Healthcare AI requires a Business Associate Agreement (BAA) covering both the platform and the underlying model provider. Anthropic and OpenAI both offer BAA-eligible enterprise tiers. Sandbox Platform offers a BAA for the infrastructure layer. Get both before you put PHI through the agent. This guide assumes you've signed both.
Hire an AI practice manager that verifies insurance eligibility before appointments, processes intake forms (extracting structured data into your EHR), and handles prior-auth submissions on payer portals. Cost: ~$250/month. Replaces 1-2 admin FTE for a 1-20 provider practice. HIPAA-aware: BAA required, audit trail standard.
Before and after
| Task | Manual process (today) | With Patty |
|---|---|---|
| Pre-appointment eligibility check | Admin logs into each payer portal individually. 38 patients × 7 min average = 4.4 hours of portal-clicking every morning. Frequently delayed or skipped, causing revenue-cycle problems at check-in. | Patty runs at 5 AM automatically. 38 patients verified by 6:30 AM. Flags 2 with issues to front desk. Admin arrives to a clean schedule instead of a checklist. |
| Prior authorization submission | Admin pulls the clinical chart, types or copy-pastes documentation into payer's web form, submits, transcribes the reference number into EHR. 25-40 min per PA. 10 PAs/day = 4+ hours of payer-portal work. | Provider orders MRI. Patty receives the order, extracts clinical justification from the chart, submits the PA with documentation attached. 3-8 min per PA. Admin reviews exceptions, not every submission. |
| Intake form → EHR entry | Patient fills out paper or PDF form. Admin manually re-types data into EHR — medications, allergies, medical history, insurance. 10-15 min/form. Common source of data-entry errors. | Patty reads the intake form, maps fields to EHR structure, pre-fills the record. Admin reviews the structured entry, corrects any ambiguity, approves. 1-2 min admin time. |
| Refill request triage | Admin reads each refill message, looks up last visit date, checks prescription history, manually types a response or routes to provider. 3-4 min each. 30 refills/day = 90-120 min of triage. | Patty reads each refill request, runs the protocol check (last visit, controlled-substance status, refill interval), flags controlled-substance or out-of-protocol requests for provider, approves routine refills for prescriber sign-off. Admin handles exceptions. |
| Denial management | Admin downloads denial EOBs, reads denial reasons, manually drafts appeal letters, collects supporting documentation, resubmits. Many denials never appealed due to time cost — lost revenue. | Patty monitors claim status, flags denials, classifies denial reason, drafts appeal letter with supporting documentation attached. Provider reviews and approves. Appeal rate increases because the bottleneck (human time) is removed. |
What it does
| Task | Volume / day at a typical practice | Time before | Time after |
|---|---|---|---|
| Insurance eligibility verification (24-48h pre-appointment) | 20-50 patients | 5-10 min/patient | 30-60 sec/patient |
| Prior authorization submission | 5-15/day | 20-45 min/auth | 3-8 min/auth |
| Intake form → EHR data entry | 10-30 forms | 10-15 min/form | 1-2 min/form |
| Patient-no-show follow-up | 3-10/day | 5 min/patient | 30 sec/patient |
| Refill request triage | 20-40/day | 2-4 min/request | 30-60 sec/request |
| Coding suggestions for visit notes (CPT/ICD) | 20-50 visits | 3-5 min/visit | 10-20 sec/visit |
A day in the life
Tuesday at a 4-doctor primary-care practice. Your AI practice manager is named "Patty":
- 5:00 AM: Patty wakes (cron). Pulls tomorrow's appointment schedule from the EHR. 38 patients on the schedule.
- 5:00-6:30 AM: For each patient, Patty logs into the relevant payer portal (Aetna, BCBS, Cigna, Humana, UHC, Medicaid), verifies eligibility, captures co-pay and deductible status, notes any plan changes since last visit. Updates the EHR with current eligibility status.
- 6:35 AM: Posts to
#front-deskSlack: "Tomorrow's eligibility check complete. 36/38 verified. Flagged: Pt MRN 1247 (lapsed coverage), Pt MRN 1851 (referral required). Front desk: please verify with these 2 before their appointments." - 9:15 AM: Provider orders MRI for a patient. Order hits Patty's queue.
- 9:18 AM: Patty pulls the patient's record, reviews recent notes for clinical justification, drafts the prior-auth request with attached documentation.
- 9:21 AM: Logs into payer's PA portal, submits the request, captures the reference number.
- 9:23 AM: Posts in EHR: "PA submitted, ref #ABC123. Expected response: 24-72h. Will follow up."
- 11:42 AM: Refill request comes in for a patient. Patty checks: last visit, last refill date, controlled-substance status, refill protocols.
- 11:43 AM: Routine non-controlled refill, within protocol. Drafts approval, queues for prescriber sign-off.
- 11:43 AM: Different refill: controlled substance, last visit was 8 months ago. Patty stops, posts in EHR: "Pt requesting [med] refill. Last visit 8mo ago, controlled substance. Recommend office visit before refill — flagged for provider review."
- 5:00 PM: Daily summary to
#admin-summary: today's eligibility checks, PAs submitted, refills processed, no-shows followed up, items needing attention.
The human practice manager's day shifts from 80% data-entry / portal-clicking to 80% exception handling and patient-facing problem solving. The work she likes; not the work she dreaded.
Scenario 2: A specialty practice's denial week
Thursday at an orthopedic surgery practice. 18 MRI authorizations were denied this week. Normally: the billing manager's entire week, most appeals never filed.
- Tuesday morning: Patty monitors claim status updates from Cigna, Aetna, UHC. Flags 18 denials. Classifies each: 11 "medical necessity — additional documentation required," 5 "coding mismatch," 2 "eligibility at date of service."
- Tuesday 8:30 AM: Patty posts in
#billing-alerts: "18 denials this week. Breakdown: 11 medical necessity (draft appeals ready for provider review), 5 coding (queued for billing team review), 2 eligibility (patient coverage gaps — front desk needs to contact patients). Preview appeals in the billing portal." - Tuesday 9:00 AM: Billing manager opens the 11 medical-necessity appeals. Each has: the denial letter, the clinical notes Patty pulled from the chart, the appeal letter Patty drafted citing relevant CPT guidelines and clinical justification. Review time: 3-5 min per appeal instead of 25 min.
- Tuesday 10:30 AM: Billing manager approves 9 appeals, edits 2, submits all 11. Would have taken most of the week; done before lunch.
- Wednesday: Patty follows up on the 5 coding denials. 3 were admin mismatches — Patty resubmits with corrected codes. 2 require clinical review — escalated to the ordering surgeon.
Appeals filed on time are the difference between collected revenue and written-off revenue. Patty makes appeals economically viable for every denial, not just the high-value ones.
Cost math
| Component | Monthly cost |
|---|---|
| Sandbox compute (ab0t.medium, ~6 hrs/day active) | $15 |
| Model API (Claude Sonnet 4.6, BAA-covered enterprise tier) | $160 |
| Sandbox Platform (with BAA, healthcare tier) | $75 |
| Storage + audit log (HIPAA retention) | $5 |
| Total | $250-280/mo |
Compare to a 1.5-FTE admin team at $5,500/mo each = $8,250/mo human cost. ~30× the leverage. The freed-up admin staff are available for patient-facing work (calls, scheduling, in-person assistance) — work that can't be delegated.
For practices with claims volumes that justify it, AI eligibility-verification alone often pays for the agent in days through reduced denials and write-offs.
ROI table: 4-provider primary-care practice, 40 patients/day
| Task | Human time (before) | Admin time (after) | Hours saved/month |
|---|---|---|---|
| Eligibility verification (38/day) | 4.5 hr/day × 20 days = 90 hr | 0.3 hr review × 20 = 6 hr | 84 hr |
| Prior auth submissions (10/day) | 4.5 hr/day × 20 = 90 hr | 0.5 hr exceptions × 20 = 10 hr | 80 hr |
| Intake data entry (20/day) | 3.5 hr/day × 20 = 70 hr | 0.4 hr review × 20 = 8 hr | 62 hr |
| Refill triage (30/day) | 1.5 hr/day × 20 = 30 hr | 0.3 hr exceptions × 20 = 6 hr | 24 hr |
| Denial management (8/week) | 2.5 hr/week × 4 = 10 hr | 0.5 hr approval × 4 = 2 hr | 8 hr |
| Total | 290 hr/month | 32 hr/month | 258 hr/month |
258 admin hours/month recaptured. At $25/hr admin cost = $6,450/month in recovered admin capacity at a cost of $250/month. 26× leverage — before counting the revenue recovered through higher appeal rates and fewer eligibility write-offs.
The revenue-side math often exceeds the labor savings: a practice that increases its appeal rate from 30% to 75% on 50 denials/month at an average value of $800/denial recovers an additional $18,000/month in net revenue.
Practice-type customization
Patty's CLAUDE.md should reflect your specialty's specific protocols, payer mix, and compliance requirements:
| Specialty | Key CLAUDE.md configuration | High-volume tasks | Extra compliance notes |
|---|---|---|---|
| Primary care / family medicine | Refill protocols by drug class, preventive care reminder templates, chronic disease management follow-up sequences, vaccine reminder workflows | Eligibility, refills, intake entry, appointment reminders | Standard HIPAA. Controlled-substance refills escalate to provider — always. |
| Behavioral health / therapy | 42 CFR Part 2 SUD record-handling rules, state-specific mental health note confidentiality, consent-before-disclosure rules baked in at every step | PA for ongoing therapy sessions, insurance benefit verification (mental health parity), appointment reminders that don't reveal diagnosis in subject lines | 42 CFR Part 2 for SUD records. Many states have stricter mental health confidentiality than HIPAA. CLAUDE.md must reflect this explicitly. |
| Orthopedics / surgical specialty | Prior-auth templates for common procedures (MRI, surgical interventions), coding library (CPT/ICD for common diagnoses), post-op follow-up sequences, implant/device documentation workflows | Prior auth (high volume, complex documentation), denial management, pre-surgical eligibility verification | Standard HIPAA. Device implant documentation has specific retention rules. |
| Dental | Dental-specific payer integrations (Delta Dental, MetLife, Cigna Dental), X-ray attachment workflows for PA, treatment-plan estimate generation | Benefits verification (annual maximum, frequency limits), pre-auth for major restorative work, treatment plan communication | Dental records fall under HIPAA if the practice submits electronic claims. Confirm BAA scope with your vendor. |
| Optometry | Vision plan benefit breakdowns (VSP, EyeMed, Davis), frame/lens eligibility, contact lens protocol rules, annual exam reminder sequences | Vision plan eligibility, annual exam reminders, lens/frame benefit verification | Same HIPAA scope as dental — electronic claims = covered entity. |
HIPAA setup (the one-time work)
Before any PHI flows through the agent, you need:
- BAA with Sandbox Platform — covers the infrastructure layer. Request from sales; usually signed in 1-2 days.
- BAA with the model provider — Anthropic and OpenAI both have BAA-eligible enterprise tiers. Free tier and consumer tier are not HIPAA-eligible. Make sure your agent is configured to use the BAA-covered endpoints.
- BAA with any third-party integrations — your EHR vendor, your payer-portal aggregator (Availity, Change Healthcare, etc.), any clearinghouse.
- Audit log retention — 6 years minimum (the HIPAA standard). Sandbox Platform's audit retention is configurable; set it to 7 years to be safe.
- Access controls — only authorized practice staff have dashboard access. The IT person sets this with role-based access in the workspace.
- De-identification rules — for any data leaving the BAA-covered boundary (e.g. analytics dashboards), de-identify. The agent's CLAUDE.md should include "never include PHI in non-BAA-covered destinations."
This setup is operator-domain (you sign the BAAs) + IT-person (technical configuration). Budget half a day for the operator side, an hour for the IT side. Once done, it's evergreen.
Onboarding
- Sign BAAs (above).
- Sign in to Sandbox Platform's healthcare workspace tier. Use the "Healthcare Practice Manager" template.
- Connect your EHR (Athena, eClinicalWorks, Epic, NextGen, DrChrono — all major US EHRs supported). Some require a one-time API approval through your EHR vendor.
- Connect payer portals via your clearinghouse (Availity / Change Healthcare). If you don't have a clearinghouse, the agent can log into payer portals directly with stored credentials, but a clearinghouse simplifies things.
- Customize CLAUDE.md: your specialty, your protocols (refill rules, PA submission templates), your escalation policy.
- Run dry-run on yesterday's eligibility checks to verify the agent matches your team's output.
Total: 1-2 hours including dry-run. Most of the time is in the EHR API approval, which is an external dependency.
30-day supervised trial
| Week | What Patty does | What you do | Goal |
|---|---|---|---|
| Week 1 | Runs eligibility checks in shadow mode — produces results but no EHR writes, no patient contact. | Compare Patty's eligibility output to your team's manual output. Note discrepancies. | Calibrate: Patty's results should match yours 95%+ before going live. |
| Week 2 | Drafts PA submissions for every order — shadow only, no submissions yet. | Review drafts against what you'd actually submit. Update PA templates in CLAUDE.md. | PA draft quality should reach submit-with-minor-edits level before going live. |
| Week 3 | First live eligibility runs. First live PA submissions with your approval step on every one. | Approve each PA before it submits. 100% oversight — this is the first real-world test. | Expect 2-3 CLAUDE.md adjustments based on live PA results. Normal. |
| Week 4 | Handles intake triage, refill triage with your approval gate on escalations and borderline cases. | Move from approving everything to approving exceptions. Spot-check 30% of routine approvals. | End of Week 4: Patty in production on all core tasks with human exception gate. |
| Month 2+ | Autonomous on routine eligibility, PA for established procedure types, refill triage. Escalates exceptions. | Monthly CLAUDE.md review. Audit random sample of 10 actions/week. Handle escalations. | Target: admin spends 1-2 hr/day supervising Patty vs 6-7 hr/day doing what Patty does. |
What goes in Patty's CLAUDE.md
You are Patty, the AI practice manager at [Practice Name], a 4-provider primary-care practice in [City, State] specializing in family medicine and preventive care.
HIPAA boundary (mandatory): You are operating under a signed BAA. All PHI access is logged. Never send PHI to any destination not covered by our BAA. If a workflow would require transmitting PHI outside the covered stack, stop and escalate to [Practice Manager Name].
What you can do: Verify insurance eligibility for scheduled patients. Submit prior authorizations with clinical documentation. Process intake forms into EHR-structured data. Triage refill requests per protocol below. Draft denial appeal letters. Send appointment reminders from approved templates. Draft no-show follow-up messages. Post daily summary to #admin-summary Slack.
Refill protocol: Routine non-controlled refills within protocol: flag for prescriber sign-off, no additional review needed. Controlled substances: always escalate to prescriber with last-visit date and prescription history. Out-of-protocol (>90-day refill, dose increase): escalate to provider. Any refill where the patient hasn't been seen in 12+ months: escalate with note.
Escalate to [Practice Manager] when: A patient expresses distress or urgent clinical need. A payer portal behaves unexpectedly. A PA is denied and the denial reason requires clinical input. Any action that would send patient-facing communication outside the approved templates.
Payer credentials: Stored in the workspace secrets manager. Do not log credential values anywhere.
What Patty doesn't do
- Diagnose anything. Patty does admin; medical decisions are provider-only.
- Approve controlled-substance refills. Always escalates to the prescriber.
- Discuss clinical care with patients. Routes clinical questions to the appropriate clinician.
- Make coverage decisions. Reports payer determinations; doesn't appeal autonomously.
- Handle patient escalations or emotional issues. Routes to a human staff member.
- Anything in violation of state-specific telehealth/scope-of-practice rules. Varies; check your state.
How this compares to existing healthcare automation
| Vendor | Best for | Pricing |
|---|---|---|
| Phreesia / Solv | Patient intake, scheduling | $200-1500/mo per location |
| Cohere / Olive (legacy) | Prior auth automation, large hospitals | Enterprise contracts |
| Eligible / Availity | Eligibility-verification clearinghouses (you'd use this WITH Patty, not instead) | Per-transaction |
| Sandbox Platform (this guide) | Mid-market practices wanting customizable, owned, audit-trail-included automation | ~$250/mo per agent |
Patty isn't replacing your clearinghouse — she's calling them. The differentiation is the breadth of work and the customization.
Common mistakes practices make
- Skipping the BAA before go-live. It happens. Someone sets up the workspace, it's working great, and they go live with patient data before the paperwork is complete. PHI flowing through an agent without a BAA is a HIPAA breach regardless of how good the technical controls are. Sign the BAAs first. Day one. No exceptions.
- Not configuring the refill escalation protocol in CLAUDE.md. Without explicit refill rules, Patty defaults to conservative behavior (escalate everything) or optimistic behavior (approve everything). Neither is right for your practice. Write your refill protocol explicitly: which drug classes, what refill intervals, which scenarios require provider review. This is the single most important CLAUDE.md section for primary care.
- Expecting Patty to replace the clearinghouse. Patty calls your clearinghouse — she's not a replacement for it. If you're using a direct-to-payer submission approach (unusual), Patty can handle portal submission directly, but most practices have a clearinghouse already. The two work together.
- Going live on PA submissions without shadow-mode validation first. PA submissions that go to payers carry your practice's name and authorization. A PA with wrong clinical documentation or wrong payer fields doesn't just get denied — it can raise flags with the payer. Run shadow mode for at least 2 weeks, compare outputs to your manual submissions, before going live.
- Not configuring behavioral health extra-confidentiality rules for mixed-specialty practices. If your practice sees any behavioral health patients alongside medical patients, 42 CFR Part 2 SUD rules and state mental health confidentiality rules apply to those records specifically. A general CLAUDE.md without these rules will treat behavioral health records the same as medical records. This is the compliance risk most practices discover after go-live, not before.
- Ignoring payer portal UI-change alerts. When a payer redesigns their portal, Patty logs a failure and generates an alert. Practices that treat these as low-priority tickets end up with PA backlogs. The fix is usually a 30-minute IT task to update the portal adapter. Treat these alerts with the same urgency as a billing alert.
Frequently asked questions
Is this HIPAA-compliant?
HIPAA compliance is a property of your deployment, not the platform alone. With BAAs signed (Sandbox Platform + model provider + EHR + clearinghouse), technical controls in place (encryption at rest and in transit, audit log, access controls), and your administrative procedures (policies, training, incident response), the deployment is HIPAA-compliant. We provide the technical infrastructure; you own the administrative side.
What about state-specific privacy laws like CMIA in California?
Varies by state. Most state laws layer on top of HIPAA's framework. The platform's configurability supports stricter requirements including data residency, retention windows, and access scoping. Your compliance counsel should review state-specific requirements before go-live in regulated states.
Can Patty work with Epic or Cerner?
If your EHR has a documented API (FHIR is the 2026 standard), yes. The integration tab lists supported EHRs out of the box. For less common systems, the platform supports custom API connectors. Most practices are connected within 1-2 days.
What if a payer portal doesn't have an API?
Common problem — many smaller payers have humans-only portals. Patty uses the platform's browser-automation capability to navigate the portal as a human would (login, fill forms, submit, capture confirmation). More brittle than API calls — portal redesigns can break flows — but works for the long tail of payers.
How do I audit what Patty did with patient data?
Every action — every PHI access, every portal login, every record write — is logged in the audit trail with timestamp, user context, and action taken. The dashboard is filterable by patient MRN, date range, and action type. 7-year retention recommended.
What if Patty makes a billing error?
Same as if a human admin made one — the practice corrects it through normal claims-correction workflows. The audit log shows exactly what Patty did and when, making correction faster than tracing a human's mistake. Patty is not a final decision-maker; billing team reviews her work.
Can Patty handle denial management and appeals?
Yes, with a denial-management workflow configured in CLAUDE.md. Patty monitors claim status, flags denials, classifies denial reason, drafts the appeal letter with supporting documentation, and queues for physician or billing staff sign-off. Appeals are human-approved before submission. Appeal rates increase because the bottleneck — human time — is removed.
What about mental health practices — any extra requirements?
42 CFR Part 2 governs substance-use-disorder records and imposes stricter consent requirements than HIPAA. If your practice handles SUD records, configure Patty to segregate those records and require explicit consent before any disclosure. State mental health confidentiality laws may impose additional requirements. Review with your compliance attorney before go-live.
Is the $250/month cost per provider or per practice?
Per Patty instance — one AI employee serving the entire practice. A 4-provider primary-care practice shares one Patty at $250/month total. Above 20 providers or with extreme volume (100+ PAs/day), consider 2 instances split by specialty or function.
How does Patty handle complex multi-payer scenarios?
Patty maintains per-payer credentials in the encrypted secrets store and uses separate browser sessions for each payer portal. For coordination-of-benefits scenarios (patient has two insurers), she submits in the correct primary/secondary order as configured in CLAUDE.md. Multi-payer workflows are among the highest-value automation targets since they're the most tedious for human staff.
Can Patty help with charge capture and coding?
Yes — Patty can review visit notes and suggest CPT and ICD-10 codes based on documented diagnoses and procedures. Suggestions go to the billing team for review before claim submission. Improves capture rates and reduces coding time without removing the billing team's approval step.
What happens when a prior auth is denied?
Patty flags the denial in the EHR, classifies the denial reason, and notifies the relevant provider via Slack. She prepares a denial summary memo with the payer's stated reason, the relevant clinical documentation on file, and a draft appeal outline. Provider reviews, adds clinical argument, approves appeal, and Patty submits.
How does Patty stay current with payer-portal UI changes?
Browser automation is inherently fragile to portal redesigns. Patty logs failures with screenshots and generates an alert to your IT contact. The platform's portal-adapter library is maintained centrally — major payer portal updates are patched within 1-3 business days of the redesign. Treat portal-change alerts with billing-alert urgency.
Can Patty send appointment reminders?
Yes — add appointment reminder workflows to CLAUDE.md. Patty sends SMS/email reminders at configurable intervals (48h, 24h, 2h before appointment), handles confirmation responses, updates the schedule for confirmed/cancellations, and auto-fills newly opened slots from the waitlist. Patient communication uses approved templates — not free-form generation.
What's the onboarding timeline?
Week 1: BAA signing, workspace setup, EHR connection (may take a day for EHR API approval). Week 2: payer portal connections, CLAUDE.md customization, dry-run testing. Week 3: shadow mode. Week 4: first live tasks with 100% human approval gate. Month 2: spot-check supervision on routine tasks.
What's next
Hire your AI practice manager
Sign the BAAs, set up in 2 hours, save 1.5 FTE worth of admin overhead.
Open Dashboard