Why Retrospective Risk Adjustment Software Just Changed: Your Compliance Checklist for 2026
Healthcare organizations have 90 days to audit their risk adjustment programs, and most don’t realize the rules have shifted.
The difference between a defensible program and an expensive compliance failure now comes down to one critical practice: two-way coding.
For years, risk adjustment felt simple. Find more diagnoses in old charts, submit them to CMS, raise the member’s risk score.
That approach is ending in 2026, and regulators are making the enforcement real. Health plans and providers that want to survive RADV audits need to understand why add-only chart review is no longer enough.
This guide walks through what retrospective risk adjustment actually means today, why the compliance landscape shifted, and what your organization needs to do right now to stay defensible.
Key Takeaways
- Retrospective risk adjustment software must now do two-way coding: adding supported diagnoses and removing unsupported ones, not add-only chart mining.
- The 2026 OIG guidance flags add-only review as a compliance risk, and the DOJ enforced this standard with a 117.7 million $ settlement against Aetna in March 2026.
- An OIG audit found 91 percent of sampled enrollee-years carried at least one unsupported high-risk diagnosis, often history-of conditions coded as active.
- CMS accelerated RADV audits for Payment Year 2020 with sample sizes of 35 to 200 enrollees and a strict five-month medical record window.
- AI-assisted two-way retrospective coding reaches 92 percent out-of-box accuracy and reduces chart review time to 8 to 12 minutes, with a 60 to 80 percent productivity gain for coding teams.
The Old Model Is No Longer Defensible
Retrospective risk adjustment has always been about the past. You look back at a member’s medical record after care has been delivered, hunt for diagnoses that should have been coded but were missed, and submit those codes to CMS.
In theory, this captures real patient complexity that claims processing overlooked. In practice, something went wrong.
The Office of Inspector General found that chart reviews accounted for roughly 6.7 billion dollars in Medicare Advantage payments in 2017 alone.
But here’s what matters: over 99 percent of those reviews only added codes; they never removed a single unsupported diagnosis.
That lopsided pattern caught regulators’ attention. Health plans that added diagnoses without removing the codes that should come out looked like they were mining charts for revenue, not cleaning records for accuracy.
The OIG flagged this pattern as a compliance risk, and the Department of Justice backed it up with enforcement.
In March 2026, the DOJ settled with Aetna for 117.7 million dollars over a program that did exactly this.
The complaint was blunt: the plan added new diagnoses but failed to delete the unsupported codes its own reviewers identified. That behavior now counts as a regulatory failure, not an operational oversight.
The lesson is simple but harsh. If your review finds a code that should come out and you leave it in anyway, that decision is documented evidence. Regulators see add-only programs as deliberately inflating risk scores.
What Changed in 2026
The February 2026 Medicare Advantage Industry-Specific Compliance Program Guidance from the OIG represents the first major update since 1999.
This document spells out which practices now draw federal scrutiny and which ones protect your organization.
The guidance is explicit: chart reviews that add diagnoses without removing unsupported ones are flagged as suspect.
Health plans must now review any software they use in risk adjustment, including vendor tools, to confirm it isn’t designed primarily to inflate risk scores without clinical validity. The standard has moved from “find more codes” to “prove every code.”
At the same time, CMS moved more aggressively on RADV audits. Payment Year 2020 audits launched in February 2026, with contract-level samples ranging from 35 to 200 enrollees and only five months to submit medical records.
For many organizations, the audit that determines compliance for millions of dollars is already underway.
The financial stakes have never been higher. Unsupported diagnoses don’t just cost you at audit time; they also undermine patient outcomes.
When billing-first risk adjustment replaces care-first documentation, the clinical record becomes less useful for actually managing patient health.
Two-Way Coding Is the Fix
Two-way retrospective coding means adding supported diagnoses and removing unsupported ones in the same review. This is the core difference between a compliance liability and a defensible program.
Here’s how it works in practice. Your team reviews a chart and identifies three things: one diagnosis that should be added because it was documented but never coded, one diagnosis that needs to stay because it’s properly supported, and one diagnosis that should come out because the documentation doesn’t actually support it. A two-way program handles all three. An add-only program ignores the third one.
Every decision gets linked to evidence. That’s where MEAT documentation comes in. MEAT stands for Monitor, Evaluate, Assess, Treat, and it’s the standard that shows a diagnosis was actively managed during an encounter. If you’re removing a code, you document why the chart doesn’t meet MEAT criteria.
That evidence trail is what makes you audit-ready. When CMS asks you to defend a code you kept or explain why you removed one, you have a documented reason, not a guess.
Building the Evidence Trail

The practical process of defensible retrospective review breaks down into four steps, each building the audit record.
First, you select charts strategically. Rather than reviewing every record, use predictive analytics to target high-value charts: members with multiple chronic conditions, members on medications that suggest undocumented diagnoses, and members whose risk scores dropped unexpectedly.
This focuses your team on the records most likely to contain missed diagnoses or unsupported codes.
Second, you validate every HCC code against current documentation. The CMS-HCC model changes yearly.
For 2026, that’s Version 28, which means coders have to revalidate codes against the current mapping.
Third, you implement retrospective risk adjustment software with both adds and deletes. This is where decision support tools make a huge difference.
AI-assisted review can flag unsupported diagnoses with the same rigor it uses to surface missed ones.
Fourth, you run quality assurance before submission. Multi-level checks confirm that every code has defensible evidence, that face-to-face encounters meet CMS requirements, and that documentation is reconciled across the patient’s care network.
This gives your team one clear place to see each member’s risk information, backed by real encounter records instead of guesswork.
What Unsupported Diagnoses Actually Look Like
Audit data shows how common this problem is. An OIG audit found that 91 percent of sampled enrollee-years carried at least one unsupported high-risk diagnosis.
The most frequent error was a history-of-condition coded as active, like a past stroke coded as an acute stroke.
These mistakes cost real money. A single unsupported HCC code can affect member risk scores for multiple years if the deletion doesn’t happen.
Multiply that across thousands of members, and the compliance exposure becomes substantial.
Worse, these errors often show up in patterns. If your organization’s coding intensity is higher than that of peer organizations, that’s a red flag for regulators.
If you’re adding diagnoses at higher rates than you’re deleting them, that’s another signal. Audit readiness means knowing your own patterns before CMS does.
The Technology Question
Many organizations ask if AI replaces human coders in retrospective review. The answer is no, and regulators want to see it that way. AI works as decision support, not automation.
The strongest programs use AI to identify candidates for addition and deletion, then let certified medical coders confirm or reject each suggestion.
The coder makes the final decision, which means the decision stays auditable. AI handles the heavy lifting of searching unstructured clinical data and linking diagnoses to evidence.
This is where speed comes from. When AI surfaces the evidence, coders spend their time judging clinical validity instead of hunting through charts.
Review time drops from 30 to 45 minutes per chart down to 8 to 12 minutes, and coding teams report 60 to 80 percent productivity gains.
Your Action Plan
Start by auditing your current program against the 2026 guidance. Are you doing two-way coding or add-only chart review?
Do you have documented reasons for every code you delete? Can you show the MEAT evidence behind every diagnosis you keep?
Next, evaluate your vendor tools. If your software is designed primarily to find new codes without surfacing unsupported ones for deletion, that’s a compliance problem. You need visibility into both sides of the coding decision.
Then, run a sample audit on your own records before CMS does. Pull 50 charts, review them with the new two-way standard, and see what you find.
Benchmark your deletion rate against your addition rate. If they’re lopsided, you have work to do.
Finally, build two-way coding into your standard workflow. Make deletion as routine and documented as addition. Train your team to see both as equal parts of accuracy.
Frequently Asked Questions
What is two-way retrospective risk adjustment coding?
Two-way retrospective risk adjustment coding means adding supported diagnoses and removing unsupported ones in the same review, with MEAT evidence behind every decision. This is the core difference between a compliance liability and a defensible program.
Why is add-only chart review no longer compliant?
Add-only chart review submits new diagnoses but ignores unsupported codes the same review identifies, which regulators now see as deliberately inflating risk scores.
The OIG’s February 2026 guidance explicitly flags this pattern as a compliance risk, and the DOJ enforced it with a 117.7 million $ settlement.
What does MEAT documentation mean in retrospective coding?
MEAT stands for Monitor, Evaluate, Assess, Treat, and it’s the standard that shows a diagnosis was actively managed during an encounter.
Every HCC code you keep must link to MEAT evidence, and every code you delete must be documented with a reason the chart doesn’t support it.
How long does an AI-assisted retrospective review take per chart?
AI-assisted review reduces chart review time to 8 to 12 minutes per chart, compared to 30 to 45 minutes for manual review alone.
This speed comes from the AI surfacing evidence so coders spend their time judging clinical validity instead of hunting through charts.
What is the difference between retrospective, prospective, and concurrent risk adjustment?
Retrospective review looks back at completed documentation to confirm and clean coded diagnoses after the encounter is done.
Prospective risk adjustment helps providers capture valid conditions while the patient is being seen. Concurrent review takes place during a care episode or soon after it ends, so coding problems can be corrected more quickly.
Does AI replace human coders in retrospective review?
No, AI works as decision support, not automation, and regulators expect to see human coders in the final decision.
AI identifies candidates for addition and deletion and links them to evidence, but certified medical coders confirm or reject each suggestion to keep the process auditable.
When does CMS audit retrospective risk adjustment?
CMS accelerated RADV audits for Payment Year 2020 starting in February 2026, with sample sizes of 35 to 200 enrollees per contract and a strict five-month medical record submission window.
Many organizations’ audits are already underway, making it critical to audit your program now before CMS arrives.
What are the penalties for add-only retrospective coding programs?
The March 2026 DOJ settlement with Aetna totaled 117.7 million dollars for a program that added diagnoses but failed to delete unsupported ones, setting a clear enforcement precedent.
Health plans and providers face both financial penalties and reputational damage when audits expose add-only programs.
How do I know if my retrospective risk adjustment software is compliant?
Review your software’s design to confirm it flags both unsupported diagnoses for deletion and supported ones for addition with equal rigor. Your software should create a documented evidence trail for every code you keep or delete, and it should support two-way coding as a standard function.
What should my organization do right now?
Start by auditing your current program against the 2026 OIG guidance to see if you’re doing two-way coding or add-only review.
Next, evaluate your vendor tools to confirm they support deletion as robustly as addition, then run a sample audit on 50 charts using the new standard before CMS does.
Moving Forward
The stakes for risk adjustment accuracy have never been higher in Medicare Advantage. Regulators are enforcing a new standard, audits are accelerating, and the financial exposure is real.
But the path forward is clear: move from add-only mining to two-way defensible coding. Your organization can be audit-ready in 2026 if you start now. The time to act is this quarter, not when CMS arrives with audit samples.
Website & Email Hosting
Get the best website & email hosting for speed, security, and peace of mind. No restrictions. Freedom to do what you need in order to run your business.










No comments yet