The Hospital Finance Podcast

Besler Holdings

If you’re concerned about revenue at your hospital, then The Hospital Finance podcast is your go-to source for information and insights that can help you protect and enhance the revenue your hospital has earned. From regulatory changes to revenue cycle optimization, readmissions to bundled payments, you’ll get important perspectives, news and strategies from leading experts in healthcare finance. For show notes and additional resources from Besler Holdings, visit https://www.besler.holdings/podcasts.

  1. 2d ago

    Locking Down Corporate AI Usage Webinar

    ← Back to All Podcasts Locking Down Corporate AI Usage Webinar In this episode, Jason Nadal, Besler Holdings’ and Sypher Security’s Information Security Officer, will provide us with a glimpse into the next Hospital Finance Academy Webinar, “Locking Down Corporate AI Usage,” live on Wednesday, October 7th, at 1 PM ET. Highlights of this episode include: How companies deal with artificial intelligence and how they should make the decision to embrace this technology What the benefits and detriments of AI usage are What tools out there to help protect your company and your data What other challenges you have in keeping aware of AI usage How you manage third parties not directly under your control The key takeaways Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome back Jason Nadal, Besler Holdings’ and Sypher Security’s Information Security Officer. In this episode, Jason will provide us with a glimpse into our next Hospital Finance Academy Webinar, “Locking Down Corporate AI Usage,” live on Wednesday, October 7th, at 1 PM Eastern Time. Welcome back, and thank you for joining us, Jason. Jason Nadal: Hi. Thanks for having me. Kelly: All right. Well, let’s go ahead and jump in. So, we know artificial intelligence is everywhere now. How should companies deal with this and make the decision to embrace this technology? Jason: Well, if you run a company right now, somebody on your team is likely already using AI. So ideally, that would be via an approved path that you have already set up, but maybe it’s just a browser tab they opened up at lunch, putting something in Google and getting AI results. Either way, the question is not, “Should we use AI?” It’s already embedded in a lot of the approved corporate tools that are already out there. So, the question is, “Do we know what we allow, what we forbid, and how do we keep that promise when the tools keep changing under our feet?” So those are the kinds of conversations that security and IT folks have when leadership asks for a practical plan around AI. So, over the next 10 minutes or so, I’ll walk through some of the benefits and risks. We’ll get into that a bit deeper during the webinar that’s upcoming, but this will give you a methodology of control you can actually run, some of the categories of tooling that support it, and the challenge of feature creep in tools that you’ve already approved. And we’re also going to look at how a vendor and open-source software assessment has to catch up. Kelly: Yeah. I mean, it is really everywhere. It’s embedded in everything now, it seems like. [laughter] Yeah. It’s a lot to keep up with. So, what are the benefits and detriments of AI usage? Jason: Sure. There’s a lot of benefits, and there’s definitely a lot of detriments as well. So, AI earns its value when it shortens the work that you’re already doing, especially that work that used to waste a lot of your time through just tedium, repeated tasks, and things like that. So, I find it really shines at drafting, summarizing, searching or researching, coding assists, and also triaging helpdesk tickets. So those are real-time gains when the data and the use case match the risk. So, in healthcare and adjacent work, that might be a little less clear. So, a nurse or revenue cycle analyst can summarize a long chart note, draft a patient letter, or speed up some prior auth paperwork. A cost report or appeals team can find patterns faster. So done carefully, ideally with this human oversight as to what’s produced, that is time returned to care and to accurate billing. But the downside is just as concrete. So, paste the wrong note into a public chatbot, and you may have moved protected health information, PHI, or something else confidential or sensitive, outside your control. So, a helpful summarizer can invent a fact, called hallucinations, that then gets treated like clinical or financial truth. There’s really a huge downside to that if it’s not checked over by humans with clinical experience. An automation that writes into scheduling, ticketing, or an EHR-adjacent system can turn a bad model answer into a real patient or operations problem. Outside of healthcare, the pattern is much the same. So, marketing could paste customer lists into a public model. Finance could paste financial forecasts. Engineering could paste source code or API keys, maybe in a hurry or just this one time, and leak information that you don’t really intend to leak. Legal can paste contract language. You get the benefit of speed, but the detriment of leaking your data, over trusting the AI, and a trail that, once it’s out there, you can’t really tidy it up after the fact. So, a key point to establishing governance is having frank discussions of what data is acceptable to this risk if it were to leak. I really can’t say that one enough. Kelly: Yeah, I mean, I know that in marketing we use it quite a bit, but I mean, you all help us really understand what we’re really in for there. So, I know there’s a lot to keep in mind. So how do you lock this down without pretending people will stop being curious? Jason: So yeah, you do need this methodology. The first thing I’d say, write an AI usage statement. This is your company’s position on how AI is used. Let it have plain language that’s easily readable. And this company position will include what interactions are allowed and what are not. Who’s able to use what classes of AI? What data classes may never leave the building? It may not just be PHI or employee data. It could be financials, as we said before, or just confidential mergers and acquisition information. So, what AI interactions require a human in the loop? What happens when someone isn’t sure? They should always be trained to ask before they just paste data in somewhere. Publish this conspicuously, train on it, and make sure that people know what’s appropriate to do with their AI. Refresh it when the landscape moves. So, if you don’t have a written position, every employee is going to have their own assumptions on what is good or bad. That’s not really empowerment. That’s just risk that’s out there unmanaged. I’d also recommend don’t write this usage statement from scratch. See what others in the industry, especially your industry, are doing, and tailor what’s out there to yourself. Secondly, you should assess the AI that is in question, the AI that you want to use in any given situation. When a third party uses AI in a product that you buy, treat that as part of vendor due diligence. Ask the vendor, “Where are these models running?” Ask whether the prompts or the outputs of those prompts are retained with them or are they used for training. Ask about sub-processors. Maybe that vendor is using somebody else to do their AI work. Ask also whether AI features can write back into your system. Don’t just accept a blanket, “We’re AI-powered,” as a checkbox. You need enough clarity to decide, yes, this is an acceptable risk. No, this isn’t going to work for us. Or yes, but we need these conditions in place to feel good about the risk of using this tool. And keep logs. Review those regularly. What is not AI today might become AI tomorrow. I’m sure all of us have seen an application that we’ve used online that just, after approved, suddenly has new AI functionality. So, train your users to notice new AI functionality added to the products that they already use. Third, you want to control access to your systems. And there are different types of access that you need to be aware of all three of these and looking into where AI touches all of these. First off, private access. This is ideal if you’re using sensitive data. Your employees would then be using AI that is hosted locally within company boundaries. Private model and private instance, your network. You can still govern who can use it, what data they may feed it, and how you log that use. Just because it’s private doesn’t mean it’s unsupervised, but at least you can keep the inner boundaries of where that data can go. Next up would be public access, people reaching third-party AI sites out in the open internet. So, you decide who can get there under what policy and how that policy stays current when new sites appear every week. So, blocking everything forever, that’s rarely an answer. But blind open access is worse. Pick that controlled path and make sure you maintain who has proper access to it. And internal access is different from private. So, this is AI that’s baked into platforms you’ve already approved. Productivity suites, especially CRMs, ticketing, EHR add-ons, collaboration tools, all of these are things that we’ve seen ripe targets to add AI functionality to. Again, the purpose is to make them easier to use, but you need to make sure you maintain the risk of that if it wasn’t there when you initially assessed that vendor. So, it could be somebody just flipped a feature flag or a vendor released a sidebar assistant. It’s not really a new public chatbot to evaluate from scratch, but there could be changes to what models are being used and the risks associated with that. So, you should treat it as a change to an approved system. You should have that same change management, the same risk review that you do for a new vendor, the same data classification questions. So, if you’re only policing public websites, you’re going to miss that AI that arrived inside your door because you’ve already let it in. Fourth, control AI access to your data. The data classification is very important. Label what your data type is. Is this file public? Is this one confide

  2. 4d ago

    Healthcare Has a Revenue Problem, But It's Really a Decision Problem

    ← Back to All Podcasts Healthcare Has a Revenue Problem, But It’s Really a Decision Problem In this episode, Angelica Landers, Healthcare Executive & Growth Strategist, discusses how healthcare has a revenue problem, but it’s really a decision problem. Highlights of this episode include: Before a hospital or healthcare organization launches a new service line, what financial questions should leadership answer first How to determine whether the service is actually worth offering Will the service actually make money? How to determine whether your payer mix can support a service line or business model before you invest significant capital into it How healthcare organizations can build stronger relationships with their payers to improve reimbursement and resolve issues What a true service line profitability analysis looks like What the financial and operational questions you want answered before you ever get to the purchase price When a healthcare organization is trying to grow, how do to decide whether to build internally, acquire another organization, or partner with someone else Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome Angelica Landers. Angie is a healthcare executive and growth strategist with more than 18 years of experience working at the intersection of healthcare operations, sales, M&A, revenue cycle, technology, and startup growth. Her experience spans provider organizations, MSOs, DSOs, digital health, telehealth, healthcare technology, and high-growth startups. She has directed 58 concurrent M&A integrations, managed revenue cycle operations generating up to $45 million in monthly collections, sold more than $500 million in managed services agreements, and built scalable operating models for healthcare organizations navigating growth and transformation. Angie brings a unique perspective that connects the financial decision to the operational reality behind it. Her work includes acquisition strategy and integration, revenue cycle transformation, payer and reimbursement strategy, healthcare commercialization, P&L and financial analysis, operational scalability, strategic partnerships, and startup growth. Through Alleviate Strategy & Solutions, Angie advises healthcare executives, investors, founders, and growth-stage organizations on the systems behind performance, helping them make better decisions about growth, acquisitions, technology, operations, and revenue. In this episode, we’re discussing: Healthcare has a revenue problem, but it’s really a decision problem. Welcome, and thank you for joining us, Angie. Angelica Landers: Thank you for having me, Kelly. I’m so excited to be here today. Kelly: Yeah, we’re excited to have you. Well, let’s go ahead and jump in. So, healthcare finance isn’t just about collecting the money. It’s about making better decisions before the service ever happens. Before a hospital or healthcare organization launches a new service line, what financial questions should leadership answer first, and how do you determine whether the service is actually worth offering? Angelica: When everyone first proposes this question, everyone automatically assumes demand or growth equals revenue. And when everyone assumes this, before everyone can get their answers out, the CFO walks in and asks the most difficult question, but I would say the most correct question. Will this service actually make money, given our payer mix, our cost structure, and our referral patterns? Or, in just the shorthand question, is this a profitable demand? Will we make money, or our ROI off of implementing this new service? So, a service line can have strong community need, excellent clinical outcomes. Your neighbor practices might be doing this, and you might have heard of their uplift in revenue. You might have heard of their growing patient population. But are those transferable to your practice is the question. Before launching any new service, leadership must determine whether the opportunity creates that sustainable economic value within their practice. So, the goal is not simply to generate revenue. The goal is to generate revenue that exceeds the cost of care. By the time a claim reaches your billing department, leadership has to make these decisions beforehand that determine whether that claim is profitable or payable. So many healthcare organizations, to start with demand is great, but we should also look at margin. Kelly: Right. No, I mean, I love what you said. I wrote it down. Will the service actually make money? It’s a great question. Angelica: Yeah. Kelly: So how do you determine whether your payer mix can support a service line or business model before you invest significant capital into it? Angelica: Yeah, so I would start with the obvious question, is there really a revenue opportunity? There’s a series of analyses and just questions that leadership should go through, grouped together with their committee, their investors, and really go through each variable of economic value. So, starting with, obviously, what service to offer? Everyone is being innovative in the healthcare industry. Within tech, the startup rise of telehealth, value-based care, I mean, all of this brings different payment models, different strategies, different positions you can bring to your practice. But the key question here is, does this service create strategic and financial value, again, to your unique situation? Not every clinical service creates that economic value. Some services just generate direct profit. They create downstream referrals, straighten payer relationships, even support other strategic growths. So, looking at just the variable of, ‘How much does this service make by revenue position?’ isn’t the entire story. Leadership should evaluate community need, of course, competitors’ offerings, strategic alignment. But a service with moderate demand and strong reimbursement may outperform a high-demand service with weak reimbursement. I would say look at both the economical value and also the community need and demand that comes with it. Kelly: That makes a lot of sense. And I think the bottom line that I kept– and the word I kept hearing over and over again was value. So that’s definitely key. So beyond negotiating the contract, how can healthcare organizations build stronger relationships with their payers to improve reimbursement and resolve issues? Angelica: So, payer collaboration does not end after a payer contract is executed. It’s just the beginning. Your payer contract director should not be the only one talking to your payers. This is a collaboration between RCM, your payer contracting department, and really with a dotted line to finance through RCM. Within each contract, you are assigned a provider relations advocate, which is the bridge between your practice and the insurance company. Many organizations only contact payers when there’s claims denying or, obviously, when contract negotiations are up for renewal. But high-performing organizations treat payers as strategic partners. You can contact your provider relations advocate when there’s prior authorization problems, when there’s an increase to your denial trends, when you’re having coverage or network access issues. But they can also help you leverage strategies that you’ve never heard of, like good-faith appeals, payout negotiations. They can also help you while you’re transitioning through billing companies, or also help you with provider education when you’re dealing with referrals and orders coming from or referring providers. When problems occur, there’s always a relationship in place. And that’s why it’s smarter to do this early on in the contracting phase. The best reimbursement strategy is often operational excellence, not aggressive contract negotiation. Kelly: Yeah, and I mean, those relationships are key there. It makes a lot of sense. So, healthcare leaders often know their revenue. But do they really know what it costs to deliver that revenue? What does a true service line profitability analysis look like? Angelica: So, this is referred to as a cost analysis. The main question we ask when performing this analysis is, how much does each service actually cost to deliver? Only after understanding this margin should expansion decisions be made within leadership. One of the most dangerous questions in healthcare is: what’s our revenue, or where is it coming from, or what is that profit margin? Without asking what is our cost per unit of care, we’re not really understanding that profit margin just yet. Many organizations obviously know their charges, their collections, their net revenue, but they’re not doing the deeper analysis of cost. So, cost per patient, cost per visit, cost per procedure. A true service level profitability analysis includes revenue, direct cost, indirect cost, and even deeper dives into those fees of those indirect costs that ultimately get calculated into the cost of care. Cost analysis also includes what volume is required to break even. So how many patients, study visits, or procedures are required before we start losing money? Also, we would like to include in that analysis what is required to generate that profit margin. So, it’s not so much if we schedule it, but do we have the staff, the tools to render that service? And all of that is included in that indirect cost that we perform during that cost analysis. Kelly: Yeah, that sounds like a pretty important process. I know that the profit margin is really important. So, Angie, when you’re evaluating a healthcare acquisition, what are the financial and operational questions you wan

  3. Sep 23

    The Growing Denials Crisis and What Healthcare Leaders Can Do

    ← Back to All Podcasts The Growing Denials Crisis and What Healthcare Leaders Can Do In this episode, Noah Breslow, CEO of Revecore, discusses the growing denials crisis and what healthcare leaders can do. Highlights of this episode include: Why denials are becoming such a significant challenge for health systems What the financial implications are on health systems Why so many organizations struggle to prevent denials before they happen What the biggest reasons denials continue to slip through the cracks How health systems can shift from reacting to denials to preventing them How AI and automation can help identify and address denial risks earlier What roles dedicated denial prevention processes play in improving outcomes What revenue cycle leaders should do now to strengthen their denial strategy Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome Noah Breslow. As CEO of Revecore, Noah brings more than 20 years of executive leadership experience with a focus on driving growth, innovation, and transformation in complex, highly regulated industries. Most recently, Noah was a partner at Bain Capital Ventures, or BCV, where he led their portfolio support team, built out data-driven investment tooling, and helped incubate two startups at the forefront of applying AI in the insurance claims processing and wealth management industries. Prior to BCV, Noah served as chairman and CEO of OnDeck, a pioneering online small business lender where he built the business from its earliest stages, took it public, and ultimately facilitated its acquisition. Earlier in his career, Noah held leadership roles in product, engineering, and marketing. He holds a Bachelor of Science in Computer Science and Engineering from MIT and an MBA from Harvard Business School. In this episode, we’re discussing the growing denials crisis and what healthcare leaders can do. Welcome, and thank you for joining us, Noah. Noah Breslow: Thanks so much, Kelly. It’s really great to be here. Kelly: It’s great to have you. Well, let’s go ahead and jump in. So why are denials becoming such a significant challenge for health systems? And what are the financial implications on health systems? Noah: Yeah, it’s a trend that’s obviously been there for a long time. But it’s getting worse and worse. So, denials have really moved from a back-office kind of nuisance to a real top-line, front and center margin issue. So, research from McKinsey shows that nearly 3% of net patient revenue is written off due to clinical denials alone. And then if you add in underpayments, the cost of appealing those denials, timely filing issues, you might get another percent or two as well, hitting hospitals. So, I think you have a big financial set of changes going on, and we can get more into that. And then you’ve also got the fact that payers have gotten a lot more sophisticated. So, they’re using AI to do AI-driven claims review, deny claims in a more automated way, in a more nuanced way, maybe than they did before. And we’re seeing just denial trends going up across the board. Kelly: Yeah, I mean, I know denials are a huge issue with such significant financial implications. So, Noah, why do so many organizations struggle to prevent denials before they happen? Noah: It’s got a variety of reasons here. I think organizations struggle to prevent denials, not because they don’t intend to stop denials. So, 47% of organizations cite improving clinical denials as a top priority, yet only around 36% have standardized processes to actually do it. So even though they want to make this an issue, actually implementing the process and the infrastructure to better manage denials is more of a challenge. The other thing about denials is you can obviously engage in that firefighting motion, right? You get a claim denied, you appeal the claim, you go back and forth to adjudicate that one claim. That’s a very different thing than fixing that root cause of the denial upstream. And I think most organizations are better positioned to do that firefighting on a claim-by-claim basis than really do that systemic analysis. “Why is this denial happening? What process do I have to fix on patient intake, or on clinical documentation, or on billing and coding to make sure that that denial doesn’t happen again in the future?” And that fragmentation is a huge challenge for hospitals. Kelly: Yeah, it seems like doing that hard work is key there. So, what are the biggest reasons denials continue to slip through the cracks? Noah: Yeah, I think it’s a multidisciplinary thing. So, you need kind of that combination of data intelligence, the reporting that says, “Hey, we’ve been submitting claims to this particular payer and these types used to get denied at this rate, but we’re seeing this uptrend in these particular types.” You have to connect that intelligence piece. What’s actually happening, and trend analysis, but then you need really human expertise to go, “Okay, why is this trend happening? What could I change upstream to maybe prevent this denial from happening in the future?” And that’s a very multidisciplinary thing. It could involve changing processes. It could involve retraining staff. It could involve system changes, collecting different pieces of information at different points in the process. So, I think it’s that multidisciplinary way to integrate the data on the back end and the intelligence gathering with the process engineering upfront to prevent those denials from happening in the future. Kelly: Yeah, I love what you said there about the combination of data intelligence and human expertise. That totally makes sense to me. Probably to others as well. So, you know how can health systems shift from reacting to denials to preventing them? Noah: Yeah. There’s a few different ways I think health systems can go from reactive mode to prevention mode. First is organizational. You have to set up processes and teams inside your revenue cycle organization that are dedicated, that make it someone’s full-time job to making those structural changes to prevent denials from happening in the future. So, organizations with those dedicated processes to prevent denials have a much higher appeal success rate than organizations who don’t have those dedicated teams. And then the other piece of it is around timing. If you imagine you go to the doctor’s office and they hit your knee with a hammer, and it takes you two months to kick, your reflexes are pretty slow, right? And so, two months later, that procedure happened a long time in the past. The patient has already gone home. The documentation may be locked down. And so working on your feedback loop, that rapid cycle from the moment that denied claim comes in to the trend analysis to going upstream and working to make those changes, it’s a governance question as much as it is a technology question, and denial trends should be front and center in revenue cycle leadership meetings, not something you check in on once a quarter. Kelly: Completely agree. And I love what you said about the reaction mode to prevention mode. That makes a lot of sense in this specific example. So, AI is all the hype. How can AI and automation help identify and address denial risks earlier? Noah: Yeah. So, AI is a tool that payers frankly have a head start on over providers. I think they’ve been implementing AI at scale now for a few years. Providers are starting to catch up, but it’s a little bit of an arms race, and providers really need to deploy AI, I think, to be the best position to handle increasing types of denials in the coming years. So, AI’s real value is pattern recognition at scale, right? Finding those connections across payers, service lines, procedure types that are driving recurring denials faster than someone could just reviewing claims one by one on their own. And so getting that AI deployed to find those patterns is critical. And the other piece, it is a moving target. So, the claims that are denied this year may not be the ones that are denied next year. There are always new types of denials coming in, and some of them can be addressed very basically, right? They could be administrative denials. They could be missing documentation. Those are more sort of straightforward process issues, but there are a lot more subtle ones in terms of the way procedures are coded and billed, the way procedures are bundled together. And that’s where, again, having that human expertise to complement the AI is so important. Kelly: Completely agree. And I mean, it does really seem like providers really need to get on the AI trainer in a major way. So, what role do dedicated denial prevention processes play in improving outcomes? Noah: It’s massive. They have that dedicated team focused on improving outcomes We see it all the time in our client base at Revecore. Some of our customers, maybe the smaller health systems that don’t have those dedicated teams focused on denials, they’re, again, more in that reactive mode, but our larger customers often do have specialized denial teams or executives focused on those. And we’ve seen some of our more sophisticated clients not only have dedicated teams, but have dedicated analytics. So, they’ll know to the analyst level on their team what their overturn rates are by procedure type, by payer, and then they start to actually optimize. So folks on the team who are better at getting certain types of denials overturned will focus there. And then other areas might be gaps that need to be addressed by training or hiring new skill sets. So dedicated team, specific measurement of payer-sp

  4. Sep 9

    Modern Identity Defense for Healthcare Series—Passkeys in Practice

    ← Back to All Podcasts Modern Identity Defense for Healthcare Series—Passkeys in Practice In this episode, Eric Englebretson, Besler Holdings’ VP of Information Technology, provides us with a glimpse into our next Hospital Finance Academy Webinar, the second in the Modern Identity Defense for Healthcare series, Passkeys in Practice, live on Wednesday, September 16, at 1 PM ET. Highlights of this episode include: What we can expect in this second installment in this series? Why passkeys specifically? How MFA isn’t solving the identity security problem What actually is a passkey? What makes passkeys phishing-resistant? HIPAA and compliance rules What’s next? Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome back Eric Englebretson, Besler Holdings’ Vice President of Information Technology. In this episode, Eric will provide us with a glimpse into our next Hospital Finance Academy Webinar, the second in its Modern Identity Defense for Healthcare series, Passkeys in Practice, live on Wednesday, September 16th, at 1 PM Eastern Time. Welcome back, and thank you for joining us, Eric. Eric Englebretson: Thank you for having me yet again. Kelly: All right. Let’s go ahead and jump in. So, Eric, the last time you talked about identity attacks in healthcare. What can we expect in this second installment in this series? And why passkeys specifically? Eric: Well, Kelly, because if part one was about why attackers go after identities, part two is going to be about the single biggest fix we’ve seen in at least 15 years. Passwords are, and I can say this without hyperbole, one of the worst security tools we have for protecting a digital identity. And honestly, passkeys are the industry’s answer. Google, Microsoft, Apple, Amazon, PayPal, if you’ve logged into any of those lately, you’ve probably already been nudged to create one. And this session is going to take the mystery out of what’s actually happening when you do. Kelly: Yeah, no, I’ve seen a lot more passkeys myself lately, so this will be interesting for me too. So, we already have MFA. Isn’t that solving the identity security problem already? Eric: So, it does help, but it doesn’t solve it. SMS codes can get intercepted via either SIM swapping and just general insecurities in the protocols behind text messages. The one-time codes you get from apps like Google Authenticator, those can still be phished and replayed if someone tricks you into typing your password and code into a fake site. And then, of course, push-based MFA has what we call and what we identified in the last session as MFA fatigue where people just approve prompts to make them stop. That’s literally how Uber got breached, in fact. Passkeys sidestep all three because they’re inherently multi-factor: something you have, the device, plus something you are or know, like a biometric or a PIN. So, it’s one seamless step, nothing to fatigue approve and nothing to get intercepted and replayed. Kelly: Very, very interesting. So, Eric, in plain English, what actually is a passkey? Eric: And this is so fun because at its core, it’s really complicated, but it’s a pair of cryptographic keys. Don’t let your eyes glaze over when I say that. I’ll explain a little bit more in the session. And ultimately, of those keys, one lives on the website server and one lives on your device, and they never trade that secret part back and forth. So, think of it like a locked suggestion box. Anyone can drop a message in using the public key portion, but only the person holding the private key can open that message box and, in this case, sign something to prove that it’s really them. The signature is what gets checked, not a password, not your private key. So, the important bits don’t go back and forth where they could be intercepted. Kelly: I mean, it sounds easy enough. So, what actually makes passkeys phishing-resistant? I mean, it sounds like a big claim given how easily we can be tricked into giving away passwords and authenticator codes. Eric: It actually is a big claim, but I think it holds up. So, each passkey you create is bound to a specific domain, and that’s one of the important bits. So, if somebody builds a pixel-perfect clone of Microsoft.com at, let’s say, micronsoft.com and you don’t notice, your device actually won’t even offer the passkey. It actually simply won’t even respond. When implemented properly, there’s no password to type, so there’s nothing to divulge and put in the wrong place. And that one property right there basically neutralizes phishing and the adversary-in-the-middle attacks, which we talked about and were the star villains of our last session. Kelly: Very interesting. So, healthcare has HIPAA and compliance rules around all of this. Do passkeys actually check that box? Eric: So, this is great. They don’t actually just check it. They exceed it. So, HIPAA Security Rule requires verifying that a person accessing e-PHI is who they claim to be, but they don’t mandate a specific technology. So, passkeys deliver cryptographic proof of identity, and that eliminates the number one credential theft vector. And that also aligns with, and I’ll explain this as well in this session, something called NIST SP 800-63B. Again, don’t let your eyes glaze over. And basically, they have what are called authenticator levels. And these meet or even go up to the next level depending on whether or not you’re using hardware keys. And then for HHS’s own 405(d) program, they’ve been recommending FIDO2 and passkeys as a priority mitigation for healthcare specifically for quite a while now. So yes, definitely, this far exceeds the things that we need for HIPAA. Kelly: Well, that is great news. And I’m looking forward to learning more about that. So, this all sounds almost too good. What’s the catch? Eric: That’s a really fair question. I get it a lot. So, in this case, we’ve got– we’re building a front door that is genuinely rock solid, made out of metal. The catch is actually a backdoor here, account recovery. So as an example, let’s say you’re storing all your passkeys on your phone. If your phone dies and you lose your passkeys, what’s guarding your way back in? Because you’ve got to have one, right? Well, usually it’s a password reset email plus an SMS code. Well, that’s the absolute weakest link protecting the strongest lock we’ve ever built. We’ll dig into exactly how to close that gap in the full session, but that’s really the only downside. Kelly: Okay. Good to know. So, if someone only takes one thing away from this episode before they join us for the live webinar, what should it be? Eric: Ultimately, it’s that passkeys aren’t just a nice-to-have. For healthcare organizations, they’re one of the most practical wins available right now against phishing, credential stuffing, and the account takeover attacks that dominate breach reports. In the full session, we’ll walk through the different types of passkeys, where they actually live on your device, device-bound versus synced trade-offs for enterprise deployments, and really an overview of creating and using one. I think it’s going to be well worth your time. Kelly: Yeah. I think so, too. I think this is going to be a great webinar. Well, thank you so much for joining us, Eric, and for giving us this glimpse into Hospital Finance Academy’s free webinar, Passkeys in Practice, that’s going to be live Wednesday, September 16th, at 1 PM Eastern Time. And as a bonus, you can also earn CPE. Thanks again, Eric. Eric: Absolutely. Kelly: Wow, sounds like things are always changing in this space for sure. Well, thank you so– Eric: Absolutely. Kelly: And thank you all for joining us for this episode of The Hospital Finance Podcast. Until next time… [music] This concludes today’s episode of The Hospital Finance Podcast. For show notes and additional resources to help you protect and enhance revenue at your hospital, visit besler.holdings/podcasts. The Hospital Finance Podcast is a production of Besler Holdings. If you have a topic that you’d like us to discuss on The Hospital Finance Podcast or if you’d like to be a guest, drop us a line at update@besler.com. Subscribe Today! 945.237.1009
116 Village Blvd., Suite 200
Princeton, New Jersey 08540 Quick Links AboutTeam
PodcastsWebinars Solutions Medicare Appeals Contact Us Contact ©2026  Besler Holdings Terms of Use | Privacy Policy | Corporate Compliance The post Modern Identity Defense for Healthcare Series—Passkeys in Practice [PODCAST] appeared first on Besler Holdings.

  5. Sep 2

    The Money is in the Note, Not the Claim

    ← Back to All Podcasts The Money is in the Note, Not the Claim In this episode, VerifyMedCodes Co-Founders Nathan Turock and Angelo Selitto, discuss why the money is in the clinical note, not the claim. Highlights of this episode include: What it means when they say “the money is in the note, not the claim” What problem VerifyMedCodes solves How the deterministic approach is different “You can’t defend a code you can’t reproduce.” How to catch issues before the claim goes out, missing modifiers, unsupported codes, and linkage problems How hospital finance leaders should be thinking about readiness How to process a clinical note without patient data ever leaving the building Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast.  We’re pleased to welcome Nathan Turock and Angelo Selitto. Nathan is CEO and co-founder of VerifyMedCodes. He leads strategy, partnerships, and go-to market, focused on helping hospitals and RCM teams turn clinical documentation into defensible, denial-resistant revenue. He founded Verify Med Codes to close the gap between what clinicians document and what actually gets paid. We have Angelo, who’s co-founder and chief architect of VerifyMedCodes. He’s a healthcare integration architect with 13-plus years’ experience across Epic, FHIR, HL7, Identity, and Clinical AI. And he’s delivered production CDS hooks and FHIR for value – based care and led ambient AI documentation rollouts across 33, 000 providers. He designed the VerifyMedCodes deterministic PHI-safe coding engine. In this episode, we’re discussing the money is in the note, not the claim. Welcome, and thank you both for joining us, Nathan and Angelo. Nathan Turock: Thank you for having us. Angelo Selitto: Thank you for having us. Thank you for the intro, and wonderful to be here. Kelly: All right. Well, let’s go ahead and jump in. So, VerifyMedCodes started as a coding engine. What problem did you set out to solve, and why do you say the money is in the note, not the claim? And Nathan, I’m going to toss this one over to you. Nathan: Okay, that’s great. The money is in the note. The way it all works, if we’re going to make it easier for the audience, the progress note that the doctor writes is actually what gets paid by the insurance companies. The way it’s set up in the United States healthcare system is the doctor writes the note, then it goes to a coding or billing agency, and they have to put in all the codes that have been created since the ’50s and ’60s by the insurance industry to make sure it’s accurate so they get paid. The problem with that is the insurance companies have made it so convoluted and so difficult to find all the proper codes. And I won’t get too into the weeds, but you have your ICD-10 codes, your EM codes, your RAF scores, your HCCs, etc. And it gets very difficult for the physician, hospital, provider to get paid what they’re owed. We created this to make it transparent. So, it goes right from the doctor’s note, we code that the English language, then we code it into the medical nomenclature of actually the entire globe, and then we code it into the coding system that has been created by the insurance companies in the United States to maybe not pay exactly what they should. So, we’re going for clear transparency because I believe that the healthcare provider should get paid what they’re worth, and they shouldn’t be convoluted or changed up by the insurance company just because they want to put all this coding into play. Kelly: Right. No, I love that y’all made that transparent. I know there’s a lot of complexities in the coding world. So, a lot of AI coding tools make compliance teams nervous because they can hallucinate a code. How is a deterministic approach different, and why does same note in, same codes out matter for revenue integrity? And Angelo, I’m going to toss this one to you. Angelo: No, it’s a great question. And a probabilistic AI coder can read the same note twice and give you two different code sets. And for revenue integrity, that’s the whole problem. You can’t defend a claim you can’t reproduce. So, our deterministic core is same note in, same codes out every time. And that’s the type of defensibility that we want to offer, right? Is that we have the history, we have the evidence-based, we are giving you the information because of what the note stated. It’s not a hallucination. It’s there in the documents. So, we’re really just carrying it forward, and you’re going to reproduce the same information because the same defensibility and the same information always surfaces. So, it’s just the AI can do its suggestions. It could offer and flag, basically recover anything that was missed and offer options. But in the end, the AI doesn’t have the final say. And I think that’s the difference between fast and defensible. Kelly: Yeah. No, I love what you said about, “You can’t defend a code you can’t reproduce.” I actually wrote that down because I really thought that that was very interesting that you said that. I love that. So, Nathan, where are hospitals leaving the most defensible money on the table today? Is it risk adjustment capture, denials, or is it somewhere else? Nathan: It’s in all those, to be perfectly honest with you. The denials is your holy grail, capturing the right amount of money for the service that you provided. The reason being is the insurance companies like to deny a lot. I know everybody out there in podcast land has never heard of an insurance company denying anything. Kelly: Right. Nathan: Exactly. So, with that being said, I’m going to sort of piggyback off of what Angelo said and to make this very digestible. Angelo loves when I say it’s an incredibly complex tool that we’ve created, but it’s an A plus B equals C or A plus B plus C equals money. Coding system A is the progress note, which is written in the English language. B is the medical terminology that we’ve also coded into a large LLM. C is all the codes from the insurance companies that we utilize their language against them so they can’t deny. So, we have A plus B plus C equals the correct dollar amount. It’s deterministic. It’s accurate. It’s to the point. So, where they’re leaving money on the table is a couple of different sectors. The first one is first pass rate, which means that the note goes through cleanly and insurance says, “Yep, it’s good to go. We’re going to pay you for it.” The second one is– the big one is denials, which when an insurance company says, “Nope, you don’t have enough data on that. We are denying this for XYZ reason,” it costs money to reprocess that note again. So, we decrease the first– or increase the first pass rate so it’s a better coding system that goes through insurance and they pay. We decrease the denials because we’re using their language, their wording, and their codings directly against them, directly correlated to the progress note. And there’s also a whole lot of other scores like RAF scores, which is risk adjustment factor, and HCC scores that get very, very complicated, that would drive most coding people nuts and gets lost a lot in the shuffle. With the technology that we have now and with how we coded this, it can’t miss. It’s A plus B plus C, LLM. It’s like a giant calculator. I know, Angelo, it’s a lot more complicated than that. But basically, it’s a giant calculator that makes sure the provider, the healthcare provider, the doctor, the hospital, what have you, gets paid what they’re owed by the insurance company. First pass rate is up, productivity for getting the claim through is increased, and denials go down. Simply put, it’s a giant calculator to make sure the doctors get paid what they’re owed. Kelly: Yeah, no. I love that A plus B plus C equals the money that you’re owed. So that’s awesome that you guys came up with that. So, Angelo, you catch issues before the claim goes out, missing modifiers, unsupported codes, linkage problems. What does that look like on a real claim? Angelo: That’s pretty much the bread and butter, right? We catch the missing modifiers, the unsupported codes, linkage problems before the claim goes out, just like you said. And it really looks like a straightforward office visit, 34-year-old, appendicitis. The engine builds the full claim, the diagnosis, six procedures, the levels, the EM. It then scrubs before submission and catches two things the payer would have bounced, one procedure, maybe a lab, an 82565 that needed a modifier 59. And without it, the payer bundles it, and you don’t get paid for it. The EM might have needed modifier 25 to sit alongside the procedure without the denial. There’s denial risk scores at 10 %. Both items flagged with the payer denial reasoning spells it out. And we basically are doing that double-check work. We’re doing that assessment before it goes out. And we also do it before an RCM tech might even see it. So the real capture is that we’re able to surface these as options as well. So, in the deterministic engine that we have, it’s not saying this is the end-all be-all. It’s a really nice system that allows you to see all of the options and see what is missing and what could have been created to build and bundle the exact claim that you guys were looking for or want to execute. Kelly: Wow, I mean, that sounds pretty impressive there. With CMS interoperability and prior authorization requirements landing in 2027, how should hospital finance leaders be thinking about readiness? And Nathan, I’m going to let you take this one. Nathan: Okay, pretty muc

4.3
out of 5
37 Ratings

About

If you’re concerned about revenue at your hospital, then The Hospital Finance podcast is your go-to source for information and insights that can help you protect and enhance the revenue your hospital has earned. From regulatory changes to revenue cycle optimization, readmissions to bundled payments, you’ll get important perspectives, news and strategies from leading experts in healthcare finance. For show notes and additional resources from Besler Holdings, visit https://www.besler.holdings/podcasts.

You Might Also Like