The platform underneath the service.
Most RCM vendors run their service on someone else's software. We built ours. Credential OS is our credentialing operating system. Eight specialized AI tools work the revenue cycle from eligibility to AR. Every PHI byte at rest is encrypted with AES-256-GCM, every AI call passes through a single audited LLM Gateway, and every code, claim, and credential decision carries the source evidence that produced it.
Four layers. One audit boundary.
The platform is layered intentionally. Specialist AI models live in the top layer. Every model call passes through the LLM Gateway in the third layer, which carries the audit log, cost meter, prompt registry, model router, and PHI scrubber. Below that sit the platform applications, with Credential OS as the credentialing OS that also powers Verification Network primitives across the suite. The bottom layer is the HIPAA-eligible foundation: encryption at rest, row-level RBAC, PHI access log, and signed BAAs all the way down the chain.
When the CFO asks what AI spent this month, the answer comes from one log. When the compliance officer asks for the model version behind a specific code, the answer comes from one query. When the security team asks what data left the building, the answer is none.
Every technology pillar, with one source of truth.
The platform decomposes into fourteen pillars. Credential OS is the credentialing OS we built in-house, featured below. The other thirteen pillars are the operating capabilities that move dollars across eligibility, denial prevention, coding, reconciliation, and AR. Each pillar links to a dedicated deep-dive page with the architecture, the metrics, and the integration map.
Credential OS Credentialing OS
Twelve sub-capabilities: NPI auto-enrichment, AI doc extraction, Pre-Flight Validator, Revenue-at-Risk, LLM Gateway, MCP server, RS256 Passport, Verification Network, WhatsApp/SMS, NPDB, CAQH sync.
22-day BCBA TAT →Coding engine
CPT, HCPCS, modifier suggestions with documentation evidence. ABA-tuned for 97151 family. Three-way match against auth, supervision, and notes.
M-05 · AI →Eligibility 270/271
Continuous coverage verification. Mid-cycle plan migration detection. Pre-visit benefit detail per appointment, by service code. Sub-300 ms round-trip.
M-04 · AI →Denial prediction
Risk score per claim before submission. 80+ root cause patterns by payer, CPT, region. Auto-routes high-risk claims for prevention work.
M-03 · AI →Security architecture
AES-256-GCM PHI at rest. RS256 asymmetric signing. PHI access log. Boot-time secret guard. Six §164.312 controls implemented in code.
HIPAA →API & FHIR
RESTful API. FHIR-native bidirectional with 6 major EHRs. HL7 and 837 fallback for 12 more. Webhook events for real-time downstream sync.
REST · FHIR →Cloud architecture
HIPAA-eligible AWS. Multi-AZ Postgres RDS. ECS Fargate compute. CloudFront edge. Secrets Manager. Reference architecture documented.
AWS →EHR integration
Epic, Cerner, Athena, eClinicalWorks, NextGen, Greenway native. 12 additional platforms via HL7. Same-app prompts, no swivel chair.
FHIR · HL7 →Claim status 276/277
Live status pull from clearinghouse on submitted claims. Auto-categorizes payer-side stalls. Surfaces stuck claims before they age into the next aging bucket.
Auto-poll →Reconciliation AI
Line-level 835/837 matching. Surfaces partial payments, contractual variances, takebacks, bundling issues. 98 percent auto-post rate.
M-07 · AI →Root cause analytics
Denial patterns by payer, CPT, provider, pod, location. Pareto rollups for monthly leadership readout. Feeds CDI and clinician education loops.
Analytics →AR workflow AI
Follow-up queue prioritized by recoverable dollars, not days. Predicts call outcome before dial. AR follow-up productivity up 2.4x measured.
M-08 · AI →Implementation playbook
14-day go-live framework. EHR connection, payer setup, BAA chain, user provisioning. Reference implementations documented.
14-day →SLA & uptime
99.9 percent platform uptime SLA. Quarterly DR drills, documented RTO/RPO. Daily encrypted cross-AZ backups. Status page for clients.
99.9% →HIPAA technical safeguards, tested every release.
Most healthcare platforms list HIPAA compliance as a marketing bullet. We mapped the §164.312 technical safeguards rule to specific platform behaviors that can be tested by automated regression suites. The card to the left is the actual control list, not a roadmap. Each one is implemented in code, exercised on every release, and documented in HIPAA_SECURITY.md.
We are explicit about the boundary. Technical safeguards inside the platform are necessary but not sufficient. Hosting on HIPAA-eligible AWS, signed Business Associate Agreements with each sub-processor, organizational risk analysis, and workforce training are required to call an operation HIPAA-compliant. We document those organizational responsibilities so they do not silently become your problem post-signing.
What runs under the hood.
Mature, boring, well-instrumented technology choices. No bleeding-edge platforms in production. Every component below is widely deployed and well understood by experienced engineering teams.
Application layer
- FrontendReact + Vite + TS
- BackendSpring Boot · Java 17
- DatabasePostgreSQL 15+
- MigrationsFlyway · 70+ versioned
- API styleREST + FHIR
- MobilePWA · iOS + Android
- MCPJSON-RPC 2.0 native
Infrastructure
- CloudAWS · HIPAA-eligible
- ComputeECS Fargate
- DatabaseRDS Multi-AZ
- EdgeCloudFront + WAF
- SecretsSecrets Manager
- BackupDaily encrypted · cross-AZ
- Uptime SLA99.9%
AI & integrations
- Model providerAnthropic Claude
- GatewayIn-house LLM Gateway
- AuditPer-call log · cost · latency
- EHR integrationsFHIR · HL7 · 837
- Payer connections1,200+ via clearinghouse
- CredentialingCAQH · NPDB · NPPES
- MessagingTwilio · WhatsApp + SMS
Frequently asked questions: the technology platform.
What is the technology stack you actually run?
How does the platform integrate with our EHR?
What is Credential OS and how does it fit into the platform?
How do you handle PHI and HIPAA?
What are the platform performance benchmarks?
What about uptime and SLAs?
Can we audit the platform before signing?
Do we get our data out if we leave?
We built the platform. Let us show you the code.
A free technology audit. CTO walkthrough of the architecture, the §164.312 control mapping, and the LLM Gateway audit pattern. No NDA wall, no sales deck. The same documents we share in serious diligence.