If You Can’t Explain the Data, You Can’t Defend It

Inside CMS Validation Expectations and Why Traceability Is Now the Standard

The Moment Data Gets Questioned

There is a point in every reporting cycle when the conversation changes.

Up to that point, the focus is on submission. Teams are working toward deadlines, ensuring measures are captured, and confirming that data has been reported correctly.

Then, at some point later, a different question is asked:

“Can you walk us through how this number was produced?”

This is where many organizations hesitate.

Not because the number is wrong.

But because the process behind it is unclear.

In 2026, that hesitation is no longer a minor issue. Under CMS audit and validation standards, it is often the starting point of exposure.

What CMS Is Actually Validating

There is still a common assumption that validation is focused on outcomes. That if the numbers are correct, the organization is in a strong position.

That assumption is outdated.

Under the Data Validation and Audit (DVA) process, CMS is not only reviewing what was submitted. It is examining the integrity of the process that produced the submission.

That includes:

• The origin of the data• The way it was captured in the EHR• The transformation of that data into a reportable format• The validation steps taken before submission

In other words, CMS is not just validating data.

It is validating data lineage.

Why Data Traceability Has Become the Standard

Data traceability is not a new concept, but it has taken on new importance.

In simple terms, traceability means the ability to move from a reported number back to the exact point in the patient record that supports it, and then forward again through the reporting process without losing clarity.

For many organizations, that path is not as clear as it seems.

Data may pass through multiple systems. It may be transformed, aggregated, or filtered. Each step introduces the possibility of misalignment.

When that path cannot be clearly explained, trust breaks down.

And when trust breaks down, validation becomes more difficult.

Where Traceability Breaks Down in Practice

The breakdown is rarely intentional. It is usually the result of reasonable operational decisions made over time.

Data is captured in different ways across practices. Some clinicians use structured fields consistently, while others rely on narrative notes. Lab results may be integrated directly in some cases and scanned in others.

Reporting tools pull from these sources, applying logic that may not be fully visible to every team involved.

By the time the data reaches the submission file, it appears clean and complete.

But when traced back, inconsistencies begin to surface.

The number is still there.

The path to the number is not.

The Hidden Risk of “Clean” Reports

One of the more challenging aspects of this issue is that it often goes unnoticed until validation occurs.

Reports can look accurate. Dashboards can show strong performance. Trends can appear stable.

This creates a sense of confidence.

But that confidence is based on output, not on process.

When CMS evaluates data, it is not relying on the appearance of accuracy. It is testing whether the reported results can be consistently reproduced and verified.

If the process is not stable, the output cannot be trusted.

A Closer Look: How Traceability Issues Surface

Consider a scenario where a quality measure shows strong performance across an ACO.

At the report level, everything appears in order. The numerator is high. The denominator is accurate. The score is competitive.

During validation, a sample of patient records is reviewed.

For some patients, the supporting documentation is clearly structured and aligns with the measure requirements. For others, the same data exists but is stored differently, perhaps in a scanned document or within narrative text.

The clinical outcome is the same.

But from a validation standpoint, the evidence is inconsistent.

This creates a situation where a portion of the reported numerator cannot be fully supported.

The issue is not that the care was incorrect.

It is that the data is not consistently traceable.

Bridging the Gap Between Systems and Accountability

One of the underlying challenges in traceability is that no single team owns the entire process.

Clinical teams focus on care delivery. Data teams focus on aggregation and reporting. Compliance teams focus on requirements and submission.

Each group performs its role effectively.

But without alignment, the connections between those roles weaken.

Traceability requires those connections to be intentional.

It requires a shared understanding of how data moves across the organization, and where accountability exists at each step.

Without that shared understanding, gaps are almost inevitable.

Building Traceability Into Existing Workflows

Improving traceability does not require starting over. It requires making the existing process more visible and more consistent.

The most effective organizations begin by mapping their data flow in practical terms. They identify where key data points originate, how they are captured, and how they are transformed as they move toward submission.

This is not a technical exercise alone. It is an operational one.

Once that path is clear, inconsistencies become easier to identify.

From there, adjustments can be made in a targeted way. Data entry points can be standardized. Validation steps can be clarified. Roles can be defined more precisely.

These changes are often small.

But they compound the effect on defensibility.

From Traceability to Trust

At its core, traceability is about trust.

CMS is not asking organizations to prove perfection. It is asking them to demonstrate that their processes are reliable, consistent, and explainable.

When an organization can clearly show how its data is generated and validated, it builds confidence.

Not just with regulators, but also internally.

Teams begin to trust the data they are working with. Decisions become more grounded. Performance becomes more stable.

Final Perspective

In today’s regulatory environment, data is no longer just an output. It is evidence.

And evidence must be traceable.

The organizations that succeed under DVA are not necessarily those with the most advanced systems. They are the ones that understand their own processes and can explain them clearly.

Because when the question comes, and it will, the answer needs to be more than a number.

It needs to be a narrative that holds up under review.

Take the Next Step

If your team has not recently examined how your data moves from patient chart to submission, now is the time to do it.

Chirpy Bird works with ACOs and practices to strengthen data traceability, improve audit defensibility, and align reporting workflows with CMS expectations.

👉 Schedule an ACO Strategy Call:https://www.chirpybirdinc.com/acos

Remember, it’s not enough for your data to be correct. It has to be trusted. That’s where Chirpy Bird shines.

Previous
Previous

From No-Shows to Closed Loops: Using Automated Text Reminders to Improve Cardiac Screening Rates and MIPS Performance

Next
Next

The Governance Gap in ACO Performance: Why Strategy Breaks Down Across Teams