Skip to content

Risk Adjustment Data Validation (RADV): A 2026 Guide for Medicare Advantage Plans

For most of the last decade, a RADV audit was something a Medicare Advantage plan might face once every several years, if at all. That math has changed. In May 2025, CMS said it would start auditing every eligible MA contract every year and grow its coder workforce from about 40 people to roughly 2,000. If your plan submits risk-adjusted diagnoses to Medicare, the question is no longer whether you will be audited. It is whether your medical records can back up the codes you sent when the auditors ask.

This guide walks through what Risk Adjustment Data Validation actually is, how a RADV audit works step by step, the two rule changes that raised the financial stakes, and the documentation practices that hold up when a certified coder is reading your charts line by line.

What is Risk Adjustment Data Validation (RADV)?

Risk Adjustment Data Validation is the process CMS uses to confirm that the diagnoses a Medicare Advantage organization submitted for payment are supported by a patient’s medical record. In plain terms: CMS pulls a sample of your members, asks for the charts, and checks whether the conditions you coded were really documented by a provider during a face-to-face visit.

Why does this matter for payment? Medicare Advantage runs on risk adjustment. CMS pays each plan a fixed amount per member per month, then adjusts that amount based on how sick each member is. Diagnoses map to Hierarchical Condition Categories (HCCs), each HCC carries a risk weight, and those weights roll up into a member’s risk score. A member with diabetes, heart failure, and chronic kidney disease generates a higher payment than a healthy member, because their care costs more.

That system only works if the diagnoses are real. A RADV audit is the check on that. When a coded HCC has no supporting documentation in the record, CMS treats the payment tied to it as an overpayment and takes the money back. So RADV sits at the intersection of coding accuracy, clinical documentation, and revenue, and it is where sloppy documentation turns into a repayment.

A quick distinction that trips people up: CMS-RADV covers Medicare Advantage (Part C). HHS-RADV is a separate program for the ACA individual and small group markets, run annually by HHS, and it works differently. When someone says “RADV” without context in the Medicare world, they almost always mean the CMS Medicare Advantage audit.

How a RADV Audit Works, Step by Step

The mechanics are more predictable than the anxiety around them suggests. Here is the sequence.

1. CMS selects contracts to audit

CMS picks the MA contracts it will review for a given payment year. Historically it targeted a small number of contracts, often ones flagged by data analytics as higher risk for coding errors. Under the 2025 expansion, the plan is to audit all eligible contracts each year rather than a subset.

2. A sample of enrollees is drawn

Within each selected contract, CMS pulls a stratified random sample of enrollees, sorted into groups by risk score so that high-, medium-, and low-risk members are all represented. In the older audit design this sample sat around 200 members per contract. The 2025 changes push the number of records reviewed per plan higher, scaling with plan size.

3. CMS requests the medical records

For each sampled member, CMS asks the plan to submit medical records that support the HCCs it coded that year. The plan gets to choose the single best record for each condition, the one document it believes most clearly supports the diagnosis. This is the moment where retrievability matters. If you cannot locate a clean, complete, provider-signed record fast, you are already behind.

4. Certified coders review the documentation

CMS coders read each record and decide whether it supports the coded diagnosis under the applicable coding guidelines. They are checking for a real, documented condition addressed during a valid encounter, not a code that appeared on a claim with nothing behind it. A diagnosis that is coded but not supported is a discrepancy.

5. Errors are calculated and extrapolated

CMS tallies the unsupported diagnoses, recalculates what the member’s risk score should have been, and figures the payment error. Then it applies that error rate across the whole contract, not just the sampled members. That extrapolation step is what turns a few hundred charts into a recovery that can reach the tens of millions of dollars.

The Two Changes That Raised the Stakes

RADV existed for years without keeping many CFOs up at night, because the financial exposure was limited. Two policy moves changed that.

The 2023 RADV Final Rule

In January 2023, CMS finalized the rule that governs how it recovers RADV overpayments, and it settled two long-running fights in CMS’s favor.

  • Extrapolation is back, starting with payment year 2018. Before this, CMS generally recovered only on the specific members it audited. Now the error rate found in the sample gets applied across the contract’s full membership. That single change is the biggest reason RADV liability grew from a rounding error to a board-level number.
  • No Fee-for-Service Adjuster. Plans and AHIP had argued for an offset to account for the fact that the risk model is itself built on fee-for-service data that contains its own diagnosis errors. CMS declined to apply that adjuster, and estimated it would recover roughly $4.7 billion over ten years as a result.

Health plans challenged the rule in court, but the core principles held: audit findings extrapolate, and there is no FFS offset softening the blow.

The 2025 audit expansion

Then came the operational escalation. In May 2025, CMS announced it would clear its RADV backlog and audit far more aggressively going forward. The specifics:

  • Audit all eligible MA contracts every year, up from roughly 60 plans annually.
  • Increase the number of records reviewed per plan, up to about 200 records for larger plans versus the previous 35.
  • Grow the medical coder workforce from about 40 to roughly 2,000 by September 1, 2025.
  • Lean on AI-assisted review to flag diagnoses that look unsupported and route those records to human coders.
  • Complete audits for payment years 2018 through 2024 on an accelerated timeline.

Read together, the 2023 rule set the financial penalty and the 2025 announcement set the frequency. A plan that once faced occasional audits with limited downside now faces annual scrutiny with contract-wide recovery on the line.

The CMS-HCC V28 Backdrop

None of this is happening in a vacuum. CMS is phasing in the CMS-HCC V28 risk adjustment model across payment years 2024 through 2026, blending it with the older V24 model along the way. V28 removed a large number of diagnosis codes from risk adjustment and raised the documentation bar for others. That means the set of conditions that even count toward payment is shifting at the same time CMS is auditing more of them. Coding to V28 correctly, and documenting to match, is now part of audit readiness rather than a separate project.

Where Plans Actually Get Caught

RADV findings tend to cluster in a handful of predictable places. The OIG has published audit after audit pointing at the same weak spots.

  • Health risk assessments with no follow-up. An in-home HRA that identifies a condition but never leads to treatment or a confirming provider visit is a classic soft spot. OIG and MedPAC have both flagged in-home assessments as a high-risk source of unsupported diagnoses.
  • Chart reviews that add codes without support. Retrospective chart reviews that append HCCs a provider never documented during an actual encounter do not survive an audit.
  • Problem lists carried forward. A diagnosis copied into the EHR problem list year after year, without a provider actively addressing it in a given year, fails the documentation standard.
  • Records that cannot be found. Sometimes the diagnosis was legitimate and the documentation existed, but the plan could not retrieve a clean, signed copy in time. That still counts against you.

The common thread is the gap between what was coded and what a provider actually monitored, evaluated, assessed, or treated during a real visit. That standard has a name.

Documentation That Survives an Audit: The MEAT Standard

Coders use the shorthand MEAT to describe what a record needs to show for a chronic condition to be codable: the provider Monitored, Evaluated, Assessed, or Treated it during the encounter. A diagnosis on a claim is not enough. The chart has to show the condition being actively managed by the provider, with the note signed and dated.

Practically, that means:

  • The condition appears in the provider’s assessment, not just a dropdown or a copied problem list.
  • There is evidence of clinical action: a medication, an order, a referral, a plan, a status note.
  • The encounter is a valid face-to-face visit with an acceptable provider type.
  • The documentation is legible, complete, and authenticated with a signature and credential.

If your provider notes routinely satisfy MEAT, most of your RADV exposure takes care of itself. If they do not, no amount of retrospective coding cleverness fixes it.

How to Prepare for a RADV Audit?

Audit readiness is less about a fire drill when the request letter arrives and more about a year-round posture. The plans that do well share a few habits.

Run your own mock RADV audits. Pull a stratified sample the way CMS would, request the best record for each HCC, and have a second coder review it against the guidelines. You want to find the unsupported diagnoses before CMS does, while you can still act on them.

Fix documentation at the source. Provider education on MEAT documentation does more for your error rate than any downstream cleanup. Coders can only work with what the clinician wrote. If the note does not support the code, the note is the problem.

Know where every diagnosis came from. Encounter data, chart reviews, and HRAs carry different audit risk. If you cannot trace a submitted HCC back to its source and its supporting record, treat that as a gap to close now.

Make records retrievable in days, not weeks. RADV response windows are tight. A plan that has to chase paper charts across a dozen provider groups will lose supportable diagnoses simply because it could not produce the record in time. Centralized, indexed, quickly searchable record retrieval is an audit-defense asset.

Reconcile your data sources. When claims, EHR feeds, and supplemental data disagree about a member’s conditions, you need one governed source of truth rather than three conflicting versions. Auditors do not care which system a diagnosis lived in; they care whether the record backs it up.

Layer prospective and retrospective review. Prospective coding gets conditions documented correctly at the point of care. Retrospective review catches what slipped through. You need both, and neither should be adding codes that clinical documentation does not support.

The plans that struggle usually treat RADV as a coding-department problem. The plans that hold up treat it as a data and documentation problem that happens to surface in an audit.

Frequently Asked Questions

What does RADV stand for in healthcare? RADV stands for Risk Adjustment Data Validation. It is the audit CMS uses to verify that the diagnoses a Medicare Advantage plan submitted for risk-adjusted payment are supported by the patient’s medical record.

What is the difference between RADV and HHS-RADV? CMS-RADV audits Medicare Advantage (Part C) plans. HHS-RADV is a separate, annual program for the ACA individual and small group markets, run by HHS, with its own methodology. They share the “validate the diagnoses” idea but are different programs with different rules.

What is extrapolation in a RADV audit? Extrapolation means CMS applies the error rate it finds in the audited sample across the entire contract’s membership, rather than recovering only on the specific members it reviewed. The 2023 Final Rule reinstated extrapolation starting with payment year 2018, which is what made RADV recoveries so much larger.

What is the RADV Final Rule? The 2023 RADV Final Rule set how CMS recovers overpayments. It confirmed that audit findings extrapolate to the full contract from payment year 2018 forward, and that CMS will not apply a Fee-for-Service Adjuster to offset those recoveries.

How many records does CMS request in a RADV audit? It varies. The older design sampled roughly 200 enrollees per contract and asked for the best supporting record per HCC. Under the 2025 expansion, CMS increased the records reviewed per plan, up to about 200 for larger plans, and moved to auditing all eligible contracts each year.

What is MEAT documentation? MEAT stands for Monitor, Evaluate, Assess, Treat. It is the standard coders use to decide whether a chronic condition is supported: the record must show a provider actively managing the condition during a valid, signed encounter, not just a code on a claim.

How can a Medicare Advantage plan prepare for RADV? Run internal mock audits, train providers on MEAT documentation, trace every submitted diagnosis back to a retrievable supporting record, reconcile conflicting data sources into one source of truth, and be able to produce clean records quickly when the request arrives.

RADV used to be an occasional inconvenience. After the 2023 Final Rule brought back extrapolation and the 2025 expansion made annual audits the norm, it is now a standing financial risk that lives or dies on documentation quality. The plans that will come through the next round of audits in good shape are not the ones with the cleverest coding shops. They are the ones whose provider notes actually show the condition being treated, and who can put their hands on the record that proves it within days. Start there, audit yourself before CMS does, and the extrapolation math stops being a threat.