A fax lands on your release-of-information desk this morning: a vendor working for a health plan wants 640 progress notes covering dates of service in calendar year 2025, and they want them in fourteen days. The cover sheet references risk adjustment and HCC ICD 10 validation. Your medical records clerk has two questions — do we have to send these, and who exactly is this company? This guide answers both, and then walks the workflow your practice needs so the next request does not turn into a scramble, an over-disclosure, or a breach entry in your log.

This is written for administrators, billing leads, and privacy officers. Nothing here tells you which code fits a given patient. It tells you how the process runs, who owns each step, and where the privacy exposure sits.

What "HCC ICD 10" Means in Your Workflow

The short answer

HCC stands for Hierarchical Condition Category. Risk adjustment models group certain ICD-10-CM diagnosis codes into condition categories; those categories feed a risk score that determines how much a health plan is paid to cover that patient for the year. So "HCC ICD 10" is shorthand for the subset of ICD-10-CM codes that map into a risk adjustment model — most commonly the CMS-HCC model used for Medicare Part C plans (widely written as MA plans) and the HHS-HCC model used on the individual and small-group exchanges.

Two operational facts follow from that. First, only diagnoses supported by a documented, signed, face-to-face encounter in the applicable data-collection year count. Second, the slate resets: conditions must be re-documented each calendar year, which is precisely why chart requests arrive in waves every winter and spring.

The Calendar-Year Reset That Drives Every Chart Chase

Risk scores are built from encounters in a data-collection year and applied to payment in the following year. Chronic conditions do not carry forward on their own. A patient with three qualifying conditions documented in 2025 starts 2026 at zero for risk adjustment purposes until each condition is documented again during a 2026 encounter.

Layer on two other calendars. ICD-10-CM code sets update every October 1, so a code valid for an October encounter may not have existed in August — your coding staff needs the fiscal-year code files, which CMS publishes on its ICD-10 page. And CMS phased its CMS-HCC v28 model in over three payment years, with the blend completed so that payment year 2026 runs fully on v28. Plans re-ran their gap lists accordingly, which is why the suspect lists your providers received in January look different from last year's.

Practical consequence for you: staffing. If your practice serves a meaningful MA population, first-quarter records volume is predictable. Budget hours for it the way you budget for open enrollment.

Where Code Selection Actually Gets Decided — and Documented

Code selection is a provider-and-coder determination made against the documentation in the encounter note. Your job as an administrator is to make sure the process is consistent, reviewable, and attributable to a person.

The documentation elements your reviewers check

Most practices train reviewers on a documentation framework — often summarized as monitoring, evaluation, assessment, and treatment — and require that the condition appear in the assessment or plan rather than only in a problem list or a copied history. Reviewers also confirm the note is signed, dated, and carries the rendering provider's credentials, and that the encounter type is one the model accepts.

Queries and attestations

When documentation is ambiguous, your workflow should route a query to the provider rather than let a coder infer intent. Write the rule down: coders do not add diagnoses, providers amend documentation, and every amendment follows your EHR's addendum function with the original text preserved. If your practice uses a year-end attestation form for chronic conditions, treat it as part of the legal record — it is discoverable, and it needs the same retention and access controls as the note it supports.

Who owns accuracy

Assign one named owner for HCC ICD 10 review quality — usually your coding supervisor — and one named owner for what leaves the building, usually your privacy officer or ROI lead. Those are different jobs. Conflating them is how a coding project becomes an unlogged bulk disclosure.

The Four Requests You Will Receive, and Who May See What

1. Retrospective chart requests from a plan or its contractor

A plan validating diagnoses for payment is engaged in a payment activity. Disclosure of protected health information to a health plan for payment is permitted without patient authorization, and that permission extends to the plan's business associate acting on its behalf. What you must do is verify that the requester is who it claims to be and is authorized by the plan — 45 CFR 164.514(h) requires reasonable verification of identity and authority.

In practice: require a letter of authorization from the plan naming the vendor and the project, on plan letterhead, with a plan contact you can call. Keep it. When the same vendor calls next year, you re-verify. You do not need a BAA with the plan's vendor — the vendor's obligations flow from the plan — but you do need proof of the relationship in your file.

2. Prospective gap and suspect lists

Plans send lists of patients with conditions they believe may be present but undocumented this year. These lists are PHI arriving from outside your organization. Decide where they live — inside the EHR or a restricted folder, not a shared drive everyone in billing can browse — and decide who deletes them when the campaign ends.

3. Requests for direct EHR access for remote coders

This is the highest-risk category and the one most often approved by someone who is not your privacy officer. If you grant access, grant it as named individual accounts with read-only rights scoped to the patients in the project, with a documented start and end date. Never share a group login. Pull the audit log at project close and reconcile the records touched against the patient list you agreed to. Terminate the accounts the day the project ends and record that you did.

4. In-home and telehealth assessment vendors

Plan-contracted clinicians perform assessments and then ask your practice for records, or send you their findings. Route these to the same verification workflow. Also decide, in writing, whether unsolicited outside assessments get scanned into your chart — if you file it, you own it for records-request and retention purposes.

Minimum Necessary When the Request Says "Entire Chart"

Bulk HCC ICD 10 requests frequently ask for the complete record. The minimum necessary standard applies to disclosures for payment, and for routine, recurring disclosures you are expected to have a policy defining what you release rather than deciding note by note.

Write that policy for this exact use case. A defensible default: signed encounter notes for the dates of service listed, plus the problem list and medication list for those dates, plus supporting diagnostics referenced in the note. Not the whole longitudinal chart, not unrelated specialty consults, not psychotherapy notes.

Two carve-outs to build into the workflow before your ROI clerk starts pulling:

  • Substance use disorder records subject to 42 CFR Part 2. If any part of your organization is a Part 2 program, those records follow their own consent rules. The 2024 final rule aligning Part 2 more closely with HIPAA carried a compliance date of February 16, 2026 — last week. If you have not re-papered your consent forms and your notice, that is this month's project.
  • State-protected categories. HIV, genetic, and reproductive health information may carry stricter state consent requirements than HIPAA. Your ROI staff should not be adjudicating that at the fax machine; give them a decision tree and an escalation path.

The BAA Questions to Settle Before One Chart Leaves

Here is the distinction that trips practices up. Vendors working for the plan are the plan's business associates. Vendors working for you are yours, and you need a signed business associate agreement before they touch PHI.

Run down your own list. If your practice pays any of the following, each one needs a BAA on file:

  • An outsourced coding or clinical documentation improvement firm reviewing your notes
  • A risk adjustment analytics platform ingesting your claims or chart data to generate gap lists
  • A release-of-information service handling bulk chart production
  • An independent contractor coder, including anyone offshore, and their subcontractors
  • Scanning, transcription, or secure file-transfer providers touching the same records

Check the substance, not just the signature. Does the agreement address subcontractors, breach notification timing you can actually work with, return or destruction of PHI at termination, and permitted use of de-identified data? HHS publishes sample business associate agreement provisions as a baseline, though the sample is not a complete contract. If you are staring at a coding vendor who wants access on Monday and you have no executed agreement, you can generate a signature-ready BAA through a six-step wizard and export it as PDF or DOCX the same afternoon — one-time purchase, no subscription, no waiting on outside counsel for a routine agreement.

A Ten-Day Workflow for a Bulk HCC ICD 10 Request

  1. Day 1 — Intake and log. ROI clerk stamps the request, opens a tracking entry, records requester, plan, patient count, date-of-service range, and stated deadline.
  2. Day 1–2 — Verification. Privacy officer confirms the letter of authorization and the plan contact. No verification, no production. Document the call.
  3. Day 2 — Scope decision. Privacy officer applies the minimum necessary policy and writes the release scope on the tracking entry.
  4. Day 3 — Special categories screen. Flag Part 2, behavioral health, and state-protected content for individual review.
  5. Day 3–7 — Production. Records staff pull to the defined scope. Second reviewer spot-checks a sample for wrong-patient inclusion before anything transmits.
  6. Day 7 — Transmission. Encrypted portal or SFTP with credentials delivered out of band. Not unencrypted email. Not a personal cloud drive.
  7. Day 8–10 — Close. Attach the manifest to the tracking entry, revoke any temporary access, and calendar the retention date for the request file.

That workflow takes about an hour to write and saves you the deposition-grade uncertainty of "we think we sent the notes."

Records-Handling Details That Turn Into Findings

Disclosures for treatment, payment, and operations are excluded from the accounting of disclosures under 45 CFR 164.528 — but that is not a reason to skip logging. Your own tracking log is the only way to answer a patient who asks what you sent to their plan, and the only way to scope an incident if the vendor's file transfer goes sideways.

Also account for the right of access. Patients can request records that reference their risk assessments, and the thirty-day clock does not pause because your team is buried in a chart chase. Federal audit interest in this area has not slowed either — CMS has publicly moved toward auditing all eligible MA contracts each payment year and expanding its coder capacity, which means more downstream requests reaching practices, not fewer.

Finally, make sure your HIPAA Security Rule risk analysis reflects reality. If contractors log into your EHR, if bulk PHI files sit on a shared drive during production season, or if a new analytics vendor ingests your claims feed, those are in scope. If your last risk analysis predates those changes, refresh the analysis and the supporting policies — automated risk analysis and policy generation is faster than rebuilding the document set by hand, and updated documentation is what an investigator asks for first.

Do This Before the Next Wave

Pull your vendor list this week. Mark every party that touches diagnosis or chart data, note whether they work for you or for a plan, and confirm an executed agreement exists for each one in the first column. Then write the two documents your staff actually needs: a minimum necessary release scope for risk adjustment requests, and a verification script for the front desk.

If the vendor list turns up a gap — and it usually does — close it before you release the next batch of charts. Draft and export the missing business associate agreement, get it signed, and file it with the request log. That is a ten-minute fix that keeps a routine coding project from becoming a reportable one.