What OIG Findings Reveal

Diagnosis code validation is the process of verifying that every ICD-10 diagnosis code submitted to CMS for risk adjustment is supported by adequate clinical documentation in the medical record — ensuring the code meets HCC mapping requirements, ICD-10 coding guidelines, and RADV audit standards before it is included in a Medicare Advantage plan's risk score submission.

RADV audit exposure is increasing as CMS expands enforcement and extrapolation methodologies. The Office of Inspector General has published dozens of audit reports examining Medicare Advantage risk adjustment practices, and the findings paint a consistent picture: diagnosis code validation remains the single largest vulnerability in the MA payment system.

OIG reports consistently find that a significant percentage of HCC-mapped diagnoses submitted by MA plans lack adequate clinical documentation to support them. Across multiple audit cycles, the error rates for sampled diagnoses range from 15% to over 40%, depending on the condition category and the plan's internal controls.

  • Financial Magnitude: OIG has estimated that unsupported diagnoses result in billions of dollars in improper payments to MA plans annually, making diagnosis validation a top enforcement priority
  • Consistent Patterns: The same categories of validation failures appear across plans of all sizes, indicating systemic industry issues rather than isolated plan-specific problems
  • Escalating Enforcement: With RADV extrapolation now in effect, the financial consequences of diagnosis validation failures have increased by orders of magnitude
  • Provider Focus: OIG findings increasingly trace validation failures to specific provider documentation practices rather than plan-level coding decisions

Understanding what RADV audits actually examine — and what auditors consistently find problematic — is the foundation of any effective validation program.

Top Diagnosis Validation Failures

OIG audit reports identify recurring categories of validation failures that account for the majority of unsupported diagnoses. Plans that focus remediation efforts on these categories will address the highest-impact vulnerabilities first.

  • Insufficient Specificity: Diagnosis codes that require greater specificity than the documentation supports — such as coding a specific type of diabetes complication when the clinical note only documents "diabetes" without complication detail
  • Missing Face-to-Face Encounter: Conditions coded from non-qualifying sources such as lab results, radiology reports, or telephone encounters without an accompanying face-to-face provider evaluation
  • Historical Diagnoses Carried Forward: Conditions listed on problem lists or assessment sections that reference prior-year diagnoses without current-year clinical evaluation or treatment documentation
  • Rule-Out Conditions Coded as Confirmed: Diagnoses documented with qualifying language such as "suspected," "probable," or "rule out" that were submitted as confirmed conditions on claims
  • Incomplete Clinical Indicators: Codes assigned without supporting clinical evidence — for example, coding major depression without documentation of symptoms, functional impact, or treatment plan

These failure patterns directly inform where organizations should invest in coding quality improvement and documentation training. Each category requires a different remediation strategy, from provider education to system-level edit controls.

Validation Error Rates

OIG audits consistently find 15-40% of sampled HCC diagnoses lack sufficient documentation support. The error rate varies by condition category, with behavioral health and vascular conditions showing the highest failure rates.

Extrapolation Impact

With RADV extrapolation, a 20% error rate in a sample of 200 diagnoses can be projected across the entire plan population, turning a finding of $500,000 in sampled overpayments into tens of millions in extrapolated liability.

Unsupported vs Unconfirmed Diagnoses

OIG draws a critical distinction between unsupported and unconfirmed diagnoses, and understanding this difference is essential for building effective validation protocols.

  • Unsupported Diagnoses: The medical record contains no documentation whatsoever to support the submitted diagnosis code. The condition does not appear in the clinical narrative, assessment, plan, or any other section of the encounter documentation. These represent the most clear-cut audit failures.
  • Unconfirmed Diagnoses: The medical record contains some reference to the condition, but the documentation uses qualifying language that does not establish a definitive diagnosis. Terms like "possible," "suspected," "consistent with," or "rule out" indicate clinical uncertainty that does not meet the standard for risk adjustment coding.
  • Insufficiently Documented: The condition is mentioned but lacks the clinical detail required to support the specific ICD-10 code assigned. For example, "heart failure" without specification of type, acuity, or laterality when the submitted code requires that specificity.

Each category requires different remediation. Unsupported diagnoses point to coding errors or system issues. Unconfirmed diagnoses indicate provider documentation habits that need targeted education. Insufficient documentation suggests a need for better ICD-10 guideline alignment between clinical documentation and coding specificity requirements.

Plans that categorize their internal audit findings using these OIG-aligned categories can target training and technology investments with much greater precision than those using generic "error" classifications.

Free Resources

Three downloads risk adjustment teams actually use

Checklists, playbooks, and frameworks — built for analysts, auditors, and VPs working RAF, RADV, and HCC.

Checklist

2026 RADV Audit Readiness Checklist

12-point compliance checklist for documentation, diagnosis code validation, extrapolation defense, and pre-audit scrub workflows.

Playbook

RAF Score Optimization Playbook

Tactical guide for analysts: HCC recapture workflows, V28 transition impacts, prospective gap-closure plays, and KPIs that move RAF lift.

Playbook

Risk Adjustment Analytics Playbook

How payer leaders sequence prospective and retrospective risk adjustment for compounding RAF lift. Deployment patterns, KPIs, and a VP-level operating rhythm.

Apply These Lessons Automatically: Our RADV Scrubber incorporates the validation checks that OIG findings indicate are most critical — catching the same issues flagged in audit reports. See the RADV Scrubber →

Provider Documentation Patterns

OIG findings consistently trace validation failures back to identifiable provider documentation patterns. Rather than treating audit failures as random events, organizations should analyze their provider networks for these systematic documentation vulnerabilities.

  • Copy-Forward Documentation: EHR templates that carry forward prior-visit assessments without requiring providers to affirm or update each condition create records where historical diagnoses persist without current clinical evaluation
  • Problem List Reliance: Providers who document conditions only on problem lists without incorporating them into the encounter-specific assessment and plan leave those diagnoses without the face-to-face encounter documentation RADV requires
  • Abbreviated Assessments: Time-pressured clinical notes that list diagnosis codes or condition names without clinical narrative, treatment rationale, or supporting findings fail validation even when the provider genuinely evaluated the condition
  • Specialist vs Primary Care Gaps: Conditions identified by specialists but not re-documented by the primary care provider during comprehensive visits create gaps where the referring provider's documentation may not meet the face-to-face standard for the billed encounter
  • Template-Driven Overcoding: EHR templates with pre-populated condition checklists can lead to coding that outpaces documentation, particularly when providers click through templates rapidly during high-volume clinic sessions

Addressing these patterns requires collaboration between compliance, clinical leadership, and health information management. The most effective programs combine provider scorecards, peer comparison data, and targeted documentation training specific to the patterns observed in each provider's records.

Technology for Code Validation

Manual chart-by-chart validation cannot scale to meet the volume demands of modern MA plans. Technology-enabled validation bridges the gap between what auditors expect and what manual processes can deliver.

  • Pre-Submission Code Scrubbing: Automated systems that cross-reference submitted diagnosis codes against ICD-10 coding guidelines before encounter data reaches CMS, catching specificity errors, invalid code combinations, and guideline violations in real time
  • NLP-Based Documentation Review: Natural language processing tools that scan clinical documentation to verify that submitted diagnoses have corresponding narrative support, flagging gaps before they become audit findings
  • Provider Performance Dashboards: Analytics platforms that track validation rates by provider, facility, and condition category, enabling targeted intervention where failure rates are highest
  • Historical Pattern Analysis: Machine learning models that compare current coding patterns against historical audit outcomes to predict which diagnoses are most likely to fail validation
  • Audit Simulation: Tools that replicate RADV audit methodology on internal data, allowing plans to identify and remediate exposure before CMS selects them for audit

The most effective technology strategies layer multiple validation checkpoints across the encounter lifecycle rather than relying on a single pre-submission scrub. Each checkpoint catches different categories of errors, and the cumulative effect is substantially lower audit exposure than any single tool can achieve alone.

Building a Validation Program

A sustainable diagnosis validation program operates continuously rather than annually and integrates technology with human expertise at every stage.

  • Establish Baseline Error Rates: Conduct an internal audit using RADV methodology to quantify your current validation failure rate by condition category, provider, and facility. This baseline drives resource allocation
  • Implement Concurrent Validation: Shift from retrospective chart review to concurrent validation that catches issues during or immediately after the encounter, when documentation correction is still feasible
  • Create Provider Feedback Loops: Share validation results with providers within 30 days of the encounter, including specific documentation examples showing what auditors expect versus what was documented
  • Prioritize High-Risk HCCs: Focus intensive validation on condition categories with the highest coefficient values and the highest historical failure rates in OIG reports — these represent the greatest financial exposure per diagnosis
  • Conduct Mock RADV Audits: Run quarterly simulated audits using CMS sampling methodology to track validation improvement trends and identify emerging problem areas before they become systemic
  • Measure and Report: Track validation rates as a key performance indicator alongside coding accuracy and HCC capture rates. Report trends to senior leadership to maintain organizational focus on compliance

The organizations that perform best in actual RADV audits are those that treat validation as an ongoing operational discipline rather than an audit preparation exercise. By the time CMS selects a plan for audit, the documentation either supports the diagnoses or it does not — there is no retroactive fix.

Key Insight: OIG audit findings are not random — they follow predictable patterns that every MA plan can learn from. The most effective compliance programs study published OIG reports, map those findings against their own data, and build validation workflows that specifically target the highest-risk failure categories. Prevention through systematic validation is orders of magnitude less expensive than remediation after an audit finding.

Ready to Validate Your Diagnosis Codes?

See how our RADV audit scrubber platform catches validation failures before submission, reducing your exposure to OIG findings and extrapolated recoveries.

Schedule a Demo