Medicare Risk Adjustment Compliance: Lessons from 2026's Enforcement Wave
CMS is auditing every Medicare Advantage contract annually starting 2026, and DOJ settled $558M+ in risk adjustment fraud cases in a single August. Here's what compliant coding actually requires.
On 26 August 2026, The Villages Health System agreed to pay $541.5 million to resolve allegations that it submitted Medicare Advantage diagnosis codes that weren't properly supported by medical records — one of three False Claims Act settlements over risk adjustment coding the Department of Justice announced in a single month. For any organisation billing Medicare Advantage on a risk-adjusted basis, the message from 2026 enforcement activity is unambiguous: risk adjustment coding accuracy isn't a back-office coding detail, it's a compliance exposure with nine-figure consequences.
What risk adjustment actually does
Medicare Advantage plans are paid more for enrollees who are documented as sicker, because a sicker population costs more to treat. Each diagnosis a provider documents and a plan submits to CMS can map to a Hierarchical Condition Category (HCC), and HCCs raise a patient's risk score — and therefore the plan's payment. The system exists to stop plans from being financially punished for enrolling higher-need patients. It becomes a compliance problem when the incentive to document more diagnoses outpaces the clinical reality: a code submitted for a condition that isn't actually being addressed at that visit inflates payment without inflating actual care.
The documentation standard: MEAT
CMS requires that every diagnosis code submitted for risk adjustment be supported by a face-to-face medical record from that payment year. The industry shorthand for what "supported" means is MEAT — a condition must be Monitored, Evaluated, Assessed, or Treated at that encounter. Any one of the four is enough, but at least one has to be clearly documented. The most common compliance failure isn't fabrication — it's coding a historical condition (a stroke from three years ago, a resolved infection) as though it were being actively managed at the current visit, when the chart shows no current monitoring, evaluation, assessment, or treatment of it at all.
That failure mode shows up starkly in CMS oversight data. An HHS Office of Inspector General audit found a 91% error rate on certain high-risk diagnosis categories, with acute stroke and myocardial infarction codes carrying a 100% error rate — meaning essentially none of the sampled codes for those conditions had current-year supporting documentation.
RADV audits are scaling up sharply in 2026
Risk Adjustment Data Validation (RADV) audits are how CMS checks submitted codes against actual medical records. Historically, CMS audited a relatively small number of Medicare Advantage contracts each year — roughly 60. Starting in February 2026, CMS moved to audit all 550-plus eligible MA contracts annually, on a quarterly cadence, with sample sizes of roughly 35 to 200 enrollees per contract and a five-month window for plans to submit supporting medical records. That's a fundamental shift from spot-checking to near-universal audit coverage, and it means coding practices that went unexamined for years are now far more likely to be reviewed.
What 2026 enforcement actually looked like
Beyond the RADV audit itself, the Department of Justice has been actively pursuing False Claims Act cases tied to risk adjustment coding, several disclosed or settled this year:
- The Villages Health System — $541.5 million (26 August 2026), for diagnosis codes lacking adequate medical record support, including codes based on unapproved amended records. The organisation received cooperation credit for self-disclosing through the HHS-OIG protocol.
- Complete Health Partners Holdings — $14.2 million (3 August 2026), following a qui tam suit alleging the organisation disseminated incorrect coding guidance and retrospectively added diagnosis codes for conditions like substance use and psychiatric disorders under a risk-sharing arrangement that rewarded higher risk scores.
- Monogram Health — $2.4 million (24 August 2026), over inaccurate diagnosis codes for conditions including malnutrition and hematological disorders, again under a risk-sharing contract structure.
- Aetna — $117.7 million (March 2026), which included $87.2 million specifically tied to "add-only" coding programs that added diagnosis codes without ever removing codes that weren't actually supported — a one-directional review process that federal investigators treated as itself evidence of a compliance failure.
A pattern runs through all four: risk-sharing or incentive-based payment arrangements that reward higher risk scores, paired with coding or documentation processes that weren't independently checking whether the added codes were actually supportable. Self-disclosure clearly mattered — The Villages' cooperation credit reduced what could otherwise have been a larger exposure.
Building a defensible risk adjustment coding process
- Train coders and clinicians on MEAT, not as an abstract acronym but against real chart examples, with particular attention to historical-versus-active diagnosis distinctions.
- Audit both directions. A coding integrity programme that only adds codes and never removes unsupported ones is exactly the pattern DOJ flagged in the Aetna settlement — a genuine compliance programme has to be willing to subtract risk score, not just add it.
- Treat risk-sharing incentive structures as a red flag to monitor, not ignore. If a coding vendor, physician group, or internal team is financially rewarded for higher risk scores, that arrangement itself needs independent compliance oversight, per the pattern across the 2026 settlements.
- Know the self-disclosure pathway. The HHS-OIG self-disclosure protocol produced meaningfully better outcomes in 2026 enforcement than waiting to be audited — a compliance programme that can catch and report its own errors is treated differently than one that gets caught.
This overlaps directly with the broader fraud and abuse landscape covered in Learnsignal's Stark Law and Anti-Kickback Statute training, since risk adjustment fraud is prosecuted under the same False Claims Act framework, and with the documentation discipline covered in incident investigation and documentation standards — the underlying skill of writing accurate, contemporaneous, defensible clinical documentation is the same one that protects against both.
Frequently asked questions
Who is liable when a coding vendor submits unsupported codes — the plan or the vendor?
Both can face exposure. Recent settlements have targeted provider groups and coding vendors directly, not just the Medicare Advantage plan itself, particularly where risk-sharing contracts gave the vendor a direct financial incentive to inflate codes.
Does a single unsupported diagnosis code create False Claims Act liability?
Isolated coding errors are a normal part of any large-scale system and are typically handled through refunds and corrections. Liability escalates when there's a pattern — systemic add-only reviews, coding guidance that ignored MEAT criteria, or a financial structure that rewarded inflated codes.
What's changing with RADV audits in 2026 specifically?
CMS moved from auditing a small subset of Medicare Advantage contracts each year to auditing all 550-plus eligible contracts annually, on a quarterly cadence, starting February 2026 — a major expansion in audit coverage.
Risk adjustment compliance sits at the intersection of clinical documentation, coding accuracy, and fraud enforcement, and 2026's settlement activity shows regulators are treating it as a top enforcement priority. Learnsignal's CPD training library covers healthcare compliance training, including fraud, billing, and documentation topics for teams navigating Medicare Advantage risk adjustment.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


