top of page

Healthcare Audit Readiness: Key Risk Areas Providers Should Review Before Year-End

Updated: Jul 22

Healthcare audit readiness poster with stethoscope and checklist, showing key risk areas and icons for revenue, payroll, cybersecurity, grants, and controls

Healthcare organizations operate in a complex environment where financial reporting, reimbursement, compliance, technology, and patient data all connect.

That is why healthcare audits can become challenging when year-end preparation starts too late. Audit issues often arise because estimates are not updated, reconciliations are incomplete, documentation is missing, or controls were not reviewed before fieldwork begins.


For healthcare leaders, year-end audit readiness is not just about gathering documents after the fact. It is about identifying the areas most likely to create audit delays, financial statement adjustments, control deficiencies, or compliance concerns.


Here are several healthcare audit risk areas providers should review before year-end.


1. Patient Service Revenue and Accounts Receivable


Patient service revenue is often one of the most complex areas in a healthcare audit because the amount billed is usually not the amount expected to be collected.

Healthcare providers may need to consider contractual adjustments, implicit price concessions, self-pay balances, charity care, denials, payor mix, Medicare and Medicaid reimbursement, managed care contracts, and subsequent collections.


Before year-end, management should ask:


  • Are contractual allowance estimates current?

  • Are AR aging reports reviewed for collectability?

  • Are denial trends considered in revenue and allowance estimates?

  • Are credit balances reviewed and resolved?

  • Is the billing system reconciled to the general ledger?

  • Are significant estimates supported by current data?


Revenue and AR estimates should be supported by more than historical percentages. They should reflect current collection experience, payor activity, denials, write-offs, and known changes in reimbursement.


2. Third-Party Payor Settlements


Third-party payor activity can create audit risk when receivables, payables, recoupments, or settlement estimates are not updated timely.

This may include Medicare cost report settlements, Medicaid activity, managed care settlements, value-based arrangements, prior-year adjustments, recoupments, overpayments, appeals, or open disputes.


Before year-end, management should ask:


  • Are settlement receivables and payables reconciled?

  • Are estimates supported by filed cost reports, correspondence, remittance data, or known settlement activity?

  • Were prior-year estimates compared to actual settlements?

  • Are appeals or disputes documented?

  • Are recoupments and overpayments reviewed for proper classification?


Settlement estimates should be reviewed before the audit begins so management can support the assumptions used in the financial statements.


3. Payroll, Staffing, and Credentialing


Payroll is often one of the largest expenses for healthcare organizations. Staffing shortages, contract labor, overtime, bonuses, physician compensation, and benefit accruals can all increase audit risk.


Healthcare organizations should review payroll-related balances and controls before year-end, including payroll accruals, PTO liabilities, contract labor, incentive compensation, physician agreements, grant-funded payroll, and credentialing records.


Before year-end, management should ask:


  • Are payroll registers reconciled to the general ledger?

  • Are PTO and benefit accruals reviewed?

  • Are contract labor arrangements properly classified?

  • Are bonus and incentive compensation amounts supported?

  • Are physician or provider compensation arrangements documented?

  • Are credentialing and licensing records current?

  • Are payroll allocations supported if costs are charged to grants or restricted funding?


Payroll issues can affect both financial reporting and compliance, especially when labor costs are allocated across programs, locations, grants, or funding sources.


4. Cybersecurity, HIPAA, and Vendor Access


Cybersecurity is no longer just an IT issue. In healthcare, it can affect operations, billing, patient data, vendor access, cash flow, compliance, and audit readiness.

Healthcare organizations should understand who has access to billing systems, accounting platforms, banking information, payroll data, patient information, and vendor portals.


Before year-end, management should ask:


  • Are terminated employees removed from systems timely?

  • Are user access rights reviewed periodically?

  • Is multi-factor authentication used where appropriate?

  • Are administrator privileges limited and approved?

  • Do vendors have access to sensitive systems or data?

  • Are backup and recovery procedures documented?

  • Is the HIPAA risk analysis current?

  • Are incident response procedures documented?


HHS emphasizes the importance of HIPAA Security Rule safeguards, risk analysis, and risk management to help protect electronic protected health information and reduce cybersecurity vulnerabilities.


5. Grants, Federal Awards, and Compliance


Some healthcare organizations receive federal, state, or local funding. This may include grants, workforce funding, research awards, provider-related funding, or other restricted support.


When healthcare organizations receive federal awards, audit risk increases if the organization does not clearly track allowable costs, period of performance, reporting requirements, payroll allocations, procurement requirements, subrecipient monitoring, or Schedule of Expenditures of Federal Awards activity.


Before year-end, management should ask:


  • Did the organization expend federal awards during the year?

  • Could federal expenditures trigger a Single Audit?

  • Are award files complete?

  • Are costs supported and allowable?

  • Are payroll allocations documented?

  • Are procurement requirements followed?

  • Are reporting requirements tracked?

  • Are internal controls over compliance documented?


The Single Audit threshold is currently $1,000,000 in federal awards expended during the fiscal year for applicable periods, and auditees should consider the effective date rules when evaluating whether a Single Audit is required.


6. Internal Controls and Documentation


Many audit issues are not caused by the transaction itself. They are caused by missing documentation, undocumented review, or controls that are not performed consistently.

Healthcare organizations should review whether key controls are designed to prevent, or detect and correct, errors in areas such as revenue estimates, AR allowances, payor settlements, payroll, user access, vendor access, journal entries, reconciliations, grants, and financial reporting.


Before year-end, management should ask:


  • Are reconciliations current and reviewed?

  • Is review evidence documented?

  • Are significant estimates supported?

  • Are exceptions investigated and corrected timely?

  • Are key approvals retained?

  • Are policies aligned with actual practice?

  • Would the audit team be able to inspect evidence that controls operated?


A review that is not documented may be difficult to distinguish from no review at all. If management is relying on review as a control, the review should leave evidence showing who reviewed it, when it was reviewed, what was reviewed, what criteria were used, and how exceptions were resolved.


Year-End Healthcare Audit Readiness Checklist


Before the audit begins, healthcare leaders should consider whether the organization has:


  • reconciled billing system reports to the general ledger

  • reviewed AR aging, denials, credit balances, and subsequent collections

  • updated contractual allowance and collectability estimates

  • reconciled third-party payor receivables and payables

  • reviewed payroll accruals, PTO, benefits, and contract labor

  • documented provider compensation arrangements

  • reviewed user access and vendor access

  • updated cybersecurity and HIPAA risk documentation

  • organized grant and restricted funding files

  • reviewed lease, debt, and major agreements

  • updated related-party information

  • documented management review controls


Helpful Resources



Final Thoughts


Healthcare audits are challenging because financial reporting, reimbursement, compliance, operations, and technology are closely connected.

A smoother audit starts before fieldwork. It starts with current reconciliations, supported estimates, documented controls, organized grant files, and leadership attention to the areas most likely to create risk.


This post is part of our Healthcare Audit Readiness Series, where we break down the audit risk areas that commonly affect healthcare providers, nonprofits, and organizations receiving federal or state funding.


If your healthcare organization needs help preparing for an audit, strengthening internal controls, reviewing revenue and AR estimates, or improving audit readiness, our office can help.

Hours

Monday–Friday | 8:00 a.m.–5:00 p.m. CT

© 2026 JConner PC. All rights reserved.

JConner
Assurance + Tax + Advisory

  • Facebook
  • Linkedin
  • AICPA SOC for Service Organizations logo

Privacy Policy

Terms & Conditions

Cookie Policy

Record Retention & Destruction

Client Portal & Electronic Communication

Website Accessibility Statement

bottom of page