INTERNAL AUDITS │ │ EXTERNAL AUDITS │
├─────────────────────┤ ├─────────────────────┤
│ • Proactive & Self │ │ • Payer & Govt │
│ Initiated │ │ Initiated │
│ • Educational Focus │ │ • Recoupment & Legal│
│ • Risk Reduction │ │ Exposure │
│ • Confidential Work │ │ • Formal Demands & │
│ Product │ │ Penalties │
└─────────────────────┘ └─────────────────────┘
Internal Audits (Self-Audits)
Internal audits are voluntary, proactive evaluations conducted by a healthcare organization's own compliance personnel or contracted internal auditors.
- Primary Goals: Identify coding and documentation vulnerabilities before external entities discover them, educate providers, optimize legitimate revenue, and verify internal policy adherence.
- Protection of Work Product: Internal audit findings conducted under the direction of legal counsel may be protected under Attorney-Client Privilege or Work Product Doctrine, shielding self-evaluations from discovery during litigation.
- Scope & Frequency: Often scheduled on a routine basis (e.g., annual baseline audits of 10 charts per provider, or quarterly focused audits).
External Audits
External audits are initiated by entities outside the healthcare organization, such as commercial insurance carriers, government contractors, or federal enforcement agencies.
- Primary Goals: Verify claim accuracy, recover overpayments, enforce statutory compliance, or investigate allegations of fraud and abuse.
- Key Initiators:
- Government Contractors: Medicare Administrative Contractors (MACs), Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs).
- Federal Agencies: Office of Inspector General (OIG), Department of Justice (DOJ), Centers for Medicare & Medicaid Services (CMS).
- Commercial Payers: Special Investigation Units (SIUs) from private insurance companies.
- Third-Party Consultants: Independent external auditing firms hired by an organization for an objective, un-biased compliance validation.
2. Retrospective vs. Prospective vs. Concurrent Audits
Timing dictates the workflow, operational impact, and financial risk of an audit. Medical audits fall into three timing categories: retrospective, prospective, and concurrent.
| Audit Timing | Description | Advantages | Disadvantages |
|---|---|---|---|
| Retrospective Audit | Review conducted after claims have been billed, processed, and paid by the insurance carrier. | • Complete data set (claim, ERA/EOB, paid amount available).<br>• Does not delay claim submission or practice cash flow.<br>• Ideal for historical trend analysis. | • Discovered errors represent immediate overpayment refund liabilities.<br>• High administrative cost to process refunds or appeals.<br>• Risk of payer extrapolation. |
| Prospective Audit (Pre-Bill Audit) | Review conducted before claims are finalized and submitted to insurance carriers for payment. | • Prevents improper billing and overpayments prior to submission.<br>• Zero refund or recoupment exposure.<br>• Immediate real-time feedback to coders and providers. | • Delays claim filing and slows practice cash flow.<br>• Labor-intensive and requires fast turnaround.<br>• Limited to smaller chart sample sizes. |
| Concurrent Audit | Review conducted in real-time during the patient's course of treatment or inpatient stay. | • Allows immediate documentation correction in the active chart.<br>• Enhances patient safety and clinical care continuity. | • Requires physical or active EHR presence.<br>• Extremely resource-intensive. |
3. Audit Sampling Methodologies: Statistical vs. Targeted
Determining how charts are selected for review is one of the auditor's most critical decisions. Audit sampling falls into two major categories: Random (Probability) Sampling and Targeted (Judgmental/Non-Probability) Sampling.
Random / Statistical Sampling
In statistical random sampling, every claim or medical record in the target population has an equal, non-zero chance of being selected.
- Simple Random Sampling: Using a random number generator to pick charts across an entire provider population.
- Stratified Sampling: Dividing the population into distinct sub-groups (strata)—such as by CPT code category, payer type, or place of service—and randomly sampling within each stratum.
- Primary Use: Baseline audits, establishing overall practice error rates, and generating statistically valid defensible samples suitable for extrapolation.
Targeted / Judgmental Sampling
In targeted sampling, the auditor deliberately selects charts based on specific risk factors, high-dollar codes, billing anomalies, or prior non-compliance.
- Common Selection Criteria:
- High-risk CPT codes (e.g., unlisted codes, Modifier -25 or -59 usage, prolonged services).
- Providers exhibiting extreme outliers on E/M bell curves.
- Claims flagged by OIG Work Plan priorities or RAC target lists.
- Providers under a active Corrective Action Plan (CAP).
- Primary Use: Focused audits, investigating suspected fraud, and verifying remediation of known coding errors.
- Key Constraint: Findings from a targeted sample cannot be mathematically extrapolated across the entire chart population because the sample is inherently biased.
4. Government Audit Entities & Enforcement Programs
Auditors must be intimately familiar with the government agencies and contractors authorized to audit Medicare and Medicaid claims:
┌──────────────────────────────┐
│ GOVERNMENT AUDITORS │
└──────────────┬───────────────┘
│
┌──────────────────┬──────────────┴──────────────┬──────────────────┐
▼ ▼ ▼ ▼
┌──────────────────┐ ┌──────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ MAC │ │ RAC │ │ CERT │ │ ZPIC / UPIC │
│ Claims & Pre/Post│ │ Contingency │ │ Improper Payment │ │ Fraud & Abuse │
│ Medical Review │ │ Recoupment │ │ Measurement │ │ Investigation │
└──────────────────┘ └──────────────┘ └──────────────────┘ └──────────────────┘
- Medicare Administrative Contractors (MACs): Conduct routine pre-payment and post-payment medical reviews (e.g., Targeted Probe and Educate - TPE program) to address local coding errors and educate providers.
- Recovery Audit Contractors (RACs): Statutory entities hired by CMS to identify and recoup improper Medicare overpayments and underpayments. RACs are paid on a contingency fee basis (a percentage of overpayments recovered).
- Comprehensive Error Rate Testing (CERT): Measures national Medicare improper payment rates by selecting random samples of claims to evaluate compliance with coverage rules.
- Unified Program Integrity Contractors (UPICs): Specialized contractors tasked with investigating suspected fraud, waste, and abuse across Medicare and Medicaid. UPICs can perform unannounced site visits, suspend payments, and refer cases to the OIG or DOJ for criminal prosecution.
5. The End-to-End Audit Lifecycle
A professional medical audit follows a structured, multi-step lifecycle from initial planning through post-audit re-evaluation:
Step 1: Define Scope & Audit Plan
│
▼
Step 2: Sample Selection & Data Gathering
│
▼
Step 3: Medical Record Review & Abstraction
│
▼
Step 4: Error Rate Calculation & Analysis
│
▼
Step 5: Audit Findings Report & Presentation
│
▼
Step 6: Corrective Action Plan (CAP) Execution
│
▼
Step 7: Follow-up Re-Audit & Monitoring
- Scope Definition & Planning: Establish the audit objective (e.g., baseline vs. focused), target timeframe (e.g., prior 12 months), payer scope, and documentation guidelines to apply.
- Sample Selection: Pull claims data and select sample charts using appropriate statistical or targeted sampling methodologies.
- Record Abstraction & Review: Compare medical record documentation against billed codes, validating identity, medical necessity, code accuracy, and modifier usage on an audit worksheet.
- Data Analysis & Error Rate Calculation: Calculate line-item error rates, financial overpayment/underpayment totals, and overall percentage compliance scores.
- Reporting Findings: Draft an executive audit report detailing methodologies, summary findings, benchmark comparisons, chart-by-chart breakdown, and compliance risk exposure.
- Provider Education & CAP Implementation: Present findings to leadership and providers in a constructive format, implementing targeted training and operational corrections.
- Re-Audit & Closure: Schedule a follow-up audit (typically 60-90 days later) to verify that corrective actions successfully eliminated documentation and coding deficiencies.
A medical practice compliance officer wants to conduct an audit to evaluate a physician's documentation for Modifier -25 usage. The compliance officer selects 25 specific claims where Modifier -25 was appended to an E/M code billed on the same day as a minor surgical procedure. Which sampling method was used, and what limitation applies to the results?
A healthcare facility receives an audit notice from a contractor paid on a contingency fee percentage based on the volume of improper Medicare overpayments it successfully identifies and recovers. Which government auditing entity has initiated this review?
A practice administrator requests a pre-bill audit of all operative reports written by a newly credentialed orthopedic surgeon before any claims are submitted to insurance payers. What type of audit timing is being utilized, and what is its primary operational benefit?
During a routine compliance review, an auditor discovers that a provider repeatedly billed CPT code 99214 without clinical documentation. The auditor calculates the overpayments across a 30-chart random sample and prepares a formal report for executive leadership. What is the next required step in the standard audit lifecycle?