OIG Work Plan Priorities Affecting Independent Practice Billing
Federal audits are targeting six specific billing patterns in independent practices right now.

The HHS Office of Inspector General's Work Plan is not a report that practices read once a year and set aside. It functions as a live enforcement signal, updated continuously as new risks appear in claims data, and it tells independent practices, in specific terms, which billing patterns the federal government is already examining. The Work Plan catalogs planned audits, evaluations, and oversight activities across Medicare, Medicaid, and other HHS programs, and OIG revises it throughout the year rather than issuing it as a single fall release. March 2026 alone brought a dense cluster of new audit announcements covering billing compliance, managed care integrity, and Medicaid financial stewardship, and the volume and specificity of those announcements point to enforcement attention that is already concentrated and active, not merely anticipated.
The process behind each entry follows a consistent structure. OIG's Engagement Committee assesses vulnerabilities across HHS programs, votes on proposed projects, and posts approved audits and evaluations publicly. Once a project lands on the Work Plan, OIG starts the work, issues findings, and tracks whether its recommendations get carried out. Entries rarely appear at random: most represent areas where OIG has already identified troubling patterns through data analysis or prior investigation, so a practice reading the announcement for the first time is often reading about a federal data review that started earlier. Completed projects carry weight too. Several audits that closed in early 2026 have already produced findings that OIG is citing in current enforcement actions, so a side-by-side read of completed reports and active projects tells you more than scanning active projects alone.
That structure changes what the document demands of a practice. Reading the Work Plan for awareness accomplishes little if the reading stops there. The document names, with precision, the billing patterns under federal review before most providers have any reason to suspect scrutiny, and treating it as a scheduling tool for internal compliance work converts that advance notice into something a practice can act on. The sections that follow build the case for why that conversion from awareness to action matters, starting with how exposed independent practices actually are.
Why Independent Practices Are More Exposed to OIG Scrutiny
Many practice administrators assume OIG enforcement activity targets only large hospital systems or headline fraud schemes, so they think smaller independent practices sit outside the blast radius. That assumption is incorrect, and acting on it carries real financial cost. Physician practices, group practices, specialty clinics, telehealth providers, and outpatient organizations all fall squarely within the scope of OIG audit activity, because Medicare billing errors and improper payments remain a federal enforcement priority regardless of the size of the entity submitting the claim.
The range of consequences that follows a compliance gap is wide enough to warrant attention at every practice size. Overpayment demands, civil monetary penalties, exclusion proceedings, and False Claims Act exposure can all trace back to something as mundane as a documentation habit or a billing workflow shortcut that nobody flagged internally. If a practice turns OIG Work Plan priorities into concrete internal audits, it can find those gaps and fix them before a federal auditor does. Practices that treat the Work Plan as background noise tend to discover their gaps only after an overpayment demand, a penalty notice, or an exclusion proceeding has already started.
Part of what makes this exposure easy to underestimate is a shift in how enforcement actually works. The government now deploys data analytics tools to identify outlier billing patterns across Medicare and Medicaid, and the random-sample audit, the kind that could plausibly miss a small practice simply by chance, has become a far smaller part of the picture. The government increasingly knows who it wants to audit before it requests a single medical record. This architecture is not confined to the federal level. New York's Office of the Medicaid Inspector General uses pattern recognition to flag unusual claims data, modeling to identify providers whose billing resembles that of providers with high error rates, and outlier analysis to catch data points that deviate sharply from expected trends; that state-level apparatus runs alongside the federal one.
The practical consequence is one that every independent practice should sit with regardless of its size or its confidence in its own clinical documentation: a practice does not need to be committing intentional fraud to show up in an OIG data query. Outlier billing patterns produced by ordinary workflow errors or undocumented shortcuts are enough on their own to trigger a review. That reality narrows the gap between a large hospital system and a five-physician specialty clinic, and it leads into the six specific billing areas where the 2026 Work Plan has turned that general exposure into active audit activity.
The six billing areas the OIG is actively scrutinizing in 2026
The 2026 Work Plan moves beyond general statements of concern in six billing areas and replaces them with active audit activity, and each area carries its own documentation or workflow failure that generates exposure.
Chronic Care Management billing is the first. In March 2026, OIG announced an audit targeting CCM payments that may not comply with Medicare's requirement that a patient have two or more qualifying chronic conditions before CCM services can be billed. Part B payments for CCM services rose at a rate between 2019 and 2024 that drew OIG's direct attention. The failure patterns OIG has identified are specific: clinical staff time gets rounded up rather than logged precisely, time gets claimed by overlapping staff members for the same period, and tasks that don't qualify as clinical care coordination end up billed as if they did. CCM billing also requires documentation establishing that a patient's conditions meet the eligibility standard and that the services billed were performed outside the scope of a regular office visit, a requirement that gets overlooked often enough to draw federal scrutiny.
Modifier 25, appended to same-day E/M and minor procedure claims, is the second area. This modifier is meant to apply only when a significant, separately identifiable E/M service is performed on the same day as a minor surgical procedure. If you apply it without documentation that actually supports that distinction, you get an overpayment and potential False Claims Act exposure. The documentation standard is specific: the E/M service note has to stand on its own, physically separate from the procedure note. The modifier should not have been billed if the note cannot stand independently of the procedure it accompanied.
Medicare Advantage risk adjustment and HCC coding form the third area. CMS began phasing in a new HCC risk adjustment model, V28, in 2024, which reduced the diagnosis mappings that qualify for payment and was expected to save billions of dollars. OIG is now analyzing MA coding patterns for upcoding: the submission of diagnosis codes that inflate a patient's risk score and, with it, the MA payment tied to that patient. If a practice treats MA beneficiaries and has not checked their diagnosis coding against the V28 mappings, it carries direct exposure here.
Inpatient neurostimulator implantation surgeries make up a narrower fourth area, relevant mainly to the surgical specialties that perform these procedures. OIG announced an audit of inpatient claims for neurostimulator implantation in March 2026, built around a coverage gap: current prior authorization requirements apply to outpatient neurostimulator surgeries but not to inpatient versions of the same procedure, a gap OIG has flagged as a vulnerability. If your practice bills these procedures in an inpatient setting, check your documentation and billing logic against current requirements before OIG checks it for you.
Telehealth and virtual services billing form the fifth area, and the compliance bar here has moved well past picking the correct CPT code. Documentation, timing requirements, medical necessity support, modifier usage, and workflow controls all carry audit weight now. Practices that expanded virtual care rapidly during the pandemic may still be running on internal processes that were built for speed rather than consistency, and that inconsistency is itself a source of audit risk.
Incident-to billing under Medicare Part B is the sixth area. OIG has an active Work Plan project determining whether services billed as incident to a physician's services actually complied with Medicare requirements. Many offices assume, incorrectly, that a non-physician practitioner's services can automatically be billed under a supervising physician's NPI for full reimbursement. Medicare requires strict supervision, an established treatment plan, ongoing physician involvement, and specific supporting documentation before that billing is appropriate, and the risk runs highest in busy practices where day-to-day workflows have evolved faster than the compliance oversight meant to govern them.
How data analytics has changed who gets audited and why billing pattern outliers matter more than intent
Each of the six areas above gets found the same way. OIG and state Medicaid inspectors have moved away from complaint-driven and random-sample audits, replacing them with algorithmic pattern detection that identifies practices for review before a single record is pulled. Selection now happens at the level of the aggregate pattern. Intent plays no role in who gets flagged first.
Government analytics tools are built to surface outlier billing patterns across Medicare and Medicaid, so if your billing deviates significantly from your peers, you get flagged for that deviation alone. New York's OMIG runs the same kind of system at the state level: pattern recognition to catch unusual claims data, modeling that identifies providers whose billing resembles that of providers with known high error rates, and outlier analysis that catches data points that are either impossible or far outside expected trends. The rheumatology scenario that illustrates Modifier 25 risk is the clearest operational example of how this works: the algorithm flagged a statistical outlier rate in modifier use before any complaint had been filed and before any record had been reviewed by a human being.
The consequence for billing strategy is direct. A practice billing CCM codes at a rate well above its peer group, or appending Modifier 25 at a rate outside specialty norms, will appear in a data query whether or not every individual claim behind that rate is clinically justified. If the aggregate pattern those encounters produce looks unusual in federal data, clinical confidence in each individual encounter will not protect a practice from scrutiny. A practice has to understand its own billing shape the way an algorithm sees it, not only the way its physicians experienced each visit.
Medicaid-billing practices face an additional, specific version of this exposure. The 21st Century Cures Act requires all Medicaid fee-for-service and managed care network providers to be enrolled with their state Medicaid agency, and OIG is now assessing whether states have actually complied with that requirement. A provider who bills Medicaid without being properly enrolled is, by definition, an outlier in the data, and that gap functions as its own audit trigger independent of anything else in the provider's billing.
Building a practice-level audit calendar from the Work Plan's priorities
The practices that consistently stay ahead of enforcement exposure are the ones that use the Work Plan as a scheduling document for their own internal reviews, running audits against each named priority on a set calendar rather than reading the document once and setting it aside. A structured approach to this work outperforms an ad hoc one, largely because it converts a list of federal priorities into a repeatable internal process rather than a one-time compliance check.
Risk stratification specific to the practice itself is the starting point. OIG priorities need to be read through the lens of the practice's own services, payer mix, and organizational risk profile, because not every item in the six-area list above applies to every practice with equal weight. A practice should identify which of the six 2026 focus areas it actually bills under, then rank those areas by claim volume and reimbursement exposure. A high-volume CCM biller is managing a different first-priority risk than a surgical practice billing neurostimulator procedures, and the audit calendar should reflect that difference rather than treat all six areas as equally urgent.
For Modifier 25, the internal audit scope should pull every claim where the modifier was appended over the prior 12 months, calculate that use as a share of same-day procedure claims, compare the resulting rate to specialty norms, and review a sample of the underlying documentation to confirm that the E/M note stands independently of the procedure note.
For CCM, the scope should pull every claim billed under the relevant codes, verify that each one has documentation showing the patient's qualifying chronic conditions, confirm that time logs are recorded to the minute and attributed to a single staff member rather than split across several, and confirm that the services billed were rendered outside the scope of a regular office visit.
For incident-to billing, the scope should cover every claim billed under a physician's NPI for a service actually rendered by a non-physician practitioner, confirm that the supervising physician was physically present in the office suite at the time, and verify that an established treatment plan exists for each patient involved.
For telehealth and remote patient monitoring, the scope should confirm patient enrollment documentation, verify monitoring time logs against what was actually billed, check that place-of-service codes reflect where the service genuinely occurred, and review modifier usage against current Medicare billing rules.
A practice that runs this kind of internal audit program on a set calendar tied directly to the Work Plan's own priorities gets the chance to find and correct its own compliance gaps on its own schedule. The alternative, waiting for OIG's data analytics to find those same gaps first, tends to arrive in the form of an overpayment demand rather than an internal memo.


