If your organization is affiliated with a Medicare Shared Savings Program ACO, you already know the ground is shifting under one-sided risk. CMS finalized changes in the CY 2026 Physician Fee Schedule that cap one-sided BASIC track participation at five performance years, within an ACO’s first agreement period, for ACOs identified as inexperienced with performance-based risk entering new agreements starting January 1, 2027. That’s down from the prior standard, which allowed up to seven years spread across two separate agreement periods.[1]The direction is explicit: push ACOs further and faster toward two-sided risk, which is exactly why two-sided risk billing readiness has become an immediate priority for ACO-affiliated provider RCM operations, not a future planning item.
For behavioral health providers sitting inside these ACO networks, that shift isn’t background noise. A denied claim used to be a cash flow problem, annoying, but contained to that one claim. Now it’s a shared financial liability, because under two-sided risk, your ACO doesn’t just share in savings when spending falls below benchmark, it owes money back to CMS when spending runs over. A denied or miscoded claim feeds directly into that equation, showing up in your ACO’s benchmark performance and in how your organization is evaluated as a participant.
This guide is written for the revenue and finance leaders, and the operations and economics owners, who are responsible for making sure behavioral health billing operations can actually withstand that shift. Not the clinical rationale for value-based behavioral health care. You know that already. This is about what changes operationally in coding accuracy, clean claim rates, denial prevention, and RCM infrastructure once your organization’s billing performance is tied to shared financial risk rather than shared savings alone, and what we’ve learned at blueBriX helping behavioral health organizations navigate exactly this transition.
Why two-sided risk raises the stakes on every claim you submit
Under one-sided arrangements, a coding error or a missed prior authorization mostly costs you the reimbursement on that specific claim. It’s painful, but it’s contained. Under two-sided risk, the math changes in three ways that matter directly to your role.
Aggregate spends visibility works against imprecise billing
ACOs are evaluated against a benchmark built from historical and regional expenditure data. Every claim your behavioral health program submits, whether it’s General BHI under CPT 99484, Collaborative Care Model codes (99492, 99493, 99494, G2214), or the newer Advanced Primary Care Management behavioral health add-ons (G0568, G0569, G0570), feeds into that aggregate picture. Overcoding, undercoding, or inconsistent documentation doesn’t just risk an individual denial. It distorts the utilization and cost data CMS uses to reconcile the ACO’s performance, and it can flag your organization for downstream audit attention.
Repayment mechanisms are real and CMS enforces them
ACOs in Track 2-equivalent risk arrangements must demonstrate the adequacy of a repayment mechanism before entering a two-sided model, and CMS can require evidence of that mechanism at other points during the agreement period. If your ACO owes shared losses, that obligation gets funded from somewhere. Affiliated provider organizations that contribute disproportionately to denied or downcoded claims become a visible line item in how that liability gets allocated internally, even when the ACO doesn’t say so explicitly in its governance documents.
Quality performance and financial performance are now interlocked, not parallel tracks
Screening for Depression and Follow-Up Plan is currently the only mental health measure built into the ACO’s required quality measure set, which means your organization’s documentation habits around that single measure carry outsized weight in how your ACO’s quality score comes together. Your behavioral health billing accuracy has become a quality input, not just a revenue input, and CMS’s own data backs up the pressure: the mean percentage of patients screened and given a documented follow-up plan improved from 43.70% in performance year 2023 to 55.36% in performance year 2024, with ACOs reporting through digital quality measures also outperforming comparable physician groups outside the program by a meaningful margin.[2]
That single measure sits inside a broader shift where quality and financial performance no longer move on separate tracks. CMS has been raising the sharing rate ceiling for higher-risk tracks precisely because the data show ACOs that take on more risk, when they perform well, generate materially higher savings to the Medicare Trust Funds. But the inverse is also true: poor documentation and denial rates depress both financial performance and the quality measure reporting your ACO depends on for its MIPS Value Pathway or alternative quality standard.
For a revenue and finance owner, this reframes the RCM conversation. Denial prevention is no longer a departmental efficiency metric you report up. It is a contributor to whether your organization stays in good standing with an ACO that may be the anchor of a meaningful share of your Medicare-associated revenue.
Knowing the stakes have changed is one thing. Knowing exactly where your claims are most likely to trip is another.
Five denial patterns that hit behavioral health ACO billing hardest
Every organization thinks it knows what a clean claim looks like, until the stakes change. Under regulation, a clean claim is simply one a payer can process without asking for more information, no fraud flag, no medical necessity review needed. Medicare’s own prompt-payment framework sets a comparable bar: Medicare Administrative Contractors are required to pay clean claims within 30 days, with interest accruing on anything paid late.[3] There’s no forgiving equivalent inside an ACO relationship, every claim that isn’t clean the first time is one more data point muddying the utilization and cost figures your ACO’s benchmark is built on. CMS’s FY2025 data shows how much room for error exists nationally: a 6.55% improper payment rate, $28.83 billion, mostly from documentation and coding gaps rather than fraud.[4] Generic RCM benchmarks don’t capture where those gaps actually surface in a behavioral health, ACO-affiliated context. They tend to cluster in a few specific, predictable places.
Time-based documentation is still the most common point of failure
CoCM and BHI codes run on monthly time thresholds and structured care plan documentation. This isn’t a theoretical risk. HHS-OIG’s current compliance priorities specifically flag billing accuracy, supervision requirements, and the appropriateness of services provided under collaborative care codes as practices increasingly implement behavioral health services. A nationwide OIG audit of psychotherapy billing during the COVID-era telehealth expansion found that providers failed to meet Medicare documentation requirements for 128 of 216 sampled enrollee-days, an error rate OIG projected to roughly $580 million in improper payments with missing or insufficient time and content documentation as the dominant cause.[5] When the care management platform and the billing system aren’t pulling from the same source of truth, this is where denials, and audit exposure, start clustering.
Beneficiary assignment logic now touches behavioral health more directly
Starting performance year 2026, CMS folded behavioral health integration and psychiatric collaborative care add-ons into the definition of primary care services used for ACO beneficiary assignment, when billed alongside APCM (Advanced Primary Care Management). Practically, that means how you code these services can affect which beneficiaries land in your ACO’s assigned population, which in turn shapes the benchmark your ACO gets measured against. Getting the coding right isn’t just about getting paid anymore. It has a real effect on assignment and benchmarking downstream.
Multiple code families now stack, and stacking increases denial surface area
BHI, CoCM, and the new APCM behavioral health add-ons can be billed together, but only under specific same-practitioner, same-month rules. OIG’s April 2026 audit of Medicare virtual check-in and e-visit billing is a useful preview of what this kind of timing violation looks like in practice: auditors found over 183,000 potentially improper payments, worth more than $2 million, largely from services billed too close together in violation of Medicare’s timing rules — not fraud, but system edits and provider education that hadn’t kept pace with the billing rules.[6] The same mechanism applies to behavioral health code stacking: if your scrubbing rules haven’t been updated for the current code list, there’s a good chance you’re denying claims, or exposing the organization to overpayment findings, that you don’t even know about yet.
Prior period adjustments hit harder under risk-bearing arrangements
A billing correction made after the fact used to just be a bookkeeping fix. Under two-sided risk, if that correction touches utilization data that’s already feeding into an active performance year’s benchmark, the timing of when you catch it starts to matter in a way it didn’t before. OIG has also noted that value-based and shared-savings arrangements themselves are drawing more scrutiny, with growing attention to the accuracy of quality measure reporting and shared savings distributions tied to these programs. That scrutiny extends to the claims data underneath those calculations.
None of this is a reason to pump the brakes on expanding behavioral health services. CMS is actively opening up more reimbursement pathways for BHI and CoCM because the clinical and financial case is strong. It’s simply a signal, backed by where regulators are already looking, that the RCM infrastructure behind these services needs to be built for this specific coding environment, not stretched from a general fee-for-service setup.
Denials aren’t the only place this catches up with you. Some of the exposure isn’t in how you bill at all, it’s in how long you’re required to prove you billed correctly.
Recognize any of these patterns?
Time documentation gaps, code-stacking errors, frequency drift, they’re easy to catch in hindsight, harder to see while they’re happening. If any of this sounds familiar, a free revenue cycle assessment with blueBriX is the fastest way to find out before your next performance year closes.
Book a demoTwo records retention clocks apply to ACO participants
Most behavioral health billing teams already know that Medicare requires providers who order, certify, refer, or prescribe covered services to maintain supporting documentation for seven years from the date of service. What’s less commonly understood is that participation in the Shared Savings Program carries a longer, separate retention obligation, and missing that second clock is one of the easiest ways to get caught off guard.
An ACO must require its participants and providers to maintain records related to ACO activities, including Medicare utilization and cost data, quality performance measures, and shared savings or loss distributions, for ten years from the final date of the agreement period or the completion of any audit, whichever is later. If there’s a termination, dispute, or fraud allegation involving the ACO or any of its participants, that window extends an additional six years beyond the resolution of the matter.
In practice, this means a behavioral health participant’s retention policy built around the seven-year Medicare standard isn’t sufficient for records tied to its ACO participation. Two different clocks are running on two different sets of documentation, and a records destruction schedule calibrated to the shorter one creates exposure that may not surface until an audit request arrives for records the practice believed it was entitled to purge.
Both of these problems, the coding pitfalls and the retention mismatch, tend to trace back to the same root cause.
The operational gap most organizations don't see until it's expensive
Here’s where most ACO-affiliated behavioral health providers get caught off guard, and it’s worth naming directly because it’s the differentiator between organizations that transition to two-sided risk smoothly and those that don’t.
The gap is system architecture
Most behavioral health billing teams know the codes cold. That’s rarely where things fall apart. Where it tends to get messy is somewhere less obvious, whether the systems around the billing team actually talk to each other.
It’s a familiar setup across a lot of organizations: clinical notes live in the EHR, BHI or CoCM time gets tracked in a separate care management platform, the billing system doesn’t fully reconcile against either, and reporting back to the ACO ends up running through spreadsheets someone stitches together by hand. None of that is unusual. Most revenue cycles grew this way; one system added on top of another as programs expanded.
Under one-sided risk, that patchwork was mostly a workflow annoyance. It slowed things down, created rework, but rarely turned into real financial exposure. Two-sided risk changes the same patchwork costs. The same disconnects that used to just be inefficient now become the places where liability quietly builds, until it surfaces all at once during a CMS audit or an ACO reconciliation dispute, usually at the point where there’s the least time to sort it out.
Worth sitting with a few questions here, not as a checklist to pass or fail, but as a way to see where the seams actually are:
A quick self-audit: where does your organization actually stand?
Print this, or work through it with your billing and compliance leads. Each question includes what a passing answer actually looks like, not just a yes or no.
1. Can every BHI or CoCM claim be traced back to its time-based documentation without someone manually reconciling across systems?
A passing answer: You can pull a specific claim and its supporting time log, care plan update, and consultant note in under a few minutes, without emailing three people or exporting from two separate platforms.
2. Is denial data segmented by behavioral health code family in real time, or does it only show up as an aggregate number after the fact?
A passing answer: You can tell, this week, whether last month’s denials cluster around CoCM, BHI, or APCM add-ons specifically, not just that “denials are up 8%.”
3. Does your claims scrubbing logic reflect the current 2026 APCM behavioral health add-on codes and their eligibility rules, including the ACO or REACH ACO participation requirement?
A passing answer: Your scrubbing rules were updated after the CY2026 code changes went live, not carried over from a prior year’s rule set with the new codes bolted on.
4. If your ACO’s reconciliation team asked for utilization data to be substantiated for a specific performance year, how long would that take, and whose job would it be?
A passing answer: You can name the person responsible and estimate the turnaround in days, not weeks, and it doesn’t require reconstructing anything from scratch.
5. Is there a shared, documented understanding with your ACO of how repayment risk tied to billing performance actually gets assessed back to your organization?
A passing answer: It’s in writing. If it’s only implied, you’ll find out how it actually works during a reconciliation dispute, not before one, and that’s the wrong moment to learn it.
6. Does your records retention policy account for both retention clocks that apply to your organization?
A passing answer: Your destruction schedule has two separate timelines built in, not one blanket policy applied to everything.
If the honest answer touches multiple systems, multiple teams, and no clear owner, that’s not a knowledge gap. It’s the same architecture gap a lot of organizations are running into right now as two-sided risk becomes the default rather than the exception.
Closing a gap like that rarely happens by asking your existing team to simply work harder. It usually takes someone who’s closed it before.
Why blueBriX is the right RCM partner for this transition
The coding rules, the audit priorities, the benchmark mechanics, all of it is available in CMS documentation if you know where to look. What’s harder to find written down anywhere is judgment: knowing which of these pressure points actually turns into a problem for your organization, and which ones are more theoretical than operational.
That’s the gap blueBriX has spent more than 17 years closing for healthcare organizations, working specifically inside revenue cycle and compliance operations for behavioral health providers, ACOs, and other value-based care participants navigating exactly this kind of transition.
It’s knowing what a reconciliation dispute actually looks like from the inside, having sat in the conversation where an ACO and a participating provider work out how a shared loss gets allocated, and understanding where behavioral health documentation tends to fall short of what an auditor is actually looking for, because that’s been seen before, not guessed at.
For organizations moving from one-sided to two-sided risk, that kind of experience tends to matter most in three places:
Reading the real risk in your current billing patterns
blueBriX’s revenue cycle team starts most engagements with a full revenue cycle assessment, looking past the surface-level denial rate to where documentation habits, coding sequencing, and prior authorization gaps are likely to create exposure once claims start feeding into shared-loss calculations.
Running the day-to-day RCM functions that actually carry this risk
This isn’t advisory work sitting on top of your existing billing operation. It’s hands-on ownership of the coding, charge capture, denial management, and accounts receivable follow-through that determines whether your claims hold up under ACO-level scrutiny, delivered without requiring your organization to switch EHR systems.
Building the reporting habit that audit readiness actually requires
Rather than waiting for a year-end scramble, blueBriX’s team works from structured weekly and monthly reporting cycles, so producing a clean, substantiated utilization record for a specific performance year is a routine output of how the work already runs, not a special project.
Across the behavioral health organizations blueBriX has worked with, the pattern holds: closing the specific operational gaps, credentialing, pre-authorization, documentation habits, tends to move the needle faster than most organizations expect. In one recent engagement, that translated to a 33% revenue increase within 90 days. The number changes case to case, but the underlying discipline doesn’t: catch it before submission, and it stops being a problem you manage after the fact.
Where this leaves revenue and operations leaders
Two-sided risk isn’t a distant policy conversation anymore. CMS has set a five-year clock on one-sided MSSP participation starting in 2027, and ACO REACH participants are already living this reality today, since REACH requires two-sided risk from day one. Whichever path your ACO is on, risk-sharing is becoming the default, and your RCM needs to keep pace.
A couple of things are worth confirming directly with your compliance team as you move forward: whether your behavioral health documentation reflects the 2026 CoCM and BHI code updates, not last year’s standards, and whether your data-sharing practices with your ACO account for the updated 42 CFR Part 2 rules alongside HIPAA. Neither of these is something this guide can settle for you. Your ACO agreement and your state’s requirements shape the specifics, so that conversation belongs with your own counsel.
What is within your control is whether your revenue cycle is ready before any of this becomes urgent. That’s the exact transition blueBriX’s team has spent nearly two decades helping behavioral health organizations navigate.


