Seven Years of Knowing.
One Month to Fix It.
Elevance Health faces a July 31 cure deadline with $935 million in accrued liability. Seven years of false data certifications. The governance lesson belongs to every Medicare Advantage organization now entering CMS’s accelerated RADV audit pipeline.
CMS found seven years of known non-compliance. The deadline to fix it is July 31.
On February 27, 2026, CMS sent Elevance Health a notice that set in motion the most publicly visible Medicare Advantage data certification enforcement action in the program’s history. CMS found that Elevance had, for over seven years, failed to submit risk adjustment data through required electronic systems, failed to delete diagnosis codes not supported by medical records, and continued to annually certify the accuracy, completeness, and truthfulness of that data — knowing the certifications were false.
By March 31, 2026, intermediate sanctions were in effect: no new enrollment into Elevance Medicare Advantage plans, no communication activities to Medicare beneficiaries. Elevance accrued $935 million in its first-quarter 2026 earnings as its best current estimate of exposure. CMS subsequently extended the cure deadline to July 31.
Seven years. One month. $935 million.
The CMS notice cited failure to submit through RAPS (Risk Adjustment Processing System) and EDPS (Encounter Data Processing System) electronic pathways, using flash drives instead, and failure to delete unsupported codes through the RAOR (Risk Adjustment Online Reference) correction process. Both are required compliance mechanisms, not optional alternatives.
What Elevance actually did — and what it means
The specific failures matter because they are not obscure technical violations. The risk adjustment data certification requirement exists because MA payment rates are calculated from diagnosis data. Plans submit diagnoses, CMS applies risk scores, and payment follows. The integrity of that payment model depends on the accuracy of submitted diagnoses.
Elevance submitted its risk adjustment data via flash drives rather than through CMS’s required RAPS (Risk Adjustment Processing System) and EDPS (Encounter Data Processing System) electronic pathways. This alone would be a compliance violation. But the deeper issue is that Elevance also had diagnosis codes in its submissions that it knew were not supported by underlying medical records — and instead of deleting them through the RAOR (Risk Adjustment Online Reference) correction process, it left them in place. Then it certified the submissions as accurate.
That certification is a legal attestation. When a plan certifies its risk adjustment data submission, it is attesting that the data reflects actual documented diagnoses supported by medical records. Elevance’s certifications said that. The data did not support it. And this happened annually for seven years.
Why this is a governance story, not just a company story
The compliance failures documented in the CMS notice, flash drive submissions, uncorrected unsupported codes, false annual certifications, are not unique to the specific organization. They reflect what can happen when data certification is treated as an administrative step rather than a governance obligation with accountability attached.
Every MA organization now entering RADV audit fieldwork for PY2018–2024 faces a version of the same question Elevance faces: what does your data certification governance actually look like?
Why this matters beyond Elevance
The Elevance case is receiving attention because of its scale — $935 million is a material figure even for a large insurer. But the governance lesson is not specific to Elevance.
Every Medicare Advantage organization certifies its risk adjustment data. Every one attests to accuracy, completeness, and truthfulness. And CMS is running the most aggressive risk adjustment data validation program in Medicare Advantage history.
In March 2026, CMS notified contracts selected for Payment Year 2020 RADV audits. The Trump administration’s CMS announced a plan to complete all remaining RADV audits for payment years 2018 through 2024. The program that had been running years behind schedule is now being accelerated.
A RADV audit does not find that a plan certified falsely — it finds that specific diagnoses in the payment year cannot be validated against medical records. But when audits produce findings of unsupported diagnoses, the next question regulators ask is whether those findings reflect isolated errors or a pattern. A pattern — especially one that persists across multiple audit years — begins to look like what the Elevance case documents: known inaccuracy, uncorrected, and repeatedly attested to as accurate.
The Department of Justice is also watching. The Elevance case includes allegations that implicate the False Claims Act. $935 million in accrued liability reflects an estimate of what those civil exposure calculations might produce. Every MA organization now entering RADV audit fieldwork for PY2018–2024 faces a version of the same question Elevance faces: what does your data certification governance actually look like?
How seven years of knowing noncompliance became a July 31 deadline
The certification at the center of the Elevance case is not complicated. Every Medicare Advantage organization submits diagnosis data to CMS for risk adjustment purposes. At the end of each submission cycle, the plan’s authorized representative signs a certification attesting that the data is accurate, complete, and truthful. The certification is a federal attestation. False statements on federal certifications are the predicate for False Claims Act liability.
“Elevance had knowledge that diagnosis codes previously submitted were not supported by medical records and had not been corrected through CMS’s required systems, yet continued to annually certify the accuracy of its risk adjustment data submissions.” — CMS Notice, February 27, 2026
What good certification governance actually requires
Most MA compliance programs have documented risk adjustment workflows, code capture, medical record submission, diagnosis validation. The question is what happens at the governance layer above those workflows before the certification is signed.
Three control points matter: verification that the deletion workflow completed before submission (not just that the workflow exists), reconciliation of what is in the final submission against any medical record audit findings that identified unsupported codes, and a named authority, not a generic compliance sign-off, responsible for confirming accuracy before certification.
If any of those three control points cannot be answered with a specific name, a specific process, and a documented completion record, the certification is being signed without the governance infrastructure to support it.
The RADV acceleration changes the calculus
The Elevance case became an enforcement matter because CMS found a seven-year pattern. But the RADV program has a different trigger: it finds unsupported codes through sample-based audits. When RADV findings reveal an unsupported code rate that is statistically significant and consistent across years, the same question emerges, was this certified as accurate? The connection between audit findings and certification governance is the exposure that matters now.
The three certification governance questions
1. Who reviews deletion-eligible codes before certification to confirm the deletion workflow ran completely?
2. Who reconciles the submission against medical record audit findings that preceded it?
3. Who has authority to delay a certification if there is an identified accuracy concern?
What RAPS, EDPS, and RAOR are
RAPS: Risk Adjustment Processing System, required for diagnosis submission. EDPS: Encounter Data Processing System, encounter-level submission. RAOR: Risk Adjustment Online Reference, the required system for correcting and deleting previously submitted codes. Using flash drives instead of these systems is not a formatting issue. It is a compliance architecture failure.
The FCA exposure pathway
Under the False Claims Act, knowing submission of false claims for federal payment creates liability. An MA organization that certifies inaccurate risk adjustment data as accurate, receives elevated risk-adjusted payments as a result, and knew the certifications were false faces FCA exposure in addition to RADV overpayment recovery. Elevance’s $935M accrual reflects both tracks.
“The July 31 deadline tells Elevance’s story in compressed form: years of known exposure, one month to fix it, $935 million on the table. Plans receiving RADV notifications today have a narrower version of the same calculation to make — and considerably more time, if they start now.”
The certification failure
False annual certifications on federally regulated submissions are the predicate for FCA liability. The compliance issue is not the unsupported codes themselves, it is attesting they do not exist when they do.
The RADV connection
PY2020 RADV audits are underway. PY2018–2024 audits are in the accelerated pipeline. When audits find unsupported codes at scale, the first governance question is whether those findings were reflected in certifications, or certified away.
The governance gap
Most MA organizations have risk adjustment workflows. Few have the governance layer that validates whether what was processed is actually what gets certified. That gap, between workflow and attestation, is the Elevance lesson.
What every MA plan receiving RADV notifications should examine
Review certifications for audited years
For years under RADV audit, review the data certification record. Identify whether any codes that were certified as accurate have since been identified as unsupported through internal review or prior audit findings. The gap between what was certified and what was later found unsupported is the exposure.
Verify deletion workflow completion
Confirm that for each audited payment year, the RAOR deletion process ran to completion before the certification was signed. If there is no documented completion record, or if deletion-eligible codes were identified after certification without a correction process, scope the gap now — before audit fieldwork surfaces it.
Map submission pathway compliance
Confirm that all submissions for audited years were made through required RAPS and EDPS electronic pathways. Non-electronic submission methods are not a minor procedural variant, they are the first finding documented in the Elevance case and the first question CMS will ask in an audit that escalates to enforcement.
Build the certification governance layer
For the next certification cycle, establish the three governance control points: named reviewer of deletion workflow completion, reconciliation process against any prior audit findings, and identified authority to delay certification if accuracy cannot be confirmed. Document all three. The absence of documentation is the compliance risk.
The Elevance case has implications across every MA governance function
Compliance
Data certification is a legal attestation, not an administrative signature. Compliance programs that treat certification as a routine workflow step, without a governance layer validating accuracy before signing, carry the same exposure the Elevance case documents.
Finance
Overpayment recovery under RADV and FCA liability under DOJ are two separate financial exposure tracks. Both are triggered by the same predicate: certified inaccurate data that produced inflated payments. The $935M figure reflects both.
Audit and risk management
Internal audit programs for risk adjustment should include certification governance as a distinct audit objective, separate from the data quality review that precedes certification. The question is not only whether the data is accurate; it is whether the organization can demonstrate that accuracy was verified before signing.
Legal and government affairs
The DOJ component of the Elevance case is active. False Claims Act settlements in MA risk adjustment are not unprecedented, the Elevance matter would be the most significant. Legal teams should understand how the FCA exposure pathway connects to the certification process, not just the data accuracy question.
IT and data governance
The submission pathway violation, flash drives rather than RAPS/EDPS, is an IT governance failure, not just a compliance oversight. The required electronic pathways are not optional alternatives; they are the regulatory mechanism for data exchange. IT governance over submission infrastructure must be clearly owned and documented.
Executive leadership
Seven years. The Elevance case is a board-level governance story about what happens when a compliance problem is identified but not resolved at the ownership level. The certification is signed by an authorized representative. Accountability for what is being attested to belongs at the top of the organization, not in a workflow step.
What did Elevance actually do wrong — and why does it matter beyond this one case?
From November 2018 through October 2025, per CMS’s February 27 notice, Elevance submitted diagnosis code corrections via encrypted USB flash drives instead of the required RAPS and EDPS electronic systems, and did not complete the RAOR deletion process for codes unsupported by medical records. Each year, an authorized representative certified that data as accurate, complete, and truthful. Elevance disputes the “knowingly false” characterization, framing it instead as a disagreement over how retroactive corrections should be handled under the risk-adjustment framework in effect at the time. Beyond this case, every MA organization signs the same annual certification, the exposure is not about flash drives specifically, it is about whether the certification is backed by a governance layer that verifies accuracy before the signature, not just a workflow that processes the data.
What is the difference between a RADV audit finding and the kind of enforcement action CMS took against Elevance?
A RADV audit samples diagnoses and tests whether medical records support them, on its own, it doesn’t establish that a plan knew the codes were unsupported. The Elevance action is different in kind: CMS alleges a sustained, known pattern, evidenced by non-compliant submission channels and repeated annual certifications despite unresolved deletions. The exposure pathway converges, though, when RADV finds unsupported diagnoses at scale across payment years, the next question becomes whether those diagnoses were certified as accurate while the plan had reason to know otherwise. That is the bridge from an ordinary audit finding to a certification-based enforcement action.
What does good risk adjustment data certification governance actually look like? Where is the governance layer, and who owns it?
It sits in the gap between the workflow that processes risk adjustment data and the moment the certification is signed. Three concrete tests: a named reviewer confirms the RAOR deletion workflow ran to completion, with a documented record, before each certification; the final submission is reconciled against any internal audit or medical record findings that flagged unsupported codes, with exceptions resolved before signing; and a named individual holds explicit authority to delay a certification if an accuracy concern is unresolved. If none of these three has a specific owner and a documented completion record, the certification is being signed without the infrastructure to support what it attests to.
If my organization is in the RADV PY2018–2024 accelerated pipeline, what should I be reviewing before audit fieldwork begins?
Reconcile, for each payment year under audit, whether any diagnosis codes were later identified internally as unsupported, and whether they were corrected through RAOR or left in the submission. Confirm the deletion workflow has a documented completion record, not just an assumption that it ran. Check whether your certification process has ever been signed while a known accuracy exception was still open. The Elevance case is the benchmark: the finding was not that unsupported codes existed. It was that they were known and certified anyway. Scoping that gap before fieldwork finds it is the entire point of this review.
What is the False Claims Act exposure pathway from MA risk adjustment data — and how does it connect to the certification?
The annual certification is a federal attestation that risk adjustment data is accurate, complete, and truthful. If a plan certifies data it has reason to know is inaccurate, and that inaccuracy produces inflated CMS payments, the predicate elements for False Claims Act liability are in place: a false statement, made knowingly, tied to a payment. That is a separate and additional track from RADV overpayment recovery, which recovers the payment itself. The $935 million figure Elevance disclosed reflects both tracks together, which is why the range is wide, roughly $350 million to $1.5 billion, rather than a single precise number.