HCC coding is how Medicare Advantage and other risk-based programs adjust payment for how sick patients are. CMS combines HCC-mapped diagnosis codes with demographic factors like age and sex to calculate a risk adjustment factor (RAF) score for each patient, which shapes what the plan is paid for that patient's care. If your health system takes on risk through Medicare Advantage contracts or an accountable care organization, your documentation and coding drive those scores.
That puts your records under federal scrutiny. In the HHS Office of Inspector General's audits of high-risk diagnosis codes, about 70% of the codes reviewed weren't supported by the medical record (1). Unsupported codes expose you to repayment, and undocumented conditions leave a patient's real complexity out of the score.
This guide explains how HCC medical coding works, what changed under CMS's V28 model, and what it takes to keep every HCC defensible.
HCC coding means reviewing a patient's medical record and identifying the diagnoses that map to a hierarchical condition category, a group of clinically related conditions that are costly to manage over time. Examples include diabetes, congestive heart failure, chronic obstructive pulmonary disease, and major depressive disorder (2).
CMS introduced its HCC model in 2004, and risk adjustment has grown as more payers move to value-based care (3). Because payment is tied to a patient's health status rather than a flat rate, plans and providers that care for sicker patients aren't penalized for it.
Only diagnoses from inpatient stays, outpatient visits, or face-to-face visits with a health care professional count (4). Medicare Advantage plans submit those codes to CMS as encounter data (4), while ACA individual and small-group plans are risk adjusted under a separate HHS-HCC model (5).
HCC coding relies only on ICD-10-CM codes. Unlike fee-for-service billing, it doesn't involve CPT® or HCPCS codes (2). Of the more than 70,000 ICD-10-CM codes in use, about 7,770 map to 115 HCCs under V28 (6), organized into 26 disease groups (7).
Each HCC carries a weight, and CMS combines those weights with demographic factors such as age, sex, and disability status to calculate a patient's RAF score. A score of 1.00 reflects average expected costs. Scores above 1.00 indicate a sicker patient, and scores below 1.00 indicate a healthier one (8).
Scores are additive, so unrelated qualifying conditions add together. They're also hierarchical, so when a patient has several diagnoses in the same disease family, only the most severe one counts toward the score (8).
V28 is CMS's current risk adjustment model. The previous model, V24, grouped ICD-10-CM codes into HCCs using category logic built on the older ICD-9 system. V28 rebuilds those categories around ICD-10-CM and uses more recent cost data (6). CMS phased it in over three years, and 2026 risk scores are the first calculated entirely under V28 (9).
Inaccurate HCC medical coding cuts both ways. Undercoding leaves a patient's complexity out of the risk score, so payment falls short of the care you're providing. Overcoding, submitting conditions the documentation doesn't support, draws regulatory and legal scrutiny.
CMS conducts Risk Adjustment Data Validation (RADV) audits to check whether submitted codes are supported by the medical record. In January 2026, Kaiser Permanente affiliates agreed to pay $556 million to resolve False Claims Act allegations that they added diagnoses to inflate risk scores (10).
A coder can only report a diagnosis as an HCC if the provider's note shows it was addressed during that encounter, not just carried over from a problem list. The documentation standard most organizations use for HCC coding is MEAT (11):
Monitor: signs, symptoms, or disease progression
Evaluate: test results or response to treatment
Assess or address: ordering tests, counseling, or reviewing records
Treat: medication, therapy, or another intervention
MEAT isn't a CMS regulation, and organizations and payers interpret it differently. I recommend writing down your own MEAT policy and applying it consistently.
Auto-populated data, like an imaging result pulled into the note, doesn't count unless the provider addresses it (12).
Specificity is one of the biggest HCC medical coding challenges. Many diagnoses have an unspecified version and a more detailed version that describes a complication or severity level, and often only the detailed version maps to an HCC. If the documentation doesn't capture that detail, your coders have to use the generic code (8).
Risk scores reset every year, so chronic conditions must be documented and reported at least once each calendar year to count (3). A condition that goes undocumented for a year drops out of the patient's score.
Plans rely heavily on chart reviews and health risk assessments to add diagnoses after the fact. MedPAC estimates the two account for about half of overall Medicare Advantage coding intensity (13), and the practice has drawn scrutiny for overstating patient complexity.
Under V28 and RADV, the standard for HCC coding should be simple: for every submitted HCC, your team can point to the documentation that supports it. That's also where AI should make coding more consistent, not less transparent.
Autonomous medical coding sits at the coding step, not the documentation step. Nym's autonomous medical coding engine assigns the ICD-10-CM diagnosis codes the provider's documentation supports, including HCC-mapped codes, and can be configured to apply your organization's MEAT policy to each diagnosis it codes. It doesn't suggest conditions the provider didn't document, and CDI work stays with your team. When documentation is ambiguous or incomplete, the engine routes the encounter to your coders with a flag explaining the issue.
Unlike black box AI solutions, Nym's engine provides a transparent audit trail for every code assignment, tracing each diagnosis to the supporting documentation and the guideline behind it. When a plan or auditor asks you to support a diagnosis, your team starts from that record instead of reconstructing the chart. Schedule a demo to see an audit trail for yourself.