Free AI Opportunity Audit

Should My Medical Practice Use AI for Claim Denials and Appeals?

Shyam Verma•
Should My Medical Practice Use AI for Claim Denials and Appeals?

Short answer: Yes for drafting appeal letters, no for most of the rest, and only after two checks. First, sort your last sixty denials: AI drafting helps the pile where the documentation was already in the chart and the payer ignored it, and it hurts the pile where documentation was genuinely missing, because a fluent letter is a well-written way of still not sending the labs. Second, get the business associate agreement in writing before a single claim leaves your office, because HHS treats any vendor handling electronic PHI as a business associate even if it cannot read the data, and at least one tool here sells a $19 a month plan while keeping the BAA on its unpriced enterprise tier. Denial prediction is the weaker half of the pitch: at this size the pattern is usually already visible to your biller, and the fix lives in documentation only a physician can edit. Buy a published subscription rather than commissioning software.

"I use AI to write appeals and it works every time"

Start with the strongest positive report. On r/medicine, where moderators verify flair, a November 2024 thread, Increased denial rate from insurers (mentions AI), drew 121 points and 40 comments. u/cbgeek65, flaired MD, Urology, wrote its second most upvoted comment at 71 points:

I use AI to write appeals and it works every time. The AI knows what the other AI is looking for.

That is the whole case for this category, and it deserves to be taken seriously: an appeal letter is written to a template, for a reader working from a template, which is what language models are good at. Two things it does not say, though. There is no volume, so nothing to price against. And "works every time" is a recollection rather than a tracked overturn rate.

The same thread carries the question this post has to answer. u/WolverineMan016, flaired MD, 9 points:

I thought denials had to come from humans and AI could only be used for approvals or to be handed over to human-review for potential denials.

Nobody in forty comments answered it. There is an answer in some states, below.

"Do spine denials actually repeat by payer, or am I overfitting a pattern?"

u/Secure_Pangolin_901 posted that question on r/CodingandBilling in December 2025, 30 points and 12 comments, describing themselves as not a coder, just the person on a spine practice's admin side who sees the reports:

What keeps jumping out is how often the same denials repeat. Same payer. Same procedure. Same medical necessity language. Charts get fixed for that one appeal, but the next case hits the same issue.

That is the denial-prediction pitch, arrived at independently by someone who has not bought anything. The top reply, u/Kind_Application_144 at 18 points, agrees and then explains why it does not lead where you think:

No you are right on the money. Most of the time we are just "billers or coders" and physicians and other higher ups do not value what we have to say, so the issue never gets fixed and then we have to deal with it and eventually will burn out.

Read that as a product spec. The pattern is already visible to someone already reporting it. Detection is not the constraint. The fix lives in the physician's documentation, and as the same commenter puts it later, no one can make corrections to the patient's chart but the physician. So prediction software buys a better-formatted version of a message nobody is acting on.

Work out whether your last three repeated denials were unseen or ignored. Only one is a software problem.

"I can barely even get eligibility working on my PM"

In September 2025 u/jjxu217 asked r/CodingandBilling what actually worked: Anyone trying AI tools for billing/denials/claims?, 23 comments. Top reply, 7 points, u/EvidenceBasedSwamp:

I can barely even get eligibility working on my PM. Have to use insurer portals still for eligibility, claim tracking, etc etc.

Their EMR is Kareo, and the gaps are with small local insurers the vendor will not fix. Then the part no vendor deck contains:

having to hack out a website, then the 2 factor code, then the password is expired because they make you change them every 90 days... then you have to save the password in your password manager... ughhhhhhh

That is the actual job. Not reasoning about medical necessity. Logging in. An AI layer that reads denials beautifully and still cannot get past a payer portal's ninety-day password rotation has automated the easy half.

u/kuehmary, same thread, on how uneven the ground is:

A lot depends on the payor - like Aetna will accept medical records by fax (so that's automated for a 252 denial) but BCBSIL requires the records to be uploaded using Availity as a reconsideration (so that's is manual).

One payer automates, the next does not, for the same denial reason, so every ROI figure you see averages across payers you do not have. Same shape as document intake at a bookkeeping practice: extraction is the easy half, and the saving depends on where the output lands.

"I'll take things I'd never submit to a tool with out a baa for 1000 Alex"

This decides whether a small practice can legally use most of what is sold to it. In June 2025 u/Informal-Market6871 offered a free claims analytics tool on r/healthIT: Brand New Claims Analysis Tool, Honest Feedback Wanted!, 14 comments. Top reply, u/tripreality00:

I'll take things I'd never submit to a tool with out a baa for 1000 Alex. Also deidentified is funny because there is only two mechanisms to deidentify phi/pii and none of them are done by someone who would probably use this.

u/pescado01 gave the commercial version: without a BAA you are dead in the water for any serious users. The builder's answer is the honest part, and expect a version of it from anyone selling here early:

Full HIPAA-grade security and BAAs are on the roadmap for later, but I'm eager to learn from billing pros on what they'd actually want before investing in enterprise features.

Roadmap is the word to listen for. A BAA is not a feature that ships in a later release, it is the precondition for handing over the first claim. And the second half of u/tripreality00's comment is what practices get wrong: de-identification is a defined standard with two permitted methods, and deleting the obvious columns from a spreadsheet is neither.

The same objection turns up on r/MedicalCoding this month, in The rise of pointless AI and OCR in the medical admin field, from u/bluestrawberry_witch:

Also if she is, or wants y'all, to use publicly available AI and anyone puts patient info- it's a HIPAA violation. Are they investing in a closed system verified HIPAA compliant AI?

Put that to your own staff before it is a question about a vendor.

That question has a published answer for the two assistants your staff already have open, and the answers differ. OpenAI's enterprise privacy page, under the question of whether its API platform can be used with protected health information, says: "We are able to sign Business Associate Agreements (BAA) in support of customers' compliance with the Health Insurance Portability and Accountability Act (HIPAA)", followed by an invitation to reach out if you require one. Read the scope there too: that answer sits under the API platform question, not next to the consumer app, and OpenAI sells a separate workspace called ChatGPT for Healthcare [openai.com]. Anthropic's plan comparison marks "HIPAA-ready offering" as No on Free, Pro, Max 5x and Max 20x, and No on Team as well. It is Yes only on Enterprise, whose plan card lists "HIPAA-ready offering available" [claude.com, both checked 2026-09-16].

Sit with the Team one, because that is exactly the tier a five-physician practice would buy: sized for two to 150 people, $20 a seat a month billed annually or $25 billed monthly, payable by card, and outside the HIPAA-ready column. Check both pages yourself before you sign anything; these tables get revised. The general shape holds across this market: HIPAA coverage lives on the tier priced by conversation, not the tier you can buy with a card.

"This thread is all ads and bots"

Anything you search here is salted, and you should know what the salt looks like. On an August 2025 r/healthIT thread, Prior auth/denials, a clinic using free AI tools to draft appeals in minutes, 12 points and 12 comments, u/GoneWeary:

This thread is all ads and bots

Among the replies: one bare product URL, one founder pitching their own product, one freelancer advertising for work. The bare URL, appealtrackr.com, no longer resolves in DNS as of 2026-09-15.

The clearer case is a March 2026 r/CodingandBilling post, Is it just me, or have the "Technical Denials" become way more aggressive since the 2026 payer updates?, 30 points and 35 comments. It reads like an office manager venting. It also complains about denials on anything not specific enough in its ICD-11 clusters. United States claims do not run on ICD-11. The diagnosis code set in use here is ICD-10-CM, maintained by the National Center for Health Statistics and still current on its page as of July 2026 [cdc.gov]. A working biller does not make that mistake. u/Jodenaje, at 12 points, replying to a comment since deleted at minus nine:

Ah, there it is. I thought something was off when you called it ICD-11 in the original post.

A one-point account in the same thread posts twice and names a denial-tracking product, whose price is in the next section.

What tools actually cost, and who hides the number

Checked on each vendor's own site on 2026-09-15, and reported as the vendor's own description, not an endorsement.

Start with the boring plumbing, because it sets the bar. Claim.MD publishes a clearinghouse price list to the cent: Unlimited at $120.00/month for unlimited claims, unlimited ERA and 1,000 eligibility transactions; Small Volume at $60.00/month for 100 claims, ERA and eligibility, labelled "Perfect for single doctor practices"; Basic at $30.00/month, nothing included, $0.50 per transaction. No setup fee, no per provider fee.

Now the AI layer. ClaimChronicle, the product plugged by that one-point account, does publish: a 14 day trial capped at 10 claims, Solo at $19/mo for 25 claims a month, Professional at $49/mo for unlimited claims, Enterprise at "Custom". Read the FAQ before the price:

We follow HIPAA-aligned security practices. Enterprise plans include a signed Business Associate Agreement (BAA).

HIPAA-aligned is not a defined term. HIPAA-compliant is. And the BAA, which the next section shows is not optional, sits on the one tier with no published number, so the real price of the $19 plan for a practice running actual claims is unknown. Note also that "EMR & Payer integrations" carries a COMING SOON label on the same page, which is exactly the gap u/EvidenceBasedSwamp is living in.

Then the demo wall. Exactrx advertises "96% Criterion-level accuracy" and a "99% First-pass approval rate" with no source and no price; every button is a demo booking [published-by-the-vendor, exactrx.ai]. Counterforce Health is free for individuals and says so plainly, "completely free for individuals" and "We will never accept money from insurance companies", with no pricing page at all. Note that it sells to both sides of the desk on one homepage: the hero is patient-facing, and lower down it pitches practices on "3-5x increase in RCM staff productivity" and "80% lower costs". None of those figures, on either half of the page, carries a source.

This is the pattern the series keeps finding. The company selling transaction plumbing tells you the per-claim rate. The company selling AI tells you an accuracy percentage.

The rules that actually apply

Five, checked against primary sources rather than a summary of them.

The payer's AI is restricted in California, and that is an argument you can use. California SB 1120, Chapter 879, approved by the Governor on 2024-09-28, amends Health and Safety Code section 1367.01 and Insurance Code section 10123.135:

Notwithstanding paragraph (1), the artificial intelligence, algorithm, or other software tool shall not deny, delay, or modify health care services based, in whole or in part, on medical necessity. A determination of medical necessity shall be made only by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues involved

Read the scope before you celebrate. It binds California health care service plans and California-regulated insurers, amends nothing federal, and constrains the payer rather than you. What it gives a California practice is a sentence to quote in an appeal when a denial comes back in seconds.

Texas wrote the blunter version, and it is already in force. SB 815 of the 89th Legislature adds section 4201.156 to the Insurance Code:

A utilization review agent may not use an automated decision system to make, wholly or partly, an adverse determination.

Wholly or partly is the phrase to notice: California's bar is written around medical necessity, Texas's reaches any adverse determination and does not let a payer escape it by putting a human signature on a machine's output. The same section explicitly leaves administrative support and fraud detection alone. The act took effect 2025-09-01 and applies to utilization review for plans delivered, issued for delivery, or renewed on or after 2026-01-01 [capitol.texas.gov]. Other states have moved too, in both directions, and some widely shared bills died in committee. Read your own state's text rather than a roundup of it.

If the plan is an employer plan, a federal floor applies wherever you are. This is the one most small practices never use. The ERISA claims procedure regulation, 29 CFR 2560.503-1, requires a group health plan to give claimants at least 180 days after an adverse benefit determination to appeal it, and to decide urgent claims no later than 72 hours, pre-service claims within 15 days, and post-service claims within 30 days, each extendable once. On appeal it requires review by a fiduciary who is neither the person who made the original decision nor their subordinate, and where the denial turns on medical judgment, that the fiduciary "shall consult with a health care professional who has appropriate training and experience in the field of medicine involved" [ecfr.gov]. Those deadlines do not care which state you practice in, and a denial that came back in four seconds is hard to square with the consultation requirement. Ask in writing who the consulting professional was.

Any AI vendor that touches a claim is a business associate, and no BAA means no PHI. HHS guidance on cloud services closes the loophole vendors reach for:

An entity that maintains ePHI on behalf of a covered entity (or another business associate) is a business associate, even if the entity cannot actually view the ePHI.

The same guidance says the two parties "must enter into a HIPAA-compliant business associate agreement (BAA)" [hhs.gov]. Neither encryption nor an inability to read the data exempts a vendor. If one will not sign, the conversation is over.

De-identification has exactly two legal methods. HHS names them: "the two methods that can be used to satisfy the Privacy Rule's de-identification standard: Expert Determination and Safe Harbor" [hhs.gov]. Deleting the name column is not one, which is u/tripreality00's point.

Where AI is the wrong answer

When the denial is a documentation gap, not a coverage dispute. The most uncomfortable comment came from the other side of the desk. In an April 2026 r/medicine thread of 220 points and 92 comments, u/Pharmacienne123, who adjudicates prior authorizations for a US government employer:

A lot of times if I deny something it is because of lack of documentation. Like these provider's offices don't even try. They will either submit no documentation or something crazy sparse.

Other clinicians there describe the opposite: everything was in the note and the reviewer had plainly not read it. Both are real, and they need opposite responses.

When it is a transport problem. u/SewistDoc46, same thread, on Medicare: in their office it is almost always a fax issue, pages arriving out of order or missing. No model fixes a fax.

When the work is a phone call. u/Noressa, same thread, on a colleague who does prior auths: each call is easily 30 minutes, most closer to 45 to 75. Software does not sit on hold.

When the documents are bad. Not from that thread but from the r/MedicalCoding one above, where u/MisterUniverse1 is the OP, on the document reader their own office runs: it triples the workload, making us triple handle the same documents, and takes twice as long. That is OCR on medical admin paperwork rather than prior-auth review, which is the point. Extraction quality tracks document quality, whatever the document is for.

On a personal ChatGPT, Claude or Gemini account. Consumer tiers carry no BAA, and on Anthropic's published table neither does the small-team tier.

Below a volume that justifies anything. At ten denials a month, the honest answer is a template and an hour of your biller's attention.

What this actually costs

The disclosure first: Ready Bytes has not built a denial or appeals system for a medical practice. We build back-office and document automation for owner-led businesses: the pattern is familiar, the trade is not.

What we would carry over is method, not domain. Extraction plus human approval before anything leaves the building, as in document intake at a bookkeeping practice. Verification against the artifact rather than the system's own report of success, the argument of Never Trust an AI Agent's Done. And the prior that boring follow-up work pays back faster than clever work, where we landed on dental no-shows and recalls.

Our ladder, published because the alternative is the section above:

  • A free AI opportunity audit at /ai-audit: fifteen to twenty questions, about five minutes, no cost. Shyam studies your setup and emails a written audit within two business days.
  • A $500 full audit if that surfaces something: read-only access, your top 3 opportunities ranked by ROI, a 90-day roadmap, and a fixed pilot quote. Credited against the pilot if you proceed.
  • A fixed-quote pilot, typically $3,000 to $8,000 over 2 to 6 weeks, scoped to one specific piece.
  • An ongoing relationship after a pilot has proved itself.

At the volume one to five physicians generate, the likeliest honest outcome is that you commission nothing: a published subscription plus a signed BAA beats a build.

Start here

Pull your last sixty denials and sort them into four piles: documentation missing, documentation present and ignored, claim itself wrong, paperwork never arrived intact. Count each pile.

That count decides everything. Pile one is a charting problem inside your practice. Pile two is where appeal drafting genuinely helps, and it is the only pile a denials AI buys you. Pile three is coding and scrubbing. Pile four is fax, portal and login work, which no model touches.

Then time one appeal end to end: finding the records, logging into the portal, re-keying the outcome. That number, not the drafting time, is what every vendor claim has to beat.

And before any tool sees a claim, ask for the BAA in writing and which plan it comes with. If the answer is the enterprise plan, the price you were quoted is not your price.


Shyam Verma founded Ready Bytes in 2009 and has been building software since 2005. He writes about back-office automation, legacy modernization and applied AI at readybytes.in/blog.

Shyam Verma

Shyam Verma

Full Stack Developer & Founder

Shyam Verma is a seasoned full stack developer and the founder of Ready Bytes Software Labs. With over 13 years of experience in software development, he specializes in building scalable web applications using modern technologies like React, Next.js, Node.js, and cloud platforms. His passion for technology extends beyond coding—he's committed to sharing knowledge through blog posts, mentoring junior developers, and contributing to open-source projects.

Comments