On this page
The denials nobody appeals
In 2024, Medicare Advantage plans made nearly 53 million prior authorization decisions and denied 4.1 million of them. Providers and patients appealed 11.5% of those denials, and 80.7% of the appeals overturned the denial in whole or part[31]. In HealthCare.gov marketplace plans the gap is wider: insurers denied 20% of in-network claims in 2023, and fewer than 1% of the denials were appealed[30].
Few of those denials turn on medicine. In the marketplace data, 6% of in-network denials cited medical necessity, against 21% for administrative reasons such as missing information, duplicates or late filing[30]. When the HHS Inspector General sampled 2019 Medicare Advantage denials, 18% of payment denials met Medicare coverage and billing rules. Most of those were caused on the plan's side by "human error during manual claims processing reviews" and "system processing errors"[6].
- 11.5% appealed, 80.7% won
- Of 4.1 million Medicare Advantage prior authorization denials in 2024, the share appealed, and the share of appeals that overturned the denial in whole or part[31]
- Under 1%
- Share of denied in-network claims in HealthCare.gov marketplace plans that were appealed, 2023[30]
- 1.2 seconds
- Average time Cigna medical directors spent per claim signing off batches of denials flagged by its PXDX system, as reported in 2023[48]
Many of these denials go unappealed for lack of staff hours. Someone has to read the 835, find the authorization, pull the right two documents and file the payer's form before the window closes. Teams work the largest first, and the rest age out.
The other side already runs software on your claims: the PXDX figure above is one insurer's, and CMS now uses AI in traditional Medicare prior authorization in six states[5]. The question for a billing operation is whether its own agents can do the dull work at the same speed without sending a single claim nobody on staff would defend.
The short version
AI-enabled vs AI-native revenue cycle
An AI-native operation lets agents take the first pass on every queue, keeps people on every decision that changes what a claim says about care or moves money, and can show for any claim who approved what. Success is measured in cash collected per staff hour and appeals filed against appealable, with no claim sent that a person did not stand behind.
The missing layer: who stands behind the claim
Agents now come with the PM system, the clearinghouse, the coding vendor and the ambient note tool, and each governs only its own actions. None governs an agent that reads an 835 in the clearinghouse, finds an authorization in a client's PM system, pulls two documents from the EHR and files an appeal in one task. That task is where a billing company's exposure sits: which client's data it read, whether it touched a code, and who approved what left.
OrchKernel sits in that gap. Agents ask it before they act; it checks the rules, holds what needs a person, and records the result against the named person the agent works for. It governs only the actions agents send through it. It is not a practice management system, a clearinghouse, an encoder or a claim scrubber, and it holds no charges, claims or payments. Details are in the OrchKernel blueprint.
Denial sorting, status checks, appeal drafts, posting exceptions, balance explanations. Each works for a named specialist, on one client, with no more access than that person.
- Approvals
- Rules
- Field access
- Human queue
- Audit log
Allows, holds for a person, or denies, and records which.
- PM system or EHR
- Clearinghouse
- Payer APIs
- Document store
- Email and fax
- Statements and payments
Where the hours and money go
US health spending reached $5.3 trillion in 2024, 18.0% of GDP[1], and a 2019 JAMA study put waste from administrative complexity at $265.6 billion a year[32]. Several figures below come from hospital and physician groups arguing against payer practices, and are labelled.
What this means for agents. The money is in appeals never filed, rework done before deadlines and denials prevented at registration: clerical tasks with clear inputs, such as an 835 line, a reason code, a payer policy and a date. The risk is elsewhere: anything that changes what a claim says about care can become a false claim.
The claim loop and where AI works today
A claim runs on standard transactions: the 837 claim, the 277CA acknowledgement or rejection, 270/271 eligibility, 276/277 status, 278 authorization, and the 835 remittance, the regulated payment and remittance advice[17]. Each 835 line carries reason codes (CARC and RARC) that say why a claim was paid, reduced or denied. Those codes are what agents sort on.
- 1Front endBefore and at the visit
- Eligibility, benefits and coverage discoveryCommon today
- Prior authorization checks and packetsGrowing
- Self-pay estimatesGrowing
- 2Mid-cycleFrom the note to the claim
- Ambient notes and documentation gap flagsGrowing
- Coding suggestions; touchless coding in narrow specialtiesCommon today
- Claim scrubbing and denial predictionCommon today
- Choosing or changing a code, modifier or diagnosis; CDI queriesKeep a person
- 3Back endAfter the claim leaves
- Claim status checks and payer callsCommon today
- Posting clean 835 remittancesCommon today
- Sorting denials, drafting fixes and appealsGrowing
- Submitting appeals, refunds, write-offs, collectionsKeep a person
The loop back. Every denial carries a reason code. Sorted daily, the codes show which registration, eligibility or authorization step failed. Fix the cause there, where it costs the least.
Who sells what
Categories, not recommendations. Every performance figure below is the vendor's own claim, directional and not an industry benchmark.
Adoption, with caveats
In a 2023 survey sponsored by AKASA, an AI vendor, with HFMA, 46% of hospitals used AI in revenue cycle work; the AHA's examples of results are self-reported by health systems and their vendors[36]. In an MGMA quick poll, 34% of medical groups had built a workflow tool with AI[38], and 61% of physicians in an AMA survey think payers' AI is raising denials[37]. We found no independent survey of AI use in medical billing companies.
Where the money went
Into roll-ups of services labor. In May 2025 New Mountain Capital combined SmarterDx, Thoughtful.ai and Access Healthcare, a revenue cycle services firm, into Smarter Technologies, which by its own account handles 400 million transactions a year and manages $200 billion in revenue[47]. Commure calls itself an "AI-native healthcare operations platform" whose aim is to "turn labor into software" (company claims)[46]. R1, one of the largest outsourcers, was taken private for $8.9 billion in November 2024[51].
Into the clearinghouses. Waystar reported $319.7 million of revenue in Q2 2026, up 18%[40], and in August announced agents that resubmit eligible denied claims on their own[39].
We found no comparable investment aimed at mid-size billing companies or in-house teams. They will get AI features from their PM system and clearinghouse while the roll-ups bid for their clients. What they can still decide for themselves is which agents act on their clients' claims, and with whose approval.
The staged path
Six stages, ordered by risk: read before write, draft before submit, clerical before coding, and autonomy earned one class of work at a time. The order also follows the money, since few denials turn on medical necessity. A billing company can run different clients at different stages; an in-house team can do the same by payer group.
- 0
Stage 0: Know your denials, payers and access
Measure before you automate.
About 4 to 8 weeks, alongside normal work
What to do
- Pull 12 months of 835 remittances and group denials by reason code (CARC and RARC), payer, client and dollars.
- Write the payer rule library for your top payers: filing limits, appeal levels and addresses, attachment rules, authorization lists.
- Find every AI feature already switched on in the PM system, EHR and clearinghouse.
- Write the role map: which role sees which fields, for which client.
- Sign a business associate agreement with any model provider before PHI reaches it, and ban PHI in public chatbots in writing.
Why now
You cannot judge an agent without a baseline, and HIPAA already requires the role map: who needs access and to which categories of PHI[19].
In place first
- Export access to 835s and work queues.
- A named compliance owner and a named privacy officer.
What to measure
- Share of denial dollars mapped to a root cause
- Share of payer volume covered by the rule library
- Baseline denial, appeal and overturn rates, days in AR, claims past filing limit
Common mistakes
- Buying a tool before you know your denial mix.
- Staff pasting claims into public chatbots while the policy is still being written.
- 1
Stage 1: Read and sort, no writes
Nothing changes on any claim.
Starts on one client or one payer group once Stage 0 covers it
What to do
- Agents sort every denial and rejection the day the 835 or 277CA arrives.
- Agents rank the AR worklist by balance and by days left before each filing limit.
- Agents check claim status electronically (276/277) before anyone picks up the phone.
- Agents match payer bulletins to the clients and codes they affect, and draft month-end client reports.
Why now
Sorting saves hours, changes nothing a payer sees, and shows within weeks whether the agent reads denials the way your specialists do.
In place first
- Read-only connections, per client.
- The denial taxonomy from Stage 0.
- A human queue with an owner for what the agent cannot place.
What to measure
- Agreement between agent and specialist sorting
- Claims reaching a filing limit unworked (target zero)
Common mistakes
- Giving read access to every client at once, so one practice's agent can see another's patients.
- Skipping a two-week side-by-side with specialists sorting the same denials, so there is no evidence for Stage 2.
- 2
Stage 2: Agents draft, people submit
Every item approved before it leaves.
After a month or two of Stage 1 on the same slice
What to do
- Agents draft rejection fixes and corrected claims for demographic, eligibility and timely-filing errors.
- Agents assemble appeal packets: the payer's form, a letter from your template, and only the attachments that denial reason needs.
- Agents draft paper EOB and exception postings, balance explanations and refund packets; a specialist approves each before it reaches a payer, a patient or the ledger.
Why now
This is where the unappealed money is, and nothing leaves without a specialist's approval. Most Medicare Advantage prior authorization appeals that do get filed succeed[31]; the constraint is the hours to file them.
In place first
- An approval step that shows the exact packet, not a summary.
- Templates owned by named people, with no clinical claims in them.
- An attachment list per denial reason.
What to measure
- Appeals filed as a share of appealable denials
- Approval-without-edit rate by draft type
- Time per approval, to catch rubber-stamping
Common mistakes
- Approving in big batches. A click on a batch is not a review, as the Cigna PXDX case below shows.
- Letting a draft touch codes or modifiers.
- 3
Stage 3: Prevent at the front end, assist the coders
Stop denials before the claim exists.
Once Stages 1 and 2 show which front-end failures cost most
What to do
- Agents run eligibility and coverage discovery before the visit.
- Agents check whether a service needs authorization and assemble the packet, through payer APIs as plans publish them under CMS-0057-F, due by 1 January 2027[3].
- Agents draft good faith estimates for self-pay patients, which are due within 1 or 3 business days[23]; a person sends them.
- Computer-assisted coding suggests codes; a coder accepts or overrides each one.
- Agents flag a possible documentation gap to a CDI specialist. They never add a diagnosis and never send a query to a provider.
Why now
A denial prevented at registration costs nothing to appeal, and the payer API deadline arrives in 2027.
In place first
- Root-cause data from Stages 1 and 2.
- Coding and CDI leads who own the acceptance rules.
- A written rule that agents never add diagnoses or send provider queries.
What to measure
- Denials in eligibility and authorization reason groups
- Coder acceptance and override rates
- Claims accepted on first pass
Common mistakes
- Treating suggestion acceptance as accuracy.
- Leading CDI queries. The Kaiser settlement was about diagnoses added after visits[15].
- 4
Stage 4: Earned autonomy, class by class
Autonomy only where the record supports it.
Months later, class by class; most classes will not qualify in the first year
What to do
- Let a named class run on its own once its approval-without-edit record supports it. Examples: resubmitting claims rejected for a member ID that matches current eligibility; posting clean exceptions under a dollar limit; routine status follow-ups.
- Autonomous coding for one narrow service line, with a pre-bill audit sample.
Why now
Under the False Claims Act, "knowingly" includes reckless disregard, with no proof of intent needed[9]. Autonomy that outruns its evidence is the risk. Vendors now sell autonomous resubmission of denied claims "with minimal human intervention"[39], so this decision may arrive as a setting in a tool you already use.
In place first
- Per-class approval history.
- Compliance sign-off per class.
- Sampling audits and a kill switch per class and per client.
What to measure
- Audit error rate by class
- Payer recoupments and reversals
- Duplicate claims
- Coder audit findings
Common mistakes
- Switching on a vendor's autonomous resubmission for every claim at once.
- Stopping the sample audit once a class has run cleanly for a month.
- 5
Stage 5: The AI-native operating model
Teams built around exceptions and root causes.
Ongoing
What to do
- Organize teams by exception type and payer, not by an alphabet split of patient names.
- Make root-cause owners responsible for cutting each denial family at its source.
- Billing companies: revisit pricing, and tell clients how agents are used on their claims.
Why now
By now the logs show which work agents carry. Staffing, pricing and client terms can follow that evidence.
In place first
- Stages 1 to 4 running with clean logs for at least two quarters.
What to measure
- Cash collected per staff hour
- Cost to collect
- Denial rate trend by root cause
- Days in AR
- Client retention (billing companies)
Common mistakes
- Cutting staff before exception volumes are known.
- Losing payer knowledge when experienced AR callers leave. Put it in the rule library first.
Your first 90 days
Stage 0 across the operation, then Stages 1 and 2 on one slice: one client or one payer group, and one denial family. We do this with design partners.
- Days 1 to 30: see the work
Rank 12 months of denials by reason code, payer and dollars, and find the five that cost most. List every queue and its backlog. Ask each PM, EHR and clearinghouse vendor what its AI changes without a person. Sign BAAs with model providers and ban PHI in public chatbots. Write the role map. Record the baseline: denial, appeal and overturn rates, days in AR, claims past filing limit.
- Days 31 to 60: read-only agents on one slice
Pick one client or payer group and one denial family, such as eligibility and authorization. Agents sort it daily and rank its AR by days left; specialists sort the same denials in parallel for two weeks to compare. Build the payer rule library for the slice.
- Days 61 to 90: drafts with approval
Agents draft corrected claims and appeal packets for the slice; a specialist approves each. Track approval-without-edit rate, time per approval, appeals filed against appealable, and deadlines met. Pick the next slice. Expect no class to have earned autonomy yet.
Don't fully automate
Agents can prepare every one of these: find the record, draft the letter, compute the balance. A named person makes the call, and the log shows who.
How the roles change
Inferred from the work, not from a survey. In each role the agent assembles the worklist, the packet or the posting, and the person keeps the judgment.
Rules that bite revenue cycle work
Across these rules the same requirements recur: a person accountable for what each claim says; access to PHI limited by role and need; records that show who did what, kept for years; clocks that start when someone identifies a problem; and, for patient-facing AI, notice and a way to reach a person. Each one is an operational control you can build.
Billing integrity: what the claim says
- False Claims Act
Liability for anyone who "knowingly presents, or causes to be presented, a false or fraudulent claim". Knowingly includes "reckless disregard", and "no proof of specific intent to defraud is required"[9]. Penalties are $14,308 to $28,619 per claim for penalties assessed after 3 July 2025, plus three times the government's damages[10].
For agents: "Causes to be presented" reaches billing companies and their software, not only providers. A claim agent running at volume without review is the plainest case of reckless disregard, and penalties are per claim.
- Overpayments: report and return within 60 days
An overpayment must be reported and returned within 60 days of being identified, suspended for up to 180 days for a timely, good-faith investigation, with a six-year lookback[11].
For agents: An agent that finds a credit balance or an overbilled pattern can start the clock. The finding goes to a person the same day.
- Medicare filing and appeal deadlines
Claims within one calendar year of the date of service[12]; a redetermination request within 120 days of receiving the initial determination[13].
For agents: Commercial and Medicaid limits come from each contract and state, so they belong in the payer rule library agents rank work from.
To be confirmed: Commercial and Medicaid timely-filing and appeal limits; they vary by contract and state and are not compiled here.
HIPAA: who may see what, and the record of it
- Business associates and subcontractors
A covered entity may let a business associate handle PHI only with "satisfactory assurance" in a written agreement, and the same flows down to subcontractors[18].
For agents: A model provider or agent platform that receives PHI is a subcontractor. Sign the BAA before the first prompt.
- Minimum necessary
Reasonable efforts "to limit protected health information to the minimum necessary"[18], and a list of "those persons or classes of persons" who need access, with the categories of PHI each needs[19].
For agents: A role-and-field access rule, in regulation. An appeal packet carries what that denial needs, not the chart; a posting agent does not see diagnoses.
- Security Rule technical safeguards
Access only for "persons or software programs that have been granted access rights"; audit controls that "record and examine activity"; protection against "improper alteration"; and authentication of each person or entity[20]. Documentation is kept six years[21].
For agents: "Software programs" covers agents: each needs its own identity, access rights and an activity record.
To be confirmed: Whether the proposed Security Rule update published on 6 January 2025 (MFA, asset inventory, encryption) has been finalized.
- Breach notice from a business associate
Notice to the covered entity "without unreasonable delay and in no case later than 60 calendar days after discovery"[22].
For agents: Whether an agent's mistake is a reportable breach is a legal call. The log has to show what was read or sent, and to whom.
Payers, prior authorization and patients
- CMS-0057-F: decision clocks and payer APIs
From 1 January 2026, Medicare Advantage, Medicaid and CHIP plans must decide standard prior authorizations within 7 calendar days and expedited ones within 72 hours, giving a specific denial reason. Prior authorization APIs, which also reach federal marketplace plans, are due by 1 January 2027[3].
- Medicare Advantage medical necessity and algorithms
Decisions must rest on the enrollee's own medical history, physician recommendations and clinical notes[14]. A CMS memo of 6 February 2024 says an algorithm "can be used to assist", but "algorithms or artificial intelligence alone cannot be used as the basis to deny admission or downgrade to an observation stay"[4].
For agents: When a denial looks like a model applied to a group, the appeal can ask for the individual review the rules require.
- WISeR: AI in traditional Medicare prior authorization
From 2026 to 2031, prior authorization for selected services in traditional Medicare in New Jersey, Ohio, Oklahoma, Texas, Arizona and Washington, using "AI and machine learning, along with human clinical review"[5].
- No Surprises Act: good faith estimates and disputes
Uninsured and self-pay patients get a good faith estimate within 1 business day when the service is scheduled at least 3 business days out, or within 3 business days when it is 10 or more days out or on request[23]. A bill at least $400 above the estimate can go to patient-provider dispute resolution[24].
For agents: An agent can draft the estimate and compare the final bill with it; a person sends it and handles disputes.
States
- California SB 1120: physicians decide medical necessity for plans
Health plans and insurers using AI in utilization review must base decisions on the individual's clinical history, and the tool "shall not deny, delay, or modify health care services based, in whole or in part, on medical necessity"; only a licensed physician or qualified professional may[25]. Approved 28 September 2024 with no urgency clause, so in force from 1 January 2025 under California's default rule.
For agents: It binds payers, not providers. On appeal, it is a reason to ask who made a California plan's medical-necessity denial.
- California AB 3030: AI messages to patients
Generative AI messages to patients about clinical information need a disclaimer and a way to reach a person, unless a licensed provider read and reviewed them. "Patient clinical information" excludes "appointment scheduling, billing, or other clerical or business matters"[26].
For agents: Most billing messages fall outside it. A balance explanation that names a diagnosis or treatment may not.
- Texas HB 149 (TRAIGA): disclosure in health care
In force 1 January 2026. Section 552.051(f): where AI is used in relation to health care service or treatment, "the provider of the service or treatment" must disclose it by the date the service is first provided. Subsection (b), which sets the duty, speaks of governmental agencies. Penalties reach $200,000 per uncurable violation, after a 60-day cure period[27].
For agents: If it applies, the provider discloses, and a billing company supports its clients.
To be confirmed: Whether (f) reaches private providers, given how it refers back to (b), and whether back-office billing AI is "in relation to health care service or treatment". Confirm with counsel.
- Texas SB 1188: records kept in the United States
From 1 January 2026, covered entities must keep electronic health records with patient information "physically maintained in the United States", including records held by cloud and third-party facilities. Practitioners who use AI for diagnostic purposes must review AI-created records and tell patients[28].
For agents: Copying Texas patients' records into an offshore tool or a model hosted abroad needs checking first.
To be confirmed: Whether offshore staff working in a US-hosted EHR are affected; the text speaks to physical storage.
- Colorado SB26-189: automated decisions
Signed 14 May 2026. Developer duties start 1 January 2027. Consequential decisions include "financial or lending services", "insurance" and "health-care services". Deployers owe notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, a right to meaningful human review, and records kept three years. The attorney general is to adopt rules by 1 January 2027[29].
For agents: Keep payment-plan, financial-assistance and collections decisions with a person.
To be confirmed: The start date of deployer duties, and whether patient payment-plan, financial assistance or collections decisions made with an agent are covered; the attorney general's rules are pending.
Contracts: binding in practice
- Business associate agreements
One with each client, and a subcontractor agreement with every model and software provider that sees PHI.
For agents: Keep a register of which models are cleared for which data, checked before every model call.
- Payer agreements and portal terms
Provider agreements set filing limits and appeal paths. Portal terms of use may restrict automated access.
For agents: Prefer standard transactions and payer APIs to bots on portals.
To be confirmed: Payer portal terms on automated or agent access; we found no public compilation.
- Client service agreements
Who approves write-offs, refunds and adjustments, any offshore restrictions, and what the client must be told about automation.
For agents: Write each client's limits into rules, so one client's write-off limit never applies to another.
When it goes wrong
Real cases first. Two are not AI failures and two are on the payer side; each still shows a control a billing operation needs.
Change Healthcare ransomware, February 2024
Attackers entered through a remote-access portal without multi-factor authentication, stayed nine days, took about 6 TB and deployed ransomware on 21 February 2024. Data on about 190 million people was taken, claims and payments stalled across the country, and UnitedHealth advanced over $6 billion to providers by mid-April[50].
The control: Controls 14 and 15. The clearinghouse layer is a single point of failure. Agents never hold clearinghouse keys; each connection has sealed credentials and its own kill switch.
Accretive Health, 2011 to 2014
A laptop holding "over 20 million pieces of information related to 23,000 patients" was stolen from an employee's car. The FTC said its user "had data that was not necessary to perform his job"[16]. Minnesota's attorney general settled for $2.5 million in 2012[51].
The control: Control 7. Access by role, field and client; no PHI in prompts, tests or training material.
Kaiser Permanente, $556 million, January 2026
Kaiser affiliates paid $556 million to resolve allegations that they mined patient histories for diagnoses and pressured physicians to add them by addenda after visits, for Medicare Advantage risk adjustment[15].
The control: Controls 1 and 4. This is the shape of a "find missed diagnoses" tool used without limits. Agents may flag a possible gap to a CDI specialist; they never add a diagnosis or send a query.
Cigna PXDX, reported March 2023
A system matched diagnoses to procedures and flagged claims; medical directors signed off denials in batches, over 300,000 in two months, at about 1.2 seconds each[48].
The control: Control 17. Payer-side, but it holds for billing: a click on a batch is not a review. Risky classes are approved one payload at a time, and approval time is measured.
UnitedHealth and nH Predict, filed November 2023
Families of Medicare Advantage patients allege an algorithm cut post-acute care short and that about 90% of appealed denials were reversed. UnitedHealth says the tool "is not used to make coverage determinations"[49]. These are allegations; the current case status is to be confirmed.
The control: Control 11. Payer automation is why appeal capacity matters: every appealable denial gets a deadline watch.
Agent failures to design against (scenarios)
Scenarios A to H are illustrations, not reported events. Each maps to the control points that stop it.
One denial's path through the gate
Here is what the controls look like on one ordinary claim. The agent does most of the work; it is stopped once, and a person approves once.
- 1Arrives
An 835 remittance posts with a CO-197 denial on a knee MRI: authorization absent.
CO means the patient cannot be billed. The money is lost unless someone acts before the appeal deadline.
- 2Allowed
The agent sorts it into the authorization family, notes the payer, the client and the appeal deadline.
Read-only, for the specialist it acts for, on that client only.
- 3Allowed
It finds the authorization number on file, dated before the scan. The payer missed it.
Reads the PM system and the 278 authorization record through the client's connections.
- 4Denied by rule
It tries to attach the whole chart to be safe. The upload is refused.
Control 8: for this reason code the list is the authorization record and the order. The attempt is logged.
- 5Allowed
It drafts the reconsideration on the payer's form with the two allowed documents.
No code, modifier or diagnosis field can change; the draft only adds evidence.
- 6Needs approval
The specialist sees the exact packet, one item at a time, and approves it.
Controls 2 and 17. The record shows who approved, when, and how long she looked.
- 7Allowed
The packet goes to the payer once, through the sealed connection, on her authority.
A timeout retry cannot send it twice. The agent never saw a portal password.
- 8Human queue
No answer in 30 days: a task lands with the specialist, with the deadline beside it.
Control 11. Thirty days is this client's setting, not a payer rule.
The OrchKernel blueprint for a medical billing company
OrchKernel sits between AI agents and the systems a revenue cycle operation connects, as drawn in the missing layer. Agents ask it before they act; it checks the rules, holds what needs a person, and records what happened.
What it is not. OrchKernel is not a PM system, an EHR, a clearinghouse, an encoder or a claim scrubber. Those stay your systems of record, and the controls below sit around them.
The mechanisms
- Approvals
- An action waits for a named person, who sees the exact payload: the corrected claim, the appeal packet, the refund amount. It runs once on approval, so a timeout retry cannot resubmit.
- Rules
- Checked before every action: no writes to code, modifier or diagnosis fields; allowed attachments per denial reason; write-off limits per client; models cleared per data class; trust tiers. Each rule allows, holds or denies, with the reason.
- Acting on a named person's authority
- Each agent works for a named specialist with no more access than that person. When she leaves or loses a client, the agent loses it too.
- Data access by role and field
- Posting and patient-messaging agents never receive diagnosis fields. Each client's systems are separate connections, so an agent on one practice cannot read another's patients.
- Tamper-evident audit log
- Every request, rule result, approval, denial and data read, each entry chained to the one before, so an edited or deleted entry shows. Retention is your setting; HIPAA documentation runs six years.
- Human queue
- Work only a person may do lands with an owner and a due date: a documentation gap for CDI, a payer feed gone quiet, a claim near its filing limit, a suspected incident.
- Connections to your systems
- PM systems and EHR billing modules, the clearinghouse, payer APIs, the document store, email and fax, statement tools, through their APIs or MCP servers. Credentials are sealed, calls go only to allowed hosts, writes are checked against the live record, and each connection has a kill switch and a budget.
Eighteen control points
Where a revenue cycle operation needs a control whatever tools it uses, who owns it, and how OrchKernel enforces it.
What the claim says
What leaves the building: submissions, money and messages
Who sees PHI
Clocks, credentials and evidence
What belongs elsewhere
- Charges, claims and payments stay in the PM system, EHR and clearinghouse. OrchKernel does not scrub claims or replace the encoder.
- Coding accuracy belongs to the coding and audit program. OrchKernel can stop agents changing codes; it cannot tell whether a code is right.
- BAAs, the compliance program and the HIPAA risk analysis are contracts and processes. OrchStack makes no HIPAA or SOC 2 claim for itself.
- MFA and user provisioning live in the identity provider and the EHR. Payer portal terms are yours to check.
- Whether something is a breach or an overpayment is a legal and compliance call. OrchKernel supplies the evidence.
Limits. An agent inside a vendor's product that does not go through OrchKernel follows that vendor's controls, so ask each vendor what its agents change without a person. OrchKernel is source-available under the Business Source License and runs on your own servers, so you can read the code that enforces these controls. If you plan to offer it to client practices as a service of your own, talk to us about licensing first.
Scorecard by stage
Record a baseline in Stage 0 and track the same numbers at each stage. Public figures exist for denial and appeal rates in some payer types, and they differ a lot by payer and setting. For almost every workflow measure there is no public benchmark, and HFMA and MGMA benchmark values are member-only, so compare each stage with your own Stage 0 numbers.
Sources
Last reviewed October 2026. Sources were read in October 2026; dates are publication or data dates.
Primary sources
Statutes, regulations, bill texts, agency data and guidance, settlement announcements and enforcement filings. Federal regulations were read on Cornell's Legal Information Institute because the official eCFR site blocked automated reading.
- 1National Health Expenditure fact sheet. Centers for Medicare & Medicaid Services, 2024 data.
- 2Fiscal year 2024 improper payments fact sheet. Centers for Medicare & Medicaid Services, November 2024.
- 3CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) fact sheet. Centers for Medicare & Medicaid Services, January 2024.
- 4Frequently asked questions related to coverage criteria and utilization management requirements in CMS final rule (CMS-4201-F). Centers for Medicare & Medicaid Services, memo to Medicare Advantage organizations, 6 February 2024.CMS memo; copy hosted by the AHA because the CMS link returned an error
- 5Wasteful and Inappropriate Service Reduction (WISeR) Model. CMS Innovation Center.
- 6Some Medicare Advantage organization denials of prior authorization requests raise concerns about beneficiary access to medically necessary care (OEI-09-18-00260). HHS Office of Inspector General, April 2022.
- 7Compliance Program Guidance for Third-Party Medical Billing Companies (63 FR 70138). HHS Office of Inspector General, 18 December 1998.
- 8Occupational Outlook Handbook: Medical records specialists. US Bureau of Labor Statistics, 2025 data.
- 931 U.S.C. 3729: False claims. Legal Information Institute, Cornell Law School.
- 1028 CFR 85.5: Adjustments to penalties. Legal Information Institute, Cornell Law School.
- 1142 CFR 401.305: Requirements for reporting and returning of overpayments. Legal Information Institute, Cornell Law School.
- 1242 CFR 424.44: Time limits for filing claims. Legal Information Institute, Cornell Law School.
- 1342 CFR 405.942: Time frame for filing a request for a redetermination. Legal Information Institute, Cornell Law School.
- 1442 CFR 422.101: Requirements relating to basic benefits. Legal Information Institute, Cornell Law School.
- 15Kaiser Permanente affiliates pay $556M to resolve False Claims Act allegations. US Department of Justice, 14 January 2026.
- 16In the Matter of Accretive Health, Inc.: complaint. Federal Trade Commission, December 2013; final order February 2014.
- 1745 CFR 162.1601: Health care payment and remittance advice transaction. Legal Information Institute, Cornell Law School.
- 1845 CFR 164.502: Uses and disclosures of protected health information, general rules. Legal Information Institute, Cornell Law School.
- 1945 CFR 164.514: Other requirements relating to uses and disclosures (minimum necessary). Legal Information Institute, Cornell Law School.
- 2045 CFR 164.312: Technical safeguards. Legal Information Institute, Cornell Law School.
- 2145 CFR 164.316: Policies and procedures and documentation requirements. Legal Information Institute, Cornell Law School.
- 2245 CFR 164.410: Notification by a business associate. Legal Information Institute, Cornell Law School.
- 2345 CFR 149.610: Requirements for provision of good faith estimates for uninsured (or self-pay) individuals. Legal Information Institute, Cornell Law School.
- 2445 CFR 149.620: Requirements for the patient-provider dispute resolution process. Legal Information Institute, Cornell Law School.
- 25SB 1120, Health care coverage: utilization review (Chapter 879, Statutes of 2024). California Legislature, approved 28 September 2024.
- 26AB 3030, Health care services: artificial intelligence (Chapter 848, Statutes of 2024). California Legislature, 2024.
- 27HB 149, Texas Responsible Artificial Intelligence Governance Act, enrolled text. Texas Legislature, effective 1 January 2026.
- 28SB 1188, electronic health records and artificial intelligence, enrolled text. Texas Legislature, effective 1 September 2025.
- 29SB26-189, Automated Decision-Making Technology. Colorado General Assembly, signed 14 May 2026.
Industry bodies and independent research
KFF and JAMA are independent. The AHA and AMA are advocacy groups whose figures support a policy position, usually against payer practices, and Premier is a hospital purchasing group. HFMA MAP App, MGMA DataDive and KLAS benchmarks are member-only and were not read.
- 30Claims denials and appeals in ACA Marketplace plans in 2023. KFF, 27 January 2025, updated 24 March 2026.
- 31
- 32Waste in the US health care system: estimated costs and potential for savings. Shrank, Rogstad and Parekh, JAMA, 2019.
- 332025 Index report (formerly the CAQH Index). DataSpring, 2025.Headline read; detail behind a free account was not read
- 34Trend alert: private payers retain profits by refusing or delaying legitimate medical claims. Premier Inc. (hospital purchasing group), 21 March 2024, 2022 claims data.
- 35Costs of caring. American Hospital Association (advocacy), 2026.
- 363 ways AI can improve revenue-cycle management. American Hospital Association Market Scan, 4 June 2024.Reports a 2023 survey sponsored by AKASA with HFMA
- 37Physicians concerned AI increases prior authorization denials. American Medical Association (advocacy), 24 February 2025.
- 38MGMA Stat polls. Medical Group Management Association, 2026.Quick polls, not representative surveys; headlines only
Vendor sources
Published by companies that sell AI or revenue cycle software. Directional, not an industry benchmark.
- 39Waystar launches new agentic solutions across the revenue cycle. Waystar, 26 August 2026.Vendor source
- 40
- 41
- 42
- 43
- 44
- 45
- 46
Company and press
Investigative reporting, a private equity firm's announcement and encyclopedia summaries, used where no primary text was reachable.
- 47New Mountain Capital forms Smarter Technologies. New Mountain Capital, 19 May 2025.
- 48How Cigna saves millions by having its doctors reject claims without reading them. ProPublica, 25 March 2023.
- 49UnitedHealth faces class action lawsuit over algorithmic care denials in Medicare Advantage plans. STAT, 14 November 2023.
- 502024 Change Healthcare ransomware attack. Wikipedia, read October 2026.
- 51R1 RCM. Wikipedia, read October 2026.