Inspiration
It starts with an official letter that millions of American families know all too well: "After careful review, your insurance claim has been denied."
Behind that decision rarely sits a doctor. Major US health insurers deny 49 million claims annually, increasingly relying on automated batch rejection algorithms. Investigations by ProPublica documented systems like Cigna's PxDx rejecting claim batches in approximately (t \approx 1.2\text{ seconds}) per file, without meaningful human physician review. Consequently, over \$220 billion in medical debt weighs down American households.
Yet there is a striking statistical asymmetry:
$$ \mathcal{P}(\text{Overturn} \mid \text{Appeal}) \in [0.60, 0.90] \quad \text{versus} \quad \mathcal{P}(\text{Abandon}) \approx 99.8\% $$
Between 60% and 90% of appeals succeed when filed, yet 99.8% of patients never appeal.
Why this massive gap? Because filing an effective insurance appeal is a complex legal instrument wrapped around a clinical evidentiary argument:
- Decoding dense CPT and ICD-10 diagnostic codes from the Explanation of Benefits (EOB).
- Retrieving exact medical necessity criteria from CMS National and Local Coverage Determinations (NCD/LCD).
- Asserting federal statutory rights under 29 U.S.C. § 1133 (ERISA § 503 full and fair review) and 29 C.F.R. § 2560.503-1.
- Demanding the clinical reviewer's medical qualifications and requesting an independent peer review.
- Complying with the strict 180-day federal filing deadline: (\Delta t = t_{\text{deadline}} - t_{\text{current}} \ge 0).
When dealing with chronic illness or recovering from surgery, no exhausted patient or caregiver has the energy to navigate this legal fortress.
However, an AI agent cannot simply take the wheel and submit legal filings autonomously. An insurance appeal is a sworn legal and medical statement executed in the patient's name, carrying sensitive Protected Health Information (PHI). Outsourcing this authority entirely to a black-box bot is unacceptable.
This core dilemma inspired ClaimWard: build an autonomous patient advocate that does all the arduous clinical and legal heavy lifting, yet remains architecturally and cryptographically forbidden from submitting without the patient's explicit review and signature.
What It Does
ClaimWard executes a 5-stage autonomous advocacy pipeline:
- Deciphers the Denial Letter: Ingests raw EOB text, hospital bills, or PDF determinations. It extracts claim numbers, billed amounts, procedure codes, diagnostic codes, denial reason codes, and the 180-day ERISA statutory filing deadline.
- Retrieves Clinical Standards: Automatically queries local CMS NCD/LCD guidelines and specialty criteria for the denied procedure (for example, CPT 72148 for lumbar MRI or J0135 for biologic therapy), identifying the exact medical necessity indicators that the insurer's denial violated.
- Drafts the Statutory ERISA Appeal: Synthesizes a formal 2-page legal appeal package. It quotes the adverse determination, cross-references documented clinical facts directly to CMS coverage rules, and asserts statutory rights under 29 U.S.C. § 1133, including mandatory reviewer qualification disclosures under § 2560.503-1(h)(2)(iii).
- Enforces the Cryptographic Patient Signature Gate (HITL): Submission is strictly blocked by Cedar zero-trust policies until the patient reviews the draft in the web portal and signs. The signature produces an unforgeable SHA-256 token cryptographically bound to the canonical digest of the reviewed letter.
- Protects HIPAA Privacy and Provides Immutable Proof: An automated redaction scanner denies any tool call carrying unredacted PHI (such as Social Security Numbers). Every authorization decision (both ALLOW and DENY) is permanently committed with SHA-256 digests into an append-only audit vault.
How We Built It
ClaimWard integrates modern AWS and open-source technologies into a zero-trust agentic architecture:
- Strands Agents SDK: The core agent orchestrator running five modular tools:
parse_denial_letter,query_clinical_criteria,draft_erisa_appeal,request_patient_signature, andsubmit_appeal_package. - Amazon Bedrock (Nova Micro): Provides rapid, cost-effective clinical reasoning across complex claim denials and policy guidelines.
- Strands Gateway Hook (
BeforeToolCallEvent): By registering our security hook at priorityHookOrder.SDK_FIRST - 1, ClaimWard intercepts every proposed tool invocation before SDK execution. If security or policy checks fail,event.cancel_toolhalts execution immediately. - Cedar Policies (
cedarpy): Implements authorization-as-code. Cedar guarantees:- Non-destructive tools (parsing, guideline queries, drafting) are permitted.
- The submission tool is strictly forbidden unless the condition holds:
$$ \text{Decision} = \text{Cedar}(\text{Agent}, \text{Submit}, \text{Appeal}) \implies \text{ALLOW} \iff (\text{human_signed} = \text{true} \;\land\; \Delta t \ge 0) $$
- Any invocation with unredacted PHI triggers an immediate, overriding DENY.
- Cryptographic Human-in-the-Loop (HITL): When a patient approves their appeal in the portal, a deterministic token is generated:
$$ \tau = \mathcal{H}{\text{SHA256}}(\text{appeal_id} \;|\; \mathcal{H}{\text{SHA256}}(\text{canonical_draft})) $$
The gateway verifies this token against the letter draft before setting human_signed = true. If the model modifies even a single character after signing, the verification fails and submission is blocked.
- Patient Portal: A modern, accessible interface built with FastAPI, Tailwind CSS, and Server-Sent Events, providing live workflow timeline tracking, an interactive signature card, and real-time audit vault inspection.
Challenges We Faced
- Balancing Full Autonomy with Patient Sovereignty: A passive chatbot that asks permission for every search is tedious; an agent that signs and files legal papers without human sign-off is reckless. We resolved this by drawing a clear boundary at reversibility: clinical research and draft generation execute autonomously, but the irreversible, legally-binding act of submission requires human authorization.
- Preventing Approval Forgery: In typical systems, "human approval" is a simple boolean flag that an LLM can simulate or carry over across modified tool calls. We solved this by cryptographically binding the approval token to the exact bytes of the drafted appeal. A signature for draft (A) cannot authorize draft (B).
- Fail-Closed Security Architecture: Ensuring that every failure mode (missing parameters, engine timeouts, format anomalies) automatically resolves to a strict DENY.
- Grounding Without Hallucination: Insurance appeals must withstand rigorous legal scrutiny by claims review committees. By grounding the drafting tool in structured CMS NCD/LCD guideline databases, every citation maps to verifiable clinical criteria.
Accomplishments That We're Proud Of
- 100% Passing Automated Test Suite: Full test coverage spanning the Cedar policy matrix (unsigned submissions, expired deadlines, unredacted PHI, missing attributes) and end-to-end multi-step agent executions on real clinical denial patterns.
- Provable Architectural Safety: Demonstrating live in the portal that attempts to submit an unsigned appeal are intercepted and denied at
BeforeToolCallEvent, logging a cryptographic DENY entry in the public audit vault. - Statutory-Grade Legal Output: Generating formal ERISA § 503 appeal packages that cite authentic statutory requirements, request medical reviewer credentials, and structure clinical arguments with precision.
- A Live, Fully Operational Patient Portal: Deployed with SSL at https://claimward.usezn.com, ready for patients, caregivers, and judges to test.
What We Learned
- Trust Is an Architectural Property, Not a Prompt: Telling an LLM "do not submit without asking" in a system prompt is fragile. True user trust comes from deterministic, code-enforced gates that make unauthorized actions structurally impossible.
- The Action Boundary Is the Optimal Control Point: Strands mutable hook ordering (
SDK_FIRST - 1) provides the cleanest enforcement surface, decoupling business logic from security rules. - ERISA Law Functions Like a Protocol: The statutory mandates of 29 U.S.C. § 1133 map naturally into policy conditions, turning administrative healthcare rights into executable software rules.
What's Next for ClaimWard
- Automated Delivery Channels: Direct electronic fax and secure payer API connectors for seamless transmission to insurer appeals units.
- Physician Attestation Chain: Integrating treating physician counter-signatures into the cryptographic approval pipeline.
- External Review Escalation: Automated escalation to Independent Review Organizations (IRO) under Affordable Care Act (ACA) § 2719 when internal appeals are exhausted.
- Expanded Guideline Knowledge Base: Broadening the CMS NCD/LCD repository to cover pediatric rare diseases, oncology therapies, and mental health parity protections under MHPAEA.


Log in or sign up for Devpost to join the conversation.