Quick Answer: A CMS RADV audit checklist is the set of pass/fail criteria the Centers for Medicare and Medicaid Services uses to confirm that a medical record supports each HCC a Medicare Advantage plan submitted for risk adjustment. Every diagnosis needs a signed, legible, face-to-face record from a valid provider type, dated in the audited payment year, with MEAT criteria documented. In 2026, RADV audits run annually across all eligible contracts, samples run 35 to 200 records, and plans get a five-month submission window. One valid record per audited HCC supports payment. Records missing a stage, a signature, or active management fail.
A Risk Adjustment Data Validation (RADV) audit checklist is the set of criteria the Centers for Medicare and Medicaid Services uses to decide whether medical records actually support the diagnosis codes that Medicare Advantage organizations (MAOs) submitted for risk adjustment. Each Hierarchical Condition Category (HCC) in an enrollee’s risk score has to be backed by compliant, face-to-face provider documentation. If it is not, CMS can collect overpayments [1].
In 2026, the stakes around this checklist look nothing like they did two years ago. The RADV program now covers all eligible MA contracts on an annual basis, with variable sample sizes ranging from 35 to 200 records per contract [2]. New audits launch about every three months, and Payment Year 2020 audits began in February 2026 [2]. Incomplete medical records remain the most common reason diagnosis codes get rejected during RADV audits.
This guide walks through the official RADV medical record checklist, adds the condition-specific requirements that trip up audit teams, and lays out what your organization should be doing right now. For a fuller breakdown of how the audit program itself works, see our overview of RADV audits in 2026.
Note on extrapolation: A September 2025 federal court ruling vacated the extrapolation methodology from the 2023 RADV Final Rule, and extrapolation enforcement is paused. Audits continue. The Department of Health and Human Services appealed the decision in November 2025 and will comply with the court’s order while pursuing outstanding and future payment year audits [2]. Treat this as a preparation window, not a reprieve.
Key Takeaways
- The RADV program now covers all eligible Medicare Advantage contracts annually, with samples of 35 to 200 records per contract.
- Every diagnosis submitted for risk adjustment must be supported by a face-to-face encounter with MEAT criteria (Monitor, Evaluate, Assess, Treat) in the medical record.
- Records that are illegible, unsigned, or missing clinical specificity will fail.
- Medicare Advantage plans get a five-month submission window per audit [2].
- A maximum of two medical records per audited HCC is allowed, but only one valid record is needed to support payment [2].
- CMS finalized the unlinked chart review exclusion in its April 2026 CY2027 Rate Announcement, so unlinked diagnoses will not count toward risk scores [3].
- Mock RADV audits on a quarterly cadence are now a baseline expectation, not a nice-to-have.
What Is a CMS RADV Audit Checklist?
It is the documentation standard that confirms each submitted HCC is supported by a compliant, face-to-face medical record for the payment year under audit. It is the same yardstick CMS coders apply when they validate your risk adjustment data.
Why it matters: every item on the checklist maps to a way a diagnosis can be disallowed. Miss the signature, the date of service, the provider type, or the MEAT documentation, and a code that earned payment can become an audit finding. The MA Risk Adjustment Data Validation program is the federal government’s primary mechanism to recover overpayments from Medicare Advantage organizations [1], so each failed item carries direct financial risk.
Here is how a RADV review works at a high level:
- CMS selects a sample of enrollees from each audited contract.
- The health plan submits medical records to validate every HCC in those enrollees’ risk scores for the payment year.
- Certified coders review each record against coding guidelines.
- Any diagnosis that does not hold up becomes a finding, and CMS may collect the related overpayment [1].
These contract-level audits happen after the final risk adjustment data submission deadline for the MA contract year [1]. The checklist is how you predict the coder’s verdict before the coder ever sees the chart.
How RADV Audits Changed in 2026
What changed is the scale and the cadence. The RADV program now targets all eligible MA contracts annually, with variable sample sizes based on contract characteristics [2]. CMS is scaling its coder workforce and using AI-enabled tools to support coder efficiency, though all final determinations are still made by certified human coders [2]. A January 27, 2026 HPMS memo from the Audits and Vulnerabilities Group confirmed PY 2020 audits began in February 2026, with future audits launching on a roughly quarterly schedule [2].
The memo also acknowledged a hard truth: despite federal estimates that MA organizations may be submitting unsupported diagnosis data tied to roughly $17 billion in overpayments each year, the last significant recovery under the RADV program was for PY 2007 [2]. Completed audits for PYs 2011 through 2013 found overpayment rates between 5% and 8% [2]. The backlog is real, and CMS is moving to clear it.
There is a second 2026 update that changes what counts as a valid diagnosis. In its CY2027 Final Rate Announcement (April 6, 2026), CMS struck the proposed V28 recalibration after a skin substitute coding anomaly distorted the underlying data, so the 2024 risk model continues for CY2027 [3]. In the same announcement, CMS finalized the exclusion of diagnoses from unlinked chart review records from risk score calculations [3]. Translation: a code that is not tied to a clean encounter record will not just fail an audit, it will not count in the first place.
As Wynda Clayton, former CMS RADV auditor and RAAPID’s Director of Risk Adjustment Coding and Compliance, puts it: “Always be ready, because this is going to happen anyway.”
The Official RADV Medical Record Checklist
The published RADV medical record checklist helps Medicare Advantage contracts judge whether a record is suitable for submission [4]. Any item answered “No” signals the record may not support the audited HCC. Here is the checklist with practical context.
Checklist question | If “No” |
Is the record for the correct enrollee? (Name + DOB or Member ID) | Fails |
Is the record from the correct calendar year for the payment year being audited? | Fails |
Is the date of service present for the face-to-face visit? | Fails |
Is the record legible to non-clinical staff? | Fails |
Is the record from a valid provider type? (Hospital inpatient, hospital outpatient, or physician) | Fails |
Are valid credentials and/or a valid physician specialty documented on the record? | Fails |
Does the record contain a signature from an acceptable provider? | Fails |
If signature/credentials are missing, is there a completed CMS-generated attestation for this date of service? | Fails |
Is there a diagnosis on the record that supports an HCC? | Fails |
Does the diagnosis support the specific requested HCC? | Fails |
Does the documentation satisfy MEAT criteria for the diagnosis? | Fails |
Source: RADV Medical Record Checklist and Guidance [4].
A maximum of two medical records per audited HCC is allowed, though only one valid record is needed [2]. Submit your strongest. A weak second record next to a strong one just adds risk.
For inpatient records, the checklist requires admission and discharge dates alongside a signed discharge summary [4]. Include all necessary pages, and confirm legibility for the non-clinical staff who may handle the file.
MEAT Criteria: The Standard That Decides Audit Outcomes
MEAT criteria (Monitor, Evaluate, Assess, Treat) are the documentation standard coders use to validate HCC diagnoses during RADV audits. Listing a diagnosis on a problem list or in an assessment is not enough. The medical record must show active management of the condition during that encounter [4]. Any one of the four elements, clearly documented, satisfies the standard.
Monitor
Labs, vitals, imaging results, or other objective data tied to the condition. For a patient with chronic kidney disease, that means a documented eGFR or creatinine value. “CKD noted” with no lab data will not survive an audit.
Evaluate
A clinical assessment performed during this visit. The physician reviewed the condition, examined the patient, or ordered relevant tests. The record has to show the clinician engaged with the diagnosis, not carried it forward from a prior note.
Assess
The record documents current status: stable, worsening, improving, or a specific stage or severity. Vague language like “stable, continue meds” with no clinical context is one of the most common failure points medical coders see.
Treat
Active treatment is documented: medications prescribed or adjusted, therapy ordered, referrals made, or a care plan updated. The treatment must connect directly to the diagnosis being validated.
Miss any one of these and the diagnosis will not pass. Wynda Clayton’s test: “Before you validate any condition, ask yourself: if I had to go before a court of law, could I defend this?” For the rules behind each element, see our RADV audit guidelines.
Condition-Specific Documentation Requirements
Certain high-risk diagnoses fail at higher rates because their documentation requirements demand more precision. Coders look for clinical detail, not general references.
The OIG published a toolkit to help MA organizations identify diagnosis codes at high risk for being miscoded [5]. Its audits found that roughly 90% of targeted high-risk diagnosis codes were unsupported by the associated medical records [5]. More recent OIG compliance audits in this series, published in 2026, found unsupported high-risk diagnosis rates above 80% across multiple MA organizations, with one report putting the error rate at 91% across 271 sampled enrollee-years [9]. The conditions below overlap heavily with these high-risk categories.
CKD (Chronic Kidney Disease)
What must be documented: Stage (1 through 5) explicitly stated, eGFR/creatinine labs, and a treatment plan or referral. Accurate staging drives both risk score accuracy and HCC assignment, so a missing stage is a missing HCC.
Common failure pattern: “CKD noted” without a stage or supporting lab values.
Wynda Clayton: “Don’t just say the patient has CKD. We need the stage. Without it, you are probably not going to pass.”
Diabetes with Complications
What must be documented: Type (1 or 2) specified, the complication explicitly linked to the diabetes, and active treatment or monitoring for that complication.
Common failure pattern: “DM 2, stable” with no complication management documented.
Records submitted to validate HCCs that involve additional manifestations (such as diabetes with renal manifestations) must include language from a physician that establishes a causal link between the disease and the complication [4].
CHF (Congestive Heart Failure)
What must be documented: Type (systolic, diastolic, or combined), current status assessed during this visit, and active treatment.
Common failure pattern: CHF on the problem list but not addressed in the encounter note. The condition exists in the chart, but nobody touched it during the visit.
Acute Stroke
What must be documented: Inpatient or ED admission record, imaging confirmation (CT/MRI), and residual deficits or active treatment.
Common failure pattern: “History of CVA” documented without residuals or supporting hospital inpatient records. OIG’s toolkit found a 96% error rate for acute stroke diagnoses that appeared only on physician claims without a corresponding inpatient record [5].
Cancer Diagnoses
CMS guidance flags cancer as a high-risk area. A notation of “history of cancer” without indication of current treatment may not validate the HCC [4]. When possible, obtain records from the treating oncologist. OIG audits found error rates of 88% to 96% for lung, breast, and colon cancer diagnoses that lacked supporting treatment evidence [5]. These remain prime RADV targets.
Building Year-Round RADV Audit Readiness
Audit readiness is not something you scramble to build when a Notice of Audit shows up. With CMS now auditing all eligible contracts on a rolling quarterly basis, MA organizations need year-round preparation. Here is what that looks like.
- Maintain a standing RADV response team. Do not assemble a group per audit notice. Assign stakeholders from compliance, coding, HIM, legal, and provider relations as a permanent working group with clear roles and accountability before any audit starts.
- Run mock RADV audits quarterly. Use the latest CMS guidance and OIG targeting criteria. Pull sample records, run them through the full checklist, and score your pass rate. If your MEAT failure rate exceeds 5%, that needs immediate attention.
- Identify and prioritize high-risk HCC cohorts. Use data analytics to flag the diagnoses OIG targets most often: acute stroke, cancer, acute myocardial infarction, and embolism [5]. Review these before regulators do.
- Test your medical record retrieval process. The five-month submission window [2] sounds generous until you are chasing records from hundreds of providers at once. When every MAO pulls records at the same time, chart retrieval vendors may run short on capacity.
- Deploy audit-specific technology. CMS is using AI-enabled tools to support coder efficiency [2]. Plans need tools that validate documentation against MEAT criteria, flag gaps, and rank the strongest records for each audited HCC. Generic workflow software will not cut it for a process this structured.
- Educate providers on documentation practices. Physicians are compliance partners, not just documentation sources. Active education on MEAT criteria, specificity requirements, and common failure patterns reduces audit exposure upstream.
- Model RADV exposure for your board. This is a financial risk item, not a compliance footnote. Plans that fail to maintain compliance may face corrective action plans and expensive remediation. Report RADV exposure as a standing risk item.
- Ensure delegation agreements include quality standards. If you delegate coding or chart review, your agreements need self-audit clauses and documentation accuracy benchmarks. The OIG’s February 2026 MA ICPG makes clear that MAOs are responsible for oversight of all first-tier, downstream, and related entities [6].
What Red Flags Do RADV Auditors Look For?
Not every audit failure comes from obviously bad documentation. Some patterns are subtle, but they trigger deeper review. Former CMS auditor Wynda Clayton calls these the signals that told her something was off.
Documentation Red Flags
- “History of” used for acute conditions (this describes resolved conditions, not active ones)
- A diagnosis on the problem list but not addressed in the encounter note
- Vague language: “stable” or “continue meds” with no clinical context
- Template or cloned documentation (identical language across multiple visits)
- Missing specificity: no stage, no type, no severity
- No lab values to support chronic conditions
Coding Pattern Red Flags
- Acute diagnosis codes submitted without hospital inpatient records
- High-value HCCs documented without specialist notes
- Cancer codes without oncology involvement
- A single provider with an unusually high HCC capture rate
- A diagnosis submitted once and never documented again
- Prescription Drug Event data inconsistent with the submitted diagnosis
Wynda: “When I saw these patterns, I knew to dig deeper.” None of these automatically mean fraud. But they attract scrutiny, and scrutiny is expensive.
Why Retrospective Reviews Must Be Two-Way
One of the biggest risk factors regulators now watch for is add-only retrospective chart review programs. The OIG’s February 2026 MA ICPG addresses this directly: federal investigations have revealed conduct that includes using chart reviews to raise risk scores while failing to remove unsupported diagnosis codes previously submitted [6]. OIG concluded that some MA organizations may be leveraging chart reviews and in-home Health Risk Assessments to increase risk adjustment payments without matching processes to ensure data accuracy [6].
The logic is simple: a review process that only adds diagnoses and never removes unsupported ones looks like a revenue engine, not a compliance program. DOJ enforcement reinforces this. In March 2026, a $117.7 million False Claims Act settlement resolved allegations that an MA organization ran an add-only chart review program that submitted additional diagnosis codes but failed to delete unsupported codes its own reviews had identified [8]. Earlier settlements, including a $556 million resolution and a separate $172 million resolution, point the same way [8]. Systems built mainly to increase risk scores can be read as intent to inflate government payments.
Compliant retrospective programs work in both directions. They identify uncaptured diagnoses that are legitimately supported (adds) and flag or remove diagnoses that lack documentation support (deletes). This two-way approach, adds and deletes, is the baseline for defensible risk adjustment now, not a best practice.
AI’s Role in RADV Audit Readiness
CMS has committed to using AI-enabled tools to support its RADV coding teams, with all final determinations made by certified human coders [2]. If the federal government uses technology to find your errors, you need technology to find them first.
Audit-specific AI can automate routine compliance checks, show documentation status across provider networks, and validate records against MEAT criteria before submission. The right tools surface the strongest documentation for each audited HCC and flag gaps before records reach CMS. Health plans using purpose-built audit technology report meaningful productivity gains, with chart review time in the range of 8 to 12 minutes per chart, while keeping coding accuracy high.*
The distinction that matters: AI that operates as decision support (transparent, with human oversight) versus AI that runs as ungoverned automation. CMS keeps human coders making final calls. Health plans should demand the same from their vendors.
Neuro-Symbolic AI, which pairs large language models with clinical knowledge graphs, generates a transparent evidence trail for every suggested HCC by linking each recommendation to documented clinical evidence in the note. That explainability holds up under both RADV scrutiny and DOJ investigation. It also strengthens appeals when legitimate documentation exists but was not surfaced during the original audit response. RAAPID reports 92% out-of-the-box AI accuracy and over 98% accuracy after human-in-the-loop quality review.*
*RAAPID internal benchmarks.
Build Audit Readiness Before the Notice Arrives
RADV audits are no longer episodic events. They are a routine, high-stakes compliance reality for every Medicare Advantage organization. The plans that survive this environment are not the ones with zero errors. They are the ones with documented, repeatable processes that catch and correct errors before regulators do.
If your current workflow cannot handle concurrent audits, validate documentation against MEAT criteria at scale, or produce defensible evidence trails on demand, it is time to reassess.
Get the RADV Defensibility Pocket Checklist
Built by Wynda Clayton, a former CMS RADV auditor, and refreshed for June 2026. It includes the “Court of Law” test, the chart-level defensibility checklist, condition-specific documentation requirements, and the red flag patterns above, in a single printable reference.
The RADV Defensibility Pocket Checklist
Built by Wynda Clayton, a former CMS RADV auditor. Includes the “Court of Law” test, chart-level defensibility checklist, condition-specific documentation requirements, and red flag patterns.
Schedule a demo of RAAPID’s RADV AI Audit Solution: purpose-built audit management with AI-powered HCC validation and real-time analytics across concurrent audits.
Frequently Asked Questions
CMS uses targeting models that analyze enrollment patterns, coding trends, and risk score variation to select eligible contracts [1]. With the program now covering all eligible contracts annually, virtually every MA plan faces yearly scrutiny. Sample sizes of 35 to 200 enrollees scale with contract size, so smaller contracts rarely draw the maximum sample [2].
CMS restored a five-month submission window, up from the three-month window first announced in May 2025 [2]. That sounds generous, but record retrieval across hundreds of providers eats the calendar fast. Build and test your retrieval process well before any audit notice arrives, not after.
CMS may collect overpayments tied to unsupported diagnoses [1]. The financial risk can extend beyond the sample to the contract level, though the methodology for calculating contract-wide repayment remains in flux after the September 2025 court ruling [2]. Audits continue regardless, and disallowed codes can lead to retroactive recoupments.
Yes. MA organizations can appeal medical record review determinations through three levels: reconsideration, Hearing Officer review, and Administrator review. MAOs must exhaust all three levels of medical record appeals before appealing a payment error calculation [7].
RADV audits focus on data validation and payment accuracy, and they result in repayment obligations. OIG and DOJ investigations can expand into fraud allegations with far larger consequences, including settlements that reach hundreds of millions of dollars [8]. The financial and legal exposure differs sharply between the two.
A maximum of two, but only one valid record is needed to support payment [2]. Submit your strongest record. Adding a weak second record next to a strong one introduces risk without adding protection.
No. In its CY2027 Final Rate Announcement (April 6, 2026), CMS finalized the exclusion of diagnoses from unlinked chart review records from risk score calculations [3]. A diagnosis that is not tied to a clean encounter record will not count, which makes encounter-linked, two-way coding the safer path.
Source
[1] Centers for Medicare and Medicaid Services, “Medicare Advantage Risk Adjustment Data Validation Program.” cms.gov
[2] Centers for Medicare and Medicaid Services, HPMS Memorandum from Steven Ferraina, Acting Director, Audits and Vulnerabilities Group, January 27, 2026. “Update on the Status of Medicare Advantage Risk Adjustment Data Validation Audits.” crowell.com
[3] Centers for Medicare and Medicaid Services, “CY2027 Rate Announcement for Medicare Advantage and Part D,” April 6, 2026. cms.gov
[4] Centers for Medicare and Medicaid Services, “RADV Medical Record Checklist and Guidance.” cms.gov (PDF)
[5] U.S. Department of Health and Human Services, Office of Inspector General, “Toolkit To Help Decrease Improper Payments in Medicare Advantage Through the Identification of High-Risk Diagnosis Codes,” Report A-07-23-01213, December 2023. oig.hhs.gov
[6] U.S. Department of Health and Human Services, Office of Inspector General, “Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG),” February 3, 2026. oig.hhs.gov/compliance/ma-icpg/
[7] Centers for Medicare and Medicaid Services, “Contract Year 2025 Policy and Technical Changes to the Medicare Advantage Program,” Final Rule, April 2024. federalregister.gov
[8] U.S. Department of Justice, “Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act Allegations,” March 11, 2026. justice.gov
[9] U.S. Department of Health and Human Services, Office of Inspector General, Medicare Advantage high-risk diagnosis code compliance audit, Report A-07-22-01207, March 2026. oig.hhs.gov
About the author
Wynda Clayton
Director of Risk Adjustment Coding and Compliance
This guide was developed with input from Wynda Clayton, MS, RHIT, Director of Risk Adjustment Coding and Compliance at RAAPID. Wynda is a former CMS RADV auditor with 20+ years of experience in healthcare coding and compliance. Her firsthand audit experience shapes RAAPID's approach to defensible coding and audit readiness. Questions? Contact Wynda at wynda.c@raapidinc.com.