Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Mitigating Compliance Risks in Genetic Testing Billing and Medical Necessity Claims

Written by: Ricky Bell 

Having spent a decade advising clinical laboratories and health systems on revenue cycle management, I can tell you that molecular diagnostics remains one of the most volatile operational areas in healthcare. Federal spending on genetic testing under Medicare Part B now sits above $3.6 billion every year. That rapid financial growth brought aggressive oversight from the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) and the Department of Justice.

In the complex arena of medical billing, molecular diagnostic testing sits right in the crosshairs of federal auditors. Regulators no longer rely on random sampling. Instead, they deploy advanced data analytics to flag billing anomalies instantly. For compliance officers and practice managers, ensuring every claim meets strict coverage standards isn't just a recommendation—it is a survival strategy that lab executives cannot afford to sleep on. Rules change overnight. When billing protocols lack internal controls, financial penalties and False Claims Act liability follow quickly behind.


Where Labs Usually Get Burned

When reviewing Federal enforcement actions, one may find specific aspects of operations that lead to regulatory setbacks, including clawbacks and fines. For example, OIG has on multiple occasions published fraud alerts with the primary goal of targeting genetic testing practices and has pointed out that claims that result in financial penalties most often stem from major failure of the system's processes rather than from honest error.

Common High-Risk Testing Behaviors:

  • High-Risk Testing Behaviors.
  • Billing unbundled molecular CPT codes.
  • Bill a panel without a chart proof.
  • No signature by the doctor on the order.

Use of non-compliant lead-generation practices that may violate healthcare marketing regulations. Incorrect use of unlisted codes that relate to the genome.

Examine billing of multi-gene panels for cancer. Legal consequences come immediately when multi-gene hereditary cancer or pharmacogenomic panels are billed without showing the medical necessity of each individual gene target. Paying entities do not generally accept that a broadly screening panel is a medical necessity simply because a patient has a family history of disease. In addition, laboratory-marketing relationship set-ups frequently breach the Eliminating Kickbacks in Recovery Act (EKRA) and the Anti-Kickback Statute. When labs pay for marketing services in proportion to volume or claim value, they open themselves up to the possibility of being investigated by the Department of Justice, a common compliance issue that many lab managers face.

Navigating Medical Necessity and Coverage Controls

Defining medical necessity in genetics testing is really about finding a middle ground between clinical utility and coverage criteria determined by payers. An example is when a physician thinks a 50-gene panel is the ideal choice for giving the right diagnosis. Still, if the local coverage policy (LCD) lists just five genes as the only ones that are covered and the patient's condition is consistent with only these genes, then the doctor will be referring to the patient for the other testing that the insurance is not covering.

Maintaining billing compliance, organizations must master the requirements set by the Molecular Diagnostic Services (MolDX) program and commercial utilization management policies. Commercial payers and state Medicaid programs frequently diverge on prior authorization rules, creating administrative friction for billing staff. Truth is, what works for Medicare might fail completely with a commercial plan.

Key Operational Checks for Coverage:

  • Review local coverage rules monthly.
  • Get prior approval before testing.
  • Document clinical rationale in charts.
  • Verify specific CPT code coverage.
  • Check doctor order signatures daily.

A pre-test verification procedure is a compulsory setup. If a lab gets referrals from community physicians outside, it will be wrong to assume that the requesting provider already wrote medical necessity notes in their EMR. The lab on its own has to verify that clinical records back up the selected test panel before carrying out the test and presenting the charge. Not checking the chart papers exposes the lab to risks during an after-payment review of billing practices. So, you don't ever want to end up having that as your big error.

How to Build an Audit Framework That Works

To prevent improper payments, progressive health systems are moving away from passive retro-audits. Implementing an active Genetic Testing Stewardship Program (GTSP) provides a proven operational blueprint. For example, Nemours Children’s Health successfully curtailed unnecessary genetic testing orders by placing certified genetic counselors directly into the ordering workflow and embedding hard-stops in their Electronic Health Record (EHR) systems.

A solid internal audit framework evaluates claims both before submission and after payment. Health systems must establish routine internal controls that evaluate coding accuracy, physician intent, and documentation completeness.

Essential Audit Program Controls:

  • Add decision support in EHR.
  • Audit high-risk codes monthly.
  • Use genetic counselors as gatekeepers.
  • Track payer denial codes weekly.
  • Check fair market value rates.

Concurrently, compliance teams should conduct random quarterly audits on claims utilizing unlisted CPT® codes (such as CPT® 81479). Unlisted codes attract automatic payer scrutiny. If your team uses unlisted codes to bypass prior authorization or LCD restrictions, auditors will flag those claims for recoupment. Training billing personnel to double-check local coverage policies ensures that claims align precisely with current billing guidelines.

Real Exposure Under Federal Statutes

The risks linked to statutory non-compliance are not just limited to denial of claims.  Compliance risks related to molecular diagnostic services can have far-reaching consequences, including the imposition of heavy statutory penalties under the False Claims Act, Stark Law, and EKRA. Pursuant to the False Claims Act, if one submits claims for tests that do not have a documented medical necessity, this may result in the payment of triple damages plus the imposition of compulsory civil money penalties per claim.

Labs need to figure out as well, how they relate their working relationships, if any, with ordering physicians, and clinical consultants. It is a federal crime under anti-kickback laws to distribute free point-of-care testing devices, offer lavish consulting arrangements, or to provide generous collection fees to ordering clinics. Basically speaking, financial arrangements between you and a referrer should only be as much as the Fair Market Value (FMV) of the service actually done. Besides, having clear and complete documentation of FMV determinations and legal opinions is another defense measure that every lab board should definitely work on.

About the Author

Ricky Bell (https://www.dastifysolutions.com/team/rickybell/) is Head of Operations at Dastify Solutions, where he oversees healthcare operations, revenue cycle management, and compliance initiatives for physician practices, clinical laboratories, and healthcare organizations across the United States. With extensive experience in medical billing, coding compliance, denial management, and revenue cycle optimization, he helps healthcare providers strengthen operational efficiency while maintaining regulatory compliance.

Resources

  1. U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG): Fraud Alert: Genetic Testing Scam.
    https://oig.hhs.gov/fraud/consumer-alerts/fraud-alert-genetic-testing-scam/
  2. American Health Law Association (AHLA): Fraud and Abuse Issues in Diagnostic and Molecular Testing.
    https://www.healthlawyers.org
  3. Centers for Medicare & Medicaid Services (CMS): MolDX: Molecular Diagnostic Tests (LCD L35025).
    https://www.cms.gov/medicare-coverage-database/view/lcd.aspx?lcdid=35025
  4. Kaiser Family Foundation (KFF): Coverage of Breast Cancer Screening and Prevention Services.
    https://www.kff.org/womens-health-policy/coverage-of-breast-cancer-screening-and-prevention-services/
  5. National Center for Biotechnology Information (NCBI / PMC): The Genetic Testing Stewardship Program: A Bridge to Precision Diagnostics for the Non-genetics Medical Provider.
    https://pmc.ncbi.nlm.nih.gov/articles/PMC9124555/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Healthcare Revenue Cycle Compliance

Common Risks and How Practices Can Address Them 

Written by: Zara Ahmad 

A revenue cycle rarely breaks because of one dramatic mistake. More often, the problem begins with something ordinary: an insurance card was updated but the old plan stayed in the system, a provider’s note lacked enough detail for coding, or a denied claim was resubmitted before anyone checked the first one.

Compliance is not limited to the billing office. It starts when patient information is collected and continues through documentation, coding, claim submission, payment posting, denials, and follow-up.

Where Compliance Risks Can Enter the Revenue Cycle

Consider a routine office visit. The front desk enters the patient’s demographic and insurance information. If the member number is wrong, or the payer on file is outdated, the claim may already be inaccurate.

The next risk may appear in the medical record. A provider knows what happened during the visit, but a coder can only rely on what is documented. If a note is vague, staff should not fill in missing details from habit or assumption.

Charge capture creates another point of exposure. A service can be missed, entered twice, or attached to the wrong date. Later, a biller may resend a denied claim without confirming whether the original is still processing. Payment posting and accounts receivable follow-up can create problems too, especially when adjustments or corrections receive little review.

Common Revenue Cycle Compliance Risks

One familiar risk is a mismatch between the medical record and the claim. The service billed should be supported by the documentation. CMS guidance for Medicare makes documentation part of determining whether applicable coverage, coding, billing, and payment requirements are supported.

Incomplete documentation is often less obvious. A note may show that care occurred but still omit information needed to support a code, modifier, or service level. If that happens regularly, the issue is no longer just one troublesome claim.

Administrative mistakes matter as well. Incorrect patient details, insurance information, provider identifiers, and dates of service can cause denials and repeated corrections. Duplicate claims are another example. When payment is delayed, resubmitting the same claim may feel harmless, but claims-processing rules include duplicate edits.

Corrections need a consistent approach – contingent upon the payer and circumstances, the right step may be a corrected claim, replacement claim, appeal, or another defined process.

Why Documentation and Coding Accuracy Matter

Documentation, coding, and billing are different jobs, but they should describe the same encounter.

Suppose a coder returns the same type of note to the same provider several times each month because one detail is routinely missing. Correcting each claim solves the immediate problem, not the workflow problem.

A short, focused discussion with the provider may be more useful than another round of individual corrections. The aim is simply to make sure the record clearly reflects the service provided and gives coding staff the information they need.

Using Internal Audits to Identify Compliance Risks

Internal audits are most useful when they answer a specific question.

A manager might sample claims involving a frequently used modifier, one provider, a service with rising denials, or a payer that has generated repeated corrections. The review can compare claims with medical records, check key fields, examine adjustments, and see whether staff followed internal procedures.

Patterns often tell the real story. Several eligibility denials traced to the same registration step suggest a front-end workflow problem. Repeated coding questions may point to training or documentation habits instead.

An audit should lead somewhere. Someone needs to own the follow-up, record what changed, and later check whether the change helped.

Building a Stronger Compliance Culture

Compliance works better when people see how their own work affects the claim. Front-office staff influence patient and insurance information. Providers influence documentation. Coders and billers influence what reaches the payer. Managers decide whether recurring problems are investigated or simply worked around.

OIG’s General Compliance Program Guidance discusses written policies, education, communication, auditing and monitoring, and corrective action as parts of a compliance program. In everyday practice, those ideas are more useful when connected to real problems rather than treated as an annual checklist.

Training should follow the same principle. If an audit finds repeated modifier errors, train on that issue. If registration mistakes are driving denials, review that workflow with the people who perform it.

Practical Steps Healthcare Practices Can Take

  1. Review a representative sample of claims regularly.
  2. Compare billed codes with the supporting medical record.
  3. Track denials and claim corrections by reason.
  4. Review write-offs, refunds, adjustments, and claim changes for consistency.
  5. Use recurring errors to guide staff and provider education.
  6. Keep billing and compliance procedures current and easy to find.
  7. Document corrective actions and check whether they worked.
  8. Follow relevant CMS, OIG, and other authoritative guidance as requirements change.

Keeping Compliance Part of Everyday Work

No revenue cycle will be completely free of errors. What matters is what happens after a mistake is found. Comply with overpayment rules. Submit appropriate claims adjustments, credit balance reports, or self-reported refunds directly to your assigned Medicare contractor.

Investigate. Correct the affected account, but do not stop there. Ask where the error entered the process, why it was not caught earlier, and whether the same thing is happening elsewhere. That turns compliance from a periodic exercise into part of ordinary revenue cycle work. Over time, it can reduce avoidable rework, support more accurate billing, and leave a practice better prepared when claims are reviewed.

About the Author

Zara Ahmad is a healthcare industry professional and Marketing Team Lead at MedsIT Nexus, with a focus on healthcare revenue cycle management, healthcare operations, and industry education. Her work involves developing educational resources on healthcare administration, revenue cycle processes, and operational challenges affecting healthcare organizations.

Resources – obtain training in conducting internal audits and investigations from the American Institute of Healthcare Compliance, a Licensing/Certification partner w/CMS.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

HCC Coding in 2026

Navigating Risk Adjustment in a Changing Healthcare Landscape 

Written by: Joy Rose, MSA, RHIA, CCS, CHA, CHPS 

In 2026, Hierarchical Condition Category (HCC) coding continues to evolve as a central pillar of risk adjustment in value-based care. Initially introduced by the Centers for Medicare & Medicaid Services (CMS) to project healthcare costs and determine payments for Medicare Advantage (MA) plans, HCC coding has become a strategic necessity across multiple payers and care settings.

Medicare Advantage Organizations (MAOs) are paid at a higher rate for patients who have conditions with greater levels of severity and multiple conditions, as their RAF scores and anticipated costs of care will be higher.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.

  • Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.
  • This requirement adds significant complexity to an already error-ridden annual Cost Report process.

Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

New in 2026 - Full transition to V28 Model has occurred

One of the biggest updates in 2026 is the full implementation of the CMS-HCC V28 model, which was first introduced in 2023. This model includes significant changes:

  • More clinically relevant or accurate groupings, especially for chronic conditions like diabetes and congestive heart failure.
  • Expanded but refined HCC categories: V28 increases the number of HCC categories from 86 to 115, creating more granular groupings while reducing additive combinations.
  • Renumbering and changing HCC categories.
  • Removal of some condition codes that were found to be less predictive of future healthcare costs.
  • Reduction in the number of ICD-10-CM codes from 9,797 to 7,770 (approximately 2294 codes deleted and 268 codes added)
  • More accurate clinical data and the use of data-drive results with the use of 2018 ICD-10-CM codes and 2019 payment information.

Healthcare providers must now re-map workflows for diagnosis coding processes and re-educate coding staff to ensure accurate code assignment based on the documentation provided by clinicians.

Greater Emphasis on Documentation Integrity - With more sophisticated audits by CMS and private payers, clinical documentation improvement (CDI) remains a top priority. Inaccurate or unsupported codes now carry steeper compliance risks, and real-time documentation tools are being widely adopted to assist clinicians. Clinicians must be educated and trained about the new model which will require even greater specificity in documentation and code assignment to ensure that the true level of the Medicare Advantage patients’ illness severity is captured and transmitted to CMS for appropriate costs analysis.

AI and NLP Integration - Natural Language Processing (NLP) and artificial intelligence (AI) tools are increasingly embedded in EHR systems to assist in identifying undocumented HCCs and improving capture rates. These tools help flag missed conditions, identify hierarchical overlaps, and ensure that chronic conditions are properly documented and reported annually. AI has its limitations according to a colleague managing denials.

Important Note - The AI tool that is being tested a major Boston medical facility is not intelligent enough to find HCCs, or even ICD-10 codes to ensure a robust denial can be created.  The medical team working with the denials team does not approve the AI findings in about 80% of the AI suggestions.

Key Challenges - Training and education remain critical as coding teams and clinicians adjust to new rules and technology.  In addition, there is coding fatigue from increased workload and regulatory pressure may affect coder accuracy and job satisfaction.

Providers must also balance HCC optimization with ethical standards and compliance, avoiding aggressive or unsupported upcoding practices. It is important for organizations to realize there is increased CMS scrutiny, by flagging providers as high-volume billing outliers or submitting claims with unusually high severity levels.

Opportunities:

  • Risk-adjustment data analytics now allow organizations to benchmark performance and track documentation trends in real time.
  • Proactive condition management enabled by accurate HCC coding allows payers and providers to better target care management and reduce preventable costs.
  • Interoperability and FHIR-based data exchange in 2026 enable smoother sharing of clinical data across systems, improving longitudinal risk tracking.
  • Increased focus on severity of patient diagnosis and claims by CMS

Real World Impact

As CMS moves further into outcome-based models and enhances its oversight of MA payments, the role of HCC coding will only grow in significance. Health systems that invest in robust CDI programs, AI-assisted coding tools, and clinician training will be better positioned to thrive in this value-based future.

Some analysts warn the shift could lower RAF scores 10-20% for providers still relying on V24-era documentation habits, since patients whose only qualifying condition was deleted in V28 effectively disappear from risk registries. Plans with large diabetic populations that previously captured a lot of complication-related detail are seeing the steepest declines, though expanding documentation breadth across different disease families can partly offset this.

Because of the revenue pressure, CMS/OIG have signaled they'll be watching closely for organizations overcompensating with inflated severity coding.

About the Author

Joy Rose, MSA, RHIA, CCS, CHA, CHPS is a member of the American Institute of Healthcare Compliance (AIHC) and serves as a subject matter expert on the AIHC Volunteer Education Committee.

References:

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Written by the American Institute of Healthcare Compliance Education Department 

The American Institute of Healthcare Compliance (AIHC) is a non-profit training organization offering certification to become a Certified Cost Report Specialist (CCRSSM) and is a Licensing/Certification Partner with CMS.  The information below is not all inclusive, is not legal or consulting advice and is for educational purposes only.

Introduction

Filing Medicare Cost Reports (MCRs) is a highly complex, high-stakes process involving intricate, frequently changing CMS regulations, extensive data allocation, and strict documentation requirements.  Due to the complexity, errors are frequent, according to findings reported by the Office of Inspector General (OIG).

As a cornerstone of the Medicare program, the MCR serves as the annual mechanism for providers to report descriptive, financial, and statistical data to CMS. Pursuant to 42 CFR §413.20(b), Medicare-certified providers are mandated to submit this comprehensive financial record to determine the proper settlement of costs for services rendered to beneficiaries. Beyond ensuring that interim payments accurately reflect actual costs, the MCR is critical for establishing future reimbursement rates, including wage indices, disproportionate share hospital (DSH) adjustments, and graduate medical education (GME) payments. Failure to file, or inaccurate filing, carries significant financial risks, making an understanding of these reports crucial for regulatory compliance and financial stability.

While frequently viewed as a burdensome regulatory filing, the MCR constitutes one of the most comprehensive, standardized, and publicly available sources of institutional financial data in the United States. As Medicare moves toward greater fiscal accountability, the MCR allows providers to identify operational inefficiencies, manage financial performance, and ensure compliance in a complex reimbursement landscape.

Which Organizations File MCRs?

Medicare-certified institutional providers, typically Part A providers, must file annual Medicare cost reports (MCR) to determine reimbursement, usually within 5 months (or 150 days) after the end of their fiscal year. These reports, filed to a Medicare Administrative Contractor (MAC), are required for hospitals, skilled nursing facilities, home health agencies, hospices, FQHCs, RHCs, and ESRD providers.

Institutional Providers Required to File Medicare Cost Reports:

  • Hospitals: Including general, psychiatric, rehabilitation, long-term care, and children’s hospitals
  • Skilled Nursing Facilities (SNFs)
  • Home Health Agencies (HHAs)
  • Hospice Providers:
  • Federally Qualified Health Centers (FQHCs):
  • Rural Health Clinics (RHCs)
  • End-Stage Renal Disease (ESRD) Facilities
  • Organ Procurement Organizations (OPOs)
  • Community Mental Health Centers (CMHCs)

When are Cost Reports Due to be Filed?

Providers should use the Medicare Cost Report Electronic Filing (MCReF) system for submissions.  The cost report is due on or before the last day of the fifth month following the close of the provider's fiscal year and filed to the provider’s Medicare Administrative Contractor (MAC).

  • Example: For a fiscal year ending December 31, the report is due May 31.
  • Non-Month-End Closings: If the fiscal year does not end on the last day of the month, the report is due 150 days after the last day of the cost reporting period.

Failure to submit can result in the suspension of Medicare payments, increased audit risk, and loss of reimbursement.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.  Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.

This requirement adds significant complexity to an already error-ridden annual Cost Report process. Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

OIG Audits CMS Contractor Cost Report Compliance

Take a look at some recent Office of the Inspector General (OIG) audit reports to see how large the financial impacts of noncompliance can be for MACs, which falls back onto the provider.

A September 2025 audit by the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) found that Novitas Solutions, Inc. (Novitas), a Medicare Administrative Contractor (MAC), failed to properly review 100% of the cost reports examined in a specific sample.

  • The errors caused by inadequate reviews led to a total of $9.4 million in corrected final settlements, consisting of $5 million in overpayments and $4.4 million in underpayments to providers.

A similar, separate OIG audit released in September 2025 also found that National Government Services, Inc. (NGS) had a 100% error rate (64 out of 64) in a sample of reopened cost reports, resulting in $5.6 million in corrected settlements.

  • The 64 cost report reopening's resulted in corrected final settlements to providers totaling $5.6 million (which consisted of $3.1 million in overpayments and $2.5 million in underpayments).

Key Findings on Cost Report Errors:

  • High Error Incidence: A 2025 OIG report revealed that 12 Medicare Administrative Contractors (MACs) failed to meet oversight requirements, with a 70% failure rate in reviewing filings.
  • Specific Errors: Common errors included misclassification of physician salaries, improper nursing/allied health program calculations, and improper bad debt reporting.
  • Financial Impact: These errors resulted in massive financial inaccuracies, including one case involving over $250,000 in improper overpayments.
  • Audit Surge Expected: Due to these findings, an increase in audits and oversight by MACs is expected.

Common Causes of Errors:

  • Inconsistent Data Sources: Failure to reconcile internal financial systems with patient data (e.g., midnight census, revenue usage files).
  • Complex Allocations: Miscalculating the allocation of costs between Medicare and non-Medicare patients.
  • Failure to Update: Carrying over errors from previous years instead of updating with current data.

Implications of Errors:

  • Overpayment Recovery: MACs can claw back funds, requiring repayment with interest.
  • Underpayments: Errors can lead to lower-than-earned reimbursements.
  • Increased Audit Risk: High error rates trigger more intensive reviews and potential civil monetary penalties.

Notable Cases of Noncompliant Medicare Cost Reporting

  • Non-Compliance with Medicare Cost Reporting Requirements

In 2018 the Office of Inspector General (OIG) reported that the National Institute of Transplantation (NIT), an independent histocompatibility lab, did not fully comply with Medicare’s cost-reporting requirements.  In the cost report in question, NIT had correctly reported only 177 of 186 cost transactions.  In total, the OIG estimated that NIT had received approximately $45,940 in overpayments from Medicare. 

OIG concluded their audit report by recommending that NIT work with the Medicare Administrative Contractor to return potential overpayments and identify any additional similar overpayments that may be related to cost reports.

  • Referring Medicare Cost Reports and Reconciling Outlier Payments

Several years ago, two organizations were cited by OIG as not always correctly referring their Medicare cost reports to CMS.  For example, Cahaba Government Benefit Administrators, LLC (Cahaba GBA) had only referred 5 out of 13 cost reports with outlier payments that were qualified for reconciliation to CMS.  The financial impact of this noncompliance was estimated to be over $9,700,000 in total, of which just over $601,000 was due to Medicare. 

Another organization, CGS Administrators, a healthcare administrator operating as a Part A, Part B, and Home Health & Hospice (HH&H) MAC for Jurisdiction 15, had referred 15 of 18 qualified cost reports to CMS for reconciliation, but of those 15 referred reports, they had neglected to reconcile the outlier payments for 14 reports.  The financial impact of these affected reports was estimated at about $39,000,000 combined, with over $16,000,000 due to Medicare.

  • Non-Compliance with Medicare Organ Statistic Requirements

In 2012, LifeCenter Northwest, a federally designated independent organ procurement organization, was reported to have not fully complied with Medicare requirements for reporting organ statistics.  In the affected cost report, LifeCenter had reported incorrect organ statistics for 15 different organs. 

If was found that Medicare’s share of organ procurement costs was overstated by about $88,000.  OIG recommended that LifeCenter submit a revised cost report to correct the overstatement and work to ensure that future reports followed Medicare requirements.

Implement Strategies Now for Compliance

  1. Internal Routine Auditing: Implement proactive monitoring to verify that data—especially payroll and equipment costs—is accurate before submission.
  2. Incorporate Prior Audit Results: Avoid repeating adjustments from previous years, as recurring errors act as "red flags" for fiscal intermediaries.
  3. Rigorous Documentation: Maintain granular support for "allowable" costs, such as marketing (informational vs. promotional) and bad debt collection efforts.

Start by addressing critical high-risk components of the report.  CMS Auditors and the Office of Inspector General (OIG) focus on several key items within the cost report.  Your organization should also focus on these same areas when conducting internal compliance audits:

  • Graduate Medical Education (GME) & Indirect Medical Education (IME):
    • Inaccurate reporting of Graduate Medical Education (GME) payments, indirect medical education (IME) costs, and Medicare bad debts.  These involve complex resident counts and are frequent targets for in-depth audits.
  • Medicare Bad Debts:
    • Facilities must prove they used "reasonable" collection efforts for non-collectible deductibles and coinsurance. Improperly documented Medicare bad debts are a frequent source of audit findings.
  • Disproportionate Share Hospital (DSH) Payments:
    • Disproportionate Share Hospital (DSH) calculations are considered high-risk audit areas on the Medicare Cost Report. Due to the complexity of the regulations and the significant financial impact on reimbursements, these calculations frequently lead to errors, underpayments, or overpayments, according to the OIG.
  • Schedule S-10 (uncompensated care UCC):
    • Worksheet S-10 is a major audit trigger as it directly affects reimbursement rates.  Auditors target improper documentation of uncompensated care on Schedule S-10, which impacts UCC/DSH payments.  As of 2026, Medicare Administrative Contractors (MACs) are scrutinizing these filings, focusing heavily on documentation that supports charity care and bad debt, according to CMS.
    • The UCC and DSH go hand-in-hand as an add-on to the DRG reimbursement, but are calculated separately. 
  • Wage Index Data:
    • This data is used to set future prospective payment rates; inaccuracies can lead to billions in misapplied funds.
  • Operational Deficiencies:
    • Late submissions, inadequate training of staff, and poor oversight of third-party contractors can lead to compliance issues.
  • Vaccinations: 
    • Vaccinations are considered a high-risk error area on Medicare cost reports for Rural Health Clinics (RHCs) and Federally Qualified Health Centers (FQHCs). Errors often arise from failing to reconcile interim payments with actual costs, lacking proper documentation (logs, invoices, time studies), and missing or incorrect coding (e.g., Condition Code A6) on claims.

Conclusion - Include Cost Report Audits in Your Compliance Program

Because Compliance Officers often overlook the high-risk area of cost reporting, it is important to implement internal routine auditing and monitoring to ensure data submitted is accurate and timely.

Your Compliance Department should be overseeing areas which can pose a high financial or legal risk to the organization.  Cost reporting falls into both categories, requiring internal auditing and monitoring of this function to ensure accuracy and timeliness is observed.

Inaccurate filing or late submissions can result in immediate payment suspension, civil monetary penalties, or exclusion from the Medicare program.  All this can be avoided through appropriate preparation and accurate training.

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

American Institute of Healthcare Compliance (AIHC®)

CMS

Code of Federal Regulations

Noridian Healthcare Solutions

Office of Inspector General

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Is it an Audit, Gap Analysis or Risk Assessment?

For Auditors and Compliance Officers 

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

New to Compliance & Auditing for Compliance?  This short article is #3 in a three-part series addressing various areas of auditing and monitoring healthcare providers for compliance.  You may want to read Article #1 – Importance of Compliance Audits and Article #2 Auditing for Anti-Kickback Statute Violations.

Introduction

A healthcare compliance audit checks adherence to laws (such as HIPAA, Stark, Anit-Kickback Statue, coding, billing rules) and includes reviewing written policies, assessing internal controls, verifying staff training, monitoring data security, examining processes, interviewing staff, and ensuring a robust reporting/corrective action process is in place.  This is all aimed at risk reduction and better patient care.

The focus of this article is to discuss the difference between a Gap Analysis and Risk Assessment when conducting an audit.

Conducting an Audit can be Complex

To audit, gap analyze, and risk assess healthcare compliance, an organization systematically identifies standards, gathers data, evaluates compliance gaps and threats, prioritizes issues, then create corrective plans.  This is followed by conducting monitoring audits and review to find and fix deficiencies before they become major problems. It is a continuous process.

Core Components of a Healthcare Compliance Audit often include:

Risk Assessment & Scope

  • Identifying high-risk areas (e.g., billing, privacy, patient safety) and defining what the audit will cover.

Performing a Documentation Review

  • Checking written policies, procedures, training records, consent forms, and compliance plans for completeness and accuracy.

Testing Internal Controls

  • Evaluating safeguards for data (EHR, access), billing, and operations to prevent fraud and errors.

Workforce Competency

  • Verifying that employees understand and follow policies through training logs and interviews.

Conducting Interviews & Observation

  • Talking to staff and watching workflows to see if policies are truly followed in practice.

HIPAA Compliance

  • Data Security & Privacy auditing to determine HIPAA/HITECH compliance, access controls, and breach protocols.

Billing & Coding Accuracy

  • Performing pre-billing and post-billing audits to ensure claims are correctly coded and comply with payer rules.

Reporting & Investigation

  • Assessing the effectiveness of hotlines, whistleblower protections, and how reported issues are handled.

Corrective Action Plan (CAP)

  • Developing and tracking steps to fix any identified compliance gaps.

Gap Analysis

The distance between where you are where you need to be

Conducting an audit often requires performing a gap analysis.  A gap analysis identifies the difference between your current state and desired compliance levels.   Simply put, it starts by defining the compliance goal, assesses current performance (what your organization is actually doing) and pinpointing exactly where the organization is falling short.

In healthcare compliance, a Gap Analysis finds what you're missing compared to a standard (e.g., Coding or HIPAA rules), showing the "what's missing" and "how far" from compliance, while a Risk Assessment identifies why you're vulnerable, evaluating the likelihood and impact of threats (like breaches) to determine what controls are truly needed to mitigate risk, forming two complementary steps to achieve full, effective compliance, not replacements for each other.

Key Steps for Risk Mitigation Gap Analysis:

1. First, start with defining the scope and objective.

  • Clearly state what you're analyzing (processes, compliance, performance) and the desired outcome or standard (e.g., regulatory compliance, industry best practice).

2. Next, define benchmarks, goals that need to be met.

  • Define the desired state. Establish benchmarks, goals, and ideal performance levels, often based on regulations, standards, or strategic objectives.
  • Create list of items being measured and evaluated.

3. Conduct an Evaluation to Assess Current State.

  • Document existing performance, processes, policies, and controls, gathering data through audits, interviews, and metrics.

4. Identify & Analyze Gaps.

  • Compare current vs. desired states to find discrepancies.
  • Use tools like SWOT or process mapping to visualize inefficiencies, as taught by AIHC in the Auditing for Compliance online course which addresses gap analysis.

5. Conduct Root Cause Analysis (RCA).

  • Dig deep to understand why gaps exist (e.g., outdated policies, lack of training, resource issues).

6. Prioritize or Rank by Severity.

  • Rank gaps by severity, impact, and risk level (e.g., using an impact/effort matrix) to focus on the most critical issues first.

7. Develop Action Plan (Remediation).

  • Create detailed plans with specific actions, assigned owners, resources, timelines, and success metrics to close each prioritized gap.

8. Implement & Execute.

  • The organization must act and ensure necessary resources and support are in place.

9. Monitor & Review.

  • Continuously track progress, measure results against KPIs, and make adjustments to ensure effective risk reduction.

10. Communicate & Report.

  • Share findings and progress with stakeholders to maintain transparency and buy-in.

Risk Assessment – The “Why” and “How Bad”

After identifying what's missing (the gaps), the risk assessment quantifies how bad those gaps are. The risk assessment evaluates potential threats to compliance and patient safety.  This process explains why gaps matter and dictates what to fix to manage risk effectively.  It includes an impact analysis, evaluating controls and calculate residual risk.

Difference between Gap Analysis & Risk Assessment:

Gap Analysis = Current vs. Standard

Risk Assessment = Threats/Vulnerabilities vs. Assets

Key steps for a risk assessment following a gap analysis:

1. Identify Risks from Gaps.

  • Take the identified gaps (e.g., lack of security training, outdated software) and pinpoint the specific threats or vulnerabilities they create (e.g., phishing, data breach, system failure).

2. Analyze Risk (Likelihood & Impact). For each identified risk, determine.

  • Likelihood: How probable is it that this risk will occur?
  • Impact/Severity: How bad would the consequences be (financial, operational, reputational) if it did happen?

3. Evaluate & Prioritize Risks.

  • Combine likelihood and impact to score each risk (e.g., High, Medium, Low) and prioritize them. Focus on high-impact, high-likelihood risks first.

4. Develop Mitigation (Control) Strategies.

  • For prioritized risks, design actions to eliminate, reduce, or transfer the risk. These are your control measures (e.g., implementing training, upgrading systems).

5. Record Findings & Controls.

  • Document the entire process, including identified risks, analysis, chosen controls, and responsibilities. This is often a legal requirement.

6. Implement Controls.

  • Put the planned actions into practice.  

7. Monitor & Review.

  • Don’t stop short, complete the cycle by regularly checking if controls are working and update the assessment as the environment, threats, or business needs change.

Auditing for Compliance

Even if you have some audit experience, taking an online course and certifying can fill-in knowledge gaps and provide essential skills to lead an audit team.

To become a lead auditor, many organizations will require you to complete a training course that covers auditing principles, management systems, and leadership skills, followed by passing an exam and gaining auditing experience, such as offered by the American Institute of Healthcare Compliance (AIHC), recognized as a Licensing/Certifying partner with the Centers for Medicare & Medicaid Services (CMS).

Resources to Stay Informed

Lead Auditors and Compliance Officers need to stay informed.  Subscribing to government notifications is one way.  You may also want to review current educational articles (free) published by the American Institute of Healthcare Compliance (AIHC)– click here for the Auditing category, and view all articles or by additional categories. 

Videos can be a helpful way to stay informed.  We recommend the following which may be of interest for you or members of your audit and compliance team!

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

  • Auditing for Compliance online training course by the American Institute of Healthcare Compliance.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

What Government Enforcement Can Teach Us About Coding and Reimbursement

Written By: CJ Wolf, MD 

This article presents educational information related to compliant documentation, coding and billing to avoid fraud, waste and abuse in our healthcare system. Dr. Wolf makes his point by presenting a qui tam case related to vascular diagnostic testing.

Medical coding is a critical aspect of accurate reimbursement for a variety of medical services. Many healthcare compliance enforcement actions, especially those brought under the Federal False Claims Act (FCA), stem from allegations of inaccurate coding.

Healthcare compliance professionals can learn a great deal from diving deep into the details of various enforcement actions. As it relates to medical coding, some enforcement actions teach compliance and coding professionals a great deal of how inaccurate coding can lead to significant investigations and multi-million-dollar settlements.

The details behind a recent $37 million settlement between the U.S. government and a medical device company, along with their former distributor, inform coders and compliance professionals about the risks of inaccurate coding related to a common medical condition known as peripheral arterial disease (PAD)1.

PAD in the lower extremities is the result of narrowing or blockage of the arteries carrying blood with oxygen to the legs. A common symptom for patients with PAD is leg pain when walking. This type of pain is frequently referred to as claudication. Physicians use their clinical knowledge, experience and certain tests to diagnosis PAD and its varying degrees of severity.

One of the most common diagnostic tests utilized by physicians to evaluate PAD is the ankle brachial index (ABI). The test can help estimate the severity of the blockage, which is important when planning treatment and management options. Medicare has coverage policies and requirements for tests that can measure blood circulation in situations such as PAD. The critical policy that played a major role in this multi-million-dollar settlement is Medicare’s National Coverage Determination (NCD) 20.14 on plethysmography.  Plethysmography involves the measurement and recording (by one of several methods) of changes in the size of a body part as modified by the circulation of blood in that part.

In addition, the definitions of certain Current Procedural Terminology (CPT®) codes, 93922, 92923, or 93924 must be accurately met to submit these codes on claims to Medicare for reimbursement of these diagnostic tests. The medical codes require that a provider conduct an ABI test plus certain additional testing. In addition, Medicare does not cover noninvasive vascular tests that use photoelectric plethysmography, also known as photoplethysmography (PPG), which uses a light sensor to detect changes in blood volume.

For example, the Medicare NCD classifies the types of technology used for the testing that is covered compared to those not covered. The covered and non-covered procedures from the NCD are listed below:

Covered

  • Segmental Plethysmography
  • Electrical Impedance Plethysmography
  • Ultrasonic Measurement of Blood Flow (Doppler)
  • Oculoplethysmography
  • Strain Gauge Plethysmography

Non-covered (Medicare considers these experimental)

  • Inductance Plethysmography
  • Capacitance Plethysmography
  • Mechanical Oscillometry
  • Photoelectric Plethysmography

Two experts in vascular diagnostic testing filed a qui tam, or whistleblower, lawsuit under the False Claims Act. They alleged the companies were marketing their devices to providers, such as physicians, telling them their testing device could be reimbursed by Medicare even though the procedure used is PPG, which is a non-covered classification as described in Medicare’s NCD. The government intervened in the case and joined in alleging that the medical codes submitted on claims to Medicare were inaccurate, thus the companies caused providers to submit false claims.

According to the legal complaint filed with the courts, the whistleblowers stated that the device manufacturer and their distributor promoted use of their PPG devices as easier, quicker, and less expensive than the use of Doppler technology for diagnosing PAD. They also claimed the companies said Medicare (and other government payers) pay out the same amount for any service that fits within a specific CPT code, irrespective of the actual cost to a medical provider to provide the service. Medical providers are consequently incentivized to perform the most inexpensive and least time-consuming services that qualify for a specific CPT code. Because the company claimed these PPG products are much less expensive and faster than the traditional diagnostic tests the devices can "diagnose" PAD within as little as five minutes, while traditional diagnostic tests take approximately 30-45 minutes.

The legal complaint also included materials about how the companies marketed the devices to providers.

The whistleblowers claimed:

  • The companies marketed one of their devices as a "new reimbursable office diagnostic test you can perform quickly and easily with no capital equipment purchase and no specialized personnel."
  • A physician gave a presentation at the New Cardiovascular Horizons (NCVH) conference and promoted the device as a method to help "increase your daily practice revenue." The presentation addresses the CPT codes that can purportedly be used to bill Medicare for services using the device and lists CPT codes 93922 and 93923.

Lessons Compliance Professionals Can Learn

Compliance professionals working for hospitals or physicians can learn a great deal from these details, such as:

  • First, compliance professionals should ensure the accuracy of any coding and reimbursement advice coming from device and/or pharmaceutical manufacturers.
  • Second, diligently review and follow Medicare and Medicaid coverage policies.
  • Third, go beyond just reading a medical code’s definition. Review enforcement settlements, audits, and authoritative references for the proper and intended use of medical codes.

This is just one of many enforcement actions that healthcare compliance professionals should be conversant about if they perform services for the common condition of PAD.

About the Author

CJ Wolf, MD, CPC, CPB, COC, AAPC Approved Instructor, is a highly regarded healthcare professional with more than 25 years of experience in revenue cycle management, practice management, compliance, coding, billing, auditing, and client services. He is a nationally recognized compliance thought leader who has published numerous articles and resources and has been featured at national conferences and events. He is a subject matter expert with Healthicity, a leading provider of compliance and auditing software solutions at https://www.healthicity.com

References:

  1. https://www.justice.gov/opa/pr/semler-scientific-inc-and-bard-peripheral-vascular-inc-pay-nearly-37m-resolve-false-claims
  2. https://www.cms.gov/medicare-coverage-database/view/ncd.aspx?NCDId=165&NCDver=1

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Monitoring Claims for Accuracy

Addressing Coding Discrepancies and CAC Limitations to Strengthen Quality and Compliance 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

Computer-Assisted Coding (CAC) can expedite your process, but is it accurate?  This article discusses the limitations of CAC and how to strengthen documentation and compliance to improve quality of care and improve the accuracy of your claims.

Introduction

As healthcare delivery becomes increasingly data-driven, the integrity of clinical documentation and billing practices directly impacts provider reimbursement, compliance with federal and state regulations, and ultimately, patient outcomes. Monitoring claims for accuracy is a vital process within revenue cycle management, serving as both a quality assurance tool and a compliance safeguard. A critical area of concern is the rise of discrepancies in coding, particularly when documentation appears clinically accurate, but coding errors—often exacerbated by overreliance on Computer-Assisted Coding (CAC)—compromise claim validity. This article explores the importance of proactive claim review processes, discusses the limitations of CAC, and outlines evidence-based strategies to ensure documentation and coding alignment. Emphasis is placed on quality as the foundation of compliance, with practical suggestions for mitigating discrepancies, even amid the time pressures faced by providers.

The Link Between Coding Accuracy, Quality, and Compliance

Accurate clinical coding is essential for several reasons: it ensures appropriate reimbursement, supports population health analytics, and reflects the true acuity and complexity of patient care. According to the Office of Inspector General (OIG), improper payments in Medicare and Medicaid programs continue to cost billions annually, often stemming from coding errors rather than fraud (OIG, 2022). Compliance programs in healthcare are thus required not only to prevent intentional misconduct but also to detect and correct unintentional inaccuracies in claims data.

The Centers for Medicare & Medicaid Services (CMS) stress that quality documentation alone is insufficient; it must be accurately translated into billing codes to meet compliance standards (CMS, 2021). When documentation is thorough but coding does not reflect that detail—whether due to human error, insufficient training, or flawed automation—the result is inaccurate reimbursement, potential audits, and regulatory penalties.

Computer-Assisted Coding (CAC): Promise and Pitfalls

CAC systems, designed to improve coding efficiency, use natural language processing (NLP) to extract clinical concepts from documentation and assign appropriate codes. While they can reduce manual workload and improve turnaround times, CAC tools are not infallible. Studies show that CAC accuracy varies widely depending on clinical domain and documentation quality (Dai et al., 2020). A major concern is that CAC tools may suggest incorrect codes if the software misinterprets nuanced clinical information or lacks the specificity required for precise classification.

A 2021 Journal of AHIMA study found that while CAC tools reduced average coding time, they introduced a 12–15% increase in coding discrepancies when not accompanied by robust human review (AHIMA, 2021). This “automation bias” can lead coders to accept system-suggested codes without sufficient validation. Moreover, CAC limitations are particularly evident in complex cases involving chronic conditions, behavioral health diagnoses, or overlapping comorbidities, where documentation subtleties are critical to proper code selection.

Encounter Discrepancies: Causes and Consequences

Encounter discrepancies arise when the documentation recorded by providers does not align with the diagnosis, procedure, or service codes submitted on a claim. Common causes include:

  • Overgeneralization by CAC tools, which may default to unspecified codes.
  • Provider time constraints, limiting detailed note-taking or code validation.
  • Inadequate coder training, particularly in emerging or specialty service lines.
  • Misalignment between clinical terminology and coding nomenclature.

These discrepancies may be flagged as errors during internal audits or external reviews, resulting in claim denials, delayed payments, or post-payment recoupments. Additionally, persistent discrepancies can trigger focused audits by entities such as Recovery Audit Contractors (RACs) or Unified Program Integrity Contractors (UPICs).

Evidence-Based Models for Monitoring and Review

To mitigate discrepancies and ensure accurate claims, healthcare organizations must adopt evidence-based quality assurance models that include routine claim review, coder education, and collaborative documentation practices.

  1. Plan-Do-Check-Act (PDCA) Cycle: This quality improvement framework can be applied to the coding process. Regular monitoring (Check), followed by targeted interventions (Act), and process refinement (Plan/Do), can drive measurable improvements in claim accuracy (Deming, 1986).
  2. Clinical Documentation Improvement (CDI) Programs: These initiatives promote ongoing dialogue between providers and coders to clarify ambiguities and ensure specificity in documentation. Studies have shown that robust CDI programs can increase coding accuracy by 20–30% (Garza et al., 2019).
  3. Concurrent Coding Audits: Instead of retrospective reviews, concurrent audits allow for real-time identification and correction of errors before claims are submitted. When coders or compliance specialists are embedded in the clinical workflow, they can flag discrepancies early and reduce downstream issues (AHIMA, 2022).
  4. Root Cause Analysis (RCA): When high-error claims are identified, RCA can be used to trace the source of errors—be it documentation gaps, CAC misinterpretation, or coder oversight—and develop targeted solutions.

Mitigation Strategies for Busy Clinical Environments

One of the persistent barriers to accuracy is the limited time that providers have with each patient. This pressure often leads to documentation shortcuts, copy-forward behaviors, or lack of specificity in notes, which in turn affects coding quality. The following strategies can help:

  • Leverage pre-visit planning tools that prompt providers on key documentation elements based on the patient’s problem list or chronic conditions.
  • Implement coder-provider feedback loops, where recurring discrepancies are discussed in monthly or quarterly forums.
  • Provide microlearning sessions or just-in-time training for coders, especially after major code set updates (e.g., ICD-10-CM changes each October).
  • Develop encounter-specific documentation templates that guide providers to document with the level of specificity required for accurate code assignment.
  • Use dashboards and KPIs to track claim denial reasons, coding error rates, and CAC override frequency. This enables continuous improvement monitoring.

The Role of Compliance Officers and Risk Management

Compliance professionals must view coding accuracy as a risk management issue. When errors go unchecked, they may result in False Claims Act (FCA) violations, whistleblower reports, and reputational damage. In fact, over 85% of healthcare compliance settlements involve allegations of inaccurate billing and coding (DOJ, 2023).

It is imperative that compliance teams collaborate closely with HIM (Health Information Management), billing, and clinical operations to:

  • Establish routine coding audits.
  • Analyze error trends and provider outliers.
  • Develop corrective action plans and re-education strategies.
  • Ensure CAC systems are updated and monitored for performance drift.

By embedding compliance into everyday workflows rather than viewing it as a retrospective function, organizations can create a culture of accountability that enhances both care and claim accuracy.

Conclusion

Coding accuracy is not merely a technical function—it is a linchpin of healthcare quality, financial integrity, and regulatory compliance. While documentation remains a critical starting point, coding must accurately reflect that documentation to meet standards of care and legal expectations.

As CAC tools become more prevalent, healthcare organizations must remain vigilant about their limitations and ensure human oversight remains central to coding decisions. With the implementation of quality improvement frameworks, clinical collaboration, and robust audit practices, encounter discrepancies can be mitigated—improving not only claims accuracy but also compliance resilience in an increasingly scrutinized healthcare landscape.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • AHIMA. (2021). Impact of Computer-Assisted Coding on Coding Accuracy and Productivity. Journal of AHIMA.
  • AHIMA. (2022). Concurrent Coding Audits in Clinical Workflows. American Health Information Management Association.
  • Centers for Medicare & Medicaid Services (CMS). (2021). Medicare Fee-for-Service 2020 Improper Payments Report.
  • Dai, H., et al. (2020). Evaluating the accuracy of computer-assisted coding systems in healthcare. Health Informatics Journal, 26(4), 2765-2778.
  • Deming, W. E. (1986). Out of the Crisis. MIT Press.
  • Department of Justice (DOJ). (2023). False Claims Act Settlements and Judgments: Annual Update.
  • Garza, H., Spivak, C., & Daniels, M. (2019). Documentation improvement and compliance outcomes. Journal of Healthcare Compliance, 41(3), 45-52.
  • Office of Inspector General (OIG). (2022). Top Management and Performance Challenges Facing HHS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

The Expanding Role of Artificial Intelligence in Healthcare

Compliance Considerations for Patient Care, Administration, and Financial Accountability   

Written By Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

As Artificial Intelligence (AI) changes the healthcare landscape, compliance professionals must anticipate how AI alters how organizations manage corporate compliance.  If your organization has implemented AI, your compliance program should now include cross-functional oversight committees to review and monitor AI deployments. Insights to considerations are provided below.

Introduction

Artificial Intelligence (AI) is revolutionizing the healthcare industry by enhancing diagnostic precision, increasing administrative efficiency, and fostering innovative patient care models. However, this advancement also demands rigorous scrutiny through a compliance lens.

Regulatory frameworks must evolve to match the complexity of AI-powered systems and ensure that patient rights, data integrity, and financial accountability remain protected. Compliance professionals must anticipate how AI intersects with laws such as HIPAA, the False Claims Act, and the 21st Century Cures Act to maintain ethical standards and institutional trust.

AI in Patient Care

AI’s impact in clinical environments includes risk prediction models, virtual health assistants, and real-time monitoring tools. Clinical decision support tools that analyze large datasets can help clinicians identify trends and recommend personalized interventions. However, risks such as bias in algorithmic training data or lack of explainability in AI decisions pose threats to equitable care. These concerns underscore the importance of incorporating transparency, fairness, and accountability into the AI development lifecycle.

Compliance teams must work with clinical leaders to ensure AI tools meet FDA regulatory classifications, including premarket submissions and post-market surveillance, to ensure patient safety. As AI begins to play a larger role in recommending or even initiating treatment pathways, the responsibility to ensure appropriate validation, risk mitigation, and documentation grows significantly. Ethical considerations such as patient consent and clinical override procedures must also be addressed in policy.  Recommendations for Physicians and Nurses to consider include:

  • Active participation in training to understand AI tool functionalities and limitations;
  • Remaining vigilant when evaluating AI-driven recommendations, using clinical judgment to identify potential biases or anomalies; and
  • Report concerns or discrepancies promptly to compliance teams.

Administrative Use of AI

Administrative AI tools can significantly improve workflow efficiencies by reducing paperwork, automating prior authorizations, and managing patient scheduling. For example, AI-driven chatbots help route patient inquiries, while robotic process automation (RPA) can streamline claims processing. Despite these benefits, improper configuration or inadequate oversight of administrative AI systems may introduce compliance risks such as data breaches or noncompliant billing practices which result in unintended consequences.

Compliance programs should include cross-functional oversight committees to review and monitor AI deployments. These teams should ensure the use of AI aligns with payer contract requirements and is auditable during external reviews or governmental investigations. Furthermore, organizations should ensure their administrative AI tools do not inadvertently violate payer rules or documentation standards. System logs, user feedback, and integration testing are essential to ensure that automation supports, rather than compromises, compliance. Recommendations for Medical Billing Coders to consider include:

  • Regularly review AI-generated billing and coding to verify accuracy against clinical documentation;
  • Report discrepancies or patterns of errors immediately to compliance teams; and
  • Participate in ongoing training to stay updated on coding standards and AI tool developments.

Information Blocking and AI

ASTP (the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT), previously known as “ONC” is organizationally located within the Office of the Secretary for the U.S. Department of Health and Human Services (HHS).  ASTP is the principal federal entity charged with coordination of nationwide efforts to implement and use the most advanced health information technology and the electronic exchange of health information.

AI applications that create or manage electronic health information (EHI) must comply with the ASTP’s information blocking rule. This includes tools that produce clinical summaries, generate patient documentation, or assist in diagnosis. Providers may invoke one of the eight permissible exceptions, but they must be able to justify their decisions with evidence. For example, the “Preventing Harm” exception may be valid if an AI-generated output could mislead or distress a patient.

Compliance officers must ensure that EHI-sharing policies are clearly documented; that patients have timely access to their data; and that systems are equipped to deliver requested data in accordance with federal requirements. Training and real-time decision support can help providers appropriately apply exceptions without violating the rule. Health systems must also monitor whether AI-generated data is accessible in usable formats and whether any AI-integrated tools restrict or delay data sharing in ways that could constitute noncompliance.

Recommendations for Allied Health Professionals to consider include:

  • Ensuring familiarity with AI-driven documentation and patient interaction tools;
  • Actively facilitate patient access to EHI generated by AI systems; and
  • Reporting any barriers to data sharing or potential compliance concerns promptly.

Financial Accountability and Algorithmic Errors

AI tools involved in billing or coding introduce serious financial accountability considerations. A coding algorithm that misclassifies a procedure or service can lead to overpayments and potential allegations of fraud. In such cases, the provider may be held liable under the False Claims Act if they knew or should have known about the inaccuracy. The Office of Inspector General’s (OIG) compliance guidance urges healthcare organizations to implement auditing mechanisms tailored to detect errors, regardless of whether those errors were made by means of electronic, human or AI.

Establishing protocols for reviewing AI-generated claims, comparing them to manual audits, and investigating anomalies is essential to achieve and maintain compliance. Compliance programs should include procedures for escalation, correction, and refund when errors are found. AI tools used for utilization review or determining medical necessity must be subject to similar scrutiny. Additionally, organizations must foster a culture where staff feel empowered to report discrepancies without fear of reprisal, and where corrective action plans include AI system revalidation. Recommendations for All Healthcare Professionals to consider is to:

  • Conduct regular audits comparing AI outputs with manual reviews, the monitor periodically to ensure compliance standards continue to be met;
  • Participate in cross-functional teams to review AI-driven financial processes; and
  • Engage in training on financial accountability, focusing on identifying AI-related discrepancies.

Conclusion

As AI continues to evolve, so must our compliance infrastructure to ensure that AI innovations align with ethical standards and legal obligations. With thoughtful integration, AI can support high-quality care, enhance administrative efficiency, and reduce costs. However, these benefits cannot come at the expense of accountability, transparency, or patient trust.

Organizations that invest in cross-disciplinary governance, risk management, and regulatory alignment will be best positioned to harness the promise of AI while safeguarding their mission and integrity. Compliance professionals must remain vigilant, agile, and collaborative to meet the demands of this fast-evolving frontier.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. U.S. Food and Drug Administration (FDA). (2021). Artificial Intelligence and Machine Learning (AI/ML)-Based Software as a Medical Device (SaMD) Action Plan. https://www.fda.gov/media/145022/download
  2. Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. https://www.healthit.gov/curesrule/
  3. U.S. Department of Health and Human Services, Office of Inspector General (OIG). (2021). Compliance Program Guidance. https://oig.hhs.gov/compliance/compliance-guidance/index.asp
  4. Office for Civil Rights (OCR), HHS. (2022). HIPAA and Health IT. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/index.html
  5. U.S. Department of Justice. (2023). False Claims Act Overview. https://www.justice.gov/civil/false-claims-act
  6. Centers for Medicare & Medicaid Services (CMS). (2023). Program Integrity Manual – Chapter 3: Verifying Potential Errors and Taking Corrective Actions. https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/pim83c03.pdf

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More