Same Rule, New Enforcement: Document to the Greatest Degree of Defensible Specificity
- Jun 14
- 3 min read
he Matrix, HealthFair, and HealthFair founder settlement deserves close attention from anyone responsible for risk adjustment strategy, documentation integrity, vendor oversight, or value-based care operations.
The case in brief: Matrix Medical Network, HealthFair, and HealthFair’s founder agreed to pay $56.5 million to resolve False Claims Act allegations involving false or invalid diagnosis codes submitted to the Medicare Advantage program. According to DOJ, the allegations centered on diagnoses generated through in-home and mobile assessments that were allegedly unsupported, unsubstantiated, inconsistent with coding and reporting standards, contradicted by testing, or not documented by other providers across multiple years. The settlement resolves the allegations only, with no determination of liability.
What this case now does is serve as a warning. The larger issue is the continued enforcement focus on whether risk-adjusting diagnoses are supported by the medical record, whether the clinical evidence is current and defensible, and whether the process used to capture those diagnoses can withstand scrutiny. And when alleged False Claims Act violations are in play, vendors should not assume they are outside the firing range.
The “medical record” in this case means more than what is sitting inside your own EHR and certainly more than a diagnosis captured in a single encounter. A single provider can substantiate a diagnosis when the documentation and clinical evidence support it. The concern is when a risk-adjusting condition appears in one isolated encounter and does not align with the broader medical record, treatment history, diagnostic testing, or follow-up care.
Documentation still has to carry the burden of proof. A diagnosis should be captured to the greatest degree of specificity a provider can clinically justify, but it cannot be stretched beyond what the record supports. Ahem, that includes suspected diagnoses that have not been substantiated.
Risk adjustment programs need clinical clarity in addition to coding logic. If a condition is assessed, treated, monitored, or evaluated, that needs to be clear in the note. If the evidence is thin, vague, historical, copied forward without clinical relevance, contradicted by test results, or based only on patient attestation or claims history, it should not be treated as support. Regardless of what a vendor says.
Now here’s the enforcement point that should have every organization paying attention: the scrutiny is not stopping at the diagnosis code. It is extending into the process used to identify, recommend, validate, delete, and submit that diagnosis. If a vendor is part of that chain of events, the vendor is part of the risk.
Vendor involvement requires disciplined oversight. Health plans and provider organizations need a clear view into the vendor’s operating model, not just the final coding output. That includes how clinical criteria are applied, how deletes are handled, and how AI, analytics, or suspecting tools influence the recommendation before it ever reaches the provider. Productivity expectations matter here too, because they can quietly shape behavior in ways no compliance policy intended.
At the end of the day, what a provider submits for coding and billing remains the responsibility of that provider, not the vendor. But the vendor’s role, and potential complicity, can no longer be treated as background noise.
Words to the wise: if your program is better at surfacing diagnoses than defending them, it is time to recalibrate.
Strategies to maintain defensible documentation:
Review vendor workflows with the same scrutiny applied to internal coding teams.
Audit adds and deletes together. Unsupported additions are obvious risk, but ignored deletes create their own exposure.
Train providers on specificity, disease status, causality, clinical criteria, and treatment impact.
Make documentation improvement part of clinical operations, not a year-end coding clean-up.
Require every submitted diagnosis to answer a simple question: where is the current clinical evidence?
This case matters because it reinforces a clear enforcement precedent. Risk adjustment compliance is being evaluated across the full operating model, from clinical assessment to coding recommendation to vendor involvement to final submission.
The DOJ release specifically calls out diagnoses allegedly submitted without sufficient support, diagnoses that did not meet coding and reporting standards, conditions not documented by other providers across multiple years, diagnoses based only on limited sources, and diagnoses contradicted by testing. That is the part every risk adjustment leader should sit with.
Organizations should use this moment to pressure-test their own programs. Start with a sample of recently submitted risk-adjusting diagnoses, especially those tied to suspecting logic, chart review, in-home assessments, mobile assessments, or vendor recommendations. Trace each diagnosis back to the clinical evidence, the provider note, the vendor workflow, and the final submitted code.
If the story does not hold together, fix the process before an auditor rewrites it for you. And that rewrite will not be cheap.


