Purpose of Compliance Auditing
Compliance auditing is a systematic, ongoing process of evaluating an organization's adherence to laws, regulations, and internal policies. For HIM departments, compliance audits typically focus on coding accuracy, documentation integrity, privacy and security practices, and billing compliance. RHIA candidates must understand audit methodology and how audit findings drive corrective action.
Types of Compliance Audits
- Baseline audits: establish an initial understanding of compliance risk across an organization or department
- Focused audits: target a specific identified risk area, such as a particular coder, procedure, or payer
- Random audits: select records without regard to known risk, providing a broad, unbiased view of compliance
- External audits: conducted by outside entities such as Recovery Audit Contractors or Medicare Administrative Contractors
The Audit Process
A well-designed audit begins with defining scope and objectives, selecting a statistically valid sample, applying consistent review criteria against coding guidelines and documentation standards, and comparing findings against an established benchmark or error threshold. Results should be documented in a formal report that identifies error rates, root causes, and financial impact, followed by a corrective action plan with defined timelines and follow-up review.
Sampling Methodology
Random sampling supports statistically defensible conclusions about an entire population of claims or records, while judgmental or targeted sampling is useful for investigating a known or suspected problem area but cannot be generalized to the broader population. Candidates should understand that regulatory bodies such as the OIG expect statistically valid sampling methods when extrapolating overpayment findings across a larger universe of claims.
Corrective Action and Education
Audit findings that reveal systemic errors should trigger targeted staff education, updated policies and procedures, and, where overpayments are identified, timely repayment to the payer, generally within 60 days of identification under the false claims overpayment rule. Failure to return known overpayments within this window can itself create False Claims Act liability.
Compliance Program Elements
An effective compliance program, consistent with OIG guidance, includes written policies, a designated compliance officer, effective training, open lines of communication, internal monitoring and auditing, well-publicized disciplinary standards, and prompt response to detected offenses.
Exam Tips
Expect questions distinguishing random from targeted sampling and questions on the 60-day overpayment return requirement. Also expect questions referencing the seven elements of an effective compliance program.
Key takeaway: Rigorous compliance auditing, paired with corrective action, is central to organizational risk management and a core Compliance domain exam topic.