E/M Coding Audit Failures 2026: Prevention Strategies
Most E/M coding audit failures do not happen because a coder faced a genuinely difficult judgment call and chose wrong. They happen because a small, predictable set of documentation gaps made an otherwise defensible claim impossible to support on review. That distinction matters enormously for revenue cycle strategy. If audit risk were mainly a function of coding complexity, the only answer would be better-trained coders. But if most failures trace back to fixable workflow and documentation habits, the financial exposure is largely preventable, and targeted intervention beats broad "document better" training every time.
This post walks through the failure patterns auditors find most often, the documentation gaps behind them, and the concrete prevention strategies that actually reduce risk before a payer comes looking.
The E/M Audit Risk Environment in 2026
Audit scrutiny on evaluation and management services has not eased. CMS contractors, including Medicare Administrative Contractors and Recovery Audit Contractors, continue to prioritize E/M upcoding, telehealth visit level selection, and prolonged service billing in their review programs. The Office of Inspector General has included E/M-related billing patterns in its work plan priorities across multiple years, and that focus has not shifted. Medicare Advantage plans conduct their own encounter data audits, and commercial payers increasingly run algorithmic prepayment edits that flag statistical outliers in billing distributions.
None of this means that every high-level E/M claim is wrong. It means that claims without documentation to defend them are exposed, and that exposure is concentrated in a predictable set of billing patterns.
The Most Common E/M Audit Failure Patterns
Time-Based Billing Without Documented Total Time
Since the 2021 E/M guidelines took effect, time became a standalone basis for selecting office visit levels. But billing based on time requires that the medical record actually state the total time spent on the date of service. Vague language such as "visit lasted approximately 45 minutes" is far weaker than a specific documented total. Claims billed at higher time thresholds without a clear, specific time statement in the note are among the most common targets in post-payment review. Missing start and stop times are not always required under current guidelines, but the total time must be unambiguous.
Prolonged Services Billed Without a Supporting Time Threshold
Add-on codes like 99417 for prolonged office services require that the base visit code's time threshold has been fully met and documented before any additional time is counted. Auditors routinely find claims where the prolonged service code was appended but the base note's documented time does not clearly reach the minimum for the base code itself, let alone exceed it. This is a mechanical documentation failure, not a nuanced coding question.
Telehealth Visit Levels That Don't Match Documented MDM
Telehealth encounters present a specific risk because the physical examination component is limited by design, which puts the entire coding weight on medical decision-making. When a telehealth note describes a high-complexity MDM level but the documentation does not actually support the data reviewed, the risk addressed, or the complexity of problems managed, the level cannot be defended. Developing consistent telemedicine documentation standards that explicitly show how MDM complexity was established despite exam limitations is one of the most effective risk-reduction steps a practice can take.
Modifier 25 Overuse on Preventive Visit Days
Modifier 25 allows a separate problem-oriented E/M to be billed on the same day as a preventive visit when a distinct, separately identifiable service was provided. Auditors look closely at whether the separately billed E/M note actually describes a problem that required distinct evaluation and management, or whether it restates elements of the preventive visit. Documentation that does not clearly separate the two services, or that addresses only a minor issue that would normally be part of routine preventive care, does not support the modifier. Periodic internal audits of modifier 25 usage are essential for practices with high preventive visit volume.
The Five Documentation Gaps Behind Most Failures
Missing MDM Elements
Medical decision-making under the 2021 guidelines has three components: the number and complexity of problems addressed, the amount and complexity of data reviewed and analyzed, and the risk of complications or morbidity. Notes that reference these elements only vaguely, for example stating "reviewed records" without identifying what records, or "complex medical history" without specifying which conditions were addressed and how, do not support higher MDM levels. Specificity is what makes an MDM argument auditable.
Vague Time Statements
Documenting that a visit was "lengthy" or "complex" does not establish the time basis for a billing level. The note must state the total time, and if counseling and care coordination time is being counted, that should be clearly reflected as well.
Copy-Forward Documentation
Carrying forward prior notes without updating them to reflect what actually happened at the current encounter is one of the most persistent and damaging documentation habits in electronic records. On telehealth visits in particular, copy-forwarded physical exam findings that could not have been performed remotely signal to auditors that the note was not generated from the actual encounter. This can turn an audit of a single claim into a broader review of documentation integrity.
Late or Unsigned Notes
A note that exists in the system but was not completed or authenticated until days after the date of service raises credibility questions in an audit. Payers and auditors can identify completion timestamps, and late signatures are frequently cited in audit findings even when the underlying clinical content would otherwise support the billed level.
Chronic Conditions Listed Without Evidence of Current Encounter Management
Listing chronic conditions in the assessment does not, by itself, demonstrate that those conditions were evaluated or managed during the specific encounter. For MDM purposes, the documentation needs to show that the condition was actually addressed: an assessment of its current status, a change in management, monitoring, or a clinical decision was made. A problem list pulled forward automatically does not accomplish this.
How HCC and Risk-Adjustment Coding Intersects With E/M Audits
For practices treating Medicare Advantage patients, E/M audits and risk-adjustment audits are increasingly intertwined. Auditors reviewing encounter data look for diagnosis codes that appear repeatedly across visits without documentation showing the condition was actually evaluated or treated on each date. What begins as a review of E/M level selection can quickly become a risk adjustment coding documentation issue, because diagnosis codes submitted with encounter data contribute to HCC capture. If the supporting documentation does not show the condition was addressed at that encounter, the diagnosis may be invalid for risk adjustment purposes regardless of whether the E/M level itself was correct. This overlap makes thorough, encounter-specific documentation a compliance requirement on two fronts simultaneously.
Four Concrete Prevention Strategies
Build Time Capture Into EHR Templates
Create a structured field in the encounter template that requires providers to enter a specific total time before the note can be closed. This does not require tracking every minute of every visit, but it removes the step of remembering to add time documentation at the end. Structured fields are more auditable and less likely to contain the vague language that creates risk.
Run Monthly Internal MDM Audits on High-Level Claims
Sampling a set of 99214 and 99215 claims each month and reviewing whether the MDM documentation actually supports the level billed catches drift before a payer does. Internal coding quality audit programs that operate on a regular cadence identify individual provider patterns early, when a conversation and a targeted adjustment can correct the issue without a formal audit finding behind it.
Develop Telehealth-Specific Documentation Standards
A one-page reference document that shows providers exactly what MDM documentation looks like for each complexity level, in the context of a telehealth encounter where the physical exam is limited, is more useful than a general training session. It should include examples of adequate data documentation, risk language, and problem complexity description specific to common telehealth visit types in your practice.
Periodically Audit Modifier 25 Claims
Pull a sample of dates where modifier 25 was billed alongside a preventive service and review whether the separately billed E/M note describes a problem that is genuinely distinct from the preventive encounter. Note any patterns by provider or by diagnosis. Modifier 25 claims are flagged routinely in post-payment review, and internal auditing identifies the patterns before they accumulate into a significant overpayment exposure.
How to Respond in the First 48 Hours After an Audit Notice
Read the full request before doing anything else. Identify the lookback period, the sample size, and exactly which claim types are being reviewed. Assign a single internal coordinator to manage the response so that document collection is organized and nothing is submitted twice or omitted. Have a certified coder pre-review each requested chart before submission to identify obvious documentation gaps, not to alter records, but to prepare accurate and complete responses and to understand where the exposure may be concentrated. Submit everything requested on time. Incomplete or late submissions frequently result in automatic denial of the claims under review, regardless of whether the underlying billing was correct.
Understanding Extrapolation Risk
When an auditor reviews a statistical sample and finds a high error rate, many audit programs allow that error rate to be applied mathematically across a much larger universe of similar claims that were never individually reviewed. This is extrapolation, and it is one of the primary reasons why maintaining low error rates through ongoing internal audits matters even for claims that a payer never specifically examines. The goal of internal auditing is not just to fix the claims that are currently under review. It is to keep the baseline error rate low enough that any sample drawn from your billing population does not trigger a projected overpayment that covers years of claims.
Building a Sustainable Ongoing E/M Compliance Program
Quarterly audits per provider, using a statistically meaningful sample size, give you a defensible baseline and a track record of self-monitoring. Feedback should be delivered one-on-one, using specific chart examples from that provider's actual cases. Public scorecards or group report cards create defensiveness and rarely change documentation behavior. Short, task-specific job aids at the point of care work better than long training decks that providers read once and set aside. Keep compliance metrics separate from RVU and productivity reporting so that providers understand that better documentation protects their revenue rather than threatening it. When documentation is seen as a compliance burden layered on top of productivity pressure, it does not improve. When it is positioned as the mechanism that makes high-level billing defensible, provider engagement changes.
Frequently Asked Questions
What E/M claims are most likely to be selected for audit, and by whom?
Claims that fall at the high end of the billing distribution for a given specialty or provider type attract attention from MAC statistical comparisons, RAC prepayment and post-payment reviews, and commercial payer algorithms. Telehealth claims billed at high levels, prolonged service codes, and modifier 25 combinations are also common selection triggers. Both government contractors and commercial payers use claim history and billing pattern data to identify outliers.
Can you bill based on both time and MDM on the same visit?
No. For any given encounter, you choose one basis for the level selection, either total time or medical decision-making. You cannot combine elements of both to reach a higher level than either alone would support. Whichever basis you use should be clearly reflected in the documentation.
What should you do if you discover a coding error internally?
Internal discovery of billing errors should trigger a structured response under your compliance program. Depending on the nature and scope of the error, the appropriate steps may include voluntary refund or credit to the payer, a look-back review to determine whether the error is isolated or systemic, documentation of the corrective action taken, and review by a compliance officer or legal counsel if the error may implicate fraud and abuse statutes. Proactive self-disclosure and repayment, when appropriate, is treated differently than errors discovered and recovered by an auditor.
What is the difference between a MAC audit and a RAC audit?
Medicare Administrative Contractors process Medicare claims and conduct both prepayment and post-payment review as part of their routine claims administration function. Recovery Audit Contractors are separate entities specifically authorized to identify and recover improper Medicare payments, and they work on a contingency fee basis, meaning they are paid a percentage of what they recover. RAC audits are generally more aggressive and are specifically focused on identifying overpayments. MAC reviews tend to be broader and may include education components alongside any repayment demands.
The Bottom Line on E/M Audit Prevention
Most E/M coding audit failures are not the result of impossible documentation challenges. They are the result of fixable habits that accumulate over time and become visible only when a payer examines a sample. The failure patterns are predictable. The documentation gaps behind them are specific. That means the prevention strategies can be specific too, and specific interventions produce measurable risk reduction in a way that general training rarely does.
To learn how MedCodex Health's ongoing audit and compliance programs help practices identify and close E/M documentation gaps before they become audit findings, visit our coding quality audit services page.