Healthcare Audit & Assurance Frequently Asked Questions
Is a healthcare financial statement audit the same as a coding and billing audit?
No. A financial statement audit addresses the financial statements as a whole. A coding and billing review examines issues such as documentation, medical necessity, and charge capture. These engagements have different objectives, even when both involve reimbursement information. The work should be scoped to the reporting or compliance question that needs to be answered.
How can healthcare organizations reduce duplicated assurance work across audit, compliance, finance, risk, and IT?
When assurance work is planned separately, organizations can face repeated walkthroughs and requests, inconsistent risk assessments, siloed findings, and gaps in coverage. An aligned approach inventories assurance providers, aligns the risk universe and work plans, standardizes reporting, and supports continuous collaboration. Each function retains its authority, while leadership receives a more unified view of risk and control effectiveness.
Why do EHR, billing, and other IT systems matter during healthcare audit planning?
Healthcare financial systems often connect with electronic health records, billing platforms, and other critical applications. Audit planning therefore considers how systems that affect financial reporting operate and how IT general controls support access, system performance, data processing, system-generated reports, and automated processes. These controls influence risk assessment and the audit procedures applied to financial information.
When can healthcare audit and accounting support be useful during a transaction or major change?
Healthcare transactions and strategic initiatives may call for financial due diligence, Quality of Earnings analysis, transaction accounting assistance, forensic accounting, valuation-related support, and financial or statistical analysis. Major accounting changes may also require new standard implementation, policy and procedure development, or internal control review.
When can co-sourced internal audit help a healthcare organization address specialized risks?
Co-sourcing or outsourcing can add targeted capability when an internal audit plan includes technical areas such as cybersecurity, technology governance, regulatory and compliance risk, fraud risk management, data privacy, or emerging technology. The model can supplement internal capacity and bring specialized expertise while internal audit, management, compliance, or board-directed oversight continues to provide direction.