Revenue Cycle Department Audit Checklist for Hospital Leaders
A revenue cycle department audit reviews every stage of the process, from scheduling to collections, to find where revenue is lost, delayed, or exposed to compliance risk. Use the checklist below to score ten areas as pass, partial, or fail, assign an owner to each gap, and prioritize by dollar impact. If several areas fail or you lack the time to test them, bring in an outside assessment partner.
Most revenue cycle problems do not announce themselves. A slow drift in denials, a coding backlog, or a stale charge master can go unnoticed until cash slows. A structured internal audit surfaces those issues early. This checklist is a practical operational and compliance review for hospital leaders. It is not a formal compliance audit protocol, which involves specific sampling methods, documentation standards, and legal and compliance procedures. A revenue cycle assessment reviews end-to-end operations, benchmarks key metrics, and produces a prioritized improvement plan. For more on that service, see What Is Revenue Cycle Consulting & Assessments?
How to Run the Audit
Set scope and period. Choose a review window, such as the last 12 months, and decide which facilities and payers are included.
Pull data first. Gather your KPIs, denial reports, A/R aging, and write-off data before you interview anyone.
Sample real accounts. Test a sample of accounts end to end rather than relying on policy documents.
Score each item as pass, partial, or fail, and note the evidence.
Assign an owner and a date to every gap, then rank by financial impact and compliance risk.
The Checklist
1. Governance and Data
Revenue cycle KPIs are defined the same way across facilities
A dashboard is reviewed monthly by leadership
Each KPI has a named owner and a target
Policies are current and staff can find them
Reports reconcile with the general ledger
2. Patient Access (Front End)
Registration data is checked for accuracy at intake
Eligibility and benefits are verified before service
Required prior authorizations are tracked and completed before service (see authorization software and services)
Patients receive cost estimates where required or appropriate, and staff collect at or before service
Registration error rates are measured and fed back to staff
For context on why this stage matters, see Why Patient Access Is Becoming a Strategic Priority
3. Charge Capture and Charge Master
The charge master is reviewed on a set schedule
Charges are captured for all billable services, including late charges
Departments reconcile charges against orders or documentation
Compliance with CMS Hospital Price Transparency requirements is monitored, including the updated 2026 requirements CMS began enforcing on April 1, 2026
4. Documentation and Coding
Coding accuracy is audited on a regular sample
Coding backlog and turnaround time are tracked
Documentation queries are answered quickly
CDI feedback reaches physicians (see CDI software and services)
Coders receive education based on audit findings
5. Claims and Billing
Claim edits are reviewed and updated as payer rules change
Rejections are worked quickly and trended by cause
Late-charge and rebilling volumes are tracked
Timely filing deadlines are monitored
Claim management workflows are documented
6. Payment Posting and Underpayments
Payments post accurately and promptly
Payments are compared against contracted rates
Underpayments are identified, tracked, and disputed
Credit balances and refunds are resolved on time
7. Denials and Appeals
Denials are categorized by root cause, payer, and dollars
Appeal deadlines are tracked
Denial trends are shared with access, coding, and clinical teams
Write-off approval rules are clear
Denial prevention is reviewed, not only denial recovery (see denial management services)
8. A/R Follow-Up and Payer Access
Follow-up work is prioritized by balance and age
Staff have efficient access to payor portals (see What Are Payor Portal Access Systems?)
Portal credentials are controlled and audited
Aged A/R is reviewed at set intervals
9. Patient Financial Services
Statements are clear and delivered by the channels patients use
Payment plans and financial assistance are easy to access
Early-out and bad debt placements follow written rules
Complaints and billing disputes are tracked
10. Compliance, Security, and Vendors
Billing compliance reviews occur regularly (see billing compliance software and services)
Access to systems is role-based and reviewed
Every vendor that creates, receives, maintains, or transmits PHI on the hospital's behalf has a current BAA, and vendor security reviews follow internal policy
Vendor performance is measured against contract terms
Staff training on compliance is current
Scoring and Prioritizing Findings
Count the failed and partial items in each section, then rank the gaps by two questions: how many dollars are at stake, and how quickly could the gap create compliance exposure? Fix quick wins first, such as unmonitored deadlines and missing owners. Plan longer projects, such as technology changes, separately.
When to Bring in Outside Help
Consider an outside partner if the audit turns up several failed areas, if you lack the staff to sample accounts, or if leadership wants an independent benchmark. RCR|HUB lists partners across revenue cycle consulting and assessment, audit services, and medical coding audit and accuracy. Use the 25 Questions guide as a model for vetting any partner you shortlist. Business Partners can subscribe to RCR|HUB's RFP Access Network for access to researched, live RFP opportunities and the hospital and healthcare organization directory.
Frequently Asked Questions
-
Many hospitals do a full operational review once a year, with targeted reviews of high-risk areas, such as coding or denials, more often. This is separate from a compliance audit plan, which OIG recommends building each year based on risk, prior findings, and high-volume services.
-
As a best practice, someone independent of the day-to-day process, such as compliance, finance, or an outside partner, helps keep findings objective. For coding and compliance reviews, use qualified audit staff.
-
It depends on scope. A focused review of one area is much faster than an end-to-end assessment across facilities.
-
In general, an audit tests performance against a defined standard, such as compliance or coding accuracy. An assessment usually looks more broadly at operations and often leads to an improvement plan. Many organizations use both.