Home / Behavioral Health Billing Errors That Lead to Medicaid Audits
Behavioral health billing is complex, and errors can lead to costly Medicaid audits. Common issues include missing documentation, incorrect coding, and eligibility mistakes. Auditors often focus on time-based CPT codes, telehealth claims, and insufficient progress notes. With Medicaid audits increasing due to initiatives like CRUSH, providers face heightened scrutiny, financial penalties, and operational strain.
Key Takeaways:
Documentation Issues: Missing signatures, vague treatment plans, and incomplete telehealth records are top audit triggers.
Coding Errors: Upcoding, incorrect modifiers, and repeated use of CPT 90837 are frequent problems.
Eligibility Mistakes: Uncredentialed staff and authorization errors can result in claim denials or recoupments.
To reduce risk:
Conduct regular internal audits.
Ensure documentation meets Medicaid standards.
Use AI tools for billing accuracy and compliance.
Proactively addressing these areas can protect your revenue and minimize audit risks.
Medicaid auditors often focus on recurring problem areas in behavioral health billing, making certain mistakes more likely to result in recoupments.
A lack of proper documentation is one of the top reasons Medicaid audits lead to repayment demands. In behavioral health, every billed service must be supported by clinical evidence, and auditors frequently uncover issues in these key areas:
Documentation Component | Common Audit Red Flags |
|---|---|
Treatment Plans | Missing provider or patient signatures, unclear or immeasurable goals, overuse of generic templates, failure to update regularly |
Progress Notes | Lack of session start and end times, no connection to treatment goals, missing provider credentials |
Medical Necessity | Vague descriptions, absence of functional impairment details, diagnosis not consistently supported throughout care |
Telehealth | Missing patient location, no consent documentation, incorrect modifiers or place-of-service codes |
“Incomplete treatment plans are one of the most common audit findings for behavioral health providers.” – Cipher Billing [4]
One overlooked issue is the need for consistent record defense over time. Medicaid payers now expect a diagnosis to be clinically justified not just at the start of treatment but throughout its duration [2]. Even a strong intake assessment won’t protect claims if follow-up notes fail to demonstrate ongoing medical necessity.
In addition to documentation problems, errors in coding and modifier use are another major source of audit risk.
Coding mistakes are common in behavioral health and often revolve around a few key issues. One of the most frequent is upcoding, or billing for a higher-intensity service than the documentation supports. For example, billing CPT 90837 (53+ minutes of individual psychotherapy) when the session note only shows 45 minutes of service can trigger a recoupment demand – even a small discrepancy like this can lead to denials.
Telehealth billing adds complexity. As of 2026, Modifier 95 should be used for audio-video sessions, while Modifier 93 or FQ applies to audio-only visits. Using outdated modifiers, such as GT instead of Modifier 95, is a common audit trigger. Complicating matters further, Medicaid modifier requirements can vary by state, so what works in one state might not apply in another.
Add-on psychotherapy codes – 90833, 90836, and 90838 – also carry risks. These codes must be paired with a primary E/M code, and Modifier 25 must be added to the E/M code to show it represents a separate service. Forgetting this modifier often leads to bundling denials. Medicaid auditors also use data analytics to flag unusual billing patterns. For instance, consistently billing CPT 90837 for every session will almost certainly attract audit scrutiny.
While less obvious than documentation or coding issues, eligibility and authorization errors can lead to substantial recoupments. A series of OIG audits across Indiana, Wisconsin, Maine, and Colorado found improper claims in every one of the 100 sampled enrollee-months, resulting in federal recoupment recommendations exceeding $123 million for Applied Behavior Analysis (ABA) services alone [6].
Some common mistakes include:
Uncredentialed Staff: Services provided by staff without proper credentials, such as behavior technicians lacking RBT certification or BCaBAs operating outside their scope, are frequent audit findings [6].
ORP Compliance: Federal rules (42 CFR §455.410) require that any provider ordering, referring, or prescribing services must be enrolled in the state’s Medicaid program. Claims are often denied if the referring provider isn’t listed in the state’s database [5].
Authorization Errors: Problems arise when providers obtain authorization for the wrong CPT code, incorrect units, or a rendering provider who didn’t deliver the service. With over 70% of Medicaid beneficiaries now enrolled in managed care plans [5], providers face the added challenge of navigating varied authorization rules for each plan. Being enrolled in one managed care plan doesn’t guarantee coverage in another.
The next section will explore strategies to help providers reduce these risks.
Billing errors can lead to financial consequences that go far beyond a single denied claim. Auditors typically examine a sample of around 100 claims, and if errors are found, they extrapolate those findings across a larger pool of claims. This process can result in recoupment demands reaching millions of dollars.
Take the audits of Applied Behavior Analysis (ABA) services in Indiana, Wisconsin, Maine, and Colorado as examples. These audits revealed significant financial repercussions, with federal recoupment recommendations for these four states surpassing $123 million [6]. Indiana, in particular, saw its Medicaid spending on ABA services skyrocket from $21 million in 2017 to $611 million in 2023. This dramatic increase caught the attention of federal auditors, leading to recoupments and systemic rate reductions [6].
State | Audit Published | Recommended Federal Refund | Primary Finding |
|---|---|---|---|
Indiana | December 16, 2024 | $39.4 million | Unsupported CPT codes, missing session notes/signatures |
Wisconsin | July 10, 2025 | $12.2 million | Notes lacked service descriptions, goals, or data |
Maine | January 16, 2026 | $28.7 million | Missing comprehensive assessments and parent signatures |
Colorado | February 25, 2026 | $42.6 million | Use of non-credentialed technicians (non-RBTs) |
In response to these findings, Indiana issued bulletin BT202627 in February 2026. This bulletin introduced a 6% rate reduction in 2026, followed by an additional 4% cut in 2027. It also imposed a lifetime cap of 4,000 hours on comprehensive ABA services and required all providers to obtain accreditation [6].
But the financial toll is just one part of the story. Billing errors also create operational hurdles that can be just as challenging.
The ripple effects of billing errors extend into administrative and operational areas, creating long-term challenges for behavioral health providers. Medicaid audits and the subsequent appeals process can drag on for years – typically 2.5 to 4.5 years – consuming staff time, piling up legal fees, and ultimately pulling focus away from patient care [7].
A May 2026 audit of Bonnie Brae, a nonprofit in New Jersey offering residential treatment for emotionally disturbed youth, highlights the operational strain these errors can cause.
Auditors found 93 duplicated progress notes and instances where clinical coordinators logged up to 436 work hours in a single month – an impossibility given the standard 160-hour work period. This led to a $1,528,109 recoupment demand and required the organization to implement a Corrective Action Plan, which included hiring additional clinicians and conducting intensive staff training [9].
The fallout from audit findings doesn’t stop at financial penalties.
Reports detailing issues like documentation failures, duplicated notes, or unlicensed staff can harm an organization’s reputation.
This damage can ripple through contract negotiations with Managed Care Organizations (MCOs), erode community trust, and undermine the ability to demonstrate clinical quality to payers focused on performance metrics [10].
To avoid the financial and administrative headaches that come with Medicaid audits, taking proactive steps is key. Conducting quarterly audits – monthly for high-volume practices – can help you keep a close eye on billing patterns before small issues snowball into major compliance problems [11].
During these audits, review 5 to 10 random charts per provider to pinpoint recurring issues like modifier mistakes, missing signatures, or outdated treatment plans. Automated tools can also help by flagging notes for time-based psychotherapy codes that don’t include required start and stop times [3][11].
Don’t overlook credentialing. A monthly check ensures that licenses are current and supervisory documentation is complete, reducing the risk of claim denials [12]. These internal checks not only improve compliance but also strengthen documentation and coding accuracy.
Interestingly, 77.17% of Medicaid improper payments are due to insufficient documentation – not fraud [5].
To tackle this, use standard templates that prompt for critical details like diagnosis linkage, functional impairment descriptions, objective measures such as PHQ-9 or GAD-7 scores, and accurate start/stop times for sessions [3][11].
If you’re reusing treatment plans, make sure they’re updated, signed, and include measurable, time-specific goals. Another critical step? Verify patient eligibility at three stages: 24 to 48 hours before the appointment, on the day of service, and again before submitting the claim. This simple process can prevent over half of rejected claims [5][4].
While manual audits are important, they can only cover so much ground. With CMS set to expand Medicaid audit operations in 2026 – reviewing up to 200 records per audit instead of the current 35 [8] – the margin for error is shrinking fast. That’s where AI-powered Revenue Cycle Management (RCM) tools come in.
These tools embed compliance checks directly into your billing workflow. For example, automated 270/271 eligibility sweeps confirm Medicaid coverage at intake and throughout the care process, catching lapses that often occur during redetermination periods [1][5].
Claim scrubbing tools validate payer-specific requirements, such as telehealth modifiers (95, GT) and Place of Service codes (02, 10), before submission [1][3]. Denial management dashboards also help by grouping rejections by code and payer, making it easier to trace issues back to documentation gaps [1].
Platforms like BHRev are designed specifically for behavioral health providers, offering features like automated eligibility checks, AI-powered claim scrubbing, denial tracking, and alerts for expiring authorizations.
By reducing manual touchpoints, these tools significantly lower the chances of errors. BHRev even offers full-scale RCM outsourcing on a performance-based model, ensuring their goals align with your clean claim rate.
Medicaid audits are ramping up. With an improper payment rate projected at 6.12% in 2026 – equating to $37.39 billion in lost revenue – and the Centers for Medicare & Medicaid Services (CMS) increasing the number of records reviewed per audit to 200 [8], relying on reactive fixes after denials is no longer a sustainable strategy.
These shifts call for proactive, ongoing improvements in billing and compliance processes.
Interestingly, most audit findings are linked to documentation gaps rather than fraudulent activity [5]. This highlights an opportunity: stronger documentation practices, regular eligibility checks, and precise coding can significantly reduce revenue risks.
To protect your practice and revenue, consider implementing these three key strategies right away:
Prioritize Documentation: Address recurring documentation errors by treating progress notes as a critical part of your revenue strategy. Ensure each note clearly connects patient symptoms, diagnoses, and interventions to justify the services provided.
Tailor Medicaid Billing Practices: Medicaid billing isn’t one-size-fits-all. Fee-for-Service programs and Managed Care Organizations have different rules, including authorization requirements, filing deadlines, and coding guidelines [10][5]. Create a payer-specific tracking system and assign someone to review state Medicaid updates monthly to minimize preventable denials.
Embed Audit Readiness into Daily Operations: Make audit preparation a routine part of your workflow. Develop a written audit response plan, appoint a dedicated contact person, and perform regular self-audits by reviewing 10–15 charts across different levels of care [8]. Leverage technology, like BHRev, to automate tasks such as eligibility checks, claims error reviews, and tracking authorization expirations.
Progress notes play a critical role in passing a Medicaid audit. They must clearly demonstrate medical necessity and highlight individualized care for each client. To ensure compliance, your notes should include the following:
Date, location, and start/stop times: Be precise, such as “10:03 AM – 11:03 AM.”
Provider’s name: Clearly identify the rendering provider.
Details of the session: Specify the service provided, the clinical intervention used, and the client’s response to the session.
Connection to treatment goals: Show how the session aligns with the client’s diagnosis, treatment goals, and level of care.
It’s important to avoid using cloned or copy-pasted notes. Each entry should reflect the unique circumstances and measurable progress of the session, ensuring the documentation is both accurate and personalized.
When billing for telehealth services, it’s important to use the correct modifiers:
Modifier 95 is used for synchronous audio-video telehealth services. However, some states may still require the older GT modifier, so it’s wise to check specific state guidelines.
Modifier 93 applies to synchronous audio-only mental health services. Many states now prefer 93 over older codes like FQ, aligning with Medicare’s policies.
Since Medicaid policies differ by state and are frequently updated, always confirm the latest requirements with your state payer. BHRev supports providers in navigating these compliance complexities.
Preventing Medicaid billing mistakes starts with having solid processes in place from the beginning. Here’s how to keep things running smoothly:
Verify Coverage in Advance: Check Medicaid coverage 48–72 hours before scheduled appointments. Pay special attention to behavioral health carve-outs and any plan-specific requirements that could affect billing.
Automate Re-Verification: Set up a system to re-verify coverage weekly for active patients. This helps identify lapses in coverage early, reducing the risk of billing issues.
Stay on Top of Authorizations: Use alerts to track authorization expiration dates. Set reminders for 21 and 7 days before authorizations expire to ensure you don’t exceed limits or miss renewals.
Document Everything: Always keep a record of your verification efforts. Include details like call reference numbers to make sure your practice is prepared for any audits.
By implementing these steps, you can minimize errors and maintain compliance with Medicaid billing requirements.
One email a month, no fluff. Unsubscribe anytime.