Defensible HCC Coding: A 2026 Audit-Ready Guide

Defensible HCC Coding Audit Guide

Risk adjustment has quietly changed jobs. For years the work was about capture, finding every condition a chart could support and turning it into a code. In 2026 the work is about proof. With the 2024 CMS-HCC model fully in place and Risk Adjustment Data Validation audits back in motion, the question an auditor asks is no longer whether a diagnosis exists, but whether you can show exactly where it was documented and how it was clinically supported.

That shift is why defensibility now matters more than volume. A program that adds codes it cannot substantiate is not building revenue, it is building liability. This guide walks through what makes coding defensible, what changed for 2026, and how a disciplined, two-way workflow keeps a program audit-ready without leaning on unsupported diagnoses.

The Vocabulary That Matters

Defensible HCC Coding The Vocabulary That Matters

A few terms carry most of the weight in any risk adjustment conversation, so it helps to pin them down before going further.

A Hierarchical Condition Category, or HCC, groups related diagnoses that predict similar future costs. Each maps from ICD-10-CM codes and carries a weight that feeds the enrollee’s risk score.

MEAT is the documentation test, shorthand for Monitor, Evaluate, Assess and Treat. A diagnosis meets it when the note shows the provider actively managing the condition during a face-to-face encounter, not merely listing it.

Two-way coding means a review both adds supportable diagnoses that were missed and removes ones the record does not support. It is the single clearest signal that a program is coding for accuracy rather than for a higher score.

What Raised the Bar for 2026

Several forces converged this year to make thin documentation far more expensive than it used to be. Understanding them explains why defensibility has moved to the center of the conversation.

Audits Now Reach Every Eligible Plan

Regulators moved from auditing a small slice of contracts each cycle to reviewing every eligible Medicare Advantage plan in newly initiated audits going forward, with larger record samples per contract. A 2025 federal court ruling did pause the extrapolation of error rates across a whole contract, but it did not pause the audits themselves, and recoveries on individual sampled records continue. In practical terms, no plan can assume it will stay outside the sampling window any longer.

Enforcement Is Real and Recent

The consequences are not hypothetical. Federal enforcement actions have resolved risk adjustment cases for sums ranging from the low tens of millions to hundreds of millions, several of them turning on programs that submitted diagnosis codes yet never removed the unsupported ones their own reviewers had flagged. The pattern regulators punish is add-only coding, and it is worth studying closely.

V28 Demands More Specificity

The 2024 CMS-HCC model, often called V28, is now fully phased in. It removes more than 2,000 diagnosis codes that previously mapped to a category, expands the payment categories from 86 to 115, and recalibrates the weights on chronic conditions such as diabetes and its complications. The result is a higher bar for the specificity and evidence behind every risk score.

What MEAT Looks Like in a Note

MEAT is easy to define and easy to fail. The gap is almost always specificity: a note that names a condition but shows no clinical attention to it will not survive review, however real the diagnosis is.

A concrete example makes it clear. Picture a single visit for a patient with heart failure and diabetes. A defensible note reads like active management, something close to “assessed leg swelling, adjusted diuretic dose, ordered follow-up labs in one week.” That one line shows the condition was monitored, evaluated and treated during the encounter, which is exactly what an auditor is looking for.

The common failure mode is copy-forward. Pasting last year’s assessment into this year’s note weakens the record rather than supporting it, because it shows no current-year clinical thinking. Each condition needs language tied to what actually happened at that visit.

Five Principles of Defensible Coding

Five Principles of Defensible Coding

Defensible scores come from a repeatable discipline rather than a one-time cleanup. These five principles hold every diagnosis to the same standard an auditor would apply.

1. Tie every diagnosis to a face-to-face encounter within the payment year. Conditions pulled from a chart review or a health risk assessment with no matching provider visit are the first thing an audit challenges.

2. Meet the MEAT standard. A chronic condition sitting in a problem list with no clinical context around it does not qualify, however obviously real it may be.

3. Revalidate chronic conditions every year. Risk scores reset annually, so heart failure, COPD, major depression and diabetes with complications all need fresh, current-year documentation to remain defensible.

4. Justify severity. Under V28, uncomplicated diabetes may no longer map to a category while diabetes with chronic complications carries real weight, so the note has to spell out that level of detail.

5. Preserve data integrity. Keep records organized and retrievable, with a clear trail of which coder reviewed the chart, what evidence supported the code and when the review happened.

Two-Way Coding Is the Real Test

If there is one habit that separates a defensible program from an exposed one, it is the willingness to delete. Most retrospective reviews only hunt for missed codes, and that add-only posture is exactly what regulators now read as intent to inflate payments. The discipline of defensible HCC coding, the approach RAAPID builds its platform around, means running the review in both directions: capturing supportable diagnoses that were missed, and removing any that lack encounter linkage or current-year support.

The practical tell is a metric. A defensible program tracks its add-to-delete ratio and treats a review that never deletes anything as a warning sign, not a success. When a program can show it removed unsupported codes on its own initiative, it walks into an audit with a very different story than one that only ever added.

Add-Only vs Two-Way at a Glance

Add-only coding Two-way coding
Finds missed codes only Finds missed codes and removes unsupported ones
Optimizes for a higher score Optimizes for a defensible score
Keeps no record of deletions Tracks the add-to-delete ratio
Reads as revenue intent Reads as accuracy intent
Appears in enforcement cases Built to survive an audit

Where AI Fits, and Where It Does Not

The volume of charts in a retrospective cycle makes some automation almost unavoidable, and used well it genuinely helps. Software can triage charts by likely value and risk, pull the relevant passages from a long note, route unclear cases into provider queries and assemble an evidence packet in a fraction of the time a manual pass would take.

The important word is assist. The same phased, guardrailed approach that other industries use when adopting AI into workflows applies just as much here: let the software surface evidence and move work between steps, but keep a certified coder approving every code before it is submitted. A model that nudges a reviewer toward an unsupported diagnosis is not a shortcut, it is a liability, and published compliance guidance calls that pattern out directly.

Handled with that discipline, automation reinforces defensibility rather than undermining it. It flags unsupported diagnoses for removal, keeps the evidence trail attached to each suggestion and frees coders to spend their judgment where it actually counts, on the calls a machine should never make alone.

An Audit-Ready Workflow, Step by Step

The principles above turn into practice through a workflow that bakes evidence in at every stage rather than checking for it at the end.

  • Prioritize charts by likely value and audit exposure, so the highest-risk records get attention first.
  • Map documented conditions to ICD-10-CM against the current V28 category structure.
  • Verify MEAT on every diagnosis, and hold back anything the note does not actively support.
  • Code both directions, adding supportable diagnoses and deleting unsupported ones, routing unclear cases to provider queries.
  • Apply a second-review QA gate with a recorded coder sign-off before anything advances.
  • Assemble each evidence packet, the source note, encounter date, code and coder attestation, into one exportable record aligned to audit fields.
  • Confirm dates, signatures and mappings before submission, and store records where they can be retrieved fast.

The Evidence Standard to Meet

Every submitted diagnosis has to trace back to a dated source note from a face-to-face visit, coded per ICD-10-CM and supported by a coder attestation. Missing dates, absent signatures or a vague source reference are the weak points an auditor finds first.

Retention runs long. Plans are expected to hold the relevant records for ten years, and audit rights extend for a comparable window, so a defensible program treats storage and retrievability as part of the job rather than an afterthought.

How Audits Are Different Now

The audit itself works differently than it did even a year ago. CMS reviews records to confirm that submitted diagnoses are supported in the chart, and when one is not, it can be removed and the related overpayment recovered. That basic mechanic has not changed, but its reach has.

Two shifts matter most. Sample sizes climbed from a handful of records per plan to as many as 200 in newly initiated audits, so a documentation gap that once hid in a small pull is now far more likely to surface. And the agency has expanded the review workforce and technology behind these audits, which compresses the timeline a plan has to respond on.

The practical consequence is that audit readiness is no longer a periodic exercise. A program has to treat every submitted diagnosis as if it will be sampled, because across a payment year the odds that some of them will be are now much higher.

Common Failure Patterns to Avoid

Auditors see the same weaknesses repeatedly, and each is avoidable. Add-only reviews that never delete anything top the list, followed by diagnoses drawn from health risk assessments with no supporting care behind them.

The rest are largely hygiene: packets missing dates or coder signatures, history-of conditions coded as if they were active, and any automated prompt that pushes an unsupported code. None of these require exotic fixes, only the discipline to catch them before submission.

A Quick-Start Checklist

  • Update codebooks and mappings to the V28 category structure.
  • Refresh coder training on MEAT and two-way review.
  • Mock-audit a sample of charts against the face-to-face encounter rule.
  • Document a ten-year retention procedure.
  • Map every evidence packet field to audit requirements.
  • Add a QA gate with a recorded coder sign-off.
  • Log every deletion, not only the additions.
  • Set a firm rule that automation never finalizes a code on its own.

The Bottom Line

Risk adjustment has moved from a revenue exercise to a discipline that sits at the intersection of clinical documentation, compliance and workflow. The plans that thrive under the 2026 rules are the ones that can prove every diagnosis, not just assert it.

Defensible coding is how that proof gets built: encounter-linked documentation, honest two-way review, a clear evidence trail and automation kept firmly on a leash. Get those right and the legitimate revenue is not lost, it is simply waiting to be claimed with confidence.

Frequently Asked Questions

What makes HCC coding defensible?

Coding is defensible when every submitted diagnosis traces to a dated, face-to-face encounter note, meets the MEAT standard and can be followed from chart to claim. Defensibility goes past accuracy to include clinical reasoning and a documented, repeatable process an auditor can verify.

Why does two-way coding matter so much now?

Add-only programs that submit codes but never remove unsupported ones now read as intent to inflate payments, and recent enforcement actions have targeted exactly that pattern. Running reviews in both directions shows regulators a program codes for accuracy rather than revenue.

What changed under the V28 model?

The 2024 model removes more than 2,000 previously mapped diagnosis codes, expands the payment categories from 86 to 115 and recalibrates weights on chronic conditions. Coding teams need to refresh codebooks, mappings and training to reflect the tighter specificity it demands.

Should AI finalize HCC codes on its own?

No. Automation can triage charts, surface evidence and route work between steps, but a certified coder should approve every code before submission. Any tool that pushes a reviewer toward an unsupported diagnosis adds risk rather than removing it.

How long do risk adjustment records need to be kept?

Plans are generally expected to retain the relevant records for ten years, with audit rights extending for a comparable period. A defensible program treats organized, retrievable storage as part of the workflow, not a separate task.

Master the Art of Video Marketing

AI-Powered Tools to Ideate, Optimize, and Amplify!

  • Spark Creativity: Unleash the most effective video ideas, scripts, and engaging hooks with our AI Generators.
  • Optimize Instantly: Elevate your YouTube presence by optimizing video Titles, Descriptions, and Tags in seconds.
  • Amplify Your Reach: Effortlessly craft social media, email, and ad copy to maximize your video’s impact.