Cardiology Billing Services
Cardiology Billing Services
Cardiology Audit Checklist Complete Billing, Coding and Compliance Guide
August 21, 2026

Cardiology Audit Checklist: Complete Billing, Coding and Compliance Guide

A cardiology claim carries more moving parts than almost any other outpatient specialty. A single stress echocardiogram can involve a professional component, a technical component, a supervising physician, a specific diagnosis to establish coverage and a payer policy that limits how often the study can be repeated. When one of those parts is documented poorly or reported incorrectly, the claim does not usually fail loudly. It fails quietly, weeks later, as a denial or a partial payment that sits in accounts receivable. A cardiology audit checklist is the tool that catches those failures before they reach a payer, or explains them after they do.

This guide walks through what a cardiology audit actually reviews, how billing audits differ from coding audits, what to check for the diagnostic and interventional services that dominate cardiology and how to turn findings into corrective actions that hold. It is written for the people who do this work: coders, billers, compliance staff, practice administrators and the cardiologists whose documentation everything else depends on.

What Is a Cardiology Audit Checklist?

A cardiology audit checklist is a structured list of review points used to verify that cardiovascular services were documented, coded and billed correctly and in line with applicable payer and coding rules. It covers patient and insurance data, provider information, clinical documentation, CPT and ICD-10-CM coding, modifiers, National Correct Coding Initiative (NCCI) edits, medical necessity and claim outcomes.

The checklist is not a single template that fits every situation. Requirements shift depending on the service, the CPT or HCPCS code, the diagnosis, the payer, the coverage policy, the date of service, the place of service and the provider type. A useful checklist accounts for that variation rather than pretending every echocardiogram or every office visit follows one rule.

Why Cardiology Practices Need Billing and Coding Audits

Cardiology combines high service volume, high per-claim value and dense coding rules. Diagnostic testing, interventional procedures, device implants and remote monitoring each carry their own coding logic, global periods and bundling edits. That combination creates more opportunities for error than a lower-complexity specialty faces and each error tends to be worth more.

Regular audits serve several practical purposes. They confirm that documentation supports what was billed, which matters both for reimbursement and for defense if a payer or government contractor reviews records later. They surface recurring patterns, such as a modifier applied incorrectly across dozens of claims, that a single denied claim would never reveal. They quantify where revenue is leaking, whether through downcoding, missed charges, bundling denials, or underpayments against contracted rates. And they give providers specific, documented feedback instead of vague reminders to “document better.”

An audit is also a compliance activity. The Office of Inspector General has long encouraged practices to run internal monitoring as part of a functioning compliance program. Finding and correcting your own errors is materially different from having a payer find them for you.

What Should a Cardiology Audit Checklist Include?

A complete cardiology audit follows the claim from patient registration through final payment. The sections below form the master checklist. Each one can be audited on its own, but the value comes from reviewing them together, because errors in one stage often explain problems in another.

Patient and demographic information

Registration errors are among the most common and most preventable reasons a claim fails. Audit the following against the medical record and the payer’s records:

  • Patient name spelled and formatted as it appears on the insurance card
  • Date of birth
  • Member ID and group number
  • Subscriber information when the patient is not the subscriber
  • Address and contact information
  • Coordination of benefits when more than one plan is active

Inaccurate demographic or insurance data produces front-end rejections that never reach adjudication and it can route a claim to the wrong payer entirely. A transposed member ID or an outdated plan is a small clerical event that turns into a delayed payment and an avoidable rework cycle.

Insurance eligibility and benefits

Confirm that coverage was verified before the service and that the verification matched the date of service. Review active coverage, effective and termination dates, benefit limitations, deductible and coinsurance, copayment, network status and any secondary coverage.

Eligibility verification reduces avoidable denials, but it does not guarantee payment. A patient can have active coverage and still receive a denial for a service the plan does not cover or does not consider medically necessary. Verifying eligibility and confirming coverage for a specific service are two different checks.

Prior authorization and referrals

Cardiology carries a heavy authorization burden, particularly for advanced imaging, nuclear studies and elective procedures. For each service that required authorization, review:

  • Whether authorization was actually required by that payer for that service
  • Whether it was obtained before the service
  • The authorization number
  • The specific service, provider and location authorized
  • The approved date range and number of units
  • Any referral requirement separate from authorization

Authorization and medical necessity are separate concepts. An authorization is a payer’s administrative approval to proceed; it does not by itself establish that the service met the payer’s medical necessity criteria and it does not always guarantee payment. Practices that struggle with authorization-related denials often benefit from a dedicated review of that workflow, a subject covered in more depth in this cardiology prior authorization guide.

Provider enrollment and credentialing

A clinically correct claim still fails if the provider data is wrong. Audit the National Provider Identifier (NPI), tax identification information, taxonomy, enrollment status and payer participation. Confirm that the rendering, billing and (where applicable) supervising provider are reported correctly and that the place of service matches where the service was actually delivered.

Enrollment gaps are a frequent and frustrating cause of denials for new hires and for providers added to a group mid-cycle. A claim submitted before enrollment is effective may be denied even though the service and coding were correct.

Clinical documentation

Documentation is the foundation the rest of the audit rests on. Review whether the record supports the reason for the encounter, relevant history, examination findings, assessment, diagnosis, medical necessity, any diagnostic testing performed, the procedure and its findings and the treatment plan. Confirm physician or qualified healthcare professional (QHP) authentication and signatures where required.

The exact documentation standard depends on the service, the coding rules and the payer. A diagnostic test typically requires an order, a reason for the test and a signed interpretive report. An evaluation and management (E/M) service requires documentation that supports the level of medical decision making or the total time reported. The audit question is always the same in spirit but specific in application: does the record support exactly what was billed?

CPT and HCPCS coding

Verify that each procedure code reflects the service documented, that units and frequency are correct and that component and comprehensive services are reported appropriately. This is expanded in the coding audit section below.

ICD-10-CM diagnosis coding

Confirm that diagnosis codes are supported by the documentation, are coded to the appropriate level of specificity and establish the medical necessity link the payer requires. This is expanded below as well.

E/M coding

Check that the E/M level matches the documented medical decision making or total time and that any E/M reported on the same day as a procedure is genuinely separate and identifiable.

Modifier use

Review every modifier against the circumstances documented in the record. Modifiers change how a claim is interpreted and paid, so an unsupported modifier is both a payment risk and a compliance risk.

NCCI and bundling

Compare code combinations against current NCCI edits. Confirm that a modifier used to report edited codes separately is actually supported by the documentation rather than applied to force payment.

Units and frequency

Confirm the number of units billed matches the service performed and stays within any Medically Unlikely Edit (MUE) or payer frequency limit.

Place of service

Verify that the place of service code reflects where the service occurred. Facility versus non-facility reporting affects payment and, for some services, whether a technical component is billed at all.

Claim submission

Check that claims were submitted within the payer’s timely filing window, cleared front-end edits and were not duplicates of an already-submitted claim.

Denials and rejections

Review the outcome of each claim. A rejection and a denial are different events with different fixes, discussed later in this guide.

Payment posting and reimbursement

Confirm that payments were posted accurately and reconciled against contracted rates, so that underpayments are caught rather than absorbed. Practices that want to strengthen this stage can review how a structured payment posting process flags discrepancies instead of quietly accepting them.

Cardiology Coding Audit Checklist

A coding audit focuses on whether the codes reported accurately represent the documented service and follow current coding guidance. It differs from a billing audit, which looks more broadly at the claim, the payer data, submission and payment. In practice the two overlap, but keeping the distinction in mind helps you scope an audit and assign findings to the right root cause.

CPT coding

For each service, compare the reported CPT code against the documentation. Review:

  • Whether the code selected matches the procedure actually performed and documented
  • Whether the service level and units are supported
  • Whether add-on codes are reported with their required primary codes
  • Whether component services have been separated when they should have been bundled (unbundling) or bundled when they should have been reported separately
  • Whether duplicate reporting has occurred
  • Any payer-specific coding instruction that differs from general guidance

CPT codes are maintained by the American Medical Association and updated annually. Coding from an outdated code set is a recurring audit finding after each January update, particularly for practices that do not refresh their charge master and encounter forms on schedule. Accurate procedure coding is central to what a specialized medical coding service exists to protect.

ICD-10-CM coding

Diagnosis coding drives medical necessity, so it deserves close attention. Audit:

  • Whether the diagnosis is supported by the documentation
  • Whether it is coded to the appropriate specificity rather than an unspecified code when a more specific one is documented
  • Whether the diagnosis supports the service billed
  • Diagnosis sequencing where it affects the claim
  • Chronic condition reporting when those conditions are evaluated or managed during the encounter

ICD-10-CM codes are maintained by the National Center for Health Statistics (part of the CDC) and CMS, with updates effective each October 1. A correct, specific diagnosis code supports the claim, but a diagnosis code by itself never guarantees coverage or payment. Coverage depends on the payer’s policy for that service.

E/M coding

Since 2021, office and outpatient E/M codes (99202 through 99215) are selected based on either the level of medical decision making (MDM) or the total time the physician or QHP spends on the date of the encounter. In 2023, this MDM-or-time framework extended to other E/M categories, including hospital, nursing facility and home visits. Emergency department visits are an exception and are selected on MDM alone.

When auditing E/M coding, review:

  • Whether the correct E/M code family was selected for the setting and patient type
  • Whether the documented MDM supports the level, examining the number and complexity of problems addressed, the amount and complexity of data reviewed and analyzed and the risk of complications
  • Whether time-based coding, if used, is supported by a documented total time on the date of the encounter
  • Whether a medically appropriate history and exam were documented, recognizing that these no longer drive the code level but are still expected as clinically appropriate
  • Whether modifier 25 is supported when a separate E/M is reported alongside a procedure

Applying pre-2021 E/M rules, which required specific history and exam elements to drive the level, is an outdated approach and a common audit error. Current guidance should be used.

Modifier auditing

Modifiers communicate specific circumstances about a service. Each one should be supported by the actual documentation, not added to secure payment. For the modifiers most relevant to cardiology, an auditor should understand what the modifier communicates, what to verify and where misuse tends to occur.

Modifier What it generally communicates What the auditor reviews Common misuse risk
25 A significant, separately identifiable E/M service by the same provider on the same day as a procedure or other service Whether the E/M is genuinely separate from the procedure’s inherent pre- and post-service work Appending 25 to every visit paired with a minor procedure
26 The professional (interpretation) component of a service with both professional and technical components Whether a separate, signed interpretive report supports the professional component Reporting the professional component when the interpretation is not documented
59 A distinct procedural service not normally reported together Whether a separate session, site, or procedure is documented Using 59 to bypass an NCCI edit without supporting documentation
76 A repeat procedure or service by the same physician Whether a genuine repeat, not a duplicate claim, occurred Confusing a repeat service with an accidental duplicate submission
77 A repeat procedure by a different physician Whether a different provider genuinely repeated the service Applying 77 when the same provider repeated the service
91 A repeat clinical diagnostic laboratory test Whether the repeat test was medically necessary, not a re-run for error Using 91 to report a confirmatory re-test of a questionable result

For each modifier, the auditor’s job is the same: confirm that the circumstances in the record match what the modifier claims. CMS provides specific guidance on the proper use of modifier 59 and its more specific alternatives (XE, XP, XS, XU), which distinguish a separate encounter, structure, practitioner, or unusual non-overlapping service. A modifier should never be added simply to obtain payment.

NCCI auditing

NCCI Procedure-to-Procedure (PTP) edits identify code pairs that should not normally be reported together. Each edit has a Column One and a Column Two code. When both codes of an edit pair are reported for the same patient on the same date of service, the Column One code is eligible for payment and the Column Two code is denied, unless a clinically appropriate NCCI PTP-associated modifier is allowed and supported.

Each edit carries a modifier indicator that tells you whether the pair can be separated:

  • 0 – the codes can never be reported together on that date of service and no modifier overrides the edit
  • 1 – the codes may be reported together under specific documented circumstances with an appropriate modifier
  • 9 – no edit applies to the pair

CMS also publishes Medically Unlikely Edits (MUEs), which set the maximum units of service for a code that would be reported on the vast majority of correctly reported claims. A denial based on a PTP edit or an MUE is a coding denial, not a medical necessity denial and under Medicare rules the patient cannot be billed for a service denied on that basis.

Because CMS updates NCCI edits quarterly, effective January 1, April 1, July 1 and October 1, an audit should always reference the edit version in effect for the date of service under review rather than the current version.

Cardiology Documentation Audit Checklist

Documentation supports coding, medical necessity and any future appeal or audit defense, so a documentation review is worth running on its own. For a sample of encounters, confirm the record includes:

  • Patient identification and the correct date of service
  • The reason for the encounter
  • Relevant clinical history and examination findings when performed
  • An assessment and a supported diagnosis
  • Documentation of any procedure performed and its findings
  • Results and, where applicable, a signed interpretation of diagnostic testing
  • Support for medical necessity
  • A treatment plan
  • Physician or QHP authentication and signatures where required
  • Consistency between what the record describes and what the claim reported

Distinguish between two related but separate ideas. The first is documentation that supports the service, meaning the record shows the service was performed and was reasonable. The second is documentation specifically required by a payer or policy, such as a particular measurement, a prior failed therapy, or a signed order retained on file. A record can satisfy the first and still fall short of the second. A thorough audit checks both.

Cardiology Billing Audit Checklist

The billing audit views the claim as a whole and asks where it is most likely to fail. The table below is a working checklist that maps each item to what you review and the risk it carries.

Billing audit item What to review Potential risk
Patient demographics Accuracy and consistency with payer records Claim rejection
Insurance Eligibility and correct payer Wrong payer, denial
Authorization Service, provider, location and date match Authorization denial
Provider NPI, taxonomy, enrollment, participation Claim payment issue
CPT Code matches documentation Coding denial
ICD-10-CM Diagnosis supported and specific Medical necessity denial
Modifiers Circumstances in the record support use Coding denial
Units Correct quantity within MUE limits Overbilling or underbilling
NCCI Current edits reviewed for the date of service Bundling denial
Timely filing Submission within payer deadline Filing denial
Documentation Complete and authenticated Audit exposure
Claim status Rejection, denial, or payment tracked Aging AR

Cardiology-Specific Services to Audit

Cardiology services do not follow one uniform set of rules. Requirements vary by service, code, diagnosis, documentation, payer, coverage policy, date of service, place of service and provider type. The areas below carry recurring audit risk.

Echocardiography

Review whether the correct procedure was reported, whether the study is supported by documentation and medical necessity and whether the interpretive report meets requirements. Echocardiography frequently splits into professional and technical components, so confirm that component reporting, including modifier 26 or TC where applicable, matches where and by whom the service was performed. Payer frequency limits on repeat studies are a common source of denials.

Stress testing

Confirm that the specific service reported matches what was performed, since stress testing spans several code combinations depending on whether the study was exercise or pharmacologic and whether imaging was involved. Review documentation, medical necessity, component reporting and units. Supervision requirements can affect whether the professional component is billable.

ECG/EKG

Verify correct CPT selection and professional versus technical component reporting. An ECG requires a documented interpretation when the interpretation is billed. Watch for duplicate reporting when an ECG is performed as part of another service that already includes it.

Cardiac monitoring

Ambulatory and remote cardiac monitoring codes depend on monitoring duration and the specific service delivered and they are a frequent source of duplicate and frequency errors. Review the monitoring period, the code selected for that period, the documentation of the service and its interpretation and any payer frequency limit.

Cardiac catheterization

Catheterization and interventional coding is among the most complex in cardiology. Review procedure documentation against CPT selection, confirm component reporting and check for bundling under current NCCI edits. Verify modifier use, medical necessity and authorization and confirm device-related documentation where applicable. Practices with significant interventional volume often audit this area separately given its value and complexity; a focused review of interventional cardiology billing rules is worthwhile.

Electrophysiology and device services

Electrophysiology procedures and cardiac device services carry their own coding, global periods and follow-up rules. Review procedure documentation, device information and the coding of interrogation, programming and follow-up services, including frequency limits on remote monitoring. Confirm CPT selection, medical necessity and payer-specific requirements. Because device follow-up and monitoring generate recurring claims, small coding errors here multiply quickly, which is why electrophysiology billing is often a dedicated audit focus.

Common Cardiology Audit Findings

The findings below recur across cardiology audits. The table pairs each with why it matters and what to review.

Audit finding Why it matters Recommended review
Unsupported modifier May misrepresent the circumstances of the service Compare modifier use against the documentation
Incorrect CPT Service may be inaccurately reported Review documentation against coding guidance
Diagnosis mismatch May affect medical necessity Compare diagnosis with the record and payer policy
Missing authorization Can result in nonpayment Verify the payer’s authorization requirement
Incorrect units May cause payment or compliance problems Compare units with the service documented
Duplicate billing May create duplicate claim activity Review the claim history
NCCI conflict Services may be bundled Check current NCCI edits for the date of service
Missing documentation Claim may lack support Review the medical record
Incorrect provider information May affect adjudication Verify enrollment and claim data
Timely filing issue Claim may be denied Review the payer-specific deadline

Overcoding, Undercoding, Upcoding and Downcoding

Coding variances fall into categories that an audit should name precisely, because the label affects both the correction and the compliance interpretation.

  • Overcoding reports a service at a higher level or intensity than the documentation supports.
  • Undercoding reports a service at a lower level than documented, which understates the work performed and leaves revenue uncaptured.
  • Upcoding describes reporting a higher-paying code than the service justifies; when done knowingly, it is a compliance and fraud concern.
  • Downcoding describes reporting a lower-paying code than the documentation supports, sometimes done defensively to avoid scrutiny.
  • Unbundling reports component services separately when a comprehensive code should be used.
  • Unsupported services are billed without documentation to back them.
  • Duplicate reporting bills the same service more than once.
  • Modifier misuse applies a modifier the circumstances do not support.

An audit should identify patterns rather than assume every variance is intentional. A single overcoded claim can result from a coding error, a documentation deficiency, a training gap, a workflow problem, or a system configuration issue long before it suggests misconduct. Distinguishing among those causes is the difference between a corrective action that works and one that blames the wrong thing. An isolated coding discrepancy is not evidence of fraud and an audit should not treat it as such.

Claim Denials as an Audit Finding

Denials are one of the richest audit data sets a practice has, because they reveal where the revenue cycle is actually breaking. Rather than treating each denial as a one-off to be worked and forgotten, analyze denials in aggregate.

For each denied claim, capture the denial reason, payer, CPT and ICD-10-CM codes, provider, location, procedure type, dollar amount, authorization status and appeal outcome. Then look for concentration. Denials clustering around one payer, one provider, one code, or one denial reason point to a systemic problem rather than random error.

Common denial categories in cardiology include medical necessity denials, coding denials, modifier denials, authorization denials, eligibility denials, duplicate claim denials and timely filing denials. Each maps to a different upstream fix. A rise in authorization denials points to the pre-service workflow; a cluster of medical necessity denials points to diagnosis coding or documentation; repeated timely filing denials point to submission timing.

Denial analysis should sit inside a broader revenue-cycle review rather than stand alone. Not every denial reflects a coding error and not every coding error produces a denial. A structured approach to denial management treats the pattern, not just the individual claim and connects denial trends back to the audit findings that explain them.

Rejection vs Denial vs Underpayment

These three outcomes are frequently confused and the fix for each is different.

Claim rejection Claim denial Underpayment
The claim fails an initial processing or validation check The claim is adjudicated but payment is refused or reduced for a stated reason The claim is paid, but at less than the expected or contracted amount
Usually requires correction and resubmission May require correction, reconsideration, or appeal depending on the reason Requires a contract and payment review, then follow-up
Often occurs before full adjudication Usually follows adjudication Occurs after payment has been made

Payer systems use different terminology and status classifications, so the same event may be labeled differently across payers. The practical distinction that matters for an audit is where in the process the claim stopped and what action recovers it.

Prospective vs Retrospective Cardiology Audits

Audits are grouped by when they occur relative to claim submission or payment.

A prospective audit reviews claims, coding, or documentation before submission or payment. Its value is prevention. Uses include pre-bill claim validation, coding review, authorization confirmation and documentation checks that catch errors while they can still be fixed at no cost. Prospective auditing is particularly useful for new providers, new services and high-value procedures.

A retrospective audit reviews claims that have already been submitted or paid. Its value is pattern detection and correction. Uses include measuring coding accuracy, identifying recurring errors, finding overpayments and underpayments, reviewing denial patterns and building corrective action plans. Retrospective audits are where most compliance monitoring happens, because they show what actually went out the door.

Most practices use both. Prospective auditing keeps errors from leaving the building; retrospective auditing tells you which errors keep coming back.

Internal vs External Cardiology Audits

Audits also differ by who performs them and why.

An internal audit is conducted by the practice’s own staff or an internal compliance function. It is flexible, ongoing and oriented toward self-correction. An external audit is conducted by an outside party, which may be an independent coding firm engaged by the practice, or a payer or government contractor reviewing claims. A payer or government audit typically applies defined criteria and stricter evidence requirements and its findings can carry financial recoupment.

The scope and evidence standard differ accordingly. An internal audit can review a small sample to spot-check a workflow. An external payer audit may demand complete records for every claim in a defined population and hold them to that payer’s specific documentation policy. Understanding which kind of audit you are in shapes how you prepare and respond.

How to Perform a Cardiology Billing and Coding Audit

The workflow below is a practical sequence. Not every audit follows every step and the depth of each step depends on the audit’s purpose, but this order keeps a review organized.

  1. Define the audit objective.
  2. Define the audit scope.
  3. Establish the audit period.
  4. Identify the applicable payer and coding rules for that period.
  5. Select the audit sample.
  6. Collect the claims and the corresponding medical records.
  7. Review the documentation.
  8. Review CPT and HCPCS coding.
  9. Review ICD-10-CM coding.
  10. Review modifiers.
  11. Review NCCI edits and bundling for the date of service.
  12. Review medical necessity.
  13. Review authorization and eligibility.
  14. Review provider information.
  15. Compare the claims against the remittance information.
  16. Document the findings.
  17. Classify the errors by type.
  18. Quantify the financial impact where appropriate.
  19. Identify the root causes.
  20. Develop corrective actions.
  21. Educate the relevant staff and providers.
  22. Perform follow-up monitoring and re-audit.

Cardiology Audit Sampling and Methodology

Auditing every claim is rarely practical, so most audits work from a sample. The sampling method should fit the audit’s purpose.

  • Random sampling supports a general accuracy estimate across a population.
  • Targeted sampling focuses on a specific area of concern, such as one code, one provider, or one service line.
  • Risk-based sampling prioritizes claims with higher exposure, including high-dollar claims, high-frequency services, high-denial services, new providers and new codes or services.

Repeated audit findings themselves justify a targeted follow-up sample. There is no universal correct sample size; the appropriate number of claims depends on the audit’s purpose, the population, the level of risk and the organization’s own requirements. State the sampling method in the audit report so the findings can be interpreted correctly and the audit can be repeated consistently.

How to Analyze Cardiology Audit Findings

Once findings are documented, root-cause analysis turns a list of errors into an action plan. The goal is to determine whether a finding is isolated or systemic and what upstream factor produces it.

Analyze findings across several dimensions: the provider, the coder, the billing staff member, the payer, the CPT and ICD-10-CM codes, the modifier, the location, the procedure, the authorization workflow, the documentation workflow, the claim-edit configuration, training and system setup. Then weigh frequency and dollar impact together, since a low-dollar error occurring hundreds of times can matter more than a single large one.

Recurring findings usually point to a process, not a person. A modifier applied incorrectly across many claims more often reflects a template default, an unclear internal instruction, or a charge-capture configuration than an individual’s judgment. Framing findings as process problems, where the evidence supports that, produces corrections that actually hold.

Cardiology Denial Trends as an Audit Tool

Denial trend analysis connects the denial data set to the audit’s root-cause work. Track denials over time and segment them by reason, payer, provider, code and service line. A trend that moves, whether up after a payer policy change or down after a workflow fix, tells you something a single snapshot cannot.

Trends also validate corrective actions. If a corrective action targeting authorization denials is working, the authorization denial rate should fall in the months after it. If it does not, the root cause was probably misidentified. Denial trends and audit findings should be read together, since each explains the other. Reducing the accounts receivable that denials create is a downstream benefit and a structured accounts receivable follow-up process depends on that upstream denial analysis.

Audit Metrics Cardiology Practices Should Track

Metrics make audit results comparable over time. Useful measures include the coding accuracy rate, documentation compliance rate, audit error rate, claim denial rate, denied claim volume and dollar value, overpayment and underpayment findings, appeal overturn rate, corrected claim rate, recurring finding rate and time to corrective action. Provider-specific and payer-specific error trends help direct education where it is needed.

When a metric uses a formula, define the numerator and denominator explicitly. For example:

Audit error rate = (claims or line items with identified errors ÷ claims or line items audited) × 100

Organizations define these metrics differently. Some measure by claim, others by line item; some count only certain error types. Because of that, always state what a metric counts before comparing results across periods or across practices. Avoid treating any single number as an industry benchmark, since published error-rate expectations vary by source and context.

How to Create a Corrective Action Plan

A corrective action plan turns findings into specific, assigned and time-bound steps. Depending on the root cause, appropriate actions include coding education, documentation education, workflow changes, claim-edit configuration updates, authorization and eligibility workflow improvements, provider feedback, billing staff training, policy updates, internal monitoring and targeted re-audits.

Each action should name a responsible party and a follow-up date and the plan should specify how success will be measured, usually through a re-audit of the same area. Corrective action should match the finding. Disciplinary action based on an isolated coding discrepancy is rarely appropriate and often counterproductive; education and process correction resolve most findings.

Medicare Considerations

Medicare rules deserve their own review, because they are specific and because they do not automatically apply to commercial payers. When auditing Medicare claims, account for:

  • Medicare coverage rules for the service
  • Medical necessity as defined by Medicare policy
  • NCCI PTP and MUE edits, which are a Medicare methodology
  • Medicare documentation and modifier requirements
  • Guidance from the practice’s Medicare Administrative Contractor (MAC)
  • Local Coverage Determinations (LCDs), which are set by MACs and can vary by jurisdiction
  • National Coverage Determinations (NCDs), which apply nationally

Coverage policy is where Medicare medical necessity is actually decided for many cardiology services. An LCD may specify which diagnoses support a given diagnostic test in a particular MAC jurisdiction, which means the same service can have different covered indications in different regions. When a requirement varies by MAC or by local coverage policy, an audit should note that explicitly rather than treating one MAC’s rule as universal. CMS maintains coverage determinations in the Medicare Coverage Database and the relevant policy for the date of service should be the reference.

Commercial Payer Considerations

Commercial payer requirements often differ from Medicare and from each other. When auditing commercial claims, expect variation in prior authorization and referral requirements, medical policies, network participation rules, timely filing windows, claim correction and appeal deadlines, documentation expectations, coverage policies and claim-editing logic.

Do not assume a commercial payer follows Medicare’s rules. A commercial plan may use different editing software, a different medical policy for the same service and a different appeal process. Where a commercial policy governs a claim, the audit should reference that payer’s current published policy rather than a Medicare rule. Avoid stating a specific commercial payer’s policy from memory; verify it against the payer’s current documentation.

Medicare vs commercial payer audit comparison

Audit area Medicare Commercial payer
Coverage CMS and applicable Medicare policies Payer-specific benefit and policy
Medical necessity Medicare coverage rules, LCDs and NCDs Payer medical policy
NCCI Medicare NCCI methodology May use different editing policies
Authorization Service-specific Medicare requirements where applicable Often payer-specific and more extensive
Timely filing Medicare-specific deadline Varies by payer and contract
Appeals Medicare-specific, multi-level process Payer-specific process
Documentation CMS and applicable policy requirements Payer-specific requirements

This table is a high-level comparison, not a substitute for the current guidance that governs a specific claim.

Cardiology Audit Prevention Framework

Auditing finds errors; a prevention framework keeps them from occurring. Mapping controls to each stage of the encounter gives the practice a repeatable structure.

Before the visit, verify eligibility and benefits, confirm referral and authorization requirements and check network status and provider participation.

During the encounter, ensure clinical documentation, diagnosis documentation, procedure documentation, medical necessity support and authentication are all in place.

During coding, review CPT, HCPCS and ICD-10-CM selection, E/M level, modifiers, units, NCCI edits, global-period considerations and the match between documentation and code.

Before claim submission, check demographics, payer and provider information, authorization, coding edits, claim validation, duplicate claims and place of service.

After submission, review rejections, denials, underpayments, accounts receivable, appeals, corrected claims, payment posting and recurring findings.

Common cardiology billing and coding audit mistakes

Audit finding Why it can create risk Prevention
Incorrect diagnosis code May not represent the documented condition Review documentation against ICD-10-CM guidance
Unsupported modifier May misrepresent the circumstances of service Validate the modifier against documentation
Incorrect CPT Service may be inaccurately reported Perform a documentation-to-code review
Missing authorization May conflict with payer requirements Verify authorization before the service
Eligibility not verified Claim may go to inactive or incorrect coverage Verify eligibility before the visit
Incorrect payer Claim may be routed incorrectly Confirm payer and coordination of benefits
Duplicate claim May result in duplicate processing Check the claim history
Incorrect units Can cause billing errors Compare units with documentation
Missing documentation Limits support for the billed service Complete a documentation review
NCCI conflict Services may be bundled Review current NCCI edits
Timely filing issue Claim may miss the payer deadline Monitor submission dates
Provider enrollment issue Claim may fail payer requirements Maintain current enrollment records

Hypothetical Cardiology Audit Scenarios

The scenarios below are illustrative and hypothetical. They do not describe real patients or real claims and they exist only to show how a finding is identified and prevented.

Scenario 1: Unsupported modifier 25

A patient is seen for a scheduled echocardiogram and the practice reports an office visit with modifier 25 on the same day. The audit concern is whether a significant, separately identifiable E/M service occurred beyond the work inherent in ordering and reviewing the study. The auditor reviews the documentation for a distinct history, assessment and decision making unrelated to the echocardiogram itself. Prevention comes from reserving modifier 25 for encounters where the record clearly supports a separate E/M, rather than defaulting to it whenever a visit and a procedure share a date.

Scenario 2: Diagnosis does not support diagnostic testing

A nuclear stress test is billed with a diagnosis that the payer’s coverage policy does not list as a supported indication. The audit concern is medical necessity. The auditor compares the documented diagnosis against the record and the applicable LCD or commercial medical policy for that service. Prevention comes from confirming, before the study, that the documented indication meets the coverage policy and from coding the most specific supported diagnosis the record establishes.

Scenario 3: NCCI bundling issue

Two procedures reported on the same date form an NCCI edit pair. The audit concern is whether the Column Two code should have been denied or reported separately. The auditor checks the modifier indicator for that pair in the edit version effective on the date of service. If the indicator is 1 and the documentation supports a separate session or site, separate reporting with an appropriate modifier may be supported. If the indicator is 0, the codes cannot be separated regardless of modifier. Prevention comes from checking current edits at the time of coding.

Scenario 4: Missing prior authorization

An elective interventional procedure is performed without a required authorization on file. The audit concern is that the payer required authorization and none was obtained. The auditor reviews the payer’s policy and the pre-service workflow to confirm the requirement and where it broke down. Prevention comes from a pre-service checklist that flags authorization-required services before scheduling.

Scenario 5: Documentation does not support the E/M level

An established patient visit is billed at a high level, but the documented medical decision making supports a lower one. The auditor compares the record against current E/M guidance, examining the problems addressed, the data reviewed and the risk. Where the documentation supports a lower level, the appropriate correction is to recode to the supported level and, if needed, educate the provider on documenting MDM or total time. Prevention comes from coding to what the record supports rather than to a habitual level.

Scenario 6: Duplicate cardiac monitoring claim

A remote cardiac monitoring service appears twice for overlapping periods. The audit concern is whether the second claim is a legitimate correction or a duplicate. The auditor reviews the claim history and the monitoring documentation to determine which. Prevention comes from claim-history checks before resubmission and clear internal handling of corrected claims so a correction is not mistaken for a new service.

How Professional Cardiology Billing Services Can Support Audit Readiness

Not every practice has the internal capacity to audit at the depth its service mix requires. Cardiology’s coding complexity, high authorization burden and recurring device and monitoring claims can outpace a small internal team, particularly when volume is high or coding staff is limited.

Outside or specialized support tends to help in specific situations: a high audit volume, repeated coding errors, complex interventional or electrophysiology services, dense payer-specific rules, recurring denials, an accounts receivable backlog, a growing appeal workload, authorization and eligibility tracking, documentation review, audit preparation, revenue-cycle analysis and staff training. A team that works only in cardiovascular care carries the coding and payer knowledge that a generalist biller has to relearn between specialties.

A practice weighing this can look at where its own findings concentrate. If audits keep surfacing the same denials, the same coding gaps, or the same authorization failures, dedicated support may resolve the pattern faster than repeated internal cycles. Cardiology Billing Services and its broader revenue cycle management work are built around that specialty focus and the related coding compliance guide covers documentation and audit readiness in more detail. No billing service can promise guaranteed compliance, guaranteed reimbursement, or guaranteed audit outcomes; what specialized support offers is consistent, cardiology-specific attention to the details that generalist billing tends to miss.

Frequently Asked Questions

What is a cardiology audit checklist? A cardiology audit checklist is a structured list of review points used to confirm that cardiovascular services were documented, coded and billed correctly and in line with applicable coding and payer rules. It typically covers patient and insurance data, provider information, documentation, CPT and ICD-10-CM coding, modifiers, NCCI edits, medical necessity and claim outcomes.

What should a cardiology billing audit include? A billing audit should review patient demographics, eligibility, authorization, provider data, CPT and ICD-10-CM coding, modifiers, units, NCCI edits, timely filing, documentation and claim status. The aim is to confirm the claim is accurate and supported before or after submission and to identify where claims are most likely to fail.

What should be reviewed in a cardiology coding audit? A coding audit reviews whether the reported CPT, HCPCS and ICD-10-CM codes match the documented service, whether the E/M level is supported by medical decision making or time, whether modifiers reflect the documented circumstances and whether code combinations comply with current NCCI edits.

Why are cardiology billing audits important? Cardiology combines high service volume, high per-claim value and dense coding rules, so errors are both more likely and more costly. Audits confirm documentation supports billing, surface recurring patterns a single denial would hide, identify revenue leakage and support a functioning compliance program.

What documentation should be checked during a cardiology audit? Check for patient identification, date of service, the reason for the encounter, relevant history and exam, assessment and diagnosis, procedure documentation and findings, diagnostic test results and signed interpretations, medical necessity support, a treatment plan and provider authentication, along with consistency between the record and the claim.

How do you audit CPT coding in cardiology? Compare each CPT code against the documentation to confirm the code reflects the service performed, that units and frequency are correct, that add-on codes accompany their primary codes and that component and comprehensive services are reported appropriately. Confirm the codes are from the current CPT code set for the date of service.

How do you audit ICD-10-CM coding? Confirm each diagnosis is supported by the documentation, coded to the appropriate specificity and correctly linked to the service to establish medical necessity. A specific, supported diagnosis strengthens the claim, but a diagnosis code alone does not guarantee coverage, which depends on the payer’s policy.

Can modifier errors be identified through a cardiology audit? Yes. A modifier audit compares each modifier, such as 25, 26, 59, 76, 77, or 91, against the documented circumstances. Common findings include modifier 25 applied without a separate E/M and modifier 59 used to bypass an NCCI edit without supporting documentation.

What is a medical necessity audit? A medical necessity audit examines whether the documented diagnosis and clinical information support the service under the applicable coverage policy. For Medicare, that means checking against relevant LCDs and NCDs; for commercial payers, against the payer’s medical policy.

How should cardiology practices audit claim denials? Capture each denial’s reason, payer, codes, provider, location, dollar amount, authorization status and appeal outcome, then analyze denials in aggregate to find concentrations. Clusters by payer, provider, code, or reason point to systemic problems that upstream fixes can resolve.

What should be reviewed before submitting a cardiology claim? Before submission, review demographics, payer and provider information, authorization, coding edits, claim validation, potential duplicate claims and place of service. This pre-bill review catches errors while they can still be corrected without a denial.

How often should a cardiology practice perform billing and coding audits? There is no single required frequency. Many practices run ongoing prospective checks plus periodic retrospective audits, with additional targeted audits triggered by new providers, new services, coding updates, or a rise in denials. The right cadence depends on volume, risk and past findings.

What is the difference between a prospective and retrospective audit? A prospective audit reviews claims, coding, or documentation before submission or payment and focuses on prevention. A retrospective audit reviews already-submitted or paid claims and focuses on detecting patterns, quantifying impact and building corrective actions. Most practices use both.

How does a cardiology audit identify revenue leakage? An audit surfaces leakage through downcoding, missed charges, underpayments against contracted rates, bundling denials and unworked denials. Comparing claims against remittance data and contracted rates reveals where earned revenue was never captured or was paid below expectation.

Can a cardiology billing audit help reduce recurring claim denials? Yes. By tracing denials to root causes, whether documentation, coding, authorization, or eligibility, an audit identifies the process breakdowns behind repeated denials. Corrective actions targeting those root causes, verified through re-audit, can reduce recurrence.

Key Takeaways

  • A cardiology audit should review far more than CPT codes; it follows the claim from registration through payment.
  • Documentation must support exactly what was reported and payer-specific requirements may add to the general standard.
  • ICD-10-CM coding should reflect the documented condition at the appropriate specificity, but a diagnosis code alone does not guarantee payment.
  • Modifier use must be supported by the actual circumstances in the record, never added to secure payment.
  • NCCI edits and payer-specific rules should be reviewed against the version in effect for the date of service.
  • Authorization and eligibility should be verified according to each payer’s requirements and authorization is not the same as medical necessity.
  • Denial trends reveal recurring workflow and coding problems that individual denials hide.
  • Findings should lead to assigned corrective actions and follow-up monitoring, not blame for isolated errors.
  • Medicare rules, including NCCI, LCDs and NCDs, should not be applied automatically to commercial payers.
  • Audit criteria and sampling methods should be documented and applied consistently so results can be compared and repeated.

Conclusion

A cardiology audit checklist works because it forces a consistent question at every stage of the claim: does the evidence support what was billed? Answered honestly across registration, documentation, coding, modifiers, edits, medical necessity and payment, that question catches most of what goes wrong in cardiovascular billing before it becomes lost revenue or compliance exposure. The findings only matter if they lead somewhere, which is why root-cause analysis, corrective action and re-audit belong in the same process as the checklist itself. Used that way, a cardiology audit becomes less an annual event and more a standing habit that keeps documentation, coding and reimbursement aligned as codes and payer policies change.

Leave a Reply