HEDIS measure data quality: what NCQA requires for star rating accuracy
Photo by Pawan Parihar on Unsplash
insight

HEDIS measure data quality: what NCQA requires for star rating accuracy

By Jason Alan Snyder·September 10, 2026

NCQA requires health plans to meet strict data quality thresholds across HEDIS measures before star ratings are calculated. A single missed mammogram record or misaligned value set can drop a plan's rating by half a star, costing millions in Quality Bonus Payments. The gap between collecting data and trusting data is where most health plans fail.

NCQA publishes over 90 HEDIS measures. CMS uses a subset of those measures to calculate Medicare Advantage star ratings. A half-star difference in a plan's overall rating can mean tens of millions of dollars in Quality Bonus Payments. And the difference between 4 stars and 4.5 stars often comes down not to clinical performance but to data quality.

This post covers what NCQA actually requires for HEDIS data quality, how star ratings are calculated, where data trust failures cost health plans the most, and what infrastructure is needed to close the gap.

What are HEDIS and NCQA quality measures?

HEDIS stands for the Healthcare Effectiveness Data and Information Set. NCQA, the National Committee for Quality Assurance, developed and maintains these measures. They are the most widely used performance measurement set in U.S. managed care.

HEDIS measures cover six domains of care: effectiveness of care, access and availability of care, experience of care, utilization and risk-adjusted utilization, health plan descriptive information, and measures reported using electronic clinical data systems. Each measure has a detailed technical specification that defines the eligible population (the denominator), the qualifying clinical action (the numerator), and the data sources acceptable for reporting.

More than 200 million people are enrolled in plans that report HEDIS data. NCQA collects and audits this data annually. The measures themselves are updated each year, with value sets, coding requirements, and age ranges shifting in ways that require constant data pipeline maintenance.

How is the NCQA star rating calculated?

CMS calculates Medicare Advantage star ratings using a combination of HEDIS measures, CAHPS (Consumer Assessment of Healthcare Providers and Systems) survey results, HOS (Health Outcomes Survey) data, and Part D drug measures. The overall star rating is a weighted composite.

For measurement year 2024, CMS weights the Part C measures at roughly 60% clinical quality (HEDIS-derived), 20% patient experience (CAHPS), and the remainder across access and process measures. The exact weighting shifts annually based on CMS's methodology updates.

Here is the sequence: health plans collect clinical and administrative data throughout the measurement year. They submit HEDIS results to NCQA. NCQA audits a sample. CMS ingests the validated results. CMS applies clustering algorithms to assign star ratings on a 1-to-5 scale. Plans with 4 stars or above receive Quality Bonus Payments, which can exceed 5% of their monthly CMS revenue.

The critical detail: CMS does not give credit for care that was delivered but not documented in compliant data. If a mammogram was performed but the claim was coded incorrectly, the member falls into the denominator without credit in the numerator. The plan's rate drops. The star rating drops. The payment drops.

What measures are included in star ratings?

CMS selects approximately 40 measures for star rating calculation in any given year. The HEDIS-derived clinical measures typically include:

  • Breast Cancer Screening (BCS)
  • Colorectal Cancer Screening (COL)
  • Comprehensive Diabetes Care (CDC), including HbA1c control and eye exams
  • Controlling High Blood Pressure (CBP)
  • Osteoporosis Management in Women Who Had a Fracture (OMW)
  • Plan All-Cause Readmissions (PCR)
  • Statin Therapy for Patients with Cardiovascular Disease (SPC)
  • Medication Adherence measures for diabetes, hypertension, and cholesterol (Part D)
  • Triple-weighted measures carry three times the impact of single-weighted measures in the star calculation. For 2025 ratings, several medication adherence and chronic condition management measures are triple-weighted. A 2-percentage-point improvement in a triple-weighted measure can shift a plan's overall rating more than a 5-point improvement in a single-weighted measure.

    What are the HEDIS stars measures?

    The term "HEDIS stars measures" refers specifically to the subset of HEDIS measures CMS selects for Medicare Advantage star rating calculation. Not all HEDIS measures count toward stars. NCQA maintains the full HEDIS set for accreditation and quality improvement purposes; CMS picks from that set for payment purposes.

    The distinction matters for data quality. Plans must report the full HEDIS measure set to NCQA for accreditation. But the financial incentive concentrates on the star-rated subset. This creates a predictable pattern: plans invest heavily in data quality for star measures and underinvest in the rest. The result is uneven data infrastructure, where some clinical domains have clean, auditable data and others have gaps that surface only during NCQA audits or state regulatory reviews.

    Key statistics

    DTI dimensions most critical for HEDIS audit survival
    DTI dimensions most critical for HEDIS audit survival

  • A half-star increase in Medicare Advantage star ratings can generate $50 million or more in additional annual Quality Bonus Payments for large plans.
  • NCQA audits require health plans to demonstrate data completeness rates above 95% for administrative data and maintain error rates below 5% on validated medical record samples.
  • CMS uses approximately 40 measures for star rating calculation, with triple-weighted measures carrying 3x impact on the composite score.
  • SuperTruth's DTI Engine reduced data standardization time for 105,000 diagnostic records from 3 weeks to 2 hours in the imaware partnership, a 95% reduction.
  • Plans that fail NCQA HEDIS Compliance Audits can face star rating reductions, accreditation sanctions, or loss of CMS contract eligibility.
  • The five data quality requirements NCQA enforces

    NCQA does not simply accept whatever data a plan submits. The HEDIS Compliance Audit process examines five areas that together define what "data quality" means in this context.

    1. Data completeness. NCQA requires plans to demonstrate that their administrative data captures a defined threshold of all eligible encounters. If a plan's claims data misses significant volumes of encounters from delegated providers, out-of-network facilities, or carve-out behavioral health vendors, the denominator and numerator calculations are wrong. Plans must document their data completeness assessment methodology and show that supplemental data sources fill identified gaps.

    2. Data accuracy. Claims must use correct value sets. HEDIS value sets define which CPT, HCPCS, ICD-10, LOINC, and SNOMED codes qualify as evidence of a compliant service. A colonoscopy coded with an outdated CPT code does not count. An HbA1c result reported without the correct LOINC code is invisible to the measure engine. NCQA updates value sets annually, and plans that fail to propagate those updates through their data pipelines produce inaccurate rates.

    3. Source verification. When plans use medical record review (chart abstraction) to supplement administrative data, NCQA requires that abstractors follow documented protocols. The audit examines inter-rater reliability, abstractor training records, and whether the abstracted data matches the source medical record. Plans cannot fabricate or infer clinical events from partial documentation.

    4. Data integration. Most plans receive data from multiple sources: claims adjudication systems, pharmacy benefit managers, lab vendors, EHR feeds, health information exchanges, and supplemental data files from provider groups. NCQA requires plans to document how these sources are integrated, how deduplication is handled, and how conflicts between sources are resolved. A lab result from a reference lab and a claim from the ordering physician for the same test should not inflate the numerator.

    5. Audit trail integrity. NCQA auditors must be able to trace any numerator hit back to its source record. If a plan reports that a member received a breast cancer screening, the auditor should be able to follow the data from the HEDIS rate to the specific claim or medical record that generated the numerator event. Plans that cannot produce this chain of custody fail the audit.

    Where data quality failures actually happen

    The top-ranked search results focus on closure rates and abstraction pitfalls. Those are real problems. But they are symptoms, not root causes. The root causes are structural.

    Supplemental data without provenance. Plans increasingly accept supplemental data from provider groups, often as flat files or bulk data extracts. These files may contain clinical events that legitimately occurred but lack the metadata needed for audit. When was the data extracted? From which system? Was the patient correctly matched? Without provenance, supplemental data is a liability during NCQA audit.

    Value set drift. NCQA updates HEDIS value sets every year. Plans that hard-code value sets into their measure engines instead of dynamically referencing the current year's specifications will produce incorrect rates. This is not a hypothetical problem. It is one of the most common findings in HEDIS audits.

    Member attribution errors. HEDIS measures define eligible populations based on continuous enrollment, age, and benefit structure. If a plan's enrollment data contains errors (wrong date of birth, incorrect enrollment spans, missing benefit flags), members are incorrectly included in or excluded from measure denominators. These errors are invisible at the individual level but distort rates at the population level.

    Lab data gaps. Measures like Comprehensive Diabetes Care (HbA1c) and Controlling High Blood Pressure depend on lab results or clinical values. Many plans lack direct lab data feeds and rely on claims to infer that a test was performed. But claims tell you a test was ordered and billed; they do not always tell you the result. Without the result value, the plan cannot determine whether the member's HbA1c was above or below the control threshold.

    Temporal misalignment. HEDIS measures define specific measurement periods, often the calendar year. A screening performed on December 28 may not appear in claims data until mid-January due to claims lag. If the plan's data extract for HEDIS reporting occurs before that claim is adjudicated, the screening is missed. This is not a data quality problem in the traditional sense; it is a temporal alignment problem that claims data lag makes worse every year.

    What NCQA star rating data trust actually requires

    NCQA's requirements map directly to the dimensions of data trust that determine whether a record can be relied upon for consequential decisions.

    Provenance answers the question: where did this data come from, and can I verify that? NCQA's audit trail requirement is a provenance requirement.

    Recency answers the question: is this data current enough for the measurement period? HEDIS's strict calendar-year windows make recency a gating factor.

    Concordance answers the question: do multiple data sources agree on the same clinical fact? NCQA's data integration requirement is a concordance requirement.

    Quality answers the question: is this record coded correctly against the current value set? HEDIS value set compliance is a quality requirement.

    Completeness answers the question: are there gaps in this data that would distort the measure rate? NCQA's data completeness assessment is exactly this.

    These are five of the eight dimensions the Data Trust Index scores. The alignment is not coincidental. NCQA's audit framework and DTI's scoring framework both exist because the same underlying problem drives both: you cannot make accurate decisions from data you cannot verify.

    The cost of getting it wrong

    A plan with 500,000 Medicare Advantage members that drops from 4.5 stars to 4 stars loses its Quality Bonus Payment. For a plan of that size, the annual revenue impact can exceed $50 million.

    But the direct revenue loss is only part of the cost. Plans below 4 stars lose the ability to market the star rating advantage. They face higher member churn during Annual Enrollment Period. They trigger enhanced CMS scrutiny. And if data quality problems persist across multiple audit cycles, NCQA can revoke accreditation, which effectively removes the plan from the market.

    The irony is that most of these losses are preventable. The clinical care was often delivered. The mammogram happened. The HbA1c was tested. The statin was prescribed. The failure was in the data pipeline, not the clinic.

    How trust scoring changes the HEDIS data problem

    HEDIS data standardization: before and after DTI Engine (imaware case study)
    HEDIS data standardization: before and after DTI Engine (imaware case study)

    Traditional HEDIS data management treats every record as equally trustworthy until an auditor proves otherwise. This is backwards. By the time an auditor finds a problem, the rates have been submitted, the star rating has been calculated, and the revenue impact is locked in.

    Trust scoring inverts this. Every record is scored at the point of ingestion, before it enters the measure engine. A supplemental data file from a provider group that arrives without provenance metadata receives a low trust score. A claims record with an outdated value set code is flagged before it contaminates the numerator. A lab result without a LOINC code is identified as incomplete before it creates a false gap.

    This is what the DTI Engine does. It scores every health data record from 0 to 100 across eight dimensions: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%). For HEDIS purposes, the Provenance, Recency, Quality, and Concordance dimensions are the ones that directly determine whether a record will survive an NCQA audit.

    Plans that score data before reporting it can set DTI floor thresholds for HEDIS measure inclusion. A record below 70 gets flagged for review. A record below 50 gets excluded from automated reporting and routed to chart review. A record above 85 flows through with confidence.

    This is not theoretical. In SuperTruth's partnership with imaware, the DTI Engine standardized 105,000 diagnostic records, reducing processing time from three weeks to two hours and saving over 200 hours per month. The same scoring infrastructure applies to HEDIS measure data: score the record, trust the rate.

    What health plans should build now

    Health plans preparing for the 2026 measurement year should address three infrastructure gaps.

    First, implement trust scoring at the point of data ingestion. Do not wait until HEDIS season to discover that 15% of your supplemental data lacks provenance. Score it when it arrives.

    Second, automate value set currency checks. Every data element that enters your measure engine should be validated against the current-year HEDIS value set. Static value set tables updated once a year are insufficient.

    Third, build concordance checks across data sources. When claims data and EHR data disagree on whether a service was rendered, you need a systematic way to resolve the conflict before it reaches the measure engine. This is not a manual process at scale; it requires data trust infrastructure that can evaluate multiple sources programmatically.

    The plans that treat HEDIS data quality as a data trust problem, not just a compliance exercise, are the ones that will hold 4.5 stars.

    The DTI Engine scores every provider and clinical record for provenance, recency, and concordance, the three dimensions that break HEDIS audits and drag star ratings down. If your team is facing NCQA compliance pressure or preparing for the next measurement year, talk to the SuperTruth commercial team. Schedule a conversation or call (215) 918-4140.

    Further reading:

  • Health plans solution
  • DTI™ Engine
  • Claims data lag: what 30-90 day reporting delays cost AI models
  • Payer data trust: what health plans need from their data before deploying AI
  • NCQA credentialing standards 2025-2026: how data trust scoring supports compliance
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    Provider data that holds up under NCQA audit.

    DTI scoring for credentialing, CMS CRUSH, and No Surprises Act.

    See our approach
    Share