Remote Surgical Auditing: Best Practices from the Home Office
Article Reference Code: NAMAS.07.17.2026
Written by: John Piaskowski, CPC-M, CPC-I, CIRCC, CCC, CPMA, CCVTC, CGIC, CGSC, CUC, COSC, CRC
In the role of a remote surgical auditor (and this might be accurate for E/M coders as well), we are put at a slight disadvantage, in many ways. First, we rely heavily upon the stated context within the signed documentation. Full stop. Any use of external data sources, references and other clinical medical records other than the ones we are auditing will impact our audit findings, either in a positive way or a negative way. We also have limited access to the providers that we audit. Our relationships and interactions are minimal, at best.
So, there are best practices that a surgical auditor (or other type of auditor) will need to conform to, in order to come to produce optimal findings and recommendations. However, there are 2 major influences on these “best practice” situations: Whether we have full access to the medical record or limited access to the medical record; and whether we have the capacity to foster quick and beneficial relationships with our providers.
Having access to the full medical record, for a home office auditor, involves being granted EMR access and the ability to navigate the patient’s chart for cases relevant data. Keep in mind that HIPAA security rules about “minimum necessary” are always to be followed in these situations where we have seemingly unrestricted (but audit-trail-monitored) access.
Have a limited access to the full medical record usually involves an arrangement where the records to be audited are given to you in a compliant, secure manner. The HIPAA security rules about use and disclosure need to be followed.
In either situation, whether you have full access or limited access to the patient’s medical record, the fine dividing line between a good and a great auditor will not be the ability to effectively use available resources, (like medical record or clinical charts), but will be the ability to effectively use those available resources without be unduly swayed into make invalid assessments. This is a pitfall we all try to avoid, but rarely self-check ourselves on.
Best Practices:
- Keep our access to medical data compliant. This is one that is a good general rule… of law. The HIPAA Security rule has strict guidelines for ensuring complaint storage and access of medical records. Treat our home office like you would an onsite physician office. Do not discuss cases with anyone not privy to the audit. Do not save files, images or identifiable records (or portions thereof) in emails, printed format or as saved digital format. Shred printouts, delete emails, send encrypted files, if needed, delete files when done. NEVER share login access to the EMR, audit system or email.
- Limited yourself to only reviewing SIGNED records by the audited provider when forming audit findings and recommendations. Including information that is found in un-attested-to records will likely attribute to an invalid finding. Also, using un-attested documentation make the audit indefensible.
- An example that I commonly see, as a surgical auditor is using information about moderate sedation from the cardiac catheterization report. Note: When a cardiac catheterization is completed, usually a 2nd similarly named file is created that contains raw data of the procedure without a provider attestation and signature. This is the data file in which a provider pulls information for a final operative report. If the moderate sedation information such as drug, dosage, and time under supervision does not make it into the signed record, this creates a validity issue. Has this data been validated by the provider to be reported?
- Another example is when the provider does not indicate the dimensions of an excised tumor in the operative report that they signed. Are we, as auditors permitted to seek out that information in a 3rd party report (like a pathology report) for the answer? Note: Unless our surgeon is also the pathologist, it is unlikely to be attested to and signed by our surgeon.
- The last best practice is to review the documentation to the best of your clinical understanding. If you have the need, you can research your deficiencies to find an answer. If there are still questions that arise even after you thoroughly research for better understanding, then this might be a deficiency in the provider’s documentation. In this case, this might not be an auditing “error” that is marked against the provider’s score, but it might be an opportunity for documentation improvement.
I prefer to have discussion for improvement over discussion about errors. This approach builds trust and a relationship based on a positive outlook and not negative outlook. Even if the documentation is sound and appropriate, but coding errors still persist. The best approach is to address corrections as opportunities, as opposed to errors. Remember, in the remote setting, it is harder to build a friendly relationship with provider due to the limited accessibility, so we need to be approachable and more receptable as possible in the little time we interact.

Contact John LinkedIn by Clicking his Name Below:
John Piaskowski, CPC-M, CPC-I, CIRCC, CCC, CPMA, CCVTC, CGIC, CGSC, CUC, COSC, CRC
NAMAS BLOG Disclaimer:
The views expressed in this article are solely those of the author and are based on her professional experience as a risk adjustment auditor and educator.
The NAMAS Blog features content written by both NAMAS staff and guest contributors. Guest contributors may present opinions or perspectives that differ from those officially instructed or encouraged by NAMAS. We believe in providing space for a range of informed viewpoints to foster dialogue, reflection, and deeper understanding within the auditing and compliance community.
Some contributors may use artificial intelligence (AI) tools in the development of their content. The decision to incorporate AI is left to the discretion of the author and does not reflect an endorsement or directive from NAMAS.
If you have questions, comments, or concerns about a specific blog post, we encourage you to contact the individual author directly. Their name and contact information are provided at the end of each post.











