Medical Coding Audits: Sampling, Prospective vs Retrospective and Findings
Healthcare
Medical Billing & Coding
Medical Coding Audits: Sampling, Prospective vs Retrospective and Findings
Share this article:
Medical Coding Audits: Sampling, Prospective vs Retrospective and Findings
Last updated: 2026-09-22
A medical coding audit is the check that tells a practice whether its billed codes match the care its notes describe, and this page walks the whole review from definition to sourcing. What the audit is comes first, then why a practice runs one at all, since the reason is money moving in two directions with a compliance floor underneath. How the review works follows, along with what it samples out of the full pile of charts and how a prospective audit run before submission differs from a retrospective one run after payment. What happens once errors surface leads into when a practice should schedule the review and who performs it. The report and its contents come next, then how a practice acts on the findings rather than filing them, and whether a virtual auditor can do this work remotely. Where these coding audit facts come from closes the page, including the numbers left off it on purpose.
What is a medical coding audit?
A medical coding audit is a structured review that compares your clinical documentation against the codes billed for it, checking whether each CPT procedure code, ICD-10-CM diagnosis code, and evaluation and management level is accurate, complete, and supported by the note. This review asks one plain question of every chart it opens. Does what the provider wrote justify what the practice billed?
Two properties set it apart from a spot check. It's systematic, so charts get pulled on a defined basis instead of only when something looks wrong, and it's documented, so what comes out is a written finding rather than a hallway opinion. An ICD-10-CM code always begins with a letter, a CPT code carries five characters, and an audit reads both against the encounter that produced them.
The review stays on the documentation. It doesn't second-guess the medicine, and it doesn't decide what care a patient needed. What it checks is whether the record supports the claim that left the building, a compliance and revenue question rather than a clinical one.
Why does a practice run a medical coding audit?
A practice runs a medical coding audit to protect itself on two fronts at once, revenue and compliance, because coding errors quietly bleed in both directions. Over-coding bills a higher level than the note supports, and it carries repayment exposure if a payer or a federal review ever looks back. Under-coding does the opposite. It bills below what the documentation would justify, so the practice performs work it never gets paid for and doesn't notice the gap.
Denials are the third reason. One rejected code showing up again points to a coding or documentation habit that an audit can name and fix at the source, rather than one appeal at a time.
There's a compliance floor underneath all of it. Coding accuracy is a condition of billing government and commercial payers, and a practice that can show it audits its own work sits in a far stronger position than one that waits to be audited from outside. The review turns coding from an act of faith into something the practice can see.
How does a medical coding audit work?
A medical coding audit works by pulling a defined set of charts and reading each one the way a payer would, note first, then the codes billed against it. The auditor never starts from the claim. They start from the documentation, decide what it supports on its own, and only then compare that against what went out the door.
A coding audit runs the same loop every time.
Pull the sample of encounters to review, chosen by provider, date, risk, or code.
Read each clinical note and decide which code the documentation independently supports.
Compare that decision against the CPT, ICD-10-CM, and E/M code the practice billed.
Flag every code mismatch, and record whether it over-states, under-states, or misses.
Group the code mismatches into patterns, so a recurring error surfaces as a trend rather than a one-off.
What comes out isn't a score on its own. It's a set of findings tied to specific charts, each traceable to the note that produced it, so a provider sees exactly where the record and the claim parted ways.
What does a medical coding audit sample?
A medical coding audit samples a slice of the practice's coded encounters rather than every chart, because reading everything would cost more than the errors it finds. The selection is where an audit earns its keep. Random pulls tell you the baseline rate across all coding, while a targeted pull built around a high-volume code, a new provider, or a service line prone to denials tells you where the risk concentrates.
What the auditor measures inside each sampled chart stays consistent. Each note is checked against the CPT, ICD-10-CM, and E/M codes, and every claim runs against coding rules that apply regardless of who billed it. National Correct Coding Initiative edits published by CMS define pairs of codes that shouldn't be billed together, and payer-specific policies add their own layer on top.
Sample size is a judgment call tied to what's at stake. Focused reviews of one worrying code run small, and a broad compliance audit reaches wider, but neither figure means anything borrowed from another practice. The count that matters is the one your own risk supports.
How is a prospective coding audit different from a retrospective one?
A prospective coding audit differs from a retrospective one by when it happens, and that single difference in timing changes what each can do. Run prospectively, an audit reviews claims before they go out, so an error gets fixed while it's still a draft and nothing has to be repaid or appealed. Reviewed after payment posts, a retrospective audit catches patterns across real, adjudicated results but can only correct them going forward.
Neither one wins outright. They answer different questions, and most practices end up running both on different cadences.
Prospective versus retrospective coding audits by timing, strength, and limit.
Audit type
Timing
Strength
Limit
Prospective
Before submission
Catches errors before any money moves
Reviews a smaller live queue, so it's slower per claim
Retrospective
After payment
Sees real payer behavior across volume
Errors are already billed and may need repayment
New providers and new service lines usually earn a prospective look first, since the cost of teaching a bad habit is highest at the start. Established coding that's running clean is better suited to a periodic retrospective check.
What happens when a coding audit finds errors?
When a coding audit finds errors, the response depends on what kind of error it is, because not every mismatch is a problem and not every problem is the coder's. One-off typos get corrected and it's done. A pattern, meaning the same error across several charts or one provider, becomes the output of the audit, because it points to a habit that keeps producing claims until someone changes the input.
Findings sort into a few buckets. Some are documentation gaps, where the note simply didn't record enough to support the code, and the fix lives with the provider. Others are coding errors, where the note supported a different code than the one billed, and the fix lives with the coder. Genuine judgment calls make up a smaller set, ones two qualified people could read differently, and those get flagged for discussion rather than marked wrong.
Errors also point in two directions, and an honest audit reports both. Over-coded charts may need correction and, depending on scope, repayment, while under-coded charts show revenue the practice earned and left uncollected.
When should a practice schedule a coding audit?
A practice should schedule a medical coding audit whenever its coding risk changes, not on a calendar it set once and forgot. Certain moments raise that risk sharply, such as bringing on a new provider, adding a service line, adopting a new EHR, or absorbing a coding guideline change. Each one introduces fresh errors before anyone has a track record to spot them.
Steady-state practices still need a rhythm. Periodic audits, run on a cadence the practice sets from its own risk, keep small drifts from compounding into a pattern that a payer notices first. How often is genuinely a local decision, and any specific number of charts lifted from another office is a guess dressed up as a target.
One trigger overrides the schedule. Spikes in denials on a particular code, a payer inquiry, or a new provider whose numbers look unusual all justify an audit now rather than at the next planned interval, because the point of the review is to find the problem before it's the payer finding it.
Who performs a medical coding audit?
A medical coding audit is performed by a trained coding auditor, someone who reads documentation and coding rules for a living rather than a general administrator with a spare afternoon. It isn't a job you hand to whoever's free. The work needs a person fluent in CPT, ICD-10-CM, and E/M guidelines, comfortable reading a clinical note, and current on the payer and federal rules that decide whether a code holds up.
Most auditors come up through coding first. Someone spends time as a certified medical coder, learns where charts go wrong from the inside, then adds an auditing credential on top, which is why our guide on how to become a medical coder describes the first half of that path. An auditor who never coded tends to miss the practical reasons a note ends up short.
Internal and external auditors both have a place. An internal reviewer knows the practice's providers and quirks, while an external reviewer brings independence and a wider view of how other practices code the same service, and a serious compliance program usually uses both.
What does a coding audit report contain?
A coding audit report contains the findings in a form a practice can act on, and it isn't just a raw list of right and wrong. Usable reports open with a summary the practice owner reads first, then add chart-level detail a coder can work through, so nothing's asserted without a chart.
A complete report usually carries a few standard parts.
An overall accuracy read on the sample's code selection, stated as the audit found it, not against a borrowed figure.
The error patterns in those code choices, grouped, so the biggest recurring issue is obvious.
Chart-level detail for each flagged encounter, naming the code billed, the code the note supported, and why.
The direction of each code error, over-coded or under-coded, so revenue and compliance risk are both visible.
Recommendations tied to each code pattern, each a specific next step rather than a general reminder.
Recommendations are the part that earns the fee. Naming a problem without saying what to change leaves the practice where it started, so the strongest reports read like a work plan.
How do you act on a coding audit's findings?
You act on a coding audit's findings by closing the loop between what the audit saw and what the practice does next, which is the step that separates a review that changes behavior from one that just files a report. Closing that loop is where the audit's benefits land. The work runs in three moves, and skipping any one wastes the audit.
First comes feedback. Each finding goes back to the person who owns it, the provider for documentation gaps and the coder for coding errors, framed as specific and fixable rather than as blame. This is where a strong coder pays off, and our rundown of the benefits of a medical coder shows what that role handles once the findings land.
Second comes the fix itself, meaning updated documentation templates, a corrected coding habit, or a claim resubmitted where the timing still allows it. Third comes the re-audit. One follow-up review on the same problem area confirms the change took hold, because an audit that's never re-run can't tell you whether anything improved.
Can a virtual auditor run a coding audit?
Yes, a virtual auditor can run a medical coding audit, because it's documentation and code review that travels cleanly over a secure connection, with no part needing a desk in your office. The auditor reads the same notes and billed codes your in-house team sees, through access your practice grants and controls. Against an in-house auditor's wage and benefits load, remote hours can cost less.
What makes it work is the arrangement around the person. Honest Taskers places HIPAA-trained professionals who sign a Business Associate Agreement before they reach protected health information, work from screened home offices, and staff the client's US time zone. Its coders and auditors do administrative and clinically adjacent work, never clinical decisions. Rates run $10.00 to $12.65 an hour depending on role and schedule, and new clients may receive a two-week working trial with their first selected professional.
When you're weighing a remote hire against a firm, staffing companies and outsourced services price the work differently, and our list of virtual medical coder companies sets hourly staffing against outsourced coding contracts.
Where do these coding audit facts come from?
These coding audit facts come from two kinds of source kept deliberately separate on this page. The workflow, meaning how an audit samples charts, compares notes to codes, and reports patterns, reflects how coding review runs across practice management and EHR systems rather than one office's protocol, so your own sample sizes and cadence will differ. Coding rules referenced, from the National Correct Coding Initiative edits to auditing credentials, trace to AAPC for medical auditing guidance and to CMS for the coding and billing rules named above.
The Honest Taskers facts, rates, trial terms, recruiting geography, and compliance posture, come from the company's own published materials, and its HIPAA compliance is verified by Accountable. Wage context for the in-house comparison comes from the U.S. Bureau of Labor Statistics "Occupational Employment and Wage Statistics" program for May 2025.
One thing you won't find here is a number. No error rate, no denial percentage, and no repayment figure appears anywhere on this page, because every one of those is answerable from your own coding data and meaningless borrowed from someone else's.
Once the review is settled and you're deciding who owns coding day to day, the seats on either side of an audit are worth reading about, since an auditor checks the work a coder produces and a staffing firm supplies both.
Honest Taskers guides for the roles that sit next to a coding audit.