Use this comprehensive checklist to ensure your practice maintains compliance with all federal and state regulations governing medical billing. Check off each item as you complete your review.
1. HIPAA Privacy & Security Compliance
- Designated Privacy Officer and Security Officer assigned
- Written HIPAA policies and procedures in place and updated annually
- Business Associate Agreements (BAAs) signed with all vendors
- Staff HIPAA training completed within last 12 months
- Risk assessment conducted within last 12 months
- PHI access logs reviewed regularly
- Encryption enabled for all electronic PHI
- Secure messaging systems in place for patient communication
- Breach notification procedures documented
- Minimum necessary standard applied to PHI access
Note: HIPAA violations can result in penalties ranging from $100 to $50,000 per violation, with annual maximums up to $1.5 million.
2. Documentation Requirements
- Medical necessity documented for all services billed
- Documentation supports the level of E/M service billed
- All entries dated, timed, and signed by provider
- Diagnostic codes reflect the current encounter
- Procedure notes completed same day as service
- Amendments properly identified and signed
- Orders documented before services rendered
- Physician orders required for all diagnostic tests
3. Coding Compliance
- Using current year CPT, HCPCS, and ICD-10 code sets
- Coders hold current certifications (CPC, CCS, etc.)
- Regular coding audits performed (minimum quarterly)
- Modifier usage follows payer guidelines
- Unbundling policies understood and followed
- Correct use of E/M documentation guidelines (2021 updates)
- National Correct Coding Initiative (NCCI) edits reviewed
- LCD/NCD requirements verified before billing
Best Practice: Conduct internal coding audits on at least 5% of claims monthly to identify patterns and training opportunities.
4. Billing Practices
- Claims submitted within timely filing limits
- Correct insurance information verified at each visit
- Prior authorizations obtained when required
- Co-pays and deductibles collected at time of service
- Written financial policy provided to patients
- Refund policy in place and followed
- Credit balances reviewed and resolved monthly
- Charge capture process documented
Timely Filing Requirements by Payer
| Payer Type |
Filing Deadline |
| Medicare |
12 months from date of service |
| Medicaid |
Varies by state (90 days to 12 months) |
| Commercial |
Typically 90-180 days (check contract) |
| Workers' Comp |
Varies by state |
5. Anti-Kickback & Stark Law Compliance
- No payments for patient referrals
- Fair market value for all contracted services
- Written agreements for all referral arrangements
- Stark exceptions documented for any self-referrals
- No gifts to patients exceeding nominal value ($10)
- Marketing practices reviewed for compliance
- Lab and diagnostic referral patterns monitored
Warning: Anti-Kickback Statute violations can result in criminal penalties up to $100,000 per violation, imprisonment, and exclusion from federal healthcare programs.
6. OIG Compliance Program Elements
- Written compliance policies and procedures
- Designated Compliance Officer
- Regular compliance training for all staff
- Open lines of communication (hotline/reporting)
- Regular auditing and monitoring
- Disciplinary guidelines for non-compliance
- Prompt response to detected problems
7. Credentialing & Enrollment
- All providers properly credentialed before billing
- NPI numbers current and correct
- CAQH profiles updated quarterly
- License expirations tracked and renewed timely
- Malpractice insurance current
- DEA registration current (if applicable)
- Medicare enrollment revalidation completed
- Group and individual enrollments aligned
8. Denial Management & Appeals
- Denial tracking system in place
- Root cause analysis performed on denials
- Appeals submitted within payer deadlines
- Appeal letter templates available
- Denial trends reviewed monthly
- Corrective actions documented
9. Patient Rights & Financial Practices
- Good Faith Estimates provided (No Surprises Act)
- Price transparency requirements met
- Patient-friendly billing statements
- Payment plan options available
- Collection practices follow FDCPA guidelines
- Charity care policy in place
Annual Compliance Calendar
| Month |
Required Action |
| January |
Update code sets, review fee schedules |
| Quarterly |
Internal coding audits, CAQH updates |
| Annually |
HIPAA risk assessment, staff training, policy review |
| Ongoing |
Denial monitoring, license tracking, compliance reporting |