Second Read

The Most Prosecuted Dollar in Health Care Is Made in a Chart Review

InstrumentRisk Adjustment · AreaRevenue

In January 2026, Kaiser Permanente affiliates paid $556 million — the largest Medicare Advantage False Claims Act resolution ever — over diagnoses added through after-visit addenda. Cigna paid $172 million, partly for a chart-review program that added codes and never deleted them. Independent Health paid up to $98 million; its vendor's founder paid $2 million personally. And in June 2026, the enforcement perimeter reached the vendor itself: Matrix Medical Network, the in-home assessment company, settled for $56.5 million. Six things from building an instrument for how risk scores are made.

1. The score is the price tag. A tenth of a point of RAF is worth roughly $1,200 per member per year — our computed convention, because no official figure exists. That's why an industry rereads charts, visits homes, and prompts physicians in the EHR. None of it is illegal. All of it is an incentive structure, and the incentive points one way.

2. OIG has priced the channels. Diagnoses appearing only on chart reviews: $6.7 billion in one payment year, $2.7 billion of it from reviews linked to no encounter at all. Health-risk-assessment channels: $7.5 billion for 2023 — with 1.7 million enrollees receiving no other care that year for the condition that paid. A diagnosis that never generates treatment is either a care-gap failure or a revenue event wearing a stethoscope, and auditors now test the difference.

3. The one-way street is the whole case. The 2014 rule declined to ban add-only chart reviews explicitly — so the exposure runs through the attestation and the overpayment rule, whose "identified" clock has started at FCA knowledge since January 2025, with a six-year lookback and no 180-day investigation runway for MA plans. A delete workflow that has never deleted anything is not compliance; it's the exhibit.

4. Pay for accuracy, never for lift. The fee structures in the settled complaints: contingency up to 20% of proven risk revenue; assessment fees tied to volume, with RAF-lift ROI decks as marketing. A finder paid per find will find. And there is no independent recapture benchmark anywhere in public — every RAF-lift number a vendor quotes is the vendor's own.

5. The audits are no longer a lottery. CMS announced RADV audits of all ~550 eligible contracts, every year, with a coder workforce of two thousand. When OIG samples its published high-risk diagnosis codes, 60–90% come back unsupported; one cross-plan stroke audit failed every single sampled enrollee — $462 million, one condition, one year. The high-risk list is public. Auditing yourself against it first is the cheapest compliance money in the domain.

6. Extrapolation is vacated — and on appeal. A court struck the RADV extrapolation rule in September 2025; the government appealed. While the vacatur stands, nothing extrapolated is collected. If it's reversed, the exposure returns to the audit years retroactively. The only defensible book reserves for both outcomes and books neither.

We built these into an instrument: the per-RAF arithmetic, the channel-exposure stack, the settlement table in program-design language, and the vetoes. Browser-only; nothing entered leaves the machine.

A capture program that only looks in the direction that pays is not a program. It's a complaint that hasn't been filed yet.

How many codes did your program delete last year — and would that number survive a deposition?

All writing