Short answer: yes, if the note was actually reviewed and signed by the clinician, every amendment is traceable, and the documented content supports the billed code. No, if the AI-drafted note was auto-signed without review or the practice cannot show who changed what and when. An auditor does not check whether AI wrote the note. They check whether it survives the same tests any note has to survive, and AI changes how the note gets drafted, not what an auditor is actually looking for.
That distinction matters because the anxiety about AI notes and audits usually points at the wrong risk. The real audit risk was never "a machine helped write this." It is an unreviewed note nobody actually attested to, documentation that cannot be traced back to who changed it and why, or content that does not support the code billed. AI documentation can make any of those worse or better depending entirely on how the tool is built, not on whether AI was involved at all. Oasys was built around that distinction specifically: the four checks below are the ones that actually determine audit outcomes, and each one is a design choice, not a side effect of using AI.
This draws on Oasys's ongoing conversations with practice owners who ask this exact question before adopting AI documentation, and Oasys's own seat at the infrastructure layer of practices running AI-assisted notes through real audits already.
Was the note actually reviewed, or auto-signed?
This is the single question that matters most, and it is also the easiest one for a practice to get wrong by accident. An AI tool that drafts a note and signs it automatically, without a clinician reviewing and actively attesting to it, has not produced a clinical note. It has produced an unattested document with a name attached.
Oasys keeps the draft fully editable until a clinician signs it, and the signature is the clinician's own action, not something the system does on their behalf. The note is not locked or attached to a claim until that signature happens. Other platforms may be built differently, and the question worth asking any AI documentation vendor directly is whether signing is an active step a clinician takes or a default the system applies.
Does the note reflect the actual session, or generic boilerplate?
Group and individual note audits both flag the same pattern: documentation that reads like a template with details swapped in, rather than something that actually reflects what happened in that specific session. This was already a risk before AI, the classic version being eight nearly identical group notes with different names at the top, and a poorly built AI tool can reproduce that failure mode at greater speed rather than fix it.
Oasys generates notes that reflect the clinical modality of the session, not just a transcript of the conversation, which is why review tends to land closer to a few minutes rather than the longer rewrite a raw transcript would require. A note built this way is structured clinical documentation specific to that session, not a boilerplate shell.
Is every amendment fully traceable?
An audit does not just check the note as it stands today. It can ask about a note that was corrected after the fact, and a practice needs to be able to show exactly what changed, who changed it, why, and when it was re-signed. A system that allows silent edits to a signed note is a liability regardless of whether AI was involved in drafting it.
Oasys keeps the full record on an amended note: who unlocked it, the reason given, the content before and after the change, and when it was re-signed. Nothing is overwritten silently. That record is what a practice actually produces if a payer asks about a specific note months later.
Does the documented content support the billed code?
This is the test that has nothing to do with AI directly and everything to do with whether documentation and billing are the same record or two records that can drift apart. A note has to support the time and content the billed CPT code claims. A 60-minute code needs 53-plus minutes of documented content behind it, not a note that could describe any length of session.
Oasys generates the CPT-coded claim directly from the signed note, so the code billed and the documentation behind it are the same record rather than two versions assembled separately. A mismatch is something a clinician can see before signing, not something an auditor finds first.
The transcript question, honestly
One more piece worth addressing directly: does keeping the raw session transcript help or hurt in an audit? It is tempting to assume more raw material is always safer. It is not that simple. A persisted transcript is a second, more detailed record of the session, separate from the clinical note, and it can be reached independently, including by subpoena, which creates its own exposure regardless of audit outcome.
Oasys removes the transcript from the record once the note is signed and locked, so what remains is the finished clinical note, the record an auditor actually reviews, not a verbatim log that could read differently from the note itself. Other platforms may retain the full transcript indefinitely, which is worth asking about directly rather than assuming is the safer default.
What auditors actually check, regardless of how the note was written
Medical necessity: does the documented content justify the service billed.
Timely signature: was the note signed within the timeframe the payer or regulation requires, not weeks later.
Content specific to the session: not a template with swapped details.
A code the documentation actually supports: time-based codes need the documented minutes; group and family codes need the participant and presence details they require.
A traceable record if anything was changed after signing.
None of these five checks are specific to AI-assisted documentation. Oasys is built to pass all five as a baseline, not as a special AI-specific safeguard bolted on separately.
How Oasys handles it
Oasys keeps every draft editable until the clinician actively signs it, so a signature always reflects real review. Notes are generated to reflect the session's clinical modality rather than a generic template. Every amendment to a signed note is fully tracked: who unlocked it, why, the content before and after, and when it was re-signed. The claim is generated directly from the signed note, so the documentation and the billed code are always the same record. The transcript is removed once the note is signed and locked, leaving the finished note as the audit-facing record.
FAQ
Does an insurance auditor care whether AI wrote a therapy note? Not directly. They care whether the note was reviewed and signed by the clinician, whether any later changes are traceable, and whether the content supports the billed code. AI involvement is not itself a flag; an unreviewed or untraceable note is.
Can an AI-drafted note be auto-signed without a clinician reviewing it? On some platforms, yes, and that is the actual risk worth avoiding. Oasys keeps the draft editable until the clinician takes the active step of signing it, so the signature always reflects real review rather than a system default.
What happens if a note needs to be corrected after it was signed? It should be fully traceable: who unlocked it, the stated reason, the content before and after, and when it was re-signed. A system that allows silent edits to a signed note is a liability in an audit regardless of how the note was originally drafted.
Does keeping the raw session transcript make a practice more audit-ready? Not necessarily. A persisted transcript is a second, more detailed record of the session that exists separately from the note and can be reached independently, including by subpoena. The note an auditor reviews is the clinical record; a surviving transcript is additional exposure, not automatic protection.
How do I know if a documented session actually supports the CPT code billed? The note needs to reflect the actual time and content the code requires: a 60-minute individual code needs 53-plus minutes of documented content, and group or family codes need the specific participant and presence details those codes require. If the code and the documentation are generated from two separate systems, that mismatch is easy to miss until an auditor finds it.
The note that holds up to an audit is not the one written fastest. It is the one a clinician actually reviewed, signed knowingly, and can trace every later change to, whether AI drafted the first version or not.
Mariam Shaker··


