HCC Coding Workflows: Records, Vendors, and Privacy
On February 3, a company you've never contracted with emails your office manager a spreadsheet of 214 patient names and asks for the full 2025 chart on each one. The signature block says they're working "on behalf of" a health plan you're contracted with. Your biller forwards it to you with a one-line question: do we have to send these?
That email is the operational tail end of HCC coding, and it is where most practices discover their records-handling process was built for subpoenas and patient requests, not for bulk payer chart retrieval. This guide covers how the HCC workflow runs inside a practice — who touches what, when, and on what clock — and then makes the privacy, records, and vendor consequences explicit. Coding and billing detail here is administrative: how your practice determines and documents code selection, not which code fits which patient.
What HCC Coding Is, in Plain Operational Terms
HCC stands for Hierarchical Condition Category. It is a grouping system CMS uses to sort ICD-10-CM diagnosis codes into categories that predict a patient's expected cost of care over the coming year. Health plans paid on a risk-adjusted basis — Medicare Part C plans, some ACA marketplace plans, and many value-based contracts — receive payment based in part on the diagnoses documented and submitted for each enrolled patient.
Practically: HCC coding is the annual process by which chronic and serious conditions that were documented and treated during a face-to-face encounter get coded, submitted, and thereby "recaptured" for the payment year. Not every ICD-10 code maps to an HCC. Codes that do map contribute to a risk score; codes that don't, don't. Your practice's job is documentation and accurate code selection, not score maximization.
The Annual Clock: Everything Resets January 1
The single most important operational fact is that risk adjustment data is collected on a calendar-year basis. A condition documented in October 2025 does not carry into 2026. It has to be documented again, during a qualifying face-to-face encounter with an acceptable provider type, in the new year.
That creates a predictable annual workload curve that most practices handle badly:
- January–March: payers push "suspect" and "gap" lists to your practice. Annual wellness visits and chronic care visits get scheduled.
- March–August: the bulk of recapture encounters happen. Coder queries pile up.
- September–December: the scramble. Outreach to patients who haven't been seen, retrospective chart review vendors calling, deadline pressure around plan submission windows.
Front-load it. A practice that books chronic-condition patients in Q1 and Q2 spends Q4 on collections instead of chart chases.
Who Does What: Role Assignments You Should Write Down
Scheduling and front desk
They flag which patients appear on payer gap lists and make sure those visits are booked as in-person encounters when the payer requires face-to-face documentation. They do not discuss diagnoses with patients. They do not tell a patient "the insurance company says you have diabetes." Script this.
The rendering provider
Documents each condition being evaluated or managed at that visit, in that visit's note, to the specificity the record supports. Signs and dates the note. Responds to coder queries within a defined turnaround — five business days is a reasonable internal standard.
Coder or CDI staff
Reviews the note against the documentation, selects codes supported by what the provider wrote, and issues non-leading queries where documentation is ambiguous. Maintains the query log. Never adds a diagnosis the provider didn't document.
Billing
Confirms the codes reached the claim, tracks rejections, and reconciles what the payer says it received against what you submitted. A diagnosis coded in the chart but dropped from the claim is invisible to the payer.
Compliance or practice administrator
Owns the query policy, the addendum policy, the vendor list, and the records-release process. That's you.
Documentation Standards Your Reviewers Will Apply
Coding staff and external auditors commonly evaluate whether a documented condition was actually addressed at the visit using shorthand frameworks — MEAT (Monitor, Evaluate, Assess, Treat) and TAMPER are the two you'll hear. These are review heuristics, not federal regulations. What matters administratively is that the note shows the condition was addressed at that encounter, by that provider, on that date.
Two policies save practices during audits:
Addendum discipline. Late entries and addenda are legitimate. Backdating is not. Your EHR should timestamp every addendum with the actual authoring date, the author, and the reason. If your system lets a note be edited silently after signature, that is a finding waiting to happen — and an integrity problem under the HIPAA Security Rule, not just a coding one.
Query neutrality. Written queries must present clinical facts and ask an open question. A query that suggests the answer creates an audit exposure and, in the wrong hands, a False Claims Act theory. Keep queries in the chart or in a retained query log; either way, they're part of the designated record set discussion.
The 2026 Model Transition: What Changed on Your Side
CMS phased in a revised CMS-HCC model over payment years 2024 through 2026, blending the older and newer versions along the way, with the newer model fully in effect for payment year 2026. Operationally, three things changed for practices:
- Some diagnosis codes that previously mapped to an HCC no longer do, and category structures were reorganized.
- Specificity matters more in several condition families, which means more coder queries, not fewer.
- Your 2024 crosswalks and cheat sheets are stale. If a payer or vendor handed you a laminated card in 2023, retire it.
Have your coding lead re-verify mappings against current CMS materials each year rather than trusting vendor-supplied summaries. CMS publishes the code sets and related guidance through its ICD-10 coding resources.
Chart Chases: The Records Request Nobody Budgeted For
Back to the February email. Bulk chart retrieval for risk adjustment is a payment activity, and HIPAA generally permits a covered entity to disclose PHI to a health plan for the plan's payment activities without patient authorization. That's the easy part. The hard parts are the four questions your staff won't think to ask.
1. Who is actually asking?
Retrieval companies work for plans. Verify the requester's identity and authority before releasing anything: a written engagement letter from the named plan, a contact at the plan you can independently confirm, and the specific contract or line of business involved. Log the verification. Your Privacy Rule verification obligation doesn't relax because the request arrived in a spreadsheet.
2. Is the scope minimum necessary?
A request for "the complete chart" on 214 patients is rarely defensible. Push back to date-of-service ranges and encounter types tied to the payment year at issue. HHS's minimum necessary guidance applies to disclosures you make in response to another entity's request; you are entitled to rely on a plan's representation of what it needs, but you are not required to accept an unbounded one.
3. How is it moving?
Fax to an unverified number, an emailed ZIP with the password in the same thread, a USB drive handed to a field auditor in your waiting room — all real, all avoidable. Require SFTP, a verified secure portal, or encrypted transfer with out-of-band credentials. If a vendor sends someone onsite to scan charts, that person needs a badge, an escort, a signed confidentiality attestation, and a workspace that isn't the break room.
4. What did you send, and can you prove it?
Keep a disclosure log with the date, requester, patient list, date range, delivery method, and staff member who released it. Disclosures for payment don't require an accounting of disclosures under the Privacy Rule, but when a plan later claims it never received a chart — or when a patient asks who has been reading their record — the log is the only thing standing between you and a guess.
Don't confuse a chart chase with a patient request
Patient access requests run on their own clock: generally 30 days, with one 30-day extension, and fees limited to a reasonable cost-based amount. Train front desk staff to route the two differently. A patient asking for their records is never a chart chase, and a chart chase never gets billed to a patient.
Your HCC Coding Vendor List Is Longer Than You Think
Write down every outside party that touches PHI in service of risk adjustment. A typical mid-sized practice finds six to ten:
- Outsourced coding or CDI firms
- Retrospective chart review vendors engaged by plans
- Chart retrieval and record copy companies
- Prospective "gap closure" platforms that read from your EHR
- Natural-language processing or AI tools that scan notes and surface suspected conditions
- In-home assessment companies requesting read access to your system
- Scanning and release-of-information services
- Analytics dashboards your MSO or IPA provisioned
Each of these is a business associate when it creates, receives, maintains, or transmits PHI on your behalf — and a written agreement is required before the data moves, per HHS guidance on business associate contracts. Where a vendor works for the plan rather than for you, the plan owns that BAA, but you still verify the relationship in writing before you release records.
If you're onboarding a coding contractor or a chart review platform this quarter and don't have an agreement ready, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when a vendor's own template arrives with the subcontractor and breach-notification clauses quietly hollowed out.
Four clauses to check before a coding vendor gets access
- Subcontractors. Offshore coding is common and lawful with proper agreements. Ask directly whether coders are offshore, in which countries, and whether downstream BAAs exist. Get it in writing.
- Breach notification timing. Sixty days from the vendor's discovery leaves you nothing. Negotiate for notice within a defined short window — many practices use five business days.
- Secondary use. Does the vendor use your data to train models, build benchmarks, or sell de-identified products? If yes, define the de-identification method and get it named in the contract.
- Return or destruction. At termination, specify the format, the deadline, and a written certificate of destruction. "Retained for internal purposes" is not an acceptable answer.
Access Provisioning: The Quiet Failure Mode
Gap-closure platforms and plan-side reviewers frequently ask for EHR logins. Every account you create is a standing door into your entire patient population, not just the patients on their list.
Provision role-limited, read-only accounts scoped as narrowly as your system allows. Set expiration dates tied to the project, not open-ended. Review the active user list quarterly and terminate the accounts of anyone whose engagement ended. Ask your EHR administrator to pull audit logs on external accounts twice a year and actually read them — unusual record-open volume from a review vendor is the pattern you're looking for.
Named accounts only. If a vendor requests one shared credential for a team of eight, that's a no, and it should be documented as a no.
Retention: Keep What an Auditor Will Ask For
Risk adjustment validation audits reach back years and require the original medical record supporting each submitted diagnosis — with a legible signature and credential, on the correct date of service. Retention periods vary by state law and payer contract; several plan agreements require ten years. Confirm your obligation against both your state's medical records statute and each payer contract, then set the longer of the two as your practice standard.
Keep the query log, the addendum history, and the disclosure log alongside the charts. Auditors ask how a code was determined, and "the coder remembers" is not an answer.
A 30-Day Cleanup Plan
- Days 1–5: Inventory every vendor and payer-affiliated party that has touched your charts for risk adjustment in the last 24 months.
- Days 6–12: Match each to a signed BAA or a documented plan-side relationship. Close the gaps.
- Days 13–18: Pull the external user list from your EHR. Disable anything stale. Set expiration dates on the rest.
- Days 19–24: Write a one-page chart-chase SOP: verification steps, scope limits, approved transfer methods, disclosure log entry. Train the two people who will use it.
- Days 25–30: Update your risk analysis to reflect the vendors and access paths you just documented, and note the HCC coding workflow as a distinct data flow.
If that last step is where your practice always stalls, automated risk analysis and policy generation will get you a defensible document set faster than another spreadsheet will.
Start With the Agreement You're Missing
HCC coding is a revenue process that quietly becomes a records-disclosure process every February. The practices that handle it well aren't the ones with the best cheat sheets — they're the ones whose vendor list is current and whose BAAs were signed before the first chart moved.
Before your next coding vendor or chart review platform gets access, build the Business Associate Agreement and have it signed. It takes about ten minutes and it's the document OCR asks for first.