Blog

Health Plan Audits Are the Most Underestimated Business Risk for Most Virtual Care Companies

Health plan audits have shifted from random checks to continuous, data-driven monitoring — it's a matter of when, not if, you will be audited. In this post, we break down the five rationalizations putting virtual care companies at risk, and the three flags that trigger most audits.

By
Megan Struxness - Head of Payer Ops & Revenue Cycle Management
Created
August 19, 2026
Updated

Executive Summary

  • Massive financial recoupments. Loss of a key contract. A sudden stoppage of incoming revenue. Finding yourself on the wrong side of a health plan audit can have a devastating impact on your business, but most virtual care founders underrate health plan audit risk. Audits have shifted from random sampling to targeted, continuous, data-driven monitoring, and the more success you have inside a plan's population, the higher your odds of being audited. Health plan audits are a question of when, not if.
  • The consequences compound fast. Plans can claw back up to three years of payments, mandate corrective action plans, expand reviews across states and specialties, terminate your contract, and refer serious findings to payer SIUs or federal regulators. One audit can consume weeks of your team's time and, at worst, unravel your entire business.
  • Three flags trigger most of the audits we see: poor documentation, excessive Level 5 coding, and incident-to billing stretched beyond CMS rules. Bridge keeps partners audit-ready with chart audits, clinical audits, proprietary AI review on 100% of claims, and manual spot checks, which is how we hold a 96%+ paid rate and a perfect audit response record.

Intro

Massive financial recoupments. Loss of a key contract. A sudden stoppage of incoming revenue. Finding yourself on the wrong side of a health plan audit can have a devastating impact on your business. This is a risk most virtual care founders underrate.


Many virtual care companies seriously underestimate both the probability and the potential penalties of a health plan audit. They treat audit risks like a check engine light in a car. If revenue keeps rolling in, and the business keeps moving, it’s full speed ahead. Nothing appears to be broken. But with every mile driven, the eventual repair only gets more expensive. As do the chances the vehicle stops working altogether.


Audits are becoming increasingly targeted, continuous, and data-driven. Health plans are relying less on random sampling and more on technology to identify which providers deserve closer scrutiny. The more success you have within a certain health plan’s population, the higher your risk of being audited.


The time required when an auditor comes calling ranges from a few dozen charts and 20+ hours of staff time to hundreds of records and hundreds of hours required by your team. The ramifications of an audit can range from a slap on the wrist to millions of dollars in recoupments to the health plan, a loss of that contract, and the involvement of state or federal regulators and law enforcement.


Health plan audit risks are not fun to discuss or plan for, and neither is investing in compliance systems and processes. But the risks are real. And they can crush your virtual care company.


The table below summarizes the most likely consequences and business impacts stemming from poor performance during a health plan audit. The time and money losses will be specific to your case. But they both will add up quickly.

Potential Consequence Business Impact
Financial Recoupments Repayment of claims, payment offsets, and delayed reimbursement can create significant cash flow pressure.
Corrective Action Plan Mandatory remediation, reporting, and ongoing payer oversight consume leadership time and operational resources.
Expanded Audit Activity Findings often lead to broader reviews across additional providers, specialties, states, or historical claims.
Network Termination Loss of in-network status can materially impact revenue, patient access, and future growth.
Regulatory Escalation Serious findings may be referred to payer SIUs or government agencies for further investigation.
Reputational Damage Adverse audit findings can strain payer relationships, slow contracting, and undermine confidence among investors and partners.

Five rationalizations putting virtual care companies at risk

We talk to a lot of virtual care founders regularly. Many of them are considering whether to partner with Bridge to scale their insurance operations. Through these conversations, we have heard several lines of faulty logic as it pertains to health plan audits. Here are the top five:

1. The chances of us getting audited are really small.

Health plans have audit requirements they must fulfill. They also are constantly monitoring claims data to identify potential fraud, abuse, or errors. So it’s a matter of when, not if, you will be audited. If you’re not being diligent about your billing practices, that reprieve is actually a bad thing. It gives you more time for bad habits to cement, and for poor processes to create a closet full of skeletons.

2. We have an RCM vendor, so they have our back.

RCM vendors simply process claims and get you paid. They have minimal accountability or responsibility for helping you avoid an audit, or to ensure you perform well if an audit occurs. It’s not their health plan contracts at risk. Outsourcing RCM does little to protect you.

3. We’ve been billing this way for a while and getting paid.

With any risky behavior, the more you do it the less risky it feels. It doesn’t really matter if you are intentionally billing a health plan incorrectly as a revenue strategy, or if you simply know your processes and procedures probably aren’t as good as they should be. The more “bad claims” you send, the more chances you take. You can quickly go from “seems to be working fine” to “we have a big problem” at any moment.

4. We’ve received some denials, but the claims were processed. Our documentation must be good enough.

Many times, your responses to initial denials of medical necessity will be evaluated by a claims team. They are not reviewed from the perspective of a clinical auditor. While you might have lucked out with your initial requests, and slipped through a few faulty claims, this doesn’t reduce your audit risk. Think about someone who is much more rigorous reviewing 150 of your claims. That should make you much less comfortable.

5.  Audits aren't a big deal.

Some providers view a potential health plan audit as inconsequential. Not all that serious. The reality is it can wreck your entire model. A full audit will eat up multiple weeks and countless hours from your team, distracting you from your day-to-day business.

And the consequences can be incredibly damaging. Based on your audit findings, a health plan can terminate your contract, blacklist you, and claw back past payments (most health plan contracts have up to three years to recoup payments). You can also be subject to civil penalties depending on the findings.

Common audit flags that can cripple your business

While there are many risky behaviors that either trigger an audit, or seal your fate if (and when) you are audited, below are the most common misfires we see from virtual care companies.

Poor Documentation

Audit flag: Incomplete or missing documentation submitted upon request for proof of medical necessity.

The details:

The CMS mantra: If it isn't documented, it didn't happen. High quality documentation is a mandate. Following proper structure while capturing all the right components for each visit type should always be a priority. Because, when submitting a claim, you are attesting in good faith that you have documentation to support it.

A lot of companies don't invest in documentation upfront. They don't set the processes, standards, and quality control early. They don't have a formal coding team, and every provider invents their own version of documentation best practices.

When you're starting out, low volume can keep you under the radar. But as you grow, so will the inconsistency of your data, and that's where the risk compounds. When a health plan pushes back with a denial for medical necessity and your documentation is determined to be lacking, a full blown audit is likely in your future. At best, you'll hand a lot of money back to the health plan. At worst, you'll trip a fraud alert, lose the money, the health plan's trust, AND ultimately, your contract.

Excessive Level 5 coding

Audit flag: Higher-than-expected rates of Level 5 E/M billing compared with specialty and peer benchmarks.

The details:

You have to be careful when billing for patients at the highest level of care. If you do it so often you rise above expected benchmarks, you'll draw attention from the health plan. If you don't have clear stories to support each of your Level 5 encounters, you've written your own ending.

When your Level 5 visits come under scrutiny, you need to have proper documentation of what happened during the visit. You have to show the provider took on the risk of medical decision-making: what assessments were made, what testing was ordered or reviewed, what treatments were prescribed, and what follow ups were administered. It's not as simple as scoring a patient as a Level 5 simply because the provider thinks they meet certain criteria. A medically complex patient does not automatically justify Level 5 billing.

Incident-to billing issues

Audit flag: High incidence of billing MD rates for lower-level providers, particularly as a strategy for covering network gaps.

The details:

It's easy to find yourself misinterpreting incident-to billing rules, even though CMS has provided very specific scenarios on when it is appropriate. We have encountered organizations attempting to stretch incident-to billing beyond its intended purpose. For example, using a single enrolled physician as the billing provider for care delivered by multiple non-physician clinicians to address network coverage gaps. This is not compliant. If you are out of bounds with incident-to billing, you may be getting claims covered now, but you are at high risk of a recoupment and losing your contract when an audit occurs.

Is the severity of a looming audit sinking in? If so, here are your next steps:

  1. Reframe and assume you will be audited. Expect it. This is the mindset.
  2. Pressure test your visit documentation. Can you consistently read your chart notes and have a complete view of what happened during that patient encounter?
  3. Take an honest look at your coding and billing practices. Use this article as a guide for understanding some of the biggest risks you're bearing.
  4. Determine your go-forward strategy. How will you improve? What's the roadmap to lower your exposure?

It's when, not if. The only real question is whether you're ready when it happens.

You may also like

Blog
Oct 16th, 2025

Inside the mind of a health plan— what they really care about when contracting for virtual care

If you’re building for patients, you’re missing the point. Telehealth only scales when it’s built for health plans. Here’s what payers actually care about and how the best virtual care companies win their trust.

Blog
Mar 23rd, 2026

Why Bridge is a charting stickler

Most virtual care companies treat charting as a checkbox. Bridge treats it as the foundation of trust. Rigorous audits turn documentation into proof of quality, improving care, earning payer confidence, and unlocking coverage at scale.

Blog
Dec 30th, 2025

Designing Care That Delights Patients and Gets Reimbursed

A case study on Neura Health’s journey from value-based ambition to a scalable fee-for-service model by using relationships, memberships, and better visit design to drive outcomes. Learn how removing insurance infrastructure bottlenecks with Bridge helped Neura double covered lives in just 30 days.

Blog
Jul 18th, 2025

Build vs. Partner: A Strategic Guide to Scaling Commercial Insurance for Virtual Care

Speed, scale, or control? A decision-making guide for virtual care leaders navigating commercial insurance expansion.