Risk adjustment coding services, owned by a certified coder.
Risk adjustment is the one place in the revenue cycle where a diagnosis, not a charge, moves the money. That makes every code a compliance artefact as well as a revenue one. We read the whole record, code what the documentation supports, delete what it does not, and leave a trail a reviewer can follow line by line. CMS-HCC V28 carries 100 percent of the risk score for payment year 2026, so any model still built on the old crosswalk is already wrong.
What it is, and who it is for
Diagnosis data is revenue data in a risk-bearing contract.
In fee-for-service the procedure pays and the diagnosis justifies it. Under risk that inverts. CMS assigns each Medicare Advantage beneficiary a Risk Adjustment Factor score built from demographics and from the conditions reported during the data collection year, and the monthly payment is scaled by that score. The same logic drives shared-savings benchmarks, capitation and much of Medicaid managed care. A real, treated, documented condition that is never coded leaves the contract funded as though the patient were healthier. A coded condition the record does not support is an overpayment waiting to be recovered. Four buyers bring us this, and it is not the same problem.
| Who | What usually breaks | What we run |
|---|---|---|
| Medicare Advantage plansRisk at the member level | Submission and deletion discipline across a delegated network, plus exposure sitting in prior-year codes the charts no longer support. | Retrospective review at scale, deletion review on prior submissions, an evidence file per member. |
| ACOs and value-based groupsBenchmark and shared savings | Under-capture for three quarters, then a rushed year-end sweep that produces volume rather than accuracy. | Prospective preparation ahead of the annual wellness visit, with concurrent review on the gap-heavy service lines. |
| Groups in capitated contractsDownside risk | Notes that support the clinical work but not the category, because nobody told the clinician which words it requires. | Concurrent review plus a feedback loop that names the gap by clinician, not by department. |
| FQHCs and health centresManaged care and wrap | Thin coding capacity, high social complexity, conditions managed by care teams that never reach a coded encounter. | A light concurrent pass on the active panel and a targeted retrospective sweep on the most complex members. |
In health centres the coding gap often sits downstream of an enrolment gap, because an unenrolled clinician's encounters never reach the payer at all. See our credentialing and payer enrolment services.
CMS-HCC V28, payment year 2026
The phase-in is over. V28 is the whole score now.
CMS introduced V28 in the CY2024 Rate Announcement and blended it in over three payment years, so scores were part V24 and part V28 through 2024 and 2025. For payment year 2026 the blend ends and V28 carries the full weight. Anyone still modelling RAF on a V24 crosswalk, or comparing scores year over year without normalising for the model change, is reading a number that does not mean what they think it means.
| What changed | The detail | What it means for coding |
|---|---|---|
| Built on ICD-10-CMMapping foundation | V28 maps ICD-10-CM directly and renumbers the categories, so a V24 HCC number does not identify the same category. | Reports and suspect lists keyed to V24 numbers have to be rebuilt, not relabelled. |
| Categories reorganisedPayment HCC set | The payment category count increased and several disease families were resegmented, changing which hierarchy a diagnosis lands in. | Codes once interchangeable within a family are no longer equivalent. Specificity decides the category. |
| Conditions constrained or removedCoefficients | CMS constrained or removed coefficients where reporting varied widely between organisations, collapsing diabetes complication tiers and removing several vascular and angina categories. | Volume strategies stop working. Lift now comes from genuinely under-documented conditions. |
| Specificity tightenedMalnutrition, depression, others | Categories now turn on severity and specificity being stated in the record rather than implied by it. | The fix is upstream in the note. A coder cannot code severity a clinician did not write. |
| Coefficients renormalisedModel-wide | The coefficient set was renormalised, and CMS applies an annual normalisation factor and coding pattern adjustment on top of the raw score. | Raw RAF movement is not performance movement. Compare like for like or the comparison is noise. |
Category-by-category detail, with the documentation language each tightened category requires, is in our HCC V28 coding reference. To model the arithmetic on your own panel, use the free RAF score calculator.
Prospective, retrospective, concurrent
Three review modes. Most organisations need two of them.
These are not competing philosophies. They are different points in the patient year, and each catches what the others cannot.
Prospective review
A coder reads the history before the encounter and hands the clinician a short list: conditions needing evaluation this year, and the specificity each category requires. It is the only mode that changes what gets written rather than how it is read afterwards, and clinicians accept it because it arrives as preparation.
Concurrent review
The chart is reviewed while the encounter is open and a query can still reach the clinician who saw the patient. This is where V28's specificity requirements are actually met, because severity and linkage get clarified while the visit is fresh. Highest cost per chart, highest yield per chart.
Retrospective review
The closed record for the data collection year is read end to end. It does two jobs the others cannot: find supported conditions never coded, and find submitted codes the record does not support, which have to be deleted. A programme that only adds and never deletes is not a coding programme, it is an exposure programme.
On most engagements we recommend prospective preparation on the active panel plus a targeted retrospective sweep on the highest-complexity members, adding concurrent review where documentation gaps cluster in one service line.
RADV and data validation audits
Code as if the chart will be pulled, because it can be.
Risk Adjustment Data Validation is how CMS confirms that submitted diagnoses are supported by the medical record. In a final rule published on February 1, 2023, CMS set out that it would extrapolate RADV findings beginning with payment year 2018 and would not apply a fee-for-service adjuster. A sampled error is therefore no longer a sampled loss. Alongside RADV, plans face data validation audits of their Part C and Part D reporting, and exchange organisations face the parallel HHS-RADV process. None of this changes what good coding looks like. It changes what an unsupported code costs. Our audit posture is in the workflow, not bolted on when a notice arrives:
- Every submitted code traces to an encounter, date of service, provider type and signature.
- Deletion review runs alongside capture, so unsupported prior submissions are corrected.
- Coder reasoning is recorded, including why a suspect was declined.
- Acceptable provider type and face-to-face rules are checked before a diagnosis is accepted.
- Signature and credential validity are confirmed, because an unsigned note supports nothing.
- Evidence packets can be produced per member, in the format a reviewer expects.
When a request does land, the work is retrieval and assembly rather than reconstruction, because the evidence was captured at the moment the code was assigned.
The workflow, and where the coder gate sits.
Four steps. The gate is the third one, and it does not move.
Scoping and transfer
Records arrive through your EHR, a secure transfer or a release-of-information vendor. We confirm the collection year, the cohort, the model version and what was submitted before. Nothing is read until the scope is agreed in writing.
AI narrows the field
The record is scanned, candidate conditions are ranked, and prior-year submissions with no current support are flagged. This produces a shortlist. It produces no codes.
Certified coder decides
A certified coder reads the record. Each candidate is accepted with the encounter and provider that support it, or declined with a reason. Each unsupported prior submission is marked for deletion. Nothing passes on a confidence score.
Audit and delivery
An independent auditor re-reads a sample of every batch against the accuracy floor. Findings go back to the coder and into provider feedback. Then the adds, the deletions and the evidence file ship together.
Quality control and what you receive
A number you can audit, and a file you can hand over.
Our public accuracy standard for coding work is 95 percent or better, measured by an independent second-read auditor on sampled charts rather than by the coder who did the work. A batch that misses the floor is re-read before it ships. Senior partners, not account managers, own the quality conversation.
| Control | How it works |
|---|---|
| Second read | An independent auditor re-reads a drawn sample of every batch. Nobody audits their own work. |
| Accuracy floor | 95 percent or better on audited samples. A miss triggers a re-read of the batch, not a note in a report. |
| Deletion parity | Deletion review is scoped and measured alongside capture. A programme that only adds is not audited work. |
| Declined-suspect log | Every declined candidate is logged with its reason, which is what shows the review was clinical rather than acquisitive. |
| Provider feedback | Gaps reported by clinician and category, with the documentation language that category requires, so the gap does not recur. |
What lands on your side at the end of a cycle: accepted adds with their supporting encounter, date of service and rendering provider; deletions with the reason the record fails them; a RAF movement summary separating model-driven change from documentation-driven change; documentation gaps by clinician and category; and the evidence file, per member, ready for a reviewer.
The surfacing layer behind the second step is described on our AI for HCC coding page and in the HCC risk adjustment AI overview. Neither replaces the coder gate.
How engagements start
A sample, a scope, a written rate.
A senior partner takes the first call. We ask what you are risk-bearing under, what the panel looks like, what was submitted last cycle and what tooling you already own. Then we read a small sample of de-identified records, because the per-chart rate depends on specialty mix and record complexity rather than a rate card. From that sample comes a scope, a per-chart rate in writing, a turnaround commitment and the quality terms, including how the accuracy floor is measured. Nothing starts before a business associate agreement is executed. If your problem sits upstream of coding, we will say so: under-capture is often an enrolment gap, a scheduling gap in annual wellness visits, or templates that make specificity harder.
Risk adjustment coding, answered plainly.
What does a risk adjustment coder do?
What is risk adjustment in coding?
What is HCC coding?
What changed in V28?
How is RAF score calculated?
How much do risk adjustment coding services cost?
Is AI replacing risk adjustment coders?
Sources and review
Primary sources for everything above.
Model rules, phase-in schedule and audit policy here come from CMS and the Federal Register, not secondary commentary.
- CMS, Medicare Advantage Risk Adjustment programme overview and model software
- CMS, CY2024 Rate Announcement (introduction and three-year phase-in of CMS-HCC V28)
- CMS, CY2026 Rate Announcement (final year of the V28 phase-in)
- CMS, Advance Notices and Rate Announcements archive
- Federal Register, Medicare Advantage RADV final rule, February 1, 2023 (extrapolation from payment year 2018, no fee-for-service adjuster)
- CMS, Medicare Risk Adjustment Data Validation Program
- Federal Register, Contract Year 2024 Policy and Technical Changes to the Medicare Advantage Program
Reviewed by Aparna Suresh, CPB
President and Founder, ASP-RCM Solutions. AAPC-certified Professional Biller. Updated September 17, 2026.
Aparna reviews ASP-RCM coding and compliance guidance before publication. Engagements are senior-led, and every code on a risk adjustment engagement is owned by a certified coder. See the senior team →
Find out what your charts actually support.
Send a small sample of de-identified records. A senior partner reads them, tells you where the capture and the exposure are, and gives you a per-chart rate in writing.