Home/Risk Adjustment Coding Services
CMS-HCC V28 · Certified coders · 95%+ accuracy floor

Risk adjustment coding services, owned by a certified coder.

Risk adjustment is the one place in the revenue cycle where a diagnosis, not a charge, moves the money. That makes every code a compliance artefact as well as a revenue one. We read the whole record, code what the documentation supports, delete what it does not, and leave a trail a reviewer can follow line by line. CMS-HCC V28 carries 100 percent of the risk score for payment year 2026, so any model still built on the old crosswalk is already wrong.

Reviewed by Aparna Suresh, CPB Updated September 17, 2026 Second read on every batch

What it is, and who it is for

Diagnosis data is revenue data in a risk-bearing contract.

In fee-for-service the procedure pays and the diagnosis justifies it. Under risk that inverts. CMS assigns each Medicare Advantage beneficiary a Risk Adjustment Factor score built from demographics and from the conditions reported during the data collection year, and the monthly payment is scaled by that score. The same logic drives shared-savings benchmarks, capitation and much of Medicaid managed care. A real, treated, documented condition that is never coded leaves the contract funded as though the patient were healthier. A coded condition the record does not support is an overpayment waiting to be recovered. Four buyers bring us this, and it is not the same problem.

WhoWhat usually breaksWhat we run
Medicare Advantage plansRisk at the member levelSubmission and deletion discipline across a delegated network, plus exposure sitting in prior-year codes the charts no longer support.Retrospective review at scale, deletion review on prior submissions, an evidence file per member.
ACOs and value-based groupsBenchmark and shared savingsUnder-capture for three quarters, then a rushed year-end sweep that produces volume rather than accuracy.Prospective preparation ahead of the annual wellness visit, with concurrent review on the gap-heavy service lines.
Groups in capitated contractsDownside riskNotes that support the clinical work but not the category, because nobody told the clinician which words it requires.Concurrent review plus a feedback loop that names the gap by clinician, not by department.
FQHCs and health centresManaged care and wrapThin coding capacity, high social complexity, conditions managed by care teams that never reach a coded encounter.A light concurrent pass on the active panel and a targeted retrospective sweep on the most complex members.

In health centres the coding gap often sits downstream of an enrolment gap, because an unenrolled clinician's encounters never reach the payer at all. See our credentialing and payer enrolment services.

CMS-HCC V28, payment year 2026

The phase-in is over. V28 is the whole score now.

CMS introduced V28 in the CY2024 Rate Announcement and blended it in over three payment years, so scores were part V24 and part V28 through 2024 and 2025. For payment year 2026 the blend ends and V28 carries the full weight. Anyone still modelling RAF on a V24 crosswalk, or comparing scores year over year without normalising for the model change, is reading a number that does not mean what they think it means.

What changedThe detailWhat it means for coding
Built on ICD-10-CMMapping foundationV28 maps ICD-10-CM directly and renumbers the categories, so a V24 HCC number does not identify the same category.Reports and suspect lists keyed to V24 numbers have to be rebuilt, not relabelled.
Categories reorganisedPayment HCC setThe payment category count increased and several disease families were resegmented, changing which hierarchy a diagnosis lands in.Codes once interchangeable within a family are no longer equivalent. Specificity decides the category.
Conditions constrained or removedCoefficientsCMS constrained or removed coefficients where reporting varied widely between organisations, collapsing diabetes complication tiers and removing several vascular and angina categories.Volume strategies stop working. Lift now comes from genuinely under-documented conditions.
Specificity tightenedMalnutrition, depression, othersCategories now turn on severity and specificity being stated in the record rather than implied by it.The fix is upstream in the note. A coder cannot code severity a clinician did not write.
Coefficients renormalisedModel-wideThe coefficient set was renormalised, and CMS applies an annual normalisation factor and coding pattern adjustment on top of the raw score.Raw RAF movement is not performance movement. Compare like for like or the comparison is noise.

Category-by-category detail, with the documentation language each tightened category requires, is in our HCC V28 coding reference. To model the arithmetic on your own panel, use the free RAF score calculator.

Prospective, retrospective, concurrent

Three review modes. Most organisations need two of them.

These are not competing philosophies. They are different points in the patient year, and each catches what the others cannot.

Before the visit

Prospective review

A coder reads the history before the encounter and hands the clinician a short list: conditions needing evaluation this year, and the specificity each category requires. It is the only mode that changes what gets written rather than how it is read afterwards, and clinicians accept it because it arrives as preparation.

At the point of documentation

Concurrent review

The chart is reviewed while the encounter is open and a query can still reach the clinician who saw the patient. This is where V28's specificity requirements are actually met, because severity and linkage get clarified while the visit is fresh. Highest cost per chart, highest yield per chart.

After the fact

Retrospective review

The closed record for the data collection year is read end to end. It does two jobs the others cannot: find supported conditions never coded, and find submitted codes the record does not support, which have to be deleted. A programme that only adds and never deletes is not a coding programme, it is an exposure programme.

On most engagements we recommend prospective preparation on the active panel plus a targeted retrospective sweep on the highest-complexity members, adding concurrent review where documentation gaps cluster in one service line.

RADV and data validation audits

Code as if the chart will be pulled, because it can be.

Risk Adjustment Data Validation is how CMS confirms that submitted diagnoses are supported by the medical record. In a final rule published on February 1, 2023, CMS set out that it would extrapolate RADV findings beginning with payment year 2018 and would not apply a fee-for-service adjuster. A sampled error is therefore no longer a sampled loss. Alongside RADV, plans face data validation audits of their Part C and Part D reporting, and exchange organisations face the parallel HHS-RADV process. None of this changes what good coding looks like. It changes what an unsupported code costs. Our audit posture is in the workflow, not bolted on when a notice arrives:

  • Every submitted code traces to an encounter, date of service, provider type and signature.
  • Deletion review runs alongside capture, so unsupported prior submissions are corrected.
  • Coder reasoning is recorded, including why a suspect was declined.
  • Acceptable provider type and face-to-face rules are checked before a diagnosis is accepted.
  • Signature and credential validity are confirmed, because an unsigned note supports nothing.
  • Evidence packets can be produced per member, in the format a reviewer expects.

When a request does land, the work is retrieval and assembly rather than reconstruction, because the evidence was captured at the moment the code was assigned.

Chart to code

The workflow, and where the coder gate sits.

Four steps. The gate is the third one, and it does not move.

Intake

Scoping and transfer

Records arrive through your EHR, a secure transfer or a release-of-information vendor. We confirm the collection year, the cohort, the model version and what was submitted before. Nothing is read until the scope is agreed in writing.

Surfacing

AI narrows the field

The record is scanned, candidate conditions are ranked, and prior-year submissions with no current support are flagged. This produces a shortlist. It produces no codes.

The gate

Certified coder decides

A certified coder reads the record. Each candidate is accepted with the encounter and provider that support it, or declined with a reason. Each unsupported prior submission is marked for deletion. Nothing passes on a confidence score.

Second read

Audit and delivery

An independent auditor re-reads a sample of every batch against the accuracy floor. Findings go back to the coder and into provider feedback. Then the adds, the deletions and the evidence file ship together.

Quality control and what you receive

A number you can audit, and a file you can hand over.

Our public accuracy standard for coding work is 95 percent or better, measured by an independent second-read auditor on sampled charts rather than by the coder who did the work. A batch that misses the floor is re-read before it ships. Senior partners, not account managers, own the quality conversation.

ControlHow it works
Second readAn independent auditor re-reads a drawn sample of every batch. Nobody audits their own work.
Accuracy floor95 percent or better on audited samples. A miss triggers a re-read of the batch, not a note in a report.
Deletion parityDeletion review is scoped and measured alongside capture. A programme that only adds is not audited work.
Declined-suspect logEvery declined candidate is logged with its reason, which is what shows the review was clinical rather than acquisitive.
Provider feedbackGaps reported by clinician and category, with the documentation language that category requires, so the gap does not recur.

What lands on your side at the end of a cycle: accepted adds with their supporting encounter, date of service and rendering provider; deletions with the reason the record fails them; a RAF movement summary separating model-driven change from documentation-driven change; documentation gaps by clinician and category; and the evidence file, per member, ready for a reviewer.

The surfacing layer behind the second step is described on our AI for HCC coding page and in the HCC risk adjustment AI overview. Neither replaces the coder gate.

How engagements start

A sample, a scope, a written rate.

A senior partner takes the first call. We ask what you are risk-bearing under, what the panel looks like, what was submitted last cycle and what tooling you already own. Then we read a small sample of de-identified records, because the per-chart rate depends on specialty mix and record complexity rather than a rate card. From that sample comes a scope, a per-chart rate in writing, a turnaround commitment and the quality terms, including how the accuracy floor is measured. Nothing starts before a business associate agreement is executed. If your problem sits upstream of coding, we will say so: under-capture is often an enrolment gap, a scheduling gap in annual wellness visits, or templates that make specificity harder.

Questions we get asked

Risk adjustment coding, answered plainly.

What does a risk adjustment coder do?
A risk adjustment coder reads the full clinical record for a patient year and assigns the ICD-10-CM diagnoses the documentation actually supports, then confirms which of them map to a payment HCC. It is not charge capture. It is proving each reported condition was evaluated or treated in the year by an acceptable provider type, documented to the specificity the category requires, and signed. The coder also flags what is missing: a problem-list condition with no supporting encounter, and a code submitted last year the current record no longer supports.
What is risk adjustment in coding?
Risk adjustment is how payers pay more for sicker populations and less for healthier ones, so an organisation is not penalised for enrolling complex patients. In coding terms the diagnoses you submit, not the services you bill, drive part of the revenue. CMS builds a risk score for each Medicare Advantage beneficiary from demographics plus the conditions reported during the data collection year, and payment is scaled by that score. Because money follows diagnosis data, accuracy is a revenue question and a compliance question at once.
What is HCC coding?
HCC stands for Hierarchical Condition Category, the grouping layer CMS puts between ICD-10-CM codes and payment. Thousands of ICD-10-CM codes map into a smaller set of payment HCCs, and each category carries a coefficient. Hierarchical means that within a disease family only the most severe reported condition counts; a lesser category in the same hierarchy is suppressed rather than added. HCC coding is the discipline of getting the diagnosis specific enough to land in the right category and documented well enough to survive a look back.
What changed in V28?
CMS-HCC version 28 was introduced in the CY2024 Rate Announcement and phased in over three payment years, reaching 100 percent of the risk score for payment year 2026. V28 maps ICD-10-CM directly, renumbers the categories so V24 numbers no longer line up, expands the payment category set, and constrains or removes coefficients for conditions CMS found were reported with wide variation. Diabetes complication tiers collapsed, several vascular and angina categories were removed, malnutrition and depression tightened, and coefficients were renormalised. Specificity now matters more than volume, and any RAF model built on a V24 crosswalk is wrong for 2026. Category detail sits in our HCC V28 coding reference.
How is RAF score calculated?
A Risk Adjustment Factor score starts with a demographic component from age, sex, Medicaid status, disability status and institutional status. CMS then adds the coefficient for every payment HCC supported by the diagnoses reported in the data collection year, applying the hierarchies so only the most severe condition in a family counts, plus the disease and disabled interaction terms the model defines. The raw score is then adjusted by the annual normalisation factor and the Medicare Advantage coding pattern adjustment. Our free RAF score calculator runs the arithmetic on your own numbers.
How much do risk adjustment coding services cost?
Risk adjustment coding is priced per chart, and the rate moves with volume and with the specialty and complexity of the records. A single specialty ambulatory chart with a short problem list is not the same unit of work as a multi specialty record with an inpatient stay and two years of history, so a single published rate would be dishonest. We quote after seeing a sample of the records and the scope. Our pricing page sets out how we structure coding, credentialing and RCM engagements, and a senior partner gives you a per chart number in writing before any work starts.
Is AI replacing risk adjustment coders?
No. AI is good at surfacing candidates: scanning a record in seconds, ranking suspected conditions, flagging where last year's submitted code has no support this year. It is not accountable. Our position is fixed. AI surfaces, a certified coder owns every code. No suspected condition becomes a submitted diagnosis without a human coder confirming the documentation supports it, and the coder's decision, not a confidence score, is what goes on the record. An auditor will ask for that, because a model output is not a defence in a RADV review.

Sources and review

Primary sources for everything above.

Model rules, phase-in schedule and audit policy here come from CMS and the Federal Register, not secondary commentary.

Reviewed for accuracy

Reviewed by Aparna Suresh, CPB

President and Founder, ASP-RCM Solutions. AAPC-certified Professional Biller. Updated September 17, 2026.

Aparna reviews ASP-RCM coding and compliance guidance before publication. Engagements are senior-led, and every code on a risk adjustment engagement is owned by a certified coder. See the senior team →

Find out what your charts actually support.

Send a small sample of de-identified records. A senior partner reads them, tells you where the capture and the exposure are, and gives you a per-chart rate in writing.