Inspiration: The Unequal Battlefield
Over 100 million Americans carry medical debt. It is the leading cause of personal bankruptcy in the United States.
Most people believe patients go broke because healthcare is expensive. The uncomfortable truth is more insidious: billing algorithms run against patients every day, and patients have no counter-algorithm.
Hospitals routinely use automated revenue-cycle management software to "unbundle" procedures—splitting single, comprehensive medical interventions into multiple separate CPT codes to bill insurers and patients twice for the same work.
When a confusing, 6-page Explanation of Benefits (EOB) arrives in the mail, patients have 30 days to dispute it before it converts into legal balance debt. Lacking medical billing degrees, 95% of patients surrender and pay.
We built UNBUNDLE to arm patients with an automated, institutional-grade counter-sentinel that audits medical claims before they become debt.
What It Does: A Medical Billing Sentinel
UNBUNDLE is not a conversational chatbot or a patient portal widget. It operates on the Aviation Ground Proximity Warning System (GPWS) / "Dark Cockpit" philosophy:
- Complete Background Silence: When claims arrive with clean billing, the system stays silent. No notification spam, no "AI thinking" animations.
- Deterministic Rejection of Invalid Claims: When an unbundled or upcoded claim arrives, the sentinel halts processing, sounds a red annunciator alert, and flags the exact violation against official federal standards.
- Least-Privilege Remediation: Instead of giving an AI model full authority to negotiate or sign documents, UNBUNDLE generates legally binding dispute packets and requires cryptographic human authorization (WebAuthn Passkey) before anything is transmitted.
The Core Audit Logic
When auditing a claim with multiple procedure codes, UNBUNDLE maps procedure pairs against the official Centers for Medicare & Medicaid Services (CMS) National Correct Coding Initiative (NCCI):
$$ \text{Violation}(\text{CPT}_1, \text{CPT}_2) \iff \text{NCCI_PTP}(\text{CPT}_1, \text{CPT}_2) = \text{Non-Payable} $$
For our benchmark EOB (St. Jude Medical Center, Claim #CLM-2026-0891), the hospital billed a surgical laparoscopic appendectomy along with an exploratory laparotomy:
- CPT 44970 (Laparoscopic appendectomy): \$2,850.00
- CPT 49320 (Diagnostic laparoscopy, separate procedure): \$1,430.00
Under CMS NCCI Chapter 6 regulations, CPT 49320 is a column-two component mutually exclusive to CPT 44970 when performed at the same operative session. The sentinel isolated this violation instantly:
$$ \text{Total Illegal Balance Billing} = \$1,430.00 $$
How We Built It: Layered Defensive Architecture
UNBUNDLE combines fast agentic reasoning with zero-trust deterministic barriers:
- AWS Bedrock AgentCore (Cognitive Layer): Orchestrates document ingestion and claims lifecycle. Extracts raw EOB fields, service dates, procedure descriptions, and modifiers from unstructured hospital bills.
- CMS NCCI PTP Rule Engine (Deterministic Barrier): LLMs are prone to hallucination and cannot be trusted with legal arithmetic. UNBUNDLE pipes extracted CPT codes into a local, compiled SQLite database containing the official CMS NCCI Procedure-to-Procedure (PTP) edit matrix. If CMS says two codes cannot be billed together without an allowed modifier (Modifier Indicator 0), the rejection is deterministic.
- Cedar Policy Engine (Authority Attenuator):
Implements AWS Cedar least-privilege access rules. The agent's intelligence is broad, but its operational authority is deliberately constrained:
- The agent can read EOBs and propose dispute letters.
- The agent cannot sign letters, dispatch emails to hospital billing departments, or alter patient records without explicit policy clearance.
- WebAuthn / FIDO2 Passkey Authorization: Before a generated dispute packet or appeal letter can be released, the patient must approve the action via hardware-backed WebAuthn (Touch ID, Face ID, or YubiKey). No root private keys or unprotected API keys can be compromised by the agent.
- Deterministic Terminal Receipt (
run_receipt.py): A sub-second test harness that evaluates 7 comprehensive adversarial test cases (unbundled claims, clean claims, mutually exclusive codes, missing modifier indicators, Cedar policy denials) and prints a cryptographically verifiable proof table in 0.4 seconds.
Challenges We Faced & How We Solved Them
1. Eliminating LLM Hallucinations in Medical Coding
Medical billing codes (CPT/HCPCS) have strict legal definitions. Early prototypes that asked LLMs "Are these two codes bundled?" frequently produced plausible-sounding but legally invalid answers. Our solution: We separated cognitive extraction from rule evaluation. The Bedrock model is only permitted to extract the CPT codes from the document; the bundling determination is executed exclusively by our deterministic NCCI SQL engine.
2. The Agentic Authority Trap
Autonomous agents that can take real-world financial or legal actions risk catastrophic failure if prompted adversarially. Our solution: We integrated Amazon Cedar authorization. Even if the Bedrock agent is jailbroken or confused by a malicious hospital note, Cedar policies deny any attempt to transmit disputes without valid cryptographic patient signatures.
3. Fighting "AI UI" Clutter
Most hackathon projects fill the screen with pulsing chatbots, streaming text, and unnecessary metrics. In medical billing, patients are already stressed. Our solution: We enforced the "Dark Cockpit" design standard. Clean claims show as calm, green status indicators on the Silence Ledger. Only active billing violations turn the dashboard amber/red with specific, actionable remediation.
What We Learned
Medical billing complexity is not accidental; it is an asymmetry created by institutional algorithms operating against defenseless humans.
Building UNBUNDLE taught us that effective AI agents must have narrow authority. By bounding generative AI with deterministic statutory rules (CMS NCCI) and formal access policies (Cedar), you can create an autonomous system that consumers can trust with their financial survival.
What's Next for UNBUNDLE
- Direct Payor EDI 835 / 837 Integrations: Ingesting claims straight from insurance clearinghouse streams before physical mail is even printed.
- Hospital Revenue-Cycle API Adapters: Transmitting formal dispute packets directly into hospital Epic and Cerner billing gateways.
- Surprise Billing & No Surprises Act (NSA) Engine: Expanding beyond NCCI edits to automatically audit out-of-network emergency room rates against independent dispute resolution (IDR) thresholds.
Built With
- agentcore
- ai-agents
- aws-bedrock
- cedar-policy
- dark-cockpit
- deterministic-receipts
- fastapi
- fido2
- healthcare
- medical-billing
- ncci-edits
- python
- react
- sqlite
- tailwind-css
- typescript
- webauthn
Log in or sign up for Devpost to join the conversation.