Behavioral-Health Audit Readiness: A Psychiatric Billing Services Documentation Pack for Payer and Privacy Reviews
Psychiatric billing services need an audit-ready documentation pack before payer reviews. Here is what OIG, CMS, and OCR findings say to assemble.

Behavioral-Health Audit Readiness: A Psychiatric Billing Services Documentation Pack for Payer and Privacy Reviews
Psychiatric billing services get audited on paperwork, not clinical outcomes. When a payer, Medicare contractor, or privacy officer pulls your records, they are checking that the chart, the claim, the consent form, and the credential file all agree on the same story. If any leg of that four-way match fails, the payment comes back.
The numbers justify the urgency. OIG estimated $580 million in improper Medicare payments for psychotherapy, including telehealth, during the first year of the COVID-19 public health emergency. CMS estimates about 9.5% of Medicare Advantage payments are improper, mostly for documentation that did not support the diagnosis coded. CMS's FY 2025 CERT data puts the Medicare FFS improper payment rate at 6.55%, $28.83 billion, with insufficient documentation behind about 53% of it. And 42 CFR Part 2 enforcement now expects every SUD-record consent practice to line up with the February 16, 2026 compliance deadline.
This article is the assembled checklist: what to have in each folder, who owns it, and how often to refresh it.
Key Takeaways
- Medicare Advantage improper payments hit about 9.5% of spend, mostly for unsupported diagnoses in documentation.
- OIG audits of psychotherapy found documentation deficiencies in 128 of 216 sampled enrollee days, with $580 million in estimated improper payments year one.
- 42 CFR Part 2 requires the new single-TPO consent structure to be live by February 16, 2026.
- Medicare telehealth flexibilities run through December 31, 2027, so modality, POS, and consent documentation still carries audit weight.
- Keep your payer-facing indices audit-ready: licenses, enrollment, NPI taxonomy, CAQH attestations, appeal logs, remittance variance reports.
What a payer or privacy audit actually pulls
The audit letter does not ask for your EHR. It asks for specific documents, and your job is to know you have them before the letter arrives. The usual pull list:
Requested item | Where it lives | Common failure |
|---|---|---|
Treatment plans and goals | Clinical chart | Goal language copied forward, no update cadence |
Progress notes tied to billed time | Clinical chart | Note does not state why the visit was medically necessary |
Consent forms (TPO, release, Part 2) | Intake file | Expired or missing consent signatures |
Authorization letters and tracking | Revenue cycle queue | Services rendered outside authorized units |
Telehealth consent and modality record | Clinical chart | No POS or platform documentation |
Credentialing and revalidation evidence | HR/Provider enrollment | Lapsed CAQH attestation or directory mismatch |
Claims and remits | Billing system | No reconciliation of authorization units to billed units |
A payer reviewing therapy claims is looking for a medical-necessity story: diagnosis, functional impairment, treatment plan, measurable goals, and progress toward them. If the note only says "client appeared stable," the service fails the audit even when it was clinically reasonable.
For the full picture on how behavioral-health claims get denied upstream of the audit, our behavioral-health claim denials page covers the error patterns. If you want to understand where psychiatric claims typically leak, start with our psychiatric billing services overview.
The Part 2 consent and disclosure folder
If your practice handles any substance use disorder records, this folder is now the first thing a privacy reviewer opens. The 2024 42 CFR Part 2 final rule took effect April 16, 2024, and compliance was required by February 16, 2026.
What has to be in place:
- A single treatment-payment-operations (TPO) consent form that names the types of records it covers, with an expiration date and revocation instructions.
- Redisclosure language on outgoing records that matches the rule: limits redisclosure unless the receiving party falls under the same confidentiality framework.
- A notice of privacy practices that explains Part 2 protections in plain terms.
- Breach notification procedures (including Part 2 breach reporting) documented and assigned to an owner.
Do not treat SUD records like ordinary psychotherapy notes. Part 2 protections are stricter, and a payer or privacy review of a SUD-touching chart will check consent scope first. We covered the operational billing side of this in our 42 CFR Part 2 consent rules guide, and our SUD counseling notes playbook walks through the documentation side.
Owner: compliance officer or clinical director. Refresh cadence: every 6 months, plus after any policy change or patient complaint.

The telehealth and e-visit documentation pack
Medicare extended its telehealth flexibilities through December 31, 2027. That buys time, not cover. For audit purposes, behavioral telehealth claims still need:
- The modality and platform documented (audio-only versus audio-video), with the matching place of service code.
- A specific telehealth consent on file. For Medicare, the in-person visit within six months of the first behavioral telehealth service remains a separate consideration depending on the service; check the current CMS FAQ before publishing any payer guidance internally.
- Session notes that match billed time and billed codes. OIG's audit of first-year COVID telehealth psychotherapy found a high share of documentation gaps around just this match.
The OIG number worth putting on your board: $580 million of an estimated $1 billion of psychotherapy payments in year one flagged as improper, with missing or weak documentation the biggest culprit. If your practice bills audio-only behavioral visits, our teletherapy audio-only verification checklist is the standard we hold those claims to, and the behavioral health prior authorization page shows where authorization tracking fits.
Owner: clinical director. Refresh cadence: monthly claims review, quarterly payer-policy refresh.
The claims, enrollment, and credentialing index
A payer audit ties claims to credentialing, so keep an index of:
- Enrollment effective dates per payer and per provider, including group reassignment attestations.
- NPI, taxonomy, and license numbers as they appear in CAQH and payer portals, cross-checked quarterly.
- Authorization logs per service line with units used, units remaining, and expiration dates.
- Payment variance reports that compare expected versus posted payment, by payer, each month.
- Appeal logs with payer reference numbers, dates, and outcomes.
The reason this folder matters is revenue: services delivered to a patient who was not yet enrolled, by a clinician whose license lapsed, or outside an authorization window all turn into recoupment requests three years later when the contractor comes back. Commercial payers have the same retrospective rights. Build the index before the request letter.
If you bill across multiple states, this is where it gets harder. License portability, payer enrollment timelines, and timely filing limits vary by state, which is why we maintain state-specific billing pages such as our New Jersey and New York pages. Enrollment hygiene is also the difference between a fast onboarding for a new clinician and a 90-day cash gap. Our credentialing services team handles that for practices that want it off their desk.
Three specifics worth tracking in the index every month:
- CAQH attestation freshness. Every active clinician needs a current attestation. Lapsed attestations are a common root cause for claims that deny for "provider not enrolled."
- Directory accuracy. What CAQH shows and what the payer portal shows should match. When they do not, claims route to the wrong tax ID and sit.
- Authorization unit burn. If a patient hits their authorized unit limit mid-month, you find that on the remittance, not in advance, unless someone is tracking it.
The privacy and security binder
OCR's recent enforcement makes this binder a board-level item. IBM's 2025 Cost of a Data Breach Report puts the average healthcare breach at $7.42 million, the highest of any industry for the 14th year straight. OCR risk-analysis failure settlements totaled roughly $6 million between early 2024 and mid-2025. Behavioral health providers hold some of the most sensitive data there is, so the binder needs:
- A documented risk analysis, updated annually and after major system or vendor changes.
- Access controls mapped to role, with quarterly access reviews and a minimum-necessary policy.
- Business associate agreements for every vendor touching PHI, including clearinghouses under Part 2 contracts.
- Incident response and breach notification procedures with assigned contacts and outside counsel.
- MFA, encryption, and audit-log review procedures in writing.
A reviewer will accept a gap as a finding, not as an excuse. Document the remediation plan with dates and owners. That is the difference between a corrective action plan and a civil money penalty.
A monthly 60-minute audit cadence
Readiness fails when it is a binder nobody opens. Run this on the same day every month:
Task | Owner | Time |
|---|---|---|
Pull 5 random charts, check treatment plan, goals, and note completeness | Clinical director | 20 min |
Reconcile last month's authorizations to billed units | Billing lead | 15 min |
Review Part 2 consent dates and expirations | Compliance officer | 10 min |
Check CAQH attestation freshness and portal directory matches | Credentialing | 10 min |
Open the privacy binder: risk analysis date, access review, incident log | Compliance officer | 5 min |
If a chart fails twice, that is a training issue, not a documentation issue. We see practices fix this by running a focused note-writing session on the two failed items and spot-checking the same provider 30 days later.

Common questions
How far back can a payer audit my charts? Medicare contractors generally work within a 3-year lookback on claims, and overpayment identification carries a 6-year False Claims Act horizon. Commercial payer contracts usually specify a lookback window too. Read your agreements; the binding term is what the auditor will cite.
What is the most common chart failure in a behavioral-health audit? Time and medical necessity. The note must tie the billed time to the diagnosis, functional status, and treatment plan. Notes that read like attendance logs lose.
Where can I get help assembling this? Our medical billing audit service is built around exactly this documentation pack, and you can start with a free audit to see where your records currently stand. If you want the broader specialty context first, read our behavioral health billing hub.
The short version: auditors do not want a war story. They want the four-way match between chart, claim, consent, and credential, indexed and refreshed on a schedule. Practices that treat that as a monthly habit survive payer reviews. Practices that treat it as a binder opening it twice a year write the bigger check when the letter comes. If you want an outside read on your current state, start with a free audit.
Reviewed by: MDRG Behavioral Health Compliance Review team. Sources cited: HHS OIG psychotherapy audit reporting, CMS FY 2025 improper payment reporting, HHS Part 2 fact sheet, telehealth policy updates, IBM 2025 Cost of a Data Breach Report, OCR enforcement summaries.
