Why the Audit Letter Arrived

Something in your billing crossed a threshold months before the letter printed. The same check that finds it also finds what you underbilled.
Updated August 2026

Audits are not random. Something in your billing crossed a threshold, a payer’s analytics flagged it, and a letter printed months later.

Almost every article about payer audits tells you how to respond to the letter. This one is about the thing that caused it, which is still running, and which is producing claims this week.

It is also about the half of the problem nobody writes about. The same analysis that shows where you are coding high shows where you are coding low, and the second number is usually larger.

Why did we get a payer audit?

Because something in your billing pattern sits outside what the payer expects for a practice like yours. Code frequency, modifier usage, units per encounter, or one provider’s distribution differing from the rest of the group. Payers run this analysis continuously, and the letter is the output of something that has been visible to them for months.

What payers are actually looking at

None of this is secret. It is ordinary distribution analysis and you can run the same checks on your own data.

Code frequency against peers. How often each code appears in your mix compared with practices of similar size and specialty. A distribution that skews toward higher-level codes stands out, and so does one that skews low.

Modifier usage. Some modifiers draw attention when they appear more often than a peer group would suggest.

Time-based codes against available hours. Where a code implies a duration, the arithmetic has to work. Total billed time per provider per day against the hours they were actually working is a straightforward check, and it is one of the first things anybody runs.

Units per encounter. How much gets billed per visit, and whether that moved.

Variation inside your own group. One provider whose distribution looks unlike everybody else’s, seeing similar patients, is the pattern most likely to trigger something.

The half nobody talks about

Every article on this subject treats coding risk as one direction. You billed too high, the payer wants money back.

The other direction is money you delivered and never claimed, and over a year it is usually the larger number.

Undercoding is invisible for a simple reason. No payer will ever write to tell you that you billed too little. A denial arrives with a code. An underbilled visit arrives as a normal payment for a lower service, and every report downstream treats it as a success.

So the only way it surfaces is if somebody looks, and the analysis that finds it is the same one a payer runs to find the opposite.

Run your distribution against peers and both directions appear in the same view. The high side is exposure. The low side is revenue.

An outlier is a question, not a verdict

This matters and it is where practices overreact.

Being outside a peer distribution is not evidence of anything. Case mix explains a great deal. A behavioral health practice seeing more complex presentations will legitimately bill differently from the average, and a provider who takes referrals nobody else wants will look like an outlier because they are one.

The point is not to move toward the middle. The point is to know which of your outliers have an explanation and which do not, before somebody else asks.

An outlier with a documented clinical reason is a defensible position. An outlier nobody has examined is a risk, and the difference between them is whether anybody looked.

Where the notes come in

Distribution analysis tells you which charts to look at. It cannot tell you whether the coding was right, because that lives in the documentation.

So the second half of the exercise is reading a sample of notes against what was actually billed, and asking one question of each: does this documentation support this code.

That question has three possible answers and all three are useful.

The note supports the code. Nothing to do, and now you know, which is worth something on its own if the code was an outlier.

The note does not support the code. That is exposure, and it is better found by you than by an auditor. It also tells you whether the problem is the coding or the documenting, which are different fixes involving different people.

The note supports more than was billed. The clinician did the work, wrote it up, and the claim went out at a lower level. That is money you earned and did not ask for, and it is the finding practices least expect.

What to do with what you find

Documentation problems fall into two groups and only one of them is a coding conversation.

Missing elements. A required component simply is not there. Time not recorded where time drives the code. A required element of the assessment absent. These are usually template or workflow problems rather than clinician problems, because the same element goes missing across many notes when a form does not ask for it.

Present but not defensible. The element exists and would not survive scrutiny. Language that is generic across every patient, copied text that no longer matches the encounter, or a conclusion the body of the note does not support.

The first is fixed by changing what the system asks for. The second is fixed by changing what people write, which is slower and needs a clinical lead rather than an administrator.

Both are prospective. Neither involves going back and amending anything, and that distinction matters more than anything else in this article.

If a letter has already arrived

Two things are true at once and practices only act on the first.

There is a response to prepare, with a deadline, and that work belongs with a healthcare attorney if the letter mentions extrapolation, comes from a special investigations unit, or alleges a pattern rather than errors. Nothing in this article is a substitute for that.

And there is a pattern that is still running. The sample covers a period that has closed. The claims going out this week are being produced by the same coding behaviour, the same templates, and the same documentation habits that generated the sample.

Practices that respond well to an audit and change nothing upstream frequently receive a second letter covering the following period. That is not bad luck. It is the same analytics finding the same pattern.

Doing this without a letter

Which is the version worth having.

Run your coding distribution by provider and by code against your peer group. Identify outliers in both directions. Pull a sample of charts from each outlier and read the notes against what was billed. Sort what you find into missing elements and weak language, and fix the templates before the people.

Practices usually find money in that exercise, because undercoding is more common than the other kind and nobody has ever gone looking for it.

What this means for you

An audit letter is a lagging indicator. By the time it prints, the pattern has been visible to the payer for months and invisible to you for longer.

The same analysis that would have shown you what they saw also shows you what you never billed for. One exercise, two findings, and only one of them is a risk.

Grab 30 minutes with us. Prep nothing. You will see where your coding sits against your peers in both directions, and which charts are worth a closer read.

Questions people ask

Why did we get a payer audit?

Because something in your billing pattern sits outside what the payer expects for a practice like yours. Code frequency, modifier usage, units per encounter, or one provider differing from the rest of the group. Payers run this analysis continuously, and the letter is its output.

How do I find out what flagged us?

Run the same analysis on your own data. Sort coding distribution by provider and by code, compare against your peer group, and the outliers appear immediately. You have the same data the payer used.

Does undercoding show up in the same analysis?

Yes, and it is usually the larger number. No payer will ever write to say you billed too little, so an underbilled visit arrives as a normal payment and every report downstream treats it as a success. The only way it surfaces is if somebody looks.

Is being a coding outlier a problem?

Not by itself. Case mix explains a great deal, and a practice seeing more complex presentations will legitimately bill differently from the average. The question is whether each outlier has an explanation, and knowing that before somebody else asks.

What do I do about documentation that does not support the code?

Sort it into missing elements and weak language. Missing elements are usually a template or workflow problem, fixed by changing what the system asks for. Weak language needs a clinical lead. Both fixes are prospective, and neither involves amending anything already written.

Read next