Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Physical Therapy & Rehab
    August 12, 2026
    33 min read

    AI Agents for Physical TherapyClinics in 2026

    A physical therapy episode is a course of visits, not a booking — so the economics are about completion, not capture. This is the implementation guide: the three clocks every visit draws against, a ranked look at prior-authorization and RCM platforms scored only on what is verifiable, and the boundary where a human has to stay.

    AI agents supporting an outpatient physical therapy clinic in 2026 — plan-of-care certification tracking, authorization block management and threshold monitoring
    $2,480
    CY2026 KX modifier threshold — PT and SLP combined; claims above it without KX are denied
    Reported: APTA payment thresholds page, citing Medicare Claims Processing Manual Ch. 5 §10.3.2
    30 days
    Window after the first day of treatment for a timely initial plan-of-care certification
    Medicare Benefit Policy Manual Ch. 15 §220.1.3
    40%
    Prior authorizations fully electronic — meaning roughly 60% still are not
    2025 CAQH Index, published by DataSpring (formerly CAQH), released 2026-02-19
    $28k–$70k
    Single-workflow agent build (clock watcher, certification packet, authorization tracking)
    Frenchy Digital scoping bands, 2026

    Key Takeaways

    • A PT visit is a draw against three depleting clocks — the 90-day certification, the payer's authorized visit block, and the annual KX dollar threshold. Each expires independently, and nothing in the clinical workflow announces it. Watching those three counters is the highest-yield automation in the specialty and it needs only read access.
    • The reported 2025 certification exception changed what gets paid: proof that the plan of care was transmitted to the referring provider within 30 days of the initial evaluation. Proof of transmission is now the payable artifact, and producing and retaining that proof is a document-rail problem, not an API problem.
    • The KX modifier is a provider attestation. An agent may compute the accumulation and assemble the justification; it may never assert the attestation. CMS requires practitioner concurrence even for AI-captured record entries, and the model attestation statement is first-person and personally liable.
    • The most expensive mistake in this category is buying a payer-side tool. Cohere Health, Anterior and basys.ai sell to health plans, not practices — and Cohere is the CMS WISeR participant adjudicating Medicare prior authorizations in Texas while selling prior-authorization AI.
    • No independent benchmark exists for prior-auth or RCM automation accuracy. Every accuracy, auto-approval and ROI figure in the market is vendor-published with no disclosed denominator. We rank on ownership, named integrations, pricing transparency and conflicts instead — and we say why.
    • Certified API access under §170.315(g)(10) is read-only. Every EHR write your agent performs is a commercial arrangement with your EHR vendor, not a certification right. Scope the write path in week one, in writing.

    A PT Episode Is a Course of Visits, Not a Booking

    Almost every piece of automation marketing aimed at outpatient rehab is built on a model borrowed from primary care: a patient books, a patient attends, a claim goes out, the money arrives. Fill more slots, lose fewer of them, and the practice does better. That model is wrong for physical therapy in a way that changes which software is worth buying.

    A plan of care is a standing series — typically two to three visits a week for four to twelve weeks against a specific therapist, often in overlapping treatment slots where one therapist runs two or three patients at once. A cancellation does not cost you one visit. It costs a slot in a series, and it pushes the certification clock. The revenue event is not the booking. It is the completed episode, billed cleanly, inside three separate windows that expire independently of each other.

    The thing outsiders get wrong. They treat a PT visit like a doctor visit — an independent transaction. It is not. Each visit is a draw against three depleting authorizations that expire on different clocks: the 90-day certification, the payer's authorized visit block, and the annual dollar threshold. A perfectly documented visit is unpaid if any one of the three has lapsed — and nothing in the clinical workflow tells the therapist that it has.

    That is the whole opportunity, and it is unglamorous. The highest-yield thing an agent can do in an outpatient rehab clinic is not write notes, answer the phone or fill the schedule. It is to watch three counters that no human in the building is formally assigned to watch, and to surface them, per patient, every morning, before the visit happens rather than after the denial arrives.

    ClockWhat it isHow software tracks itAuthority
    Plan-of-care certificationDuration of the plan of care, or 90 calendar days from initial treatment, whichever is less; recertified at least every 90 daysCalendar — derivable from the date of initial treatmentMedicare Benefit Policy Manual Ch. 15 §220.1.3
    Authorized visit blockA finite number of visits granted by a commercial payer or its delegated utilization-management vendor; re-authorization must land before the block runs outCounter — decremented per attended visit, on the payer's counting rules, not yoursPayer contract and UM vendor policy — no single primary source
    Annual dollar threshold (KX)$2,480 for PT and SLP combined; $2,480 for OT separately; claims above it without the KX modifier are deniedAccumulator — year-to-date therapy dollars per patient, per discipline pairReported: APTA, citing Medicare Claims Processing Manual Ch. 5 §10.3.2
    Targeted medical review threshold$3,000, not indexed until after 2028 — a review trigger rather than a payment gateAccumulator — same series, different alertReported: APTA payment thresholds page

    The three depleting clocks in an outpatient rehab episode, plus the review threshold. Dollar figures are reported rather than primary — see the limitations section.

    Read that table as a systems diagram rather than a compliance list. Two of the four rows are pure calendar arithmetic derivable from data your chart already holds. One is a counter whose decrement rule belongs to somebody else. One is an accumulator whose definition — which dollars count — is the single question most likely to be answered wrongly in an implementation. Everything in this guide follows from that shape.

    Plan-of-Care Certification and the 2025 Exception

    The certification chase is the specialty's defining administrative workflow, and it is a strange one: the therapist writes the document, and then spends weeks trying to get a physician to sign it. The cadence is set out in the Medicare Benefit Policy Manual, Chapter 15, section 220.1.3, and it is worth knowing precisely, because the deadlines are what an agent computes.

    • Initial certification duration: Covers the duration of the plan of care, or 90 calendar days from the date of the initial treatment, whichever is less.
    • Timeliness — 30 days: Timely certification of the initial plan is met when physician or NPP certification is documented, by signature or verbal order, and dated in the 30 days following the first day of treatment, including the evaluation.
    • Verbal orders — 14 days: If the order to certify is verbal, it must be followed within 14 days by a signature to be timely. That is a second, shorter clock nested inside the first, and it is the one most often missed.
    • Recertification — every 90 days: At least every 90 days after initiation of treatment under that plan, or sooner if a significant modification becomes evident. A physician may certify for any duration up to 90 days.
    • Who may not certify: Chiropractors may not certify or recertify therapy plans of care. Optometrists may certify only low vision services. A workflow that routes a certification request to the wrong provider type produces a document with no effect.

    Then there is the change that most reshapes what software is worth building. Reported effective for dates of service on or after January 1, 2025: when a patient is referred by a physician or NPP, certification is satisfied by a signed and dated order or referral in the record, plus documentation that the plan of care was submitted to the referring provider within 30 days of the initial evaluation. The referring provider need not return a signed copy. Silence operates as assent. APTA cites 42 CFR Part 424 Subpart B and 89 Fed. Reg. 97710, 97912-97918.

    Cite the Federal Register, not the manual. The Benefit Policy Manual PDF still carries older text for §220.1.3 and does not yet reflect this exception, so the Federal Register pages are the controlling authority. We mark the exception as reported rather than primary for that reason, and you should confirm the current position with your MAC before you build payment logic on it.

    If it holds as described, the operational consequence is large: the payable artifact stops being a returned signature and becomes proof of transmission. That is a document-rail problem rather than an API problem — fax confirmations, portal receipts, direct-message logs — and it is precisely the kind of evidence software produces reliably and humans lose. An agent that transmits the plan of care, timestamps the transmission, names the recipient and channel, and files the artifact immutably is doing something with direct revenue consequence and no clinical judgement in it at all.

    What the agent must not do is decide that the plan of care is clinically appropriate, or that a modification is significant enough to trigger early recertification. Those are the therapist's judgements, and the physician's agreement is a clinical act that software cannot manufacture. The agent's job is to make sure nobody has to remember a date.

    Authorization Per Visit Block — and What CMS-0057-F Does Not Do for You

    The second clock belongs to somebody else. Commercial payers and their delegated utilization-management vendors authorize outpatient rehab in blocks of visits, and the re-authorization has to land before the block runs out or the visits are simply unpaid. The clinic's exposure is a counting problem across dozens of concurrent episodes, each with a different payer, a different block size and a different submission channel.

    A lot of 2026 vendor content implies this problem is about to be standardised away. It is worth being precise about what is actually happening, because the distinction between what binds payers and what helps practices is where budgets get wasted.

    CMS-0057-F: binds payers, not you

    The rule's obligations run to Medicare Advantage organizations, state Medicaid and CHIP fee-for-service, Medicaid and CHIP managed care, and QHP issuers on the federally facilitated exchanges. Commercial and ERISA plans are not covered. The codified text at 42 CFR §422.122 requires a specific reason for denial beginning January 1, 2026, public reporting of prior-authorization metrics beginning in 2026, and a FHIR prior-authorization API beginning January 1, 2027. Decision timeframes are live now: 7 calendar days standard and 72 hours expedited.

    Nothing in it obligates your practice to buy software. What it gives you in 2026 is leverage: an enforceable decision clock, a written denial reason regardless of channel, and — new, and badly underused — each affected payer's own published prior-authorization metrics, with the first postings due March 31, 2026. Approval rates, denial rates and average decision times, published by the payer, are a diligence and negotiation artifact you did not have two years ago.

    The 2027 API is a payer-side obligation. A practice benefits only if its EHR or its vendor builds a client against it. Payer readiness is not practice capability.Ask any vendor which specific payers' FHIR prior-authorization APIs it will consume, and get the answer in writing with a date attached.

    The reality check, from a federal primary source dated last month. CMS's own AI prior-authorization model, WISeR, publishes fax cover-sheet instructions. The WISeR Provider and Supplier Operational Guide, version 7.0, last updated July 24, 2026, tells providers that requests may be sent by mail, fax, esMD or the electronic portal, and instructs them to place the prior authorization form on the page immediately after the fax cover sheet. Every one of the six WISeR participants publishes a fax number or a portal URL; none publishes an X12 278 or FHIR endpoint in the guide. Anyone claiming prior authorization became a solved, standards-based problem in 2026 is contradicted by CMS.

    The adoption data agrees. The 2025 CAQH Index, published by DataSpring (formerly CAQH) and released February 19, 2026, puts fully electronic prior-authorization adoption at 40%, up from 31% in the 2023 Index, built on data from more than 600 provider organizations and health plans representing 63% of insured lives. The corollary is the number that should shape your plan: roughly 60% of prior authorizations are still not fully electronic. Four different things are sold as "ePA" — the X12 278 transaction, HL7 FHIR and Da Vinci, portal automation, and fax or phone. Make a vendor tell you which one it means, per payer.

    One more thing that touches outpatient rehab directly. WISeR reaches the office setting — place of service 11 — not just hospitals, and its selected services include epidural steroid injections for pain management and percutaneous vertebral augmentation, which is the referral population many rehab clinics share with pain management and physiatry. WISeR is live: implemented January 1, 2026, it survived a GAO rule determination and a Congressional Review Act repeal resolution that the Senate rejected in late July 2026, with a House appropriations rider still pending. It is politically unstable and legally operative. It also runs a real federal gold-card equivalent: from July 2026, CMS and the participants automatically exempt providers from prior authorization and pre-payment review on demonstrated compliance — at least ten prior-authorization requests in an assessment period, plus a minimum affirmation rate that each participant sets and posts publicly. The exemption is granted at the individual NPI level, added quarterly, and held for at least a year. CMS does not publish the threshold number.

    Note the counterweight before you build a strategy on gold carding. Medscape's reporting on state-mandated gold-card programs is headlined on the finding that experts say they offer little relief. Exemption programs are worth tracking; they are not a plan.

    The KX Threshold, the 8-Minute Rule, and What an Agent May Compute

    The third clock is an accumulator. Reported figures for CY2026: a $2,480 KX modifier threshold for physical therapy and speech-language pathology combined, and $2,480 for occupational therapy separately, up from $2,410. Claims above the threshold submitted without the KX modifier are denied. A separate $3,000 targeted medical review threshold is not indexed until after 2028. We mark these as reported: the CMS therapy-services page returns an error to automated retrieval, so the numbers come from APTA's payment-thresholds page, which cites the Medicare Claims Processing Manual Chapter 5, section 10.3.2.

    KX is an attestation, and that settles the boundary. The modifier represents the provider's assertion that services above the threshold are medically necessary and that the justification is documented. An agent may accumulate the dollars, rank the patients approaching the line, and assemble the documentation the attestation would rest on. It may not assert it. The Medicare Program Integrity Manual, Chapter 3 §3.3.2.4 says explicitly that practitioner concurrence is required when AI technology captures the transcription of medical record entries, and CMS's own model attestation statement is first-person, credentialed, and closes with the author acknowledging that falsification, omission or concealment may bring administrative, civil or criminal liability. There is no configuration in which software attests.

    The rest of the billing mechanics are, by contrast, exactly the kind of deterministic arithmetic that software should have been doing for a decade. From the Medicare Claims Processing Manual, Chapter 5:

    1. 1.The 8-minute rule: 1 unit for 8 through 22 minutes; 2 units for 23–37; 3 units for 38–52; 4 units for 53–67; 5 units for 68–82; 6 units for 83–97. Units billed must reconcile to timed minutes documented. This is a table lookup, and an agent that runs it before the claim drops catches the mismatch while the therapist can still correct the note.
    2. 2.Discipline modifiers GP, GO, GN: Required on therapy services — GP for a PT plan of care, GO for OT, GN for SLP — and a claim line may carry only one. A presence-and-uniqueness check, trivially automatable, and a recurring source of avoidable rejections.
    3. 3.CQ and CO assistant modifiers: Required since January 1, 2020 for services furnished in whole or in part by a PTA or OTA, paired to GP and GO respectively. Since January 1, 2022 those lines are paid at 85 percent of the otherwise applicable Part B amount, with the 15 percent reduction taken last, right before sequestration. Unpaired CQ or CO claims are rejected and returned as unprocessable — which means an unpaired modifier is not a denial you appeal, it is a claim that never landed.
    4. 4.Multiple procedure payment reduction (MPPR): Reduces the practice-expense component when more than one unit or procedure is furnished to the same patient on the same day. It applies to multiple units as well as multiple procedures, and it applies across disciplines — PT plus OT plus SLP on the same day. Full payment goes to the unit with the highest practice expense. An MPPR-aware expected-payment estimate is one of the few genuinely useful forecasting outputs available to a rehab clinic.

    Everything in that list is computable from data the chart already holds, requires no write access, and produces a result you can count inside one billing cycle. That combination is rare, and it is why we push clinics toward pre-submission checking before anything more ambitious.

    One structural note for practices whose referral base includes physiatry. Orthopedic surgery, physical medicine and rehabilitation, pain management, anesthesiology, interventional pain management and neurosurgery are the six Part B specialty codes in the low back pain cohort of the Ambulatory Specialty Model — a mandatory Innovation Center model running January 1, 2027 through December 31, 2031, with an eligibility threshold of 20 or more attributed episodes, two-sided risk, and scoring that includes meaningful use of certified EHR technology. It applies to the attributed clinicians, not to the therapy practice directly, but it changes the interoperability conversation with your referring physicians, and it is the most defensible reason we know to bring them into an integration project rather than build one in isolation.

    Attendance and Completion — and the Numbers We Refuse

    Because a PT episode is a series, the economics are about completion rather than capture. A patient who attends four visits of a twelve-visit plan has consumed an evaluation, a certification cycle and an authorization, and produced a fraction of the episode's value — while occupying a recurring slot that could have carried someone through to discharge. Attendance management, cancel and no-show backfill, and the distinction between a clinical discharge and a silent dropout are the operating levers that matter most.

    And here is where we have to stop and refuse to give you a number.

    We could not source a single credible PT completion or dropout statistic.The figures that circulate in this market — that 20 to 30 percent of patients never complete their plan of care, or that only about 30 percent complete — trace in our research to a rehab-EMR vendor's annual industry survey, and we could not chase them to a published methodology. We are not printing them. Nor are we printing the general appointment-economics numbers vendors use to size this problem: the "$200 per no-show" and "$150 billion a year" figures both trace to a single 2017 byline by a scheduling vendor's chief medical officer with no methodology, and every phone abandonment benchmark used to sell voice agents fails the same test.

    Naming the absence is more useful to you than repeating the number, for a concrete reason: if there is no credible industry benchmark, then your own baseline is the only number a business case can rest on. Measure it before you automate anything. Visits scheduled versus attended, by therapist and by day of week. Episodes that reach documented discharge versus episodes that simply stop. Days from initial evaluation to certification. Re-authorizations submitted before the block ran out versus after. Four weeks of that data costs nothing but attention, and it converts every later ROI conversation from an argument into arithmetic.

    On the automation itself: reminders, waitlist backfill and re-engagement outreach are real and useful, and they are also where a rehab clinic most easily walks into state disclosure law. Keep the line clean. Confirming an appointment, telling a patient how many visits remain on an authorization, or asking them to call the front desk is administrative — California's AB 3030 expressly excludes appointment scheduling, billing and other clerical or business matters from its definition of patient clinical information. A generative message that discusses the patient's pain, progress or what they should do about a flare-up is clinical, and in California it needs a generative-AI disclaimer and instructions for reaching a human provider unless a licensed provider read and reviewed it first. In Texas, HB 149 §552.051(f) reaches further: any AI use in relation to a health care service or treatment must be disclosed to the patient no later than the date the service is first provided, with no human-review exemption on its face.

    And a naming rule that catches people out: in California, holding an AI out with a title implying a health care licence is enforceable against the entity deploying it, with each use a separate violation. Calling your reminder agent "Nurse Ava" is not a branding decision.

    Top 10 Prior-Authorization & RCM Automation Platforms

    This is the section most likely to be wrong in every other article you read on this topic, for two reasons: it usually mixes payer-side and provider-side products into one list, and it usually ranks on accuracy figures that nobody has audited. We are going to do neither, and explain why before we rank anything.

    Methodology — what we scored, what we excluded, and when we checked. Checked 2026-08-12. We scored on attributes a buyer can verify without a vendor's cooperation: who the product is sold to; named integrations that are actually verifiable on the vendor's own site; corporate ownership and stability from public record; pricing transparency; whether security certifications are publicly stated; and disclosed conflicts of interest. We did not score on accuracy, on auto-approval rate, or on ROI. Rankings are opinion built on verifiable inputs, expressed as tiers rather than fake-precision scores. Re-check by opening each vendor's integrations page, its pricing page and its security page, and by searching for its most recent funding or ownership event — every finding below was reached that way and every one has a shelf life.
    The accuracy disclaimer, stated plainly: no independent benchmark exists for this category. We searched for peer-reviewed or independent evaluations of prior-authorization and RCM automation accuracy and found none. Every accuracy, auto-approval, denial-rate and ROI figure in this market is published by the vendor selling the product, with no disclosed methodology, no defined denominator and no third-party audit. The closest thing to third-party evaluation is KLAS Research, which added "Revenue Cycle Prior Authorization" as a category in 2026 — and KLAS scores customer satisfaction on a 100-point scale, not whether the software is accurate. KLAS awarded no Best in KLAS in that new category in 2026. Accuracy is excluded from our scoring by design, and any vendor comparison that ranks on it is ranking on marketing.

    Now the distinction that saves money.The most expensive common mistake in this category is buying a payer-side tool. Several of the best-funded, best-marketed "AI prior authorization" companies do not sell to practices at all — they sell to health plans, and their product is the thing on the other side of your request. A practice cannot deploy them. Some of them are, quite literally, adjudicating your requests.

    VendorWhat it actually isOwnership / funding (reported)Why a practice cannot buy it
    Cohere HealthPayer-side utilization management and prior-authorization adjudication for health plans (Cohere Unify)Independent, VC-backed; $90M Series C in May 2025 led by Temasek; about $200M total reportedIt is the CMS WISeR participant adjudicating Medicare prior authorizations in Texas, per the WISeR Guide v7.0 Table 2, and it also runs Humana's MSK prior authorization. A Texas practice buying from Cohere would be buying from its own adjudicator
    AnteriorPayer-side clinical AI — prior authorization, payment integrity, risk adjustmentIndependent; $40M round announced February 12, 2026 (NEA, Sequoia, FPV, Kinnevik); $64M total since a June 2024 Series ANo provider-facing product. Its published '99.24% clinical accuracy' claim is a textbook example of two-decimal precision on an unaudited internal metric
    basys.aiGenerative AI for prior authorization, utilization management and payment integrity, sold to health plansIndependent, Cambridge MA, founded 2022; $2.4M total disclosed from a pre-seed round announced August 15, 2023Wrong buyer. A practice cannot deploy it. That reason is sufficient on its own and it is the only one we publish — we draw no conclusion about the company's viability

    Payer-side vendors that appear in provider-facing "top prior-auth software" lists. Checked 2026-08-12.

    Where that fact comes from, and where our opinion starts. Table 2 of the CMS WISeR Model Provider and Supplier Operational Guide, v7.0 (July 24, 2026) names the WISeR Participant for each of the six model states: Cohere Health, Inc. for Texas, Humata Health, Inc.for Oklahoma, Genzeon Corporation for New Jersey, Innovaccer Inc. for Ohio, Zyter Inc. for Arizona and Virtix Health LLC for Washington. That roster is CMS's. The observation that follows — that two of those adjudicators also market prior-authorization AI, and that this is a conflict a buyer should price in — is ours, and CMS says nothing of the kind.

    That pattern is stacked most deeply at Optum, whose provider-facing Digital Auth Complete went live in January 2026 and is powered by Humata Health — the WISeR participant adjudicating Medicare prior authorizations in Oklahoma — inside UnitedHealth Group. A practice buying prior-authorization software there is buying from the parent of its largest payer, running on the engine of a Medicare prior-authorization adjudicator. None of this is illegal, all of it is publicly disclosed, and we found it disclosed in no vendor comparison article. Ask about it directly, in the room, and write the answer down.

    The provider-side ranking. It is nine, not ten. After removing payer-side products, autonomous-coding products that are a different category, and one enterprise platform with no evidence it sells to independent practices, nine credible provider-side candidates remain. We are not backfilling a tenth to reach a round number, because the only way to do that would be to include a vendor we could not verify is still actively selling — and that is exactly the failure this section exists to avoid.

    Rank & vendorCategoryNamed integrations (verifiable)Ownership / funding (reported)Pricing transparencyVerdict
    1 — Waystar (Nasdaq: WAY)Provider-side incumbent RCM platform; eligibility, claims, denials, prior auth (Auth Accelerate)Not verified — no definitive named-integration list captured; link the vendor's own pagePublicly traded, audited public financials. Acquired Iodine Software at $1.25B enterprise value; closedNot published — contact salesTier A on corporate transparency. The only vendor here whose financials are audited and public. Integration and security claims still require your own diligence, and the Iodine integration is new enough to be unproven
    2 — Candid HealthProvider-side RCM and billing engine — detects, flags and works claim issuesVerified on the vendor's own site: Medplum, Healthie, Elation Health, Canvas, Qualifacts OnCall; payments via Square, Stripe, Chargebee, CedarIndependent; $120M Series D reported, tripling its valuation from a February 2025 Series CNot publishedTier A on verifiability — the only vendor in the roster whose named integration list checked out in full. Note the fit signal: those are digital-health-native EMRs, not the large ambulatory or rehab-specific systems most PT clinics run
    3 — AvailityMulti-payer provider portal and clearinghouse — eligibility, authorization requirements, PA submission with attachments, claims, remittancePayer-side breadth rather than EHR breadth; Availity cites 170 million covered lives and exclusive-portal status for many payers. No consolidated list capturedPayer-owned: Elevance Health, HCSC, Florida Blue/GuideWell and BCBS Minnesota among owners; Novo Holdings bought Francisco Partners' minority stake in 2021 and FP has exitedThe only published price fact in the roster: submission to sponsoring payers on Essentials is free. Essentials Plus is a paid subscription with no published dollar figureTier A on pricing transparency, with a disclosed structural conflict — the provider portal most practices use for prior auth is part-owned by payers on the other side of the transaction. State it neutrally; it explains why it is free
    4 — InfinxProvider-side prior-authorization specialist plus broader RCM for clinics, imaging centres and labsNot verified — the product page truncated on fetchMajority-owned by the Tandon Group; Norwest an existing shareholder; KKR acquired a significant minority stake in May 2024Not publishedTier B. Carries the strongest third-party signal in the category and it is still not an accuracy benchmark: 90.1 on KLAS's 100-point scale in the April 2026 Revenue Cycle Prior Authorization report card, versus an 85.8 segment and 83.1 software average. KLAS scores customer sentiment, and awarded no Best in KLAS in the new category
    5 — AdonisProvider-side RCM orchestration — revenue-risk detection and automated resolution across denials, delays and payer frictionDowngraded on re-check: Epic is the only integration verifiable as page text; the /integrations URL returns 404 and logo images carry empty alt attributesIndependent, founded 2022; $40M Series C on March 25, 2026 led by Quadrille Capital with General Catalyst and Bling Capital; $95M+ total reportedExplicitly not published — 'Request a Demo'Tier B. Genuinely provider-side and selling to physician groups and MSOs. Its site shows a HIPAA badge and an AICPA mark; no SOC 2 Type II or HITRUST is stated, and an AICPA logo is not a SOC 2 Type II report. Ask for the report
    6 — Infinitus SystemsAI voice agents that place and receive calls to payers — benefit verification, authorization status, claims, prescription follow-upNo named EHR integrations verified. Its integration surface is the telephoneIndependent; $51.5M Series C led by Andreessen Horowitz with Memorial Hermann, GV, Coatue and Kleiner Perkins; ~$102.9M total reportedNot publishedTier B, and the most honest illustration in the category: in 2026 the most reliable way to get an agent to interoperate with a payer is to have it phone them. For patient-facing voice, see our separate ranked table on communication and voice platforms rather than this one
    7 — Latent (Latent Health)Provider-side medication prior authorization — interprets drug approval criteria, orchestrates PAs, 340B compliance and appealsProcesses EHR data; no named EHRs verifiedIndependent, Y Combinator alum; $80M Series A announced March 2026 co-led by Spark Capital and Transformation Capital, with McKesson Ventures among investors; ~$600M valuation reportedNot publishedTier C for outpatient rehab — a real specialization, but medication access is not a PT clinic's authorization problem. Note also that a drug distributor is an investor in a medication-access tool; disclose it. An $80M Series A at a $600M valuation is an early-stage company at a late-stage price
    8 — Rivet (Rivet Health)Provider-side pricing and contract analytics — Revenue Diagnostics, Payer Performance, Patient Pricing. Not a prior-auth engineNot verifiedIndependent; ~$28.8M total disclosed — $8.25M Series A then a $20.5M Series B in June 2022 led by Catalyst Investors; no disclosed raise since 2022. Reported figures; we located no primary release, so treat them as secondaryPublishes no dollar figures anywhereTier C on category fit. If your problem is underpayment detection and patient estimates it is in scope; if your problem is authorization submission, this is not that tool
    9 — Enter.HealthProvider-side full RCM replacement — claims, denials, eligibility, coding, patient billing, payer communicationsDisqualifying: the vendor's own integrations page names not one EHR, PM system or clearinghouse. It says it 'supports all EHRs' and that it becomes your clearinghouse via unnamed partnersNot verified. Still operating; no shutdown foundNot publishedListed as a cautionary entry, not a recommendation. An unfalsifiable claim on the exact axis that determines whether the product works for you, on the page whose purpose is to answer it — plus a deep, hard-to-reverse clearinghouse dependency from a vendor that will not name its upstream partners

    Provider-side prior-authorization and RCM automation platforms, ranked on verifiable attributes only. Checked 2026-08-12. Rankings are opinion; the inputs are public.

    The finding that matters most to a rehab clinic is what is missing from that table. Sixteen vendors were examined and one — Candid Health — publishes a fully verifiable named integration list. No rehabilitation-specific EHR appears anywhere in that one verifiable list, and for the other fifteen we could not verify a named EHR integration at all, so whether any of them connects to your rehab EMR is simply unestablished on the public record. Not one publicly states SOC 2 Type II or HITRUST status on the pages we fetched. And exactly one published price fact exists across the entire roster: Availity Essentials is free to providers for sponsoring payers. Sixteen vendors, zero published dollar prices otherwise. Treat every claim about fit with your specific rehab EMR as unverified until the vendor demonstrates it in your instance, with your data.

    Four categories were deliberately excluded rather than ranked. Payer-side products (above). Autonomous coding platforms such as Nym Health and CodaMetrix — healthy companies, different category; CodaMetrix has the most credible provenance in the roster, having spun out of Mass General Brigham, but that provenance is not a published study and we found no peer-reviewed evaluation. Enterprise health-system RCM such as AKASA, where we found no evidence of sales to independent practices. And 2026 entrants— R1 RCM's Phare Access (launched January 15, 2026; R1 was taken private in November 2024 by TowerBrook and Clayton, Dubilier & Rice, so no public financials), Optum's Digital Auth Complete, UiPath's healthcare agentic push announced at ViVE in February 2026, and PrescriberPoint (April 2026) — all new, none independently evaluated. New is not disqualifying. Unproven and unverifiable together are.

    Finally, the figures we will not print, and the reason for each. This table is the part of the section we would most like other publishers to copy.

    FigureWhere it comes fromOur position
    '86% of claim denials are potentially avoidable' (and its 85%, 87% and 'nearly 90%' mutations)Traces to the Change Healthcare 2020 Denials Index — vendor-published, analysing 102 million hospital transactions from July 2019 to June 2020Refused. Wrong population (hospitals, not practices), six years stale, COVID-distorted, and the original report is no longer retrievable. Every current citation goes to secondary coverage
    'Auto-approval rates of over 90%' (Auth Accelerate)Waystar, vendor-publishedRefused as a neutral figure. No denominator, no definition of which payers or service lines
    'Up to 9x ROI', 'up to 90% of requests can be auto-approved', and provider satisfaction stated as both 93% and 94%Cohere Health, vendor-published — the two satisfaction figures appear in the same press releaseRefused. A vendor that cannot keep its own headline metric consistent within a single release is the clearest available illustration of why none of these numbers are usable
    '99.24% clinical accuracy'; '76% increase in auto-approvals'Anterior, vendor-publishedRefused. Two-decimal precision on an unaudited internal metric
    '68% of orders cleared in one hour', '~97% in one day', 'auth-related denial rate under 1%'R1 RCM (Phare Access), vendor-publishedRefused. No methodology, no denominator
    '94.5% clinician acceptance rate'PrescriberPoint, vendor-publishedRefused, and worth understanding: it measures clinicians accepting a draft, not payers approving a request. A metric that sounds like accuracy and is not
    PT patient dropout and attrition rates ('20–30% never complete their plan of care', 'only 30% complete')The recurring origin in this market is a rehab-EMR vendor's annual industry survey; we could not chase it to a published methodologyRefused. Completion is the right thing to manage; it is not something anyone has credibly measured for you
    '$200 per no-show' and '$150 billion a year' in missed appointments; any phone-abandonment benchmarkBoth trace to a single 2017 byline by a scheduling vendor's chief medical officer, with no methodology. The abandonment benchmarks fail the same testPermanently refused across everything we publish
    '$258 billion avoided' (2025 CAQH Index headline)A modelled opportunity estimate from the Index publisherNot usable as a savings figure. The 40% electronic prior-authorization adoption figure from the same report is fine

    Figures excluded from this article, with the reason. Checked 2026-08-12.

    Against all of that, here is a statistic that does survive sourcing, because it comes from a professional association surveying its own members with a stated methodology. The 2025 AMA Prior Authorization Physician Survey — a nationwide survey of 1,000 practicing physicians, 400 primary care and 600 specialists, fielded in December 2025 and released May 2026 — reports 40 prior authorizations per physician per week and 13 hours of physician and staff time weekly, with 40% of practices having staff working exclusively on prior authorization. And the number that should sit at the front of every vendor meeting: 60% of physicians are concerned that AI increases or will increase prior-authorization denial rates, while the entire vendor category sells AI as the fix. That tension is real, it is sourced, and it belongs in your diligence.

    The Write Path: Certified API Access Is Read-Only

    This is the single most important architectural fact in the whole cluster, and it is the one most likely to be glossed over in a demo. The ONC/ASTP Certification Companion Guide for §170.315(g)(10), last updated May 15, 2026, states it directly:

    The § 170.315(g)(10) certification criterion requires Health IT Modules to support API-enabled "read" services for single and multiple patients. … These services specifically exclude "write" capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.

    ONC/ASTP Certification Companion Guide, §170.315(g)(10), updated 2026-05-15

    So an agent can read the chart through a certified API in any certified EHR. Every write — booking the next visit in the series, posting the charge, filing the note, updating the plan of care, marking the certification received — happens one of three ways, and you must know which one your vendor means:

    1. 1.A vendor-discretionary write API: A commercial arrangement with your EHR vendor, governed by that vendor's app review and API terms, frequently with per-transaction fees. There is no certification requirement compelling any EHR vendor to offer this. It is a negotiation, and it has a price and a lead time.
    2. 2.Robotic automation driving the user interface: A bot typing into your EHR or a payer portal. Ask directly whether it runs under a named human's credentials, because if it does, your audit trail says your employee did it. Ask how many portals the vendor maintains and what its mean time to repair is after a portal redesign. No vendor publishes that number.
    3. 3.A human: Slower, and frequently the correct answer for anything with billing, legal or clinical consequence. The agent assembles and proposes; a named person commits.
    The exact question to put to your EHR representative, in writing."For our licence and our version: which specific write endpoints or interfaces are available to a third-party application, what does your app-review process require and how long does it take, are there per-transaction or per-connection fees, what are the rate limits, and can you confirm this in writing?" If the answer is a marketplace URL rather than an endpoint list, you do not have an integration plan — you have a hope. Scope this in week one, before a single workflow is designed, because retrofitting a write path is what turns a fixed-price project into a time-and-materials argument.

    There is a security dividend hiding in this constraint that is worth taking deliberately. An agent that cannot write cannot be injected into writing. Prompt injection is unsolved — a controlled simulation published in JAMA Network Open in December 2025 found attacks succeeded in 94.4% of 108 evaluations at turn four and persisted in 69.4% of follow-ups, with flagship models showing high susceptibility; and work published in Nature Communications found that sub-visual prompts embedded in medical imaging data can cause harmful output and are non-obvious to human observers. Those are simulations rather than field data, and we found no published study of injection through referral faxes, portal messages or payer portals in a live practice — the absence of that evidence is itself worth stating. But the mitigation that survives all of it is architectural: least privilege at the API boundary, read-only by default, a human signature as the only path from draft to record, unique agent identity so a successful attack is reconstructable, and out-of-band confirmation for anything irreversible. Note the uncomfortable corollary of the "non-obvious to human observers" finding — a human in the loop who cannot see the injection cannot review it away. Frame this as blast-radius reduction, never as solved.

    Two HIPAA mechanics follow from giving an agent its own access. 45 CFR §164.312(a)(1) already frames access rights as attaching to persons or software programs, and §164.312(a)(2)(i) makes unique user identification a required, not addressable, implementation specification. A shared service account that makes agent actions indistinguishable from a human's is the compliance failure to name and avoid. And your model provider, your agent-framework vendor and that provider's own cloud host are all business associates or subcontractor business associates under 45 CFR §160.103 — one BAA with the app vendor does not close the chain. Whether a given model provider will sign a BAA, and on which tier, changes without notice; re-check the provider's own current documentation on the day you sign, not on the day you read an article.

    The Human-in-the-Loop Boundary Table

    Write this down before anything is built, get your compliance lead to sign it, and put it in the vendor contract. The boundary is not a philosophical position; most of it is set by statute and manual, and the parts that are not are set by what you can afford to have go wrong unattended.

    ActionWho decidesWhy
    Compute days-to-recertification, visits remaining, and year-to-date threshold accumulation; build the daily worklistAgent aloneAdministrative data movement — expressly outside the device definition under 21 U.S.C. §360j(o)(1)(A), which names appointment schedules, claims and billing information, and business analytics
    Assemble the plan-of-care packet and the authorization packet from the chart; produce a transmission logAgent alone, human sendsAssembly is administrative. Transmission of a plan of care to a referring provider is a document-rail action whose proof is the payable artifact under the reported 2025 exception — keep the log immutable
    Reconcile timed minutes to billed units under the 8-minute rule; check GP/GO/GN presence and CQ/CO pairing before the claim dropsAgent proposes, biller confirmsThe manual's unit table is deterministic, but unpaired CQ/CO lines are rejected as unprocessable and the underlying minutes are a clinical record. A human owns the correction
    Apply the KX modifierNever automatedKX is a provider attestation of medical necessity. CMS requires practitioner concurrence even for AI-captured record entries, and the model attestation statement is first-person, credentialed and personally liable
    Sign or attest to any note, evaluation or progress reportNever automatedMedicare Program Integrity Manual Ch. 3 §3.3.2.4. Reviewers will not consider an attestation from anyone other than the author of the entry, and an attestation cannot be used to backdate a plan of care
    Decide whether a patient's plan of care should be modified, extended or dischargedNever automatedClinical judgement. A specific treatment output or directive fails FDA's Criterion 3; the enforcement-discretion policy announced in the January 2026 CDS guidance is a posture FDA can withdraw, not an exclusion
    Answer a patient's clinical question in writing or by voiceHuman review before it goes outIn California, generative-AI communications about patient clinical information require a disclaimer and human-contact instructions unless a licensed provider read and reviewed it first; administrative matters such as scheduling and billing are expressly excluded from that rule
    Any AI use in relation to health care service or treatment (Texas)Disclose to the patientTexas HB 149 §552.051(f) requires disclosure no later than the date the service is first provided, except in emergencies. It has no human-review exemption on its face
    Perform work billed 'incident to' a physician's serviceNever automated42 CFR §410.26(a)(1) defines auxiliary personnel as an individual who meets state licensure. Software is not an individual and cannot hold licensure. There is no incident-to pathway for AI-performed work
    Submit a prior authorization to a payer as the submitting partyHuman submitsNo payer publicly states that it accepts prior authorizations submitted by an autonomous agent. A payer accepting a FHIR transaction is not a payer blessing an agent-authored submission
    Release records, move money, or message a patient at scaleOut-of-band human confirmationIrreversible actions are where prompt injection converts into harm. This is design reasoning, not a cited rule — but it is the control that survives an attack you cannot see

    The autonomy boundary for an outpatient rehab clinic. Authorities cited in the sources list.

    The organising principle behind the whole table is a single statutory sentence. 21 U.S.C. §360j(o)(1)(A) excludes from the device definition software intended for administrative support of a health care facility, and it names the things: processing and maintenance of financial records, claims or billing information, appointment schedules, business analytics, practice and inventory management, determination of health benefit eligibility. An agent doing those things is outside the device definition by statute, not by FDA grace. The moment it starts producing clinical recommendations, a different and much harder four-criterion test applies under §360j(o)(1)(E), and FDA's Clinical Decision Support Software guidance reissued January 29, 2026 does not make that easier so much as it announces an enforcement-discretion policyover one criterion failure. Write it that way, because discretion is revocable without notice-and-comment and an exclusion is not. FDA said nothing new about generative AI specifically; do not let a vendor tell you otherwise, and treat any claim that FDA "approved" or "cleared" an administrative AI product as a red flag on its face.

    One more duty that is live today and routinely missed: 45 CFR §92.210 imposes an ongoing duty on covered entities to make reasonable efforts to identify uses of patient care decision support tools that employ input variables measuring race, colour, national origin, sex, age or disability, and to mitigate the resulting discrimination risk. It applies whether or not the tool is AI and whether or not FDA calls it a device. If your agent prioritises a worklist, that prioritisation is in scope for the inventory.

    The Sequenced Implementation Path

    Seven phases, in order, with an owner, an entry criterion, an exit criterion and a defined response when the phase fails. The sequencing is deliberate: everything read-only comes before anything that writes, and everything with a countable result comes before anything with a narrative one. Week ranges assume a single-site clinic of five to fifteen therapists and overlap by design.

    Phase 1 — Baseline and inventory (weeks 1–2)

    Owner: practice administrator, with the billing lead. Entry: leadership agreement that no automation ships before the before-state is measured. Exit: four weeks of baseline captured — scheduled versus attended visits by therapist and weekday, episodes reaching documented discharge versus stopping, days from initial evaluation to certification, re-authorizations submitted before versus after block exhaustion, and denial reasons grouped by cause. Plus a written inventory of every payer, its authorization channel (fax, portal, phone, X12 278, FHIR) and its block size.

    If it fails: if you cannot extract the baseline, stop. A clinic that cannot measure attendance and certification lag today will not be able to prove an agent changed either. Fix reporting first; that is a smaller, cheaper project and it is the prerequisite.

    Phase 2 — EHR read and write feasibility read (weeks 1–3)

    Owner: integration engineer, with the practice administrator in the room for the vendor call. Entry: Phase 1 payer inventory started. Exit:a written answer from your EHR vendor to the five questions in the write-path section — available write endpoints, app-review requirements and duration, fees, rate limits, confirmation in writing — plus a confirmed read path and a test credential that is not a clinician's login.

    If it fails: if no write path exists or the terms are unacceptable, do not cancel the project — re-scope it to read-and-propose with human commit, and say so in the business case before anyone budgets on closed-loop automation. This phase failing quietly is the most common cause of a project that dies in month five.

    Phase 3 — The three-clock watcher, read-only (weeks 3–7)

    Owner: clinic operations manager as product owner; integration engineer as builder. Entry: read access confirmed and unique agent identity provisioned with its own audit trail. Exit: a daily worklist showing, per active patient, days to recertification, visits remaining against the authorized block, and year-to-date therapy dollars against the KX threshold — reconciling to the EHR and to remittance data with zero unexplained differences for two consecutive weeks.

    If it fails:the failure is almost always definitional rather than technical — which date starts the clock, which dollars count, how the payer decrements the block. Freeze the build, take the three definitions to your billing lead and one payer representative, write them down, and restart. Do not ship an accumulator you cannot reconcile; a false "you are clear" produces denied claims at volume.

    Phase 4 — Certification packet and proof of transmission (weeks 6–11)

    Owner: front-office lead; clinical director signs off on packet contents. Entry: Phase 3 recertification dates reconciling cleanly. Exit: the agent assembles the plan-of-care packet, a named human transmits it, and every transmission produces a stored, timestamped, immutable artifact naming recipient and channel — with a weekly audit showing 100% of transmissions in the period have a retained artifact. Median days from initial evaluation to transmission tracked against the 30-day window.

    If it fails: if artifacts are produced but not retained, or the retention is mutable, stop relying on the reported 2025 exception for those episodes and chase signatures the old way until the defect is fixed. Proof you cannot produce on audit is not proof.

    Phase 5 — Authorization tracking and re-auth packet assembly (weeks 10–16)

    Owner: authorization coordinator; billing lead as escalation. Entry: payer inventory complete with channel per payer, and a documented decrement rule per payer. Exit:re-authorization packets assembled and queued for human submission at a defined trigger — typically three visits remaining — with a per-payer dashboard showing submissions before versus after block exhaustion, and a variance check against the payer's own remaining-visit figure at each renewal.

    If it fails:if a payer's counting rule cannot be pinned down, route that payer entirely to the human queue and keep it there. Partial coverage that staff trust as complete is worse than no coverage. Never let the agent submit as the submitting party — no payer publicly permits it.

    Phase 6 — Pre-submission claim checking (weeks 14–20)

    Owner: billing lead. Entry: Phase 3 stable; agreement that the agent blocks nothing and proposes everything. Exit: every claim passes an automated check before it drops — timed minutes reconciled to units under the 8-minute rule, GP/GO/GN present and unique per line, CQ/CO paired correctly to GP/GO, MPPR-aware expected payment computed — with a measured reduction in rejections and unprocessable returns against the Phase 1 baseline.

    If it fails: if the check produces more false flags than corrections, tune the rules against a retrospective sample of your own last 500 claims rather than loosening the thresholds. An alert nobody trusts is an alert nobody reads.

    Phase 7 — Attendance, completion and controlled write access (weeks 18–28)

    Owner: clinic operations manager, with compliance sign-off on message templates. Entry: Phases 3 to 6 in steady state; a written human-in-the-loop boundary approved. Exit: reminder, waitlist-backfill and re-engagement flows live and measured against the Phase 1 attendance baseline; message templates reviewed against the administrative-versus-clinical line; and, only if Phase 2 produced a real write path, the first write workflow — typically booking the next visit in an existing series — enabled behind a human confirmation.

    If it fails: revert to read-and-propose. The write path is the only part of this sequence that can be removed without losing the value of everything before it, which is exactly why it goes last.

    Two notes on economics. The integration layer is largely a fixed cost paid once and reused: the first agent pays for the connection, the identity, the audit trail and the review queue; the third inherits all of it. And the sequencing above deliberately front-loads the workflows whose results are countable in a single billing cycle, because a clinic that cannot show a result in a quarter will not fund a second phase.

    What Breaks First, How You Detect It, How You Roll Back

    These are the failure modes specific to outpatient rehab, in roughly the order we see them appear. Note that almost none of them is a model failure. They are integration failures, definition failures and trust failures — which is where these projects actually die.

    Failure modeDetection signalRollback
    Silent date drift on recertification — the agent's due date and the EHR's differ by a day or two over how initial treatment date, evaluation date and holidays are handledDaily reconciliation count between the agent's due-date list and the EHR's own certification field; alert on any nonzero differenceDemote the agent to advisory and keep the manual tickler running until the difference holds at zero for two consecutive weeks
    Authorized-visit counter drift — cancellations, no-shows and the payer's counting rules disagree with yoursReconcile against the payer's stated remaining-visit figure at every re-authorization; treat variance above one visit as a stop conditionFreeze the counter, revert to the payer portal figure as the system of record, and re-derive the rule from the last three authorizations before re-enabling
    Threshold accumulator counts the wrong dollars — charges versus allowed amounts, or PT and SLP not combined correctly against the shared thresholdReconcile the accumulator monthly against remittance data; alert on any patient whose agent-computed total and remittance-derived total differ by more than a nominal amountSuspend threshold alerting entirely rather than run it wrong. A false 'you are clear' is worse than no alert, because it produces denied claims at volume
    Portal automation breaks after a payer redesigns its siteSynthetic transaction run against each payer portal every morning, with a per-portal success rate on a dashboard, not buried in logsRoute that payer's authorizations back to the human queue automatically on two consecutive failures. Never let a silent scraper failure look like an empty worklist
    Proof of transmission is produced but not retained — the plan of care went out inside 30 days and you cannot prove itWeekly audit that every plan of care transmitted in the period has a stored, timestamped artifact naming the recipient and channelStop relying on the exception for those episodes and chase the signature the old way while the retention defect is fixed
    Prompt injection through an inbound referral fax, portal message or payer-portal pageTreat every agent action that was not derived from structured chart data as an anomaly to review; log the exact input that produced any proposed actionRevoke the agent's tool access to anything with commercial effect, keep read-and-summarise, and reduce blast radius before restoring. Assume you cannot detect the injection — published work shows injected prompts can be non-obvious to human reviewers
    Staff treat an agent-drafted note as filed when it was only draftedReconcile drafts created against notes signed daily; any draft older than 48 hours without a signature is an exceptionChange the interface so drafts are visibly unfiled and cannot be dismissed, and re-train. This is the failure that turns into an unbillable visit and, at scale, into a compliance finding
    Reminder and re-engagement messaging drifts from administrative into clinical adviceSample outbound messages weekly against the administrative-versus-clinical line; any message discussing symptoms, progress or what the patient should do about pain is an escalationRoll the message templates back to the last reviewed version and route the category to human authorship. In California the clinical-information test brings disclosure duties with it

    Failure modes, detection signals and rollbacks for an outpatient rehab agent deployment.

    The meta-rule. Every automated step needs a defined rollback that a non-engineer can execute during business hours, and every rollback should land in the same place: the human queue that existed before the agent did. Do not decommission the manual process until the automated one has held its detection signal at zero for two consecutive weeks. The cost of running both for a month is trivially small compared with the cost of a silent failure discovered through a denial batch 60 days later.

    Vendor Red Flags

    Twelve things that should slow a purchase down. None is automatically disqualifying on its own; three together usually are.

    • An accuracy or auto-approval percentage on the homepage: There is no independent benchmark in this category. Every such figure is vendor-published with no denominator. Ask what the denominator is, which payers, and which service lines. The answer is more informative than the number.
    • Two-decimal precision on an internal metric: A '99.24% clinical accuracy' claim signals an unaudited internal measurement dressed as science. So does a headline metric that contradicts itself inside a single press release.
    • Cannot say which of the four ePA channels it means, per payer: X12 278, FHIR/Da Vinci, portal automation, or fax and phone are four different products. A vendor that answers 'we handle prior auth' has not answered the question.
    • 'Writes back into your EHR' without naming how: Certified API access is read-only. Make them say whether it is a commercial write integration, UI automation, or a human. If it is UI automation, ask whose credentials it runs under.
    • 'Supports all EHRs' with no named systems: An unfalsifiable claim on the exact axis that determines whether the product works for you. One vendor in the roster we examined makes this claim on the page whose entire purpose is to list integrations.
    • An AICPA logo or a 'HIPAA compliant' badge offered as a security certification: An AICPA mark is not a SOC 2 Type II report, and HIPAA compliance is a property of a covered entity's practices and contracts, not of software. Ask for the SOC 2 Type II report and the BAA before the demo, not after the contract.
    • No disclosure of payer ownership or adjudication relationships: Ask directly: do you or your parent adjudicate prior authorizations for any payer we bill, including under the CMS WISeR model? Do payers hold equity in you? These are answerable questions with public answers.
    • A single BAA offered as covering the whole chain: Your model provider and its cloud host are subcontractor business associates. A BAA with the app vendor alone does not close the chain, and 'we train on your data' terms collide with the rule that a business associate may not use PHI in a way the covered entity could not.
    • Reluctance to run a retrospective on your own historical data: The only meaningful evaluation available is against your last few hundred claims, your worst faxes and your real payer mix. A vendor unwilling to be measured that way is telling you something.
    • Claims that FDA 'approved' or 'cleared' an administrative AI product: FDA's 2026 CDS guidance grants enforcement discretion over a criterion failure. Enforcement discretion is not clearance and is revocable. The word 'approved' in this context is a competence signal.
    • A prompt-injection 'guardrail' effectiveness rate: No independent benchmark exists for clinical prompt-injection defence. Any number here is marketing. Ask instead about least privilege, agent identity, audit logging and what the agent physically cannot do.
    • Pressure to decommission the manual process at go-live: Run both until the detection signals hold. A vendor whose commercial model depends on you switching off the fallback immediately has misaligned incentives with your revenue cycle.

    What This Costs and How Long It Takes

    These are the bands Frenchy Digital uses to scope healthcare operations AI work in 2026. They assume integration feasibility and baseline measurement are in scope from the start, because retrofitting either one is what turns a fixed-price project into an argument.

    EngagementRangeTimelineTypical scope in outpatient rehab
    Discovery + workflow audit$9k–$22k2–4 weeksBaseline measurement of the three clocks, EHR read and write feasibility read, payer and authorization inventory
    Single-workflow agent$28k–$70k4–9 weeksThe three-clock watcher, certification packet assembly with transmission proof, or authorization block tracking — one of them, instrumented
    Multi-workflow platform with EHR/PM integration$70k–$180k9–16 weeksTwo or three workflows on one integration, a shared human review queue, exception routing and audit logging
    Enterprise / multi-site / regulated build$180k–$420k+14–24 weeksMulti-clinic rollout, unique agent identity and full audit trail, human-in-the-loop instrumentation, SOC 2 posture

    Frenchy Digital cost bands for physical therapy and outpatient rehab AI agent engagements, 2026.

    Senior-led delivery runs $150–$225 per hour, and ongoing retainers run $2,500–$9,500 per month covering model and dependency upgrades, evaluation expansion, incident response and a quarterly technical review. Every engagement carries a 30-day post-launch warranty, and you receive a written scope with a fixed-price phased proposal within 5 business days of the discovery call.

    Included at every tier: the integration feasibility read including the write path, a baseline measurement of the workflow before anything is automated, a written human-in-the-loop boundary, a review queue with instrumentation, exception routing, unique agent identity and audit logging, and full source-code and IP ownership transferred to you at delivery. Frenchy Digital is a senior-led Black-owned Los Angeles agency, and we do not build lock-in. Book at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601.

    A budgeting note specific to rehab. The three-clock watcher is the cheapest thing on this list and the only one whose payback is countable in a single billing cycle, because a denial avoided is a denial you can name. Sequence it first, prove it, and fund the rest out of what it returns. Clinics that pilot three disconnected point products in parallel get materially worse economics than clinics that sequence two or three workflows through one integration.

    Limitations — What We Could Not Verify

    A short, unflattering list. If you are building a business case, build it on this rather than on the confident parts.

    • The 2026 threshold dollar figures are reported, not primary: CMS's therapy-services page returns an error to automated retrieval. The $2,480 KX threshold and the $3,000 targeted-review threshold come from APTA, which cites the Claims Processing Manual. High confidence, not primary. Confirm with your MAC before configuring an accumulator.
    • The 2025 certification exception is not yet in the manual: The Benefit Policy Manual PDF still carries older §220.1.3 text. The Federal Register pages are the controlling authority. We could not confirm the exception against a current manual revision, so treat it as reported and cite the Federal Register.
    • Which dollars count toward the threshold: We did not verify from a primary source whether the accumulation runs on submitted charges or allowed amounts, or exactly how a practice should treat mid-year payer changes. This is the definition most likely to be implemented wrongly, and it is a question for your MAC and your billing lead, not for a vendor.
    • No exact Medicare payment amounts appear in this article: We did not fetch the Physician Fee Schedule Addendum B, so we print no per-code dollar figures. Any vendor ROI model built on per-code payment assumptions should show you its source.
    • Security certifications for every vendor in the ranked table: Not one of the sixteen vendors examined publicly states SOC 2 Type II or HITRUST status on the pages we fetched, and none advertises a HIPAA BAA — although, handling PHI, they must execute them. We could not turn this into a table column with real values, so we turned it into buyer guidance instead.
    • Named EHR integrations for most of the roster: Only Candid Health publishes a fully verifiable named list. Adonis's integrations URL returns a 404 and only 'Epic' is verifiable as page text. Every other integration claim in this category is the vendor's own assertion, and we found no EHR-side listing corroborating any of them.
    • The read-only certification fact was not re-fetched this session by every source: The §170.315(g)(10) read-only characterisation rests on the ONC/ASTP certification companion guide updated May 15, 2026. It is settled and uncontroversial, but note that a proposed ASTP/ONC rule published December 29, 2025 would remove the clinical decision support certification criterion and reserve §170.315(a)(9). It remains proposed; we located no final rule.
    • Colorado's AI law has a contested effective date in circulation: SB 26-189, signed May 14, 2026, repeals and reenacts the Colorado AI Act. Its enrolled text sets an effective date of January 1, 2027 and applies to consequential decisions made on or after that date, with a healthcare carve-out for HIPAA covered entities plus a general patient notice of use of advanced technologies. An August 12, 2026 date circulates in secondary trackers, derived from a site-wide banner about bills passed without a safety clause; this bill has one. We use the enrolled text. We also found no verified litigation against it and do not repeat that claim.
    • State utilization-review AI statutes could not be cited: A growing number of states, including Texas, Arizona and Maryland, restrict payers from using AI as the sole basis for a medical-necessity denial. We could not verify the individual statutes, citations or effective dates, so we name no bill numbers. The same applies to the gold-carding statutes outside Texas.
    • No PT-specific completion or dropout benchmark exists that we could source: See the attendance section. Your own baseline is the only defensible number.
    • Prompt injection through the channels a clinic actually uses is unstudied: The published work covers patient dialogue and medical imaging. We found no published study of injection via referral faxes, portal messages or payer portals in a live practice. Extrapolating is analysis, not evidence — and the absence of evidence is not reassurance.
    • One classic productivity figure, correctly caveated: The often-quoted finding that for every hour of direct clinical face time there are nearly two additional hours on EHR and desk work comes from Sinsky et al., Annals of Internal Medicine, 2016 — 57 physicians, 430 observed hours, four specialties, four states, with the authors noting the data came from self-selected, high-performing practices and may not be generalizable. It is a decade old and it did not study physical therapists. We cite it only as context, never as a current measurement of your clinic.

    None of this argues against building. It argues for building one read-only workflow with a measured baseline, a named write path, and a human boundary written down before the first line of code. The clinics that get value from agents are the ones that instrumented the before-state and picked a workflow where the result is countable in a quarter — which, in outpatient rehab, is almost always the three clocks.

    Putting It Into Practice

    A physical therapy clinic is not a booking business with a clinical layer on top. It is an episode business running against three independent expiry clocks, in which the most expensive events are silent: a certification that lapsed, a block that ran out two visits ago, a threshold crossed without a modifier. None of those is a hard problem for software. All of them are unowned.

    So the sequence is: measure the before-state, get a written answer on the write path, build the read-only clock watcher, make proof of transmission a retained artifact, then work outward to authorization packets and pre-submission checking. Keep the KX attestation, the signature and every clinical judgement with a licensed human, because statute and manual put them there and no vendor configuration moves them. And when a vendor hands you a percentage, ask for the denominator — in a category with no independent benchmark, that question is worth more than the number.

    A zero-click clinic is not an unstaffed one. It is a practice where the default administrative path completes without a human click, and humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal or safety decision. In outpatient rehab that means the calendars run themselves and the therapist never signs something a machine decided.

    A one-page diligence checklist.Take this into the vendor meeting. Every question has a verifiable answer, and a vendor's willingness to answer is itself data.

    1. 1.Who do you sell to?: Payers, providers, or both. If both, ask whether the payer business touches any plan you bill, and whether the company or its parent participates in the CMS WISeR model.
    2. 2.Name your integrations, and show me the page: Not logos. Named systems, on your own site, that I can read as text. Then show me a corroborating listing on the EHR vendor's marketplace.
    3. 3.Which of the four ePA channels do you use, per payer?: X12 278, FHIR/Da Vinci, portal automation, or fax and phone. Give me the list by payer for my top ten by volume.
    4. 4.How do you write into my EHR?: Commercial write API, UI automation, or a human. If UI automation, whose credentials? How many portals do you maintain and what is your mean time to repair after a portal redesign?
    5. 5.Send me the SOC 2 Type II report and the BAA before the demo: And the subcontractor list, including your model provider and its cloud host.
    6. 6.Will you run a retrospective on my last 500 claims?: On my payer mix, my worst faxes and my rehab EMR. Before contract, not after.
    7. 7.What is the denominator on every percentage in your deck?: Which payers, which service lines, what period, who audited it.
    8. 8.What can your agent physically not do?: Give me the tool list and the permission scope. I want the answer to include the KX modifier, the signature, and submitting to a payer as the submitting party.
    9. 9.Which specific payers' FHIR prior-authorization APIs will you consume in 2027?: Names and dates, in writing. Payer readiness is not your capability.
    10. 10.What is your rollback?: When your integration breaks, what happens to my worklist, how fast do I know, and who tells me?

    If a vendor answers all ten without hedging, you are dealing with a serious company. If it answers three and reframes the rest as roadmap, you have learned something worth more than the demo.

    One last word on where the liability sits. Nothing in federal law lets software be the licensed professional. Medicare's "incident to" rules define auxiliary personnel as an individual who meets state licensure requirements — software is not an individual, cannot be excluded by the OIG, and cannot hold a licence, so there is no incident-to pathway for AI-performed work. Corporate-practice statutes say artificial legal entities have no professional rights, privileges or powers. And Texas put the whole doctrine in five words when it permitted practitioners to use AI for diagnostic purposes only while acting within the scope of their licence, "regardless of the use of artificial intelligence," and only if the practitioner reviews all records created with it.

    The licence does not move. Neither does the liability. Build accordingly, and the rest of this is just engineering.

    Automating an Outpatient Rehab Clinic?

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. You leave with an EHR write-path feasibility read, a baseline measurement plan for the three clocks, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Automating an Outpatient Rehab Clinic?

    Book a free 60-minute discovery call. You leave with an EHR write-path feasibility read, a baseline measurement plan for the three clocks, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1Medicare Benefit Policy Manual, Chapter 15 — Covered Medical and Other Health Services (certification cadence, §220.1.3)
    2. 2Medicare Claims Processing Manual, Chapter 5 — Part B Outpatient Rehabilitation Billing (8-minute rule, GP/GO/GN, CQ/CO, MPPR)
    3. 3APTA — Medicare's New Exception to the Plan of Care Certification Requirement
    4. 4APTA — Medicare therapy payment thresholds (KX and targeted medical review)
    5. 5CMS National Correct Coding Initiative Policy Manual for Medicare Services, revision 1/1/2026
    6. 6CMS Medicare Program Integrity Manual, Chapter 3 §3.3.2.4 — Signature Requirements (practitioner concurrence for AI-captured entries)
    7. 7ONC/ASTP Certification Companion Guide — §170.315(g)(10) Standardized API for Patient and Population Services (read-only)
    8. 842 CFR §422.122 — Prior authorization API and denial-reason requirements for MA organizations (eCFR)
    9. 942 CFR §422.568 — Standard organization determination timeframes
    10. 10CMS Fact Sheet — Interoperability and Prior Authorization Final Rule (CMS-0057-F)
    11. 11CMS WISeR Model Provider and Supplier Operational Guide, version 7.0 (last updated July 24, 2026)
    12. 12WEDI Federal Update, July 27, 2026 (WISeR CRA outcome; CMS prior-auth metrics reporting)
    13. 13Georgetown CHIR — CMS's WISeR Model Faces Potential Repeal Following GAO Determination
    14. 14AMA 2025 Prior Authorization Physician Survey (PDF)
    15. 152025 CAQH Index — published by DataSpring (formerly CAQH)
    16. 162025 CAQH Index release, February 19, 2026 (GlobeNewswire)
    17. 17HL7 Da Vinci Prior Authorization Support (PAS) Implementation Guide v2.2.1
    18. 1821 U.S.C. §360j — device definition and the administrative-support exclusion, §360j(o)(1)(A) and (E)
    19. 19FDA — Clinical Decision Support Software, final guidance issued January 29, 2026 (PDF)
    20. 20FDA — Clinical Decision Support Software guidance landing page (docket FDA-2017-D-6569)
    21. 2142 CFR §410.26 — Services and supplies incident to a physician's professional services
    22. 2245 CFR §164.312 — HIPAA technical safeguards (access control, unique user identification, audit controls)
    23. 2345 CFR §160.103 — definition of business associate, including subcontractors
    24. 2445 CFR §92.210 — Nondiscrimination in the use of patient care decision support tools
    25. 25California AB 3030 — generative AI in patient communications (Health & Safety Code §1339.75)
    26. 26Texas SB 1188 — artificial intelligence in the electronic health record (Health & Safety Code §183.005)
    27. 27Texas HB 149 (TRAIGA) — §552.051(f) health care AI disclosure
    28. 28Colorado SB 26-189 — repeal and reenactment of the Colorado AI Act (bill page)
    29. 29Lee RW et al. — Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice. JAMA Netw Open. 2025;8(12):e2549963
    30. 30Clusmann J et al. — Prompt injection attacks on vision language models in oncology. Nat Commun. 2025;16:1239
    31. 31Waystar — investor release on the acquisition of Iodine Software
    32. 32Availity Essentials — provider portal product page
    33. 33Availity Essentials Plus — paid subscription tier (no price published)
    34. 34Novo Holdings — Availity investment (2021 purchase of Francisco Partners' minority stake)
    35. 35Infinx named top-scoring vendor in the KLAS Revenue Cycle Prior Authorization report (vendor announcement)
    36. 36KKR invests in healthcare revenue solutions provider Infinx (Businesswire, May 2024)
    37. 37Adonis raises $40M Series C (PR Newswire, March 25, 2026)
    38. 38Candid Health raises $120M Series D (MobiHealthNews)
    39. 39Infinitus Systems raises $51.5M Series C (PR Newswire)
    40. 40Latent raises $80M to close the gap between diagnosis and treatment (Businesswire, March 2026)
    41. 41Cohere Health — $90M Series C announcement
    42. 42Anterior closes $40M, bringing total funding to $64M (PR Newswire, February 2026)
    43. 43Medscape — State-Mandated 'Gold Card' Programs to Ease Prior Authorization Burdens Offer Little Relief, Experts Say
    44. 44Becker's — the '86% of denials are potentially avoidable' figure, traced to the Change Healthcare 2020 Denials Index
    45. 45Sinsky C et al. — Allocation of Physician Time in Ambulatory Practice. Ann Intern Med. 2016;165(11):753-760
    46. 46Enter.Health integrations page — the source of the 'supports all EHRs' claim, with no named EHR, PM system or clearinghouse
    Chris Machetto - CEO & Founder, Frenchy Digital of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2019 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.