RCM & Prior Auth AI
M

MDaudit

MDaudit sells a cloud platform for billing compliance and revenue integrity to health systems, physician networks, regional hospitals and ambulatory surgery centers, and says more than 100 US health systems with over $1 billion in net patient revenue use it. Compliance and revenue teams run scheduled, risk based, denial and coding quality audits of physicians, hospitals and coders in one workflow, alongside billing and denial risk analytics. Payer Audit Management tracks RAC, TPE and CERT audit requests and exchanges records with review contractors electronically.

In August 2025 MDaudit completed its acquisition of Streamline Health Solutions, bringing eValuator and RevID into the suite. eValuator reviews every encounter between coding and billing with a rules engine that learns from encounter and audit data, while a team of coding specialists writes and refines the rules. RevID reconciles charges before the claim goes out.

The newer AI pieces sit on top of that workflow. Auditor Assist, launched in July 2026, reads medical records and coded claims to assess coding integrity, learns from auditor decisions and leaves the final call with the auditor. SmartScan.ai pulls patient and audit details out of payer request letters, and AI Assist answers questions about claims, denials and audit data in plain language. Denials Predictor works differently, applying a payer rules engine to flag high dollar charges likely to be denied.

The platform runs on AWS and holds HITRUST r2 certification plus a HITRUST ai1 certification for AI security, with reports released through its trust center on request.

AI Health Index verifiedOctober 11, 2026
Compare MDaudit with other vendors
Founded
—
Headquarters
Wellesley, Massachusetts, United States
Website
mdaudit.com/
Categories
rcm-and-prior-auth, autonomous-medical-coding
Indexed Products
Auditor Assist, eValuator, RevID, Payer Audit Workflow, SmartScan.ai, AI Assist, Denials Predictor
Buyer Segments
Large IDN, Community Health System, Academic Medical Center, Medical Group
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
CC on AI CentralityArtificial intelligence is a feature layer on a product whose value stands without it. A learned component is a model whose parameters are estimated from data: machine learning, or a statistical model fitted to population data, including one then updated on the patient measurements. A fixed formula, a rule set, or a feedback controller that adjusts a dosing factor from the patient own readings is not one, however patient specific its output and whatever the vendor calls the adjustment.
Vendor Published

Audit workflow and analytics are the core of the platform: scheduling audits, routing findings, tracking coder and provider performance, managing payer audits and monitoring billing risk.

Learned models run inside several modules. eValuator's engine learns from encounter and audit data to group cases and surface rule candidates, Auditor Assist reads records and coded claims to assess coding integrity, and SmartScan.ai extracts data from payer letters. Denials Predictor runs on payer rules rather than a learned model. The workflow and analytics work without any of these, and the models speed up and widen the review around them.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Auditors stay in charge of each finding. Auditor Assist proposes an assessment of coding integrity, the auditor makes the decision, and the tool learns from those decisions over time. In Coder Workflow, coders can contest an auditor's finding through a review and rebuttal process, and corrective action plans follow from audit results.

SmartScan.ai takes thumbs up or thumbs down feedback on each extraction, and a letter it cannot fully read is routed to MDaudit's team for review. In eValuator, coding specialists write and refine the rules the engine applies.

What sets the point at which a case is escalated, and how confidence is shown to the auditor, is not described.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Two modules come with an account of how they learn. SmartScan.ai is trained on each customer's payer letters during implementation and improves as more letters arrive. eValuator's engine finds trends in encounter and audit data and groups encounters by clinical and financial similarity, and specialists then write the rules it runs. Denials Predictor is described as a proprietary payer rules engine built on a nationwide payer base, with rule groups that show why a charge is likely to be denied.

MDaudit calls its approach augmented intelligence that keeps staff in control. No model, model family or language model provider is named for any module, including AI Assist, which answers questions in plain language, and no versioning or update practice is described.

CC on Model Supply Chain DisclosureThe architecture is described and no model provider is named. Naming a hosting provider alone does not lift a record out of this band. Record the host in the note, because it matters for residency and breach scope, and grade on the model layer, which is the question this axis is named for.
Vendor Published

Four subprocessors appear on the trust center: Amazon Web Services as the cloud provider, Okta for identity, Vanta for continuous compliance monitoring and HITRUST MyCSF.

No model provider is on the list or on the AI pages, although AI Assist answers questions in plain language. MDaudit says customer data is not shared with third party vendors, which suggests its models run inside its own AWS environment, but the model layer itself is not identified.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

Cooper University Health Care is named on an eValuator case study reporting $3.2 million in impact and a 15.9 times annual return across 8,690 audited cases. MDaudit also cites $243.9 million in combined eValuator client impact in 2025, more than $375 million retained through Payer Audit Workflow in 2025, about $40 million retained through SmartScan.ai over twelve months, and $31 million in added revenue for one unnamed customer.

Named customers include University of Chicago Medicine, Rutgers Health, Temple Health, US Oncology and UMass Memorial. The figures are MDaudit's own, and only the $31 million says how it was checked, against 835 remittance data. Auditor Assist, the newest piece, has no performance result behind it yet.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule behind them.
Vendor Published

Customer data is not shared with third party vendors or with other customers, according to MDaudit, and SmartScan.ai runs in MDaudit's private infrastructure on AWS, trained on each customer's own payer letters.

How long records, claims and audit data are kept is not stated, and nothing addresses de identified data. Guardrails against wrong outputs, and how a safety event is handled, are not described.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here. A vendor whose product does not process protected health information grades here too when it says so plainly and explains the scope, with a service privacy document behind it: stating a position a buyer can rely on is the posture this axis grades, and the band above is closed to it because there is no agreement to publish.
Vendor Published

Health systems send MDaudit PHI from their records and claims, and the company says it protects that data under HIPAA Privacy Rule guidelines, with a business associate agreement in place with AWS, its cloud provider.

Its trust center lists a 2025 HIPAA Type 1 report and a HIPAA compliance data sheet, released on request. The business associate agreement MDaudit signs with its own customers is not public, so its terms and its reach to subcontractors cannot be read in advance.

BB on Security Certifications and Trust CenterA recognized certification is named in the vendor own material without the artifact, or with a scope or renewal question the buyer has to raise. A recognized certification here is an audit of how the vendor operates security, such as SOC 2, HITRUST or ISO/IEC 27001. A certification has a scope and a clock, and both are part of this grade. A certification the vendor attaches to its data center, hosting facility or cloud provider, rather than presenting as its own, is the host's and does not count here.
Vendor Published

MDaudit holds HITRUST r2 certification and a HITRUST ai1 certification for AI security. Its trust center lists certification letters with scope and the full r2 and ai1 assessment reports, alongside SOC 2, TX-RAMP Level 2 and CORL Cleared. The site also describes a Cloud Security Alliance STAR Level 1 listing as a certification; Level 1 is a self assessment.

It runs two penetration tests a year and lists separate test reports for the MDaudit, eValuator and RevID applications, plus an external network test.

The documents are released through an access request rather than downloaded directly, and the portal does not show report dates for the r2 certification or the SOC 2 work.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalized for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Audit findings, predicted denials and reconciled charges are the work product, reviewed by compliance and coding staff before anything changes a claim. Nothing in MDaudit's materials touches diagnosis or treatment, and no device status is claimed.

The rules that govern this kind of product are payer and billing compliance rules, which is the market MDaudit sells into.

BB on AI Governance and Bias DisclosureA governance framework with named process behind it, such as certification to an artificial intelligence management standard, or material written for a customer own review committee to evaluate the product with. A framework covering the vendor whole portfolio counts when its scope reaches this product; what it cannot supply is the product specific evaluation the band above asks for. Published results within the one group where the performance of this product is most at risk also sit here: evaluation on the question this axis asks, short of the comparison across groups the band above requires. A medical device clearance or certification, and the quality system behind it, does not reach this band on its own; it is graded under regulatory status. A regulator reviewed plan governing how the model may change does reach it.
Vendor Published

A HITRUST ai1 certification covers MDaudit's AI security program, assessed on top of its HITRUST r2 core. The trust center also offers an AI solutions brochure, an AI security FAQ and a training and governance guide for AI Assist, which gives a customer's review committee material to work from.

No evaluation of coding accuracy across specialties, payers or facility types is available, so how Auditor Assist or eValuator perform on different kinds of encounters cannot be checked.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

Every finding passes through an auditor or a coding team before it changes a claim. SmartScan.ai reports that it fully extracted all data elements from 81 percent of payer letters and partly from another 12 percent, without saying how many letters were measured.

Nothing stands behind the output itself. No accuracy commitment, remediation obligation or indemnity is offered for an audit finding or a predicted denial, and MDaudit's customer terms are not public.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

Claims, remittances, audit data and medical records are the inputs, and eValuator reviews encounters between coding and billing, which requires feeds from a hospital's record and billing systems. On the payer side, Payer Audit Management sends records to review contractors through esMD and receives additional documentation requests and review results through eMDR.

No record system or encoder is named on the product pages. The trust center lists a FHIR technical workshop and data flow diagrams for MDaudit and eValuator, released on request.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

The platform runs as a single cloud service on AWS, with SmartScan.ai in MDaudit's private AWS infrastructure. Its TX-RAMP Level 2 certification is the one required for cloud services sold to Texas state agencies.

No AWS region, residency option or tenant isolation model is stated on the public pages, though network and data flow diagrams are listed in the trust center.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

Pricing comes through a demo and a quote, module by module, across billing compliance, revenue integrity and coding. The buyers are compliance, revenue integrity and coding leaders at larger organizations, and nothing is sold self serve.

SmartScan.ai is included in the External Audit Workflow module at no extra fee. No module or platform price is listed, and implementation costs are not stated.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

MDaudit sells to health systems and integrated networks, physician networks, regional hospitals and ambulatory surgery centers, and its audits cover physicians, hospitals and coders.

Named customers include University of Chicago Medicine, Rutgers Health, Acclaim Physician Group, Temple Health, US Oncology and UMass Memorial, and Cooper University Health Care is named on an eValuator case study.

eValuator's results are given for inpatient and outpatient encounters, and its page does not say whether it reviews professional claims.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Head to head

Vendors the index assesses as direct competitors to MDaudit for the same buyer.

Adjacent comparisons

Products a buyer researches alongside MDaudit that do a different job: a different category, a different layer of the stack, or a specialist scope. These pages exist to settle whether the comparison is real before it settles which one to pick.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Quoted on request
Licensed by module across billing compliance, revenue integrity and coding, sold through a demo and a quote to health systems, physician networks, hospitals and ambulatory surgery centers. Business associate agreement with AWS stated; the customer agreement is not public. Not stated. Vendor Published

SmartScan.ai comes inside the External Audit Workflow module at no extra fee. No other module or platform price is listed.