Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Orthopedics
    August 12, 2026
    29 min read

    AI Agents for Orthopedic PracticesSurgery, DME and Work Comp

    An implementation guide, not a pitch. Where the unautomated admin time in an orthopedic practice actually sits, what a certified EHR API will and will not let an agent do, and a phased build plan with owners, exit criteria and rollbacks.

    AI agent automation for orthopedic practice operations, surgical scheduling and workers' compensation workflows in 2026
    40 / week
    Prior authorizations per physician, per week
    AMA 2025 Prior Authorization Physician Survey (n=1,000), released May 2026
    13 hours
    Physician and staff time spent on prior authorization each week
    AMA 2025 Prior Authorization Physician Survey, released May 2026
    Read-only
    Scope of certified EHR API access under 45 CFR 170.315(g)(10)
    ONC/ASTP Certification Companion Guide, updated May 15, 2026
    Jan 1, 2027
    Ambulatory Specialty Model start; orthopedic surgery is in the low back pain cohort
    CY2026 PFS final rule, 90 FR 49266; 42 CFR 512.710(d)(2) at 90 FR 49578

    Key Takeaways

    • Certified EHR API access under 45 CFR 170.315(g)(10) is read-only. Every write an agent performs — booking a block, posting a charge, filing a note — is vendor-discretionary, a robot typing into a user interface, or a human. Get the answer in writing before you buy.
    • The unautomated administrative time in orthopedics sits in pre-op clearance coordination, DME documentation and the workers' compensation and personal injury rails — none of which the standard X12 transaction set reaches, and all of which the commercial-payer automation market ignores.
    • An agent may draft, assemble, chase and flag. It may never attest. CMS Program Integrity Manual Chapter 3, section 3.3.2.4 explicitly requires practitioner concurrence for AI-captured record entries, and 42 CFR 410.26(a)(1) leaves no 'incident to' pathway for AI-performed professional work.
    • WISeR is live and reaches orthopedics: arthroscopic knee lavage and debridement, epidural steroid injections, percutaneous vertebral augmentation and cervical fusion, in the office setting as well as the ASC. Its NPI-level exemption program began in July 2026 and is worth engineering for.
    • The Ambulatory Specialty Model makes low back pain episode performance mandatory for orthopedic surgery from January 1, 2027, at a 20-episode eligibility threshold, scored partly on meaningful use of certified EHR technology. The counting starts before the model does.
    • We refuse every AI accuracy, containment and auto-approval figure in this market, because all of them are vendor-published and no independent benchmark exists. Score vendors on ownership, named integrations, security posture, pricing transparency and conflicts instead.

    Three Revenue Systems in One Building

    Most automation proposals arrive at an orthopedic practice priced off its commercial payer mix. That is the first mistake, and it is expensive, because a meaningful share of orthopedic volume is not health insurance at all. Workers' compensation and personal injury have different authorization mechanics, different documentation obligations — causation, apportionment, work restrictions, return-to-work status — different payment timelines, and, critically, no eligibility API and often no electronic remittance. Automation built on the assumption of standard X12 270/271/278/835 transactions simply does not reach that revenue.

    So before anyone demos anything, sort your practice into its actual rails. Ours is a three-way split, and the third one is where the unautomated hours live.

    RailWhat it runs onAutomation reality
    Commercial and Medicare fee-for-serviceX12 270/271 eligibility, 278 authorization, 837 claim, 835 remittance; certified EHR read APILargely standardized. This is the part the software market already serves.
    Workers' compensationState-specified authorization forms, claims administrators, state fee schedules, utilization review timelinesNo eligibility API, no in/out-of-network, no deductible, frequently no electronic remittance.
    Personal injury / third-party liabilityAttorney correspondence, liens and letters of protection, PIP or MedPay where the state has itPayment deferred to settlement — sometimes years. Not an accounts-receivable process in the usual sense.

    The scheduling picture is equally two-headed. An orthopedic practice reconciles a high-volume clinic — post-op checks, injections, new injury evaluations — against operating room block time that is allocated by a hospital or ambulatory surgery centre, is use-it-or-lose-it, and is booked well ahead. A cast and DME room and an in-office imaging suite are separate constrained resources on top of that. The clinic calendar and the OR calendar have different owners, different granularity and different consequences for failure, and the software that manages one usually has no visibility into the other.

    The framing that survives contact with reality:the question is not “which AI platform should we buy.” It is “which of our three rails is the agent touching, what can it actually commit on that rail, and who signs.” A vendor who cannot answer that in the first meeting is selling to the wrong specialty.

    One piece of evidence about physician time is worth citing here precisely because of how carefully it has to be cited. Sinsky and colleagues, publishing in the Annals of Internal Medicine in December 2016, found that for every hour of direct clinical face time, physicians spent nearly two additional hours on EHR and desk work. Orthopedics was one of the four specialties observed. The limits matter as much as the number: 57 physicians, 430 observed hours, four states, with 21 physicians self-reporting after-hours diaries showing one to two hours nightly, and the authors state the data came from “self-selected, high-performing practices and may not be generalizable.” It is a 2016 study. We cite it because it is real, and we date it because it is old — which is more than can be said for most numbers in this market.

    The Write-Path Constraint: Certified Access Is Read-Only

    This is the single most important architectural fact in practice automation, and almost no vendor deck contains it. The ONC/ASTP certification criterion at 45 CFR 170.315(g)(10) — the one behind every “we integrate with your EHR” claim — requires read services only. From the Certification Companion Guide, last updated May 15, 2026:

    The § 170.315(g)(10) certification criterion requires Health IT Modules to support API-enabled “read” services for single and multiple patients. … These services specifically exclude “write” capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.

    ONC/ASTP Certification Companion Guide, § 170.315(g)(10), updated May 15, 2026

    Read that again with a surgical scheduler in mind. An agent can be guaranteed to read demographics, problems, medications, allergies, results, notes and coverage, to search, and to export in bulk. Everything else — booking the block, writing the note, filing the document, updating the insurance record, placing the order, posting the payment — is not covered by certification. It exists only if your EHR vendor chose to build it and chose to let your automation vendor use it.

    ActionWhat it runs onWhat that means for you
    Read the chart (demographics, problems, meds, results, notes, coverage)Certified API, 45 CFR 170.315(g)(10)Guaranteed in any certified EHR. No vendor negotiation required.
    Bulk export a population for episode or recall analysisCertified API, FHIR Bulk Data AccessGuaranteed. This is how episode counting for the Ambulatory Specialty Model gets built.
    Book or reschedule a surgical block; post a charge; file a note; update coverageVendor-discretionary write API, RPA on the user interface, or a humanNot covered by certification. Exists only if your EHR vendor built it and lets your vendor use it.
    Submit a workers' compensation authorization requestOutside the health-IT rail entirelyState forms and a claims administrator. No standardized transaction exists to automate against.
    Send a records package to a plaintiff attorneyOutside the health-IT rail entirelyA release-governed disclosure. Human review of scope and authorization is mandatory.

    Do not overstate the constraint either. Some EHR vendors voluntarily publish write-capable FHIR endpoints; Epic's developer documentation, for example, documents create support on resources including DocumentReference, Observation, QuestionnaireResponse, AllergyIntolerance, Condition, Communication and BodyStructure, and update support on a smaller set. The honest characterisation is that the documented write surface is narrow and resource-specific — it is not a general ability to modify the clinical record. And Epic is a health-system EHR; a three-surgeon independent practice generally cannot buy it at all, so for most readers this is a question about athenahealth, eClinicalWorks, NextGen, ModMed or a specialty orthopedic system rather than about Epic.

    The exact question to send your EHR representative

    Copy this into an email and require a written answer before you sign an automation contract: “Which FHIR resources can a third-party application create or update in my instance? Is that through a certified API or a proprietary one? What does it cost? Does it require your approval per vendor? And if the answer is ‘no write API’, is the proposed integration performing UI automation under a named user's credentials?”

    The last clause is the one that matters most and the one vendors answer least clearly. If the write happens by a robot typing into the interface on a staff member's login, then your EHR audit log will attribute the agent's actions to that human being. That is a compliance problem before it is a technical one — 45 CFR 164.312(a)(2)(i) makes unique user identification a requiredimplementation specification, not an addressable one, and 45 CFR 164.312(a)(1) already frames access rights as attaching to “persons or software programs.” The rule contemplated software as an access principal decades ago. Give your agent its own identity.

    Is this changing? On the federal agenda, yes; in today's rules, no. ASTP/ONC published a proposed rule on December 29, 2025 signalling an intent to move beyond read-only interactions in future API requirements and proposing to remove the “third party seeking modification use” condition from the information-blocking Infeasibility exception. It remains a proposed rule; the comment period ran into late February 2026 and we located no final rule as of August 12, 2026. Write access is on the agenda. It is not a right today, and no procurement decision should assume it will be one by the time your build ships.

    The design consequence, stated once: a read-only guarantee means an agent can always decide and draft. It cannot always commit. Every workflow in this article is architected around that sentence, and it is also — usefully — the strongest available security control. An agent that cannot write cannot be manipulated into writing.

    Surgical Scheduling and Pre-Op Clearance

    Booking a case is not one task. It is the reconciliation of a facility block, an implant or vendor representative, a prior authorization, and a set of medical and cardiac clearances that live in other practices' charts. The scheduler's real job is chasing the fourth item, and it is chased across fax machines, portals and phone calls that belong to organisations you do not control and cannot integrate with.

    That makes pre-op clearance the highest-yield first agent in an orthopedic practice, for a reason that has nothing to do with how clever the model is: the entire coordination layer is computable from data the chart already holds, and none of it requires a write.Which cases are booked, on what dates, needing which clearances, from which consultants, requested when, received or not — that is a join across the surgical calendar and the document inbox. It is exactly the shape of problem a read-only agent is good at. How many staff hours it consumes across practices is not something we could source to any published measurement — capture it in your own Phase 0 baseline rather than accepting anyone's figure for it.

    Step in the clearance loopWho owns itWhy
    Which cases have an outstanding clearance, from whom, and for how longAgent, aloneRead-only computation over the chart and the surgical calendar. No clinical judgement involved.
    Draft and address the clearance request packet to the consulting practiceAgent drafts, human sendsThe packet is a disclosure. A human confirms recipient, scope and authorization before transmission.
    Escalate a clearance that has aged past the practice's thresholdAgent, alone (notification only)Notification to a named human is not a clinical action.
    Decide whether a returned clearance is adequate for this patient and this procedureSurgeon onlyClinical judgement with safety consequence. Never delegated to software.
    Confirm the case is cleared and release it to the blockHuman commitThe commit is the irreversible action. It carries the surgeon's judgement, so it carries a human's identity.

    Note where the line falls. The agent may compute, draft, notify and escalate. It may not decide that a returned clearance is adequate, and it may not release the case. The reason is statutory rather than stylistic: 42 CFR 410.26(a)(1) defines auxiliary personnel as “any individualwho is acting under the supervision of a physician,” who has not been excluded from federal health care programs and who “meets any applicable requirements to provide incident to services, including licensure, imposed by the State.” Software is not an individual, cannot be excluded by the OIG and cannot hold state licensure. There is no “incident to” pathway for AI-performed professional work. Whatever the agent does is either an administrative task requiring no licensure, or a task whose professional component was performed by a named licensed human.

    The second surgical-side agent worth building is a global-period guard. Orthopedic E/M denials cluster around a distinction CMS states plainly in the Medicare Claims Processing Manual, Chapter 12: “If evaluation and management services occur on the day of surgery, the physician bills using modifier ‘-57,’ not ‘-25.’ The ‘-57’ modifier is not used with minor surgeries because the global period for minor surgeries does not include the day prior to the surgery.” That single distinction generates a large share of orthopedic E/M denials, and it is deterministic — which makes it a rule engine, not a language model, and you should insist that your vendor implement it as one.

    ScenarioCorrect constructSource note
    E/M on the day of or day before major surgeryModifier -57 (decision for surgery)CMS Chapter 12 is explicit: 'If evaluation and management services occur on the day of surgery, the physician bills using modifier -57, not -25.'
    E/M on the day of a minor surgeryModifier -57 does not applyThe global period for minor surgeries does not include the day prior to the surgery, so -57 is not used.
    Split surgical and post-operative care between physicians-54 (surgical care only) and -55 (post-op management only)Same procedure code, same date of service, reported by each physician with the relevant modifier.
    Complication requiring a return to the operating roomCode the procedure actually performed on the return tripNot the original procedure code.
    Non-surgeon manages an underlying condition during the post-op periodPlain E/M, no modifierCMS gives the cardiologist managing an underlying condition as the worked example.
    Build note: anything deterministic should be deterministic. Modifier selection rules, global-period arithmetic, threshold accumulation and date math do not need a generative model, and putting one there adds an unreviewable failure mode to a problem that had none. Reserve the model for the genuinely unstructured parts — reading an inbound clearance letter, drafting a narrative, summarising a payer policy — and keep it behind a human commit point.

    DME Dispensing and Its Documentation Burden

    In-office dispensing — braces, boots, slings, bone stimulators — looks like retail and bills like a supplier relationship. That mismatch is where the money leaks. The payable artifact is not really the claim line; it is the documentation package behind it, and the package is assembled by whoever happened to be in the cast room.

    The regulation is clear on one point and deliberately silent on several others. 42 CFR 424.57 defines a DMEPOS supplier to include a physician or Part A provider that sells or rents Part B covered items, and conditions payment on having a DMEPOS supplier number — but that requirement “does not apply to items furnished incident to a physician's service.” That carve-out is the reason many orthopedic practices dispense without a separate supplier enrollment.

    What we will not tell you:whether your particular practice qualifies for the statutory accreditation exemption available to physicians and certain practitioners, or what surety-bond position applies to you. We could not verify either to a primary source, so we will not print a bond amount and we will not print a blanket “physicians are exempt from accreditation.” Check your own enrollment status with your MAC before you build any workflow that assumes an answer. A vendor who states your exemption confidently without seeing your enrollment record is guessing with your money.

    What an agent can do here is narrow, unglamorous and worth real money: completeness checking before the item leaves the room.For each dispensed item, does the record hold the order, the medical-necessity documentation the payer's policy actually names, the delivery evidence, the patient acknowledgement, and the correct linkage to the encounter and the diagnosis? Every one of those is a read-only question. The agent computes the gap list and hands it to the person standing in the cast room while the patient is still there — which is the only moment at which a gap is cheap to close.

    1. 1.Pre-dispense gap check: Against the specific payer's published documentation requirements for that HCPCS item, not against a generic checklist. The rule set is versioned content with a named owner, re-verified quarterly.
    2. 2.Delivery evidence capture: The agent can prompt for it, timestamp it and file it into the work queue. Whether it can file it into the chart depends entirely on your write path — see the previous section.
    3. 3.Post-dispense reconciliation: Items dispensed against items billed against items with complete documentation. Three lists that should be identical and rarely are. Surfacing the difference weekly is a read-only report and a genuine revenue finding.
    4. 4.Denial pattern feedback: When a DME denial reason code enters your top five, the gap check that should have caught it is either missing or stale. Treat every new denial code as a defect report against the rule set.

    What the agent must not do is decide medical necessity, or assert it. Necessity is a clinical determination that a licensed clinician attests to, and an attestation is the one act that no configuration permits software to perform. The agent surfaces whether the documentation supporting the clinician's determination is present. It does not form the determination.

    Workers' Compensation and Personal Injury

    Here is the part of an orthopedic practice that nobody's software models, and the one rail with no standardized transaction to automate against at all. Workers' compensation is a parallel payment universe: no explanation of benefits or coordination of benefits as commercial billing understands them, no in-network or out-of-network distinction, no deductible or out-of-pocket maximum, and rates set by state fee schedules rather than a single national schedule. Billing errors in this rail can carry regulatory consequences rather than merely a denial.

    California is the most concretely documented example we can offer, and it illustrates the shape of the problem everywhere. Treatment requires a request for authorization submitted to the claims administrator, and Labor Code section 4610(i)(1) requires the utilization review determination “within five normal business days from the receipt of a request for authorization … but in no event more than 14 days from the date of the medical treatment recommendation by the physician.” Revised Division of Workers' Compensation utilization-review regulations are reported to have taken effect April 1, 2026, replacing references to the specific DWC form with a general “request for authorization” and requiring an incomplete request to be accepted or returned marked “not complete,” with reasons, within five business days.

    Verify this one yourself before relying on it. We could not parse the California DWC regulation text directly and the April 1, 2026 effective date rests on utilization-review industry summaries rather than on the rulemaking record. If you are a California practice building a workflow around that date, confirm it against the DWC rulemaking page first. Every other state has its own forms, its own clocks and its own fee schedule, and none of them is a variant of the others.

    So what is automatable? The clock and the packet — never the submission decision and never the clinical opinion. Obtaining a workers' compensation authorization is a document exchange with a claims administrator on state-specified forms and timelines, with no interoperable rail to build against. An agent can assemble the packet from the chart against the treatment guideline the state applies, prove and log transmission, watch the statutory clock, and escalate when a determination is overdue. A human signs and sends. That is not a compromise; it is the correct design, because the request carries a physician's treatment recommendation and the timelines attach to that recommendation.

    Personal injury is a third rail again, and its automation is inventory rather than transaction. Payment runs through third-party liability, personal injury protection or medical payments coverage where the state has it, and liens or letters of protection where payment waits on settlement — which can be years. The useful agent here is an aging and obligation tracker: which cases have an executed lien or letter of protection on file, which attorney has which records request outstanding and for how long, which balances sit against an unsettled matter, and which documentation obligations remain open.

    Three things the agent must never touch on a comp or PI case

    • Causation and apportionment opinions. These are physician attestations with legal consequence in an adversarial proceeding. There is no drafting assistance that is safe here, because a draft in the record is discoverable.
    • Work restrictions and return-to-work status. Same reasoning, plus a direct safety consequence for the patient and a direct financial consequence for the employer and the carrier.
    • Records releases to attorneys, carriers or claims administrators. A release is a disclosure governed by authorization scope. A human confirms recipient, scope and authorization every single time, and the agent's role stops at assembling a candidate package for that human to review.
    The partition rule. Comp and PI accounts should be excluded from every payer-rail automation by construction, not by a rule that a configuration change could switch off. If a comp account can appear in an eligibility queue or a commercial claim scrubber at all, you have built a defect that will eventually produce a wrong-rail submission — which in this universe is a compliance event, not a rework.

    Prior Authorization, WISeR and the 2027 Specialty Model

    Orthopedic prior authorization runs on two fronts: imaging, frequently through a delegated radiology-benefit or musculoskeletal-benefit manager rather than the plan itself, and the procedure. The burden numbers most worth citing are the ones physicians reported themselves. The AMA 2025 Prior Authorization Physician Survey, a nationwide survey of 1,000 practising physicians fielded in December 2025 and released in May 2026, reports 40 prior authorizations per physician per week, 13 hours of physician and staff time weekly, and 40 percent of practices with staff working exclusively on prior authorization. Ninety-four percent say it increases burnout and 74 percent say denials have increased over five years. It is a self-reported physician survey and should be attributed as one — but it is a physicians' association surveying practising physicians and publishing its methodology, not a vendor measuring its own product.

    One finding from that survey deserves to sit at the centre of any vendor conversation: 60 percent of physicians are concerned that AI is increasing, or will increase, prior authorization denial rates — while the entire vendor category sells AI as the cure. Both things can be true simultaneously, and a buyer should hold both.

    Now the specifically orthopedic development. The CMS WISeR model was implemented January 1, 2026 and runs six performance years through December 31, 2031. It introduces machine-assisted review into Original Medicare in six states, each with a named participant company, and its selected service categories reach straight into orthopedic and spine practice.

    StateMAC jurisdictionWISeR participant
    TexasJH / NovitasCohere Health, Inc.
    OklahomaJH / NovitasHumata Health, Inc.
    New JerseyJL / NovitasGenzeon Corporation
    OhioJ15 / CGS Administrators, LLCInnovaccer Inc.
    ArizonaJF / NoridianZyter Inc.
    WashingtonJF / NoridianVirtix Health LLC

    The service categories listed in the CMS WISeR Provider and Supplier Operational Guide version 7.0, dated July 24, 2026, include arthroscopic lavage and debridement for the osteoarthritic knee, epidural steroid injections for pain management, percutaneous vertebral augmentation, cervical fusion under local coverage determinations L39741, L39758 and L39793, and several nerve-stimulator categories. The sites of service include the office at POS 11 and the ambulatory surgery centre at POS 24, so this is not a hospital-only programme. Four decision types exist — provisional affirmation, non-affirmation, provisional partial affirmation and dismissal — with resubmission and peer-to-peer review available.

    The trap in the guide: not submitting a prior authorization request does not avoid review. Claims for these services submitted without a request are routed to the WISeR participant for pre-payment medical review instead. The programme is functionally mandatory in those six states. And the service list moves — seven versions of the guide in nine months, with codes added, removed and delayed. Any article, including this one, that publishes a static code list will be stale within a quarter. Link the guide and re-check it.

    There is a real exemption programme attached, and it is worth engineering for. Section 5 of the guide states that beginning July 2026, CMS and the WISeR participants automatically exempt providers and suppliers from prior authorization and pre-payment review on demonstrated compliance, on two stated requirements: submit at least ten prior authorization requests across WISeR select items and services during an assessment period, and achieve a minimum affirmation rate threshold. Exemptions are granted at the individual NPI level, not to the facility or organisation; they are added quarterly, held for at least a year, and removal requires at least 60 days' notice before the next quarter. CMS does not publish the affirmation threshold — each participant sets and publicly posts its own. So any specific percentage you are quoted is either that participant's own posted criterion, which you should read at the source, or a confusion with the Texas commercial gold-card standard, which is a different programme entirely.

    WISeR is politically unstable and legally operative, and both halves of that sentence matter. The Government Accountability Office concluded on May 12, 2026 that the model meets the Administrative Procedure Act definition of a rule, which triggered expedited Congressional Review Act procedures; the Senate rejected the resolution of disapproval in late July 2026; and a House appropriations amendment that would bar CMS from funding the model passed committee in June 2026 and, as far as we can establish, has not been enacted. Do not plan on it disappearing, and do not describe it as cancelled.

    A conflict worth knowing before you shortlist software: Cohere Health and Humata Health, both marketed as prior-authorization AI companies, are the entities reviewing Medicare prior authorization requests in Texas and Oklahoma under WISeR.Optum's Digital Auth Complete, live since January 2026, is powered by Humata Health. None of this is illegal and the arrangements are publicly disclosed. It is simply a conflict a practice should know about before buying prior-auth software from the company adjudicating its Medicare requests, and we have not seen it disclosed in a single vendor comparison article.

    Two more calibrations. First, on how electronic “electronic prior authorization” actually is: the 2025 CAQH Index, published by DataSpring (formerly CAQH) and released February 19, 2026, puts electronic prior authorization adoption at 40 percent, up from 31 percent in the 2023 Index, built on data from more than 600 provider organisations and health plans representing 63 percent of insured lives. The corollary is the useful half — roughly 60 percent of prior authorizations are still not fully electronic in 2026. Disclose what that benchmark is: as of January 2026 the publishing organisation is for-profit and owned by health-plan-affiliated shareholders. It is an industry benchmark, not an independent one.

    Second, the most quotable primary-source reality check available: CMS's own AI-assisted prior authorization model publishes fax cover-sheet instructions in a document dated July 2026. The guide directs that when submitting by fax, the prior authorization form goes on the page immediately after the cover sheet. Every one of the six participants publishes a fax number or a portal URL; none publishes an X12 278 or FHIR endpoint in the guide. Any claim that prior authorization became broadly automatable in 2026 collides with that document.

    And a negative finding that belongs in every procurement conversation: we could not find a single payer that publicly states it accepts prior authorizations submitted by an autonomous AI agent, nor any payer policy that explicitly permits it. A payer accepting a FHIR transaction is not the same as a payer accepting an agent-authored submission; the standard is silent on who or what composed the payload. Nobody has blessed the agent.

    The 2027 item that changes orthopedic economics: the Ambulatory Specialty Model

    Finalised in the CY2026 Physician Fee Schedule final rule at 90 FR 49266, with the specialty list at 42 CFR 512.710(d)(2), the Ambulatory Specialty Model is a mandatory CMS Innovation Center model running five performance years from January 1, 2027 through December 31, 2031, targeting heart failure and low back pain. The low back pain cohort is defined by clinicians whose plurality Part B specialty code is anesthesiology, interventional pain management, neurosurgery, orthopedic surgery, pain management, or physical medicine and rehabilitation. Eligibility attaches at 20 or more attributed episodes from the relevant episode-based cost measure in the eligibility year. It carries two-sided risk, with adjustments applied to future Part B payments out of an incentive pool, and CMS explicitly declined to use a MIPS-style performance threshold.

    One correction to make in advance, because it is already circulating wrongly: the ±9 percent figures in the rule text describe MIPS, not the Ambulatory Specialty Model. Do not attribute them to ASM.

    The reason this belongs in an automation article is the fourth scoring domain. ASM scores on quality, cost, care coordination and meaningful use of certified EHR technology. That is where an interoperability and agent story legitimately attaches for orthopedics — and the episode counting that determines whether you cross the 20-episode threshold is a bulk-export-and-compute problem you can start solving today, on read-only access, before the model begins.

    The Human-in-the-Loop Boundary Table

    Every implementation needs this table written down before the first line of code, because the boundary is where the liability sits and because “human in the loop” used as a slogan is worse than useless. Federal law draws its sharpest line not between AI and not-AI, but between administrative data movement and clinical recommendation. 21 U.S.C. 360j(o)(1)(A) excludes from the device definition software intended for “administrative support of a health care facility, including the processing and maintenance of financial records, claims or billing information, appointment schedules, business analytics … practice and inventory management … [and] determination of health benefit eligibility.” That is a statutory exclusion, not FDA grace, and almost everything in this article lives inside it.

    Decision or actionWho may take itWhy
    Assemble a prior authorization packet from the chart against published payer criteriaAgent aloneAdministrative data movement. 21 U.S.C. 360j(o)(1)(A) excludes administrative support of a health care facility from the device definition by statute.
    Compute outstanding pre-op clearances, DME documentation gaps and global-period conflictsAgent aloneComputation over data the chart already holds. Read-only, reversible, no clinical output.
    Draft a note, a letter, an appeal narrative or a request for authorizationAgent drafts, clinician commitsCMS Program Integrity Manual Ch. 3 §3.3.2.4 requires practitioner concurrence on AI-captured entries. The signature is the commit.
    Suggest a code, a modifier or a documentation element before submissionAgent suggests, biller reviews, clinician attestsCoding suggestion is administrative; the medical-necessity attestation behind the claim is not.
    Send an outbound automated call or text to a patientAgent acts only inside a verified consent recordFCC 24-17 brings AI voices under the TCPA. 47 U.S.C. 227(b)(3) makes each call a separate violation at $500, trebled to $1,500 if willful.
    Answer a patient question about clinical status or symptomsClinician, or clinician-reviewed with disclosureCalifornia Health & Safety Code 1339.75 requires a GenAI disclaimer and human-contact instructions unless a licensed human read it first.
    Determine causation, apportionment, work restrictions or return-to-work statusPhysician only — never automatedThese are physician attestations with legal consequence in a workers' compensation or liability proceeding.
    Sign or attest to a record entry, a plan of care, or a medical-necessity certificationNever — no configuration permits itCMS PIM Ch. 3 §3.3.2.4; reviewers must not consider an attestation from anyone other than the author of the entry.
    Perform work billed 'incident to' a physician serviceNever42 CFR 410.26(a)(1) defines auxiliary personnel as an individual meeting state licensure. Software is not an individual.
    Issue a specific diagnostic or treatment directive to a clinicianDo not build itFDA's 2026 CDS guidance: a specific directive output fails Criterion 3. Enforcement discretion is a revocable posture, not an exclusion.

    Two entries deserve expansion. The first is attestation. The Medicare Program Integrity Manual, Chapter 3, section 3.3.2.4 — revision 13008, effective January 17, 2025 — names AI directly: the treating practitioner's signature “indicates that the physician/NPP affirms the note adequately documents the care provided,” and CMS notes that “this type of practitioner concurrence is also required when using Artificial Intelligence (AI) technology to capture the transcription of medical record entries.” The same section forbids reviewers from considering an attestation from anyone other than the author of the entry, forbids attestations where no associated record entry exists, and states that an attestation cannot be used to backdate a plan of care. There is no configuration in which an agent attests.

    The second is the recommendation boundary. FDA's Clinical Decision Support Software guidance was issued January 29, 2026, superseding a January 6, 2026 version which itself replaced the September 2022 guidance. It is widely misdescribed. FDA did not reclassify single-output software as non-device: software providing a specific preventive, diagnostic or treatment output or directive still fails Criterion 3. What FDA announced is an enforcement discretion policyover that failure where only one option is clinically appropriate and the function otherwise meets the statutory criteria. Enforcement discretion is revocable without notice-and-comment; a statutory exclusion is not. Write it as discretion, and never write that FDA “approved” or “cleared” anything here.

    FDA also moved automation bias into the Criterion 4 analysis. At its March 11, 2026 town hall, FDA stated that in determining whether a function meets Criterion 4 it considers both the level of automation and the time-critical nature of the clinician's decision-making, because “in situations that require urgent action, automation bias increases because there is not sufficient time for the user to adequately consider other information.” Read that as a consideration rather than a test — in FDA's own examples a time-critical workflow becomes a device when paired with a specific directive output. The defensible design conclusion is analytical: the more autonomous and the more time-pressured the workflow, the harder it is to claim the clinician is independently reviewing. In an orthopedic practice, almost nothing needs to be both.

    One live duty that is routinely missed. 45 CFR 92.210, “Nondiscrimination in the use of patient care decision support tools,” appears in the current CFR and imposes an ongoing duty to make reasonable efforts to identify tools using input variables that measure race, colour, national origin, sex, age or disability, and to mitigate the resulting discrimination risk. It applies whether or not the tool is AI and whether or not FDA calls it a device. Compliance is reported to have been required from May 1, 2025. If you are deploying anything that touches patient care decisions, that inventory is a deliverable, not an afterthought.

    The Sequenced Implementation Path

    This is the section the article exists for. Each phase has an owner, an entry criterion, an exit criterion and a defined response when it fails. Phases overlap deliberately — Phase 4 can start while Phase 3 is measuring — but no phase starts before its entry criterion is met, and no phase is declared done on a demo.

    Phase · timingWhat gets builtOwnerEntry / exit criteria
    0 · Weeks 1–2Baseline and inventoryPractice administrator + discovery leadEntry: named executive sponsor and an agreed budget band. Exit: a written baseline of eight metrics and a signed data map.
    1 · Weeks 3–4Write-path determinationIT lead / EHR administratorEntry: signed baseline. Exit: a written answer from the EHR vendor on which FHIR resources a third party may create or update, at what cost, under whose credentials.
    2 · Weeks 5–9Agent one — pre-op clearance tracker (read-only, draft-only)Surgical scheduler as process ownerEntry: write-path answer plus an executed BAA chain. Exit: 30 consecutive business days where the agent's outstanding-clearance list matches a human audit on a 20-case sample with zero misses.
    3 · Weeks 10–14Agent two — DME documentation completeness and global-period pre-bill checksBilling managerEntry: Phase 2 exit met. Exit: flag precision measured on 200 consecutive claims, and a measured move in one named denial reason code against the Phase 0 baseline.
    4 · Weeks 12–18Agent three — workers' comp and personal injury document railWorkers' comp coordinator + counselEntry: a complete inventory of the state forms and claims administrators you actually deal with. Exit: packet assembled and transmission proven with a logged artifact; a human signs and sends every time.
    5 · Weeks 16–24Agent four — patient communication under TCPA and consent controlsFront-office manager + counselEntry: consent inventory and revocation handling built and tested. Exit: every outbound automated contact traceable to a consent record, revocation honoured within 10 business days.
    6 · Ongoing, quarterlyRe-verification and drift controlPractice administratorEntry: any agent in production. Exit: none — this phase does not end. Re-check payer policies, the WISeR service list, vendor corporate status and your own metrics every quarter.

    Phase 0 — Baseline and inventory (weeks 1–2)

    You cannot improve what you have not measured, and every vendor benchmark you will be shown is somebody else's denominator. Before anything is bought, capture eight numbers from your own systems: interval from surgical decision to booked date; number of cases currently held for outstanding clearance and their ages; DME items dispensed versus DME items billed versus DME items with complete documentation, for the last 90 days; your top five denial reason codes by dollar and by count; workers' compensation authorization request turnaround, from recommendation to determination; personal-injury balances by age band; total inbound call volume, answered, abandoned and after-hours from your own carrier call detail records; and staff hours per week spent on prior authorization.

    If a phase fails: if you cannot produce those numbers in two weeks, stop. Do not proceed to procurement. The inability to measure the baseline is itself the finding, and the first engagement is a data-visibility project rather than an agent project. A practice that automates without a baseline cannot later distinguish a working agent from a seasonal fluctuation, and will renew a contract it should have cancelled.

    Phase 1 — Write-path determination (weeks 3–4)

    Send the email from the write-path section to your EHR representative and hold the project until a written answer arrives. In parallel, execute the business-associate chain: the application vendor, the model provider and the model provider's cloud host are all business associates or subcontractor business associates under 45 CFR 160.103, and a single BAA with the application vendor does not close the chain. Ask specifically for terms that satisfy 45 CFR 164.502(a)(3), which prohibits a business associate from using PHI in a manner the covered entity could not — the clause a “we train on your data” term collides with.

    If a phase fails: no written answer within ten business days means you assume read-only and re-scope the build so that every commit is human. That is not a downgrade. Read-and-draft agents with human commit points are where the defensible value is, and a build that assumed write access it never received is a rewrite, not a delay.

    Phase 2 — Pre-op clearance tracker (weeks 5–9)

    First agent, chosen because it is high-value, entirely read-only and structurally unable to harm a patient. It maintains the outstanding-clearance list, generates request packets for human review and transmission, escalates on a clock, and produces a daily reconciled view against the surgical calendar. It commits nothing.

    Exit criterion, stated precisely:30 consecutive business days in which the agent's outstanding-clearance list matches a human audit of a 20-case sample with zero missed items. Not “the team likes it.” If the agent misses one item, the 30 days restart. The strictness is deliberate — this is the phase where the practice learns whether the underlying data is good enough to build the rest on.

    If a phase fails: a repeated miss is almost never a model problem. It is a data problem — a clearance filed as an unindexed scan, a consultant whose faxes arrive without a patient identifier, a case type nobody documented. Fix the intake, not the prompt.

    Phase 3 — DME documentation and global-period pre-bill checks (weeks 10–14)

    Second agent, first revenue-facing one. Deterministic rules for the -57 versus -25 distinction, global-period conflicts and DME documentation completeness, running before submission rather than after denial.

    Exit criterion: flag precision measured over 200 consecutive claims — what proportion of flags a human biller agrees with — and a measured movement in one named denial reason code against the Phase 0 baseline. Precision matters more than recall here: an agent that flags everything trains staff to ignore it within a fortnight.

    If a phase fails: low precision means the rule set encodes a payer policy that is either stale or was never right. Freeze the rule, re-verify against the published policy, and version the rule set with a named owner. If precision cannot be brought above the level at which billers act on flags, retire the rule rather than tolerating it.

    Phase 4 — Workers' comp and PI document rail (weeks 12–18)

    Third agent, and the one with no standardized transaction to automate against at all. Entry requires a complete inventory of the state forms, claims administrators and treatment guidelines you actually deal with — not a generic template. The agent assembles the request packet, proves transmission with a logged artifact, watches the statutory clock, and escalates an overdue determination to a named human.

    Exit criterion: for 40 consecutive requests, the packet the agent assembled was accepted by the reviewing human without material addition, and every transmission has a retrievable proof artifact. A human signs and sends every one of the 40. Auto-submission is not a later phase; it is not a phase at all.

    If a phase fails: if packets need material human addition more than occasionally, the state guideline mapping is wrong or the chart lacks the elements the guideline requires. Both are fixable. Neither is fixed by a better model.

    Phase 5 — Patient communication under TCPA and consent controls (weeks 16–24)

    Last, not first, because it carries the sharpest statutory exposure in the whole build. The FCC's Declaratory Ruling FCC 24-17, released February 8, 2024, confirms that the TCPA's restrictions on artificial or prerecorded voice encompass current AI technologies resembling human voices, including voice cloning. Under 47 U.S.C. 227(b)(3) the private right of action provides actual damages or $500 per violation, whichever is greater, trebled to $1,500 for willful or knowing violations, with no cap and no injury requirement — and each call and each text is a separate violation. Do the arithmetic before the demo, not after the campaign.

    The carve-outs are narrower than most practices assume. A health care message to a wireless number from a covered entity or business associate needs prior express consent — it is relieved of the written requirement, not exempt. Health care messages to residential landlines are exempt from consent but capped at one call per day and three per week per patient, with opt-outs honoured. Anything that introduces an advertisement or constitutes telemarketing needs prior express written consent regardless of who is calling — which is exactly where a reactivation or service-line campaign lands. Caller-identity disclosure at the start of an artificial or prerecorded message has always been required under 47 U.S.C. 227(d)(3) and 47 CFR 64.1200(b). A general federal duty to announce that a caller is AI is proposed and is not law; the FCC's notice of proposed rulemaking in CG Docket 23-362 was adopted August 7, 2024 and had not been finalised as of August 12, 2026.

    On revocation, what is in effect now: any reasonable method of revocation must be accepted, “STOP,” “QUIT,” “END,” “REVOKE,” “OPT OUT,” “CANCEL” and “UNSUBSCRIBE” are per se reasonable, and revocation must be honoured within 10 business days. The broader “revoke-all” provision — one revocation killing all automated contact from that caller — was extended by the FCC's Consumer and Governmental Affairs Bureau on January 6, 2026 to January 31, 2027. Build for it now anyway; you will not want to re-architect consent under a deadline.

    Exit criterion: 100 percent of outbound automated contacts traceable to a consent record, revocation honoured within 10 business days on test cases, caller identity disclosed at the start of every artificial-voice message, and reminders and marketing in physically separate consent pools with separate kill switches.

    If a phase fails: any traceability gap stops the outbound programme entirely until it is closed. There is no partial credit on a per-violation statute.

    Phase 6 — Quarterly re-verification (ongoing)

    The WISeR service list changed seven times in nine months. Payer policies move. Vendors get acquired, renamed and withdrawn. Quarterly, a named person re-checks: the WISeR select items list against the current guide version; your top five denial codes against your rule set; each vendor's corporate status, ownership and support responsiveness; your BAA chain against any new subprocessor; and your own eight baseline metrics against the ones you captured in Phase 0. This phase has no exit criterion because it does not end.

    What Breaks First, and How You Roll Back

    Failure in these systems is rarely dramatic. It is silent: the agent keeps producing confident output while quietly doing the wrong thing, and nobody notices for a billing cycle. So every failure mode below is paired with a detection signal — something observable in a dashboard or a log without anyone having to suspect a problem first — and a rollback that a non-engineer can execute.

    Failure modeDetection signalRollback
    RPA breaks after an EHR or payer portal interface changeCompleted agent tasks drop more than 20 percent day over day; the exception queue grows without a matching volume changeKill switch to manual queue; hold the work rather than letting it silently fail; invoke the vendor's mean-time-to-repair commitment
    The agent acts under a staff member's credentials, so the audit trail names a humanAudit log shows a named employee acting outside working hours or at inhuman ratesSuspend the service account immediately; re-provision a unique agent identity per 45 CFR 164.312(a)(2)(i) before resuming
    A clearance goes stale between the original booking and a rescheduled surgical dateClearance date precedes the current surgery date by more than the practice's policy windowHard rule: a stale clearance never auto-clears a case; the case returns to the surgeon's queue
    A workers' compensation patient is routed through commercial-payer logicAny comp or PI account appearing in an eligibility or claim-scrub queue at allHard partition at the account level; comp and PI accounts are excluded from every payer-rail automation by construction, not by rule
    Prompt injection through an inbound fax, referral PDF or portal messageAgent output contains instructions, recipients or fields with no counterpart in the source document; unusual tool-call patternsFax-triggered paths carry no side-effecting tools; revert to read-and-draft only; preserve the artifact and reconstruct from the audit log
    Payer policy changes and the scrubber keeps enforcing a stale ruleA new denial reason code enters your top five within a billing cycleFreeze the affected rule, re-verify against the payer's published policy, and treat the rule set as versioned content with an owner
    An outbound campaign crosses from reminder into marketingAny automated message containing service-line promotion or an offerSeparate consent pools with separate kill switches; marketing requires prior express written consent and must never share a pool with reminders
    The vendor's corporate status changes under youAcquisition, rename, product withdrawal, or a support contact who stops answeringQuarterly vendor re-verification; contractual data export in a documented format; never let a single vendor hold the only copy of your workflow logic

    The first row is the one to plan for, because it is the most likely and the least discussed. Where a vendor cannot get an API write, the write happens by robotic process automation — a robot typing into the EHR's user interface. RPA breaks on interface changes, is usually invisible in the EHR audit log as a system action, and attributes actions to whatever human's credentials it runs under. Ask any vendor how many payer portals and EHR screens it maintains automation against, and what its mean time to repair is after an interface change. No vendor publishes this. Getting a number in a contract is the point of asking.

    Portal automation carries three risks a practice can evaluate without a legal opinion. Credential risk: a scraping vendor generally operates under your staff's portal login, so the audit trail says your employee did it — ask directly whether it runs on a named human's credentials. Unilateral termination risk: the payer or EHR can cut access without breaching anything, and your workflow breaks with no notice and no remedy; there is documented precedent of platform owners terminating third-party data access unilaterally. Fragility: a portal redesign breaks the bot. We found no FTC action, court ruling or regulatory guidance specifically addressing AI agents scraping payer portals, so anyone who tells you the legality is settled in either direction is wrong.

    Prompt injection: reduce the blast radius, do not claim to have solved it

    An orthopedic practice's inbound channels are dense with untrusted text: referral faxes, imaging reports from outside facilities, clearance letters, attorney correspondence, claims-administrator responses. Any agent reading them is reading instructions it did not author.

    The peer-reviewed evidence is unambiguous about susceptibility and honest about its own limits. Lee and colleagues, in JAMA Network Open in December 2025, ran a controlled simulation across 12 clinical scenarios and reported that across 216 evaluations, attacks achieved 94.4 percent success at turn four and persisted in 69.4 percent of follow-ups, with extremely high-harm scenarios succeeding in 91.7 percent of dialogues. The caveats belong in the same breath: it is a simulation rather than field data, the main experiment used lightweight models with a five-dialogue proof-of-concept on flagship models, and three co-authors disclose company roles. Clusmann and colleagues, in Nature Communications in February 2025, ran 594 attacks against four vision-language models and found all susceptible, with sub-visual prompts embedded in imaging data that were “non-obvious to human observers.”

    That last phrase is the one that breaks the standard mitigation story: a human in the loop who cannot see the injection cannot review it away. We could locate no published study of prompt injection through referral faxes, portal messages or payer portals in a live practice — the absence of evidence is itself the reportable fact, and extrapolating from dialogue and imaging studies to your fax line is reasoning, not a finding.

    What actually helps is architectural, because it does not depend on detecting the attack: least privilege at the API boundary; read-only by default, which is free and is the strongest control available; the human signature as the only path from draft to record; unique agent identity and audit controls under 45 CFR 164.312(a)(2)(i) and (b) so a successful injection is reconstructable afterwards; and out-of-band confirmation for anything irreversible. What does not help is any vendor claim of an injection “detection” or “guardrail” accuracy rate. No independent benchmark for clinical prompt-injection defence exists, and every figure we encountered came from a party selling the defence.

    The Numbers We Refuse to Print

    In the medical-practice AI market, almost every circulating operational statistic was published by a company selling software to the specialty it describes. Our house rule is that when we cannot find a non-seller source, we say so in the article. Naming the absence is more useful to an operator than repeating the number, and it is the only way a reader can tell the difference between our figures and a brochure's.

    The claimWhat it actually traces toOur verdict
    "$200 per no-show" and "$150 billion a year in missed appointments"Both trace to a single 2017 byline by a scheduling vendor's chief medical officer. No published methodology.Refuse. Measure your own no-show cost from your own schedule and fee schedule.
    Any phone abandonment benchmark ("7% abandonment", "85% never call back", "42% of calls missed")Every instance traces to a vendor blog, a dead attribution, or a report that does not exist under the name cited.Refuse. Pull 60–90 days of your own carrier call detail records before signing anything.
    "86% of claim denials are potentially avoidable" (and its 85%, 87%, "nearly 90%" mutations)Change Healthcare 2020 Denials Index: a vendor analysis of 102 million hospital transactions, July 2019–June 2020. The original report is no longer retrievable and the population was hospitals, not practices.Refuse. Six years stale, wrong population, vendor-published, primary artifact gone.
    MGMA claim-rework figures ("$25–$118 per rework", "50–65% never reworked")Chased to origin in prior research and found unsupportable.Refuse.
    Any AI accuracy, containment, resolution or auto-approval rateEvery figure in this market is vendor-published. No independent benchmark exists for agent platforms, prior-auth automation, voice agents or ambient scribes.Refuse as a neutral number. Quote it only as "what this vendor chose to claim," attributed.
    "AI saves clinicians N hours per week"Every instance encountered was vendor-published or vendor-funded.Refuse. Measure your own before-and-after on your own data.
    "$258 billion avoided" (2025 CAQH Index headline)A modeled opportunity estimate, not observed savings.Use only if labelled as the publisher's model. The 40 percent electronic prior authorization figure from the same report is fine.
    "95% of GenAI pilots fail", "85% of AI projects fail", "87% never reach production"Permanently banned in our house style; none survives sourcing.Refuse.

    The general form of the problem deserves stating explicitly, because it governs how you should read every ranked list of AI vendors you encounter, including ours: there is no independent benchmark for accuracy in any of these categories. Not for agent platforms, not for prior-authorization automation, not for voice agents, not for ambient scribes. Every accuracy, containment, resolution and auto-approval figure in the market is vendor-published, none discloses a denominator, a payer mix or a service line, and the terms are not even comparable to each other — “containment,” “resolution,” “answer rate” and “routine interactions” are four different denominators, none defined publicly. Score vendors on things that can be checked: ownership and corporate stability from public record, named and verifiable EHR integrations, published security posture, whether a BAA is offered in writing, pricing transparency, and conflicts of interest. Those are all verifiable. Accuracy is not.

    What we will use, and why. The AMA prior authorization figures, because the AMA surveyed 1,000 practising physicians nationwide and published the methodology. The WISeR facts, because they come from a CMS operational guide with a version number and a date. The certified-API read-only constraint, because it is quoted verbatim from ONC/ASTP. The prompt-injection studies, because they are peer-reviewed and we can name their limitations. The Sinsky time study, because it is real, and we date it every time because it is from 2016. That is the whole list. Everything else in this article is either a regulation we quoted or reasoning we labelled as reasoning.

    Vendor Red Flags for an Orthopedic Buyer

    These are not stylistic objections. Each one is a question whose answer materially changes what you are buying, and each has produced a real failure in this market.

    1. 1."We write back into your EHR" without naming the mechanism: Certified API access is read-only. So a vendor claiming write-back is either in a private commercial integration programme with that specific EHR, running a bot on a human's login, or not actually writing. Make them say which, in the contract.
    2. 2.An accuracy, containment or auto-approval percentage on the pricing page: Every one is self-published with no denominator and no third party. Its presence tells you what the vendor thinks you will not check. Ask for the denominator, the payer mix and the service line; the answer is more informative than the number.
    3. 3."HIPAA-compliant AI" presented as a property of the product: HIPAA attaches duties to covered entities and business associates, never to software. There is no OCR guidance defining a compliant AI product. Rewrite the claim in your own head as "used under a BAA with these specific controls" and then ask to see the BAA and the controls.
    4. 4.No SOC 2 Type II report or BAA offered before the demo: Across the vendor research behind this cluster, not one vendor in the prior-auth and RCM category publicly stated on its own site that it offers a BAA, and SOC 2 Type II status was rarely published. That makes it a question you must ask in writing, and a reasonable vendor answers it in a day.
    5. 5.The vendor is on the other side of your table: Cohere Health and Humata Health adjudicate Medicare prior authorizations under WISeR in Texas and Oklahoma while selling prior-auth AI, and Optum's Digital Auth Complete is powered by Humata. Availity, the free provider portal, is part-owned by payer organisations. None of this is improper; all of it is a disclosure you should have before signing.
    6. 6.A static list of WISeR codes, or any "prior auth is solved in 2026" claim: The WISeR guide reached version 7.0 in nine months and still prints fax cover-sheet instructions. A vendor whose material has not been updated against the current guide version is telling you how often it re-checks its own facts.
    7. 7.No named EHR integrations, only logos: In our vendor research, exactly one company in the prior-auth and RCM category published a fully verifiable named-integration list. Logos are not integrations. Ask for the customer reference on your specific EHR, at your specific version.
    8. 8.A single point of failure with no export path: The February 2024 Change Healthcare cyberattack affected 192.7 million individuals — the largest healthcare breach in US history — and took down claims processing for practices that had no second rail. Ask what happens to your workflow when this vendor is offline for three weeks, and require a documented data-export format in the contract.
    9. 9.Pricing that will not be stated: Across sixteen prior-auth and RCM vendors researched, zero published a price other than one clearinghouse's free tier for sponsoring payers, and across seventeen patient-communication vendors exactly one published a starting price. That is the category norm rather than a scandal — but it means every third-party "2026 pricing" page you find was written by a competitor or an affiliate, and none of it is reliable.
    10. 10."Your EHR can't do this" — check first: In 2026 the EHR vendors moved into the agent layer themselves. Before buying a third-party platform, ask your own EHR vendor what agentic capability ships natively, on what timeline, and at what price. The honest buying question is no longer "which agent platform" but "what does my EHR already ship, and what is genuinely left over."
    One negative you should never accept from us or anyone else:“Vendor X has no BAA” or “Vendor X has no SOC 2.” The only defensible statement is “we could not find a published statement on Vendor X's site as of this date.” Trust centres get missed, badges do not render to automated fetchers, and an absolute compliance negative about a named company is both unfair and usually wrong. Ask the vendor. Get it in writing. That is the whole procedure.

    Cost, Timeline and Payback

    These are Frenchy Digital's published ranges for healthcare automation work. They are the same across this cluster, and they are ranges rather than a price because the honest answer depends on your write path, your payer mix and how much of your revenue sits on the workers' compensation and personal-injury rails.

    EngagementRangeTimeline
    Discovery + workflow audit$9,000 – $22,0002–4 weeks
    Single-workflow agent (clearance tracking, DME documentation, authorization packet assembly)$28,000 – $70,0004–9 weeks
    Multi-workflow platform with EHR / practice-management integration$70,000 – $180,0009–16 weeks
    Enterprise / multi-site / regulated build (audit logging, human-in-the-loop, SOC 2 posture)$180,000 – $420,000+14–24 weeks

    Senior-led engineering runs $150–$225 per hour; ongoing retainers run $2,500–$9,500 per month; every build carries a 30-day post-launch warranty; and full source-code and IP ownership transfer to the client. We send a written, fixed-price, phased proposal within 5 business days of the discovery call. Frenchy Digital is a senior-led Black-owned Los Angeles agency; you can reach us at +1 (424) 272-5601 or book directly at calendly.com/frenchydigital/discovery-call.

    On payback, we will not hand you a multiplier, because every ROI figure in this market is modelled by the party selling the software. What we will do is tell you the arithmetic to run on your own Phase 0 baseline. The AMA's figure of 13 hours of physician and staff time per week on prior authorization is a starting point for the burden, but the number that matters is yours, at your loaded labour cost. Add to it the dollars sitting in your top denial codes that trace to documentation gaps rather than clinical disagreement, and the balances aging on comp and PI cases whose obligations nobody is tracking. That figure, minus the run-rate cost of the agent and the human review time it still requires, is your payback. If your vendor computes it for you from their own benchmark instead of your data, you are reading a brochure.

    Start With the Baseline, Not the Software

    A discovery call with Frenchy Digital maps your surgical, DME and workers' compensation workflows against what a certified EHR API can actually do — and produces a written, fixed-price phased proposal within 5 business days.

    What We Could Not Verify

    Every article should carry this section and almost none do. These are the specific things we went looking for and did not establish to our own standard. Where we could not verify something, we left it out of the body or hedged it explicitly — and where a fact matters to your build, this is your list of things to check before you rely on it.

    • DMEPOS accreditation and surety-bond position for physician practices: The supplier-number carve-out for items furnished incident to a physician's service is confirmed in 42 CFR 424.57. Whether a given orthopedic practice qualifies for the statutory accreditation exemption, and what bond position applies, is not. We print no bond amount and no blanket exemption claim.
    • The California DWC utilization-review regulation effective date: The April 1, 2026 date rests on utilization-review industry summaries rather than the DWC rulemaking record, which we could not parse. Verify it directly before building a California-specific workflow around it.
    • Workers' compensation as a general proposition: No single primary document establishes the general characterisation of workers' comp as a parallel payment universe; it is synthesised from state agency fee-schedule material and specialty billing sources. The California statutory citation is specific; the general framing is not.
    • Exact Medicare payment amounts for any code named here: We did not fetch the Physician Fee Schedule Addendum B, so we print no Medicare dollar figures anywhere in this article.
    • The WISeR affirmation-rate threshold: CMS does not publish it; each participant sets and posts its own. Any specific percentage you are quoted for WISeR exemption is either a participant's own posted criterion or a confusion with the Texas commercial gold-card standard.
    • Whether the House appropriations rider against WISeR was enacted: It passed committee in June 2026. We found no evidence of enactment and therefore do not describe WISeR as defunded.
    • Any vendor's SOC 2 Type II status, HITRUST certification or published BAA offer: Across the vendor research behind this cluster, these were rarely published on vendors' own sites. We treat that as a buying instruction — ask in writing — not as a finding about any named company.
    • Any vendor price: Effectively none is published in these categories. Every third-party pricing page we examined was written by a competitor or an affiliate.
    • State gold-carding statute citations outside Texas: Several states are named in secondary coverage as having gold-carding laws. We could not verify the citations or effective dates, so we name none of them here. Reporting also suggests state gold-card programmes have delivered limited relief in practice — do not model savings on one.
    • The effective-date reading of Colorado's SB 26-189: Our source materials conflict. The enrolled bill's own effective-date section places the substantive duties at January 1, 2027, applying to consequential decisions made on or after that date, with narrow rulemaking provisions effective on passage. A separate reading placed part of the act earlier in 2026. We follow the enrolled text and flag the disagreement rather than resolving it for you.
    • State AI-in-utilization-review statutes: A growing number of states have legislated on payer use of automated decision systems in medical-necessity determinations. We could not verify individual bill numbers or effective dates, and bill numbering in the secondary coverage we found is itself unreliable. We name no bill we did not read.
    • Prompt injection through faxes, referral PDFs or payer portals in a live practice: No published study exists that we could locate. Our reasoning about those channels is extrapolation from dialogue and imaging research and is labelled as such in the text.

    A last note on the regulatory backdrop, because it moves. The HIPAA Security Rule notice of proposed rulemaking published January 6, 2025 is still only proposed, with final action projected for July 2027 on the Unified Agenda — so the 2003 Security Rule as amended in 2013 governs your practice today, and encryption at rest remains addressable rather than required. Do not let a vendor tell you that multi-factor authentication, asset inventory or encryption at rest are currently mandated by that rule; they are proposals. Separately, CMS-0057-F binds payers rather than practices: decision timeframes, specific denial reasons and public prior-authorization metrics are live now for covered payers, and the FHIR prior authorization API is a January 1, 2027 obligation on the payer side. Your practice benefits from that API only if your EHR or vendor builds a client against it — payer readiness is not practice capability.

    The zero-click clinic, honestly defined. It is not an unstaffed practice and should never be sold as one. It is a practice where the default administrative path completes without a human click, and humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal and safety decision. In orthopedics that means the clearance chase, the DME documentation package and the comp authorization clock run themselves — and the surgeon still clears the case, the clinician still signs the note, and a named human still sends the packet. Anything sold as more autonomous than that is either misdescribing the regulation or misdescribing the product.

    Map Your Orthopedic Admin Load in One Call

    Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned Los Angeles agency. We will map your surgical, DME and workers' comp workflows and send a written, fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1ONC/ASTP Certification Companion Guide — 45 CFR 170.315(g)(10), updated May 15, 2026
    2. 2CMS WISeR Model Provider and Supplier Operational Guide, v7.0 (July 24, 2026)
    3. 3CY2026 Physician Fee Schedule final rule — Ambulatory Specialty Model, 90 FR 49266
    4. 4Medicare Claims Processing Manual, Chapter 12 — global surgery, modifiers -54/-55/-57
    5. 5Medicare Program Integrity Manual, Chapter 3 §3.3.2.4 — signature and attestation requirements
    6. 642 CFR 424.57 — DMEPOS supplier standards and the incident-to carve-out
    7. 742 CFR 410.26 — auxiliary personnel and 'incident to' services
    8. 821 U.S.C. 360j(o) — software functions excluded from the device definition
    9. 9FDA, Clinical Decision Support Software — final guidance issued January 29, 2026
    10. 10FDA CDS final guidance town hall transcript, March 11, 2026
    11. 1145 CFR 164.312 — HIPAA Security Rule technical safeguards
    12. 1245 CFR 160.103 — definition of business associate, including subcontractors
    13. 1345 CFR 92.210 — nondiscrimination in the use of patient care decision support tools
    14. 1442 CFR 422.122 — Medicare Advantage prior authorization requirements (CMS-0057-F)
    15. 15AMA 2025 Prior Authorization Physician Survey (released May 2026)
    16. 162025 CAQH Index, published by DataSpring (formerly CAQH), released February 19, 2026
    17. 17FCC Declaratory Ruling FCC 24-17 — AI voices under the TCPA (February 8, 2024)
    18. 1847 CFR 64.1200 — TCPA implementing rules, health care message provisions
    19. 19Lee RW et al., Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice, JAMA Netw Open. 2025;8(12):e2549963
    20. 20Clusmann J et al., Prompt injection attacks on vision language models in oncology, Nat Commun. 2025;16(1):1239
    21. 21Sinsky C et al., Allocation of Physician Time in Ambulatory Practice, Ann Intern Med. 2016;165(11):753-760
    22. 22ASTP/ONC HTI-5 proposed rule — deregulatory actions, published December 29, 2025
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital, a senior-led Black-owned Los Angeles agency building HIPAA-conscious AI automation for medical practices, surgical groups and healthcare operators.