top of page

Preparing for a Medicaid Audit Without Panic

woman seated at desk drinking from mug while typing

This article is intended for educational purposes and reflects general guidance based on published standards, industry practices, and publicly available audit findings. It does not constitute legal, financial, or compliance advice and does not create a consultant-client relationship. Medicaid compliance requirements vary by state and payer. Please consult qualified legal counsel and compliance professional familiar with your state's specific requirements before making compliance-related decisions.

Audits Don't Create Problems. They Reveal Them.

The audit notice arrives, and for most providers, the first feeling isn't confidence or determination. It's overwhelm. Suddenly every client file feels suspect. Every personnel record becomes a question mark. Each policy and procedure feels outdated. All shared drives start looking like a series of scavenger hunts. Teams start asking who owns this, were signatures collected for this, where is that documentation stored, and has anyone checked on that credential recently?


That reaction is completely understandable. But here's the part that matters: audits rarely create those questions. They expose the places where organizational systems weren't clearly defined long before the audit notice arrived. One of the most common themes that surfaces during audits isn't that nobody cared. It's that everyone assumed someone else owned the task. A missing physician order. An unsigned treatment plan. An expired background check. An outdated policy. A business associate agreement that was never finalized. When responsibility lives in assumptions rather than clearly defined ownership, compliance tasks slowly drift off the radar.


For many providers, especially solo practitioners, small agencies, and growing organizations, that gap doesn't exist because people are indifferent to compliance. It exists because they're wearing ten different hats. One day they're interviewing candidates. The next they're covering client sessions, troubleshooting billing issues, responding to caregiver concerns, onboarding new staff, or squeezing documentation into the last hour of the evening. They're also relying on memory more than systems. Someone "knows" the physician order was received. Someone "thought" HR uploaded the background check. Someone "assumed" the treatment plan was signed. Assumptions feel efficient until an auditor asks for proof.


Good systems reduce the amount of remembering, scrambling, and last-minute heroics required from he people running them. They make the right thing easier to do, even on busy days. In behavior analysis, we rarely expect lasting behavior change from a single intervention. We shape behavior over time through small, intentional changes that build toward a larger goal. The same principle applies to organizations. Audit readiness isn't achieved by pulling a week-long spring after receiving a notice. It's shaped through consistent practices, routine monitoring, and gradual improvements that become part of how your organization operates every day.


Compliance as a task is reactive, stressful, and unsustainable. Compliance as organizational design is proactive and, over time, almost automatic. Every audit finding is data. Some data tell you an individual made a mistake. More often, they tell you the system made the mistake easy to make.


That distinction matters more than any checklist.

When the Numbers Tell a Story

In March 2026, the U.S. Department of Health and Human Services Office of Inspector General released the finsings of its audit of Colorado's fee-for-service Medicaid payments for Applied Behavior Analysis services. The results were sobering. Colorado's Medicaid ABA payments had grown from $60.1 million in 2019 to $163.5 million in 2023. The OIG reviewed $289.5 million in payments across 2022 and 2023. Of the 100 sampled enrollee-months reviewed, every single one contained at least one claim line that was improper or potentially improper. The OIG recommended Colorado refund $42.6 million to the federal government.


The audit didn't uncover widespread fraud or intentional misconduct. What it found was something far more common, and far more preventable: systemic documentation failures, credentialing gaps, and unclear billing practices across the board. Colorado is not alone. The OIG's ABA audit series currently spans eight state projects, with more reports still coming. Indiana, Wisconsin, Maine, and Colorado have all been reviewed. The pattern is consistent across every state: misaligned understandings of what's billable, insufficient documentation standards, and a lack of routine internal review.


Rather than viewing the report as a reason for alarm, providers can use it as an opportunity to evaluate whether their own systems support the quality of care they work hard to deliver every day.

What the Auditors Actually Found

Before you can build better systems, it helps to understand what breaks down. The Colorado audit findings are unusually specific, which makes them useful. They tell you exactly where the risk lives.


Of the 100 sampled enrollee-months:

  • 93 did not meet documentation requirements

  • 18 involved providers without appropriate credentials

  • 7 lacked a required diagnosis or treatment referral


Among the potentially improper payments, auditors flagged claims where services were not fully described, where nontherapy time appeared to be billed as therapy time, and where group activities were billed under codes intended for individual treatment.


The OIG's recommendations to Colorado were equally instructive. They called on the state to provide additional guidance to ABA facilities on three specific areas: documenting ABA services (including session note content and signature requirements), billing ABA services (including what counts as billable time), and credentialing requirements for providers.


Three areas. Documentation. Billing. Credentialing. That is not a compliance department problem. That is an organizational systems problem, and it's fixable.

Technology Has Raised the Bar

Twenty years ago, responding to a documentation request often meant digging through filing cabinets, tracking down paper charts, and hoping the right signature was on the right form. Today, electronic health records, EVV systems, billing platforms, cloud storage, and digital credentialing have changed what auditors expect. And how quickly they expect it. When documentation is requested during an audit, there is generally an assumption that records can be producted quickly and electronically. The threshold for "acceptable" has risen considerably.


The challenge is that technology doesn't automatically create good systems. An EHR can't compensate for inconsistent documentation practices. A billing platform can't flag what it doesn't know to look for. Digital tools are only as strong as the workflows and training behind them. The Colorado audit found documentation failures at scale in organizations that almost certainly had electronic systems in place.


Buying software is not the same things as building a system. Technology can make good systems faster and easier. It can make them more transparent. but it can't create consistency where consistency doesn't already exist.

PDG Perspective: The strongest organizations don't wait for an audit to find gaps. They build systems that make quality, consistency, and compliance part of everyday operations, not a spring that happens after a letter arrives.

What an Audit Actually Is

Audits generally aren't looking for perfection. They're looking for evidence that your organization consistently delivers services as documented, bills appropriately, maintains required records, and corrects problems when they're identified. That's a meaningfully different bar, and a much more achievable one.


At its core, a Medicaid audit is a structured review designed to determine whether billed services were supported by appropriate documentation, delivered by qualified providers, and reimbursed according to applicable requirements. Depending on the type of audit reviewers may examine clinical documentation, billing records, authorizations, credentialing, or other records that demonstrate services were provided as claimed.


Many audits are routing oversight activities designed to protect public funds and ensure consistent application of Medicaid requirements. That said, audits can carry significant consequences when documentation or systems don't support the services billed. Understanding what reviewers are looking for shifts the conversation from fear to preparation.

Audit vs. Credentialing Review: Know the Difference

One of the most common sources of confusion for providers is treating a Medicaid audit and a credentialing or readiness review as the same thing. They're related, but they're not interchangeable. And preparing for one without understanding the other leaves real gaps.

Medicaid Audit

Credentialing/Readiness Review

Focuses on services delivered

Focuses on the organization as a whole

Reviews clinical documentation

Reviews policies and procedures

Examines billing records

Examines personnel files

Verifies authorizations

Verifies training records

Reviews EVV compliance

Reviews licensure and credentialing

Assesses medical necessity

Assesses organizational infrastructure

The underlying principle connecting both: strong systems make every review easier. An organization with clean, consistent documentation and current personnel records doesn't just survive audits. It moves through them without panic, because the work was already done.

The Four Pillars of Audit Readiness

Strong audit readiness is built on four interconnected pillars. Think of them less as a checklist and more as organizational habits that support one another over time.

People

Do your staff understand not only what they're expected to do, but why it matters? Training, competency verification, clear expectations, and ongoing feedback create consistency. Documentation quality doesn't improve because people care more. It improves because organizations invest in teaching, reinforcing, and supporting good practices.

Can two different employees follow the same workflow and arrive at the same result? Policies, SOPs, and workflows should reduce guesswork. The goal isn't simply having written procedures. It's ensuring they're current, accessible, understood, and consistently followed.

Would someone outside your organization understand exactly what occurred based solely on the record? Complete, accurate, and timely documentation protects clients, providers, and organizations. The Colorado audit findings weren't simply about missing records. They frequently involved documentation that was incomplete or insufficient to support the services billed.

How does your organization discover small issues before someone else does? Internal audits, routine quality assurance, policy reviews, and corrective action plans aren't signs that something is wrong. They're evidence that your organization is committed to getting better.

Together, these four pillars create organizations that aren't just audit-ready. They're better equipped to deliver consistent, high-quality services every day.

Build One Small Habit

One of the most common things we hear from providers, especially smaller agencies and solo practitioners, is some version of: "I know I should do this, but I don't know where to start without overhauling everything."


You don't have to fix everything this quarter. You just have to fix something. Progress beats perfection every time.


Here's a rolling internal audit calendar that distributes the work across twelve months, so nothing piles up into a crisis:

  • Month 1: Review 5 client files for documentation completeness

  • Month 2: Audit personnel files: credentials, licenses, training records

  • Month 3: Review your policy manual: Are policies current and dated?

  • Month 4: Review supervision documentation: frequency, signatures, content

  • Month 5: Audit authorizations: Are they current? Do billed services align?

  • Month 6: Review billing reconciliation: Are codes being used correctly?

  • Month 7: Review EVV compliance and session note quality

  • Month 8: Review onboarding documentation for recent hires

  • Month 9: Spot-check data collection records

  • Month 10: Review corrective action files and incident documentation

  • Month 11: Review HIPAA compliance, Business Associate Agreements, and secure documentation storage

  • Month 12: Full policy and procedure review


Twelve small improvements made consistently are often far more sustainable than one massive compliance project completed under pressure. By the end of a year, you've completed a meaningful internal audit without ever spending a panicked weekend cleaning up your organization before a site visit.

What This Moment Requires

The OIG audit series is not finished. More state reports are coming. As federal and state agencies tighten oversight of Medicaid ABA spending, driven in part by cost increases that far outpaced patient growth, the scrutiny on providers is only going to increase. That's not cause for panic. It's cause for preparation.


The agencies that come through this period in the strongest position won't be the ones that scrambled hardest after receiving an audit notice. They'll be the ones that spent the previous year intentionally building systems: reviewing files, updating credentials, tightening session notes, and asking themselves the hard questions before anyone else did. If you're reading this and wondering where your organization stands, that's the right instinct. The next step is simple: pick one pillar, pick one month, and start.


No organization is perfect. Every provider, large or small, will find opportunities to strengthen their systems over time. The organizations that navigate audits most successfully aren't necessarily the ones that never make mistakes. They're the ones that have built systems capable of finding those mistakes, learning from them, and improving. The goal isn't perfection. It's consistency. And consistency, practiced over time, builds confidence long before an audit letter ever arrives.

Prisma Dimensions Group provides consulting services to ABA and behavioral health organizations navigating compliance, HR, and operational systems. If you'd like to talk through where your organization stands, contact us here or by email at info@prismadimensionsgroup.com.

 
 
 

Comments


  • LinkedIn
  • Facebook
  • Instagram

© 2025 by PRISMA DIMENSIONS GROUP, LLC

bottom of page