What Your RCM Coding and Billing Audits Might Not be Catching

Revenue cycle teams are, as a rule, very good at regulatory compliance. Coding accuracy, payer rules, billing regulations, audit readiness; this is the core discipline RCM is built around. But this is one strong piece of a larger compliance program that also needs privacy, security, and increasingly AI oversight built in alongside it. Some of the largest recent penalties in healthcare haven't come from coding errors at all, and they've instead come from the data and technology sitting underneath the coding and billing function.

The Data Underneath the Claims

Revenue cycle operations sit on an enormous volume of protected health information — diagnoses, procedures, Social Security numbers, financial and insurance data, often aggregated across every patient a practice or health system touches. That makes RCM systems a natural target for attackers. Comstar, a billing and collections company serving more than seventy ambulance services as a business associate, settled with OCR after a ransomware attack went undetected for a week and exposed the ePHI of roughly 585,000 individuals, with OCR citing a failure to conduct an adequate risk analysis. MMG Fusion, a patient-communication software vendor to dental and healthcare practices, settled with OCR after a data breach affecting approximately 15 million individuals, tied to the same core finding: an inadequate risk analysis and a delay in notifying the covered entities it served.

Both companies were business associates. Both failures traced back to the same root cause: an inadequate risk analysis that went unaddressed until a breach forced the issue. Revenue cycle operations run on this same kind of vendor relationship every day, from clearinghouses and billing platforms to patient communication tools and outsourced collections. That means a defined cadence of vendor risk assessments, documentation of each partner's own risk analysis and security practices, and a clear process for acting when a vendor falls short, not a one-time review filed away and forgotten.

Where AI Fits into the Same Picture

AI has moved into the revenue cycle quickly, such as assisted coding, denial-risk scoring, claim scrubbing, and generated appeal narratives, often built directly into billing platforms rather than adopted as standalone tools. In one of the largest False Claims Act healthcare settlements of the past two years, a hospital system paid $23 million to resolve allegations that its automated coding system defaulted emergency department visits to the highest-reimbursement billing code whenever a patient's vital signs were checked more times than the hours they were in the department. It did this regardless of how severe their condition was or what care they received. The government's position was that the automation was matching codes to reimbursement rather than care, and nobody was checking. A parallel pattern is playing out on the payer side. A major insurer is currently in litigation and facing broad court-ordered discovery over allegations that an AI tool was used to predict and drive post-acute care coverage denials with insufficient physician oversight. This presents the same fundamental allegation of an algorithm making a financially consequential decision with the human review that was supposed to sit on top of it wasn't doing its job.

An AI governance program brings all relevant stakeholders into the same review process, so a coding assistant or a denial-prediction tool gets evaluated by people who can see the full picture, not just the department that adopted it. That program defines what the tool is doing, requires a qualified person to review and be able to override its output before its finalized, and monitors the tool's decisions against outcomes on an ongoing basis to catch drift before a regulator or a whistleblower does. Revenue cycle AI doesn't need a separate governance structure from the rest of the organization. It needs a seat inside the one the organization should already be building.

What Weaving this Together Actually Looks Like

A full RCM compliance program connects billing compliance, privacy, security, and AI oversight into a single coordinated effort rather than parallel ones: current business associate agreements and vendor diligence for every platform and clearinghouse in the chain, a clear picture of where claims data actually flows and who has access to it, security expectations for billing systems and vendors that match the sensitivity of what they hold, and a shared process for evaluating any technology — including AI features — that a vendor adds to the platform. This is additive to the regulatory compliance work already happening, not a replacement for it.

Independent Validation Matters Here Too

Once a program is built, the next question is whether it actually holds up in practice, and that's best answered by someone outside the team that built it. An independent assessment of RCM compliance that looks not just at coding accuracy but at privacy, AI, and other concerns gives organizations a defensible, third-party view of where the program stands before a payer audit, a regulator, or a whistleblower asks the same question first.

CohesiveIQ helps healthcare organizations build full-picture RCM guardrails — connecting billing compliance with privacy, security, and AI governance — and provides independent assessments to validate they hold up. Contact us to talk through where your RCM operation stands.

blogs and articles

Latest insights and trends

The Governance Gap: Why AI Needs a Program, Not Just a Policy

A committee isn't a governance program.

The Attacker Just Got a Co-Pilot: Cybersecurity in the Age of AI

AI didn't break security. It sped up the clock.

The Data You Hold Isn't All Governed the Same Way

HIPAA covers less of your data than you think.

M&A Due Diligence Doesn't Wait for You to Be Ready

Compliance gaps show up in the price, not just the audit.

Why Healthcare Companies Can't Treat State Privacy Law as a One-Time Checkbox

HIPAA compliance isn't privacy compliance anymore.

Why an Independent Assessment of Your Compliance Program Isn't Optional Anymore

DOJ and OIG now expect proof, not paperwork.

Stop retrofitting compliance after the fact.

The earlier you build it in, the cheaper and faster it gets.