It usually arrives as a letter. Sometimes a fax, sometimes a portal notification you almost miss. An insurer — or a Medicaid integrity contractor, or a licensing board — wants to see your records for a list of clients and dates of service. You have thirty days, sometimes fewer.
Nothing about your care was wrong. But that's not what's being tested.
What's being tested is your documentation. And in an audit, the rule is brutal and simple: if it wasn't documented, it didn't happen — and if it was documented but can be quietly rewritten, it barely counts as documentation at all.
This post is about what actually happens in a therapist audit, why they're increasing, what reviewers really look for, and how to run a practice where the audit letter is an afternoon of exporting files instead of a months-long crisis.
Audits are rising — and they're increasingly algorithmic
For years, audits felt like something that happened to other practices. That's changed.
Commercial payers and public programs have sharply increased scrutiny of behavioral health claims since the pandemic-era telehealth surge — retroactively reviewing the flood of remote-session claims, tightening utilization management, and running automated flags on high-volume CPT codes. The American Psychological Association has documented how insurers audit services after the fact — sometimes years later — and may demand back tens of thousands of dollars if care is deemed not medically necessary. Solo practitioners and small practices, who deliver much of the country's mental health care, often don't have the reserves to absorb a major clawback.
It's not humans picking your file out of a cabinet, either. Reporting by ProPublica (covered in the APA's analysis above) found that one major insurer used an algorithm to flag therapists with "atypical" practice patterns — like frequent sessions — for review, a practice regulators in multiple states found violated mental health parity law. The flag finds you; a reviewer follows.
Common triggers reviewers and billing experts consistently cite:
- Heavy use of 90837 (the 53+ minute session code) without documented justification for the longer session
- More than one session per week without documented medical necessity
- An adjustment-disorder diagnosis lingering past six months
- Cloned notes — copy-pasted or template-filled notes that read identically session to session
- Implausible daily volume — more billed minutes than the day holds
None of these are proof of anything. All of them get letters sent.
How the math of a clawback works
Here's the part most therapists don't learn until they're inside one.
An audit is typically scored pass/fail per chart, with a passing threshold around 80%. Score below it, and the insurer issues a recoupment — a demand to repay. And they rarely stop at the charts they actually read. Through sampling and extrapolation, the error rate found in a small sample is applied to every claim you submitted over the look-back window. Ten flawed notes can become a five-figure demand.
The look-back window is longer than most people assume: commonly 12–24 months for commercial plans, and up to five or six years for Medicare and Medicaid where error or fraud is suspected. Appeal windows, by contrast, are short — often 30–60 days for commercial payers — and many recoupments are reduced or overturned on appeal, precisely because the underlying care was fine and the problem was fixable documentation.
Which brings us to the most important fact in this entire topic:
Most clawbacks stem from documentation gaps, not inappropriate care.
Read that again. Therapists mostly don't lose audits because they treated someone badly. They lose because the paper trail couldn't prove the care was necessary, delivered as billed, and recorded before — not after — the letter arrived.
What auditors actually check
Four things, over and over.
1. The golden thread
Auditors look for a continuous clinical logic: the assessment defines the problem → the treatment plan sets measurable goals and interventions → each progress note shows the intervention delivered and the client's response, tied back to those goals → plan reviews (typically every 90 days) update the story. That chain is called the golden thread, and it's the evidence of medical necessity.
A note can be beautifully written and still fail — because it doesn't connect to any plan goal. When the thread breaks, treatment reads as continuing indefinitely with no demonstrated direction, which is the working definition of "not medically necessary."
2. Time and code accuracy
If you billed 90837, the note needs to support a 53+ minute psychotherapy session — and the extra time needs a reason. Reviewers clock your documentation against your codes. Rounding up isn't a gray area; it's treated as billing for services not rendered.
3. Specificity, not vibes
"Client continues to make progress" is a liability. "Panic attacks reduced from 4/week to 1/week against Goal 2; continued avoidance of driving supports ongoing treatment" survives review. Vague notes cluster in failed audits.
4. Record integrity — the part almost nobody thinks about
Here's the quiet one. When a chart is pulled — by an auditor, a licensing board, or a subpoena — a threshold question is whether the record is trustworthy: who wrote it, when, whether it was signed, and whether it was changed after the fact. A record that can be silently edited after you learn you're being audited is worth very little as evidence — and editing records after an audit notice is the single fastest way to turn a billing dispute into a fraud allegation. The correct mechanism is an amendment: a dated addition with a stated reason, preserving the original. Auditors know the difference. So do boards.
Designing a practice that's ready before the letter
You can treat audit-readiness as a quarterly chore — self-audit your charts, re-check your plan review dates, tighten your note language. You should. But the deeper fix is structural: use systems where good documentation is the byproduct of doing the work, not a second job after it.
This is the problem Mirova was built around. Here's what that looks like concretely — and honestly.
Notes are drafted while the session is fresh. Record a session and Mirova drafts the SOAP note with suggested ICD-10 codes and CPT codes assigned from actual session duration — so the time your note reflects is the time that happened, not a reconstruction at 9pm on Friday. You review, edit, and sign. The clinician always confirms; the AI never signs anything.
Signing means something. When you sign a note, it locks. It cannot be silently edited afterward — by anyone. Every change before signing is versioned with who made it and when, and the record distinguishes what the AI drafted from what the human wrote. After signing, changes happen the way auditors expect: as amendments, with a required reason, preserving the original. That's the integrity story an auditor is checking for, built into the software's spine rather than your willpower.
The golden thread is scaffolded, not remembered. Treatment plans carry 90-day review cycles so the plan-review cadence payers expect doesn't depend on a calendar reminder you set eight months ago. Every note carries an audit-readiness score — a running answer to "would this chart survive review?" while you can still fix it, instead of a verdict after the letter arrives.
Necessity has evidence behind it. This one is unique to how Mirova works: clients leave voice reflections between sessions, and the platform surfaces patterns, early signals, and week-over-week trends. When you document why treatment continues — ongoing impairment, incomplete skill integration, symptom recurrence — you're drawing on observed clinical signal from the client's actual week, not reconstructing it from memory. Medical necessity stops being an adjective and starts being a record.
The response to the letter is an export, not an excavation. When records are requested, Mirova produces a client's complete file in one export: a cover page with provider credentials, every signed note as a PDF, treatment plans, and the audit trail. Thirty-day deadline; one afternoon.
And because it's us: the honest caveat. No software makes you unauditable — the flags are the payer's, and clinical judgment in the note is always yours. What software can do is make the failure mode — undocumented, unsigned, unlinked, retroactively edited records — structurally hard to fall into. That's the job.
A short self-audit you can run this week
- Pull three recent charts at random. Can a stranger trace assessment → plan goal → note → plan review without help?
- Check your 90837s. Does each note support 53+ minutes and say why the longer session was needed?
- Find your last treatment plan review date for each active client. Inside 90 days?
- Search your notes for "continues to make progress." Replace every instance with a measurable statement.
- Ask the uncomfortable question: if you had to prove a note hasn't changed since the session date, could you?
If item 5 made you pause, that's the one worth fixing first — it's the one you can't fix retroactively.
FAQ
What triggers an insurance audit of a therapist?
Common triggers include frequent use of 90837 without documented justification, more than one session per week without documented necessity, adjustment-disorder diagnoses used beyond six months, cloned or templated notes, and volume patterns flagged by payer algorithms. A trigger isn't an accusation — but it starts a review.
How far back can an audit go?
Typically 12–24 months for commercial payers, and up to five or six years for Medicare and Medicaid where error or fraud is suspected. Appeal windows after a recoupment notice are much shorter — often 30–60 days for commercial plans.
What is a clawback or recoupment?
A demand to repay the insurer for previously paid claims after a post-payment review. Audits are commonly scored pass/fail around an 80% threshold, and error rates from a sample can be extrapolated across all claims in the look-back period — which is how small documentation issues become large dollar amounts.
Can I fix my notes after receiving an audit notice?
Never by editing them. Altering records after notice can convert a documentation dispute into a fraud allegation. The legitimate path is a formal amendment — dated, with a stated reason, preserving the original. Mirova enforces exactly this: signed notes lock, and post-signature changes are amendments with required reasons.
How does Mirova help with insurance audits?
Notes are drafted from the actual session with CPT codes tied to real duration, signed notes lock against silent edits, every version and amendment is preserved with who/when/why, treatment plans carry 90-day review cycles, each note gets an audit-readiness score, and a complete client file — signed notes, plans, and audit trail — exports in one click.
Be ready before the letter exists
The practices that survive audits calmly aren't lucky — their records were built defensible from day one, as a side effect of how they work.
Start a free 14-day trial — no card required — and see what a signed, versioned, export-ready chart feels like. Or book a demo and we'll walk through the audit export with your practice's real workflow in mind.
This article is general information, not legal or billing advice. Audit procedures, look-back windows, and appeal deadlines vary by payer, plan, and state — consult a healthcare attorney or billing specialist for a specific notice, especially where fraud is alleged or the amount is substantial.