Medical Billing Audit Checklist: 27 Hidden Revenue Leaks
Revenue rarely disappears in one visible event. It leaves through small, approved-looking transactions, such as a missed charge, an underpaid claim, or a denial that no one appealed, because nothing appears wrong. Our Revenue Cycle Management Services team at TMS Billings focuses on billing accuracy and audit readiness, and a structured medical billing audit checklist is how we replace guesswork with a repeatable review. A revenue leak is any point where earned revenue is delayed, reduced, or lost. This guide explains why an audit matters, presents all 27 checks by claim-flow stage, and shows how to measure results.
Why a Medical Billing Audit Checklist Matters for Your Practice
An audit turns suspicion about lost revenue into evidence. What does a medical billing audit include? It is a structured review of claims and the revenue cycle management (RCM) steps behind them, comparing what the electronic health records (EHR) document, what was coded, what was billed, and what was paid.
Common signs of revenue leakage in medical billing include rising denials, aging accounts receivable (A/R), unexplained underpayments, and flat collections despite steady patient volume. Any one of these signals justifies a closer look, because small revenue leaks compound across every claim.

A well-run internal revenue cycle audit is a sound choice for practices with the time and expertise to perform it, while an outside reviewer adds independence and specialty depth. Practices that use a billing vendor should also compare medical billing pricing models with the collections the vendor delivers. MGMA publishes revenue cycle benchmarking and best-practice resources for practice leaders through its revenue cycle insights page.
Medical Billing Audit Checklist: 27 Hidden Revenue Leaks at a Glance
A medical billing audit checklist reviews the revenue cycle in claim order: registration and eligibility, charge capture and coding, claim submission, payment posting, denial management, and A/R follow-up. Working through 27 checks by stage shows where revenue leaks and which fixes to prioritize first.
The table below summarizes each stage, what your team verifies, and the revenue leaks it exposes. Use it as a map before working through the individual checks.
| Stage | What You Verify | Revenue Leak It Exposes |
|---|---|---|
| 1. Front End (Checks 1–5) | Patient identity, eligibility, authorizations, provider enrollment, and check-in collections | Rejected claims, preventable denials, and uncollected patient revenue |
| 2. Charge Capture and Coding (Checks 6–11) | Charge completeness, entry timing, code accuracy, diagnosis specificity, modifiers, and documentation | Missed charges, delayed billing, underpayment, and payment recoupment |
| 3. Claim Submission (Checks 12–15) | Claim scrubbing, clearinghouse acceptance, duplicate submissions, and timely filing | Avoidable rejections, claims never received, and unrecoverable claims |
| 4. Payment Posting (Checks 16–19) | Remittance-to-deposit matching, fee-schedule variance, underpayment appeals, and credit balances | Unposted cash, silent underpayments, and overpayment exposure |
| 5. Denial Management (Checks 20–23) | Denial categorization, denial trends, appeal timeliness, and corrective feedback | Repeat denial patterns, missed appeal deadlines, and denials never prevented |
| 6. A/R Follow-Up, Patient Balances, and Compliance (Checks 24–27) | Aged A/R, patient statements, adjustments, and compliance safeguards | Stalled claims, uncollected balances, improper write-offs, and compliance exposure |
The checks are numbered continuously from 1 to 27 in the sections that follow, so your team can assign, score, and track each one without renumbering between stages.

Checks 1–5: Front-End Registration, Eligibility, and Enrollment
Front-end errors are the least expensive to fix and the most costly to ignore, because every downstream step inherits them.
1. Patient identity and demographics. Match at least two identifiers to the record and confirm address, guarantor, and subscriber details. Leak: rejected claims and returned statements.
2. Eligibility and benefits verification. Confirm active coverage, plan type, copay, deductible, coinsurance, and coordination of benefits before the visit. Leak: eligibility denials and the wrong payer billed.
3. Prior authorization and referrals. Confirm required authorizations and referrals were obtained, valid for the date and service, and linked to the claim. Leak: preventable authorization denials.
4. Provider credentialing and payer enrollment. Confirm each provider holds active enrollment with every payer on the dates of service; our Credentialing Services often handle this. Leak: denials for non-enrolled providers.
5. Patient responsibility at check-in. Confirm copays, deductibles, and prior balances are identified and collected at or before the visit. Leak: patient revenue that ages uncollected.
Checks 6–11: Charge Capture and Coding
Coding and charge capture decide how much your practice is paid for care it has already delivered. Within your medical billing audit checklist, this medical coding audit checklist compares each billed code with the clinical note. A medical coding audit finds errors that claim edits cannot detect.
Coders whose work is being audited should hold the Certified Professional Coder (CPC) certification from AAPC, and AAPC also offers the Certified Professional Medical Auditor (CPMA) credential for audit specialists. The American Medical Association maintains CPT codes, while CMS maintains HCPCS Level II codes and National Correct Coding Initiative (NCCI) edits.
6. Charge capture completeness. Reconcile the appointment schedule and encounter list against charges entered to find visits or procedures with no charge. Leak: missed charges.
7. Charge entry lag. Measure the days from date of service to charge entry and review the outliers. Leak: delayed billing and timely filing risk.
8. E/M and CPT/HCPCS accuracy. Compare codes, levels of service, and units against the clinical note to find undercoding and overcoding. Leak: underpayment and compliance exposure.
9. ICD-10-CM specificity and medical necessity. Confirm diagnoses are coded to the highest supported specificity and linked to the billed procedure. Leak: medical necessity denials.
10. Modifier and bundling logic. Validate modifiers against documentation and NCCI edits. In gastroenterology medical billing services, a screening colonoscopy that becomes diagnostic needs the payer-specific modifier. Leak: silent bundling denials.
11. Documentation support. Confirm the signed note, orders, and time or medical decision-making documentation support the billed service and the billed provider. Leak: audit findings and payment recoupment.
The colonoscopy example is illustrative, so confirm each payer’s current modifier policy before correcting claims.

Checks 12–15: Claim Submission and Clearinghouse Controls
A claim that was sent is not necessarily a claim that was accepted, and only acceptance reports confirm the difference. A clearinghouse routes claims between your practice and payers, and your clean claim rate, the share of claims accepted and paid on first submission, shows how well these controls work.
12. Pre-submission claim scrubbing. Confirm claims pass payer-specific edits before release and that edit failures are worked promptly and corrected at the source. Leak: avoidable rejections.
13. Clearinghouse acceptance reports. Review rejection and acceptance reports regularly and confirm each claim was accepted by the payer, not merely sent. Leak: claims that never reached the payer.
14. Duplicate claims and duplicate charges. Detect repeated submissions and repeated charge lines by comparing patient, date of service, and code across claims. Leak: duplicate denials and overpayment exposure.
15. Timely filing tracking. Track filing deadlines by payer, since limits vary by contract, and review unbilled or unsubmitted claims approaching them. Leak: permanently unrecoverable claims.
Checks 16–19: Payment Posting and Underpayment Recovery
Payment posting is where underpayments are either caught or quietly accepted.
16. ERA-to-deposit reconciliation. Match electronic remittance advice (ERA) postings to bank deposits and flag unposted or misposted payments. Leak: unposted cash and misapplied payments.
17. Contract and fee-schedule variance. Compare allowed amounts paid on a sample of claims against contracted or fee-schedule amounts for each payer and procedure code. Leak: silent underpayments.
18. Underpayment appeals and recovery. Confirm identified underpayments are logged with supporting documentation, appealed within payer deadlines, and tracked to resolution. Leak: recoverable revenue written off.
19. Credit balances and overpayments. Review credit balances and payer overpayments, and return them within the required timeframe after confirming requirements with compliance counsel. Leak: compliance exposure.
Contract terms and payer policies differ, so confirm every variance finding against the actual contract before an appeal is filed.
Checks 20–23: Denial Management and Appeals
Denials are diagnostic data, and a denial that is corrected but not traced to its cause will return. The CMS health care payment and remittance advice page explains the claim adjustment reason code (CARC) and remittance advice remark code (RARC) sets, which X12 maintains.
20. Denial categorization by CARC and RARC. Group denials by CARC, RARC, and root cause so each denial can be traced to a specific fix. Leak: repeat denial patterns.
21. Denial rate by payer, provider, and code. Trend the denial rate at each level to expose outliers that averages hide. Leak: concentrated problems.
22. Appeal timeliness and outcomes. Confirm appeals are filed within payer deadlines with supporting documentation and that overturn outcomes are tracked. Leak: revenue lost to missed deadlines.
23. Root-cause feedback loop. Confirm denial findings return to the front desk, coders, and providers as corrective actions with named owners. Leak: denials that are worked repeatedly but never prevented.
Enrollment gaps are a frequent root cause of denials, so weigh the credentialing cost of keeping enrollment current against the revenue a lapse can put at risk.
Checks 24–27: A/R Follow-Up, Patient Balances, and Compliance
Aged accounts receivable (A/R) and compliance controls determine whether earned revenue is collected and whether it can be defended if questioned. Every medical billing audit checklist should therefore pair collections review with HIPAA compliance and screening against the Office of Inspector General (OIG) exclusion list.
24. Aged A/R review. Review A/R by aging bucket and payer, confirm every aged claim has an owner and a next action, and trend days in A/R. Leak: stalled claims.
25. Patient statements and collections workflow. Confirm statements go out on schedule, payment options are offered, and balances receive follow-up before referral to collections. Leak: uncollected patient balances.
26. Write-offs and adjustments. Review adjustments for authorization, reason codes, and patterns by user or payer. Leak: improper or excessive write-offs and internal-control gaps.
27. Compliance and data safeguards. Confirm HIPAA safeguards, a Business Associate Agreement (BAA) with each vendor and clearinghouse, OIG exclusion list screening, and record retention. Leak: compliance exposure.
Confirm BAA terms and state-specific requirements with your compliance counsel. The HHS Office for Civil Rights publishes sample Business Associate Agreement provisions, the reference for the compliance language a vendor contract should include.
How to Run Your Medical Billing Audit Checklist: Sample Size, Frequency, and KPIs
Run a full audit at least annually, review core metrics more often, and base the sample on risk rather than convenience. Knowing how to conduct a medical billing audit starts with those three decisions.
Sample size depends on claim volume and prior error rates, so no single number applies to every practice. Choose a representative, risk-based sample spread across payers, providers, and high-volume or high-risk codes.
How often should you audit medical billing? Complete a full audit at least annually, review key performance indicators (KPIs) monthly or quarterly, and add a targeted review after any payer policy change, EHR or practice management (PM) system change, or new provider onboarding.

The internal vs external medical billing audit decision has no universal answer. An internal review builds staff knowledge and costs less in cash outlay, while an external reviewer adds independence and specialty expertise. If protected health information (PHI) is shared with an outside reviewer, a BAA is generally required, and practices considering that option can review current service pricing.
Track clean claim rate, denial rate, days in A/R, net collection rate, and charge entry lag against a baseline set before corrective action, and treat any figure as illustrative because payer mix and case mix affect results. HFMA’s MAP Keys are the industry-standard KPI set for measuring revenue cycle performance.
How TMS Billings Supports Medical Billing Audits
TMS Billings applies a staged audit approach that mirrors this checklist. Certified coders perform a medical coding audit by comparing documentation with billed codes, analysts review denials and underpayments, and monthly reporting tracks clean claim rate and related KPIs. Each finding receives a clear corrective action with an assigned owner. Outsourced denial management can also shorten the resubmission cycle compared with handling it in-house, although results vary by practice.
The checklist can be run entirely in-house, and practices that want an independent revenue cycle audit or ongoing support can work with our RCM and billing support team. Your medical billing audit checklist remains useful either way, because it defines exactly what the audit must verify.
At a multi-provider practice, collections stayed flat despite steady patient volume. A staged internal audit surfaced missed charges, a repeated denial pattern tied to front-end eligibility errors, and underpayments from one payer, and once owners were assigned to each finding and KPIs were reviewed monthly, denial trends became visible and the resubmission backlog eased.
Key Takeaways
- A medical billing audit checklist replaces guesswork with 27 repeatable checks that follow each claim from registration to final collection.
- Front-end errors are the least expensive to fix, because eligibility, authorization, and enrollment mistakes are inherited by every downstream step.
- Charge capture, coding, and documentation checks decide how much revenue your practice receives for care already delivered.
- Acceptance reports, remittance reconciliation, and denial root-cause analysis reveal underpayments and repeat problems that averages and assumptions conceal.
- Run a full audit at least annually, use a risk-based sample, and track days in A/R and other KPIs against a baseline.
- Internal and external reviews both work; choose based on your team’s time, expertise, and need for independence.
Related Reading: for further coverage of billing cost and revenue cycle topics, see medical billing services cost in California, medical billing services cost in Texas, and the mental health billing cost comparison.
Final Thoughts
Physician owners and practice administrators cannot correct what they do not measure, and revenue leakage rarely announces itself. Work through this medical billing audit checklist, assign an owner to every finding, and repeat the review on a fixed schedule so your team always knows where revenue is delayed, reduced, or lost. KPI benchmarks, coding rules, and compliance requirements update periodically, so confirm current requirements with your vendor or counsel. To discuss an independent review of your billing, Book a Free Consultation.
FAQ's
What is a medical billing audit checklist?
A structured review tool that lists what to verify at each stage of the claim, from registration and coding through payment posting, denials, and A/R follow-up, so your practice can locate lost revenue.
How often should you audit medical billing?
Most practices benefit from a full audit at least annually, lighter monthly or quarterly reviews of core KPIs, and a targeted review after payer policy changes, system changes, or new provider onboarding.
What does a medical billing audit include?
It reviews registration, eligibility, charge capture, coding, claim submission, payment posting, denials, and accounts receivable, comparing documentation, codes, claims, and payments to identify errors, underpayments, and compliance gaps in your workflow.
Who should perform a medical billing audit?
A certified internal team member, such as a CPC or CPMA, can perform it when time and expertise allow; an external reviewer adds independence and specialty depth. Any reviewer receiving PHI needs a BAA.
How many claims should you review in a medical billing audit?
The right number depends on claim volume and prior error rates. Choose a representative, risk-based sample across payers, providers, and high-volume or high-risk codes, and expand it when errors cluster in one area.
What are the most common hidden revenue leaks in medical billing?
Missed charges, eligibility and authorization errors, coding mismatches, unworked denials, silent underpayments, and aging balances lead the list. Working through a medical billing audit checklist by stage reveals which apply to your practice.


