Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
Answer first: build a chart that defends itself without you in the room
To prepare for a payer audit in behavioral health, assume the reviewer is a former federal agent, treat the records request letter as a legal event, and produce a chart that defends itself without you in the room to narrate it. Everything after this is process.
Here is what most operators miss. Commercial payer Special Investigations Units are not staffed by junior claims clerks. Former FBI, HHS-OIG, and State Medicaid Fraud Control Unit personnel move into non-governmental SIUs and carry the same investigative posture with them. That is who reads your PHP notes (ASAM Level 2.5, an outpatient level of care).
The financial exposure is not theoretical. CMS reported that the FY 2024 Medicare Fee-for-Service estimated improper payment rate was 7.66%, or $31.70 billion, alongside a Medicaid improper payment rate of 5.09%, or $31.10 billion. CMS then reported FY 2025 figures showing the Medicare FFS estimated improper payment rate at 6.55%, or $28.83 billion. Commercial payers watch those numbers and calibrate their own audit budgets against them.
On the criminal side, the DOJ announced its 2025 National Health Care Fraud Takedown, which charged 324 defendants, including 96 doctors, nurse practitioners, pharmacists, and other licensed medical professionals, in 50 federal districts and 12 State Attorneys General’s Offices, for their alleged participation in schemes involving over $14.6 billion in intended loss. Behavioral health featured prominently. In Arizona, Farrukh Jarar Ali, 41, of Pakistan, was charged by indictment with conspiracy to commit health care fraud and wire fraud, three counts of wire fraud, and money laundering in connection with an alleged $650 million scheme involving at least 41 substance abuse treatment clinics in Arizona. That case, more than any other in 2025, put SUD operators on payer heat maps in Arizona, Florida, and Ohio.
Know which audit is actually in front of you
Before you pull a single chart, identify what kind of audit you are dealing with. The response is not the same.
- Prepayment audits. The payer holds the claim and asks for documentation before releasing money. Cash flow pressure hits immediately. Your billing team needs to turn records around fast and clean.
- Post-payment audits. The payer already paid, sampled your claims, and is now looking for overpayments. Expect a demand letter, and potentially extrapolation across a much larger universe of claims.
- SIU audits. A different animal entirely. If the letterhead says Special Investigations Unit, this is a fraud investigation, not a routine audit. Bring healthcare counsel in before you send anything.
How do SIUs pick you? Data. Health plan payment integrity teams run analytics that flag claim aberrancies, outlier utilization, and unusual coding frequency compared to peers. If your average length of stay at ASAM Level 3.5 residential sits two standard deviations above your regional peers in Florida, or your UA billing frequency in Ohio looks like an outlier against every other SUD provider in that market, your name is already on a list.
Federal investigators use the same playbook. DOJ analysts and HHS-OIG are pooling more data than ever. DOJ also introduced the creation of a Health Care Fraud Data Fusion Center, designed to enhance the detection, investigation, and prosecution of healthcare fraud. CMS Administrator Mehmet Oz put the posture bluntly in the takedown announcement, noting that CMS is “probably the largest target of all, responsible for about $ 1.7 trillion dollars of disbursements,” and CMS announced that it successfully prevented over $4 billion from being paid in response to false and fraudulent claims and that it suspended or revoked the billing privileges of 205 providers in the months leading up to the Takedown.
The documentation standard: medical necessity, defensible on its face
Reviewers are not reading your chart for narrative flavor. They are reading it to see whether each service billed is supported by contemporaneous documentation that establishes medical necessity at the level of care billed. If your PHP note (ASAM Level 2.5, an outpatient level) reads identically to your residential note, you have a problem before the letter arrives.
Insufficient documentation is not a small error category. It is the error category. CMS is direct about this: “Most improper payments occurred in situations where a reviewer could not determine if a payment was proper because of insufficient documentation from a state, provider, or the Part D Sponsor”. In traditional Medicare specifically, insufficient or no documentation was the most common reason for improper payments, accounting for roughly two-thirds of improper payments. That is not fraud in the criminal sense. Those are charts that could not defend themselves. Commercial payers apply the same logic on recoupment.
Here is what our team at Atlantic Health Strategies looks for on a mock chart audit, in the order it costs operators money:
- Physician or qualified professional signature on the initial assessment, dated on or before the first billed service.
- ASAM Criteria 4th Edition dimensional documentation supporting the specific level of care billed. Do not paraphrase the criteria. Document to them.
- Individualized treatment plans with measurable objectives, signed by the client and the clinician, updated at the intervals required by state licensure and the payer contract.
- Group notes that reflect the individual client’s participation, not a copy-paste roster narrative.
- Utilization management documentation that ties continued stay to clinical progress, not census pressure.
- Drug testing orders that are individualized, not standing orders applied to every client on admission.
If those six items are not clean, no consultant is saving you when the request letter hits the fax line.
The 72 hours after the letter arrives: what to do, what not to do
An audit letter is a legal document with a deadline. Here is the operator playbook.
Log the letter the day it arrives. Identify the requesting department. If it is SIU, retain healthcare counsel before responding to anything. Do not alter, destroy, or “supplement” any records, and do not sign anything, including non-disclosure or confidentiality agreements, without counsel reviewing it first.
Then run the internal steps: pull the exact claims and date ranges requested, no more and no less; log every document you send with a bates-style index; produce records through a secure channel with delivery confirmation; and preserve the metadata. Do not add late entries to notes. If a note is missing, it is missing. Late-entered documentation, when discovered on audit, converts a documentation dispute into a fraud allegation. That is the swing that ends careers.
Your team should build a tracking spreadsheet noting dates, methods of contact, who you spoke with, and what was discussed. When the auditor’s findings letter arrives six months later, that log is what your appeal is built on.
Remember what a payer can actually do. Delayed payments. Recoupment of prior payments. Corrective action plans. Removal from the plan network. The most severe path is a referral to HHS-OIG or the DOJ. That is not the common outcome, but it is on the menu, and the Arizona case is instructive: Ali submitted approximately $650 million in false and fraudulent claims to AHCCCS, and AHCCCS paid approximately $564 million for these false and fraudulent claims before the federal indictment landed.
The compliance program you should have built before the letter
The operators who survive audits without material recoupment share the same operational backbone. Their teams run mock chart audits quarterly, not annually. Their clinical leaders map each payer contract’s utilization management requirements to their EMR templates. Their trainers walk clinicians through ASAM 4th Edition dimensional documentation, not generic “note-writing.” Their compliance leads read the payer’s medical policy for SUD and MH services and rewrite assessment templates against it. And their analysts run an internal SIU-style outlier review on their own billing before a payer runs one for them.
The pressure is structural, not personal. The National Health Care Anti-Fraud Association puts the number this way: “A conservative estimate is 3% of total health care expenditures, while some government and law enforcement agencies place the loss as high as 10% of our annual health outlay, which could mean more than $300 billion.” Payer SIU budgets are justified against that number. When a plan looks at Florida, Arizona, Texas, or Ohio SUD providers with unusual billing curves, the pressure to audit is baked into the payer’s own operating model.
Two closing thoughts for behavioral health operators.
First: your billing company is not your compliance program. A biller who codes what the chart says is doing their job. A compliance program is what makes sure the chart supports what the biller codes. Different function, different accountability, different reporting line.
Second: if you are a PE-backed operator preparing for a transaction, unresolved payer audits and open SIU inquiries are the single fastest way to blow up a quality-of-earnings review. Diligence buyers will find them. Founders and sponsors should clean these before going to market, not after.
Frequently asked questions
What triggers a behavioral health SIU audit?
Outlier billing patterns caught by analytics. Payer SIU tools detect claim aberrancies, over-utilization, and unusual coding frequency compared to peer providers. Common behavioral health triggers include long lengths of stay at residential and PHP levels, high-frequency UA billing, and repetitive group note language across clients. DOJ has expanded that same posture through a Health Care Fraud Data Fusion Center that pools federal analytics across HHS-OIG, FBI, and CMS.
How much of Medicare and Medicaid spending is considered improper, and does that mean fraud?
CMS reported the FY 2024 Medicare Fee-for-Service improper payment rate at 7.66% ($31.70 billion) and the Medicaid rate at 5.09% ($31.10 billion). FY 2025 dropped the Medicare FFS rate to 6.55%, or $28.83 billion. CMS is explicit that improper payments are not the same as fraud; the majority of improper payments arise from insufficient documentation from a state, provider, or Part D sponsor. Practically, that means most recoupment risk comes from charts that cannot defend the service billed, not from criminal intent.
What should I do the day an SIU records request letter arrives?
Identify the requesting department. If it is the SIU, retain healthcare counsel before you produce anything. Do not alter, supplement, or backdate records. Preserve the exact state of the chart, produce only what is requested through a secure channel with delivery confirmation, log every communication, and do not sign any confidentiality or non-disclosure agreement without legal review. Late-entered documentation discovered during audit converts a documentation dispute into a fraud allegation.
How do payer audits affect a behavioral health M&A transaction?
Open audits, active SIU inquiries, and unresolved recoupment demands surface immediately in a quality-of-earnings and compliance diligence review. They reduce purchase price, trigger indemnity holdbacks, or kill deals outright. Founders and PE sponsors preparing for exit should resolve or reserve for these matters well before going to market, and should be able to produce a documented internal audit program showing the issue is contained.
References
- CMS, Fiscal Year 2024 Improper Payments Fact Sheet
- CMS, Fiscal Year 2025 Improper Payments Fact Sheet
- U.S. Department of Justice, 2025 National Health Care Fraud Takedown Announcement
- U.S. Attorney’s Office, District of Arizona: Charges Against 7 Defendants in 2025 Takedown
- HHS-OIG, 2025 National Health Care Fraud Takedown Media Materials
- Healthcare Law Insights, DOJ Launches Health Care Fraud Data Fusion Center (Aug. 2025)
- Epstein Becker Green, The First National Health Care Fraud Takedown of the Second Trump Administration
- National Health Care Anti-Fraud Association, The Challenge of Health Care Fraud