Back to Module 4: Risk Adjustment and Attribution

Lesson 2

How Risk Models Work

About 5 min

HCCs, risk scores, and coding intensity: how diagnoses turn into dollars, and how the process gets gamed.

The dominant risk adjustment approach in American healthcare is the Hierarchical Condition Category (HCC) family of models, used by Medicare Advantage, ACO benchmarking, marketplace risk adjustment, and many Medicaid programs. Understand HCCs and you can read most risk adjustment you will meet.

The pipeline: diagnoses to dollars

  1. Collect diagnoses. Every ICD-10 code on the patient’s claims during the base year.
  2. Map to condition categories. Thousands of codes collapse into a smaller set chosen for cost prediction: diabetes with complications, heart failure, COPD, major depression. Cheap or vague conditions are deliberately excluded.
  3. Resolve hierarchies. Within a disease family, only the most severe manifestation counts; across families, conditions add.
  4. Sum coefficients. Each category plus demographics carries a coefficient from national spending data. The total is the risk score, normalized so average is 1.0. A 2.0 predicts roughly double cost, and in Medicare Advantage roughly doubles the payment.

Two properties matter: the model is prospective (this year’s diagnoses set next year’s payment, hence the annual documentation ritual) and transparent (anyone can read the coefficient table, which makes it auditable, and also makes it a menu).

Coding intensity: the menu problem

Because each captured category has a knowable dollar value, an industry exists to capture them: wellness visits structured to re-document every chronic condition, chart-review programs, in-home assessments, “suspecting” algorithms, EHR prompts.

The result is well documented: identical patients score higher where coding incentives are stronger. Medicare Advantage scores have drifted upward relative to traditional Medicare for years, with overpayment estimates in the tens of billions annually.

Worth remembering: any model that pays on self-reported inputs will bend those inputs. Regulators respond with an across-the-board coding intensity haircut, periodic removal of commonly abused codes, and RADV audits that check coded diagnoses against medical records, with extrapolated paybacks.

Limits even honest users hit

  • Weak individual prediction. The models work in aggregate only; small panels stay risky under capitation no matter how good the adjustment.
  • New patients score as healthy. No diagnostic history, artificially low score.
  • Social risk is nearly invisible. Beyond markers like dual eligibility, the models do not see housing, food, or isolation, so providers serving the socially burdened remain underpaid relative to true need.

Key takeaways

  • HCC models map diagnoses to categories, resolve hierarchies, and sum coefficients into a payment-scaling score.
  • Transparency makes the model auditable and gameable at once; coding intensity is structural.
  • Even honest scores predict weakly for individuals and barely see social risk.

Check your understanding

1. A patient is coded with both 'diabetes without complications' and 'diabetes with chronic complications.' How does an HCC model score this?

2. Why do risk scores need to be re-documented every year?

Share