Blog

Medical claims audit at the payer: how it works, what gets reviewed and why every claim can be audited

16 min readBy Alex Meincheim, CEO & Co-founder, UpFlux

Medical claims audit is how a Brazilian health plan checks every bill from hospitals, clinics, labs and physicians before paying it. This guide walks through it from inside the payer: the TISS intake, administrative and clinical review, denials and appeals, sampling versus full coverage, and where AI fits.

Medical claims audit at the payer: how it works, what gets reviewed and why every claim can be audited

Medical claims audit is the process a health plan operator (the payer) uses to check every bill sent by hospitals, clinics, laboratories and physicians before paying it. It answers three questions: was what was billed actually performed, was what was performed necessary, and is the amount billed what the contract says.

Most content on the subject is written from the billing side. This guide goes the other way and describes the audit from inside the payer, the party that receives the claim, reviews it, denies items when needed, answers the appeal and pays. The context is Brazilian private healthcare (known locally as saúde suplementar), regulated by the ANS, the National Supplementary Health Agency.

To keep the reasoning concrete, we follow an illustrative payer that receives 80,000 claims a month. Its numbers are made up for teaching purposes. Market figures, where they appear, come from linked public sources.

What medical claims audit is

At the payer, medical claims audit is the technical, administrative and contractual review of every claim submitted by a network provider. The claim arrives in a standard format, goes through automated edits, is reviewed by healthcare professionals and ends in one of three decisions: pay in full, pay in part with a denial, or return it for correction.

In Brazil, the denial of a billed item is called a glosa: the payer refuses to pay all or part of an item on the bill. We cover it in depth in the article on hospital claim denials.

The goal is not to pay less. It is to pay correctly. An unfounded denial triggers an appeal, rework and friction with the provider network. An improper payment is medical expense with nothing behind it and pushes up the medical loss ratio (sinistralidade, claims expense over premium revenue). A well-run audit reduces both errors at once.

The payer's view and the provider's view

Both sides use the same word for different processes. It helps to separate them.

Aspect Audit at the payer Audit at the provider
Who does it The payer's own physicians, nurses and analysts, or contracted third parties The hospital's billing team and internal audit
When it happens After the claim is submitted, before payment Before the claim is sent, during the stay or in pre-billing
Central question Should I pay what was billed, and how much Did I bill everything that was done, the way the contract allows
Outcome Payment, denial or return Claim billed, denial avoided or appeal filed
Main reference Contract, negotiated price table, TISS, clinical guidelines Medical record, prescription and contract price table

Who audits claims at the payer

Three profiles work in the same flow, with different competencies.

The physician auditor is responsible for reviewing clinical appropriateness and is the one who can challenge the indication for a procedure, length of stay and clinical conduct. The role is regulated by the Federal Council of Medicine (CFM). CFM Resolution 2,448/2025, published on November 4, 2025, revoked CFM Resolution 1,614/2001, which had governed medical auditing since 2001. The new rule keeps medical auditing as an act reserved to physicians, requires disagreements to be grounded in the patient's clinical history, and bars denying procedures that were previously authorized and proven to have been performed.

The nurse auditor reviews consistency between prescription, clinical notes and billed items: supplies, drugs, daily rates, fees and nursing procedures. COFEN Resolution 720/2023 from the Federal Nursing Council governs nurses' work in auditing and revoked COFEN Resolution 266/2001. It lists as reserved to nurses the organizing, planning, coordinating and evaluating of audits and counter-audits, including denial appeals, as well as issuing opinions.

The claims analyst, with no healthcare training, runs the administrative review: member registration, eligibility, validity of the authorization, codes, price-table values and contract rules. It is the highest-volume step and the one that benefits most from automation.

The steps of medical claims audit: from TISS to the denial appeal

The flow below is what most Brazilian payers run, with variations in naming.

Step What is checked Who does it Output
1. Intake Claims and batches in the TISS standard, valid XML, network provider, correct billing period System and claims department Batch accepted or rejected at intake
2. Administrative review Member eligibility, waiting periods, prior authorization, TUSS codes, price-table values, duplicates, submission deadline Claims analyst supported by automated rules Claim released for clinical review, administrative denial or return
3. Clinical review Appropriateness of billed items given diagnosis, prescription and clinical notes; quantities; length of stay; OPME; bundles Nurse auditor and physician auditor Claim approved, partial or full clinical denial
4. Denial Reason recorded with a standard code, amount denied, justification Auditor responsible for the step Claim review statement sent to the provider
5. Denial appeal Provider's challenge with documentation, re-review by the payer Nurse and physician auditor Denial upheld or reversed, with payment of the reversed amount
6. Payment and close Reconciliation of the final amount, accounting provision, indicators Finance and claims Claim closed and data for management

Step 1: intake in the TISS standard

TISS (Troca de Informações na Saúde Suplementar, the supplementary health information exchange standard) is mandatory for communication between payers and providers. The official ANS page lists the current version, identified as the July/2026 TISS Standard, and ANS Normative Resolution (RN) 497/2022 as the rule that governs it. The standard has five components: organizational; content and structure; representation of health concepts; communication; and security and privacy.

For the audit, what matters is that the claim arrives structured. Each claim form carries member, provider, procedures with codes, quantities, amounts and dates. That makes the administrative review almost fully automatic and builds the database the clinical review will use.

Step 2: administrative review

Here the system checks what does not depend on clinical judgment. The member was active on the date of service. The procedure required authorization and it exists. The billed code is on the contract price table and the amount matches. The same claim is not in another batch. The submission deadline in the contract was met.

At our illustrative payer with 80,000 claims a month, a well-configured review settles most low-complexity claims: consultations, simple tests and therapy sessions without complications. What is left goes on to clinical review.

Step 3: clinical review

This step needs a healthcare professional. The auditor reads the claim alongside what is known about the case: diagnosis, main procedure, length of stay, prescriptions. The question is whether each billed item is consistent with the clinical picture and with what the contract provides for that type of care.

Step 4: denial

A denial is the refusal to pay all or part of an item or of the claim. Every denial needs a coded reason. The TISS standard keeps its own terminology for denial and refusal messages, which lets the provider understand the refusal and lets the payer measure its most frequent reasons. For the types of denial and how providers respond to them, see the article on hospital claim denials.

The denial has to be justified. Under CFM Resolution 2,448/2025, cited above, the physician auditor's disagreement must start from the patient's clinical history, and procedures that were pre-authorized and proven to have been performed cannot be denied. That forces the payer to decide well at authorization, because claims audit does not fix a poorly granted authorization.

Step 5: denial appeal

The provider can challenge. ANS RN 503/2022, which covers contracts between payers and providers and revoked RN 363/2014, requires in article 13 that billing and payment deadlines and procedures be stated in the contract. Article 14 requires the administrative and technical audit routine to be stated as well, including the grounds for denial and the deadlines for challenge, for the payer's response and for payment when a denial is reversed. Its sole paragraph sets the deadline to challenge a denial equal to the deadline for the payer to respond.

In practice, the payer is on a clock to re-review. An appeal not answered within the contractual deadline becomes a liability and a source of friction with the network.

Step 6: payment and close

The closed claim feeds the accounting provision, the medical loss ratio calculation and the network management indicators. A late close delays all of that.

Prospective, concurrent and retrospective audit

Beyond the steps, the audit is spread over time.

  • Prospective audit: happens at authorization, before care. It decides whether the procedure will be covered. It is not claims audit, but it defines what the claim will be able to bill.
  • Concurrent audit: happens during the hospital stay, through bedside visits or daily review. It follows length of stay, OPME (orthotics, prostheses and special materials) and complications.
  • Retrospective audit: happens after care, on the submitted claim. It is the subject of this guide and the highest-volume step.

What the auditor looks for in a claim

Clinical review looks at a well-known set of points. The most frequent:

  • Items with no clinical match. A drug billed without a prescription, a test with no recorded indication, a procedure incompatible with the diagnosis.
  • Quantities. Daily rates beyond the length of stay, supplies above the usual amount for the procedure, sessions above what was authorized.
  • Consistency between procedure size and billing. A smaller surgery billed with the professional fees and charges of a larger one. Anesthesia billed for a procedure that does not require it.
  • Bundles. Items billed separately when the contract sets a closed bundle for that procedure, or the bundle billed and its items billed again.
  • OPME. Orthotics, prostheses and special materials above the negotiated price, in a quantity incompatible with the procedure, or without specific authorization.
  • Daily rates and fees. Room type different from the contracted one, an operating room fee with a time incompatible with the procedure, an ICU daily rate with no clinical notes to justify it.
  • Professional fees. More assistants than provided for, multiple procedures without the reduction set in the price table, duplicate billing through different channels.
  • Duplicates and resubmissions. The same claim, or part of it, in different batches or different billing periods.

Each specialty and each type of admission has an expected pattern of items, quantities and amounts. That is why clinical review does not scale with fixed rules alone: what is normal for a hip replacement is not what is normal for a childbirth.

Sampling versus full coverage: the math of cost and risk

This is the core limitation of the traditional model. Back to the illustrative payer.

It receives 80,000 claims a month. Suppose the administrative review automatically releases or denies half, with no clinical judgment. That leaves 40,000 claims a month that need clinical review.

An experienced auditor, going claim by claim with access to whatever documentation exists, handles something like 60 claims a day across a mix of complexity. Over 22 working days, that is about 1,320 claims a month. With 12 auditors, capacity is roughly 15,800 claims a month.

The gap is the problem: 40,000 claims needing review, 15,800 being reviewed. About 24,000 claims a month, 60% of what needed a clinical look, go to payment without anyone reading them. The numbers are illustrative, but the proportion will be familiar to anyone who runs a claims department.

The traditional answer is sampling. The payer sets a cutoff: claims above a certain amount, claims from certain providers, inpatient claims. Anything below the cutoff is paid without review. That protects against large, concentrated errors. It does not protect against the small, repeated error, which is exactly what piles up across thousands of low-value claims.

The size of that pile across the sector is known. The study by IESS with EY, published in November 2023, estimated losses from fraud, abuse and waste at between R$ 30 billion and R$ 34 billion in 2022, the equivalent of 12.7% of payers' revenue. A study by PwC Brazil indicates that fraud consumes more than 10% of payers' revenue. And the sector remains large: the ANS recorded about 53 million members in medical plans in June 2026.

Sampling was the right answer while only a professional could read a claim. Today's question is what changes when every claim can be read before the auditor decides.

How AI changes the volume, time and quality triangle

Claims departments have always lived inside a triangle. Increasing the volume reviewed takes more time or lowers quality. Cutting cycle time takes less volume or less depth. Improving quality takes more time per claim.

Clinical models by specialty change the shape of the triangle. The idea is simple: for each type of care there is an expected pattern of items, quantities, length of stay and amount. A model trained on the payer's own history and on clinical guidelines compares each incoming claim with that pattern. The result is not "approve" or "deny." It is a classification: this claim is within the expected pattern; this claim has a deviation of this type, on this item, with this financial impact.

That reorganizes the work into two queues.

The first queue holds the claims consistent with the pattern. They can be released automatically, with a record of the model that assessed them and the criteria used. They are most of the volume.

The second queue holds the claims with deviations. They reach the auditor with the deviation already pointed out, the item flagged and the amount at stake calculated. The auditor does not have to hunt for the problem. They decide whether the deviation is justified by the clinical case or becomes a denial.

At the illustrative payer, automated triage reads all 40,000 claims that needed clinical review. Suppose 10% of them, 4,000 claims, show a deviation with material impact. The same 12 auditors, with capacity for 15,800 claims a month, now cover every flagged case with room to spare, and can spend the remaining time on provider-pattern investigations, denial appeals and concurrent audit. Coverage goes from 40% to 100%. Cycle time drops, because most of the volume no longer waits in line. And quality rises, because every human decision is made with the context already assembled.

The principle behind this model is that AI reveals and the auditor decides. The technology does not sign a denial. It shows where to look and at what impact. Technical responsibility stays with the physician and nurse auditors, as the CFM and COFEN resolutions require.

Three conditions separate a project that works from a more expensive fixed rule:

  • Models by specialty. A single amount threshold produces false positives in orthopedics and false negatives in oncology.
  • Traceability. Every automatic release records which model, which criteria and which version, to answer appeals and external audits.
  • Feedback. The auditor's decisions on flagged claims flow back into the model.

Indicators to track in claims audit

A claims department is managed with a few indicators, measured consistently.

  • Review coverage: share of received claims that went through clinical review, human or automated. It is the indicator that sampling hides.
  • Denial rate: amount denied over amount billed, by provider, by specialty and by reason. A high rate concentrated in an administrative reason points to a registration or contract problem, not a conduct problem.
  • Denials upheld after appeal: share of the amount denied that stays denied after the challenge. It measures the quality of the denial. A high reversal rate means the payer is denying poorly and paying late.
  • Cycle time: days from receipt of the claim to payment or to the appeal response. It should be compared with the contractual deadlines required by RN 503/2022.
  • Value avoided per auditor: sum of upheld denials attributable to human decisions, divided by the number of auditors. It shows where professional time produces the most.
  • Backlog: claims received and not yet reviewed, in count and in value. It is the operational health indicator of the department.
  • Contribution to the medical loss ratio: change in medical expense attributable to the audit, measured against the same prior period. It closes the loop with the indicator the board follows.

Common implementation mistakes

These mistakes repeat in projects to restructure the department, with or without technology.

  • Starting from denials instead of correct payment. Denial targets produce weak denials, mass appeals and a poor relationship with the network.
  • Fixed rules for everything. A single amount cutoff or a generic quantity limit produces false positives at scale and keeps the auditor busy with irrelevant cases.
  • Ignoring authorization. Claims audit does not fix a poorly granted authorization, and the CFM rule bars denials of pre-authorized procedures that were proven to be performed.
  • Not measuring coverage. Without knowing how many claims went through unreviewed, the payer does not know how much risk it is accepting.
  • Treating the appeal as an exception. The denial appeal is a step with a contractual deadline and predictable volume. It needs a queue, an owner and an indicator.
  • Deploying technology without feedback. A model that does not learn from the auditor's decisions becomes a more expensive fixed rule.

The common thread is that medical claims audit is a decision process, not a filter. Every decision, human or automated, needs the right context and a record. The medical claims audit solution page describes the flow from intake to appeal.

How UpFlux does it

UpFlux takes over the transactional work of healthcare claims with a digital team: AI agents operated by specialists, working inside the systems payers and hospitals already use. In claims audit that means 100% of claims audited with 450+ clinical models, which compare each claim with the expected pattern for the specialty. In a typical cooperative, 92% of claims are released automatically and the auditor decides the cases with impact, with the deviation and the amount already pointed out. The solution runs in 40+ Unimed System cooperatives and 20+ hospitals. Underneath sits the Enterprise AI layer (Nous, Intelligent Agents and RoAI, which measures the return of every AI action). See the medical claims audit solution and what we do for healthcare.

Frequently asked questions

What does a medical claims auditor do?

At the payer, the medical claims auditor checks whether each item billed by a provider was performed, was necessary and complies with the contract. The physician auditor is responsible for clinical appropriateness and the nurse auditor for consistency between prescription, clinical notes and billed items. The work results in approval, a justified denial or return of the claim, and includes re-reviewing the appeals filed by the provider.

What are the types of healthcare audit?

By timing, an audit can be prospective, at authorization; concurrent, during the hospital stay; or retrospective, on the submitted claim. By subject, it can be administrative, checking registration, eligibility, codes and amounts, or clinical, checking the clinical consistency of the items. By who performs it, it can be internal, done by the payer or the hospital itself, or external, done by contracted third parties.

What is the difference between medical claims audit and medical auditing?

Medical auditing is the set of acts reserved to physicians that assess the appropriateness of procedures, conduct and length of stay, regulated by the CFM. Medical claims audit is the payer's full process over the submitted claim, which includes medical auditing, nursing auditing and the administrative review. Every claims audit includes medical auditing when clinical judgment is involved, but a good part of a claim is settled without it.

What is a denial (glosa) in claims audit?

A denial, called glosa in Brazil, is the refusal to pay all or part of an item or of a claim submitted by the provider. It can be administrative, due to a registration, code or deadline error, or clinical, due to a lack of clinical or contractual consistency. Every denial needs a coded reason and a justification, and the provider has the right to challenge it within the deadline set in the contract, under ANS RN 503/2022.

Is it possible to audit 100% of medical claims?

Yes, as long as reading each claim does not depend on a professional alone. With clinical models by specialty, every incoming claim is compared with the expected pattern for that type of care; consistent claims are released automatically with a record, and those with deviations reach the auditor with the problem and the impact already identified. The auditor still decides, but now decides on the cases that matter instead of on a sample.

Which indicators should a claims audit track?

The main ones are review coverage, denial rate by reason and by provider, share of denials upheld after appeal, cycle time from receipt to payment, backlog in count and value, value avoided per auditor, and contribution to the medical loss ratio. Coverage and denials upheld after appeal are the two that keep the department from optimizing for denials instead of correct payment.

Keep reading

AI in Tasy: auditing hospital bills before billing, with fewer denials
Healthcare

AI in Tasy: auditing hospital bills before billing, with fewer denials

AI in Tasy for claims audit means reviewing every patient bill before it closes and goes to billing, not after the payer's denial arrives. An AI agent reviews 100% of bills, points out the likely denial reason and the suggested fix, and leaves the decision with the auditor.

Read
Hospital claim denials from the payer's side: criteria, justification and how to cut unfounded denials on both sides
Healthcare

Hospital claim denials from the payer's side: criteria, justification and how to cut unfounded denials on both sides

A hospital claim denial (glosa, in Brazil) is the payer's refusal to pay all or part of a billed item, with a coded TISS reason the hospital can appeal. This guide covers the types and reason codes, how payers justify each item, fair versus unfounded denials and what each error costs, ANS appeal rules and how consistent auditing cuts unfounded denials.

Read