Quick Answer: Defensible risk adjustment means every submitted diagnosis connects to a valid clinical encounter, is supported by MEAT-based documentation, and carries a traceable record of who validated it and why. The standard moved in 2026: OIG’s first Medicare Advantage compliance guidance since 1999 treats failing to remove unsupported codes as a compliance failure [2], a March 2026 DOJ settlement traced $106.2 million of a $117.7 million penalty to an add-only chart review program [3], and three OIG audits found 81 to 91 percent error rates in high-risk diagnosis codes [4][5][6]. Five pillars build a program that holds two-way validation, encounter linkage, evidence trails, mock audits, and provider enablement.
Understanding Defensible Risk Adjustment in 2026-27
Medicare Advantage organizations spent years optimizing for diagnosis capture. The next competitive advantage will come from diagnosis defensibility.
That observation comes from the other side of the table, from years spent reviewing medical records during RADV audits. The plans that struggled were rarely the ones with the fewest diagnoses. They were the ones who could not explain their diagnoses. A code with no visit behind it, no evidence in the note, and no record of who validated it or why: that is what turns an audit from an administrative exercise into a financial event.
Defensible risk adjustment means every submitted diagnosis connects to a valid clinical encounter, is supported by documentation, and can be explained during review. The organizing question has changed. It is no longer “Did we capture the diagnosis?” It is “Can we prove why we captured it?”
This playbook lays out five pillars for building a program that can answer. None of them requires a new regulation to justify. They respond to expectations already in force.
Key Takeaways
- Defensible risk adjustment means every diagnosis connects to a real encounter, carries MEAT-based evidence, and can be explained during review without reconstruction.
- OIG’s February 2026 compliance guidance treats failing to identify and remove unsupported codes as a compliance failure in its own right [2].
- A March 2026 False Claims Act settlement traced $106.2 million of a $117.7 million penalty to an add-only chart review program [3].
- Three March 2026 OIG audits found 81 to 91 percent of sampled high-risk diagnosis codes unsupported, with acute stroke and acute myocardial infarction reaching 100 percent in individual audits [4][5][6].
- RADV audits now run on a quarterly cadence with a 5-month record submission window, so readiness must be continuous [7].
- Five pillars make a program defensible: two-way validation, encounter linkage, evidence trails, mock audits, and provider enablement.
Why Defensibility Is the New Standard in Risk Adjustment
Consider how most programs still operate. Retrospective chart review closes the gap between claims and records, and most of that review runs one direction: find diagnoses to add. Audit preparation begins when a notice arrives.
That model matched the old rules. The rules moved in three ways worth interpreting rather than just reciting.
Three signals, one direction
First, CMS finalized policies in the CY 2027 Rate Announcement that affect diagnoses from unlinked chart review records used in risk score calculations [1]. Read the direction, not just the provision: diagnoses generated by review activity alone, disconnected from documented care, are losing standing.
Second, the OIG published its first Medicare Advantage compliance guidance since 1999, which treats failing to identify and remove unsupported codes as a compliance failure in its own right [2]. That sentence should change how every plan designs its retrospective program.
Third, RADV audits now run on a repeating quarterly cadence [7]. When review is continuous, readiness has to be continuous. Spreadsheets and email threads do not survive a quarterly rhythm.
What auditors mean by alignment
From an auditor’s perspective, these three changes share one theme: alignment. A defensible program aligns the diagnosis, the encounter, the provider’s documentation, the clinical evidence, and the audit trail that connects them. When those five line up, review is routine. When they don’t, every audit is an emergency. Our guide to building defensible RAF scores covers the scoring side of this alignment.
The Five Pillars of a Defensible Risk Adjustment Program
These five pillars are not new regulations. They are the recurring themes across CMS policy, OIG findings, and enforcement outcomes:
- Two-way validation: review what should be captured and what lacks support.
- Encounter linkage: connect every diagnosis to real clinical care.
- Evidence trails: make every coding decision traceable.
- Mock audits: test readiness before an external review does.
- Provider enablement: improve documentation where care happens.
The order matters. Get the review right, connect it to care, make it traceable, test it, then go upstream so the problems stop arriving.
Pillar 1: Move From Add-Only Review to Two-Way Validation
A defensible retrospective program reviews charts in both directions: it adds diagnoses that claims missed and removes diagnoses that documentation cannot support. If unsupported diagnoses create audit exposure, why are many organizations still reviewing charts in only one direction?
Why one-way programs persist
Usually, because the program was built that way, and the incentives never forced a redesign. Traditional review hunts for diagnoses to add. A defensible review is valid in both directions: conditions that should be captured and conditions that lack sufficient support. Corrections get submitted, not parked in a queue.
Think of it as the two-way street CMS built into supplemental data. Plans are expected to add the diagnoses their claims missed and remove the diagnoses their documentation cannot support. Using only one lane is the pattern that draws attention. Our overview of retrospective risk adjustment shows how modern programs are structured around both lanes.
What the enforcement record now shows
The enforcement record proves the point. In March 2026, the Department of Justice announced a $117.7 million False Claims Act settlement with a major Medicare Advantage insurer; $106.2 million was traced to an add-only chart review program [3]. The program design was the conduct at issue, not isolated errors. The same month, three OIG audits found 81 to 91 percent of sampled high-risk diagnosis codes unsupported, with acute stroke and acute myocardial infarction reaching 100 percent error rates in individual audits [4][5][6]. OIG has told the industry which chart-review patterns it considers red flags.
Add-only vs. two-way review at a glance:
|
Add-only chart review |
Two-way validation |
|
|
Review direction |
Finds diagnoses to add |
Reviews adds and removals in one pass |
|
Unsupported codes |
Left in place or parked in a queue |
Corrected and submitted for deletion |
|
How regulators read it |
Flagged in OIG’s 2026 compliance guidance; central to the March 2026 False Claims Act settlement [2][3] |
The two-way pattern CMS built into supplemental data |
|
Financial profile |
Near-term RAF gain, unbounded audit liability |
Bounded near-term cost, compounding risk reduction |
|
Audit posture |
Reconstruction after the notice arrives |
Retrieval from evidence that already exists |
The trade-off leadership should weigh honestly
Removing unsupported diagnoses reduces RAF this quarter. Keeping them builds audit exposure that compounds across payment years, at an extrapolated scale once sampling methodology questions are resolved. One is a visible, bounded cost. The other is an unbounded liability accruing quietly. The better long-term position is not close.
“The riskiest code in your data is usually a history of a condition sitting there as active. A patient comes in for a stroke follow-up, and the stroke gets coded as if it were a day. Pull your single-occurrence codes and your high-risk diagnoses, stroke and heart attack first, and ask whether the note supports an active condition. That is the review OIG is already running, so run it before they do,” says Wynda Clayton, Director of Risk Adjustment Coding and Compliance at RAAPID and a former CMS RADV auditor.
Reviewing both directions does not require doubling headcount; AI-assisted validation supports reviewers by identifying unsupported and missed codes in a single pass, as modern retrospective programs are now built.
Two-way validation answers whether a diagnosis belongs. The next question is whether it can be traced back to actual patient care.
Pillar 2: Anchor Every Diagnosis to an Encounter
A diagnosis is anchored when it carries a date of service, an identified rendering provider, and evidence in that visit’s note; without all three, it is not ready to submit. When a plan cannot indicate where a diagnosis originated, does it matter how accurate the code appears?
The first question auditors ask
During record review, the first question is not whether the code is clinically plausible. It is where the code came from: which visit, which provider, which note. A diagnosis becomes defensible when the organization can show where, when, and why it was documented.
CMS policy is moving in the same direction. The CY 2027 Rate Announcement finalized the treatment of unlinked chart review records in risk scores [1], continuing a broader shift toward encounter data as the foundation of payment. Plans anchoring documentation to encounters are being built for rules already on the calendar.
The three-part linkage gate
Operationally, this is a three-part gate that must be met before any code leaves the pipeline. Is there a date of service in the encounter data? Is the rendering provider identified? Does that visit’s note contain evidence for the condition? Any “no” means the code is not ready, however plausible it looks.
Where linkage breaks
One pattern repeatedly appears during audits: linkage breaks in the same places. Supplemental feeds that never carried encounter identifiers. Chart review findings orphaned from the visits they came from. Assessments performed apart from ongoing care. OIG flags these sources when they function mainly to raise risk scores [2]. Map where your diagnoses originate, and you will find where your linkage risk lives.
Linking a code to a visit proves the encounter happened. Proving the code was right requires an evidence trail.
Pillar 3: Build Evidence Trails That Survive Review
An evidence trail records what was evaluated, when, by whom, and why, captured at the moment of coding rather than rebuilt after a notice arrives. If your best coder left tomorrow, could anyone explain the decisions they made last quarter?
Retrieval versus reconstruction
That question is the difference between retrieval and reconstruction, and it is in reconstruction that audit responses fail. An organization in retrieval mode responds to a record request by exporting existing evidence. An organization in reconstruction mode responds by launching a project: pulling charts, hunting encounters, and retracing decisions from memory nobody has. Both organizations face the same deadline. Only one of them is racing it.
Auditors want more than a list of diagnoses. They want to see what was evaluated, when, by whom, and why. A program that captures those answers as a byproduct of coding never has to reconstruct anything.
The Four Questions every diagnosis should answer
Here is a framework worth keeping. Every submitted diagnosis should be able to answer four questions:
- Where did it come from? The encounter.
- What supports it? The evidence.
- Why was it coded? The reasoning.
- Who validated it? The trail.
A diagnosis that answers all four survives review. A diagnosis that answers two is a finding waiting to be written.
Capture MEAT at the moment of coding.
MEAT-based evidence answers the first two questions: each HCC is tied to language indicating the provider Monitored, evaluated, assessed, or treated the condition at that encounter. The operational discipline is timing. Capture the MEAT linkage at the moment of coding, not after a notice arrives, because evidence located years later is a reconstruction wearing a compliance costume. Our MEAT criteria guide covers the standard in detail.
Explainability is an operational requirement, not a feature
The last two questions make explainability an operational requirement. When a tool suggests a code and cannot explain why, the plan owns that gap in the review; the vendor does not answer to CMS. An opaque suggestion, however accurate, transfers its risk to whoever submits it.
Evidence-first workflows exist for exactly this reason. RAAPID’s platform, built on Neuro-Symbolic AI, surfaces each suggested code with its supporting evidence attached so a reviewer can see the reasoning and accept or reject it. The technology provides evidence. The judgment stays human.
Download the Defensible Risk Adjustment Checklist to put these standards into practice.
An evidence trail you have never tested is a theory. The fourth pillar is where you test it.
Pillar 4: Run Mock Audits Before CMS Does
A mock audit samples your highest-risk codes the way OIG does, on the quarterly cadence that CMS now runs, so you learn your error rate before an external reviewer assigns you one. What would your error rate be if CMS sampled your highest-risk contracts today? If leadership cannot answer, that is the exposure.
The audit rhythm is set
RADV audits for payment year 2020 have been running quarterly since February 2026, with the five-month record submission window restored, and CMS has announced plans to scale to roughly 2,000 certified coders [7]. Extrapolation is paused under a September 2025 federal court ruling. Interpret that correctly: it is time to prepare, not permission to relax. Findings assessed now do not disappear if the methodology returns on appeal. Our RADV audit guide for 2026 covers the current cadence and windows in detail.
Run it the way the real ones are run.
A mock audit tests four things: documentation support, encounter linkage, evidence availability, and the review process itself. Fidelity to the real process is what makes the exercise worth running:
- Sample the way OIG samples. Draw high-risk HCCs, single-occurrence codes, and acute conditions coded outside acute settings because that is where external reviewers start.
- Race the real clock. Retrieve records within a five-month window to test your true retrieval speed, including the provider charts that live outside your own systems.
- Score in both directions. Count the unsupported codes you find with the same rigor as the missed ones, because that is the score an auditor would give you.
- Correct, document, and repeat. Submit corrections, record the remediation, and run the cycle again next quarter so readiness becomes a rhythm rather than an event.
Our CMS RADV audit checklist provides a working template for each step.
Turn audit risk into a number your CFO can fund
The mock audit also changes the conversation with your CFO. It converts audit risk from an unknown into a number: internal error rate translated into contract-level dollars. Remediation stops competing for budget as a compliance cost and starts winning it as a risk-reduction investment. Finance funds numbers, not anxiety.
Every pillar so far operates after documentation exists. The last one fixes documentation at the source.
Pillar 5: Enable Providers Instead of Pressuring Them
Provider enablement improves documentation quality at the source through pre-visit planning, in-visit decision support, and feedback, rather than prompts and pressure. If the same documentation gaps generate queries every quarter, why keep querying instead of fixing the source?
Why pressure backfires
Endless retrospective queries treat the symptom forever. Pressure makes it worse: prompts and incentives designed to push diagnosis codes are a red flag in OIG’s guidance [2], and clinicians who feel treated as revenue generators disengage from the documentation you depend on. Pressure produces codes. It does not produce evidence, and evidence is the asset this entire playbook is built on.
Documentation at the moment of care
The goal is not more documentation. It is accurate documentation when care happens. The safest diagnosis is the one made during the visit, with evidence written into the note in real time, because it arrives already carrying its encounter, its provider, and its clinical support. Pre-visit planning surfaces conditions worth confirming. In-visit decision support helps the clinician document what is clinically real with specificity while retaining final authority. Our guide to prospective risk adjustment shows what encounter-driven documentation looks like in practice.
Education with feedback loops
Pair the workflow with education, and close the loop. Teach specificity and evidence standards once, then show providers how their documentation performed: which notes cleanly supported their diagnoses, which generated queries, and how their habits changed. Feedback earns engagement that pressure never will, because it treats clinicians as the owners of documentation quality rather than the targets of it.
Measure success by the queries you no longer send.
Conclusion
After years of reviewing records on the government’s side of RADV, one thing is clear about the plans that handle audits well: nothing separates them after the notice arrives. The work was already done. Every diagnosis could answer the four questions.
The five pillars are one system. Validation gets the codes right. Linkage grounds them in care. Evidence trails make them provable. Mock audits verify readiness. Provider enablement fixes quality at the source.
The organizations that succeed through 2027 won’t be the ones that find the most diagnoses. They’ll be the ones who can defend every diagnosis they submit.
Get the Defensible Risk Adjustment Walkthrough
See what a two-way review finds in your data
Frequently Asked Questions
Short answer: Defensible risk adjustment means every diagnosis you submit ties to a real visit, has evidence in the record, and can be explained during an audit.
Full answer: Defensible risk adjustment is a program design in which every submitted diagnosis connects to a valid clinical encounter, is supported by documentation meeting MEAT criteria, and carries a traceable record of who validated it and why. The standard is proof, not plausibility: a defensible diagnosis can be explained during a RADV audit or OIG review without reconstruction.
Short answer: A defensible diagnosis answers four questions: which encounter it came from, what evidence supports it, why it was coded, and who validated it.
Full answer: A defensible diagnosis answers four questions: where it came from (the encounter), what supports it (the evidence), why it was coded (the reasoning), and who validated it (the trail). In practice, that means a dated encounter with an identified rendering provider, documentation showing the condition was monitored, evaluated, assessed, or treated, and an evidence link captured at the moment of coding.
Short answer: Yes. OIG’s 2026 guidance treats failing to remove unsupported codes as a compliance failure, and enforcement has already penalized add-only programs.
Full answer: OIG’s 2026 compliance guidance treats failing to identify and remove unsupported codes as a compliance failure in its own right [2], and the March 2026 False Claims Act settlement traced $106.2 million to an add-only chart review program [3]. Two-way validation, adding missed diagnoses and removing unsupported ones, is the pattern regulators now expect a compliant program to show.
Short answer: Quarterly, matching the cadence CMS now runs RADV audits on, so your internal testing keeps pace with the real review cycle.
Full answer: Quarterly, matching the cadence CMS now runs RADV audits [7]. Each cycle should sample high-risk HCCs the way OIG does, test record retrieval against the five-month submission window, score diagnoses in both directions, and document remediation before the next cycle begins.
Source
[1] CMS, CY 2027 Medicare Advantage and Part D Rate Announcement, April 2026. cms.gov
[2] HHS OIG, Industry Segment-Specific Compliance Program Guidance for Medicare Advantage Organizations, February 2026. oig.hhs.gov
[3] U.S. Department of Justice, False Claims Act settlement press release, March 11, 2026. justice.gov
[4] HHS OIG, Audit Report A-07-22-01207, March 2026. oig.hhs.gov
[5] HHS OIG, Audit Report A-07-22-01208, March 2026. oig.hhs.gov
[6] HHS OIG, Audit Report A-03-22-00004, March 2026. oig.hhs.gov
[7] CMS, RADV audit HPMS memorandum, January 27, 2026. cms.gov