How to Prepare Your ABA Practice for a Documentation Audit

How to Prepare Your ABA Practice for a Documentation Audit

Most audit problems do not begin with anything dramatic. They start with a missing signature, a late session note, or a few units billed after an authorization expired.

Individually, these issues may look easy to fix. When the same problem appears across dozens of clients or over several months of claims, it becomes much harder to explain.

That is why an ABA practice shouldn't think about audit readiness only after receiving a records request. It should be built into the way sessions are scheduled, documented, reviewed, and billed every day.

This has become especially important as Medicaid-funded autism services receive greater regulatory attention. Recent federal audits have examined whether complete documentation, appropriate provider credentials, active authorizations, and billing supported payments.

The goal is not to make your team afraid of an audit. It’s to ensure your records clearly reflect the care your clinicians are already providing.

Why ABA Documentation Is Under More Scrutiny

The U.S. Department of Health and Human Services Office of Inspector General has completed several audits involving Medicaid payments for ABA and related autism services. Recent reviews in Colorado, Maine, Wisconsin, and Indiana identified improper or potentially improper payments tied to documentation, billing, credentialing, and authorization requirements.

In each review, all 100 sampled enrollee-months contained at least one claim line that auditors considered improper or potentially improper.

That finding sounds alarming, but it needs context. It does not mean that most ABA providers are intentionally billing incorrectly. Many of the problems identified involved records that did not adequately support the service, billable time, provider, or code listed on the claim.

A service can be clinically appropriate and still be questioned if the supporting record is incomplete.

During an audit, the reviewer does not have access to your staff’s memory or the conversations that happened in the clinic. The record has to stand on its own.

What Could Lead to an ABA Audit?

Some audits are routine. Others are connected to payer monitoring, complaints, credentialing concerns, unusual billing patterns, or a broader government review.

A sudden increase in billing volume may attract attention, but so can something as simple as repeated time overlaps. Claims may also be reviewed when a practice frequently bills a certain code, exceeds authorization limits, uses an incorrect rendering provider, or submits documentation that does not match the service.

None of these automatically proves that a claim was improper. The question is whether the practice can show what happened and why the claim was submitted the way it was.

Start with the Session Note

When preparing for a documentation review, session notes are the natural place to begin.

A reviewer should be able to read the note and understand when the service took place, who delivered it, what occurred during the session, and how the work related to the client’s treatment plan.

The exact requirements vary by payer, but a complete ABA session note will commonly include the date and location of service, start and end times, the rendering provider, treatment targets, interventions used, the client’s response, objective data, and the appropriate signature.

The note should also sound like it was written for that particular session. Repeated language is not necessarily a compliance problem, especially when treatment procedures remain consistent. However, notes that look nearly identical from one appointment to the next may not show enough about what actually happened.

Documentation for direct treatment should also look different from documentation for protocol modification or caregiver guidance. Each service represents different clinical work.

For more help with the content payers commonly expect, see this guide to writing ABA session notes for insurance.

Make Sure the Records Agree

One of the simplest ways to test your documentation is to select a claim and follow it backward.

Start with the submitted claim. Compare it with the session note, schedule, authorization, treatment plan, and provider record.

Do the dates match? Does the documented time support the number of units billed? Was the provider approved to perform that service on that date? Was the authorization still active?

The goal is not to make every record look identical. A scheduled appointment may have ended early because a client became sick, for example. In that case, the note and claim should reflect the time that was actually delivered rather than the original calendar block.

Problems often arise when different teams are working from different information. The scheduler may not know that an authorization is about to expire. Billing may not know that the provider’s credentialing status changed. A clinician may correct the session time in a note without realizing that the original time is still attached to the claim.

These small disconnects are easy to miss when information lives in different systems. Over time, they can create the kinds of inconsistencies that become difficult to untangle during an audit.

Check Authorization Details Before Looking at Billing

A well-written note does not make a service billable if the client did not have an active authorization for it.

When reviewing a claim, confirm that the date of service fell within the authorization period and that the service code was approved. Look at the number of units available, the number already used, and any restrictions related to the provider or place of service.

Pay close attention around reauthorization dates. A short gap between two authorization periods can leave a practice with services that were delivered but cannot be billed.

Practices sometimes track authorization balances in spreadsheets or update them only after claims are created. That makes it easier to discover a problem after the session has already happened.

A better process gives the scheduling team visibility into remaining units before appointments are booked. It also gives clinical leaders enough notice to complete reassessments and reauthorization paperwork before coverage runs out.

Confirm Who Actually Delivered the Service

Auditors may review whether the rendering provider had the necessary certification, license, enrollment, or supervision on the date of service.

This is more complicated than checking whether someone is currently credentialed. The record needs to show that the provider was eligible when the service took place.

For every staff member, the practice should be able to locate relevant certification and license information, payer enrollment dates, background checks when required, and supervision records. Any expiration or renewal dates should be monitored before they pass.

The rendering provider on the claim should also match the person who performed the service. If claims are submitted under a supervisor or another clinician by default, the practice may create records that do not accurately reflect who worked with the client.

Credentialing gaps can affect more than one claim. When a missed renewal is discovered months later, every service delivered during that period may need to be reviewed.

Does the Note Support the Billing Code?

A claim can contain the correct client information, date, and number of units while still using a code the documentation does not support.

This is particularly important for services such as protocol modification. If a BCBA bills for protocol modification, the note should explain what was observed, what clinical changes were made, and why those changes were necessary. A statement that the BCBA “provided supervision” may not be enough to support the service.

The same idea applies to caregiver guidance. The note should show that the caregiver participated and describe the guidance or skills addressed.

Flychain’s 2026 ABA CPT Codes and Reimbursement Guide offers a useful breakdown of commonly used ABA codes, including 97151, 97153, 97155, and 97156. It also explains why the provider’s credentials, modifiers, and documentation can affect whether a claim is paid correctly.

Their guide makes an important point for practice owners: understanding what a code pays is only part of the picture. The documentation still needs to support the work represented by that code.

Exact billing requirements differ across payers, so your payer contracts and current billing guidance should remain the final source of truth.

Pay Attention to Signatures and Late Entries

Missing signatures are easy to overlook because they do not change the clinical content of a note. From an audit perspective, though, the signature helps establish who completed or approved the record.

An internal review should look for unsigned notes, missing supervisor signatures, and records signed outside the payer’s required timeframe.

Your practice should also have a clear process for correcting documentation. Staff will occasionally notice that a time, location, or other detail was entered incorrectly. The correction should preserve the original record and show what changed, when it changed, and who made the change.

Backdating a note or replacing the original entry can create more concern than the initial mistake.

If your team needs clearer documentation expectations, the Council of Autism Service Providers offers ABA session note templates designed to support consistency across common ABA services. Templates still need to be adapted to payer rules and the individual client, but they can provide a useful starting point.

Review a Sample Instead of Everything at Once

An internal audit does not need to begin with thousands of claims. Starting too broadly can make the process feel unmanageable and leave the team with a long list of problems but no clear idea of what to fix first.

Choose a small group of claims from different clinicians, clients, service codes, and payers. Follow each claim through the entire workflow.

As you review the sample, write down anything that does not align. Then look for repetition.

If several clinicians are missing signatures, the answer may be a clearer completion process or additional training. If sessions regularly exceed authorization limits, the underlying issue may be how the schedule is created. Incorrect rendering providers could point to outdated credentialing information in the billing workflow.

The most useful finding is not always the individual error. It is the process that allowed the same error to happen more than once.

Warning Signs That Your Current Process Needs Attention

You probably do not need a formal audit to know when documentation has become difficult to manage.

Billing may regularly wait for unfinished notes. BCBAs may spend part of every week asking clinicians to add details or correct time entries. Authorization balances may be maintained in separate spreadsheets that only one person fully understands.

Another warning sign is how long it takes to answer a basic question. If leadership cannot quickly determine which notes are incomplete, whether a clinician was credentialed on a particular date, or how many units remain for a client, responding to a payer request may require a major manual effort.

That does not necessarily mean the underlying care or claim was wrong. It means the practice may have trouble proving that it was right.

This is one of the larger costs of disconnected systems in an ABA practice. Staff end up spending time comparing calendars, notes, spreadsheets, and billing records instead of addressing problems as they occur.

Where Practice Management Software Fits

Audit readiness still depends on staff training, clinical oversight, and a clear understanding of payer requirements. Technology cannot decide whether a service was clinically appropriate, but it can make missing or inconsistent information much easier to catch.

AI-generated session notes are a good example. Some clinicians may be tempted to paste session details into a general-purpose AI tool such as ChatGPT or Claude to save time. If those details include protected health information and the tool has not been approved by the practice, properly configured for healthcare use, and covered by the necessary agreements, that decision can put the practice’s HIPAA compliance at risk.

The problem is not simply that a tool uses AI. The risk comes from sending sensitive client information into an outside system without confirming how the data is stored, processed, accessed, or retained. Consumer AI accounts may not include the safeguards, access controls, or business associate agreement needed for handling PHI. Even a well-intentioned shortcut can move client information outside the practice’s protected environment.

Purpose-built systems handle this differently. Raven Health’s AI-generated session notes are created from the session data clinicians already collect inside the platform. Client information stays within Raven’s encrypted, protected workspace rather than being copied into a separate consumer AI tool.

The clinician can review the generated narrative, make changes, and finalize the record. That review is important. AI can help turn structured session data into a readable note, but the clinician remains responsible for confirming that the final documentation accurately reflects the session.

There is also a practical benefit. When the note begins with data already captured during treatment, clinicians do not have to retype sensitive details into another system. That reduces manual entry and makes it less likely that information will be lost between data collection and documentation.

When the same platform also connects the note to the schedule, authorization, provider record, and claim, the practice has a clearer trail from the service that occurred to the payment that was requested.

The goal is not to add AI for the sake of it. It is to give clinicians a safer way to reduce documentation time without moving sensitive information through tools that were never approved for that purpose.

Build Audit Readiness into the Routine

Waiting for a records request is one of the hardest ways to discover that documentation has been inconsistent.

A better place to start is with a handful of recent claims. Ask someone who was not involved in the original session to review the supporting records. Can that person understand what service was provided and why it was billed? If something does not make sense, an outside reviewer may have the same question.

Use those gaps to improve the process. That might mean clarifying note expectations, reviewing one service code with clinicians, or changing when authorization balances are checked.

The purpose of an internal audit is not to create more paperwork. It is to make sure the paperwork your team already completes accurately reflects the care being delivered.

When that happens consistently, an outside review becomes less about reconstructing the past and more about producing records your practice already knows are complete.

Conclusion

Being ready for an ABA documentation audit doesn’t have to mean adding more work to your team. Regularly checking session notes, billing, authorizations, and provider records can help you catch small issues before they become bigger problems. The goal is simple: keep your records accurate and make sure they clearly support the care your practice provides.

Please note: This article is intended for general informational purposes and is not legal, billing, privacy, or compliance advice. Requirements vary by payer, state, contract, service, and technology configuration.

Sources:

https://www.flychain.us/resources/aba-cpt-codes-reimbursement-guide

https://oig.hhs.gov/reports/work-plan/browse-work-plan-projects/srs-a-25-029/

https://www.casproviders.org/casp-session-note-templates

Keep Reading

All Articles
Differential Reinforcement in ABA
Blog

Differential Reinforcement in ABA

When a child or adult engages in challenging actions like yelling, hitting, or running away, caregivers often instinctively rely on reprimands or timeouts. However, Applied Behavior Analysis takes a completely different, highly positive route. Instead of focusing heavily on what an individual is doing wrong, therapists focus almost entirely on what they should be doing instead.

September 14, 2026
5 Signs Your ABA Practice Has Outgrown Its Documentation Workflow
Blog

5 Signs Your ABA Practice Has Outgrown Its Documentation Workflow

Running a growing Applied Behavior Analysis (ABA) practice is exciting, but growth can expose problems that were easy to manage when your team was smaller. One of the first places this becomes obvious is clinical documentation. A workflow that worked for five clinicians may become difficult to manage with 20. Session notes start piling up, BCBAs spend more time reviewing documentation, and small inconsistencies can eventually create problems with billing, authorizations, and clinical decision-ma

September 7, 2026
ABA Credentialing Guide for New Practices
Blog

ABA Credentialing Guide for New Practices

Starting a new ABA practice is an exciting venture, but before you can treat your first patient and collect your first payment, you have to clear a major administrative hurdle.

September 2, 2026
For Clinical Leads

See What Your Data Looks Like on Raven.

Bring one learner's data (or a screenshot of your current graphs) and we'll show you the same data in Raven's clinical view in under 30 minutes.

Book a Clinical WalkthroughSee Pricing
Collection Rate
98%+
Customers focus on therapy while Raven drives results.
Payment in as Little as
8 days
With less than a 1% claim denial rate.