Proactive Self-Audits: How to Identify Red Flags Before the MACs Do 

By Elizaveta Bannova, CPC, CPMA, CPCO, CFPC | WCH Service Bureau 

We recently hosted one of our webinars — “Proactive Self-Audits: Identifying Red Flags Before the MACs Do” — as part of our 25th Anniversary Special Webinar Series. The questions kept coming long after the session ended. 

If you missed it, here’s what you need to know: the most valuable, up-to-date compliance guidance we have comes through our webinars — not from generic articles, not from recycled blog posts. Newsletter subscribers attend all our special webinars for free, so if you’re not on the list yet, now is the time to sign up and catch the next one. 

In the meantime, here are the key takeaways every provider should know. 

Why Proactive Self-Audits Are No Longer Optional 

Audits are not a matter of if — they are a matter of when. The question is whether you find your own problems first, or whether a MAC, RAC, SMRC, UPIC, or OIG finds them for you. The financial and legal consequences of the latter can be devastating. 

Understanding who is watching — and what they are looking for — is the foundation of any real compliance program. 

Know Your Auditors: A Quick Risk Map 

The federal audit landscape involves multiple overlapping contractors, each with different triggers and risk levels. Here’s how they stack up: 

CERT (Comprehensive Error Rate Testing) — Low risk. Conducted by CMS contractors through random sampling, its primary purpose is to measure the national improper payment rate. Your chances of being selected are statistical, not targeted. Claim adjustments are possible but the focus is reporting, not enforcement. 

TPE (Targeted Probe & Educate) — Moderate risk. This is where many providers first feel the pressure. MACs run TPE when they detect high error rates or unusual billing patterns. They review 20–40 claims at a time (pre- and post-payment) and the focus is documentation and billing accuracy. It starts as educational, but it can escalate quickly if issues aren’t corrected. 

MAC Audits — Moderate risk. Your regional MAC conducts routine claims oversight triggered by data trends, new provider activity, or billing errors. They look at billing accuracy and coverage compliance. Expect claim denials and recoupment if problems are found. 

RAC (Recovery Audit Contractor) — Moderate-to-High risk. Private RAC contractors use data mining to hunt for overpayments and underpayments. This is primarily post-payment review, and the financial impact is direct: recoupments and required refunds. 

SMRC (Supplemental Medical Review Contractor) — Moderate-to-High risk. SMRCs conduct targeted national audits on high-risk areas identified by CMS, CERT, or OIG findings. They focus on medical necessity and high-risk services, with recoupment handled through your MAC. 

UPIC (Unified Program Integrity Contractor) — Very High risk. UPICs investigate fraud, waste, and abuse. Triggers include data analytics, complaints, and referrals. Outcomes can include payment suspension, extrapolation, and legal action. This is not a routine audit — it is an investigation. 

OIG (Office of Inspector General) — Extreme risk. The OIG operates at the federal level and focuses on detecting fraud and program abuse. Triggers include whistleblowers, investigations, and national risk areas. Financial consequences include civil penalties, exclusions from federal programs, and criminal liability. 

The Red Flags You Need to Find Before They Do 

Across years of audit work, the same categories of problems surface repeatedly. Here is where providers are most vulnerable: 

Documentation Deficiencies 

Missing physician signatures or dates, illegible notes, incomplete progress notes, and copy-paste (“cloned”) documentation across visits are among the most common audit triggers. Start-stop times are critical for time-based billing and frequently missing. Templates that are not individualized to the patient are a particular concern — auditors recognize them immediately. 

Medical Necessity Failures 

A diagnosis that does not support the service billed, no documented symptoms or clinical indication, services exceeding reasonable frequency or duration, and failure to meet LCD/NCD criteria are all grounds for denial and recoupment. If results did not impact patient care — document how and why they did. 

Coding Errors 

Upcoding without documentation support, incorrect CPT/HCPCS selection, use of outdated codes, modifier misuse (particularly -25 and -59), and unbundling services in violation of NCCI edits are common findings in both MAC and RAC reviews. 

E/M Risks 

Missing required elements, time-based billing without documented time, cloned exam findings, and overuse of high-level visits (99214/99215) are red flags in every E/M-focused audit. Complexity must be consistent with what is documented. 

Telehealth Deficiencies 

With the expansion of telehealth, a new category of documentation failures has emerged: missing patient consent, missing provider and patient location, incorrect modifiers, wrong place of service, and incorrect CPT/HCPCS codes. Telehealth claims are under active scrutiny. 

Incident-To Billing 

Billing incident-to for new patients, lack of a documented physician plan of care, services billed outside the established treatment plan, and insufficient documentation of supervision are among the most misunderstood compliance risks in multi-provider practices. 

Locum Tenens and Reciprocal Billing 

Missing or incorrect modifiers (Q6 for fee-for-time arrangements, Q5 for reciprocal billing), billing for services when the regular physician was not actually unavailable, and billing for services beyond 60 days are frequently flagged. 

Fraud and Abuse Red Flags 

Billing for services not rendered, phantom patients, kickbacks or referral schemes, altered documentation, and excessive billing spikes are the most serious category — and the one that can move a case from a MAC review to a UPIC investigation or OIG action. 

The 4 Pillars of Audit Prevention 

The Compliance Success Framework presented in the webinar is built on four pillars: 

  1. Accurate Documentation — every service, every time, individualized to the patient 
  1. Medical Necessity Justification — diagnosis must support the service; document clinical rationale 
  1. Correct Coding and Billing — use current codes, correct modifiers, and comply with NCCI edits 
  1. Continuous Monitoring — internal chart audits, claim review before submission, LCD/NCD updates in your EHR 

The golden rule has not changed: “If it was not documented, it didn’t happen.” 

What to Do Right Now 

Do not wait for an ADR letter to start taking compliance seriously. Here are immediate steps: 

  • Run an internal audit on your top 10 billed codes from the past 90 days 
  • Check for cloned documentation in your EHR — run a search for identical notes across dates 
  • Verify that all telehealth claims from the past year have proper consent, location, and modifier documentation 
  • Confirm your incident-to billing has a documented physician plan of care for every patient 
  • Review your billing patterns against peer benchmarks — are you a statistical outlier in any service category? 

If you find problems, address them proactively. Voluntary disclosure and internal correction are always better than waiting for an external audit to uncover the same issues. 

Stay Ahead of the Curve 

The regulatory environment changes constantly — LCD updates, new telehealth rules, modifier guidance, OIG work plans. The providers who stay out of trouble are the ones who stay informed. 

Our 25th Anniversary Webinar Series is designed to bring you exactly this kind of actionable, current compliance education. Newsletter subscribers attend for free. The next session may be the one that keeps your practice out of an audit finding. 

Subscribe at https://insights.wchsb.com/subscribe/  

Sources 


Discover more from Doctor Trusted

Subscribe to get the latest posts sent to your email.

Discover more from Doctor Trusted

Subscribe now to keep reading and get access to the full archive.

Continue reading