Skip to main content
Should You Deploy AI in Risk Adjustment Coding?Compliance Program Frameworks
5 min readFor Ethics & Hotline Program Leaders

Should You Deploy AI in Risk Adjustment Coding?

You're considering an AI-powered coding assistant that promises to "maximize risk scores" and "identify missed HCC opportunities." Your Medicare Advantage panel is expanding, and your coding staff is stretched thin. The business case seems strong.

However, the Department of Justice and Centers for Medicare & Medicaid Services (CMS) have made Medicare Advantage fraud a top enforcement priority. Introducing AI adds a new layer of compliance risk to an already scrutinized area.

Here's how to decide whether AI belongs in your risk adjustment workflow, and if so, under what conditions.

The Decision You're Facing

You have three options for managing diagnosis coding and risk adjustment in your Medicare Advantage population:

  • Manual coding with human oversight only
  • AI-assisted coding with structured physician review
  • Fully automated AI coding with minimal human intervention

Each option carries different compliance risks, resource needs, and operational implications. The False Claims Act doesn't differentiate between fraudulent claims from human error or algorithmic mistakes. Your liability remains the same.

Key Factors That Affect Your Choice

Your current coding accuracy baseline. If you're struggling with documentation quality or coding consistency, AI won't solve the problem. It'll amplify it. Ensure you have clean data and clear clinical documentation practices before introducing any technology.

Your physician review capacity. Some states require physicians to review AI-generated content before signing off on medical records. Even if not mandated, it's a critical safeguard. If your providers can't review charts carefully, you're not ready for AI-assisted coding.

The specificity of your AI tool. Generic AI scrapers that pull historical diagnoses without clinical context can inflate risk adjustment, which enforcement agencies target. A patient who took opioids after surgery ten years ago doesn't have a substance use disorder today. Poorly designed AI might code it that way.

Your documentation standards. Risk adjustment codes must be supported by documentation of patient care, treatment, or management at that specific visit. If your AI tool suggests codes not addressed during the encounter, you're building a False Claims Act case against yourself.

Path A: Manual Coding with Human Oversight

Choose this path when:

  • Your coding staff can handle the current volume
  • You're seeing high variability in AI vendor demonstrations
  • Your documentation practices need strengthening
  • You operate in a state with strict physician review requirements
  • Your compliance program is still developing

What this looks like in practice: Certified coders review encounter documentation and assign diagnosis codes based on what's documented. Physicians sign charts only after reviewing clinical content for accuracy. Regular internal audits compare diagnosis codes to clinical documentation.

The compliance advantage: Every code has a human decision-maker who can explain the clinical rationale. When CMS or DOJ reviews your charts, there's a clear chain of accountability.

The operational constraint: You're limited by human coding capacity. You may miss legitimate risk adjustment opportunities because coders don't have time to review every nuance of complex charts.

Path B: AI-Assisted Coding with Structured Physician Review

Choose this path when:

  • You have strong baseline documentation practices
  • Your physicians understand their review obligations
  • You're selecting AI tools designed specifically for compliant risk adjustment
  • You can implement mandatory physician review before chart closure
  • Your compliance program can audit AI suggestions against clinical documentation

What this looks like in practice: AI reviews encounter notes and suggests potential diagnosis codes based on documented clinical findings. These suggestions go to your coding team for validation. Before any chart closes, the treating physician reviews all AI-generated content and confirms it reflects actual patient care delivered during that visit.

You build audit protocols that track how often AI suggestions get rejected, which code categories generate the most AI errors, and whether risk scores inflate without corresponding changes in clinical complexity.

The compliance advantage: AI helps identify documentation gaps and coding opportunities, but humans make the final call. You gain efficiency without losing clinical judgment.

The operational requirement: You need robust workflows. Physicians must have protected time for chart review. Your compliance team needs to monitor AI performance continuously. This isn't "set it and forget it" automation.

Path C: Fully Automated AI Coding

Don't choose this path. Not in the current enforcement environment.

If a vendor claims their AI can code charts without physician review, they're selling you False Claims Act liability. The government targets "coding intensity" practices that inflate risk scores without clinical justification.

Even if the technology works perfectly 95% of the time, that 5% error rate translates to thousands of potentially fraudulent claims at scale. When those claims systematically upcode severity, you've created a pattern that triggers whistleblower cases and government investigation.

Summary Matrix

Approach Compliance Risk Operational Capacity When to Use
Manual coding only Lowest (clear accountability) Limited by human capacity Documentation practices need work; state requires strict physician review; early compliance maturity
AI-assisted with physician review Moderate (requires strong controls) Scales with proper workflows Strong documentation baseline; physicians have review time; compliance can audit AI performance
Fully automated AI Highest (liability without judgment) Appears efficient but creates exposure Never in current enforcement environment

The Requirements That Drive Each Path

The False Claims Act creates liability for submitting claims you know, or should know, are false. "Should know" includes deliberate ignorance and reckless disregard. If you deploy AI that routinely suggests unsupported codes, and you don't have controls to catch those errors, you meet the "should know" standard.

Risk adjustment codes must reflect conditions documented as affecting patient care during the specific encounter being coded. Historical diagnoses that aren't currently managed don't count. AI tools that automatically roll forward prior conditions without clinical validation create exactly this problem.

Your path forward depends on whether you can implement the controls that turn AI from a compliance risk into a compliant tool: mandatory physician review, continuous audit of AI suggestions, and the operational discipline to reject codes that aren't clinically supported, even when they'd increase reimbursement.

Choose the path that matches your current capabilities. Don't let vendor promises or revenue pressure push you into automation your compliance program can't support.

You Might Also Like