Picture two Medicare Advantage members. Both are 72 years old. Both live in the same ZIP code. One walks three miles a day and takes a single blood pressure medication. The other manages type 2 diabetes with kidney complications, congestive heart failure, and COPD.
If a health plan received the same monthly payment for both members, the math would break almost immediately. Plans would compete to enroll the healthiest people and avoid the sickest ones. Risk adjustment coding exists to prevent exactly that. It translates a patient’s documented diagnoses into a risk score, and that risk score determines how much CMS pays the plan to care for that person.
In 2026, this process carries more financial and regulatory weight than at any point in its 20-plus-year history. Three things converged at once:
- The CMS-HCC V28 model is now fully phased in. Payment year 2026 is the first year risk scores are calculated 100% under V28, which removed thousands of diagnosis codes from the payment model.
- RADV audits went from occasional to universal. In 2025, CMS announced it would audit every eligible Medicare Advantage contract every year, roughly 550 contracts, and said it planned to clear its audit backlog covering payment years 2018 through 2024 by early 2026.
- The dollars are enormous. More than 34 million people, over half of all Medicare beneficiaries, are enrolled in Medicare Advantage. MedPAC’s March 2025 report estimated that MA payments would run about $84 billion higher in 2025 than the cost of covering the same enrollees in traditional Medicare, with coding intensity named as a major driver.
Put simply: the codes your organization submits are worth more scrutiny, and are getting more scrutiny, than ever before. This guide covers how risk adjustment coding actually works, what changed under V28, how to build a compliant and accurate coding program, and where AI-enabled workflows fit in
What Is Risk Adjustment Coding?
Risk adjustment coding is the process of capturing and reporting a patient’s diagnoses, through ICD-10-CM codes supported by clinical documentation, so that payers and CMS can calculate an accurate risk score for that patient. That risk score, called a Risk Adjustment Factor (RAF) score in Medicare Advantage, adjusts the monthly capitated payment a plan receives for each member.
The core idea is fairness in payment. A plan caring for a member with multiple chronic conditions should receive more funding than a plan caring for a healthy member, because the expected medical costs are higher.
A few things distinguish risk adjustment coding from everyday fee-for-service coding:
- It is diagnosis-driven, not procedure-driven. CPT codes determine payment in fee-for-service. In risk adjustment, ICD-10-CM diagnosis codes drive payment.
- Chronic conditions must be recaptured every year. RAF scores reset each January 1. A member’s diabetes documented in 2025 contributes nothing to their 2026 risk score unless it is documented and coded again during a 2026 face-to-face encounter.
- Documentation standards are stricter. A diagnosis on a problem list is not enough. The condition must be supported in the medical record, typically evaluated against MEAT criteria (more on that below).
Who relies on risk adjustment coding?
- Medicare Advantage plans, which live and die by RAF accuracy
- ACOs and ACO REACH entities, where benchmarks and shared savings depend on risk scores
- MSOs and medical groups in capitated or delegated arrangements, where downstream revenue flows through risk-adjusted payments
- ACA marketplace plans, which use the HHS-HCC model for the individual and small group markets
- Medicaid managed care plans, many of which use CDPS or state-specific models
How Risk Adjustment Coding Works: HCCs and RAF Scores Explained
Step 1: Diagnoses become ICD-10-CM codes
During a face-to-face encounter (including qualifying telehealth visits), a provider documents the patient’s conditions. A coder, or increasingly an AI-assisted coding workflow with human review, translates that documentation into ICD-10-CM codes. ICD-10-CM contains over 74,000 diagnosis codes, but only a fraction of them affect risk-adjusted payment.
Step 2: Codes map to Hierarchical Condition Categories (HCCs)
CMS groups clinically related, cost-predictive diagnosis codes into Hierarchical Condition Categories (HCCs). Diabetes with chronic complications, congestive heart failure, and major depressive disorder each map to their own HCC. A sprained ankle does not, because it doesn’t predict future cost.
The “hierarchical” part matters. Within a disease hierarchy, only the most severe manifestation counts. If a member has diagnoses mapping to both “diabetes with chronic complications” and “diabetes without complications,” only the more severe category contributes to the score.
Step 3: HCCs produce a RAF score
Each HCC carries a coefficient, a relative weight reflecting expected cost. Add up the member’s demographic factors (age, sex, dual-eligibility status, disability status, institutional status) plus their disease coefficients plus any disease-interaction factors, and you get the RAF score.
- A RAF of 1.0 represents average expected cost.
- A healthy 68-year-old might score around 0.4.
- A member with CHF, diabetes with complications, and COPD might score 2.5 or higher.
Step 4: RAF scores adjust payment
The plan’s base county rate is multiplied by the member’s RAF score (after CMS applies a normalization factor and the statutory 5.9% coding intensity adjustment) to produce the monthly payment. Small per-member differences compound quickly: a 0.1 RAF difference can be worth roughly $1,000 or more per member per year. Across 50,000 members, that’s a $50 million swing.
Key point: Risk adjustment coding accuracy is not about maximizing scores. It’s about making the score match the patient’s true, documented clinical reality. Undercoding starves care programs of funding. Overcoding creates audit liability and False Claims Act exposure.
What Changed for 2026: The V28 Model Is Fully Here
The CMS-HCC V28 model phased in over three payment years: 33% in 2024, 67% in 2025, and 100% in 2026. For the first time, there is no V24 blend cushioning the transition. What V28 says is what you get paid.
The headline changes under V28
- More HCC categories, fewer payable codes. V28 expanded from 86 HCCs to 115, reflecting reclassification under ICD-10 rather than ICD-9 logic. At the same time, roughly 2,000+ ICD-10-CM codes that mapped to a payment HCC under V24 no longer do under V28.
- Constrained diabetes coefficients. The three diabetes HCCs now carry equal weight, which removed the payment difference between “diabetes with complications” and “diabetes without complications” that drove years of documentation queries.
- Removed or narrowed categories. Several conditions that were frequent targets of coding-intensity programs lost payment status or were restructured, including a number of vascular disease, angina, and drug/alcohol use codes.
- Lower average risk scores. CMS projected the model change alone would reduce MA risk scores by roughly 3% relative to V24, though the actual impact varies widely by population and by how dependent an organization’s historical RAF was on codes that V28 removed.
What this means for coding teams in practice
- Recapture discipline matters more, not less. With fewer payable codes, every legitimately documented chronic condition carries relatively more weight. Missing an annual recapture of CHF or CKD stage 4 hurts more under V28.
- Suspecting logic built for V24 is now actively misleading. If your prospective workflows still surface V24-payable conditions that no longer map, you’re spending provider time chasing codes with zero payment relevance.
- Specificity is the new intensity. V28 rewards precise, well-documented staging (CKD stages, heart failure type, depression severity) rather than volume of loosely supported diagnoses.
Prospective vs. Retrospective Risk Adjustment Coding
Most mature programs run both motions. The balance between them is shifting.
Retrospective coding: the look-back
Retrospective programs review charts after encounters happen, typically through second-level coder review or chart retrieval projects, to find documented conditions that were never coded and submitted.
- Strengths: Recovers legitimately documented diagnoses; useful for sweeps ahead of submission deadlines.
- Weaknesses: It can’t fix documentation that never happened. If the provider never assessed the condition during a face-to-face visit, there is nothing compliant to capture. Retrospective-heavy programs also correlate with the “found diagnoses” patterns that RADV auditors and the DOJ scrutinize most closely.
Prospective coding: getting it right at the point of care
Prospective programs surface suspected and historical conditions before or during the visit, so the provider can evaluate, document, and code them in real time.
- Strengths: Produces documentation and codes together, which is the most defensible position in an audit. Improves care, because conditions get clinically addressed, not just coded. Aligns naturally with annual wellness visits and pre-visit planning.
- Weaknesses: Requires real workflow infrastructure: unified member data, suspecting logic current with V28, and a way to put insights in front of providers without adding clicks.
The 2026 reality: With universal RADV audits and extrapolated recoveries in play, the industry center of gravity has moved decisively toward prospective, point-of-care accuracy backed by strong documentation, with retrospective review repositioned as a validation and completeness check rather than the primary revenue motion.
MEAT Criteria: The Documentation Standard That Decides Audits
A diagnosis code is only as good as the note behind it. The widely used standard for whether documentation supports a risk-adjusted diagnosis is MEAT:
- M – Monitor: signs, symptoms, disease progression or regression (“A1c trending down, continue current regimen”)
- E – Evaluate: test results, medication effectiveness, response to treatment
- A – Assess/Address: ordering tests, discussion, review of records, counseling
- T – Treat: medications, therapies, referrals, procedures
A condition listed on a problem list with no supporting narrative fails MEAT. So does “history of” language applied to an active condition, or a diagnosis carried forward by copy-paste with no evidence the provider addressed it at that visit.
Documentation habits that survive RADV review
- Document each chronic condition’s status and plan at least once per year during a face-to-face encounter.
- Use the most specific ICD-10-CM code the documentation supports. “Diabetes, unspecified” when the note describes stage 3 CKD from diabetic nephropathy leaves both accuracy and defensibility on the table.
- Avoid problem-list-only coding. Auditors validate against the encounter note, not the problem list.
- Watch linking language. Causal relationships (“CKD due to type 2 diabetes”) must be documented, not inferred by the coder, except where ICD-10-CM assumption rules explicitly apply.
- Kill the copy-paste note. Cloned documentation is one of the fastest ways to get an entire chart’s diagnoses questioned.
RADV Audits in 2026: What Every Compliance Team Should Know
Risk Adjustment Data Validation (RADV) is CMS’s mechanism for verifying that submitted diagnoses are supported by medical records. Three developments define the current environment:
- Extrapolation is live. Under the 2023 RADV final rule, CMS extrapolates audit findings across a contract’s population starting with payment year 2018, without applying a fee-for-service adjuster. An error rate found in a sample can be projected into a contract-level recovery worth tens or hundreds of millions of dollars.
- Audit coverage went universal. CMS’s 2025 announcement moved RADV from auditing roughly 60 contracts per year to all eligible contracts annually, backed by a plan to expand its coder workforce from around 40 to approximately 2,000 and to use technology to accelerate record review.
- The DOJ is active in parallel. False Claims Act cases against major MA organizations over unsupported diagnoses have continued, and whistleblower activity around one-way chart review programs (adding codes but never deleting unsupported ones) remains a live risk.
The compliance takeaway: every organization submitting risk adjustment data should be able to answer, for any member, “show me the face-to-face encounter note that supports this HCC.” If your internal audit can’t do that reliably today, an external one eventually will.
Common Risk Adjustment Coding Errors (and What They Cost)
- Unsupported diagnoses. The classic RADV failure: a submitted code with no MEAT in the encounter documentation. This is the error extrapolation punishes hardest.
- Missed annual recapture. A member’s amputation status, HIV status, or CKD doesn’t disappear on January 1, but their RAF contribution does if no one documents the condition that year. Recapture rates below roughly 80-85% usually signal a workflow gap, not a healthier population.
- Under-specificity. Coding “heart failure, unspecified” when documentation supports chronic systolic CHF. Under V28’s tighter mappings, vague codes frequently map to nothing.
- Coder-inferred causal links. Assigning combination codes (diabetes with CKD) when the provider never linked the conditions and no assumption rule applies.
- Acute codes carried as chronic. A resolved acute condition (an old CVA coded as active stroke rather than late effects, for example) inflates the score and hands auditors an easy finding.
- Stale suspecting lists. Chasing V24-era codes that no longer carry payment weight burns provider goodwill and coder hours with no return.
Building a High-Performing Risk Adjustment Coding Program: 7 Best Practices
1. Unify your data before you optimize your coding
Suspecting logic is only as good as the data feeding it. Claims, EHR feeds, ADT events, labs, pharmacy, and HIE data need to resolve to a single member record. When a care manager and a risk adjustment coder see different condition histories for the same member, both accuracy and compliance suffer.
2. Make prospective review the default motion
Deliver condition insights inside the pre-visit and point-of-care workflow: what was documented last year, what lapsed, what clinical evidence suggests an unaddressed condition. The provider confirms or refutes with the patient in the room, which is where compliant documentation is born.
3. Rebuild suspecting logic natively for V28
Retire V24 logic entirely. Prioritize conditions that are payable under V28, clinically probable for the member, and due for annual recapture.
4. Treat coder education as a continuing program
The FY2026 ICD-10-CM update, V28 mapping changes, and evolving Coding Clinic guidance all land on coders’ desks. Certified risk adjustment coders (CRC credential through AAPC is the common standard) need protected time for ongoing education, not just production quotas.
5. Audit yourself the way CMS would
Run routine internal RADV-style validation: sample submitted HCCs, pull the encounter documentation, and score MEAT support. Track your error rate over time and, critically, delete unsupported codes when you find them. Two-way review is both a compliance obligation and your best legal defense.
6. Give providers feedback loops, not scorecards alone
Provider-level recapture and documentation-quality reporting works best when it comes with specific chart examples and quick education, ideally embedded in the tools they already use. Blame-oriented RAF scorecards produce gaming; workflow-embedded nudges produce documentation.
7. Measure the right KPIs
- Annual chronic condition recapture rate (by condition and by provider)
- MEAT-support rate from internal audit samples
- Suspect confirmation rate (how often prospective suspects are clinically validated)
- Coding turnaround time from encounter to submission
- Deletion rate alongside addition rate, because a program that only ever adds codes is a red flag
Where AI and Automation Fit in Risk Adjustment Coding
AI has moved from pilot projects to production in risk adjustment workflows, and 2026-era programs generally use it in four places:
- NLP-driven chart review. Natural language processing reads unstructured notes at scale, flagging documented-but-uncoded conditions and MEAT evidence for human coders to validate. The compliant pattern is AI-assisted, human-confirmed, never auto-submitted.
- Suspecting and prioritization. Machine learning models combine claims history, labs, pharmacy fills, and utilization signals to rank which members most likely have unaddressed, payable, clinically real conditions, so provider attention goes where it matters.
- Point-of-care surfacing. Instead of a PDF gap report emailed monthly, condition insights appear inside the clinical workflow at the moment of the visit, often as an overlay on the existing EMR.
- Pre-submission validation. Automated checks catch hierarchy conflicts, unsupported combination codes, and codes lacking a qualifying encounter before data goes to CMS, shrinking audit exposure at the source.
The organizations getting real returns from AI in risk adjustment share one trait: they solved data unification first. A model scoring suspects off an incomplete member record produces confident nonsense.
Frequently Asked Questions About Risk Adjustment Coding
What is risk adjustment coding in simple terms?
It’s how a patient’s documented health conditions get turned into a risk score that determines how much a health plan is paid to cover that patient. Sicker, more complex patients generate higher scores and higher payments, so plans are funded fairly for the care their members actually need.
What does HCC stand for in coding?
HCC stands for Hierarchical Condition Category. CMS groups thousands of ICD-10-CM diagnosis codes into these categories based on clinical similarity and expected cost. Under the V28 model used for payment year 2026, there are 115 payment HCCs.
What is a good RAF score?
There’s no universally “good” RAF score, because the right score is the one that accurately reflects the population. The average is normalized around 1.0. What programs should evaluate instead is recapture rate, documentation support rate, and whether year-over-year RAF movement is explained by real clinical change.
Do diagnoses need to be recaptured every year?
Yes. Risk scores reset every calendar year. A chronic condition only contributes to the current year’s RAF score if it was documented during a qualifying face-to-face (or eligible telehealth) encounter in that year and submitted with a supported ICD-10-CM code.
Can AI replace risk adjustment coders?
No, and compliant programs don’t try. AI is highly effective at reading charts at scale, surfacing suspects, and pre-validating submissions, but certified coders make the final call on code assignment and providers remain responsible for documentation. The workable model is AI-assisted review with human confirmation.
Who can perform risk adjustment coding?
Most organizations require certified coders. The Certified Risk Adjustment Coder (CRC) credential from AAPC is the most common specialty certification, and CPC or CCS-credentialed coders with risk adjustment training are also widely used.
How does risk adjustment coding affect patient care?
Done properly, it improves care. Prospective risk adjustment surfaces chronic conditions for annual clinical evaluation, which means lapsed conditions get re-assessed and treatment plans get updated. The revenue it protects funds care management, quality programs, and supplemental benefits.