The Code Is Only as Good as Your Ability to Defend It
Accurate risk adjustment coding is table stakes. What separates organizations that survive audits from those that don't is whether they can prove it, and most can't.
There is a version of this conversation that most provider organization leaders are not having yet. They are focused on closing care gaps, improving HCC capture rates, and reconciling encounter data before deadlines. Those are legitimate priorities. But they are incomplete. The question that should be keeping your compliance and coding leadership up at night is not whether your codes are right. It is whether you can prove they are right when a payer or CMS decides to look.
That distinction is not semantic. It is the difference between revenue that holds and revenue that gets clawed back.
"Inaccurate coding gets you in trouble. Accurate coding you can't defend gets you in the same place, just with more paperwork."
The audit environment has changed materially in the last several years. RADV audits are no longer periodic inconveniences. They are a structured mechanism for revenue recovery, and CMS has made clear it intends to use them more aggressively. Commercial risk-bearing contracts follow similar patterns. The documentation standards being applied in these audits are exacting, and the margin for ambiguity has narrowed. What passed review in 2019 may not pass today.
The gap most organizations don't see coming
Here is what we observe consistently when working with large provider organizations: coding accuracy and coding defensibility are treated as the same problem. They are not. Accuracy asks whether the right HCCs were captured. Defensibility asks whether the clinical documentation in the medical record can withstand scrutiny, and whether a trained auditor, working from your chart alone, would arrive at the same conclusions your coders did.
That gap is real, it is common, and it is expensive. Organizations with sophisticated coding programs still carry meaningful audit risk because the documentation infrastructure, including the specificity of physician notes, the completeness of problem lists, and the clarity of clinical linkage, does not support the codes that were legitimately assigned. The code is correct. The chart doesn't prove it.
This is a physician documentation problem as much as it is a coding problem. It is also a workflow problem, a training problem, and increasingly, a technology problem. But it does not get solved by adding another coding review layer at the back end. It gets solved upstream, at the point of care, before the encounter closes.
What large organizations get wrong
Scale creates a specific kind of vulnerability. Large health systems and provider organizations often have volume on their side: thousands of encounters, broad HCC coverage, robust analytics. What they frequently lack is documentation consistency at the provider level. A network of fifty employed physicians will have fifty different documentation habits, fifty different levels of specificity, and fifty different interpretations of what "addressed" means for a chronic condition.
Centralized coding teams do their best to work with what they are given. But they cannot manufacture clinical specificity that was never captured. When an auditor asks to see the documentation supporting a Diabetes with CKD code, or a Major Depression code, or a Morbid Obesity code, the chart has to stand on its own. A coder's note in the margin does not count.
"The chart has to stand on its own. A coder's note in the margin does not count."
The organizations that manage this well have made physician documentation a clinical quality issue, not just a revenue cycle issue. They have built feedback loops between audit findings and provider education. They have made specificity a standard, not an exception. And they have invested in real-time tools that surface documentation gaps while the physician is still in the encounter, not six months later when an appeal is the only option left.
Compliance is not a one-time project
The other structural problem in large organizations is the tendency to treat audit readiness as a periodic initiative rather than an operational state. Organizations will commission a chart audit review ahead of a contract renewal or in response to a bad RADV result, close the immediate gaps, and return to business as usual. Three years later, the same vulnerabilities have re-emerged because the underlying documentation culture was never changed.
Sustainable audit defense is not an event. It is a system, one that includes ongoing documentation monitoring, closed-loop provider feedback, regular coding validation against current CMS guidance, and clear ownership of the process at the leadership level. The organizations getting this right are not doing more audits. They are making audit readiness a continuous operating condition.
The leadership imperative
None of this happens without executive sponsorship. Coding and documentation quality sit at the intersection of clinical operations, compliance, and finance, and that intersection is historically where accountability gets diffuse. Physicians defer to coders. Coders defer to compliance. Compliance escalates to legal. Legal writes a policy. The policy sits in a shared drive.
What actually works is a clear owner, typically a Chief Compliance Officer, CMO, or VP of Revenue Integrity, who has both the authority to set documentation standards and the organizational relationships to hold providers accountable to them. The technical infrastructure matters. The analytics matter. But the single biggest predictor of whether an organization can defend its code is whether someone in the C-suite has made it their job to ensure it can.
If no one owns it, no one defends it. And if no one defends it, the code doesn't count, regardless of how accurate it was.