Guide

RADV-adjacent: MA chart pulls and your accuracy stake

Summary

A Medicare Advantage risk adjustment chart request is a plan or CMS contractor asking for copies of a patient's medical record to verify that a diagnosis code submitted for that patient's risk score is actually supported by the documentation. It's a validation check, not automatically an audit finding: you're confirming what you already coded, and a well-documented chart with a specific diagnosis, an assessment, and a signed note usually closes it without further action.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

What triggers a risk adjustment chart request

A risk adjustment chart request arrives because a diagnosis code you or another clinician submitted for a patient contributed to that patient's CMS Hierarchical Condition Category (HCC) risk score, and the Medicare Advantage plan or a CMS contractor is validating it against the medical record. The request itself is routine — plans run these continuously, not just for patients flagged as suspicious.

Most requests ask for the specific encounter note tied to the diagnosis in question, sometimes with a broader date range around it. You'll typically get several weeks to respond, though the exact window is the plan's own policy — check the letter itself, since a missed deadline can convert a routine request into a more adversarial one.

How this differs from a HEDIS or quality chart pull

A risk adjustment request checks whether a diagnosis code is supported in the note; a HEDIS or quality-measure chart pull checks whether a specific service happened — a screening, a follow-up visit, a lab result — for a measure a health plan is reporting for its own accreditation. They're different systems behind different documents, even when the same plan sends both.

HEDIS is the measure set most plans use for this second kind of review, and it reaches into outpatient behavioral health through measures like antidepressant medication management and follow-up after an ED visit for mental illness 1. This formal quality-measure system is distinct from the flatter commercial bonuses some payers pay outside any formal scorecard. If a request references a HEDIS measure by name rather than a diagnosis code, you're looking at routine chart pulls for quality reporting, not a risk-adjustment validation — the response and the stakes differ.

What the reviewer is actually checking in your note

Reviewers are validating that the diagnosis meets what's often called MEAT — the note shows the condition was Monitored, Evaluated, Assessed, or Treated at that visit, not simply carried forward on a problem list. A diagnosis copied from a prior note without any current-visit evidence of clinical management typically fails validation even when the diagnosis itself is accurate.

Two mechanics matter independent of MEAT: the note needs a valid signature or an acceptable attestation if one was missed 2, and it needs to reflect a service that met Medicare's coverage conditions for the visit type billed 3. A signature gap is one of the most fixable failures — Medicare's own guidance describes how to cure a missing signature through attestation rather than losing the encounter entirely 2.

How to respond: format, copies, and your own file

Respond in whatever format the request specifies — most MA plans and their records vendors now accept a secure portal upload or fax, and a growing share pull directly from your EHR if you've connected a health information exchange. Send exactly what's requested, not your entire chart, and keep a dated copy of both the request and your response in your own file.

Track the deadline on your own calendar the day the request arrives rather than trusting a follow-up reminder — plans vary in how much notice they give before escalating a non-response, and a lapsed deadline is treated the same as a refusal in most contracts. If several requests arrive in the same period, respond to each on its own deadline rather than batching them, since batching is the most common way a single deadline gets missed.

Sending the records securely

A chart request is a live ePHI disclosure, and the transmission channel matters as much as the content: a secure portal or encrypted fax line, never a plain email attachment. HHS's Security Rule requires administrative, physical, and technical safeguards for ePHI scaled to your practice's size, anchored in a documented risk analysis 4.

If your practice hasn't run that risk analysis, ONC and OCR publish a free Security Risk Assessment tool sized for a solo or small practice, which is the fastest way to have a defensible answer ready before the next records request arrives, not after one already has 5. Run it once a year at minimum, and again after any change to how you transmit records — a new portal, a new fax vendor, or a new billing service handling the same disclosures.

Building a chart that survives a risk adjustment pull before one arrives

The cheapest way to handle a risk adjustment chart request is to never need to scramble for one: document every active diagnosis's current status at least once a year, even conditions that feel stable and unremarkable, since a stable condition still needs a current-visit note showing it was addressed. A problem list entry with no visit tying to it in the past year is exactly what a reviewer flags first.

A short annual internal check — pull a handful of your own charts for patients with chronic diagnoses and confirm each has a recent note that monitors, evaluates, assesses, or treats the condition — catches most gaps before a plan does. This costs an afternoon a year and is far cheaper than responding to a request under a deadline with a chart that doesn't actually support what was coded.

What happens after — and what it isn't

A risk adjustment chart pull that comes back clean ends there; most do. If the reviewer finds a diagnosis your note doesn't support, the consequence is usually a payment adjustment tied to that one diagnosis, not an automatic fraud referral — a single unsupported code corrected on request looks very different from a pattern across many charts.

A pattern is what escalates: repeated unsupported diagnoses can move a plan toward the takeback letter process to recover overpayments, and in more serious cases toward enrollment consequences like revocation or the kind of broader review that resembles a Medicare RAC or TPE audit rather than a one-off validation. Individual plans run their own procedures for this — Aetna's provider portal, for instance, publishes its own policies and appeal paths 6, and your specific plan's contract controls which process applies. Keep a copy of the records request and your response indefinitely in the same file; it's the fastest way to show a reviewer this was an isolated, corrected issue rather than a pattern.

Common questions

A risk adjustment request validates a single diagnosis code behind a patient's risk score, sent by the plan itself; a RAC or TPE audit is a formal Medicare program-integrity review of billed claims, often covering many patients and looking for overpayment patterns. A clean risk-adjustment response rarely escalates into either, but a pattern of failures can.

The window is set by the requesting plan or contractor and appears in the request letter itself rather than a fixed federal rule. Calendar the deadline the day the letter arrives — a missed response is treated as a non-response in most MA plan contracts, which forecloses the easier fix and moves you toward escalation.

An accurate diagnosis without contemporaneous support in the note typically still fails validation, because the review checks the record, not your clinical memory. Going forward, document the condition's status — monitored, evaluated, assessed, or treated — at every visit where it's addressed, not just at the visit it was first diagnosed.

No — plain email is not an appropriate channel for a chart containing PHI. Use the secure portal or encrypted fax method the request specifies; if your practice hasn't documented its safeguards for this kind of disclosure, a HIPAA risk analysis is the place to start before the next request arrives.

A single corrected diagnosis from one chart pull, by itself, does not typically threaten enrollment. Enrollment-level consequences trace to patterns — repeated unsupported codes, or issues found alongside a separate program-integrity audit — not an isolated validation finding that you address promptly and accurately.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.National Committee for Quality Assurance (2026). HEDIS. National Committee for Quality Assurance (NCQA). linkThat HEDIS is a distinct measure set health plans use for their own quality reporting, including behavioral-health-relevant measures, separate from Medicare Advantage risk-adjustment diagnosis validation.
  2. 2.Centers for Medicare & Medicaid Services (2023). Complying with Medicare Signature Requirements. CMS Medicare Learning Network (MLN905364). linkThat Medicare requires an authenticated signature and describes how attestation cures a missing signature, supporting how to fix a signature gap found during a chart-pull review.
  3. 3.Centers for Medicare & Medicaid Services (2026). Medicare Benefit Policy Manual (Pub. 100-02). Centers for Medicare & Medicaid Services (CMS). linkThat coverage conditions and their documentation requirements, including for psychiatric services, determine whether a visit supports the diagnosis a reviewer is validating.
  4. 4.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires safeguards for ePHI scaled to practice size, anchored in a risk analysis, supporting the requirement to transmit chart-request responses securely.
  5. 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC/OCR publish a free Security Risk Assessment tool sized for small practices, supporting the how-to for preparing a defensible safeguard record before responding to a chart request.
  6. 6.Aetna (2026). Aetna Clinical Policy Bulletins. Aetna provider portal. linkThat Aetna publishes its own provider-facing policies as a named example of a plan-specific procedure — used only as an example, not as what all MA plans do.

https://www.gale.care/for-providers/cdq-risk-adjustment-pulls · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)