RADV Audits, $674M in Settlements & Risk Adjustment 2026
Logo

Two Settlements. $674 Million. What the 2026 Enforcement Environment Means for Medicare Risk Adjustment Programs

3Gen Consulting
3Gen Consulting, Content TeamAugust 21, 2026
RADV audits Medicare risk adjustment 2026 FCA settlements Kaiser Aetna OIG enforcement risk adjustment solutions compliance

For most of the past decade, Medicare Advantage risk adjustment compliance was understood primarily through the lens of RADV audits – CMS's program for reviewing a sample of submitted diagnosis codes against the underlying medical records. A RADV finding could result in recoupment, adjustments, and operational scrutiny. Significant, but manageable.

In the first quarter of 2026, the financial stakes changed.

What the $674 Million in Settlements Actually Reveals

On January 14, 2026, the Department of Justice announced that five Kaiser Permanente affiliates agreed to pay $556 million to resolve False Claims Act allegations – the largest MA risk adjustment FCA settlement on record. The DOJ alleged that Kaiser had engaged in a systemic pattern, spanning 2009 to 2018, of pressuring physicians to add diagnoses to patient records well after medical visits, collectively adding approximately half a million diagnoses and generating what the government characterized as roughly $1 billion in additional Medicare payments [1].

Whistleblowers – including a physician who identified coding practices he believed were inflating risk scores – will receive approximately $95 million from the settlement.

On March 11, 2026, the DOJ announced that Aetna agreed to pay $117.7 million to resolve similar allegations [2]. The Aetna case illustrates a crucial compliance distinction. The government's allegations included two separate theories: first, that Aetna submitted inaccurate diagnosis codes; and second, that during a chart review program, Aetna's coders "selectively added codes that increased reimbursement while failing to remove unsupported codes that would have reduced payments" [3]. A former Aetna risk-adjustment coding auditor filed the qui tam complaint. Her relator share: $2.01 million.

Two settlements. Two insider whistleblowers. One operational pattern at the center of both cases: retrospective chart reviews and addenda processes used to add diagnoses, without a corresponding obligation to remove codes that were not supported.

Why "Failure to Delete" Is the Compliance Insight That Changes How Risk Adjustment Programs Must Be Built

The most important enforcement signal from the 2026 settlements is not the dollar amount. It is the legal theory.

The government's position – upheld through settlement in both cases – is that failing to delete or withdraw an inaccurate diagnosis code constitutes a False Claims Act violation independent of the act of submitting that code. If a Medicare risk adjustment program identifies a diagnosis that is not supported by the medical record and does not delete it, the plan has potential FCA exposure – even if that code was not the product of any active manipulation.

This has structural implications for how risk adjustment programs are designed.

A purely retrospective chart review model – in which coders are hired to review completed medical records and identify additional diagnoses to submit – is now the highest-risk risk adjustment methodology. If that model is not paired with an equal and rigorous obligation to identify and remove unsupported codes, the chart review itself becomes a compliance liability. Regulators have demonstrated they view "one-way ratchet" retrospective processes as FCA-eligible conduct.

The directional answer is a shift toward concurrent and prospective Medicare risk adjustment – capturing conditions at the point of care rather than identifying them retrospectively and using gap identification to alert treating physicians to undocumented conditions before encounters close. Contemporaneous documentation is materially harder to characterize as manipulation.

What the Broader Enforcement Landscape Signals for 2026 and Beyond

The settlements do not stand alone. The enforcement environment around RADV audits and MA risk adjustment has been building across multiple federal channels simultaneously.

The OIG's 2026 MA audit series – four coordinated compliance audits published in the first half of the year – found the majority of sampled diagnosis codes unsupported by medical records in every case. The June 2026 acute stroke audit found 97 of 97 sampled codes unsupported, generating an estimated $462 million in overpayment exposure [4]. These are RADV-style audits – not FCA cases – but they identify the documentation patterns that FCA investigations then scrutinize.

The OIG also added a work plan project specifically comparing the CMS-HCC V24 and V28 risk adjustment models, examining whether the V28 transition produced the anticipated savings and whether coding patterns shifted in response to model changes [5]. This signals active federal interest in whether MA organizations adapted their coding to the new model appropriately.

Most significantly, the OIG published its Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG) in 2026 – the first update to the agency's MA compliance guidance since its original 1999 document [6]. The MA ICPG sets out what the OIG considers an effective compliance program for MA organizations, grounded in the agency's enforcement experience from "decades of work on matters involving the MA program, including audits, evaluations, investigations, enforcement actions, data analyses, development of industry resources, and monitoring under Corporate Integrity Agreements." For MA risk adjustment leaders, this document is the federal government's clearest current statement of what it expects.

Taken together, the picture is consistent: federal oversight of MA risk adjustment coding is systematic, coordinated, and not slowing down.

What Medicare Risk Adjustment Programs Must Include in 2026 to Be Defensible

The compliance requirements for a defensible Medicare risk adjustment program have shifted materially in 2026. Organizations relying on program designs developed before the 2026 settlements are evaluating risk under a different regulatory framework than currently exists.

A defensible program in this environment requires:

  • Bidirectional code validation. Every process designed to identify additional diagnoses must be paired with an equally rigorous process to identify and remove diagnoses that are not supported by the medical record. The Aetna settlement makes clear that the government views a one-way process as FCA-eligible conduct.
  • Contemporaneous documentation as the primary foundation. Concurrent risk adjustment – coding at or near the point of care – and prospective gap identification – alerting treating physicians to potentially under documented conditions before the visit – produce documentation that reflects clinical reality at the time of the encounter. This is structurally more defensible than retroactive addenda processes.
  • CMS-HCC V28 alignment. The OIG's active work plan comparison of V24 and V28 signals that organizations whose risk scores do not reflect the expected trajectory under V28 may attract scrutiny. Risk adjustment programs must be calibrated to V28's updated HCC categories, coefficient values, and specificity requirements – not carried forward from V24 workflows.
  • Insider awareness as a compliance variable. Both the Kaiser and Aetna cases were brought by insiders – a physician and a coding auditor – who observed documentation practices they believed were improper. Risk adjustment program governance now includes managing the compliance posture of the program as seen by the people operating it, not only how it appears to regulators.
  • OIG MA ICPG alignment. The new compliance guidance provides a voluntary but substantive framework for MA program design. Organizations that can demonstrate alignment with the MA ICPG – including governance structures, internal monitoring, and response protocols – are better positioned when FCA exposure is assessed.

How 3Gen's Risk Adjustment Solutions Address the 2026 Enforcement Environment

At 3Gen Consulting, our risk adjustment solutions are designed around the documentation integrity requirements that the 2026 enforcement environment has made explicit – not as a response to the settlements, but as the foundational architecture of a defensible program.

RiskGen-i – our AI-enabled risk adjustment platform – supports prospective gap identification and concurrent HCC capture, aligned to CMS-HCC V28. Rather than retrospectively reviewing charts for codes to add, RiskGen-i surfaces potentially under documented conditions before or during the encounter – enabling treating physicians to address and document them contemporaneously. This is the directional shift the enforcement environment is pointing toward.

RiskGen-Core – our coder-led risk adjustment model – pairs certified HCC specialists with structured audit workflows that validate both what is captured and what should be removed. The bidirectional validation architecture is built in, not added as an afterthought.

Both programs produce RAF performance reporting and audit trail documentation that gives MA  leadership real-time visibility into coding accuracy and compliance posture – the type of governance infrastructure that the OIG's MA ICPG describes as foundational to an effective compliance program.

For Medicare Advantage plans evaluating their risk adjustment programs in the context of 2026's enforcement realities, the question is not whether to address the compliance gap – it is how quickly the existing program can be assessed and restructured. The Kaiser and Aetna settlements have established what is at stake. The OIG's compliance guidance, work plan, and audit series define what the government is looking for.

If your Medicare Advantage risk adjustment program was designed before 2026's enforcement landscape took shape, the gap between your current program and a defensible one is worth understanding precisely. Connect with 3Gen's risk adjustment specialists.

[1] U.S. Department of Justice, “Kaiser Permanente Affiliates Pay $556M to Resolve False Claims Act Allegations,” 14 January 2026. Available: https://www.justice.gov/opa/pr/kaiser-permanente-affiliates-pay-556m-resolve-false-claims-act-allegations.

[2] U.S. Department of Justice, “Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act Allegations,” 11 March 2026. Available: https://www.justice.gov/opa/pr/aetna-agrees-pay-1177-million-resolve-false-claims-act-allegations.

[3] Whistleblower Law Collaborative, “Aetna Agrees to Pay $117.7 Million to Settle Medicare Part C Case,” 20 March 2026. Available: https://www.whistleblowerllc.com/aetna-agrees-to-pay-117-7-million-to-settle-medicare-part-c-case/.

[4] HHS Office of Inspector General, “CMS Potentially Overpaid Medicare Advantage Organizations $462 Million Based on Certain Unsupported Acute Stroke Diagnosis Codes,” 1 June 2026. Available: https://oig.hhs.gov/reports/all/2026/cms-potentially-overpaid-medicare-advantage-organizations-462-million-based-on-certain-unsupported-acute-stroke-diagnosis-codes/.

[5] HHS Office of Inspector General, “Trends, Patterns, and Key Comparisons Related to CMS-HCC Risk Adjustment 2020 Model (V24) and 2024 Model (V28),” 15 January 2026. Available: https://oig.hhs.gov/reports/work-plan/browse-work-plan-projects/trends-patterns-and-key-comparisons-related-to-cms-hcc-risk-adjustment-2020-model-v24-and-2024-model-v28/.

[6] HHS Office of Inspector General, “Medicare Advantage Industry Segment-Specific Compliance Program Guidance,” February 2026. Available: https://oig.hhs.gov/documents/compliance/11464/ma-icpg.pdf.

Is Your Medicare Risk Adjustment Program Built for 2026's Enforcement Environment?

Get a risk adjustment program assessment from specialists.

form

Connect with our experts to:

  • Assess your RADV audit readiness 
  • Validate V28 coding alignment 
  • Build bidirectional code governance

Explore our strategic insights & resources

Pathology Revenue Health Check
E-Guideread more
RADV audits Medicare risk adjustment 2026 FCA settlements Kaiser Aetna OIG enforcement risk adjustment
Blogread more
alt Thumb edit
Infographicread more
View All ResourcesView All Resources

FAQs

The FAQ section simplifies key information about 3Gen Consulting’s services, helping partners navigate our offerings, methodologies, and value.

Talk to an ExpertTalk to an Expert

RADV (Risk Adjustment Data Validation) audits are CMS's program for reviewing a sample of diagnosis codes submitted by Medicare Advantage organizations against the underlying medical records, with overpayments recovered when codes are found unsupported. The Kaiser and Aetna cases were False Claims Act matters brought by DOJ under whistleblower complaints – a legally distinct mechanism that can result in treble damages and nine-figure liability, rather than the claim-level recoupment typical of RADV audits.

Both cases involved retrospective chart review and addenda processes that selectively added revenue-generating diagnosis codes while failing to remove or delete codes that were not supported by medical records – a pattern the DOJ characterized as a "one-way ratchet." The government's position in both cases is that the failure to delete an inaccurate code constitutes a False Claims Act violation independently of the act of submitting that code.

The DOJ's enforcement theory – confirmed through settlement in both the Kaiser and Aetna cases – establishes that identifying an unsupported diagnosis and failing to remove it creates FCA exposure, even without any active submission of a false code. Medicare risk adjustment programs that conduct chart reviews without an equal and systematic process for identifying and removing unsupported diagnoses are operating under a compliance design the DOJ has now characterized as legally actionable.

The OIG published its Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG) in 2026 – the first update to the agency's MA compliance guidance since the original 1999 document. The MA ICPG draws on the OIG's enforcement experience across audits, investigations, and Corporate Integrity Agreements to define what an effective compliance program for MA organizations looks like, including risk adjustment coding governance.

A defensible program requires bidirectional code validation – processes that identify both what should be added and what should be removed – combined with concurrent and prospective risk adjustment that captures diagnoses contemporaneously rather than through retrospective addenda, CMS-HCC V28 alignment, and governance infrastructure that produces audit-ready documentation. The OIG's MA ICPG provides a voluntary framework for what the government considers adequate compliance program design.

3Gen's risk adjustment solutions – RiskGen-i (AI-enabled prospective and concurrent HCC capture) and RiskGen-Core (coder-led with bidirectional audit workflows) – are built around the documentation integrity requirements that 2026's enforcement environment has made explicit. Both programs are aligned to CMS-HCC V28, produce RAF performance reporting with audit trail documentation, and include the bidirectional validation architecture – identifying what should be captured and what should be removed – that the Kaiser and Aetna settlements establish as the compliance standard.

let's
talk