Elevance certified its Medicare data as truthful while its own coders had flagged the codes as unsupported

A smiling doctor in a white coat talking to a patient in a clinic

Elevance Health’s Medicare Advantage arm signed an annual certification, year after year, telling federal regulators that the diagnosis data behind its Medicare payments was accurate, complete and truthful. A federal enforcement notice made public in February 2026 says that certification did not match what the company already knew: Elevance’s own certified coders had reviewed many of the same diagnosis codes and determined they were not supported by patients’ medical records, yet the company kept signing the certification anyway. The Centers for Medicare & Medicaid Services says that contradiction ran from 2018 through 2025 and became part of the legal basis for sanctions against 45 of Elevance’s Medicare contracts, sanctions that were ultimately called off in July 2026 after Elevance corrected the underlying data.

Elevance’s Own Coders Found the Problem First

According to CMS’s February 27, 2026 sanction notice, Elevance “explicitly acknowledged in its correspondence to CMS that it conducted retrospective medical record reviews and identified diagnosis codes that it has been unable to verify by medical record documentation.” Those reviews, the notice states, “were conducted by certified coders” — Elevance’s own staff, not an outside auditor or a government investigator — who determined that certain diagnosis codes providers had previously submitted for Medicare Advantage risk-adjustment payments did not hold up against the underlying medical charts. CMS’s notice labels these “potentially unverified diagnosis codes,” the same phrase Elevance used in its own letters to the agency describing them.


Free download: The first-hour steps in order, who to call at banks, agencies and credit bureaus, and what to document. Get the free scam and identity-theft action card.

Seven Letters Disclosing the Problem, Six Telling Elevance to Fix It

Between November 13, 2018 and October 10, 2025, Elevance sent CMS seven separate letters disclosing the unverified codes rather than correcting them through CMS’s official Risk Adjustment Processing System, Encounter Data Processing System, or Risk Adjustment Overpayment Reporting module. CMS answered with six letters of its own, dated between July 12, 2019 and May 16, 2025, each repeating that Elevance had to submit the corrections through those required systems and that the encrypted USB flash drives it kept sending instead did not count. The codes at issue covered patient visits from 2015 through April 2023 — Medicare Advantage payment years 2016 through 2024 — a span CMS says affects “numerous contracts and beneficiaries.”

The Certification Kept Being Signed Anyway

Federal regulation requires Medicare Advantage insurers to certify, based on their “best knowledge, information, and belief,” that the risk-adjustment data they submit is “accurate, complete, and truthful,” a promise built into both the annual certification itself and the electronic data agreement each insurer signs with CMS under 42 C.F.R. 422.504(l). CMS’s notice concludes Elevance violated that regulation because the company “continued to annually certify the accuracy, completeness, and truthfulness of its risk adjustment data submissions” while its own coders’ reviews showed some of that same data was unsupported and had not been corrected through the required channels. The unsupported codes were not a rounding error: CMS’s notice states that diagnosis codes lacking medical-record support “increase capitated payments” from Medicare, meaning the certification problem tracked directly to how much the government paid Elevance for each affected beneficiary. CMS’s notice also acknowledges that no insurer submits perfect data, but says the “best knowledge, information, and belief” standard still requires good-faith efforts to investigate and correct known errors rather than to keep ignoring information already in hand about unsupported diagnoses.

What Federal Law Says About Knowing and Not Fixing It

Separately from the certification requirement, federal law imposes what CMS’s notice calls the “Overpayment Rule”: once an insurer identifies an overpayment, Section 1128J(d) of the Social Security Act gives it 60 days to report and return the money. CMS’s notice cites a federal appeals court’s description of that rule as unambiguous: “the Overpayment Rule requires that, if an insurer learns a diagnosis it submitted to CMS for payment lacks support in the beneficiary’s medical record, the insurer must refund that payment within sixty days. The Rule couldn’t be simpler.” The notice measures “knowingly” using the False Claims Act’s definition, which reaches beyond deliberate deception to include “deliberate ignorance and reckless disregard of the truth” — a standard CMS applied to Elevance’s own coders identifying the unsupported codes years before the company corrected them through its required systems.

The Case Closed Without Taking Effect

CMS’s notice grounds the sanctions in specific regulatory violations — an inaccurate annual certification, missed 60-day deadlines for reporting overpayments, and a failure to submit data through required systems — the same set of facts described above: Elevance kept certifying data as accurate that its own coders had already identified as unsupported. Those sanctions, which would have suspended new enrollment and communications across the 45 named contracts, never took effect. CMS notified Elevance in a July 13, 2026 letter, again signed by John A. Scott, director of the agency’s Medicare Parts C and D Oversight and Enforcement Group, that the company had completed its corrective steps on July 9, 2026 and that the enforcement process for the matter had been closed. Elevance’s own quarterly filing with the Securities and Exchange Commission for the period ending June 30, 2026 records that same July 13 notification, closing out a dispute that began with the company’s own coders raising a question about data Elevance kept certifying as true.


Guarding a Medicare Number Against Misuse

Elevance’s dispute with CMS was about the company’s own systems re-certifying Medicare diagnosis data internally, not about a beneficiary’s Medicare number being stolen or misused by an outsider. But the same kind of record CMS says went uncorrected for years — diagnosis and coding data tied to an individual’s Medicare number — is also the kind of record an identity thief targets, and a beneficiary has no equivalent of CMS’s enforcement notices to flag when something in a personal file does not match reality.

The Senior Fraud Defense & First-Hour Recovery Kit is a 9-page kit built around a first-hour recovery plan, a family code word, and a fraud evidence and report log.

Read the first-hour recovery plan in The Senior Fraud Defense & First-Hour Recovery Kit.

This article was researched and drafted with the assistance of AI and reviewed by an editor.

Leave a Reply

Your email address will not be published. Required fields are marked *