CMS/HCC Risk Adjustment: A Practice Operations Guide
It's the second week of February and an email lands in your records inbox: a retrieval vendor, working for a Part C health plan, wants 340 charts in 14 days. They've attached a spreadsheet of patient names, dates of birth, and member IDs. They'd also like read-only credentials to your EHR so they can pull the rest themselves.
That request exists because of CMS/HCC risk adjustment — the model CMS uses to pay Medicare Part C plans based on the documented health status of their enrollees. Your practice is not paid under that model, but you generate the documentation it runs on. This guide covers the operational mechanics, then the privacy and vendor obligations that come attached, because the second half is where practices get hurt.
What CMS/HCC Risk Adjustment Asks of Your Practice
CMS/HCC stands for the CMS Hierarchical Condition Category model. CMS groups ICD-10-CM diagnosis codes into condition categories, assigns each category a relative weight, and pays Medicare Part C organizations a risk-adjusted capitated amount per enrollee. Higher documented clinical complexity means a higher payment to the plan.
Three operational facts follow from that, and they're the ones your staff needs to internalize:
- Diagnoses reset every calendar year. A condition documented in 2025 does not carry forward for 2026 payment purposes. It must be captured again in a qualifying encounter during the payment year.
- The diagnosis must come from an acceptable encounter and an acceptable provider type, and it must be supported by the record — not by a problem list carried forward untouched.
- Plans, not practices, submit the data to CMS. Your practice's role is to document accurately, code from the documentation, and respond to record requests and queries.
For payment year 2026, plans are working under version 28 of the model, the final step of a phase-in CMS laid out in its rate announcements. Version 28 restructured condition categories and changed which codes map to a payment category. The practical effect on your practice: plans and their vendors are chasing a different mix of charts than they were three years ago, and specificity in documentation matters more than volume. CMS publishes the model files and rate announcements on its risk adjustment page.
The Calendar That Drives Every Chart Chase
Risk adjustment work is seasonal, and if you staff for it evenly across the year, you will be underwater in Q1 and idle in Q3.
January through May
Peak retrieval season. Plans are closing out the prior payment year before CMS's final submission window shuts, and simultaneously starting the current year's capture. Expect the heaviest volume of chart requests, provider queries, and pressure for remote EHR access during these months.
June through September
Second-wave sweeps and gap-closure outreach. Plans send lists of members with conditions documented in prior years that haven't been re-captured in the current year. Your schedulers may get pressure to book annual visits.
October through December
Year-end capture push, and the window in which unaddressed gaps become permanently uncapturable for that payment year. Also the season when plans propose in-office assessment programs staffed by their own clinicians — a vendor arrangement that needs privacy review before your medical director says yes.
RADV audits — CMS's Risk Adjustment Data Validation program — arrive on their own schedule. CMS finalized its RADV methodology in 2023, including extrapolation of audit findings for audit years beginning with 2018. When a plan is selected, it must produce the medical record that supports each sampled diagnosis. That request lands on your HIM staff, often for encounters several years old, frequently with a short turnaround.
How Practices Determine and Document Code Selection
This is administrative guidance about process. Code selection for a specific patient is a clinical and coding judgment made by the treating provider and your certified coders, working from the documentation in front of them.
Most practices build their process around a few operating rules:
- Code from the encounter documentation, not from the problem list. A condition that appears only in a copied-forward problem list, with no assessment in the note, is the single most common finding in a failed audit.
- Apply a documentation convention consistently. Many practices train providers on the MEAT convention — that a condition be Monitored, Evaluated, Assessed, or Treated in the note. It's an industry documentation standard, not a CMS regulation, but it gives coders a defensible test.
- Route queries through a named person. When a coder or a plan vendor believes documentation supports a more specific code, that query goes to the provider through a documented, non-leading query process. Never let a vendor edit a note.
- Log every addendum. Late entries and amendments must be identifiable as such, with author and date. Your EHR should enforce this; verify that it does.
Assign one person — usually your coding lead — to own the annual mapping review when CMS updates the model or the ICD-10-CM code set. Do not let that live with "whoever notices."
The Chart Chase: Who Is Actually Asking, and Under What Authority
Here is where administrators get it wrong in both directions — either refusing legitimate requests and creating friction with plans, or handing over records to anyone with a spreadsheet.
When the requester is the plan or the plan's retrieval vendor
A health plan requesting records to support risk adjustment submissions is generally engaged in payment and health care operations. HIPAA permits a covered entity to disclose PHI to another covered entity for the recipient's payment activities and for certain health care operations, without patient authorization, under 45 CFR 164.506. A retrieval vendor acting for the plan is the plan's business associate — not yours. You do not sign a BAA with them.
What you should do instead, every time:
- Obtain written confirmation from the plan naming the vendor as its authorized retrieval agent for the specific project, with an effective date range.
- Verify that every patient on the list is actually an enrollee of that plan and a patient of your practice. Mismatches happen and they are your liability, not theirs.
- Confirm the request is scoped to the encounters and date ranges relevant to the payment year — not "the complete chart."
- Log the disclosure. Payment and operations disclosures don't require an accounting to the patient, but you'll want the record when someone asks what left the building.
When you hire the coder, the auditor, or the analytics platform
Different analysis entirely. If your practice contracts with a coding company, a retrospective chart review firm, a risk adjustment analytics platform, or a scribe service to improve your own documentation capture, that entity is your business associate. You need a signed BAA in place before a single record moves.
HHS explains the scope of the relationship in its business associate guidance. The gap I see most often: a practice signs a services agreement in December to hit a Q1 capture target, the vendor starts pulling charts in January, and the BAA is still "with legal" in March. If you need a signature-ready agreement fast, you can generate a Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than letting the contract lag the data flow.
EHR Access for Risk Adjustment Vendors
Remote read-only access is faster than fulfilling 340 individual requests. It is also the arrangement most likely to show up in a breach report.
Rules to write into your access policy before you grant a single login:
- Unique credentials per person. Not per vendor. The Security Rule requires unique user identification at 45 CFR 164.312(a)(2)(i), and shared accounts destroy your ability to attribute activity.
- Scope access to the patient cohort. If your EHR supports restricting a role to a defined patient list or a payer group, use it. If it can't, you've just given a third party your entire panel.
- Set an expiration date on the account at creation. Ninety days, renewable. Vendor project managers rotate; access outlives them.
- Pull the audit log monthly during the project. Look for records accessed outside the cohort, off-hours bulk activity, and export volume.
- Disable within 24 hours of project close. Assign this to a named person with a calendar entry, not to "IT."
Apply the same discipline to bulk exports. A CSV of 340 patients emailed to a personal address is a reportable event; the same file transferred through the plan's secure portal is routine.
Minimum Necessary in a Bulk Records Pull
The minimum necessary standard applies to payment and health care operations disclosures. It does not apply to disclosures to another provider for treatment, and it does not apply to disclosures to the patient. Risk adjustment requests sit squarely in the category where it does apply — see the HHS minimum necessary guidance.
Practically, that means your HIM staff should be releasing the encounter notes, problem-relevant labs, and assessments for the dates requested — not psychotherapy notes, not unrelated specialty consults, not the full longitudinal record because it was easier to hit "print all." Build a standard risk adjustment release template in your EHR and train to it. "Easier" is not a defense.
State law layers on top. Substance use disorder records covered by 42 CFR Part 2, HIV status, and reproductive health information carry additional restrictions in many jurisdictions. Your release protocol needs a flag-and-escalate step for those categories.
A Workable Workflow, by Role
Front desk: confirms insurance and captures the plan at every visit. Wrong payer on file means your practice fields requests for patients who aren't in the plan's population — and discloses records it shouldn't.
Providers: assess and document conditions at the visit. No addenda requested by anyone outside the practice.
Coding lead: owns the query process, the annual code-set review, and the internal audit sample — pull 20 charts a quarter and check documentation support.
HIM/records: validates requester authority, scopes the release, logs the disclosure, and transmits securely.
Privacy officer: reviews every new vendor before onboarding, holds the BAA file, and reviews access logs during active projects.
Administrator: keeps the vendor list current and reconciles it against the BAA file twice a year. Every vendor touching PHI appears on both lists or neither.
Five Things to Fix This Quarter
- Reconcile your vendor inventory against your executed BAAs. Note every gap with a name and a due date.
- Write a one-page requester-verification checklist and tape it above the records workstation.
- Audit active EHR accounts for external users. Disable anything without an owner and an expiration date.
- Build the standard risk adjustment release template so staff stop exporting full charts.
- Confirm your risk analysis reflects current vendor data flows — including remote EHR access — and update it if it doesn't. If yours is stale, automated risk analysis and policy generation will move faster than a spreadsheet rebuild.
CMS/HCC work isn't going away, and the volume of third parties requesting your records under it keeps climbing. The practices that handle it cleanly aren't the ones that say no — they're the ones where every request has a verified requester, a scoped release, a logged disclosure, and, where the vendor works for you, a signed agreement dated before the first chart moved. Start with the BAA gaps, since those are the fastest to close and the hardest to explain after the fact.