Receiving an audit or records request from an insurance company, or a third party working on its behalf, can feel intimidating. But understanding why audits happen and preparing your practice before a request arrives can make the process much more manageable.
For behavioral health practices that work with insurance, audits and record reviews are an important part of the reimbursement landscape. This isn’t limited to providers who participate in a payer’s network. Out-of-network providers who give patients superbills for reimbursement may also have their documentation reviewed or audited by the patient’s health plan.
These reviews can serve different purposes, from verifying claims and supporting documentation to reviewing medical necessity or other administrative requirements. In some cases, health plans hire third-party organizations to conduct these reviews on their behalf. When an out-of-network claim is involved, any repayment or recoupment resulting from the review may be handled differently because the insurer may have reimbursed the patient rather than paying the provider directly.
Rather than waiting until a request arrives, practices can benefit from building strong documentation, billing, and compliance habits into their everyday workflows.
The word audit can cover several different types of reviews, and understanding what you're being asked for is an important first step. Depending on the circumstances, a health plan or third-party organization may conduct a review related to claims, treatment, or administrative requirements. Some audits take place before payment, while others review claims that have already been paid. Risk-adjustment audits are another type of review and serve a different purpose from reviews focused on treatment or reimbursement.
When your practice receives a request, carefully review who sent it, why the information is being requested, which patient and dates of service are involved, what records are requested, and when a response is due. Understanding the type and scope of the request can help your practice determine the appropriate next steps.
While terminology can vary by payer, some common types of reviews include:
Pre-payment reviews: Conducted before a claim is paid to determine whether the claim and supporting documentation meet the payer’s requirements.
Post-payment reviews: Conducted after payment to verify that billed services were supported by the documentation. Depending on the findings, the payer may seek repayment.
Medical necessity or treatment reviews: Evaluate whether services meet the payer’s criteria for coverage, including factors such as the type, frequency, or duration of treatment.
Risk adjustment reviews: Verify diagnosis and other clinical information used by certain health plans for risk-adjustment purposes. These reviews have a different objective from determining whether an individual service should be reimbursed.
Administrative or documentation reviews: May focus on whether records contain required information or meet other payer, contractual, or administrative requirements.
Because the purpose, documentation requested, and potential outcomes can differ, review the request carefully before responding. Look for information identifying the type of review, the patient and dates of service involved, the records requested, the response deadline, and any instructions provided by the payer or reviewing organization.
If the purpose of the request is unclear, consider contacting the payer or reviewing organization for clarification before submitting records.
Audit readiness starts long before an auditor contacts your practice. Clinical documentation provides a record of the services delivered, treatment planning, and the patient's progress. Most licensing boards and professional organizations emphasize the importance of maintaining accurate, current, and relevant records and notes that adequate records are generally necessary for third-party reimbursement.
Documentation can also help a provider explain the services and billing if questions arise later. For practices, that makes consistent documentation more than an administrative task. It's an important part of supporting continuity of care, accurate billing, and preparedness for outside review.
Timely documentation is another important part of audit readiness. Keeping documentation and billing closely connected helps ensure that the clinical record accurately supports the services being billed. This becomes particularly important during a payer review. A health plan may compare claims with the supporting clinical documentation, and discrepancies or incomplete documentation can create reimbursement concerns.
TherapyNotes® helps keep these workflows aligned by requiring the associated note to be completed before a claim can be submitted. This built-in step helps ensure supporting documentation is in place before the claim moves forward.
Practices should still establish clear expectations around when notes should be completed, reviewed, and signed so documentation remains timely, accurate, and consistent across the practice.
Audit preparedness isn't only an individual clinician responsibility; especially in a group practice. Practice leaders can establish consistent expectations for documentation, coding, billing, and record management so clinicians and administrative team members understand their responsibilities. Guidance from professional organizations, including the American Psychological Association (APA), emphasizes appropriate training for staff, supervisees, and billing personnel who handle clinical records and confidential information.
Guidance from professional organizations, including the American Psychological Association (APA), emphasizes appropriate training for staff, supervisees, and billing personnel who handle clinical records and confidential information.
Regular internal reviews can help practices identify gaps before they become larger problems. Consider periodically reviewing whether documentation supports billed services, treatment plans are current, required information is consistently recorded, and practice policies align with payer requirements. The goal isn't to document for an auditor. It's to build reliable workflows that support good clinical and business practices every day.
A records request doesn't necessarily mean you should immediately send an entire patient chart. Start by reviewing the request carefully to understand why the records are being requested, what information is needed, and which dates of service are included. The appropriate response may depend on the type of review, payer requirements, provider contracts, applicable laws, and the specific information requested.
HIPAA's minimum necessary standard generally requires covered entities to take reasonable steps to limit certain uses, disclosures, and requests for protected health information (PHI) to the minimum necessary to accomplish the intended purpose. However, there are exceptions to this standard, and there may be circumstances in which an entire medical record is appropriate.
If the request is for a risk adjustment review, its purpose may differ from an audit focused on payment or medical necessity. Confirm the purpose of the request and the records needed before responding.
Behavioral health practices should also pay particular attention to psychotherapy notes. Under HIPAA, psychotherapy notes that meet the regulatory definition and are maintained separately from the patient's medical record receive additional protections and generally require patient authorization for disclosure, with limited exceptions.
If you're uncertain about how to respond, review your payer agreement and applicable privacy requirements and consider seeking guidance from a qualified compliance or legal professional before releasing records. Your professional liability or malpractice insurance carrier may also offer risk management or consultation services as part of your coverage, so check with your carrier to see what resources are available to you.
Preparing for a third-party audit doesn't need to mean creating an entirely separate process. Instead, focus on everyday habits that strengthen your practice:
Complete documentation accurately and promptly.
Make sure documentation supports the services being billed.
Maintain consistent documentation and billing processes across your team.
Understand the requirements of the insurance plans you work with.
Keep clinical records organized and secure.
Train team members on documentation, billing, privacy, and records-request procedures.
Establish a process for reviewing and responding to payer and third-party requests.
These habits can make responding to an audit less disruptive while also supporting stronger day-to-day practice operations.
Third-party audits and records requests may be an unavoidable part of working with insurance, but they don't have to catch your practice unprepared.
Strong documentation, consistent billing processes, clear internal policies, and an understanding of payer requirements can help your team respond more confidently when a request arrives. More importantly, these practices support accurate records, continuity of care, and a healthier practice overall.
By treating audit readiness as part of your everyday workflow, you can spend less time worrying about what an auditor might find and more time focused on providing quality care.
* The content of this post is intended to serve as general advice and information. It is not to be taken as legal advice and may not account for all rules and regulations in every jurisdiction. For legal advice, please contact an attorney.