About the CPMA Exam & AAPC Certification Standards
Key Takeaways
- The CPMA exam consists of 100 multiple-choice questions administered over 4 hours in an open-codebook format with a 70% passing score threshold.
- AAPC certification standards require passing the examination, earning 36 continuing education units (CEUs) every two years (16 of which must be auditing-specific for CPMA), and adhering strictly to the AAPC Code of Ethics.
- Exam content is organized across seven official domains, with the heaviest concentration on Medical Record Auditing Abstraction (36 questions across 15 cases), Compliance and Regulatory Guidelines (21 questions), and Medical Record Standards and Documentation Guidelines (17 questions).
- Certified Professional Medical Auditors must possess deep expertise across regulatory compliance standards, coding rules, medical necessity concepts, and statistical sampling methods.
- Successful exam candidates effectively utilize authorized coding manuals (CPT, ICD-10-CM, HCPCS Level II) to verify coding conventions, modifiers, and documentation guidelines under exam timed conditions.
About the CPMA Exam & AAPC Certification Standards
Executive Summary: The Certified Professional Medical Auditor (CPMA®) credential offered by AAPC represents the gold standard for healthcare professionals specializing in medical record auditing, compliance oversight, and risk management. The CPMA examination evaluates a candidate's knowledge of medical documentation guidelines, regulatory compliance, coding accuracy, financial risk assessment, and auditing methodologies.
The role of the Certified Professional Medical Auditor has expanded significantly in modern healthcare administration. As federal regulatory bodies, private payers, and healthcare enforcement agencies intensify scrutiny on billing compliance, medical record documentation, and medical necessity, healthcare entities rely heavily on CPMAs to safeguard financial integrity and ensure strict regulatory adherence.
1. AAPC Certification Standards & Professional Requirements
AAPC (American Academy of Professional Coders) established the CPMA credential to validate advanced proficiency in evaluating medical records for accuracy, compliance, and clinical documentation integrity. Obtaining and maintaining the CPMA credential requires satisfying rigorous educational, exam, and ethical benchmarks.
Credentialing Requirements and Experience Standards
To earn the full CPMA designation, candidates must demonstrate relevant healthcare compliance or auditing experience:
- Examination Success: Achieving a score of 70% or higher on the 100-question CPMA examination.
- Experience Requirement: Candidates must possess at least two years of documented experience in medical auditing, coding, billing, or healthcare compliance.
- Apprentice Designation (CPMA-A): Candidates who successfully pass the examination but lack two years of verified experience receive the CPMA-Apprentice (CPMA-A) designation. The apprentice status is removed once the candidate submits proof of two years of relevant work experience or completes approved mentorship hours.
Maintenance and Continuing Education Units (CEUs)
Maintaining the CPMA credential demands ongoing professional development:
- CEU Requirement: Credentialed CPMAs must submit 36 AAPC-approved CEUs every two years (the single-credential baseline), of which at least 16 CEUs must be auditing-specific to satisfy the CPMA specialty policy, alongside annual AAPC membership dues.
- Annual Coding Guidelines Updates: Auditors must stay current with annual updates to ICD-10-CM, CPT, HCPCS Level II, and CMS National Correct Coding Initiative (NCCI) edits.
2. CPMA Exam Structure and Format
The CPMA examination is structured to evaluate real-world problem-solving skills, regulatory recall, and practical auditing scenarios. Rather than testing simple rote memorization, the exam emphasizes the practical application of guidelines to complex medical record excerpts.
| Exam Parameter | Details & Specifications |
|---|---|
| Total Questions | 100 multiple-choice questions |
| Time Allowed | 4 hours (240 minutes) |
| Passing Score | 70% (equivalent to answering at least 70 out of 100 questions correctly) |
| Exam Format | Open-codebook format (approved coding manuals permitted) |
| Administration | Live online proctored (computer-based) or in-person at designated testing centers |
| Authorized Books | Official Current Year CPT® Professional Edition, ICD-10-CM, HCPCS Level II |
Exam Tip: Time management is vital. Candidates have an average of 2.4 minutes per question. Allocating time effectively between straightforward regulatory questions and lengthy documentation audit vignettes is essential for completing all 100 items.
3. Core Content Domains & Exam Weighting
The CPMA examination curriculum is organized into seven official content domains defined by AAPC. The 100 scored questions distribute across these domains as follows (question counts are AAPC's published blueprint allocation; percentages are derived from those counts). Each domain tests specific competencies critical to daily medical auditing duties.
Domain 1: Medical Record Standards & Documentation Guidelines (17 questions / ~17%)
This section assesses understanding of medical record legalities, signature requirements, record retention rules, and clinical documentation principles. Topics include:
- The medical record; authorship and authentication (electronic health record signatures, scribes, incident-to billing).
- HIPAA privacy and release of medical record information; covered entities; HIPAA privacy regulations.
- JCAHO / The Joint Commission documentation standards and record retention rules.
- The advance beneficiary notification (ABN) and legal requirements of the medical record.
- Amendments, addenda, and late entries in paper and electronic health records (EHR).
- Key components of medical documentation: Chief Complaint (CC), History of Present Illness (HPI), Review of Systems (ROS), Past, Family, Social History (PFSH), Examination, and Medical Decision Making (MDM).
- Analyzing the operative report.
Domain 2: Compliance & Regulatory Guidelines (21 questions / ~21%)
This is the largest multiple-choice domain. It evaluates knowledge of statutory laws and federal compliance standards governing healthcare fraud, abuse, and program integrity:
- Compliance Plan: The OIG's seven core elements of an effective healthcare compliance program.
- Fraud and Abuse; Civil Monetary Penalties Law; Federal False Claims Act (FCA): Civil and criminal liability for submitting false or fraudulent claims, including qui tam (whistleblower) provisions.
- Stark Law & Anti-Kickback Statute (AKS): Prohibitions against physician self-referral and remuneration for referrals.
- Types of Audits: Prospective, retrospective, random, and focused.
- OIG Regulations and Work Plan; OIG-imposed Corporate Integrity Agreements (CIAs).
- National Correct Coding Initiative (NCCI) and CMS guidelines for E/M documentation.
- Recovery audits and other government programs: Medicare Administrative Contractors (MACs), Recovery Audit Contractors (RACs), Comprehensive Error Rate Testing (CERT), Zone Program Integrity Contractors (ZPIC) / Unified Program Integrity Contractors (UPIC), and Medicaid Integrity Contractors (MIC).
Domain 3: Coding & Reimbursement Concepts (13 questions / ~13%)
Auditors apply coding conventions and reimbursement rules to validate claim accuracy:
- CPT® coding concepts and modifier usage (including -25, -59, -57, -24, and the X{EPSU} subsets).
- Diagnosis coding and medical necessity (ICD-10-CM linkage to documented services).
- Evaluation and Management documentation guidelines (1995/1997 guidelines and the revised 2021/2023 Office and Outpatient rules).
- Coding guidelines versus payer guidelines (LCDs, NCDs, and commercial payer policies).
Domain 4: Scope & Statistical Sampling Methodologies (7 questions / ~7%)
This domain covers operational audit design:
- Audit scope: Defining internal vs. external, baseline vs. routine, and focused vs. random audits.
- Statistical sampling: Simple random sampling, stratified sampling, cluster sampling, targeted (judgmental) sampling, and the limits of extrapolation.
Domain 5: Quality Assurance & Risk Analysis (2 questions / ~2%)
A small but distinct domain focused on audit defensibility:
- Listing the resources required for various types of audits.
- Identifying support for audit decisions (documentation that makes findings defensible).
Domain 6: Communication of Results & Findings (4 questions / ~4%)
This domain tests the reporting and remediation lifecycle:
- Validation of audit results and analysis and report of audit findings.
- Communicating audit results to providers, administrators, and compliance teams.
- Corrective action plan design and ownership.
Domain 7: Medical Record Auditing Abstraction (15 cases, 36 questions / ~36%)
The single largest scored area is a practical case-based abstraction section. Each test taker audits approximately 15 medical records spanning the following service lines:
- Evaluation and Management (E/M) and Surgery (the heaviest case mix).
- Physical therapy, Radiology, Psychiatry, Hematology/Oncology, and Infusion services.
Auditors extract documentation, assign/validate codes, verify modifier and medical-necessity support, and flag compliance risk for each case.
4. AAPC Code of Ethics for Medical Auditors
Ethical integrity is non-negotiable in medical auditing. Auditors hold access to sensitive clinical data, provider billing records, and practice financials. AAPC requires all certified members to adhere strictly to the AAPC Code of Ethics.
┌──────────────────────────────┐
│ AAPC Code of Ethics │
└──────────────┬───────────────┘
│
┌──────────────────┬─────────────┴────────────┬──────────────────┐
▼ ▼ ▼ ▼
┌──────────────────┐ ┌──────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ Integrity & │ │ Objectivity │ │ Confidentiality │ │ Professional │
│ Honesty │ │ & Fair Audit │ │ (HIPAA/PHI) │ │ Competence │
└──────────────────┘ └──────────────┘ └──────────────────┘ └──────────────────┘
The core ethical duties expected of a CPMA include:
- Integrity and Honesty: Auditors must present truthful, objective audit findings without alteration, bias, or suppression of facts to appease employers or providers.
- Objectivity and Independence: Auditors must remain free from conflicts of interest. An auditor should not audit their own coding work or maintain financial ties that compromise impartial evaluation.
- Confidentiality: Maintaining strict confidentiality of patient health information (PHI) and proprietary practice financial data in accordance with HIPAA standards.
- Professional Competence: Pursuing continuous education to remain proficient in evolving coding codes, guidelines, and federal statutory mandates.
5. Strategic Preparation & Open-Book Exam Tactics
Mastering the CPMA exam requires tactical preparation due to the open-book format and strict time constraints.
- Tab and Cross-Reference Coding Books: Use color-coded tabs for major CPT categories, evaluation and management guidelines, modifiers, and ICD-10-CM official coding guidelines.
- Pace Through Case Vignettes: Skim the question prompt and documentation review requirements before reading long clinical medical records to pinpoint relevant details quickly.
- Focus on High-Yield Formulas: Be prepared to calculate financial error rates, percentage of error per line item, and sampling size distributions without relying on external software.
- Prioritize Regulatory Definitions: Ensure clear understanding of federal agencies (OIG, CMS, DOJ) and statutory definitions (FCA, Stark Law, AKS) to answer regulatory questions efficiently.
A medical auditor is conducting a baseline audit for a newly hired physician. During the review, the auditor discovers that the physician routinely bills Evaluation and Management (E/M) code 99214 without documenting a chief complaint or medical decision making (MDM) supporting that level of service. Under the AAPC Code of Ethics and professional auditing standards, what is the auditor's primary responsibility?
An examinee preparing for the CPMA examination is reviewing the time allocation for the test. The examination contains 100 questions administered over a total duration of 4 hours (240 minutes). On average, how much time does the examinee have to complete each question?
Which domain accounts for the largest share of scored questions on the CPMA examination?