RCM & Prior Auth AI
L

Lyric

Payment accuracy and integrity for health plans, and the oldest company in this index by founding date: it began in 1989 and its pre payment editing engine is the former ClaimsXten, with over 30 years of rules and policy content behind it. That history matters to the AI question, because the machine learning sits on top of an established rules engine rather than replacing it. Lyric42 is the orchestration platform, coordinating payment decisions across rules, workflows, policy, and payment accuracy products, and designed to let a plan run a multi vendor strategy through one integration to core systems.

Replay is the audit automation engine, using AI to prioritize high impact claims and automate DRG validation, coordination of benefits review, and itemized bill analysis, with the company reporting up to 3x productivity and 4x findings for internal audit teams while reducing dependence on external vendors. LyricIQ provides the analytics layer. The stated framing is decision intelligence producing payment decisions that are independent, verified, and explainable, applied before disputes and rework enter the system. Named 2025 Best in KLAS for Pre payment Accuracy and Integrity, and reports serving more than 100 payers. Headquartered in Newtown Square, Pennsylvania.

AI Health Index verifiedJuly 27, 2026
Compare Lyric with other vendors
Founded
1989
Headquarters
Newtown Square, Pennsylvania
Website
www.lyric.ai
Categories
rcm-and-prior-auth, healthcare-admin-automation
Indexed Products
Lyric42, ClaimsXten, Replay, LyricIQ
Buyer Segments
Payer
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
CC on AI CentralityArtificial intelligence is a feature layer on a product whose value stands without it.
Vendor Published

Descriptive rather than critical, and unusual in that the underlying asset is not a platform but a rules corpus: over 30 years of pre payment editing content built as ClaimsXten since 1989. Machine learning and predictive analytics genuinely improve prioritization, audit targeting, and orchestration, and Replay applies AI to select which claims are worth auditing.

But the payment decisions themselves rest on codified policy and clinical rules, and the company describes decisions as grounded in policy and expert clinical review. A plan buys the rules and the accumulated policy content first; the AI decides where to point them.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The stated design goal is payment decisions that are independent, verified, and explainable, grounded in policy and expert clinical review, which places a documented rationale behind each determination rather than an opaque score. Explainability matters more here than in most categories, because a payment decision a plan cannot justify becomes a provider dispute.

Held back from A because the boundary between automated action and human review is not published: pre payment editing that automatically adjusts or denies a claim is consequential, and the company does not state which determinations execute without review. That is the same gap flagged for Banjo Health, and the same question Cohere Health answers explicitly.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

No model architecture, evaluation methodology or accuracy figure was located for the machine learning components.

The explainability position is genuine and is credited on the autonomy axis: payment decisions are described as independent, verified and explainable, grounded in policy and clinical review, which places a documented rationale behind a determination rather than an opaque score. For a category where an unexplainable decision becomes a provider dispute, that is the right design.

Explainability of a rule is not transparency about a model, though, and the two are being conflated. The rules corpus is inspectable by construction. What is not published is how the machine learning that prioritises claims for audit was trained or how well it performs: no hit rate baseline, no precision figure, and no statement of what proportion of flagged claims survive review. The company reports up to three times productivity and four times findings for audit teams, which describes throughput rather than accuracy.

The platform's acquisitions and partner tools compound this, since a plan is now buying decisions produced by several organisations' models under one interface.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No retention period, statement on whether customer data trains or improves models, or de identification posture was located, and no model, hosting arrangement or sub processor list was named. The concentration is among the largest in this index, with claims data flowing through the pre payment editing product covering a reported one hundred and eighty five million lives, and audit automation reaching itemised bills and medical records supporting diagnosis related group validation, which is clinical detail rather than transaction data.

Two questions matter and neither is inferable from marketing. The first is pooling: whether one plan's claims experience informs models or rules served to another. That is the question this category turns on, because the value of an editing corpus compounds precisely by aggregating what has been learned across payers, and a plan contributing its own denial patterns to a shared asset is funding its competitors' recovery rates.

The second concerns the multi vendor architecture, since partner tools running on the platform mean plan data reaches organisations other than the vendor the plan contracted with, and each partner has its own retention and training posture that the plan never negotiated.

A sub processor list is therefore not a formality here but the substance: ask for it, with the retention terms attached to each partner rather than to the platform operator alone, and establish which parties see clinical records as distinct from claims.

AA on Clinical and Operational EvidencePeer reviewed or independently evaluated performance, prospective and multi site where the claim requires it, with the method available to read.
Vendor Published

The strongest third party validation in the payer side cluster: named 2025 Best in KLAS for Pre payment Accuracy and Integrity, which is a buyer survey result rather than a vendor claim, in a category KLAS only began covering in October 2023. Reported scale of more than 100 payers with stated retention, against a business operating since 1989, is a durability signal that recent entrants cannot match. Replay productivity figures of up to 3x and 4x findings are vendor stated and should be treated as such.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

No retention period, no statement on whether customer data is used to train or improve models, and no de identification posture was located.

The concentration is among the largest in this index. Claims data flowing through the pre payment editing product covers a reported 185 million lives, and audit automation reaches itemised bills and medical records supporting diagnosis related group validation, which is clinical detail rather than transaction data.

Two questions matter. Whether one plan's claims experience informs models or rules served to another, which is the pooling question this category turns on and which is never inferable from marketing. And what partner tools running on the platform may retain, since the multi vendor architecture means plan data reaches organisations other than the vendor the plan contracted with. Ask for the subprocessor list and the retention terms attached to each partner, not just to Lyric.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

No business associate agreement terms were located, but the HITRUST certification the company claims incorporates the privacy and security rule requirements among the sources it harmonises, so the controls have been examined against them rather than merely asserted. That is the standard middle rung: demonstrable programme, undisclosed contract.

Business associate status is unambiguous. The company processes claims on behalf of health plans, which makes it a business associate of covered entities at very large scale.

The question worth pressing follows from the platform model rather than the company. Lyric42 is sold as a route to run a multi vendor payment integrity strategy through a single integration, with tools from partners alongside Lyric's own. Establish whether partner tools operate as Lyric's subcontractors under its agreement with the plan, or whether the plan contracts each partner separately, because that determines who the plan can hold responsible when member data is mishandled by a tool it reached through this platform.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

The company states HITRUST and SOC 2 certification consistently across its own formal announcements and site, and separately that its command centre product adheres to the privacy rule, HITRUST, SOC 2 and ISO standards. Two independent frameworks named in the company's own materials places this above the many vendors here naming one or none.

Held at B rather than A on precision, which is the same test applied across this index. No HITRUST level is stated and e1, i1 and r2 differ materially in assurance. No SOC 2 report type is given, and Type I against Type II is the whole question. The phrase SOC 2 certified is also imprecise, since SOC 2 produces an attestation report from a CPA firm rather than a certification. No trust centre or report access route was located.

The scale makes the specifics worth chasing rather than accepting. The pre payment editing product is reported in use by 100 health plans including eight of the top nine United States payers, covering 185 million lives. Ask for the HITRUST level and validity dates, the SOC 2 type and period, and whether the scope covers the newer platform and acquired products or only the legacy editing engine.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No FDA pathway applies and none is expected. Claims editing and payment integrity operate on transaction and billing data with no diagnostic or treatment decision surface.

Graded C because a real regulatory environment governs this work and no position is published on any of it. Prompt payment laws in most states set deadlines and penalties for claim adjudication, and a pre payment edit that delays a claim sits inside those timelines. Appeal and dispute rights give providers a route to overturn determinations, which makes overturn rates a regulatory as well as a commercial measure. The growing set of state laws conditioning AI involvement in coverage and payment decisions reaches this territory directly.

Unlike utilization management, payment integrity has no accreditation equivalent to URAC or NCQA, so there is no external body examining this vendor's determinations at all. That absence is the finding rather than a technicality: the only checks on a payment integrity engine are the plan's own governance and the provider's willingness to appeal.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No AI governance framework, bias evaluation or subgroup performance disclosure was located.

The direction of the product is what makes this consequential. Payment integrity systems recommend paying less, and a wrong reduction is absorbed by a provider or a member, neither of whom is the customer and neither of whom chose the vendor. Where audit targeting is model driven, the question is whether flag rates vary by facility type, geography, specialty or practice size, because documentation quality tracks the resourcing of where care was delivered rather than whether the claim was right.

Credit where it is due, and it is unusual: the company's own framing acknowledges that inaccurate payment decisions cause provider abrasion and slow payment for care already delivered, and it markets low abrasion as an objective rather than treating recovery volume as the only measure. That is a more honest statement of the tradeoff than most in this category offer. What is missing is evidence: no false positive rate, no overturn rate on appeal, and no published breakdown of either.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

The explainability position is genuine and it covers the wrong layer, which is the distinction that decides this grade. Payment decisions are described as independent, verified and explainable, grounded in policy and clinical review, which places a documented rationale behind a determination rather than an opaque score, and for a category where an unexplainable decision becomes a provider dispute that is the right design.

But explainability of a rule is not transparency about a model, and the two are being conflated. A rules corpus is inspectable by construction, so describing rule based decisions as explainable is describing a property they could not fail to have. What is not published is the machine learning that prioritises claims for audit: no architecture, no training description, no hit rate baseline, no precision figure, and no statement of what proportion of flagged claims survive review.

That selection step is where the model actually exercises discretion, because it determines which providers face scrutiny and which do not, and a provider selected disproportionately has no visibility into why. Reported productivity and findings multiples describe throughput rather than accuracy, and a system that surfaces four times as many findings while overturning more of them on review is not obviously better.

The acquisitions and partner tools compound this, since a plan is buying decisions produced by several organisations' models under one interface. Ask for the selection model's precision and what survives review.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Integration is aimed at payer core systems rather than EHRs, which is correct for this buyer. The distinguishing architectural claim is that Lyric42 delivers the advantages of a multi vendor payment integrity strategy through a single integration, so a plan can use several specialist vendors without maintaining separate connections to each. Held back from A because named core administrative systems and integration specifics were not retrieved.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

The platform is described as cloud native, which establishes delivery model but nothing else. No hosting provider, region, tenancy model or data residency commitment was located, and no subprocessor list is published.

The subprocessor question is unusually important here and is the one to lead with. The platform is explicitly designed so a plan can select, configure and deploy tools from partners alongside Lyric's own, reaching a library of editing, analytics and overpayment detection capabilities through one integration. That is the commercial argument, and it means claims data for the plan's members is processed by organisations the plan did not integrate with directly and may not have assessed.

Establish which partners are active in a proposed configuration, where each processes data, what each retains, and whether the plan is notified when a new partner is added to the platform.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Third Party Estimated

No public pricing. Contact the vendor. Enterprise agreements with health plans. Payment integrity is frequently sold on contingency against recoveries rather than licence, and that distinction materially changes vendor incentives, so buyers should establish the model. The company positions Replay partly as reducing dependence on external audit vendors, which implies a licence rather than contingency posture, but this was not confirmed.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Precisely bounded to health plan payment accuracy across both pre payment and post payment activity: claims editing, fraud waste and abuse detection, DRG validation, coordination of benefits review, itemized bill analysis, and audit automation. No claims outside payer operations.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise agreements with health plans; licence versus contingency model unconfirmed Third Party Estimated

No rate card published. Enterprise agreements with health plans. The structural question in payment integrity is licence versus contingency: many vendors in this category price as a percentage of recoveries, which aligns them with finding more overpayments rather than with getting payment right the first time. Those are not the same objective, and the difference shows up as provider abrasion. Lyric's positioning around first pass accuracy and reducing dependence on external audit vendors suggests a licence posture, but the model was not confirmed and should be established directly.