Retrospective HCC Coding: Complete Guide to Audit-Ready Reviews

Risk adjustment work is under closer review in 2026. The 2024 CMS-HCC model is now fully in effect, and Risk Adjustment Data Validation (RADV) audit cycles have restarted.
For CY 2026, CMS completed the three-year phase-in of the 2024 CMS-HCC model and calculated 100% of Medicare Advantage risk scores using that model. For coding teams, the goal is clear: build audit-ready, two-way retrospective reviews that hold up under scrutiny.
Key Terms
Retrospective HCC coding is the review of past encounters to confirm which Hierarchical Condition Category (HCC) diagnoses were documented and supportable, then correcting the record with both additions and deletions.
MEAT stands for Monitor, Evaluate, Assess and Treat. It describes the kind of clinical documentation that shows a diagnosis was actively managed during a face-to-face encounter.
Two-way coding means a reviewer captures missed diagnoses and removes unsupported ones. Risk-adjusted payments must be supported by diagnoses documented from face-to-face encounters and coded per ICD-10-CM guidelines.
What Changed for 2026
The 2024 CMS-HCC model, often called V28, includes 115 payment HCCs out of 266 total categories. Codebooks, mappings and reviewer training should reflect that structure.

OIG has published Medicare Advantage compliance guidance that flags the risk-adjustment process as vulnerable to fraud and abuse. It also lists practices to avoid, including AI-driven prompts that nudge unsupported diagnoses.
CMS published a RADV audit schedule in March 2026. The schedule lists initiation months by payment year, including March 2026 for PY 2020 and May 2026 for PY 2021.
AI Workflow Automation, Not Autopilot
AI workflow automation uses software to coordinate repeatable steps so people spend less time on manual handoffs. In coding, that can include chart triage, evidence extraction, queue routing and packet assembly.
In practice, AI workflow agents can move work from one step to the next, summarize chart details and flag evidence for a human reviewer. Generative tools can also support automation through summarization and data analysis.
The key word is review. Certified coders should approve every code. If you want a broader primer on how AI task agents coordinate tasks across steps, that background helps explain why human oversight stays central here.
The Audit-Ready Workflow
Chart Selection and Prioritization
Rank charts by likely value and risk. Prioritize members with open gaps and encounters most exposed to audit sampling.
Documentation Ingestion and ICD-10 Mapping
Pull encounter notes and map documented conditions to ICD-10-CM. Confirm each mapping reflects the current V28 category structure.
MEAT Verification
Check that the note shows the condition was monitored, evaluated, assessed, or treated. A diagnosis without MEAT should not be submitted.
Two-Way Coding and Query Management
Add supportable diagnoses and delete those the record does not support. Route unclear cases to provider queries with specific documentation questions. This is where AI workflow automation can help, moving files between tasks while coders make the coding decisions.
QA Gates and Sign-Off
Apply a second review before anything advances. A certified coder signs off, and the sign-off is recorded.
Evidence Pack Generation for RADV
Assemble the source note, encounter date, code and coder attestation into one exportable packet aligned to RADV fields.
Submission Hygiene and Retention
Confirm dates, signatures and mappings before submission. Store records where they can be retrieved quickly.
Evidence Standards to Meet
Medicare Advantage organizations (MAOs) must ensure submitted diagnoses are documented from face-to-face visits and coded per ICD-10-CM and AHA Coding Clinic guidance. That face-to-face rule is one of the first things an audit tests.
Every code needs a dated source note and a coder attestation. Missing dates, signatures or source references weaken the packet.
Retention is long. MAOs must retain relevant records for 10 years, and CMS retains audit rights for 10 years from the end of the final contract period.

Common Failure Patterns to Avoid
Add-only reviews are a frequent problem. An OIG analysis found that over 99% of chart reviews added diagnoses, and diagnoses reported only on chart reviews led to an estimated $6.7 billion in 2017 Medicare Advantage payments.
Watch for diagnoses drawn only from health risk assessments without supporting care. Also watch for AI or EHR prompts that push unsupported codes, which OIG guidance calls out directly.
Other common gaps include reviews that never delete anything and packets missing dates or coder signatures. Each is easy for an auditor to spot.
The Tools Landscape
When comparing options, focus on features that support defensible work: two-way coding support, MEAT evidence surfacing, exportable audit packets and role-based permissions. Treat vendor claims as capabilities to verify against your own charts, not as guaranteed outcomes. Document queue routing, evidence extraction, packet assembly, user permissions, exception handling, approval logs, audit exports and coder sign-off controls before selecting AI agents.
A Quick-Start Checklist
- Update codebooks and mappings to reflect the V28 category structure.
- Refresh coder education on MEAT and two-way review.
- Mock-audit 20 charts against the face-to-face encounter rule.
- Confirm your 10-year retention procedure is documented.
- Map evidence pack fields to RADV requirements.
- Add a QA gate with recorded coder sign-off.
- Log every deletion, not just additions.
- Set a rule that AI never finalizes a code alone.
A Mini-Timeline for 2026 Audits
CMS lists PY 2020 audits beginning in March 2026 and PY 2021 audits beginning in May 2026.
CMS sends RADV audit notices through HPMS to identified points of contact a few weeks before the submission window opens. Stage your work so evidence packs for older payment years are ready before notices arrive.
FAQ
1. Should AI finalize HCC codes?
No. AI workflow automation can route files and surface evidence, but certified coders should approve every code before submission.
2. What should a RADV packet include
Include the source note, encounter date, diagnosis code, MEAT support, coder attestation and retrieval details.
Author
Vlad Orlov
Managing brand partnerships at Respona, Vlad Orlov is a passionate writer and link builder. Having started writing articles at the age of 13, their once past-time hobby developed into a central piece of their professional life.


