EMR Hacks from Auditors Who’ve Seen It All
Article Reference Code: NAMAS.07.03.2026
Written by: Melissa Kirshner and Erin Fogolini
During COVID, how many of us had telehealth visits only to review the progress note uploaded to the provider’s electronic medical records (EMR) to see “lungs clear to auscultation, heart RRR”? When questioning a provider after the fact, the provider stated, “I know. But that is part of our template. It defaults all negative findings unless I change them. I forgot to remove those things.” EMR shortcuts, or “hacks”, are not always malicious. Many are workflow shortcuts, documentation habits, template behaviors, or system workarounds that can create compliance, coding, quality, and legal risk. For auditors, the key is learning to recognize patterns that may affect accuracy, medical necessity, authorship, and integrity of the record.
As documentation automation expands, auditors need to shift from reviewing what was documented to the veracity of the documentation. There are numerous “hacks” that are pretty commonplace: copy and paste; pull forward; template creation and usage. Is copy/paste or pull forward a problem? Not in and of itself, but can you tell whether the provider actually performed those services in this visit or if they were just referring to the older services? It calls the entire record into question. Is the provider’s record or observation reliable?
Overuse or inaccurate use of smart phrases that auto-populate the clinical record – when the same wording or phrase is used on every medical record, it calls into question the accuracy of the information. How was every patient and every visit identical?
Some of the more common thoughts and concerns related to EMRs include:
| Documentation Issue | Legal Question |
|---|---|
| Copy/Paste | Was care actually performed? |
| Contradictory Note Elements | Is the record reliable? |
| Missing Assessment Rationale | Did the provider meet the standard of care? |
| Late Entries | Were they disclosed appropriately? |
| Template Overuse | Did the physician independently evaluate the patient? |
| Audit Log Inconsistencies | Was the record altered? |
These documentation issues all contribute to “note bloat”. Auditors must be trained to look at specific structural “anchors” across different EMR layout. Skip the HPI and exams templates entirely on your first pass. Go straight to Assessment/Plan/Impression section of the note. If the provider didn’t synthesize their thoughts here, a high-level e/m code or complex HCC is already at risk.
Next, move to the orders placed or results reviewed sections. Compare the auto data pulled into the note against the actual orders log to verify that the provider actually ordered or reviewed them during this specific encounter. Are you able to easily identify what the provider ordered today or if she is referencing results from a previous visit?
While these documentation challenges have existed for years within traditional EMR workflows, the introduction of Artificial Intelligence (AI) is creating an entirely new layer of audit risk.
And now, with AI moving into the EMR arena, the auditor’s role is further expanding. AI has been implemented in multiple ways to assist providers with capturing visit documentation, to automate and improve the revenue cycle, to actually begin coding visit documentation. But none of these functions are bulletproof. AI is only as good as it was trained, and training AI is really no different than training a new employee. It is just an employee that can work at lightning speed.
One use case for AI that has audit concerns is ambient scribe technology. The system listens to the visit and writes a note, in the provider’s voice, for documentation purposes. While the demonstration of scribe technology has been powerful, the technology is still not 100% accurate. Providers must be validating all ambient scribed notes to ensure accuracy. This is not a new compliance issue. Providers have always had the issue of needing to verify their documentation after using scribe tools. When Dragon was first introduced, numerous documentation errors resulted in hours of investigation. Now, with AI, the documentation looks like it could be valid without provider review. Example, the provider and patient are talking about a family member’s recent diagnosis of cancer. Ambient AI can, and has, picked up the family member’s diagnosis as belonging to the patient. In another example overheard at conference recently, the AI scribe was trained to ignore discussions regarding vacations, but the patient’s injury occurred on vacation as was relevant to the visit in question. How will auditors identify these types of documentation issues?
Many EMRs have also embedded AI for coding assistance. Organizations implementing AI-assisted documentation and coding should ensure that auditors understand how the system generates recommendations and how to validate whether documentation supports the codes being assigned. As AI begins to suggest ICD-10 codes, auditors should be looking to ensure that the diagnosis is appropriately supported by the provider’s documentation. Was the diagnosis assigned to the patient valid or was it part of a discussion of the patient’s family history and picked up by the ambient scribe in error? Looking at the coding being completed, are you seeing sudden increases in E/M levels or modifier usage? Perhaps the issue is that you were historically undercoding, but it is also likely that the AI coder embedded within the EMR is upcoding inaccurately. Auditors will play a key role in identifying documentation patterns and providing feedback to the operational and technological teams to improve tool performance.
Auditors, pre-AI and now even more with embedded AI technology, should be viewing the patient’s documented problem list/past medical history (PMH) with a skeptical eye. Review the PMH side-by-side with the encounter note. Are you finding evidence of “ghost-diagnoses”? Are there conditions billed on the claim that were never mentioned, not managed or not monitored by your provider as documented within the body of the note?
EMR shortcuts, along with the emergence of AI tools, feel necessary operationally, but they create substantial audit vulnerabilities. The organizations must safely balance efficiency with compliance through clear documentation and authentication workflows; regular auditing and feedback to providers, operational and technology staff; expanded training on compliance expectations and risks; and finally, assurance of accurate justification for billing and coding decisions.
Finally, as an auditor, you must understand the specific idiosyncrasies and nuances of the EMR software in use. Auditing now requires more than just clinical and coding knowledge. Recognizing documentation risk is only part of the job. Efficiently navigating the EMR is equally important. The faster an auditor can locate key information, the more effectively they can identify documentation vulnerabilities, validate provider actions, and evaluate the integrity of the record. The auditor’s ability to navigate the system efficiently is critical; mastering platform-specific shortcuts and understanding how each EMR integrates AI can drastically reduce your audit time.
Some of the platform specific EMR shortcuts that we have gathered are as follows:
- EPIC
- Use CTRL+spacebar for a chart search. Instead of clicking through the left-hand navigator, hit this shortcut and enter keywords such as “Radio” “path” or “A1C”.
- Filters in chart review: Click the gear icon on the Notes tab in Chart review. You can now filter the chart to hide system text, such as nurse triage, telephone calls, etc, leaving just the provider notes for review.
- Cerner/Oracle Health
- In the Powernote section, auditors can change the view filter from “All Notes” to “Physician Notes Only.”
- Utilize the Table of Contents to drag and drop your menu items on the far left sidebar allowing you to modify the view. One suggestion is to move Advanced Cohort Review, Orders, and Diagnostics to the very top of the list allowing faster access to individual charts and decreasing the amount of scrolling required.
- Athenahealth
- “Full Chart” View: Instead of clicking into individual historical encounters, use the “Full Chart” toggle or “Briefcase” icon to pull a continuous vertical stream of the patient’s entire timeline. You can then use the browser-native Ctrl + F to scan the entire history at once.
- NextGen
- Category Filters: In the Document History tab, uncheck “All Categories” and explicitly select only “History & Physical,” “Progress Notes,” and “Consults.”

Contact Melissa LinkedIn by Clicking her Name Below:
Melissa Kirshner, MPH, CPC, CPCM, CPCO, CDEO, CRC, CPB, CFPC, CPMA, COBGC, CEMC, CPC-I
Melissa Kirshner, MPH, CPC, CPC-M, CPCO, CDEO, CPMA, CRC, CEMC, CFPC, COBGC, AAPC Approved Instructor, AAPC Fellow, has been involved in the healthcare world for over 30 years, with experience in billing, coding, auditing, education, practice management, and risk adjustment. She is currently the executive director of a large provider organization in Southeast Michigan. She is a passionate educator for both the AAPC Live Virtual Instructor team as well as for her own private coding students. Kirshner is a founding member of the Novi, Michigan local chapter, where she currently serves as chapter president. She proudly sits on the 2025-2027 AAPC National Advisory Board.
Contact Erin LinkedIn by Clicking her Name Below:
Erin Fogolini, CPC, CRC, CPMA
NAMAS BLOG Disclaimer:
The NAMAS Blog features content written by both NAMAS staff and guest contributors. Guest contributors may present opinions or perspectives that differ from those officially instructed or encouraged by NAMAS. We believe in providing space for a range of informed viewpoints to foster dialogue, reflection, and deeper understanding within the auditing and compliance community.
Some contributors may use artificial intelligence (AI) tools in the development of their content. The decision to incorporate AI is left to the discretion of the author and does not reflect an endorsement or directive from NAMAS.
If you have questions, comments, or concerns about a specific blog post, we encourage you to contact the individual author directly. Their name and contact information are provided at the end of each post.












Erin Fogolini, CPC, CPMA, CRC, is a seasoned healthcare revenue professional with over 15 years of expertise in medical billing, advanced coding, and healthcare quality metrics. Specializing in ICD-10 and HCPCS, has extensive experience managing coding operations across Pulmonology, Cardiology, and Family Practice specialties. A strategic thinker in healthcare data, Erin also specializes in Risk Adjustment and HEDIS compliance, helping practices maintain financial health while delivering exceptional, measurable patient care.