Home | Resource Center | Articles
Key Takeaways

Commercial payor audits are becoming more aggressive as insurers use analytics, automated reviews and vendor-driven processes to identify billing patterns they consider outside expected norms. Providers can reduce risk by understanding contract requirements, strengthening documentation workflows and responding strategically when audit letters arrive.

 

Commercial payor audits are becoming a growing concern for health care providers of all sizes. For years, many practices focused heavily on Medicare and Medicaid compliance, where fraud and abuse rules, federal oversight and False Claims Act exposure have long shaped billing behavior. Commercial payor audits were often viewed as less aggressive or less likely to result in major repayment demands. That is changing.

Commercial payors are now using advanced analytics, automated claim reviews and vendor-driven audits to identify billing patterns they believe fall outside expected norms. As a result, a provider may receive a demand letter seeking repayment of hundreds of thousands of dollars, often based on a small sample of claims that have been extrapolated across a larger group. For practices that depend on commercial insurance contracts, these audits can create serious financial, operational and legal risk.

 

Why Commercial Payor Audits Are Increasing

One of the biggest drivers behind the increase is data. Payors are continuously mining structured claims data to identify outliers. They may compare a provider’s evaluation and management code distribution against specialty peers, review modifier usage, track units per patient or flag sudden changes in reimbursement patterns. A practice does not have to be accused of intentional wrongdoing to be selected. Its data may simply look different from what the payor expected.

This can be especially risky when a practice changes billing vendors, adds a new service line or adjusts coding processes without validating the impact. A sharp increase in collections may look positive internally, but it can also trigger payor scrutiny. In other words, the same revenue trend that appears to signal improved performance may also raise a red flag.

 

How Audit Reviews Typically Work

Many commercial payor audits begin with a checklist-style review. The reviewer may not be evaluating the record the way a clinician would. Instead, the payor or its audit vendor often converts written policy requirements into a grid and scores the record based on whether each required element is present or absent. If a key field is blank, the claim may fail even if the underlying clinical care was appropriate and even if the relevant information appears elsewhere in the chart.

This distinction matters because documentation is now being judged on both substance and structure. A chart can contain the right clinical information but still fail an audit if the information is not located where the payor’s checklist expects to find it. In some cases, a human narrative review may not occur unless the provider appeals and forces a second-level review.

 

Common Findings That Lead to Denials

Several findings appear repeatedly in commercial payor audits. Incident-to billing errors are a common example. If the supervision arrangement or signature process does not meet payor requirements, every claim submitted under that workflow may be vulnerable. Missing orders, missing operative elements and unsupported time-based services also create risk. When a code requires documented time, the minutes should appear in the record itself, not only in a schedule or separate system.

Evaluation and management levels are another frequent target, especially when records appear cloned or overly templated. If notes look nearly identical from visit to visit or across patient populations, reviewers may question whether the documentation supports the level billed. Modifier use, particularly modifiers 25 and 59, is also closely reviewed. The documentation must clearly establish that the services were separate, distinct and supported by the clinical record.

Medical necessity findings can be more complex because the payor’s definition may differ from how a clinician understands the term. A service may be clinically reasonable, but the payor may apply a narrower policy. Discrete field denials are also increasingly common. These occur when information exists in the chart narrative but is absent from a specific structured field, leading the payor to score the element as missing.

 

How Providers Can Prepare Before an Audit

The best defense is a proactive compliance process. Providers should start by understanding the contracts and policies that apply to their highest-volume payors and most-used codes. Each payor contract may be different, so practices should not assume that Medicare rules or another payor’s requirements will apply. Revenue cycle leaders, billing managers and compliance teams can help map key payor requirements to the exact location where the required information appears in the electronic health record.

Internal analytics can also help. Practices should review code distribution, modifier use, utilization patterns and provider-level variation. If one provider’s billing profile differs significantly from others in the same practice or from available specialty benchmarks, the practice should understand why and confirm the documentation supports the pattern.

Template design is equally important. The goal is not to blame clinicians for missing a checkbox. Instead, practices should fix workflows and templates so providers can document care accurately, efficiently and in the right place. Regular internal audits, whether quarterly or annually, can identify issues before a payor does. When performed under the direction of legal counsel, certain audit work may also be protected by attorney-client privilege, depending on the facts and jurisdiction.

 

What to Do When an Audit Letter Arrives

When a demand letter arrives, providers should not ignore it or respond casually. Deadlines matter. The first step is to preserve the letter, calendar all response dates and involve experienced counsel. Practices should identify what plans, codes, dates of service and policies are involved before sending records or making statements to the payor.

Providers should also avoid amending old records simply to make them look more complete. Electronic records are time-stamped and traceable. Retroactive changes can make an oversight appear more serious. If information exists elsewhere in the chart, the better approach is often to explain where it appears and correct the process going forward.

 

Challenging the Demand

A commercial payor audit is, at its core, usually a contract dispute. That means the contract, provider manual, appeal rights, look-back limits and recoupment language all matter. Providers may be able to challenge whether the payor used the correct policy, whether the policy was incorporated into the contract, whether extrapolation is permitted and whether the reviewer had appropriate expertise for the specialty involved.

Settlement may also be a practical option. Although it can feel like conceding, settlement can limit financial exposure, structure repayment over time, release certain claims and avoid the cost of arbitration or litigation. The decision should be based on the strength of the documentation, contract terms, cash flow, payor relationship and long-term business strategy.

 

Taking Control Before the Payor Does

Commercial payor audits are unlikely to disappear. As payors continue to use analytics and automated review tools, providers need documentation processes that can stand up to both clinical review and checklist-based scrutiny. By understanding contract requirements, auditing internally, improving templates and responding strategically when letters arrive, practices can move from a reactive posture to a more prepared and defensible position. Windham Brannon and Hill Health Law are here to help providers navigate these challenges with confidence. If you have questions or need support, please reach out to Denise Gaulin, Lori Baker or your Windham Brannon advisor today.

 

Frequently Asked Questions
  • Why are commercial payor audits increasing? Payors are using data analytics and automated claim reviews to identify billing patterns that appear unusual or inconsistent with their policies.
  • What types of issues commonly lead to denials? Common findings include incident-to billing errors, missing documentation, unsupported time-based services, templated notes and unclear modifier use.
  • How can providers prepare before an audit occurs? Practices should review payor contracts, test documentation workflows, monitor billing patterns and perform regular internal audits.
  • What should providers do if they receive an audit letter? Providers should preserve the letter, calendar all deadlines, involve experienced counsel and review the applicable contracts and policies before responding.