RAAPID raises Series A funding with a Strategic “Industry Trifecta”. Read More

Home » Blogs 

CMS-HCC Model V28: What Changed, the RAF Impact, and the CY2027 Update

Quick Answer: CMS-HCC Model V28 became fully operative on January 1, 2026, replacing V24 across 100 percent of Medicare Advantage risk scores. It cuts valid ICD-10-CM diagnosis codes from 9,797 to 7,770, expands hierarchical condition categories from 86 to 115, and lowers average MA risk scores by a projected 3.12 percent. [1] The model rewards clinical severity over diagnosis volume, which structurally ends the add-only chart review era. Organizations still coding on V24 logic are submitting diagnoses that no longer generate a score and may generate an audit flag.

Looking for the CY2027 payment impact? This guide covers how the model works. For what the CY2027 Rate Announcement costs your risk scores, including the unlinked chart review and audio-only exclusions, see CY2027 Rate Announcement: What It Actually Costs Your Risk Scores.

Key takeaways

  • V28 is fully operative as of payment year 2026 and governs 100 percent of MA risk adjustment scores.
  • Valid diagnosis codes fell by a net 2,027. Many conditions that drove RAF scores under V24 no longer count at all.
  • Constraining forces related HCCs to share a coefficient, removing the duplicate credit multi-condition patients earned under V24.
  • Severity of illness now outweighs diagnosis count, reversing the incentive that drove a decade of add-only chart mining.
  • OIG’s March 2026 audit found a 91 percent error rate on high-risk diagnoses, with acute stroke and acute MI at 100 percent. [5]
  • Two-way coding, adding missed diagnoses and removing unsupported ones, is now the defensible standard.
  • AI platforms with explainable, MEAT-based evidence trails are the practical path to defensible coding at scale.

What is the CMS-HCC Model V28?

CMS-HCC Model V28 is the current Hierarchical Condition Category risk adjustment model that CMS uses to calculate risk adjustment factor (RAF) scores for Medicare Advantage members.

V28 replaces V24, which governed Medicare Advantage for the prior decade. Where V24 mapped diagnoses to 86 HCC categories using 9,797 ICD-10-CM codes, V28 uses 115 categories but recognises only 7,770 diagnosis codes, a net reduction of more than 2,000. [1]

That single change cascades. It alters which conditions generate risk scores, how much each is worth, and which coding practices survive an audit.

The intent is consistent with every recent CMS rulemaking: pay for documented patient care, not coding volume. For providers and risk-bearing organizations, the model now rewards clinical precision over diagnosis count, and it penalises records that cannot prove a condition is current and active.

The V24 to V28 transition timeline

CMS finalized V28 in the 2024 Rate Announcement and phased it in across three payment years, reaching full implementation on January 1, 2026.

Payment year

V28 weight

V24 weight

PY 2024

33%

67%

PY 2025

67%

33%

PY 2026

100%

0%

Source: CMS 2024 Rate Announcement [1]

Autonomous Retrospective Risk Adjustment Solution

One platform. Every HCC validated. Revenue secured.

Retrospective Risk Adjustment Solution

That blend is why the rollout felt manageable in 2024 and sharp in 2026. A plan running V24-era coding still collected most of its expected score in payment year 2024, when two-thirds of the calculation ran on the old model. By 2026 the cushion is gone. Any gap between V24 habits and V28 requirements now shows up at full size.

The timing is the part organizations underestimated. The same year V28 hit 100 percent, RADV audits resumed at scale. The model change and the enforcement change arrived together.

What changed from V24 to V28

Four shifts define the new model, and each one raises the bar for the record.

Code volume and HCC categories

Valid ICD-10-CM codes dropped from 9,797 to 7,770, a net reduction of 2,027 (2,236 removed, 209 added). HCC categories expanded from 86 to 115. [1]

The model now covers more clinical conditions at higher specificity while excluding a large share of the codes that previously contributed to risk scores. Organizations still running V24-era logic are almost certainly submitting codes that generate nothing.

CMS-HCC mapping

V24

V28

HCC categories

86

115

Valid ICD-10-CM codes

9,797

7,770

Net code change

baseline

-2,027 (2,236 removed, 209 added)

Projected avg. RAF impact

baseline

-3.12%

Source: CMS 2024 Rate Announcement [1]

Constraining

V28 introduces constraining: related HCCs are assigned the same coefficient value to prevent double-counting clinically linked conditions.

Under V24, a patient with a chronic condition plus a related complication generated separate, additive HCC contributions. Under V28, both map to the same coefficient. Every form of the disease now carries identical weight, regardless of complication status. [1]

The result is a lower RAF score for patients with multiple chronic conditions, with no change in their actual health status.

Severity over volume

V28 prioritises severity of illness over the number of diagnoses. A patient with two serious conditions can outscore a patient with five mild ones.

This is the reversal that matters most strategically. It inverts the incentive that drove add-only retrospective chart mining for a decade, and it rewards records that reflect true clinical complexity.

Specific category changes

  • Depression: codes cut by more than half. Only moderate-to-severe active major depression generates an HCC. Mild, unspecified, or in-remission depression no longer counts. [1]
  • Morbid obesity: drew direct enforcement scrutiny in the Aetna case, where $11.5 million of the $117.7 million settlement resolved allegations of false morbid obesity codes for PY 2018 through 2023. [3]
  • Protein-calorie malnutrition: no longer a valid HCC code under V28.

Each change makes the same point: the diagnosis has to be real, current, and documented.

How HCC V28 mapping works

HCC V28 mapping translates ICD-10-CM diagnosis codes into hierarchical condition categories, then applies hierarchies so only the most clinically significant category in a related family counts toward the score.

The chain runs in three steps. A clinician documents a condition. A coder assigns the ICD-10-CM code the record supports. The model maps that code to one of its 115 HCCs, if a valid mapping exists. Many codes map to a single HCC. The 2,236 codes removed in V28 now map to nothing at all.

What is hierarchy in HCC mapping?

Hierarchy means that within a family of related conditions, the most severe category supersedes the less severe ones. A patient is credited once for the highest-acuity condition documented, not for every step below it.

This predates V28. What changed is how tightly the model draws those families. If the record supports the complicated form of a chronic disease, that higher HCC trumps the uncomplicated category, and only the higher one counts. Constraining goes a step further by forcing some related HCCs to share an identical coefficient, flattening the extra credit a plan could earn from documenting linked conditions separately.

The operational takeaway for risk adjustment coding teams: re-verify your crosswalks against current V28 definitions every cycle. A crosswalk built on V24 logic keeps routing codes to categories that no longer carry weight, inflating expected scores the model will never pay. Mapping is an ongoing control, not a one-time setup.

How V28 lowers RAF scores for most members

RAF scores are lower under V28 for most MA patients, with a CMS-projected 3.12 percent average decline. [1] Members with several related chronic conditions can see a steeper drop, because constraining strips out the duplicate credit those conditions earned under V24.

A RAF score blends demographic factors with diagnosis-driven HCCs, and V28 reworked the diagnosis side. A lower score does not mean a member’s health improved. It means the model now credits fewer of the conditions in the record.

Which is why documentation now decides reimbursement. A code that cannot be tied to a current encounter with clinical evidence is no longer a quiet revenue adjustment. It is an audit flag. For a framework on protecting scores without crossing into optimization, see how to build defensible RAF scores.

thumb

The Essential Guide to CMS-HCC Model V28

Access the Full List of Chronic Conditions & Key Updates Now

Expert perspective

“V28 isn’t a technical update to a model. It’s CMS signaling that documentation should reflect actual patient complexity, not a list of codes. If you can’t link a diagnosis to a current encounter with MEAT-based evidence, you shouldn’t be submitting it.”

Wynda Clayton, MS, RHIT, CRC, Director of Risk Adjustment Coding & Compliance, RAAPID | Former CMS RADV Auditor

How V28 reshapes chronic condition coding

V28 hits chronic conditions hardest, because constraining and the new weighting together strip out the additive credit that high-prevalence conditions earned under V24. For most plans, this is where the projected RAF decline actually lives.

Diabetes is the clearest case. Under V24, complications often added separate HCC value. Under V28, all forms share one coefficient, so documented complications no longer multiply the score the way they once did. [1] The same logic runs across the categories that dominate MA panels: chronic kidney disease, COPD, heart failure, vascular disease. All still matter clinically and all belong in the record, but the model now expects each documented with stage and status rather than simply listed.

Vascular disease deserves particular attention, because it is where history-of conditions get miscoded most often. A resolved embolism recorded as current vascular disease is exactly the unsupported diagnosis that erodes audit standing while adding risk the plan cannot defend.

The practical path for large chronic populations runs through better records of the conditions clinicians already treat, not through finding more diagnoses to add. Two-way review matters here too: a chronic condition coded as active when the record shows it resolved is precisely what a RADV auditor pulls.

Lower scores that are fully defensible are a stronger position than higher scores that collapse under review.

What OIG audits reveal about high-risk diagnoses

OIG’s March 2026 compliance audit (Report A-07-22-01207) shows what V28-era audits actually find: a 91 percent error rate on high-risk diagnoses. OIG reviewed 271 sampled enrollee-years across nine high-risk categories and found 247 with unsupported codes. [5]

Two categories stood out. Acute stroke and acute myocardial infarction each carried a 100 percent error rate, 30 of 30 apiece. [5]

The dominant error pattern across all nine categories: history-of conditions coded as active diagnoses. A past stroke coded as acute stroke. Resolved cancer coded as active malignancy. A prior embolism coded as current vascular disease.

That is exactly the distinction V28 makes critical. The same acute, high-cost conditions that justify higher reimbursement when genuinely documented are the ones most likely to attract scrutiny when the record does not hold up. And across this audit series, high-risk groups have repeatedly shown error rates in the 80 to 95 percent range, which tells you the problem is systemic, not isolated to one plan.

MEAT criteria: the anchor for defensible V28 coding

MEAT criteria (Monitoring, Evaluation, Assessment, Treatment) is the documentation convention used to validate HCC diagnoses. Any one of the four elements, tied to a current face-to-face encounter, supports a coded condition.

Under V24, the broader code set let some diagnoses persist in annual submissions without airtight evidence. V28 closes that window. Fewer valid codes plus constraining mean every code submitted has to earn its place.

The OIG audit makes this operational. Across all nine high-risk categories, the medical review contractor asked one question: did the record document the condition as current, active, and appropriately treated, rather than a historical reference? [5]

MEAT is an industry convention rather than a CMS-named standard, but it maps cleanly onto what auditors look for, which is why it remains the practical foundation of defensible coding.

How V28 affects dementia and cognitive impairment coding

Dementia remains a high-RAF condition under V28, and the model expands those categories to capture finer clinical distinctions. But it demands more specific documentation to qualify. [1] For plans with older, higher-acuity panels, dementia is one of the highest-value and highest-risk areas in the entire model.

The clinical reality: dementia is estimated to be underdiagnosed in roughly 60 percent of cases. [6] That creates two problems at once, missed clinical recognition and missed coding. When dementia is finally documented, it has to be documented well, because the model expects the record to support the exact category coded.

Mild cognitive impairment (MCI) sits right at the classification threshold. It is not dementia, and the record has to make that distinction clear. A note mentioning “memory problems,” or carrying a historical dementia reference, will not survive an audit.

Three habits make dementia coding defensible under V28:

  • Document type and stage. Distinguish MCI from early, moderate, or advanced dementia. Code to the level the record supports.
  • Tie the diagnosis to a current encounter. MEAT-based evidence from a current visit, not a problem-list carryover.
  • Capture the functional picture. Charting that connects the condition to function, treatment, and care planning is far more defensible than a standalone diagnosis line.

What V28 means for providers

The model shifts real work to providers, because the documentation that supports a defensible code can only be created at the point of care. Risk adjustment is no longer something a retrospective team can fully repair after the fact.

Concretely: the conditions a clinician evaluates and treats have to be documented with enough specificity to map cleanly to a V28 HCC. That means severity, status (active versus historical), and the clinical reasoning behind the assessment.

The healthiest programs treat this as clinical support, not pressure. Providers respond to guidance that fits their workflow and respects their judgment, not to coercion or revenue targets. That distinction matters under V28, because the same enforcement actions that target add-only chart review also scrutinise programs that appear to push providers to code for reimbursement rather than for care. Decision support at the point of care, surfacing the evidence and letting the clinician decide, is both the compliant approach and the one providers actually adopt.

Health plans own the risk score and the audit exposure. Provider organizations own the clinical record that has to support it. The organizations that perform best under V28 treat these as one shared problem, because a risk score is only as defensible as the chart behind it.

How health plans should adapt

  • Audit current coding against V28 mapping. Identify which ICD-10-CM codes in your workflow are no longer valid. With 2,027 codes removed, existing workflows almost certainly carry obsolete codes that generate no score and may generate audit flags.
  • Shift from volume to clinical precision. Invest in clinical documentation improvement at the point of care, not retrospective code addition.
  • Run two-way retrospective reviews. The Aetna action establishes that programs which add codes but never remove unsupported ones are a legal liability. Every review should surface both. See RAAPID’s retrospective risk adjustment solution.
  • Flag high-risk categories proactively. Apply targeted validation to OIG focus areas before submission: acute stroke, acute MI, embolism, sepsis, vascular disease, and cancers where history-of conditions may have been coded as active.
  • Use AI with an auditable evidence trail. CMS plans to use AI as a coder support tool in audits. [4] Plans whose tools cannot produce an evidence trail are at a structural disadvantage.

The CY2027 update, in brief

CMS finalized the CY2027 Rate Announcement on April 6, 2026 with a 2.48 percent net payment increase, and did not finalize the proposed V28 recalibration. The existing V28 calibration continues into CY2027, so the coefficients above remain the ones in force. [7]

CMS did finalize two diagnosis-source exclusions for CY2027: diagnoses from unlinked chart review records and from audio-only encounters no longer count toward risk scores. [7]

The full payment impact, including how to quantify your own exposure, is covered separately: CY2027 Rate Announcement: What It Actually Costs Your Risk Scores.

For reference: proposed CY2027 coefficient changes (not finalized)

These were floated in the February 2026 Advance Notice and set aside. Treat as deferred context, not current policy. They indicate the direction of the eventual recalibration.

Condition / HCC

Proposed coefficient change

CKD Stage 3A

-50.4%

Drug Use Disorder (moderate/severe)

-24.3%

Morbid Obesity

-19.4%

COPD

-18.8%

Rheumatoid Arthritis

-17.3%

Major Depression

-13.7%

Heart Failure

-10.8%

Diabetes

-6.6%

Bladder/Colorectal/Other Cancers (HCC 22)

+12.1%

Septicemia/Sepsis/SIRS/Shock (HCC 2)

+15.6%

Source: CMS 2027 Advance Notice, February 2026 (proposed, not finalized) [2]

The role of AI in V28 compliance

The volume of code changes, the precision required in ICD-10-CM to HCC mapping, and the dual obligation to add and remove codes now exceed what manual workflows handle reliably at scale.

The most defensible platforms do four things. They analyse structured and unstructured data to surface conditions that still qualify under the model’s tighter requirements. They cross-walk V24 codes to V28, flagging what was removed or reclassified. They give providers documentation guidance during the encounter, not only after. And they generate evidence trails linking every suggested HCC to the specific clinical language in the record.

The unstructured data point matters more under V28 than it did under V24. The two things the model rewards, severity and whether a condition is currently active, usually live in the clinical narrative, not the structured problem list. A platform that only reads structured data misses the detail that makes a code defensible.

CMS’s own RADV plan calls for AI as a coder support tool, with human certified coders retaining all authority over overpayment determinations. [4] That is the same human-in-the-loop model RAAPID uses: Neuro-Symbolic AI surfaces the evidence and validates the HCC; the clinician or coder makes the final call. RAAPID’s platform reaches 92 percent out-of-the-box accuracy, rising above 98 percent after human-in-the-loop QA review, with a 60 to 80 percent productivity gain for coding teams.*

Generic NLP can spot that the word “diabetes” appears in a chart. What it cannot reliably do is separate a current, actively managed diabetic condition with documented complications from a historical mention of resolved glycemic issues. V28 demands that distinction at scale, and it demands an evidence trail that holds up when an auditor asks why a code was submitted.

Conclusion

V28 has changed what defensible risk adjustment looks like. Fewer valid codes. Weighting built on clinical seriousness. Constraining that eliminates duplicate credit. And an enforcement environment with active RADV audits, OIG reviews finding 91 percent error rates on high-risk diagnoses, and DOJ settlements aimed squarely at add-only programs.

The message is the one V28 delivered from the start: prove the codes you submit.

This is not a documentation problem alone. It is a clinical accountability problem. The organizations that navigate V28 link every code to encounter-grounded evidence, run two-way reviews that capture missed complexity and remove unsupported codes, and use AI that can show its work to an auditor.

RAAPID’s Clinical AI Platform was built for this environment: explainable, evidence-based, two-way, and audit-ready. To see how RAAPID supports MA plans and providers under V28, request a demo.

*Internal RAAPID benchmark. 92 percent out-of-the-box accuracy is an independently validated proof-of-concept figure; 98 percent-plus reflects final quality accuracy after human-in-the-loop QA review.

Frequently asked questions

 Yes. V28 became fully operative for payment year 2026, so 100 percent of Medicare Advantage risk scores are now calculated under it. The phased rollout (33 percent in 2024, 67 percent in 2025) is complete. [1]

CMS finalized V28 in the 2024 Rate Announcement and phased it in over three payment years: 33 percent in 2024, 67 percent in 2025, 100 percent in 2026. The transition completed on January 1, 2026. [1]

115 hierarchical condition categories and 7,770 valid ICD-10-CM diagnosis codes. V24 used 86 categories and 9,797 codes, so V28 added 29 categories while cutting a net 2,027 codes. [1]

The most severe condition in a related family supersedes the less severe ones, so a patient is credited once for the highest-acuity category documented. V28 also adds constraining, which forces some related HCCs to share the same coefficient.

Fewer valid diagnosis codes, plus constraining, which removes the duplicate credit that clinically related conditions earned under V24. CMS projected a 3.12 percent average decline. A lower score does not mean the patient got healthier. [1]

CMS expects programs to both add missed diagnoses and remove unsupported ones. The March 2026 Aetna settlement, $117.7 million, penalised an add-only program that submitted codes without deleting unsupported diagnoses found in the same review. [3]

Per OIG’s March 2026 audit (A-07-22-01207): acute stroke, acute MI, embolism, lung cancer, breast cancer, colon cancer, prostate cancer, sepsis, and pressure ulcer. Acute stroke and acute MI showed 100 percent error rates in the sample. [5]

 MEAT (Monitoring, Evaluation, Assessment, Treatment) is the documentation convention used to validate HCC diagnoses. Each submitted diagnosis should be supported by at least one element in the record, tied to a current face-to-face encounter, not a historical reference.

V28 expands high-RAF dementia categories but requires more specific documentation. MCI records must reflect the exact level coded, supported by MEAT-based evidence from a current visit. [6]

Severity, status (active versus historical), and the clinical reasoning behind the assessment, tied to a current encounter. V28 rewards specificity, so a condition recorded with clinical detail is far more defensible than a problem-list carryover.

Wynda 1

Wynda Clayton, MS, RHIT, CRC

Director of Risk Adjustment Coding & Compliance, RAAPID

Wynda is a recognized leader with over 20 years of experience in risk adjustment, coding, and compliance. A seasoned former CMS RADV auditor and educator, she focuses on improving coding accuracy and maintaining regulatory standards. At RAAPID, Wynda leads AI-driven initiatives that support defensible, value-based care delivery and reimbursement accuracy.

Lastest Posts

Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Disclaimer: All the information, views, and opinions expressed in this blog are inspired by Healthcare IT industry trends, guidelines, and their respective web sources and are aligned with the technology innovation, products, and solutions that RAAPID offers to the Risk adjustment market space in the US.