
RADV audit medical records create an operational burden long before a health plan submits anything to CMS. Each contract-specific enrollee data list has to become traceable record pulls tied to the correct member, audited HCC, encounter, provider, and deadline.
Across overlapping audits, several EDLs can trigger provider research, request preparation, portal submissions, repeated follow-up, file matching, intake review, and replacement pulls at the same time. Teams must separate returned paperwork from usable support while enough time remains to act when a record fails.
A reassuring completion rate can hide the exposure leadership needs to see. A provider may return a file on time, yet the record may contain the wrong date, an invalid source, a missing signature, or no diagnosis that supports the audited HCC.
Retrieval completion is not RADV readiness.
A health plan has control when every audited HCC has plan-validated support or a visible exception. Every exception needs an owner, a next action, and a remaining deadline.
That distinction matters as CMS accelerates its audit schedule. As of July 2026, CMS intends to initiate payment year 2024 audits in August 2026 and payment year 2023 audits in November 2026. Payment year 2022 audits are scheduled for January 2027, followed by payment year 2025 audits in April 2027. CMS states that these dates may change.

Medicare Advantage Risk Adjustment Data Validation is CMS’s primary process for reviewing diagnoses submitted for risk-adjusted payment. CMS checks whether sampled enrollees’ medical records support those diagnoses. Unsupported diagnoses may produce payment error findings and overpayment recovery under the applicable audit methodology.
RADV is distinct from HEDIS and broader payment integrity work. HEDIS retrieval supports quality measures. Payment integrity may examine claims, coding, medical necessity, billing, or policy compliance. RADV audit medical records must support the audited HCCs connected to sampled Medicare Advantage enrollees.
RADV, HEDIS, and payment integrity pulls may reach the same providers, but their review standards, deadlines, and submission processes differ. The six healthcare audits insurance companies manage show the broader range of compliance, financial, clinical, and operational reviews payor teams may need to support.
A sample with a manageable member count can still produce a demanding retrieval program. One member may have several audited HCCs. Each HCC can connect to multiple diagnosis codes, dates of service, and possible provider sources.
Weak reporting often compresses three different states into one status called “complete.”
A returned record means only that a provider or custodian sent a file.
A record that passes plan intake has cleared the initial checks for the member, date, provider source, signature, credentials, coversheet, record type, and file quality.
Plan-validated HCC support means the coding or compliance team determined that the documentation supports the audited HCC and is ready for submission.
That third state reflects the plan’s internal determination. The Intake Feedback Report confirms whether the record and coversheet passed CMS intake. CMS provides diagnosis abstraction and audited-HCC results at the end of the audit in the Audit Report Package.
A dashboard that reports only returned records can hide the HCCs most likely to affect the audit result. The meaningful measure is how many audited HCCs have usable support, not how many files have reached an inbox.
CMS announced that newly initiated audits will include all eligible Medicare Advantage contracts for each payment year. The agency then issues methods and instructions for the specific payment year. Teams need to apply the sample design, data collection period, HCC model, and submission rules issued for the audit in front of them.
The payment year 2021 methodology shows how concentrated the work can become. CMS limited the sampling frame to enrollees who met defined eligibility criteria and ranked in the top quartile under one or both improper-payment prediction models.
It then selected a simple random sample of 35, 50, 100, or 200 enrollees, depending on the contract’s sampling-frame stratum. When a frame was no larger than the assigned sample, CMS audited the full frame. These sample sizes apply specifically to payment year 2021.
Sample size alone does not predict retrieval difficulty. The burden depends on how many selected HCCs lead to fragmented provider histories, unavailable custodians, or records that fail intake. A smaller sample can still create serious deadline exposure when one provider holds the only known support for an audited HCC.
CMS initiates a contract-specific audit through an Audit Notice. Use the period before the applicable medical record submission deadline to assign the contract point of contact, retrieval lead, coding lead, compliance reviewer, and escalation owner.
For payment year 2021, CMS allows no more than five designated points of contact per contract. Lead POC forms may take up to five business days to process during peak periods, such as the beginning of an audit cycle. Resolve CDAT access, ownership, and reporting authority before retrieval work accelerates.
Once CMS releases the contract-specific EDL in CDAT, teams must convert sampled enrollees, audited HCCs, and associated diagnoses into executable provider requests. The file identifies what must be defended. Provider and encounter research still have to determine where the strongest record may sit, who currently holds it, and whether another source exists.
This is where RADV audit medical records become a workload problem. A member and diagnosis code do not automatically identify the current custodian, the most defensible encounter, or the request channel that will produce the record in time.
CMS designed the payment year 2021 audits to calculate an extrapolated overpayment estimate. Under the current instructions, CMS will collect the sum of payment errors identified for sampled enrollees. CMS reserves the right to collect extrapolated amounts later if legally permissible.
The 2023 RADV rule was vacated by a federal district court in 2025. CMS reported in May 2026 that the decision remained under appeal.

CMS requires at least one valid medical record and medical record coversheet to support each audited HCC listed in the EDL. One record may support several audited HCCs when the plan identifies each applicable HCC on the coversheet and submits the record once.
Submit a targeted, legible record from an acceptable source. It must document the needed diagnosis within the correct data collection period. Additional pages provide no value when they do not strengthen support.
Before RADV audit medical records enter the coding queue, intake reviewers should confirm the member, date of service, provider source, and record type. The same review should cover the signature, credentials, coversheet match, and file quality.
CMS may invalidate a submission for the wrong enrollee, a missing date, an invalid source, or missing credentials. Dates outside the data collection period and other intake defects can also stop the record before diagnosis abstraction.
Record type changes the requirements. Under the payment year 2021 instructions, inpatient submissions require admission and discharge dates plus a signed discharge summary. Physician and hospital outpatient records tie to a specific date of service.
CMS also requires one medical record per PDF file and limits each file to 100 MB for the payment year 2021 audit. The same instructions limit each enrollee’s submissions to twice the number of audited HCCs.
That limit turns record selection into an operating decision. A weak file can consume capacity that the team later needs for stronger support.
For payment year 2021, a CMS-generated attestation may address certain missing signature or credential issues for physician and hospital outpatient records. Records submitted as hospital inpatient documentation are excluded from that attestation process.
A progress note from an inpatient stay may be treated as an outpatient record when it identifies a specific date of service and meets the other applicable requirements. In that form, it can include a CMS-generated attestation.
An attestation cannot repair the wrong member, an invalid date, an unacceptable source, an illegible file, or documentation that lacks the needed diagnosis.
Model context matters as well. CMS completed the phase-in of the 2024 CMS-HCC model for organizations other than PACE in calendar year 2026. CMS uses that model for 100 percent of those 2026 risk scores, as confirmed in the calendar year 2026 risk adjustment implementation memo.
An active RADV audit may cover an earlier payment year under different models. Keep the payment year and applicable model attached to the request and review record. Otherwise, current mappings can quietly enter an older audit workflow.
The EDL controls the audit population, but providers cannot act on it until the plan converts it into request-level work. Teams still have to normalize provider names and locations, distinguish the rendering provider from the current custodian, and match dates of service to likely source systems.
Missing locations or stale provider names can delay release. Closed or acquired practices may require custodian research. After a file returns, it still has to be matched to the correct member, encounter, contract, and HCC before review can begin.
A RADV pull list should remain the authoritative record as work moves through retrieval, intake, coding, compliance, and submission. It must show whether the request reached the correct source and whether the returned record passed intake. It must also show whether enough time remains to replace the file.
When teams use one “complete” status for every stage, leadership receives a progress report instead of a risk report.
Consider a common sequence. Retrieval marks a line complete when the file arrives, then intake finds a missing credential. Coding sees the exception near the internal cutoff.
Meanwhile, the original practice has stopped responding and the alternative encounter belongs to another custodian. By the time the status is corrected, provider research, outreach, and waiting may have to begin again with a different source.
CMS reviews each submitted medical record and coversheet for validity. The Intake Feedback Report in CDAT shows whether the submission passed and gives an invalidity reason when it did not.
While the submission window remains open, the plan may replace an invalid record and coversheet. The internal retrieval cutoff must protect time for submission, CMS intake review, exception routing, replacement retrieval, and resubmission.
An invalid submission may eliminate later options. CMS states that records deemed invalid during intake are ineligible for appeal. A plan also cannot introduce a new medical record during a medical record review determination appeal.
The appeal must rely on documentation included in the initial audit submission.
When an MA organization seeks a hardship exception for an audited HCC, CMS expects evidence that it pursued documentation from all providers that submitted a relevant encounter for that HCC.
CMS also directs plans to locate custodians for closed, retired, deceased, transferred, or acquired practices when custodial requirements apply. Ordinary provider nonresponse generally does not support a hardship exception. Routine lost-record issues, practice transfers, common IT problems, and closures may also fall short.
Late discovery of an unavailable provider reduces the plan’s remaining options. The response still needs valid support or a CMS-approved exception.
Bulk retrieval keeps provider outreach and request administration from consuming the audit window. The plan sends one organized pull population, then manages provider activity, returned records, and exceptions through a consistent structure.
Routine pulls determine workload. Exceptions determine deadline risk.
Once normal requests are moving, attention should shift to delayed providers, invalid files, missing custodians, and HCCs without another identified encounter. Start with records that have no second source. Then move to aging requests with an available alternative and routine pulls still following the expected path.
This order protects the plan’s remaining options. It also stops a large volume of routine activity from masking the smaller group of records most likely to affect the response.
Bulk retrieval should keep payment years and contracts separate at the request level. Leadership still needs one portfolio view of capacity, exceptions, and deadlines. The current CMS schedule places several payment years in close succession, so a plan may be mobilizing one audit while closing another.
The healthcare audit season playbook explains how to coordinate overlapping record populations without blending RADV, HEDIS, and payment integrity requirements.

Coding, compliance, and risk adjustment teams should spend the audit window on records that require judgment. Their time belongs in documentation review, exception decisions, coversheet preparation, and submission control.
We use RecordGateway to manage the retrieval layer of the RADV response. The plan provides the pull list, contract and product groupings, provider data, and internal deadline. We organize the request population, manage provider follow-up, keep delivered records tied to the underlying request, and surface exceptions before they consume the replacement window.
A large population of RADV audit medical records can enter one intake process without losing contract or product ownership. Teams can then separate released work from aging, delivered, incomplete, and blocked requests without rebuilding the same report across additional trackers.
Returned files arrive in an organized queue for the plan’s validation process. Coding and compliance teams enter when judgment is required. They do not need to spend the submission window checking routine provider statuses or reconciling file names.
We manage retrieval. The plan determines whether a diagnosis validates an HCC, selects its final coding position, prepares coversheets, and submits through CDAT.
Medical records retrieval for insurance companies explains how bulk intake, centralized provider follow-up, status visibility, and consistent delivery reduce file-by-file administrative work.
Bring us the EDL structure, contract and product organization, provider data, and internal cutoff. Schedule a RADV retrieval workflow review to identify where pull-list intake, provider follow-up, and exception handling could threaten the submission window.
A RADV audit is a CMS review of Medicare Advantage risk adjustment data. CMS checks whether diagnoses submitted for risk-adjusted payment have support in sampled enrollees’ medical records. Unsupported diagnoses may affect the payment error calculation and lead to overpayment recovery.
RADV audit medical records are physician, hospital outpatient, observation, or inpatient records submitted to support audited HCCs. The documentation must meet the requirements for the audited payment year. Those requirements cover the member, date, provider source, record type, signature, credentials, coversheet, and file quality.
A plan needs at least one valid medical record and coversheet supporting each audited HCC in the EDL. One record may support several audited HCCs when the plan identifies each applicable HCC on the coversheet and submits the record once.
The Intake Feedback Report confirms whether a submitted record and coversheet passed CMS intake validity checks. CMS provides diagnosis abstraction and audited-HCC results at the end of the audit in the Audit Report Package.
The pull list should connect each audited HCC to the contract, payment year, member, diagnosis, candidate encounter, provider, custodian, and request status. It should also show the intake result, exception reason, alternative source, owner, coversheet status, and CDAT disposition. A plan has control when each audited HCC has plan-validated support or a visible exception. Every exception needs an owner, a next action, and a remaining deadline.