Open-source technologies have become a standard part of modern analytics, data science and AI. Organizations across regulated industries are adopting tools like Python to accelerate innovation while building more flexible analytics environments.
But adopting open-source technologies introduces a new challenge.
As organizations modernize, they must also maintain the governance, transparency and auditability required by regulators, auditors and business stakeholders. The conversation is no longer about choosing one programming language over another. It's about creating analytics environments where multiple technologies can work together without compromising trust.
Recent announcements from the Centers for Medicare and Medicaid Services (CMS) illustrate this shift. While much of the discussion has focused on CMS introducing Python-based reference code for Hierarchical Condition Category (HCC) risk adjustment models, the larger story is about how organizations modernize analytics while preserving the controls required for payment-critical operations.
HCC risk adjustment coding software has sparked considerable discussion across the health insurance industry. Much of the conversation has focused on a simple question: Is CMS moving from SAS to Python?
Focusing solely on the programming language misses the larger story.
What CMS is signaling is not simply a software transition. It is a broader shift toward open analytics ecosystems – an environment where organizations can leverage multiple technologies while maintaining the governance, transparency, and compliance required for payment-critical operations.
For health plans, the strategic question is no longer whether to embrace open-source technologies. The question is how to modernize while preserving the controls and accountability that regulators, auditors and business stakeholders demand.
The programming language is only one part of the transition
Python has become one of the most widely adopted languages for analytics, data science and AI. CMS's introduction of Python-based reference codes reflects that broader industry trend.
But the underlying requirements are not changing. The transition does not alter risk adjustment methodologies, model coefficients, payment calculations or regulatory requirements.
Health plans remain responsible for producing accurate, reproducible and auditable results regardless of which language executes the model.
That distinction matters because model code represents only one part of the process. The harder work is operationalizing analytics across the systems, teams and controls that support risk adjustment.
Modernization extends beyond model execution
Risk adjustment is not a standalone model. It is an enterprise process involving encounter ingestion, diagnosis validation, coding analytics, reconciliation, payment forecasting, reporting and audit support.
Most health plans have spent years building these capabilities into complex operational workflows. As organizations adopt Python-based reference implementations, they must ensure those workflows remain stable, traceable and compliant.
This is where modernization efforts often encounter friction.
Introducing a new language may be relatively straightforward. Maintaining data lineage, version control, testing standards, security controls and audit readiness across multiple technologies is considerably more difficult.
The organizations that succeed will be those that modernize the entire analytics ecosystem, not just the model code.
Parallel validation can reduce transition risk
For health plans, the transition period presents an opportunity to validate, optimize and strengthen their risk adjustment operations.
Many organizations are expected to run SAS and Python implementations in parallel during the transition. This congruent process allows teams to reconcile results, identify discrepancies, validate assumptions and build confidence before production deployment.
But parallel validation creates new operational demands. Multiple teams – including actuarial, risk adjustment, analytics, IT and compliance – must collaborate using consistent data, shared controls and common reporting frameworks.
When those activities happen in disconnected environments, organizations can increase complexity and compliance exposure.
When they happen on a unified analytics platform, health plans can use the transition to improve governance, collaboration and operational consistency.
Enterprise platforms matter more in an open ecosystem
Organizations once evaluated analytics platforms largely based on the programming language they supported.
That is no longer enough.
The most important question is no longer whether a platform supports multiple languages and tools while applying consistent governance across them.
A modern platform such as SAS® Viya® enables organizations to run SAS and Python workloads on the same governed data foundation. Teams can use open-source technologies without sacrificing security, lineage, reproducibility or compliance across the analytics life cycle.
For health plans, that creates flexibility to adopt CMS Python reference code without weakening the controls around payment-critical workflows.
The goal is not to choose between modernization and governance. It is to create an environment where both can coexist.
A compliance change can become a broader modernization opportunity
Forward-looking health plans can treat the CMS transition as more than a technical or compliance exercise.
The same capabilities required to support HCC model validation – data quality monitoring, model governance, workflow automation and advanced analytics – can also improve diagnosis capture, coding accuracy, performance, quality measurement and value-based care initiatives.
In this sense, the transition creates an opportunity to elevate risk adjustment from a regulatory function to a strategic enterprise capability.
What this shift means for regulated industries
The CMS transition is one example of a larger change already underway.
Organizations across regulated industries are adopting open-source technologies while facing continued pressure to produce trusted, explainable and auditable results.
The organizations that will derive the greatest value are not those that simply implement Python first. They are the organizations that build modern, governed analytics environments capable of supporting whatever technologies come next.
Open analytics and enterprise governance are becoming less separable, not more.
The future of regulated analytics will depend on how confidently organizations can use new technologies without losing control of the decisions those technologies support.