Your 90-Day AR Analysis is complimentary - See your true collection gap.
RAC, OIG, and Payer Audit Defense, Compliance, and Billing Risk Management

Healthcare Billing Compliance and Risk Management Services

A billing audit does not begin when an auditor contacts your practice. It begins months earlier, when a pattern in your claims data triggers a prepayment review, an OIG work plan flags your specialty, or a payer's data mining algorithm identifies statistical outliers in your coding. Healthcare billing compliance services address the risk before the letter arrives.

Healthcare Billing Compliance: The Risk Landscape
OIG Recoveries From Healthcare Fraud and Abuse$3B+ annually
RAC Audit Recovery Rate (Medicare)>70%
Most Common Audit TriggerE/M Upcoding
Avg. Cost of a Single False Claims Act Case$2M+
MBC Pre-Bill Audit Catch Rate99.1%
Years Managing Compliance Billing25+

Audit and enforcement data sourced from OIG Annual Reports, CMS RAC program data, and MBC managed-practice compliance records

Compliance Risk Alert

Most Billing Audits Find Problems That Were Present for Years Before the Audit Began

RAC, OIG, ZPIC, and payer audits do not create billing problems. They expose billing problems that have been accumulating in the claims data for years. The financial exposure in a billing audit is proportional to how long the compliance gap existed before it was identified, because auditors look back across multiple years of claims when calculating overpayment demands.

3 Yrs
Standard Medicare look-back period for RAC audits. Six years applies in cases involving potential fraud, extending the financial exposure window significantly
3x
Treble damages applied under the False Claims Act when billing errors are determined to constitute knowing misrepresentation, not simple mistakes
Pre-Pay
Prepayment review suspends reimbursement on all new claims from a flagged provider until each claim passes individual documentation review, devastating cash flow
Proactive
The only effective compliance strategy. Identifying and correcting billing patterns before they appear in audit data costs a fraction of what post-audit remediation requires

Healthcare Billing Compliance: Who Audits Your Claims

The Federal, State, and Commercial Bodies Reviewing Your Billing Right Now

Federal Audit Programs
RAC, OIG, ZPIC, and MAC: Federal Bodies With Authority to Recover Medicare and Medicaid Overpayments

Recovery Audit Contractors identify and recover improper Medicare payments on a contingency fee basis. OIG investigations target fraud and abuse patterns flagged in its annual Work Plan. Zone Program Integrity Contractors conduct prepayment reviews and post-payment audits on providers with statistical billing outliers. Medicare Administrative Contractors review claims for coverage and coding compliance before payment.

State Medicaid Audits
MFCU and State Medicaid Integrity Contractors: State-Level Audit Authority Over Medicaid Billing

Medicaid Fraud Control Units investigate provider fraud and patient abuse within each state's Medicaid program. State Medicaid Integrity Contractors conduct independent audits of Medicaid billing to identify overpayments. State-specific Medicaid billing rules vary significantly, and a billing practice compliant under Medicare may trigger a Medicaid audit in specific states.

Commercial Payer Audits
Commercial Payer Special Investigations Units: Contractual Audit Rights That Most Practices Underestimate

Every commercial payer contract includes audit rights that allow the payer to review claims and request medical records for any claim submitted within the contract's look-back period. Commercial payer Special Investigations Units use predictive analytics to identify outlier billing patterns, often flagging the same E/M upcoding, unbundling, and modifier misuse patterns that federal auditors target.

Where Healthcare Billing Compliance Risk Accumulates

The Six Billing Patterns Most Likely to Trigger an Audit or Generate an Overpayment Demand

These are not theoretical risks. Each one appears consistently in OIG work plans, RAC audit findings, and commercial payer SIU investigations across healthcare specialties.

E/M Level Distribution That Skews High Relative to Specialty Peer Benchmarks

CMS and commercial payers compare each provider's E/M level distribution against specialty peers. A provider billing level 4 and 5 E/M codes at a significantly higher rate than specialty peers triggers statistical outlier flags. The pattern does not have to involve fraud to generate an audit. It only has to look statistically unusual relative to the provider's specialty.

Modifier Misuse: Using Modifier 25 and Modifier 59 to Bypass Bundling Edits Without Documentation Support

Modifiers 25 and 59 are the two most frequently audited modifiers in Medicare and commercial payer billing. Modifier 25 requires a separately identifiable E/M service with its own documentation. Modifier 59 requires a distinct procedural service with clinical documentation establishing why two codes were not bundled. Applying either modifier routinely without encounter-specific documentation support is a primary audit trigger.

Medical Necessity Documentation That Does Not Support the Code Billed

A claim can be coded and submitted correctly in every technical respect and still generate an overpayment demand if the medical record does not contain the clinical documentation required to establish medical necessity for the service billed. Auditors do not evaluate whether the service was appropriate clinically. They evaluate whether the documentation in the record meets the payer's coverage criteria for the code billed.

Unbundling Separately Billable Services That Payer Edits Require to Be Billed Together

Unbundling occurs when a provider bills multiple codes for services that a payer's bundling edits require to be reported as a single code. NCCI edits define which code combinations are bundled under Medicare. Commercial payers maintain their own bundling rules that may differ from NCCI. Systematic unbundling generates both overpayment demands and potential fraud exposure under the False Claims Act.

Incident-To Billing Without Supervising Physician Presence Meeting CMS Requirements

Billing services as incident-to a physician's service allows practices to bill at the physician's rate for services provided by non-physician practitioners. CMS requires the supervising physician to be physically present in the office suite, not merely available by telephone, at the time the service is rendered. Incident-to claims submitted when this supervision requirement is not met constitute an overpayment under Medicare rules.

HIPAA Compliance Gaps in Billing Workflows That Create Regulatory Exposure Separate From Claim Accuracy

HIPAA Privacy and Security Rules impose specific requirements on how patient data is handled within the billing process, including transmission of PHI to clearinghouses, storage of claim data, and access controls on billing software. A billing workflow that handles claims accurately but transmits or stores PHI in violation of HIPAA creates regulatory exposure that is separate from and in addition to any overpayment risk.

MBC Healthcare Billing Compliance Services

How MBC Builds and Maintains Audit-Ready Billing Compliance

Each service addresses a distinct compliance risk dimension. Full detail on MBC's revenue cycle management services is available on the services page.

Prospective Billing Audit: Pre-Submission Claim Review Against Payer Coverage Criteria

MBC's CPC and CCS-certified coders review claims before submission, validating that each code is supported by the documentation in the medical record and meets the payer's coverage criteria. Claims that do not meet the standard are returned to the practice for documentation correction before submission, not after a denial or audit request.

E/M Distribution Monitoring Against Specialty Peer Benchmarks

MBC monitors each provider's E/M level distribution monthly and compares it against CMS and MGMA specialty benchmarks. When a provider's distribution begins drifting above peer norms, MBC generates a provider-level coding report before the pattern reaches the statistical threshold that triggers a payer outlier flag or audit selection.

Modifier Compliance Review: Documentation Validation for Modifier 25, 59, and High-Risk Modifiers

MBC validates modifier 25 and modifier 59 usage at the claim level, confirming that encounter documentation supports the modifier before submission. High-risk modifier combinations are flagged for human review rather than passing through automated scrubbing, which applies rules but cannot evaluate documentation sufficiency.

RAC and OIG Audit Response: Documentation Assembly and Overpayment Appeal Management

When a practice receives a RAC additional documentation request or OIG audit notice, MBC assembles the clinical record documentation required to support each audited claim and prepares the appeal arguments matched to the specific denial rationale. Appeals are filed with the clinical evidence and coding rationale the administrative law process requires, not generic form responses.

HIPAA Billing Compliance: PHI Handling, Transmission Security, and Access Control Review

MBC's billing workflows are built on HIPAA-compliant infrastructure with encrypted claim transmission, role-based access controls on patient data, and business associate agreements in place with every clearinghouse and billing platform used in the revenue cycle. PHI handling within the billing process is auditable and documented.

Ongoing Compliance Monitoring: OIG Work Plan Tracking and Payer Policy Update Integration

MBC monitors the OIG Annual Work Plan and tracks payer local coverage determination updates to identify when a billing practice that was compliant last year has become a compliance risk this year. Policy changes are integrated into billing workflows before they affect submitted claims, not after a denial pattern reveals the gap.

Healthcare Billing Compliance: Audit Program Reference

Federal and State Audit Programs That Review Healthcare Billing Claims

Each audit program operates under distinct statutory authority, uses different selection criteria, and carries different financial and regulatory consequences.

Audit Body Program Type Selection Trigger Financial Consequence
RAC Medicare Post-Payment Statistical outlier in claim volume, E/M distribution, or procedure frequency relative to specialty peers Overpayment demand with 3-year look-back. Appeals through multiple ALJ levels. Interest accrues on disputed amounts.
OIG Federal Investigation Annual Work Plan priorities, whistleblower complaints, referrals from MAC or RAC findings Civil Monetary Penalties, False Claims Act exposure with treble damages, exclusion from Medicare and Medicaid programs
ZPIC / UPICs Prepayment and Post-Payment Data analysis identifying potential fraud indicators, including billing patterns inconsistent with beneficiary diagnoses Prepayment review suspending all Medicare payments until each claim passes documentation review individually
MAC Claim Processing Review Local Coverage Determination compliance, medical necessity documentation, and modifier usage on submitted claims Claim denial, demand for refund of previously paid claims, referral to ZPIC or OIG if patterns suggest systemic issues
MFCU State Medicaid Investigation State Medicaid data analysis, beneficiary complaints, referrals from state Medicaid agencies State-level False Claims Act exposure, exclusion from state Medicaid program, referral to federal authorities
Commercial SIU Payer Contract Audit Predictive analytics identifying outlier billing patterns within the payer's provider network data Contractual recoupment, suspension of provider contract, referral to federal authorities in fraud cases

Why Provider Groups Choose MBC for Billing Compliance

What MBC's Compliance Approach Delivers That Reactive Billing Cannot

Compliance Built Into Every Claim Before Submission, Not Applied After an Audit Request

MBC's compliance review is embedded in the pre-submission billing workflow. Every claim passes through documentation validation, modifier review, and coverage criteria check before reaching the clearinghouse. The cost of this review is a fraction of what a single RAC audit demand costs to defend.

Statistical Outlier Monitoring That Flags Risk Before Auditors See the Data

MBC monitors E/M distribution, modifier usage rates, and procedure frequency per provider against specialty benchmarks on a monthly basis. When a pattern begins moving toward statistical outlier territory, MBC corrects the coding workflow before the claim data reaches the payer's analytics engine.

Audit Response Capability: Documentation Assembly and ALJ-Level Appeal Preparation

When an audit notice arrives despite compliant billing, MBC has the documentation records and coding rationale to respond at every appeal level, from redetermination through Administrative Law Judge review. Practices with MBC managing their billing have the documentation infrastructure that reactive billing companies cannot reconstruct after the fact.

Nationwide Coverage

Healthcare Billing Compliance Services in Your State

MBC delivers compliance billing with state-specific Medicaid audit program knowledge and commercial payer SIU intelligence built into every engagement.

Provider Group Outcomes

Provider Groups That Avoided Audit Exposure Through MBC's Compliance Billing

What practice leaders found when proactive compliance replaced reactive billing.

MBC identified that our modifier 25 usage rate was running at nearly three times the specialty benchmark. We had no idea. They restructured our documentation workflow before we ever received an audit notice. Eighteen months later, the pattern is gone from our data.
Compliance OfficerDermatology Group Practice, California
We received a RAC additional documentation request covering 140 claims across two years. MBC assembled the complete documentation package and prepared the appeal arguments. We overturned 118 of the 140 claims. Without their documentation infrastructure, we would have had no basis for appeal.
CFOOrthopedic Physician Group, Texas
Our previous billing company had been applying incident-to billing rules incorrectly for two years. MBC caught it in the first compliance review. Correcting before any audit saved us from what would have been a significant overpayment demand across that entire period.
Practice AdministratorFamily Medicine Group, Ohio

Frequently Asked Questions

Frequently Asked Questions About Healthcare Billing Compliance Services

RAC contractors select claims using automated review of billing patterns, targeting providers whose E/M level distribution, procedure frequency, or modifier usage differs statistically from specialty peers. Proactive compliance monitoring identifies when your practice's claim data is moving toward those statistical thresholds and corrects the underlying billing or documentation workflow before the pattern reaches the selection criteria RAC contractors use.
A billing error is an incorrect claim submitted without knowledge of its inaccuracy. The False Claims Act applies when a provider knowingly submits, or causes to be submitted, a false or fraudulent claim for payment. The legal standard for "knowing" includes cases where a provider acts with deliberate ignorance or reckless disregard of the claim's accuracy. A sustained pattern of the same billing error, particularly after internal coding reviews, can be characterised as reckless rather than inadvertent, shifting the legal exposure from simple overpayment to False Claims Act liability.
MBC assembles the clinical documentation supporting each audited claim, prepares the coding rationale matching each code to the documentation in the medical record, and submits a structured appeal response to the appropriate audit level. For RAC audits, MBC manages the process through redetermination, reconsideration, and Administrative Law Judge appeal stages. The documentation infrastructure maintained throughout the billing engagement provides the foundation for an effective response.
Yes. MBC's billing infrastructure is built on HIPAA-compliant systems with encrypted PHI transmission, role-based access controls, and business associate agreements in place with every platform in the billing workflow. PHI handling within the revenue cycle is auditable and documented, providing the practice with evidence of HIPAA compliance that extends to the third-party billing function.
The standard look-back period for RAC audits is three years from the date of service. In cases where OIG investigators determine that fraud occurred, the look-back period under the False Claims Act extends to six years, and in cases of fraudulent concealment, up to ten years. State Medicaid look-back periods vary by state. This extended look-back window means that compliance patterns corrected today still carry historical exposure for claims already submitted within those windows.

Healthcare Billing Compliance and Risk Management

Find Out Whether Your Current Billing Creates Audit Exposure Before an Auditor Does

MBC's free compliance review examines your E/M distribution, modifier usage, documentation sufficiency, and HIPAA billing workflow against current audit benchmarks and OIG work plan priorities.