Healthcare
21 min read
The order matters more than the tool. Where to start RCM automation across eligibility, prior auth, scrubbing, denials and underpayments.

Zach Shapiro
TL;DR: Revenue cycle management automation pays back fastest when you start upstream, where denials are born, and work downstream. For most physician groups, ASCs and behavioral health practices the order is: eligibility and benefits verification, then claim scrubbing tuned to your own denial history, then denial triage and A/R follow-up, then prior authorization, then underpayment and contract variance, then patient estimates and coding assist. Pick one countable unit (initial denial rate by reason, cost to collect, days in A/R) before you buy anything. Use RPA only for stable screens, AI agents for reading and drafting, and keep humans on coding judgment, medical necessity arguments and write-offs.
A practice administrator at a 14-site orthopedic group pulls the last quarter of 835 remittance files and sorts the denials by CARC code. The top three are not exotic. CO-27 (coverage terminated), CO-197 (authorization absent) and CO-16 (claim lacks information). Every one of them was knowable before the patient walked in. The billing team spent the quarter appealing problems the front desk could have caught with a correct eligibility response and a working authorization log.
That pattern is why the order of automation matters more than the brand of tool. Experian Health's State of Claims 2025 survey found that 41% of providers now report denial rates of 10% or higher, up from 30% in 2022, and only 14% are using AI to reduce denials. Most groups are not short on vendors pitching "AI medical billing." They are short on a sequence that matches where their money actually leaks.
This guide is for CFOs, VPs of revenue cycle and practice administrators at multi-site physician groups, ambulatory surgery centers, specialty practices and behavioral health organizations. It covers what to automate first and in what order across the front end, mid cycle and back end, how RPA differs from AI agents in RCM, when outsourcing beats automation (and when it does not), what to measure, and what to keep in human hands.
Key takeaways
Denials are rising and most are preventable upstream. Experian Health reports 41% of providers see denial rates of 10% or more in 2025, and its respondents rank missing or inaccurate data and authorization issues among the top causes.
Eligibility is the cheapest first win. The 2024 CAQH Index puts the provider cost of a manual eligibility check at $8.57, a portal check at $4.46 and a fully electronic check at $2.00.
Prior authorization is the heaviest manual load. The AMA's 2024 physician survey found practices complete 39 prior authorizations per physician per week, consuming about 13 hours of physician and staff time.
Fighting denials after the fact is expensive. Premier estimates hospitals spent $25.7 billion contesting denials in 2023, about $57.23 per claim, and roughly 70% of those denials were eventually overturned.
Adoption is broad but shallow. An HFMA Pulse Survey commissioned by AKASA (April 2025) found 80% of health systems are exploring, piloting or implementing generative AI in the revenue cycle, but most are not yet at scale.
Regulation is moving prior auth onto APIs. Under CMS-0057-F, impacted payers must return prior auth decisions within 72 hours (urgent) and 7 days (standard) starting in 2026, with FHIR prior authorization APIs due in 2027.
The tool is rarely the bottleneck. Automation fails when your PM system, clearinghouse, contracts and payer rules do not agree on who the patient, the payer and the expected payment are.
What is revenue cycle management automation?
Revenue cycle management automation is software that performs or prepares the repetitive work of getting paid for care: checking coverage, obtaining authorizations, building and editing claims, posting payments, working denials and following up on open A/R. It ranges from simple rules (a claim scrubber edit) to scripted bots (RPA logging into a payer portal) to AI agents that read a denial letter, check the payer's policy, pull the clinical note and draft an appeal for a human to approve.
The revenue cycle is usually split into three segments, and automation behaves differently in each:
Front end: scheduling, registration, eligibility and benefits verification, prior authorization, patient estimates and point-of-service collection.
Mid cycle: charge capture, clinical documentation, coding and claim creation, including the scrubber edits that run before an 837 goes to the clearinghouse.
Back end: claim status, payment posting from 835 ERAs, denial management, appeals, underpayment and contract variance recovery, patient statements and A/R follow-up.
The useful question is not "which of these can be automated." Nearly all of it can be, partly. The useful question is which step, automated first, removes the most work from every step after it.
What should you automate first in the revenue cycle?
Automate the step that creates the most avoidable denials in your own data, which for most groups is eligibility and benefits verification, followed by claim scrubbing tuned to your top denial reasons. Those two steps sit upstream of everything else, run on structured transactions (270/271 and 837 edits) that are mature and well understood, and produce a result you can count within weeks.
The scoring rule we use
Before ranking workflows, score each candidate on four questions. Give each a 1 to 5, multiply, and sort.
Volume: how many times a month does this task happen across all sites?
Downstream cost of an error: if this step goes wrong, how much rework and write-off does it cause later?
Rule clarity: can a good employee explain the decision in a checklist, or does it take years of payer-specific judgment?
Data availability: is the information already in a system you can connect to (PM, EHR, clearinghouse), or does it live in a fax queue and someone's memory?
Eligibility scores high on all four. Coding assist scores high on volume and error cost but low on rule clarity and carries compliance exposure. Underpayment recovery scores high on error cost but low on data availability for most groups, because the payer contracts are PDFs in a shared drive and nobody has loaded the fee schedules.
The default order (adjust it to your denial mix)
Wave 1: eligibility and benefits verification, plus scrubber edits built from your last 12 months of denials.
Wave 2: denial triage and routing, claim status and A/R follow-up, payment posting exceptions, then prior authorization.
Wave 3: underpayment and contract variance, patient estimates, charge capture reconciliation and coding assist.
Here is the arguable part. Many groups start with an AI appeals tool because denials are the visible pain. That is the wrong first purchase for most of them. An appeals engine makes you faster at fighting fires that eligibility and scrubbing would have prevented, and Premier's finding that roughly 70% of contested denials end up paid tells you how much of that fight was avoidable in the first place. Fix the front of the pipe, then automate the back.
The exception is the specialty practice where authorizations dominate the denial list. An oncology, imaging, orthopedic or behavioral health group with CO-197 at the top should pull prior authorization into Wave 1.
How do you automate the front end: eligibility, prior authorization and patient estimates?
Automate the front end by moving every coverage question onto electronic transactions, running them on a schedule before the visit rather than at check-in, and routing only the exceptions to a person. The work becomes "review what the system flagged" instead of "call or log into every payer."
Eligibility and benefits verification automation
The 2024 CAQH Index estimates a $20 billion industry opportunity from moving manual administrative transactions to automated ones, and eligibility is the biggest single piece of it. The mechanics are not complicated:
Run batch 270/271 checks against the schedule 3 to 5 days out, then again the day before, through your clearinghouse (Availity, Waystar, Experian Health, TriZetto and others) or your PM's built-in tool in athenahealth, eClinicalWorks, NextGen, ModMed or Epic.
Parse the 271 for the fields that cause denials later: active coverage dates, plan product, PCP assignment for HMOs, carve-outs (behavioral health benefits routed to a separate vendor are a classic), remaining deductible and visit limits.
Run coverage discovery on self-pay and "no insurance on file" patients.
Send only mismatches to staff: wrong subscriber ID, terminated coverage, secondary payer not on file, a plan that requires a referral the scheduler did not capture.
Where AI earns its place here is the 271 that comes back vague. Payers return benefit details as free-text messages that a rules engine misreads. An agent can read those messages, compare them to what the visit type needs, and write a one-line exception for the front desk: "Plan shows behavioral health carved out to a separate administrator; obtain that ID before the 10/14 intake."
Prior authorization automation
Prior authorization automation works in three layers: detect whether an auth is required, assemble and submit the request, then track status until a decision posts to the encounter. The 2024 CAQH Index found providers spend an average of 24 minutes per authorization by phone, fax or email and 16 minutes through a payer portal, and puts the provider cost at $12.88 manual versus $5.38 electronic.
Detection: match the scheduled CPT or HCPCS code, payer, plan product and place of service against payer auth lists. These lists change often and live in PDFs and portal pages, which is exactly where AI reading beats static rules.
Assembly: pull the diagnosis, prior treatment history and relevant notes from the EHR and map them to the payer's medical policy criteria. An agent can draft the clinical summary. A clinician or trained auth specialist should confirm it.
Submission and tracking: submit through X12 278, a payer portal or, increasingly, payer APIs. CMS-0057-F requires impacted payers (Medicare Advantage, Medicaid and CHIP programs and plans, and qualified health plans on the federal exchanges) to stand up FHIR prior authorization APIs by 2027, so any portal-scraping approach you build now has a shelf life.
For behavioral health, track authorized units and session counts against scheduled visits. The denial is often not "no auth" but "auth exhausted," and it shows up weeks after the sessions were delivered.
For ASCs, tie the auth to the exact procedure on the case schedule in HST Pathways, SIS or your ASC system. A procedure that grows in the OR (an added level, a different implant) is a common source of auth mismatches.
Patient estimates
Patient estimates belong in Wave 3 for most groups, because an accurate estimate depends on two things you should fix first: clean eligibility data (deductible remaining, coinsurance) and loaded contract rates (the allowed amount). Without both, an estimate engine produces confident wrong numbers, and a wrong estimate costs you patient trust and a call to the billing office.
There is a compliance floor regardless. Under the No Surprises Act, CMS guidance requires providers to give uninsured and self-pay patients a good faith estimate within set timeframes after scheduling (for example, within three business days when the service is scheduled at least ten business days out). Automate the generation and delivery of those first.
How do you automate the mid cycle: charge capture, coding assist and claim scrubbing?
Automate the mid cycle by tuning claim scrubber edits to your own denial history first, reconciling charges against the schedule and procedure logs second, and adding AI coding assist last, with coders reviewing its suggestions. The scrubber is cheap and fast. Coding assist is valuable and carries the most compliance risk in the whole revenue cycle.
Claim scrubbing built from your denials
Every clearinghouse ships generic edits (NCCI pairs, invalid modifiers, missing NPI). The gap is the edits specific to your payers and your specialties. Take 12 months of 835 data, group denials by CARC and RARC code, payer and CPT, and write a pre-submission edit for every pattern that repeats. A modifier 59 versus XU issue with one Medicaid plan, a place-of-service mismatch at one site, a taxonomy code that one payer insists on. This is unglamorous work. It is also where many groups find their quickest drop in initial denial rate, because the feedback loop from denial to edit is usually broken today.
Charge capture
Missed charges never show up as denials, which is why they hide. Automate the reconciliation: every scheduled and arrived appointment should have a charge, every OR case should match its implant and supply log, every infusion should match the drug administration record. An agent can run that comparison daily and list the gaps by provider and site.
Coding assist (AI medical billing and coding)
Can AI do medical billing and coding? It can suggest codes from documentation and flag documentation that will not support the level billed, and that is useful. The HFMA Pulse Survey commissioned by AKASA found 89% of respondents say missed or inaccurate codes significantly affect revenue. But final code selection on surgical cases, complex E/M and anything that touches a compliance audit should stay with a certified coder. Treat the AI as a first reader that shortens the coder's work, measured by coder minutes per chart and audit accuracy, not as a replacement.
How do you automate the back end: denials, appeals, underpayments, payment posting and A/R?
Automate the back end by letting software sort, route and draft, and letting people decide. Denial triage, claim status checks, payment posting exceptions and first-draft appeals are high-volume reading work. Choosing which accounts to write off, which payer to escalate and which medical necessity argument to make is judgment work.
Denial management automation
Triage: categorize each denial by root cause (eligibility, authorization, coding, timely filing, medical necessity, duplicate, COB), expected recovery value and appeal deadline, then route it to the right queue.
Appeal drafting: an agent reads the denial, the payer's policy and the encounter documentation, then drafts the appeal letter and attaches the supporting records. A human reviews and sends.
Feedback: every denial with a preventable root cause becomes a scrubber edit or a front-end rule. Without this loop, denial automation just processes the same denials faster.
We wrote separately about the data model that sits under denial and underpayment detection in how to detect denials and underpayments from the data layer up, so this guide stays at the sequencing level.
Underpayments and contract variance
An underpayment is a claim the payer paid, just not at the contracted rate. It does not appear on a denial report, so most groups never see it. Detecting it requires your payer contracts loaded as machine-readable fee schedules (often expressed as a percentage of a Medicare fee schedule for a given year, with carve-outs for implants or high-cost drugs) and matched to every 835 line. That loading work is why this sits in Wave 3. Once it is done, the variance report runs itself, and the appeal drafts look a lot like denial appeals.
Payment posting
Most PM systems already auto-post clean 835 ERAs. The automation opportunity is the exceptions: paper EOBs, lockbox images, recoupments and takebacks, and payments that will not match a claim. An agent can read a scanned EOB, match it to the open claim and stage the posting for a poster to approve.
A/R follow-up
Replace manual claim status calls and portal checks with 276/277 status transactions on a schedule, then have the system work the "no response" queue by payer and age. Staff time goes to accounts where a phone call actually changes the outcome.
RPA vs AI agents in RCM: which should you use?
Use RPA for stable, structured, screen-based tasks that will not change for a year; use AI agents for work that requires reading unstructured documents or deciding the next step. Use neither where a standard transaction or API exists, because an X12 or FHIR connection will outlast both.
RPA (robotic process automation) records clicks and keystrokes. It is good at copying a value from one screen to another thousands of times. It breaks when a payer redesigns a portal or adds a field, and someone has to fix the bot. Revenue cycle teams that ran large RPA programs know the maintenance queue well.
AI agents read and reason over documents: denial letters, payer policies, clinical notes, scanned EOBs, contract PDFs. They decide what to do next within limits you set, and they draft outputs for review. They are slower and more expensive per step than a rule, so they should not do what a rule can.
Rules engines and standard transactions (270/271, 276/277, 278, 835, 837) remain the backbone. They are cheap, auditable and payer-supported.
Our position: in 2026, do not build new RPA bots against payer portals for eligibility, claim status or prior authorization if a transaction or API path exists or is coming under CMS-0057-F. Spend that budget on the agent layer that handles the exceptions those transactions produce, and on the data foundation both depend on.
Outsourcing vs automation: should you outsource medical billing or automate it?
Outsource when your problem is staffing capacity and you lack the management depth to run a revenue cycle; automate when your problem is cost per transaction, denial rate or visibility. They are not mutually exclusive, and the best outcomes we see pair a billing partner with automation the practice controls.
MGMA's November 2024 Stat poll found 36% of practice leaders planned to outsource or automate part of their revenue cycle in 2025, with collections, billing and coding the most common targets. The same poll captured a countertrend: some practices moved work back in house after the Change Healthcare cyberattack disrupted claims processing.
Questions to ask before you sign or renew an RCM outsourcing contract:
Who owns the data? You should receive raw 837, 835 and 277 files and work-queue history, not just a monthly PDF dashboard.
How is the vendor paid? A percentage-of-collections fee gives the vendor little reason to pass automation savings back to you.
What is automated versus offshored? Many "AI-powered" billing services are labor arbitrage with a portal on top.
Can you see root causes? If denials are categorized by the vendor's internal codes instead of CARC and RARC, you cannot audit the work or fix upstream causes.
What happens on exit? Transition of open A/R and history should be in the contract.
If you outsource, keep the data layer in house. It is what lets you measure the vendor, switch vendors and automate later without starting over.
What data layer does RCM automation need?
RCM automation needs one connected, reconciled view of patients, payers, encounters, claims, payments and contracts across every system you run. Without it, each tool sees a slice, and an agent that cannot see the contract cannot tell an underpayment from a correct payment.
In a typical multi-site group, that data is spread across:
One or more PM and EHR systems, especially after acquisitions (a group running athenahealth at legacy sites and eClinicalWorks at acquired ones is common).
The clearinghouse, holding 271, 277 and 835 responses.
Payer contracts and fee schedules, usually PDFs and spreadsheets.
Payer policies and auth lists, on payer websites.
Credentialing records (a non-credentialed provider produces denials no scrubber catches).
Specialty systems: an ASC platform, a behavioral health EHR such as Netsmart, Qualifacts or Valant, a lab or imaging system.
Three problems have to be solved before automation is reliable.
Entity resolution. The same patient carries different MRNs at different sites. The same payer appears as "UHC," "United Healthcare," "UMR" and "Optum," which are related but not interchangeable for contract purposes. The same provider bills under different locations and NPIs.
Shared definitions. "Denial rate" at one site counts claims; at another, it counts dollars or lines. "Days in A/R" may use gross or net charges. Agree on one definition before you report anything.
Relationships. A claim links to an encounter, which links to an authorization, a payer plan, a contract and a fee schedule. A knowledge graph stores those links explicitly so an agent can follow them: this claim, under this plan, should have paid this amount under this contract.
That is what OutcomeCatalyst's company brain does: it connects the systems you already run into one governed layer, and our claims and appeals agents work on top of it. On PHI: our platform is HIPAA-aligned and SOC 2 Type 2 aligned, with the formal audit underway and expected to complete before year-end. Whatever vendor you pick, require a business associate agreement and know where PHI is stored and processed.
If you are weighing whether to build that layer yourself, our buy vs build guide lays out the honest tradeoffs, including when building it in house is the right call.
How do you measure ROI on revenue cycle automation?
Measure ROI by naming one countable unit per workflow before you automate, baselining it for at least 90 days, and tracking the same unit after go-live at the same sites. If you cannot name the unit, you cannot prove the return, and the project will lose its budget at the next review.
Countable units that work
Initial denial rate by root cause (claims denied on first submission, split by eligibility, auth, coding and so on).
Clean claim rate (first-pass acceptance at the clearinghouse and the payer).
Cost to collect (total revenue cycle cost divided by cash collected).
Days in A/R and percentage of A/R over 90 days.
Touches per claim (how many times a person handled it before payment).
Auth turnaround time and auth-related denials per 1,000 visits.
Contract yield (paid amount as a share of contracted expected amount).
Estimate accuracy (estimated versus actual patient responsibility).
A worked example (hypothetical numbers)
Take a hypothetical 22-site physician group submitting 16,000 claims a month with an 11% initial denial rate. That is 1,760 denials a month.
Sorting 12 months of 835s by CARC shows 30% of denials trace to eligibility and registration (CO-27, CO-22, CO-31 and similar): about 528 a month.
Automated pre-visit eligibility with exception routing prevents 60% of those: about 317 denials avoided per month.
At an assumed internal rework cost of $35 per denial, that saves about $11,095 a month in staff time.
Assume 20% of those denials were never recovered, at an average allowed amount of $165. Preventing them recovers about $10,461 a month.
Combined, roughly $21,556 a month, or about $258,700 a year.
Against an assumed $8,000 a month in software and services plus $40,000 in one-time implementation, year-one cost is $136,000, and year-one net benefit is about $122,700. Payback lands around month three.
Every number above is an assumption for illustration. Swap in your own denial mix, rework cost and contract rates. The method is what matters: one root cause, one unit, a baseline, and a before-and-after on the same sites.
What should you not automate in revenue cycle management?
Do not fully automate decisions that require clinical judgment, carry compliance exposure or affect a patient's finances in ways they cannot easily reverse. Agents should take the reading, reconciling and first-draft labor; people should keep the decisions.
Final code selection on surgical, complex E/M and high-dollar cases.
Medical necessity arguments and peer-to-peer reviews with payer medical directors.
Write-offs and adjustments above a dollar threshold you set.
Financial hardship, charity care and payment plan decisions for patients.
Contract interpretation disputes with payers, which often turn on relationships as much as language.
Sensitive behavioral health records. Substance use disorder records covered by 42 CFR Part 2 carry disclosure rules that any automated appeal or record attachment workflow must respect.
The adoption risk runs the other way too. A tool that produces drafts nobody trusts gets ignored. Built is not adopted. Put the agent's output inside the work queue your billers already use in Epic, athenahealth or your PM system, show the source for every suggestion, and let staff correct it so the corrections become rules.
How do you start: a 90-day RCM automation plan
Start with 30 days of baselining, 30 days of a narrow pilot at one or two sites, and 30 days of measured expansion. The plan below assumes Wave 1 (eligibility plus scrubber edits) but works for any workflow.
Days 1 to 30: baseline and connect
Pull 12 months of 837 and 835 data from your clearinghouse and PM system.
Group denials by CARC and RARC, payer, site, provider and CPT. Agree on one definition of denial rate.
Pick one countable unit and record the baseline by site.
Connect the PM, clearinghouse and contract data into one view and resolve patients, payers and providers across sites.
Confirm BAAs, access controls and where PHI is processed.
Days 31 to 60: pilot narrowly
Turn on scheduled eligibility checks and exception routing at one or two sites.
Write scrubber edits for the top ten repeat denial patterns.
Run any agent in shadow mode: it drafts, a person decides, and you log every correction.
Meet weekly with front desk and billing leads. Ask what they ignore and why.
Days 61 to 90: measure and expand
Compare the pilot sites' unit against baseline and against non-pilot sites.
Expand to remaining sites if the unit moved; fix the data or workflow if it did not.
Score Wave 2 candidates with the four-question rule and pick the next one.
Frequently asked questions
What is RCM automation?
RCM automation is software that performs or prepares the repetitive work of the healthcare revenue cycle, from eligibility checks and prior authorization to claim edits, payment posting, denial management and A/R follow-up. It includes rules engines, RPA bots and AI agents.
What should be automated first in revenue cycle management?
For most practices, eligibility and benefits verification and claim scrubber edits based on your own denial history. They prevent the most downstream denials, use mature transactions and show results within a quarter. Specialty and behavioral health practices with authorization-heavy denials should add prior authorization to that first wave.
Can AI do medical billing and coding?
AI can suggest codes, flag documentation gaps, draft appeals, read EOBs and route work. It should not make final coding decisions on complex or high-dollar cases without a certified coder's review, and every suggestion should show its source.
Will AI replace medical billers?
It changes the job more than it removes it. Status checks, data entry and first drafts shrink; exception handling, payer escalation, appeals strategy and front-end coaching grow. Groups that redeploy staff to those tasks get more from automation than groups that cut headcount first.
What is the difference between RPA and AI agents in revenue cycle management?
RPA repeats fixed clicks on a screen and breaks when the screen changes. AI agents read unstructured documents and choose the next step within limits you set. Use standard transactions and APIs where they exist, RPA for stable screens, and agents for reading and drafting.
Should we outsource medical billing or automate it?
Outsource for capacity, automate for unit cost and visibility. If you outsource, keep ownership of your raw claim and remittance data so you can measure the vendor and automate later.
How long does RCM automation take to show ROI?
Eligibility and scrubber improvements often show movement in initial denial rate within one to two quarters. Underpayment recovery and coding assist take longer because they depend on contract loading and coder adoption. Baseline first, or you will not be able to tell.
Is AI in revenue cycle management HIPAA compliant?
It can be, depending on the vendor's controls and your agreements. Require a BAA, ask where PHI is stored and processed, and ask about audits. OutcomeCatalyst is HIPAA-aligned and SOC 2 Type 2 aligned, with the formal audit underway and expected to complete before year-end.
Is RCM automation worth it for a small or specialty practice?
Often yes, if you start with what your PM system and clearinghouse already include (batch eligibility, scrubber edits, ERA auto-posting) and turn those on fully before buying anything new. The larger gains come when multiple sites or systems need one view of denials and contracts.
Sources
Experian Health, "State of Claims 2025" survey results. experian.com
CAQH, "2024 CAQH Index Report." caqh.org
American Medical Association, "Fixing prior auth: Nearly 40 prior authorizations a week is way too many." ama-assn.org
Premier Inc., "Claims Adjudication Costs Providers $25.7 Billion." premierinc.com
AKASA, HFMA Pulse Survey on generative AI in the revenue cycle (April 2025). akasa.com
MGMA Stat, "Automating and outsourcing medical practice revenue cycle management" (November 2024 poll). mgma.com
Centers for Medicare & Medicaid Services, "CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F)" fact sheet. cms.gov
Centers for Medicare & Medicaid Services, "Good Faith Estimate and Patient-Provider Dispute Resolution Process for Uninsured or Self-Pay Individuals." cms.gov
OutcomeCatalyst connects the systems you already run into a governed intelligence layer your team and your agents can reason over. Demos on this site use fictional data. To see this on your own practice, start a conversation.
Your systems, your documents, and what your people have been carrying around in their heads. Thirty minutes to see what an AI brain could look like in your company.
Book a strategy call
© 2026 OutcomeCatalyst
