>>
Industry>>
Healthcare>>
The Liability Nobody in the Ro...Ask a health plan CFO what their risk adjustment exposure is and you get a range, a set of assumptions, and visible discomfort. The number is not knowable with the tools most plans have, and everyone in the room understands that.
That is a strange position for a line item driving a large share of revenue, and it is why risk adjustment has moved from an operations conversation to a board conversation.
What changed
Federal audit findings became hard to argue with. The HHS Office of Inspector General has audited diagnosis codes it identifies as high risk for miscoding, and reports that it "reviewed medical records that MAOs provided as support; however, a high percentage of the associated HCCs could not be validated." Its conclusion is that it has "indications that MAOs are submitting diagnosis codes for payment that are not verifiable." These are audits of documentation sufficiency, not of clinical judgement.
Compliance guidance was rewritten. OIG issued industry segment-specific compliance guidance for Medicare Advantage, updating guidance it last published for this sector in 1999. The guidance itself is voluntary. What it points at is not. It lists "failing to remove diagnosis codes previously submitted to CMS when chart reviews provide information that those codes were unsupported or otherwise invalid" among conduct revealed by federal investigations, and records that MA organisations "must also report to CMS: (1) unsupported and otherwise invalid diagnosis codes ... and (2) overpayments" under 42 U.S.C. 1320a-7k and 42 CFR 422.326.
For a finance function that distinction is the whole point. Finding an unsupported code is discretionary. Reporting it, once found, is not. Which means a review capability that cannot find one is not a neutral gap in the operating model. It is the thing standing between the organisation and a duty it already has.
Payment rules tightened. In its CY 2027 rate announcement, CMS finalised the exclusion of chart review diagnoses not linked to a qualifying encounter.
The effect on the balance sheet is specific. Diagnoses submitted without defensible documentation are not revenue, they are unquantified contingent liability. The quantity is unknown because most plans cannot examine their own submitted population and say which codes would survive review.
Why the current window matters
Audit activity has become regular rather than episodic. At the same time, extrapolation of audit findings across a contract population remains paused following federal litigation.
That pause is the strategic point. It defines a period in which a plan can examine and correct its own submissions before the financial mechanics of a finding become harsher. Plans reading it as relief are reading it wrong. Plans reading it as a window are reading it correctly, and the difference will show up in their numbers later.
Where vendor evaluation goes wrong
Most plans have vendors doing this work, and the criteria those vendors were selected against are now the problem.
A chart review vendor is measured on yield: conditions identified, risk score impact, return per chart. Those are discovery metrics. None measure whether the vendor can tell you a submitted code is unsupported, and a vendor paid on yield has no reason to volunteer that capability.
Underneath the commercial issue sits a technical one that surprises most boards. Systems built on statistical prediction compute the probability that a code applies. Their output is candidates and confidence values. That output structure has no position corresponding to "this code should be removed."
OIG has already flagged the automated form of one-directional review, naming prompts "generated by artificial intelligence algorithms" that push clinicians toward adding risk-adjusting diagnoses. A board asked whether its own tooling can only add should be able to get a straight answer, and at present many cannot.
So the one-directional pattern is not solvable through vendor management. No contract term extracts a negative finding from a system with no way to express one, and the usual remediation, more review cycles and tighter oversight, operates on an output the tool cannot produce.
The question that separates vendors
The practical evaluation questions follow, and they are hard to answer in a demo.
Show the output for one record. Not a dashboard. The artifact a coder actually sees.
Can the system tell us a submitted diagnosis is unsupported, and what does that output look like on screen?
When coding criteria change mid-year, what has to happen, how long does it take, and who does it?
Vendors differ substantially here, and the difference does not show up in a capability comparison or an accuracy figure. Risk adjustment solutions for health plans built on explicit rule representation answer these questions differently from those built on prediction alone. The distinction becomes visible at the point a record is pulled, which is later than anyone would choose to discover it.
The trade-off worth demanding
Explicit rule representation carries a maintenance burden. Criteria change, and each change means updating and revalidating the knowledge base. Predictive systems avoid this entirely, which is much of why they deploy faster.
Any vendor presenting an inspectable architecture as having no downside is describing marketing rather than engineering, and the right response is scepticism about the rest of the pitch.
What this is actually about
Those objectives select different tools. A system optimised to find more will find more. Asking it to also remove what should not be there is asking for an output it was never built to have.
For a CFO trying to put a number on the exposure, that distinction is where the number comes from.
Comments