13 Common Medical Coding Errors to Avoid in 2026
Common medical coding errors cost billing teams thousands in rework. Learn 13 mistakes to avoid in 2026 and get cleaner claims from the start.

Denial rates keep climbing even after training and audits. Here is why the real error happens before any coder opens the chart, and what it takes to stop fixing the same mistake twice.
Claim denials are one of the most persistent revenue drains in practice management. The common assumption among practice administrators and billing decision-makers is that if they keep training their coders and running periodic audits, they'll eventually get denials under control. Yet denial rates keep climbing, even across practices that are already doing what they were told to do: training coders, running audits, and reviewing payer guidelines. See our AI medical scribe for how this works in practice.
That rise happened across an industry that has spent heavily on corrective programs. The problem isn't effort but visibility into where the errors actually start.

Denials, in other words, are a lagging indicator, and managing them solely at the AR stage is a strategy that guarantees the same errors will repeat in the next billing cycle. They show up in your accounts receivable report, so that is where attention goes. But a denial is an outcome, not a cause.
The cause is almost always a coding error, and coding errors carry a steep operational tax beyond the initial rejection. Reworking a single denied claim costs between $25 and $181.
Multiply that across a practice seeing dozens of denials per month, and the rework burden compounds fast, quarter after quarter, even after "fixes" are applied. Retraining coders addresses coder behavior. Audits catch errors after claims are built. Neither intervention touches the moment when clinical context is actually captured. A practice that retrained its coding staff twice in two years can still see unchanged denial rates if the encounter notes feeding those coders remain incomplete.
"Coding errors are slipping through before claims go out, suggesting a lack of proactive review processes; errors are being caught too late or not at all."
The error was already baked in before the coder opened the chart.
11.81% Initial claim denial rate in 2024
Key takeaways
- Most coding errors don't originate at the billing desk, they're baked in the moment a provider documents a visit under time pressure and clinical context gets lost.
- One ortho group audited its own claims and found a 33% overcoding rate that no one inside the practice had detected, not through training, not through periodic audits.
- Medicare Advantage denials average 15.7% on first pass; commercial payers sit at 13.9%, and those numbers haven't moved despite years of coder training budgets.
- Coder training addresses how codes are selected. It cannot fix what was never written down in the first place.
- The 13 errors covered here, from upcoding and undercoding to missing modifiers and unsupported diagnoses, each trace back to a single upstream failure: incomplete clinical documentation.
- Catching errors before a claim is built requires moving the fix into the exam room, not the billing queue.
- iScribe Health's AI-powered scribing captures clinical encounters in real time, inside your EHR, so the documentation that reaches your coders actually reflects what happened, closing the gap where most of these 13 errors begin.
The Hidden Layer - How Incomplete Documentation Creates Coding Errors Before Anyone Bills a Claim
The common assumption among practice administrators and billing decision-makers is that if they keep training their coders and running periodic audits, they will eventually get denials under control. In reality, coding errors rarely announce themselves at the billing desk. They take shape much earlier, in the exam room, when a provider documents a visit under time pressure and clinical complexity quietly disappears from the record before any coder ever opens the chart. Understanding where that loss happens, and what it costs, is the only way to stop treating the symptom instead of the source.

The 33% Overcoding Rate Nobody in the Building Knew Existed
33% Overcoding rate missed by internal audits
A real-world review of a substantial series of orthopedic encounters surfaced a 33% overcoding rate that internal coders, billing staff, and periodic audits had all missed entirely. That finding aligns with broader research: Albagmi et al. (Saudi Pharmaceutical Journal, 2023) identified systematic miscoding across hospital departments despite standard oversight practices, concluding that periodic audits and coder retraining were insufficient to bring errors under control. The errors persisted not because coders were careless, but because the conditions producing them were never addressed.
That condition is familiar to any high-volume practice: clinicians routinely chart two or more hours outside of patient care time, and the documentation produced under that burden is compressed, incomplete, and stripped of the nuance that accurate E&M coding depends on. iScribe Health's Ambient Listening and Conversational AI captures the encounter as it unfolds, and its Automated E&M Coding intelligence applies at the point of note completion, after the AI drafts the encounter summary, so the coded output reflects what actually happened clinically rather than what a fatigued provider managed to type at the end of a packed schedule. The result is coding consistency across providers that a periodic audit cycle simply cannot manufacture after the fact.
Why Coders Can Only Be as Accurate as the Notes They Receive
The same Albagmi et al. study identified incomplete or inaccurate clinical documentation as the primary root cause of miscoding, placing the origin point upstream of the billing desk entirely. Coders work from what the note says. If a provider documents a visit in four minutes under a packed schedule and omits the clinical complexity that justified a higher-level code, the coder assigns what the record supports.
That is not a coding error. It is a documentation gap that the coder had no way to close. The scale of that gap is larger than most practices recognize.
Research on unstructured clinical data shows that diagnosis codes can capture only a fraction of clinically documented information for certain high-stakes conditions, meaning a significant share of what a provider actually observed and recorded never translates into a coded data point. That is not a billing team failure. It is the predictable outcome of documentation workflows that leave critical clinical detail buried in free-text narrative, invisible to any coding logic applied downstream.
iScribe Health's E&M Coding Intelligence is designed to surface that detail at the moment the note is completed, directly inside the practice's existing EHR, so that the coded claim reflects the full clinical picture rather than the fragment a manual process happened to capture. The goal is defensible documentation, notes that support the code assigned and withstand payer scrutiny, not simply faster documentation.
How Lack of Diagnostic Specificity Silently Inflates Audit Risk
Unspecified diagnosis codes are one of the clearest signals that documentation quality broke down at the encounter level. When a provider documents a condition without laterality, acuity, or clinical context, the coder defaults to an unspecified ICD-10 code, not because they lack skill, but because the record gives them nothing more specific to work with. That unspecified code then becomes the claim's weakest point: payers in 2023 and 2024 have increasingly moved from flagging unspecified codes for review to outright denying them, which means an encounter that was fully legitimate clinically generates a denial rooted entirely in a documentation gap that occurred hours earlier in the exam room.
The documentation pressure behind that gap is real and cumulative. Clinicians drowning in manual charting, routinely spending significant time on documentation that ambient AI can help reclaim, are not omitting laterality or acuity out of indifference. They are omitting it because the documentation environment does not support specificity at the speed the schedule demands.
iScribe Health's Ambient Documentation captures encounter detail in real time, and its Real-Time Denial Alerts flag specificity gaps before a claim is submitted rather than after a denial arrives. For high-volume practices and health systems where clinicians regularly chart two or more hours outside of patient care, that shift from reactive denial management to proactive documentation precision directly impacts revenue at the encounter level, every patient, every day.
Related Reading
- Medical Coding Ai Tools
- What Is Evaluation And Management Coding
- Medical Coding Documentation
- Time-based E&m Coding
13 Common Medical Coding Errors to Avoid, and the Documentation Root Cause Behind Each One
Initial denial rates for Medicare Advantage averaged about 15.7% on the first pass, and commercial payers aren't far behind at roughly 13.9%. Those numbers have stayed stubbornly high despite years of coder training budgets and periodic audit cycles. The reason is straightforward once you see it: most of the 13 errors driving those denials were not created at the billing desk.
They were created the moment a provider's note lost clinical context. The majority of medical group leaders flagged claim denial rates as a significant challenge to their revenue cycle performance in MGMA's Stat polling, and the same report noted that training alone, without systemic process and technology changes, does not move the needle. That finding aligns with what billing teams experience in practice.
A coder working from a thin or vague note is not making a competency error. They are making a documentation-constrained guess. The audit finding and the corrective action are systematically misaligned when the root cause sits upstream.
What follows is a working taxonomy of all 13 errors, grounded in where each one actually starts.
1. Upcoding - Billing a Higher-Complexity E/M Level Than Documentation Supports
Upcoding occurs when a claim reflects a higher-complexity evaluation and management level than the clinical note can actually justify. This is the error with the steepest legal exposure: the Department of Justice has secured substantial False Claims Act settlements from practices that consistently billed higher-complexity E/M codes against notes that documented only lower-level complexity. The documentation root cause is almost always a provider note that lists a problem without capturing the decision-making complexity, time, or data review that would support the higher level. Coders who receive a note showing "reviewed labs, adjusted medication" with no further detail face a binary choice: undercode or guess upward.
2. Undercoding - Choosing a Lower E/M Level to Avoid Audit Scrutiny
Undercoding is the mirror problem, and it is far more common than most administrators realize. Coders who have absorbed the institutional anxiety around upcoding audits routinely default to lower E/M levels even when documentation would support a higher one. The revenue loss is invisible because no payer flags it and no audit catches it. Billing teams often describe this as the safer path, but a practice leaving a legitimate higher-level E/M code on the table across a high volume of encounters per month is quietly bleeding significant revenue annually. The fix is not courage at the billing desk; it is documentation specific enough that the correct level is unambiguous.
3. Unbundling - Reporting Component Codes Separately When a Comprehensive Code Exists
Unbundling is billing separate CPT codes for individual components of a service that should be reported under a single comprehensive code, and the Centers for Medicare & Medicaid Services (CMS) treats it as a form of fraud. A common example is reporting each element of a blood test panel as a separate line item when a single panel CPT code covers all components. The National Correct Coding Initiative (NCCI) edits exist specifically to catch this, and they fire automatically at the payer level. NCCI edit violations are a consistent driver of automated claim rejections. The documentation origin is a procedure note that lists individual components without signaling the clinical context that would make a bundled code obvious.
4. Missing or Incorrect Modifiers - Omitting Laterality, Distinct Procedural Service, or Bilateral Indicators
Modifier misuse is one of the most reliably frustrating sources of denials for billing teams because the underlying service was real and the code was correct, but the claim still fails. Modifier 25 and Modifier 59 are the two most frequently cited culprits. Modifier 25 requires documentation that a separately identifiable evaluation and management service occurred on the same day as a procedure; without a note that clearly separates the two, the modifier is indefensible. Modifier 59 requires evidence that two procedures were genuinely distinct. When the clinical note does not capture that distinction, the modifier becomes an unsupported assertion that payers reject on review.
5. Using Unspecified ICD-10 Codes When a More Specific Code Is Available
Unspecified ICD-10 codes are not placeholders; payers increasingly treat them as documentation failures. Coding asthma as J45.9 (unspecified) when the clinical note contains enough information to support J45.51 (severe persistent asthma with acute exacerbation) is a specificity error that payers have begun rejecting outright rather than simply flagging for review. The golden rule of coding applies directly here: if it is not documented, it did not happen. When a provider's note says "asthma, doing poorly" without capturing severity, persistence, or exacerbation status, the coder cannot assign a specific code regardless of what the provider actually observed in the room.
6. Diagnosis-to-Procedure Mismatch - ICD-10 Code Does Not Justify the CPT Billed
A diagnosis-to-procedure mismatch occurs when the ICD-10 code on the claim does not establish medical necessity for the CPT code billed alongside it. Payers use automated logic to cross-reference these pairings, and a mismatch triggers an immediate denial. The documentation root cause is almost always a note where the provider documented a finding but did not connect it explicitly to the clinical decision to order or perform the procedure.
Coders are not clinicians; they cannot infer the connection the provider understood but did not write. What is missing is visibility into the clinical reasoning that justified the service.
7. Duplicate Billing - Submitting the Same Service Twice Across Claims or Dates
Duplicate billing typically surfaces when a claim is temporarily denied and then resubmitted without confirming whether the original was eventually processed. It also occurs when the same service appears on both a professional and institutional claim, or when a service is entered twice in the practice management system on the same date. This error is largely a workflow and systems problem, but incomplete documentation of service dates and encounter identifiers makes it harder to catch before submission. Payers flag duplicates automatically, and repeated instances attract compliance scrutiny beyond the individual denial.
8. Incorrect Place-of-Service Code - Billing Office Setting When Service Was Rendered in a Facility
Place-of-service codes directly affect reimbursement rates because CMS pays differently for the same procedure depending on where it was performed. Billing a service with a place-of-service code for an office setting when the service was actually rendered in a hospital outpatient department or ambulatory surgery center is both a compliance error and a reimbursement calculation error. The documentation origin is often an encounter note that does not clearly record the physical location of the service, leaving the billing team to assume based on the provider's usual practice pattern rather than the actual encounter record.
9. Coding from the Superbill Alone - Ignoring the Clinical Note for Specificity
The superbill is a shortcut that was designed for speed, not accuracy. When a coder assigns codes based solely on the superbill checkbox without reading the clinical note, specificity is lost at the point of translation. Providers or administrators who have worked in high-volume practices know this pattern well: the superbill says "diabetes," the note says "type 2 diabetes with diabetic chronic kidney disease, stage 3."
Those are not the same code. Coding from the superbill alone is the fastest path to unspecified ICD-10 codes, diagnosis-to-procedure mismatches, and missed comorbidities, all in a single encounter. The note is the record of what actually happened; the superbill is a summary that was never designed to carry that weight alone.
10. Failure to Code All Documented Conditions - Leaving Comorbidities Off the Claim
Outpatient coding guidelines are clear that coders should report all conditions that affect patient management during the encounter, including comorbidities that influence clinical decision-making. Leaving a documented condition off the claim understates the complexity of the encounter and, in value-based and risk-adjusted payment models, directly reduces the practice's attributed risk score and reimbursement. The documentation failure here is a provider note that mentions a condition in passing without connecting it to the management decisions made during the visit, giving the coder no clear signal that the condition is clinically relevant to the encounter.
11. Global Surgery Period Violations - Billing Separately for Services Included in the Surgical Package
CMS defines a global surgery package that includes pre-operative, intra-operative, and post-operative services within a specified period. Billing separately for services that fall inside the global period is a common CPT coding mistake that payers catch through automated edits. The documentation problem is a post-operative note that records a service without indicating whether it represents a new problem, an unrelated condition, or a complication, all of which can justify a separate charge. Without that clinical context in the note, the coder cannot support the modifier needed to break out of the global package, and the claim is denied.
12. Time-Based Coding Errors - Claiming Prolonged Service Time Without a Documented Start-and-Stop Record
The 2021 E/M guideline revisions made time a standalone basis for E/M level selection, which opened a legitimate coding pathway but also introduced a new and growing source of errors. Post-2021 audit findings from AAPC and CMS have identified time-based claims where the documentation shows a total time notation but no start-and-stop record, no breakdown of time spent on care coordination versus face-to-face contact, or time entries that do not align with the complexity of the note itself. A total-time notation without supporting context does not satisfy the documentation standard, and payers are increasingly sophisticated about identifying the gap.
13. Incorrect Revenue Codes on Institutional Claims - Facility Billing Mismatches That Trigger Technical Denials
Revenue codes on UB-04 institutional claims must align precisely with the services described in the clinical documentation and with the corresponding HCPCS codes on the same claim. A mismatch, such as a revenue code indicating a medical/surgical supply when the documentation supports a pharmacy charge, triggers a technical denial that has nothing to do with medical necessity or coding specificity. These errors are most common in facility billing environments where clinical documentation and charge capture happen in separate systems with limited cross-referencing.
The fix requires both accurate documentation at the encounter level and a charge capture workflow that maps clinical services to revenue codes without manual interpretation gaps. Most practices handle this pattern by investing in coder education after a denial spike, which addresses the symptom without reaching the source. The hidden cost is that every audit cycle is reviewing errors that were already baked into the documentation before the coder ever opened the encounter.
When AI-powered scribing captures the full clinical narrative in real time at the point of care, including severity indicators, time documentation, comorbidities, and procedure-to-diagnosis linkage, the documentation root cause behind errors like upcoding, unspecified ICD-10 codes, time-based coding gaps, and diagnosis-to-procedure mismatches is addressed before it ever reaches the coder's queue. In the real-world orthopedic encounter review referenced earlier in this article, the 33% overcoding rate identified was traced entirely to documentation gaps at the encounter level, the exact upstream point where ambient AI capture intervenes. That turns a reactive denial-management workflow into a proactive documentation-quality system.
The documentation quality gains are most pronounced in high-volume clinical settings where providers are routinely managing a large number of encounters per day and encounter complexity is the detail most likely to be abbreviated under time pressure.
Recognizing all 13 errors is the diagnostic step, but recognition alone does not stop the next denial from hitting your AR. The next section breaks down three prevention strategies that actually work, starting not at the billing desk but at the moment the encounter note is written.
Related Reading
- Orthopedic Coding Guidelines
- E&m Coding Cheat Sheet
- Medical Coding Automation
- Orthopedic Medical Coding
- Urology Coding Guidelines
How to Avoid Medical Coding Errors - Two Prevention Strategies That Actually Work
Catching errors at the point of documentation rather than at the billing desk requires a structured audit process built around the same 13 error categories identified above. Pre-bill audits, real-time EHR alerts, and coder-clinician feedback loops each target a different stage of the revenue cycle, but they share a single operating principle: the further upstream an error is caught, the lower its cost to the practice in both dollars and administrative time.
Prevention starts well before a claim reaches the payer. Most practice administrators already know the three core levers: run audits, train coders on annual code updates, and tighten documentation at the encounter. The harder truth is that each lever has a structural ceiling, and understanding where each one stops working is what separates practices that hold the line on denials from those that keep retraining the same coders on the same errors.

Regular Coding Audits - Catching Errors in Arrears vs. Continuous Review
Regular coding audits are a necessary baseline. AAPC and AHIMA both recommend a minimum quarterly audit cadence for most practices, with higher-risk specialties auditing monthly. The problem is structural, not procedural.
This is not a theoretical risk. CPT and ICD-10-CM coding errors in outpatient physician documentation are a recognized, persistent pre-submission problem. Practices know errors are entering the claim stream before claims go out and still lack a consistent mechanism to intercept them at the encounter level. When you factor in the significant lag between claim submission and denial surfacing, a quarterly audit is effectively reviewing documentation failures from prior billing cycles, meaning organizations are measuring revenue damage that compounded across the interim while the correction loop was still completing.
Resubmission windows are closing and the revenue is already delayed before the audit even surfaces the error. A practice that shifts from quarterly chart reviews to continuous, encounter-level review catches errors in the same week they occur rather than 90 days later, breaking the compounding erosion that arrears-based auditing cannot interrupt. This is precisely where iScribe Health's architecture changes the equation.
Because iScribe Health's Ambient AI Documentation and E&M Coding Intelligence operate at the point of note completion, after the AI drafts the encounter summary and before the claim is assembled, E&M coding decisions surface in real time inside the clinician's existing EHR workflow rather than weeks later in a denial queue. The Real-Time Denial Alerts layer adds a downstream safety net, but the more consequential intervention happens earlier: the AI flags coding issues while the encounter context is still fresh and the physician is still present, converting what would have been an arrears-discovered error into an encounter-level correction. For high-volume practices where clinicians regularly chart two or more hours outside of patient care, this shift also reduces the after-hours documentation burden, the "pajama time" that compounds both physician burnout and documentation quality, because the AI drafts the encounter summary during the visit itself, leaving less incomplete or rushed documentation to generate downstream coding risk.
Annual Code-Update Training Tied to Real Encounter Patterns
Generic annual training is not enough. ICD-10-CM codes are updated every October by CMS, and HCPCS codes change quarterly. Using outdated or incorrect code sets is one of the most consistent drivers of front-end claim rejections, and a one-time annual training session cannot keep pace with that update frequency.
Practices that tie training to real encounter patterns, pulling examples from their own denied claims by error type and mapping them to the specific code changes that drove the denial, consistently outperform those that rely on generic vendor-led update webinars. The format matters less than the specificity: coders who see the connection between a real encounter in their specialty and a newly active code retain and apply it; coders who sit through a slide deck covering every specialty equally do not. iScribe Health's Automated E&M Coding and AI Customization features reinforce this principle operationally rather than pedagogically.
Because the system is integrated directly with the practice's supported EHR and is continuously applied across every patient encounter, the coding logic it surfaces reflects the actual code sets in use at that moment, not a training slide prepared months before an October update cycle. Clinicians and coders reviewing AI-assisted coding suggestions at the point of note completion are, in effect, seeing current code application against real encounters in their own specialty, which is exactly the encounter-pattern specificity that makes training stick. The ongoing, per-encounter nature of iScribe Health's deployment means code-update exposure is not a once-a-year event but a continuous, embedded part of daily clinical practice.
Next steps
If your denial rates have stayed stubbornly high despite audits and coder retraining, the path forward starts with addressing documentation quality at the point of care, before the claim is ever assembled. Start with our AI medical scribe.
The evidence from the body of this article makes the sequence plain. Denial rates climbed to 11.81% in 2024 precisely during periods of increased audit and training investment, which means the control points being optimized are structurally disconnected from the root cause. At the same time, periodic audits operate in arrears on records that were already deficient before submission, with a 60 to 120 day lag that turns every correction cycle into a review of revenue damage that has already compounded. Together, those two realities point to one action: close the documentation gap at the encounter level, in real time, rather than chasing its consequences through the billing cycle.
Start with iScribe Health. The ambient documentation captures the full clinical narrative during the visit, and the automated E&M coding intelligence surfaces coding decisions at the point of note completion, while the encounter context is still fresh and the provider is still present. The result is charts that arrive at the billing desk with the specificity, laterality, comorbidity detail, and diagnosis-to-procedure linkage that accurate code selection depends on. That is not a faster version of the same workflow. It is the upstream intervention that periodic audits and annual training were never designed to be.
Frequently Asked Questions
Why do we keep seeing the same denial rates even after we've retrained our coders multiple times?
Retraining coders addresses coder behavior, but it never touches the moment when clinical context is actually captured. If the encounter notes feeding your coders are incomplete, the error is already baked in before the coder opens the chart, meaning unchanged denial rates are the predictable result even after multiple rounds of training.
What's the real difference between upcoding and undercoding, and which one is more common?
Upcoding means billing a higher-complexity E/M level than the documentation supports and carries significant False Claims Act legal exposure. Undercoding, defaulting to a lower E/M level out of audit anxiety, is actually far more common, and the revenue loss is invisible because no payer flags it and no audit catches it.
How does a wrong or missing modifier cause a denial when the procedure code itself was correct?
Modifiers like Modifier 25 and Modifier 59 require the clinical note to explicitly support their use, Modifier 25 needs clear documentation that a separately identifiable E/M service occurred on the same day as a procedure, and Modifier 59 needs evidence that two procedures were genuinely distinct. When the note doesn't capture those distinctions, the modifier becomes an unsupported assertion that payers reject on review, even if the underlying procedure code was accurate.
If my provider documents a diagnosis and orders a procedure, why would the claim still get denied for a mismatch?
Payers use automated logic to cross-reference ICD-10 and CPT pairings, and a denial fires when the diagnosis code doesn't explicitly establish medical necessity for the procedure billed. The root cause is almost always a note where the provider documented a finding but didn't connect it in writing to the clinical decision to order or perform the procedure, coders cannot infer reasoning the provider understood but didn't write.
Can duplicate billing really happen by accident, and how does it typically start?
Yes, duplicate billing most commonly occurs when a temporarily denied claim is resubmitted without confirming whether the original was eventually processed, or when the same service is entered twice in the practice management system on the same date. Incomplete documentation of service dates and encounter identifiers makes it harder to catch these instances before submission, and repeated occurrences attract compliance scrutiny beyond the individual denial.
