The line: documentation that supports vs documentation that launders
Summary
Aggressive coding becomes fraud at the documentation line: billing the highest level your note genuinely supports is lawful; billing a level the note does not support is a false claim. Under the current framework, an office-visit level is set by medical decision-making or total time, and the record must show it. The False Claims Act punishes not just lies but reckless disregard, so 'I didn't realize' is not a defense — the note is.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
When does aggressive coding cross into fraud?
Aggressive coding crosses into fraud at one line: whether the documentation supports the code. Selecting the highest level your note genuinely justifies is lawful and expected. Billing a level the note does not support is a false claim, whatever you call it internally. The False Claims Act does not require a provable lie — it reaches reckless disregard for whether a claim is true, so sloppiness is not a safe harbor 1Ref 1U.S. Department of Justice (2026).The False Claims Act.That the False Claims Act reaches knowingly false claims including reckless disregard, with treble damages, per-claim penalties, and qui tam suits..
upcoding is the shorthand for billing a higher-paying code than the encounter supports. It is not a gray-area strategy with a compliant version; it is the thing the fraud statutes are built to catch. The reason the record matters so much is that the record is the evidence. In an audit or an FCA case, the question is never what you meant — it is whether the note, standing alone, shows the service and the complexity you billed. Penalties run to treble damages plus a penalty for each claim, so a small per-visit overcode multiplied across a panel becomes a large number quickly.
What 'supported' means under the current E/M framework
'Supported' has a precise meaning for office and outpatient visits. The visit level is chosen by medical decision-making or by total time on the date of the encounter, and the record must document whichever you used 2Ref 2Centers for Medicare & Medicaid Services (2023).Evaluation and Management Services Guide.That office-visit levels are selected by medical decision-making or total time and what must be documented to support the level.. Since the 2021 revisions, history and exam no longer set the level 3Ref 3American Medical Association (2023).CPT evaluation and management (E/M) revisions.That the 2021 E/M revisions removed history and exam as level-setting elements in favor of medical decision-making or total time.. So an auditor's question is narrow: does the note show the decision-making complexity, or the time, that the billed level requires?
That shift is often misread as license. If history and exam no longer drive the level, some clinicians reason, then a long checklist review of systems is free padding. It is the opposite: padding that does not reflect real decision-making or real time is exactly the pattern that reads as manufactured. The defensible habit is to document the number and complexity of problems addressed, the data reviewed, and the risk of the management chosen — the elements the medical-decision-making table actually scores — or to record start-and-stop time honestly and code to it. Let the encounter set the level, and the level is defensible.
Documentation that launders vs documentation that supports
Documentation supports a claim when it shows the work; it launders a claim when it manufactures the appearance of work that did not happen. Cloned notes are the classic tell — a record where every visit carries identical review-of-systems and assessment language reads to an auditor as boilerplate, and cloned notes as evidence have anchored real enforcement. Medical necessity is the other half: the service must be reasonable and necessary, and medical necessity on paper is what an auditor scores.
Copy-forward is not itself prohibited; carried-over text that no longer describes the current encounter is the problem. The same is true of scribe and template output: a template is a starting point, not a finished note, and a finished note has to reflect what actually happened in the room. Two disciplines keep you clear. First, edit every note to the specific visit — the assessment and plan are where an auditor looks for individualization. Second, make the note answer why, not just what: a high level of decision-making documented against a service with no clear necessity fails on the necessity axis even if the complexity is real.
The three states of mind the False Claims Act punishes
The False Claims Act punishes three states of mind, and only one is a deliberate lie. It reaches actual knowledge that a claim is false, deliberate ignorance of its truth, and reckless disregard for whether it is true 1Ref 1U.S. Department of Justice (2026).The False Claims Act.That the False Claims Act reaches knowingly false claims including reckless disregard, with treble damages, per-claim penalties, and qui tam suits.. That structure is the point: a provider who never checks whether the notes support the codes cannot hide behind not having checked. Penalties run to treble damages plus a penalty per claim, and a relator can file the case.
This is why 'my biller handled it' and 'the EHR suggested the code' are not defenses. Delegating the mechanics of coding is fine; delegating responsibility for whether your claims are true is not, because the claim goes out under your number. The practical takeaway is that a light-touch, recurring self-review is not optional hygiene — it is what converts a reckless-disregard posture into a documented, good-faith one. The clinician who samples a handful of their own charts each quarter and corrects what they find is in a categorically different position from the one who never looks.
How the line gets tested: audits and the SIU call
The line gets tested in an audit. A payer's special investigations unit, or a Medicare contractor, pulls a sample of your notes and compares them to the codes billed; a pattern of unsupported levels can be extrapolated across your claim volume, turning a handful of charts into a large demand. The siu call is where that starts, and knowing the counsel threshold — the point at which you stop answering alone — protects you before you say something you cannot walk back.
A records request or a courteous call asking you to 'explain your coding' is not automatically an accusation, and treating a routine review as a crisis wastes goodwill. But the tone changes when the request references a pattern, a specific code family, or a projected overpayment, or when the caller is an investigator rather than a reviewer. Those are signals to slow down, gather the actual notes before you characterize them, and get advice on the response. Answering expansively from memory, or agreeing to characterizations of your own records you have not re-read, is how a manageable review becomes a bigger problem.
If you find your own coding problem
If a self-review turns up a real coding problem, the exposure is manageable if you move correctly. The OIG's compliance guidance for small practices treats periodic self-auditing as a core element precisely because finding and fixing an error yourself is the strongest evidence against the 'knowing' state of mind the False Claims Act punishes 4Ref 4HHS Office of Inspector General (2023).General Compliance Program Guidance.That OIG's small-practice compliance guidance treats periodic self-auditing as a core program element.. A simple overpayment gets refunded through the payer; conduct that implicates the federal fraud laws has a formal self-disclosure protocol 5Ref 5HHS Office of Inspector General (2026).Health Care Fraud Self-Disclosure Protocol.That OIG maintains a self-disclosure protocol for conduct implicating the federal health care fraud laws, distinct from a routine overpayment refund..
The sequence matters more than speed. Quantify the issue with a focused look-back rather than guessing at scope, decide with advice whether it is a routine overpayment or something that rises to the self-disclosure level, and document what you found and what you changed. That paper trail is itself protective: it shows a functioning compliance habit rather than a cover-up. The worst move is the human one — noticing a pattern, feeling the dread, and doing nothing, which leaves the reckless-disregard door wide open for anyone who later looks.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.U.S. Department of Justice (2026). The False Claims Act. U.S. Department of Justice. link ✓That the False Claims Act reaches knowingly false claims including reckless disregard, with treble damages, per-claim penalties, and qui tam suits.
- 2.Centers for Medicare & Medicaid Services (2023). Evaluation and Management Services Guide. CMS Medicare Learning Network (MLN006764). link ✓That office-visit levels are selected by medical decision-making or total time and what must be documented to support the level.
- 3.American Medical Association (2023). CPT evaluation and management (E/M) revisions. American Medical Association (AMA). link ✓That the 2021 E/M revisions removed history and exam as level-setting elements in favor of medical decision-making or total time.
- 4.HHS Office of Inspector General (2023). General Compliance Program Guidance. HHS Office of Inspector General (OIG). link ✓That OIG's small-practice compliance guidance treats periodic self-auditing as a core program element.
- 5.HHS Office of Inspector General (2026). Health Care Fraud Self-Disclosure Protocol. HHS Office of Inspector General (OIG). link ✓That OIG maintains a self-disclosure protocol for conduct implicating the federal health care fraud laws, distinct from a routine overpayment refund.
https://www.gale.care/for-providers/fa-medical-necessity-fraud-line · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.