RAAPID raises Series A funding with a Strategic “Industry Trifecta”. Read More

Home » Blogs 

RADV Audit Guidelines: 2026 Rules, MEAT Criteria, and Defensible Documentation

RADV audit guidelines are the rules the Centers for Medicare and Medicaid Services (CMS) uses to confirm that diagnosis codes submitted by Medicare Advantage organizations are backed by real medical records. In plain terms: every Hierarchical Condition Category (HCC) you submit for payment must trace to a face-to-face encounter in the payment year, with documentation that shows the condition was managed. Risk adjustment data validation (RADV) is how CMS checks that the money it pays for member risk matches the clinical reality in the chart.

What changed in 2026 is the scope and the stakes. CMS is moving to audit all eligible Medicare Advantage contracts every year, restored a five-month medical record submission window, and is using AI to support its reviewers while human coders make the final call [1]. At the same time, federal enforcement has shifted from “find more codes” to “prove the codes you found.” The Department of Justice and the Office of Inspector General (OIG) are penalizing plans that added diagnoses but never removed the unsupported ones they spotted [4][5]. Defensible coding, every diagnosis encounter-linked, evidenced, and auditable, is now the whole game.

Key Takeaways

  • RADV audit guidelines require that every submitted diagnosis trace to a face-to-face encounter in the payment year and meet MEAT-based documentation [1].
  • CMS confirmed PY2020 RADV audits began in February 2026, on a quarterly cadence, with a restored five-month record window and sample sizes of roughly 35 to 200 enrollees [1].
  • A September 2025 federal court ruling vacated CMS’s extrapolation methodology, so extrapolated penalties are paused pending appeal, but the audits themselves continue [2].
  • The March 2026 Aetna settlement ($117.7M) penalized an add-only chart review program that submitted codes but failed to delete unsupported ones, making two-way coding the compliance benchmark [4].
  • OIG found a 91% error rate across 271 sampled enrollee-years in a March 2026 audit of a Medicare Advantage plan (report A-07-22-01207), with history-of conditions coded as active diagnoses the most common failure [5].

Quick Answer

RADV audit guidelines define how CMS validates Medicare Advantage risk adjustment payments: each diagnosis must be supported by a face-to-face medical record from the payment year and meet MEAT criteria (Monitored, Evaluated, Assessed, or Treated). In 2026, CMS is auditing all eligible contracts annually with a five-month record submission window and sample sizes of 35 to 200 [1]. Extrapolated penalties are paused after a September 2025 court ruling, but audits continue [2]. Recent DOJ and OIG actions show the real risk now sits with add-only programs that never remove unsupported codes [4][5].

Industry First RADV Audit Solution 
AI-powered solution enables health plans to efficiently manage and streamline RADV audits
Industry First Autonomous RADV Audit Solution 3

What RADV Audit Guidelines Require in 2026

RADV audit guidelines are CMS’s documentation and validation rules for confirming that submitted HCCs reflect conditions actually treated and recorded during a payment year. They set what counts as a valid record, who can sign it, and what evidence proves a diagnosis.

Three requirements sit at the core of every RADV review:

  • Encounter link. Each diagnosis must come from a face-to-face encounter (with limited telehealth exceptions) that happened during the payment year under audit.
  • Provider authentication. The rendering provider’s name, credentials, and a valid signature with a date must appear on the record.
  • Clinical evidence. The note must show the condition was actively managed, not just listed or carried forward from an old problem list.

These rules matter because a single unsupported diagnosis is not just one deletion. CMS removes the HCC, recalculates the member’s Risk Adjustment Factor (RAF) score, and recovers the related payment. For a Director of Risk Adjustment, the guidelines are the difference between a clean audit and months of remediation. For more on the audit itself, the cadence, the sample, and the 2026 timeline, see our guide to RADV audits in 2026.

Why CMS Tightened RADV Oversight

The push behind stronger RADV oversight is straightforward: federal watchdogs have flagged MA overpayments for years. The Government Accountability Office and OIG have repeatedly documented diagnosis codes that drove payment but had no clinical support [5][6]. The Medicare Payment Advisory Commission (MedPAC) reported in March 2026 that Medicare Advantage costs the program about 14% more than equivalent fee-for-service care, roughly $76 billion in a single year [3].

That gap is what CMS is chasing. Strengthening oversight through RADV is the agency’s most direct tool to recover improper payments and hold MA plans to the same documentation standard providers already meet. The federal government is not arguing that members are healthy. It is arguing that plans must prove the conditions they coded.

How Often RADV Audits Happen Now

CMS has moved from auditing a small slice of plans to reviewing the whole market. For years the agency examined roughly 60 contracts at a time. It is now building toward auditing all 550-plus eligible MA contracts on an annual basis [1]. The old “audit lottery,” where most plans never got selected, is over.

A January 27, 2026 CMS memo confirmed that PY2020 RADV audits started in February 2026 and will run on a quarterly cadence [1]. Sample sizes range from about 35 to 200 enrollees per contract, scaled to contract size. The practical message for every Medicare Advantage organization: assume you are in scope this year, and build year-round audit readiness rather than scrambling when a notice lands. Plans that want a ready-to-use prep tool can start with our CMS RADV audit checklist.

The MEAT Criteria Checklist for RADV Documentation

MEAT criteria is the documentation convention that a diagnosis is valid when the note shows the condition was Monitored, Evaluated, Assessed, or Treated. Any one of the four elements, documented clearly, is enough to support the code. MEAT is an industry convention auditors apply, not a term CMS coined, but it maps directly to what RADV reviewers look for.

Use this checklist on every chart before it goes to CMS:

  • Monitor: Note signs, symptoms, disease progression, or response to therapy (for example, “HbA1c 8.2%, up from 7.4%”).
  • Evaluate: Record test results, exam findings, or a review of the condition’s status.
  • Assess/Address: Document clinical reasoning, a care plan, or a referral tied to the diagnosis.
  • Treat: Capture medication changes, procedures, therapies, or other active management.
  • Encounter check: Confirm the date of service falls in the payment year and the visit was face-to-face.
  • Specificity check: Verify the ICD-10-CM code carries the required digits and matches the documented condition.

Here is the line between a record that holds up and one that fails:

Passes RADV review

Fails RADV review

“Type 2 diabetes with diabetic retinopathy; HbA1c 8.2%, metformin increased to 1000mg BID; retinopathy screening ordered.”

“History of diabetes” or “DM2, stable, continue meds.”

“Acute CVA during March admission; neuro deficits documented, rehab ordered.”

“Stroke” listed on problem list with no current management.

The most common RADV failure is exactly that right-hand column: history-of conditions coded as active diagnoses. OIG found this pattern again and again in its 2026 audits [5]. For a deeper walkthrough of the standard, see our explainer on MEAT criteria in HCC coding.

What a Valid RADV Record Must Contain

Every record you submit must stand on its own. A reviewer who has never seen the patient should be able to open the chart and confirm the diagnosis. Missing one element can trigger deletion of the HCC.

A valid record includes:

  • Member identification: Full name and date of birth, or member ID, on every page.
  • Provider credentials: Name, specialty, and a valid signature with a date.
  • Service date: Inside the payment year being audited.
  • Encounter type: Face-to-face, with limited telehealth exceptions.
  • Diagnosis specificity: An ICD-10-CM code coded to the correct level of detail.
  • MEAT evidence: Clear proof the condition was managed during the visit.
  • Legibility: Readable by non-clinical audit staff.

When CMS allows more than one record to support a member’s HCC, only one valid record needs to meet the standard for that condition to hold. Copying forward an old problem list does not count. The provider has to show work done at that encounter.

Autonomous Retrospective Risk Adjustment Solution

One platform. Every HCC validated. Revenue secured.

Retrospective Risk Adjustment Solution

Where the RADV Extrapolation Rule Stands in 2026

This is the update most plans get wrong. The 2023 RADV final rule let CMS apply a sample error rate across an entire contract, a method called extrapolation, and the agency projected recovering about $4.7 billion through 2032 [2]. Then a September 2025 federal court ruling vacated that extrapolation methodology. As a result, extrapolated penalties are paused pending appeal [2].

Read that carefully, because two things are true at once. The audits are still happening, on the expanded annual schedule. Only the extrapolation of sample error rates to the full contract population is on hold. CMS can still identify unsupported diagnoses, delete them, and recover the direct overpayment on the sampled members.

For MA plans, this is a preparation window, not a reprieve. If extrapolation returns on appeal, the math is steep. To illustrate the methodology: a real OIG audit identified about $480,000 in sample overpayments that, applied across the contract, pointed to roughly $27 million in projected exposure [5]. The smart move is to clean documentation now, while the financial multiplier is paused.

What the Settlements Reveal: Two-Way Coding Is the Standard

Recent enforcement makes the new rule of risk adjustment data validation unmistakable: adding codes is not enough, and ignoring the ones you should remove is now treated as intent. On March 11, 2026, the Department of Justice announced a $117.7 million False Claims Act settlement with a major Medicare Advantage insurer [4]. The breakdown tells the story:

  • $87.2 million resolved allegations that an add-only chart review program for PY2015 submitted additional diagnosis codes to CMS but failed to delete or withdraw unsupported codes the same reviews had identified [4].
  • $30.5 million resolved allegations of knowingly submitting false morbid obesity diagnosis codes across PY2018 to PY2023 [4].

The case began with a whistleblower, a former risk adjustment coding auditor inside the plan [4]. The lesson for every Director of Risk Adjustment and Chief Compliance Officer: a one-way program that finds codes to add but never acts on codes to delete is the exact pattern regulators now read as inflation of payments.

OIG’s audits reinforce the point. In report A-07-22-01207 (March 2026), OIG found that 247 of 271 sampled enrollee-years, a 91% error rate, carried unsupported high-risk diagnosis codes, with acute stroke and acute myocardial infarction showing 100% error rates [5]. The fix is structural, not cosmetic: two-way coding that adds supported diagnoses and removes unsupported ones, backed by an evidence trail. That is the foundation of defensible RAF scores.

How RAAPID Supports Defensible RADV Coding

Manual review cannot keep pace with annual, market-wide audits, and add-only tools now create the very risk CMS is hunting. RAAPID’s RADV Audit Solution, powered by Neuro-Symbolic AI, takes a different path. It pairs large language models with a clinical knowledge graph to validate each HCC against MEAT-based evidence in the note, and it works in two directions: it surfaces supported diagnoses to add and flags unsupported ones to remove.

What that means in practice:

  • Explainable evidence trail. Every suggested HCC links to the specific documentation that supports it, so the diagnosis can stand up to CMS scrutiny.
  • Decision support, not automation. The platform recommends; certified human coders make the final determination, which mirrors how CMS itself now uses AI as coder support [1].
  • Two-way coding built in. Adds and deletes in one workflow, the direct answer to the add-only programs DOJ has penalized.
  • Speed with control. Chart review runs in about 8 to 12 minutes per record, with 92% out-of-the-box accuracy that reaches 98%-plus after human-in-the-loop quality review.
  • Productivity for stretched teams. Coding teams report 60 to 80% productivity gains,* freeing experts from low-value manual work.

The result is a single source of truth for member risk, where every diagnosis is encounter-linked, evidenced, and audit-ready. See how it works in a live demo.

RADV Audit Readiness: Practical Steps

Risk adjustment data validation rewards plans that prepare year-round, not in a fire drill. Audit readiness is a discipline, not a one-time scramble. Start here:

  • Assess current documentation quality. Sample charts across your provider networks and measure how many would survive a MEAT check today.
  • Target your highest-risk diagnoses. Focus first on acute conditions and chronic codes that auditors challenge most, like the stroke and MI categories OIG flagged [5].
  • Run two-way validation. Add supported codes and remove unsupported ones so your submissions reflect documented reality, not optimistic capture.
  • Educate clinicians. Give providers clear, specific feedback on documentation gaps instead of generic reminders.
  • Build retrieval and response muscle. Confirm you can pull records fast and assemble a clean submission package inside the five-month window [1].

Plans that treat every diagnosis as if it will be audited turn RADV from a threat into proof of quality.

Common Questions from RADV Audit Teams

A risk adjustment data validation (RADV) audit is CMS’s review of medical records to confirm that diagnosis codes a Medicare Advantage plan submitted for payment are supported by documentation from a face-to-face encounter in the payment year. Unsupported codes are deleted and the related payment is recovered [1].

Each diagnosis must come from a face-to-face encounter in the payment year and show MEAT evidence: the condition was Monitored, Evaluated, Assessed, or Treated. The record needs member identification, a credentialed provider signature with date, and an ICD-10-CM code coded to the right specificity [1].

No, extrapolation is paused. A September 2025 federal court ruling vacated CMS’s extrapolation methodology, so extrapolated penalties are on hold pending appeal. The audits continue, and CMS can still delete unsupported diagnoses and recover the direct overpayment on sampled members [2].

Under the January 2026 CMS memo, sample sizes run from about 35 to 200 enrollees per contract, scaled to contract size. Plans get a restored five-month medical record submission window to gather and submit documentation, not the tighter timelines seen in earlier cycles [1].

Because adding codes without removing unsupported ones is now treated as intent to inflate payments. The March 2026 Aetna settlement put $87.2 million against an add-only PY2015 program that submitted codes but failed to delete unsupported ones its own reviews found [4]. Two-way coding is the compliant standard.

History-of conditions coded as active diagnoses. OIG audits in 2026 repeatedly found past conditions, such as a prior stroke coded as an acute stroke or resolved cancer coded as active, driving 91% error rates in sampled enrollee-years [5]. Active management at the encounter is what separates a valid code from a deletion.

Conclusion: Defensible Coding Is the New Compliance Standard

RADV audit guidelines in 2026 reward one thing: proof. Every diagnosis needs an encounter, evidence, and a clear trail back to the chart. CMS is auditing the whole market, OIG keeps finding the same history-of errors, and DOJ is settling cases against plans that added codes but never removed the bad ones. Extrapolation is paused, which gives plans a window to fix documentation before the financial multiplier returns.

The plans that come through this in good shape will be the ones that build two-way, evidence-first coding into daily operations. That is defensible accuracy, and it is where compliance and quality finally point the same direction. To see how RAAPID’s RADV Audit Solution makes coding audit-ready, book a demo.

*Internal RAAPID benchmark, based on RAAPID platform performance data; not an externally published figure.

About the author

Wynda 1

Wynda Clayton, MS, RHIT, CRC

Director of Risk Adjustment Coding & Compliance, RAAPID

Wynda is a recognized leader with over 20 years of experience in risk adjustment, coding, and compliance. A seasoned former CMS RADV auditor and educator, she focuses on improving coding accuracy and maintaining regulatory standards. At RAAPID, Wynda leads AI-driven initiatives that support defensible, value-based care delivery and reimbursement accuracy.

Lastest Posts

Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Disclaimer: All the information, views, and opinions expressed in this blog are inspired by Healthcare IT industry trends, guidelines, and their respective web sources and are aligned with the technology innovation, products, and solutions that RAAPID offers to the Risk adjustment market space in the US.