Audit-Ready Resource Center

Fraud, Waste & Abuse Red Flags

An auditor-focused framework for recognizing patterns that warrant additional review, education, monitoring, or escalation.

Four Categories of Red Flags

A red flag is a signal for further review—not proof of fraud, waste, abuse, or improper intent.

1

Documentation

Conflicting statements, unsupported diagnoses, missing linkage, copied-forward content, or incomplete time support.

2

Coding & Billing

Code intensity exceeds documentation, modifiers change payment without support, or edits are repeatedly overridden.

3

Utilization & Patterns

Unusual frequency, volume, service mix, or outlier behavior across providers, locations, or service lines.

4

Operational & Process

Recurring errors after education, weak controls, unresolved findings, or inconsistent query and review practices.

Risk Signals That Warrant Review

Review the complete record, claim context, applicable rules, and comparison data before reaching a conclusion.

E/M and Service Levels

High-level services reported at an unusual rate or documentation that does not reflect the reported intensity.

Modifiers and Edits

Frequent modifiers, repeated bypasses, or payment-impacting modifiers without clear documentation support.

Diagnosis Reporting

Diagnoses reported without current evaluation, treatment, monitoring, or relevance to the encounter.

Medical Necessity

Services, tests, or frequency inconsistent with the documented condition or applicable coverage requirements.

Duplicate Services

Same or similar services reported multiple times without documentation distinguishing each service.

Provider or Location Outliers

Patterns materially different from peers, historical performance, or expected service-line behavior.

The Auditor Response Framework

Use a consistent sequence so the review is traceable, reproducible, and proportional to risk.

1
Define the Signal
State the observable pattern or concern without assigning intent.
2
Validate the Evidence
Review the record, claim, coding logic, edits, policy, and relevant comparison data.
3
Assess Scope and Impact
Determine whether the issue is isolated or patterned and evaluate compliance, financial, quality, and operational risk.
4
Document the Finding
Describe the condition, criteria, evidence, impact, and recommended response objectively.
5
Determine the Response
Correct, educate, monitor, expand the audit, or escalate through the appropriate compliance process.

Use Objective Audit Language

Describe what the evidence supports without assigning intent that has not been established.

Instead of

The provider committed fraud.
The coder intentionally unbundled the service.
This is abusive billing.
The claim is clearly false.

Use

The observed pattern warrants additional review under the applicable compliance process.
The reported services do not meet the documented or policy requirements for separate reporting.
The pattern may create compliance and reimbursement risk and should be evaluated further.
The claim elements are inconsistent with the documentation reviewed.

Three Questions Before Finalizing

QUESTION 1Did I distinguish the red flag from a confirmed finding?
QUESTION 2Did I validate the documentation, coding, policy, and pattern evidence?
QUESTION 3Did I avoid conclusions about intent and route the issue appropriately?
Recognize the Signal. Validate the Evidence.

A red flag starts the review—it does not finish it.