XpertDox
Autonomous medical coding through the XpertCoding product, paired with a business intelligence layer reporting coding accuracy, billing levels and provider performance, with dashboards for fee for service, quality measures and risk adjustment. Founded 2015 in Birmingham, Alabama by two physicians, originally to improve clinical trial access; the first product was XpertTrial, a trials database and patient recruitment platform. Corporate headquarters is now Scottsdale, Arizona with a Birmingham regional office, and company press materials variously give Scottsdale and Phoenix. Led by co founder and chief executive Sameer Ather, a physician with a doctorate, with Mateo Montoya as chief technology officer.
The architecture is explicitly hybrid: ensemble machine learning models, neural networks and rules based clinical intelligence together, rather than a single end to end model. Integration is unusually broad at the connection layer, covering API, SMART on FHIR, HL7 ADT messaging and robotic process automation, which suits smaller organizations without modern integration engineering.
Published accuracy and turnaround figures do not agree across the company's own materials and should not be quoted without checking the date of the source. Claims located include 95 percent of claims coded within 12 hours at 95 percent accuracy, 98 percent accuracy within 24 hours, and 99 percent accuracy within 24 hours. This is a disclosure quality problem rather than necessarily a performance one, and it is graded as such.
Market position is the clearest differentiator in the category. XpertDox targets federally qualified health centers, urgent care, primary care and pediatrics rather than academic medical centers and large integrated delivery networks, and its risk adjustment and quality measure reporting depth fits the value based care arrangements common in that segment. A named FQHC customer is Community Health Programs of the Berkshires, announced November 2025. The company also distributes through billing companies, including a 2024 alliance with Positive Results Billing, and is listed on the athenahealth Marketplace.
Funding is small, roughly 2.5 million dollars total, including 1.5 million dollars in 2022 led by the leadership of TN3, an Arizona private equity firm. That capital position, set against enterprise competitors holding tens of millions, is the material risk to record on the supply chain and viability axes.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The engine is the product. Clinical documentation is extracted from the record system, a proprietary hybrid model assigns the codes, and claims are submitted, with the company describing minimal human supervision across the automated share. Nothing underneath would function without the model.
The business intelligence layer is worth naming as a qualification and then dismissing as one. Dashboards, provider benchmarking and audit trails are substantial parts of what customers describe valuing, and they are reporting on the model's output rather than an independent product. The company also retains a manual review queue for claims the engine declines, which is the correct design in this category rather than a dilution of it.
Both boundary numbers are published and a validation mechanism sits behind them, which puts this near the top of the B band. Automation is stated above 94 percent and accuracy above 99 percent, and the company publishes a comparison table placing competitors at 50 to 70 percent automation and above 95 percent accuracy, which is a claim about rivals rather than a disclosure about itself and should be read as such.
The oversight design is more fully described than most of this lane. A manual review claims workflow is a named component of the platform rather than an implied fallback, multi step quality control is listed as a distinct feature, and an audit trail runs underneath. A buyer can therefore see what happens to the charts the engine does not take.
What holds it below A is the same gap that separates the rest of this category from Fathom: no contractual service level agreement on automation rate, accuracy or turnaround was located, so the published figures carry no enforceable commitment. The free first month does function as a validation trial in the way Fathom's risk free trial does, letting a provider check quality on their own claims before relying on it, and that is the closest thing to recourse on offer.
The architecture is stated with unusual specificity for this category. XpertCoding is described as a hybrid engine combining ensemble models, neural networks and symbolic reasoning together with payer guidelines, and the company presents the hybrid design as its differentiator against single approach systems. Naming symbolic reasoning alongside neural components is a real architectural disclosure and it explains how payer specific rules are enforced deterministically while the learned components handle the language.
Output scope covers CPT and ICD-10 with explicit support for Category II performance codes, hierarchical condition categories for risk adjustment, and clinical documentation improvement. Turnaround is quantified rather than described: above 94 percent of claims submitted within 24 hours and the remainder within 48. Model training period is stated at under one month.
Two gaps. No foundation model, model class or training data provenance is disclosed behind the word proprietary. And the accuracy figure is not stable across sources: material located in this pass gives 95 percent within 12 hours, 98 percent within 24 hours, and above 99 percent on the current site. The current figure should be used and dated rather than treated as a settled number.
The word proprietary is doing the work that enumeration should. The hybrid engine is described at the level of technique, ensemble models, neural networks and symbolic reasoning, and no party behind any of it is named. No foundation model provider, model class or version, no hosting arrangement, no sub processor list, and no position on whether customer documentation contributes to model development was located.
One element of the architecture partially answers the provenance question by implication rather than by statement. Symbolic reasoning over payer guidelines suggests a rule layer maintained in house against published payer policy rather than learned from customer data, which would be a cleaner supply chain than a purely learned system. The company does not say so, and the index does not infer it.
The certification set is the mitigating factor that keeps this off the bottom of the band. An information security management certification carries supplier and third party control requirements, so a control framework covering the chain exists even though its contents are not published. Ask for the base model, the sub processor list, and how the payer rule layer is sourced and updated.
The strongest customer evidence in this lane by breadth, and it is named rather than anonymised. Roughly nineteen customer organisations are published by name, spanning federally qualified health centers, urgent care, pediatrics, primary care and at least one large integrated system, with several attributed testimonials carrying quantified outcomes: a 15 percent increase in charge capture with a 22 percent reduction in claim denials at one, coding related denials below one percent at another, charge entry lag under two days with a 20 percent charge capture increase at a third, and a 32 percent quality score improvement across a payer at a fourth.
Third party presence is real but is review platform rather than research. The product carries ratings and a performance badge on a software review site, a five out of five rating and a 2024 revenue cycle award on a health system marketplace, and appearances on trade media company lists. Those reflect customer satisfaction and editorial selection, not measurement.
Held at B rather than A because nothing independent has validated the automation or accuracy figures. There is no research organisation spotlight of the kind covering Fathom and Arintra, no peer reviewed publication, and no audited accuracy measurement against a gold standard. The named customer outcomes are customer reported, which is stronger than vendor reported and weaker than assessed.
More is published here than anywhere else in this lane, and it is specific rather than gestural. The security programme is broken into named control domains: access controls, data encryption, data backup, risk assessments, network security and workforce training. Encryption and access control appearing as stated commitments rather than as an implication of a certification badge is genuinely uncommon in this category, and a business continuity management certification covers the backup and availability side that most vendors leave entirely undescribed.
All of it is externally assessed rather than self declared, through an information security management certification and a service organisation control report at the more demanding of the two report types.
Held at B rather than A because the stewardship specific questions remain open. There is no retention schedule, no statement on whether customer documentation contributes to model development or improvement, no de identification position, and no breach or incident disclosure. Those are the questions a health system asks after the certifications are satisfied, and the trust center is the natural place to answer them.
The health privacy claim is presented in a form that does not exist, and that is the finding on this axis. The company displays a compliance badge alongside its genuine certifications, labelled and styled as a certification. There is no certification scheme for the federal health privacy rule; compliance with it is a legal obligation attested to by the covered entity and its business associates, not a credential awarded by an assessor. Presenting it as a badge next to three real certifications invites a buyer to read all four as equivalent when one is a category error.
The substantive position is better than that presentation suggests. An information security management certification and a service organisation control report both cover control domains that overlap substantially with the health privacy security rule, so the underlying controls are externally assessed even though not against a health specific framework. What is missing is any health specific certification of the kind two competitors in this lane hold.
No business associate agreement posture, template or execution requirement was located. Graded C rather than higher for the missing health specific assessment and the miscategorised badge, and rather than lower because real externally assessed controls sit underneath.
The most substantial security disclosure in the autonomous coding lane, from the smallest company in it.
Three externally assessed credentials are displayed, and critically one of them carries its type. A service organisation control report is specified as the second report type, which is the one covering operating effectiveness over a period rather than design at a point in time, and stating the type is the distinction most vendors blur. Alongside it sit an information security management certification and a business continuity management certification, the latter covering a domain almost nobody in this category addresses at all. All three carry a verb and a scope boundary and therefore count as evidence rather than assertion.
A dedicated trust center exists as a standing page, linked from both the primary navigation and the footer, and the underlying control domains are enumerated on the public site: access controls, data encryption, data backup, risk assessments, network security and workforce training.
Graded A on the strength of three real credentials plus a trust center, against competitors holding one credential and no trust center. Two things would need to be true for this to be unimpeachable and are not: no certification date, audit period, auditor or report request process was located, and a fourth badge on the same row claims a certification for a framework that has no certification scheme, which is recorded on the privacy posture axis.
No device pathway applies and none is claimed. Assigning billing codes from documentation is an administrative determination rather than a clinical one, so the absence of a clearance is correct and is not a gap.
The exposure sits in claims submission, where codes are representations to a payer and the framework for error is federal false claims enforcement, landing on the billing provider rather than the vendor. The company's payer specific claim scrubber and rule alignment are aimed squarely at that risk, which is the right posture.
One feature carries a regulatory dimension the company does not address. Proactive charge recovery identifies and recovers missed charges on claims already submitted, which means generating corrected or additional claims against past encounters. Rebilling prior periods sits closer to payer audit and overpayment rules than forward coding does, and nothing published describes the controls, documentation standard or provider approval governing it. Graded C rather than lower because the regulatory position is otherwise correctly represented.
The drift instrument exists and is described in enough detail to see what it reports. Daily reporting covers level of billing, claim volume and provider performance, the analytics suite benchmarks provider and clinic performance against each other, and average billing trends with provider score comparisons are named dashboard components. Distribution of assigned billing levels across providers is precisely the aggregate view that makes systematic upcoding or downcoding visible, and it is a standing report rather than something produced on request during an audit.
A multi step quality control process and an audit trail sit alongside it at the individual claim level, so the population view and the case view are both covered.
The governance question this raises is one the disclosure itself invites. Multiple published customer outcomes describe charge capture rising by 15 to 20 percent and billing levels moving after implementation, which is the intended commercial effect and is also, structurally, what a drift problem would look like from the outside. Nothing published distinguishes recovered legitimate revenue from level inflation: no distribution against an expected benchmark, no external audit of coded output, no bias or fairness testing, and no validation methodology. Held at B because the instrument is real and no result from it is published.
A stated performance level exists to hold the vendor to, which is the threshold Arintra fails. Accuracy above 99 percent, automation above 94 percent, and claim submission within 24 hours for the same share are all published as numbers, and customer references independently report coding related denial rates below one and two percent, which is the nearest thing in this lane to a published reversal rate even though it comes from customers rather than the vendor.
Two mechanisms sit between the claim and the buyer's risk. A complimentary first month lets a provider validate coding quality on their own claims before relying on it, which is the same instrument Fathom offers and which converts an unverifiable claim into a testable one at no cost. Multi step quality control and a manual review queue handle the charts the engine declines.
None of it is recourse. No service level agreement, warranty, indemnity or remediation commitment was located, no confidence threshold governing autonomous handling is disclosed, and no accuracy breakdown by coding element exists, which matters because evaluation and management level assignment is both harder and more often challenged on audit than procedure code selection. The provider carries the false claims exposure regardless. Ask what contractual commitment, if any, attaches to the published accuracy figure after the free month ends.
The strongest interoperability disclosure in the lane, on both credentials and standards.
Two vendor marketplace listings exist and both are externally verifiable: a listing in the dominant record system vendor's showroom and a listing on a second major ambulatory vendor's marketplace. Those satisfy the credential test in a way that an adjective about integration quality does not.
The connection layer is enumerated rather than summarised, covering robotic process automation, direct interface integration, HL7 ADT messaging and SMART on FHIR. Naming four distinct mechanisms including two published standards tells a buyer exactly how the product will reach their environment and lets them match it against what their own system supports, which no competitor in this lane does. The company positions the product as record system agnostic on that basis, and states that no client side technical support is required to implement, which is a claim about integration burden that a buyer can test cheaply during the free first month.
Both directions are covered: extraction of clinical documentation inbound and automated claim submission and posting outbound. Graded A because the credentials are named, the standards are enumerated, the mechanism list is broad enough to fit most environments, and the round trip is addressed.
The hosting position is undescribed. No cloud provider, region, residency commitment, tenancy model or customer controlled deployment option was located for the processing of clinical documentation.
One infrastructure detail was visible during retrieval and is deliberately not being treated as evidence: the company serves marketing assets from a public cloud bucket in a named United States region. Website asset hosting says nothing about where protected documentation is processed or stored, and inferring the latter from the former would be exactly the kind of unsupported leap this index avoids.
What is published that bears on this axis is the business continuity side. A business continuity management certification and a stated data backup control mean recovery and availability are externally assessed, which is more than any competitor in this lane offers and is a different question from residency. The trust center is the natural place to state processing region and tenancy, and it does not.
Ask for the processing and storage regions, the tenancy model, and whether any personnel outside the United States hold access to production data.
The most complete commercial disclosure in the autonomous coding lane, which is notable given this is also the smallest company in it by capital raised.
Three things are published that peers withhold. The pricing mechanism is named: per claim, described as transparent and flexible, which tells a buyer how cost scales with volume rather than leaving them to discover it in negotiation. Implementation economics are stated: zero upfront fees. And a complimentary first month of coding is offered, which converts the evaluation from a paid pilot into a free one. The company additionally states that no client side technical support is required and that the training period runs under one month, both of which are real costs at other vendors and are quantified here.
Held at B rather than A only because no absolute price or range is published, so a buyer knows the unit and not the rate, and cannot model total cost without contacting sales. The comparison table framing much of this positions competitors as offering none of these terms, which is a marketing claim about others rather than a disclosure about itself.
Ask for the per claim rate, whether it varies by specialty or claim complexity, and what happens to the rate on claims routed to manual review.
Coverage is deep in ambulatory outpatient and the published customer roster corroborates it rather than merely asserting it. Named organisations span federally qualified health centers, urgent care chains, pediatric groups, primary care, multi specialty groups and a billing company, which is a coherent segment rather than a scattered list.
The coding depth matches that segment specifically. Support for Category II performance codes, hierarchical condition category risk adjustment and quality measure reporting is the exact combination that value based arrangements in community and safety net settings require, and it is a genuine differentiator against competitors optimised for fee for service volume in large systems.
What is absent bounds the record. No inpatient, emergency department or surgical coverage was located, and the architecture and references point away from the academic medical center and large integrated delivery network buyer that Fathom and Arintra target. A buyer should read this as a segment fit rather than a limitation. Nothing addresses coding regimes outside the United States.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published as an amount; per claim basis stated
|
Per claim. The company publishes a flexible pricing model described as transparent per claim pricing. The rate itself, and whether it varies by specialty, claim complexity or manual review routing, is not disclosed. | Not disclosed. No business associate agreement posture, template or execution requirement was located. Note that the company displays a health privacy compliance badge styled as a certification, for a framework that has no certification scheme; the genuine credentials are an information security management certification, a business continuity management certification and a service organisation control report at the second report type. | Zero upfront fees stated. A complimentary first month of coding is offered as a risk free trial. Model training period stated at under one month, and the company states no client side technical support is required to implement. | Vendor Published |
The most complete commercial disclosure in the autonomous coding lane, from the smallest company in it by capital raised. No absolute price or range is published, so a buyer knows the unit of charge and not the rate. What is published, and what peers withhold, is the mechanism and the entry terms: per claim pricing described as transparent and flexible, zero upfront fees, and a complimentary first month of coding offered as a risk free trial.
The company additionally states a model training period of under one month and that no client side technical support is required to implement, both of which are real costs at other vendors in this category and are quantified here rather than left to discovery. Much of this is presented in a comparison table positioning competitors as offering none of these terms, which is a marketing claim about others rather than a disclosure about itself and is recorded as such.
The free first month is also the vendor's de facto recourse mechanism, since no service level agreement, warranty or indemnity was located, so a buyer should establish what contractual commitment attaches to the published accuracy figure once the free period ends. Ask for the per claim rate, whether it varies by specialty or claim complexity, and how claims routed to manual review are billed.