Guide

Routine chart pulls: HEDIS season and what they are grading

Summary

Most chart requests from a payer are routine, not the opening move of an investigation: a plan closing a gap in a HEDIS measure, refreshing a credentialing file on its recredentialing cycle, or confirming a signature during a claim review. A genuine audit — a broad date range, a special-investigations letterhead, a named coding pattern — looks different and arrives with different language. Reading the request itself tells you which one you're facing.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Why do payers keep requesting charts?

Most chart requests are routine administrative pulls, not the opening move of an investigation: a payer verifying a HEDIS measure, refreshing a credentialing file, or confirming a signature on a claim under review. A genuine audit — a risk-adjustment pull, an outlier profile, a pattern investigation — looks different and arrives with different language. Learning to tell the two apart saves a lot of unnecessary alarm.

The routine bucket is the one most solo practices actually see: a quality department asking for a handful of visits tied to one measure, or a credentialing team confirming active practice ahead of a recredentialing deadline. Both run on a calendar the plan controls, not on anything the practice did wrong. Neither typically comes from a special investigations or program integrity unit, and neither usually names a broad date range or a pattern across many patients.

The rest of this page walks through the two routine reasons in detail, what a payer-specific medical-necessity request looks like, and the tells that separate a routine pull from an audit — which gets its own, more detailed page below.

HEDIS season: what's actually being graded

During HEDIS season — typically the first several months of the calendar year — a plan's chart request usually exists to close a gap in one specific measure it must report to its own accreditor, not to evaluate the whole chart. HEDIS is the standardized measure set health plans report, and several of its measures reach directly into outpatient behavioral-health practice patterns, including antidepressant medication management and follow-up after an emergency department visit for mental illness 1.

A HEDIS-season request is narrow by design: it usually asks for evidence tied to the numerator and denominator of one measure — did the patient stay on the medication through the defined window, did the follow-up visit happen within the required timeframe — rather than a full clinical review. The requester is typically the plan's quality-improvement department, working from a list of members who fall into a measure's eligible population, not a unit looking for a billing problem.

Because the request is measure-specific, the fastest response is usually the correct one: pull exactly the visits and documentation the letter names, send them by the requested deadline, and move on. Treating a HEDIS request like an audit wastes time neither the practice nor the plan needs spent.

Credentialing and recredentialing pulls

A second routine source is credentialing. NCQA's credentialing standards require plans to primary-source-verify a clinician's licensure, query the National Practitioner Data Bank, and recredential the clinician at least every 36 months, and a chart pull sometimes accompanies that cycle to confirm active practice and documentation consistency 2. This bucket runs on a calendar, not a clinical trigger.

Because verified information ages — NCQA's standards set a window for how current a verification has to be before it counts as fresh — a plan may reach out even when nothing about the practice has changed, simply because its own file is approaching that aging limit 2. A credentialing-driven chart request is usually light: confirmation that the clinician actually saw the patients on file, or a spot check of a signature, rather than a deep clinical review.

The practical response is the same as for HEDIS: confirm what's being asked, send exactly that, and expect the cycle to repeat roughly every three years for as long as the practice stays in-network with that plan.

Payer-specific medical necessity reviews

A third routine reason is a payer confirming medical necessity against its own published clinical policy rather than any national standard. Every major payer maintains its own policy library, and the request letter usually names the specific policy the reviewer is checking the note against — a detail worth reading closely before assuming the review applies a standard the practice has seen from a different payer.

Anthem, Aetna, and UnitedHealthcare each publish their own medical and reimbursement policies through their provider portals 345. These are examples of how a policy-driven request works, not a claim that all payers apply the same rule: the paying payer's own published policy and the practice's contract with that payer control what the note has to show, and a note written to satisfy one payer's threshold may not automatically satisfy another's.

Before responding to a medical-necessity request, pull the specific policy the letter cites rather than relying on memory of a similar request from a different plan. The fastest way to lose a review that should have been a routine pass is answering the wrong payer's standard.

When routine becomes an audit

A request stops being routine when it broadens: a wide date range instead of a handful of visits, a letter from a special investigations or program integrity unit instead of quality or credentialing, or language describing a pattern — a coding-level distribution, a risk-adjustment diagnosis, a utilization profile measured against peers — rather than a single measure or file update.

Each of those patterns has its own mechanics worth understanding on its own terms: a risk-adjustment-adjacent pull works differently from a HEDIS request, an outlier E/M coding distribution gets flagged by comparing a practice's bell curve to its specialty's, a utilization profile compares the practice against the specialty curve broadly, and an upcoding investigation looks for specific documented patterns payers mine for. None of those is answered the same way a routine measure-verification request is.

If a request escalates further into a formal finding — an alleged overpayment, a demand for repayment — the response shifts again, into the mechanics of a takeback letter and the appeal process, which is a different page and a different clock entirely.

Building a request-ready habit

Treat every chart request the same way regardless of its source: log it, pull exactly the records asked for, meet the stated deadline, and keep a copy of what was sent and when. A practice that already keeps this kind of log alongside its regular bookkeeping records has the material ready before the letter even arrives.

A simple log needs only a handful of fields: the date the request arrived, which department sent it, what it asked for, what was sent back, and the date it went out. Over a year or two, that log becomes its own useful record — a practice that can show every request was answered on time and in full has a much easier time if a routine pull is ever followed by a harder question.

The habit costs little and pays for itself the first time a plan claims a response never arrived. A dated log with a copy of what was sent settles that dispute in minutes instead of turning into a longer argument about a deadline that may or may not have been met.

Common questions

Usually not. Most chart requests are routine — tied to a HEDIS measure, a credentialing cycle, or a signature check on a specific claim — and come from a plan's quality or credentialing department, not a special investigations unit. A request naming a broad date range, describing a coding or billing pattern, or arriving from a program-integrity team is the one worth treating more carefully.

The letter states the deadline, and it's usually a matter of weeks rather than days during HEDIS season. Pull exactly the visits and documentation named, send them by the stated date, and keep a copy. These requests are narrow and measure-specific, so responding quickly and completely is almost always the fastest way to close them out.

Credentialing runs on a calendar independent of anything happening in the practice. Verified licensure and other credentials age, and standards require plans to refresh their file and recredential a clinician at least every 36 months, so a request can arrive purely because the plan's records are approaching that limit, not because of any concern.

No. Each major payer publishes its own clinical and reimbursement policies, and a chart request checking medical necessity is usually measured against that specific payer's published policy and the practice's contract with it. A note written to satisfy one payer's threshold does not automatically satisfy a different payer's — read the cited policy before responding.

Scope and source. A routine pull names a handful of visits tied to one measure or one credentialing item and comes from a quality or credentialing department. An audit broadens the date range, describes a pattern across many charts, and often comes from a special investigations or program integrity unit — those signal a different kind of review with different stakes.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.National Committee for Quality Assurance (2026). HEDIS. National Committee for Quality Assurance (NCQA). linkThat HEDIS is the measure set plans report, and that antidepressant medication management and post-ED follow-up are measures reaching into outpatient behavioral-health chart evidence.
  2. 2.National Committee for Quality Assurance (2026). Credentialing — NCQA. National Committee for Quality Assurance (NCQA). linkThat NCQA's credentialing standards require primary-source verification, an NPDB query, a verification aging window, and recredentialing at least every 36 months, explaining calendar-driven credentialing pulls.
  3. 3.Anthem (2026). Anthem Provider Policies. Anthem provider portal. linkNamed as one payer's own published policy library, an example of a payer-specific medical necessity standard rather than a universal rule.
  4. 4.Aetna (2026). Aetna Clinical Policy Bulletins. Aetna provider portal. linkNamed as one payer's own published policy library, an example of a payer-specific medical necessity standard rather than a universal rule.
  5. 5.UnitedHealthcare (2026). UnitedHealthcare Policies and Protocols. UnitedHealthcare provider portal. linkNamed as one payer's own published policy library, an example of a payer-specific medical necessity standard rather than a universal rule.

https://www.gale.care/for-providers/cdq-payer-chart-reviews · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)