A HIPAA-Compliant Revenue Cycle Command Center, Built Solo
A regional medical-billing company was sitting on a firehose of claim data it could not operate on. We turned their raw EHR exports into a HIPAA-compliant command center — AR aging, denial analytics, and a priority work queue behind enterprise single sign-on — and delivered the initial scope in roughly a third of the projected hours.
Client (anonymized): a Tennessee-based medical billing company managing accounts receivable for multiple healthcare facilities. Engagement: data platform and operational tooling, ongoing. Vertical: healthcare revenue cycle management. No client name, no protected health information, and no identifying figures appear on this page.
The problem
The client's billing operation ran on nightly exports from their EHR (eClinicalWorks). The data was all there — claims, balances, payer mix, aging — but it lived in a database nobody could operate from. There was no shared view of what was owed, by whom, aging into which bucket; no way to see which denials were clustering or which accounts were worth working first; and no defensible audit trail over data that is, by definition, protected health information. Staff prioritized AR by intuition and spreadsheets. A regulated business was flying on feel.
What we built
A production web application — a revenue cycle command center — on top of the existing data estate:
- AR aging and analytics. Total and per-facility receivables by aging bucket and payer responsibility, built from the latest clean snapshot so nothing double-counts.
- Denial analysis. Denial concentration surfaced by category, so preventable losses stop hiding inside an aggregate.
- Claim-level workflow. Every claim carries persistent status, notes, and history that survive a full EHR reload — a stable claim identity that is not tied to a row that gets truncated and rebuilt nightly.
- A priority work queue. Standing, role-agnostic queues that rank the highest-value accounts to work first, instead of whatever is on top of the pile.
- Multi-facility consolidation. As the engagement grew, a second facility's aged AR was folded into the same platform as its own client view, without disturbing the first.
All of it behind enterprise single sign-on (Microsoft Entra ID) with enforced multi-factor authentication and role-based access — administrators, account managers, and AR staff each see exactly what their role allows — and a HIPAA control layer: every screen and API that touches PHI writes to an access audit log, all API responses are set no-store, no PHI ever lands in test data or logs, and every subprocessor in this system's data path is covered by a business associate agreement.
How — and why it matters
This was delivered by one principal consultant, not a team, using an AI-leveraged development practice to move at a pace a traditional shop cannot match. That is the differentiator, and it is not a gimmick: the same leverage that made delivery fast also made it disciplined — dev-before-prod on every change, a test suite gating every ship, and a live security test that verifies every PHI response carries a no-store header before it reaches a browser.
Production-grade software, in a regulated vertical, at startup speed.
Results
- Original scope delivered in roughly a third of the estimated hours — and the client redirected the freed budget into a substantially larger build rather than pocketing it.
- A core AR view's load time cut from about 20 seconds to about 5 seconds through a two-phase read design — the difference between a tool people avoid and one they live in.
- A complete PHI audit trail across every data surface, with role-based access enforced through enterprise SSO and MFA — the compliance posture a billing company needs to survive a review.
- One operational picture across multiple facilities, with the highest-value accounts ranked to the top of the queue.
The engagement model
The relationship started as a fixed scope and, once trust was established, moved to an ongoing, request-driven cadence — the client emails what they need, it ships to production, and the week's work rolls into one invoice. No change orders, no estimate-and-wait. That is what an embedded, AI-leveraged operator can offer that a staffing firm cannot.
Production credibility where money, technology, and healthcare intersect. If your billing data is in the same shape this client's was, the RCM Data Healthcheck is the two-to-three-week, fixed-fee way to find out what is recoverable — and its fee credits toward Managed AI Operations if you continue.
A 30-minute call to see whether your billing data is hiding the same recoverable AR and preventable denials.
Book a 30-minute intro call