Medical Billing Fraud: Reading an EOB Like an Investigator
Most medical billing fraud isn't a doctored PDF — it's honest-looking documents describing dishonest care. How to read the EOB, the bill, and the codes together.

Medical paperwork is dense, jargon-heavy, and boring to read closely — which is precisely why it's such fertile ground for document fraud. An explanation of benefits, a superbill, an itemized statement: each is a wall of codes and figures that most people skim and few can fully parse. Fraud hides comfortably in documents nobody wants to read line by line. Whether you're an insurer, an employer running a health plan, or a patient who suspects something's off, learning to read these like an investigator changes what you see.
Key takeaways
- Medical billing fraud is usually fabrication — services never rendered, or codes altered to inflate a claim — not tampering with a real bill.
- The EOB and the itemized bill should tell the same story; when they diverge, that's the thread to pull.
- Procedure codes are the fraud's fingerprints — upcoding, unbundling, and phantom services all live in the code lines.
- Document forensics catches altered artifacts; consistency and coding checks catch the fabricated ones.
The documents and what each is for
Three documents carry most of the signal:
- The EOB (explanation of benefits) — what the insurer says happened: services, allowed amounts, what was paid, what the patient owes. It's the payer's version of the story.
- The itemized bill / superbill — what the provider says happened: each service, its code, its charge. It's the provider's version.
- The claim — the coded submission that drove the payment.
Fraud shows up when these three disagree, or when one of them describes care that doesn't match reality. A patient who never had a procedure and an itemized bill that lists it are telling two different stories, and only one of them is true.
Where the fraud actually lives: the code lines
Most medical billing fraud isn't a doctored PDF — it's honest-looking documents describing dishonest care. That makes procedure and diagnosis codes the center of gravity:
- Upcoding — billing a more expensive service than the one provided. A routine visit coded as a complex one. The document looks perfect; the code is inflated.
- Unbundling — splitting a single bundled procedure into separate line items to bill more than the bundle allows.
- Phantom billing — charging for services, tests, or supplies never provided at all.
- Duplicate billing — the same service billed twice, sometimes across two documents so neither looks wrong alone.
None of these require editing a document, which is why a fraud program that only looks for tampering misses them. You catch them by cross-referencing the codes against the care, the dates, and each other.
How to read the documents together
Reconcile the EOB and the itemized bill. They describe the same episode. Line them up: do the services, dates, and amounts match? A charge on the itemized bill that never appears on the EOB, or a service on the EOB the patient has no memory of, is where you start asking questions.
Sanity-check the codes against the visit. Does the complexity of the coded service match what actually happened? Does a bundled procedure appear as suspiciously many separate lines? Do the dates of service line up with when the patient was actually seen? You don't need to memorize code sets to notice when the coded story is richer than the real one.
Check the provider and the dates. Phantom billing often uses real provider identities for services that didn't occur, or dates when the patient wasn't there. Confirming the provider is legitimate and the dates are plausible closes off a common route.
Where document forensics comes in
Not all of it is code-level. Some medical fraud is a tampered document — an altered itemized bill submitted to an employer for reimbursement, a fabricated superbill created to support a claim for care that never happened, a receipt for a treatment that was never rendered. Those carry the ordinary tamper and fabrication tells: fonts that don't match, figures typed over a template, metadata revealing the "scanned" bill was authored in editing software, a provider logo pasted at the wrong resolution. When a medical document is submitted as evidence — for reimbursement, for a claim, for an audit — authenticating the artifact is a real and necessary layer on top of the coding analysis. It's the same fabrication problem that runs through insurance claims generally.
Putting it together
The strongest approach runs two checks in parallel. Coding and consistency analysis catches the fraud that lives in genuine-looking documents describing false care — the majority of it. Document forensics catches the minority that's an actually-forged artifact. Neither alone is enough: a program that only authenticates documents waves through every phantom charge on a clean-looking bill, and one that only checks codes misses the fabricated receipt submitted for reimbursement. Read the documents against each other, read the codes against reality, and read the files themselves for tampering.
Frequently asked questions
What's the most common type of medical billing fraud?
Billing for services that were never rendered — phantom billing — along with upcoding, where a more expensive service is billed than the one provided. Both live in genuine-looking documents, so they're caught by cross-referencing codes against the actual care, dates, and other documents, not by looking for a tampered file.
How do I check an EOB for fraud?
Reconcile it against the itemized bill and your own memory of the care. Confirm the services, dates, and amounts match across both documents, question any service you don't recognize, and sanity-check that the coded complexity matches what actually happened. Divergence between the payer's story (EOB) and the provider's story (itemized bill) is the key signal.
Can document forensics detect medical billing fraud?
It detects the portion that's a forged or altered artifact — a fabricated superbill, an altered itemized bill, a fake treatment receipt — using the usual tamper tells. It won't catch fraud that lives purely in the codes on a genuine document, like upcoding or phantom services; that requires coding and consistency analysis. The two together cover both halves.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
How Insurers Catch Fake Receipts in Claims
Inflated and invented receipts quietly tax every insurance book. Here's how claims teams separate genuine proof of purchase from edited and generated fakes — without slowing honest claims.
Fake Certificates of Insurance: How to Spot Them Before They Cost You
A COI is a promise printed on one page — and one of the most-faked business documents. What a certificate actually proves, the red flags, and how to verify one properly.
The Padlock Lies: What HTTPS Actually Proves
The padlock is the most misunderstood symbol on the internet. It certifies the pipe, not the shop — and almost every phishing page you will ever see has one.