Built for the people who have to sign off.
Appelo is a revenue-cycle tool for healthcare, so protecting PHI isn't a feature — it's the architecture. Here's exactly how we treat your patient and claims data, and how we keep your team in control at every step.
Human-in-the-loop by design
Appelo prepares and drafts. A member of your staff reviews and approves every output before anything is submitted. No clinical or coverage decision is ever automated.
Built for HIPAA
PHI is designed to be encrypted in transit and at rest, with role-based, least-privilege access and administrative, physical, and technical safeguards. Controls follow the SOC 2 framework, with independent audit on the roadmap.
Isolated cloud architecture
The app runs on HIPAA-eligible AWS inside a private network. The database is never exposed to the internet, and every tier is reachable only through a hardened, monitored edge.
BAA-backed, end to end
We sign a Business Associate Agreement with every practice we work with — and the AI that drafts your appeals runs under a BAA too, on a covered, HIPAA-ready path.
Never trained on your data
Your patient and claims data is never used to train AI models — ours or our providers'. It is processed to do your work, and for nothing else.
Complete, exportable audit trail
Every AI draft, every human approval, and every sign-in (and failed attempt) is logged with who, what, and when — and exportable for your own compliance review.
The architecture, end to end.
Appelo runs on HIPAA-eligible AWS. PHI only travels over encrypted connections through isolated, monitored tiers — and the AI that drafts appeals is reached privately, inside the network.
Encrypted in transit (TLS) and at rest (KMS) · database unreachable from the internet · BAA-covered AWS services only.
One denied claim, through the whole system.
- 1
Sign in
Dana (revenue cycle) signs in with Google. The request crosses Route 53, a web application firewall, and the load balancer before it reaches anything.
- 2
How the claim got here
This claim entered from an uploaded 835 remittance (or 837 file) — or a provider email to the intake address. Files are stored encrypted in S3 and reconciled in-VPC; payments post, denials route to the queue, underpayments get flagged. No clearinghouse integration, and nothing leaves the AWS network.
- 3
Load the claim
The app — running in a private subnet on Fargate — reads the denied knee-arthroscopy claim (CLM-2026-04471, denial CO-197) from the encrypted database.
- 4
Track the lifecycle
Before this denial, the claim moved through its lifecycle — submitted, accepted, adjudicated — each transition timestamped on its timeline. When a payer underpays or denies, Appelo flags it and routes it into the appeal workflow you see here.
- 5
Draft — grounded, not guessed
The agent sends only the context needed for this appeal to Claude on Amazon Bedrock, over a private VPC endpoint — so the PHI never leaves the AWS network. The letter streams back citing only real payer/CMS policy from Appelo's continuously-updated policy feed; it can't invent a policy number.
- 6
Check the draft
A second AI pass verifies every factual claim against the actual text of the documents on file — quoting the line that backs it, flagging anything the record doesn't state or contradicts — and pulls only the minimum-necessary excerpt (e.g. the imaging read, not the whole note) for attachment.
- 7
A person approves
Dana sees the documentation-readiness check, closes or confirms any open gaps, edits if needed, and approves. Submit stays locked while a gap is open — an override is logged. Nothing is submitted automatically; the human makes the call.
- 8
Submit & record
The approved letter is saved and submitted. The AI draft, the human approval, and the full agent trace (which model ran, for how long) are written to an immutable, exportable audit trail. Infrastructure access is logged separately in CloudTrail.
Overnight, a scheduled agent drafts newly denied claims so they're grounding-checked and waiting in the review queue by morning — still, nothing is submitted until a person approves.
The AI drafts. A person decides. The data stays covered.
Appelo uses frontier AI to draft appeals and spot documentation gaps — but the model never acts on its own, and the data it sees is handled under contract.
- Human-in-the-loop. No clinical or coverage decision is automated. Your staff reviews and approves every output before it leaves the building.
- Starts at the point of care. A clinical note can be checked against the payer's requirements the moment it's written — conservative-care sequencing, prior auth, documentation — so conflicts surface as next actions for the care team, not as denials months later. The note is processed in-VPC like everything else.
- Grounded, never guessed. Letters cite only real, curated payer policy — the agent can't invent a policy or LCD number.
- Every claim verified. A second AI pass checks each claim against your documentation before you approve; unsupported claims become open documentation gaps that must be closed or confirmed.
- Runs on Amazon Bedrock. Claude is reached through Bedrock over a private VPC endpoint, covered by our AWS BAA — so PHI never traverses the public internet to a consumer endpoint.
- No training on your data. The model is used to do the task in front of it, then governed by the agreed retention terms. Your data never trains a model.
- Minimum necessary. Only the context needed for a given appeal is sent to the model — and only the required excerpt (e.g. the imaging read, not the whole office note) is prepared for attachment.
- Learns from your data only. When a payer decision is recorded, Appelo updates that payer's playbook from your own completed outcomes to strengthen the next appeal — using only your practice's data, never another customer's without de-identification and a BAA.
- De-identified benchmarks. Peer benchmarks are built from de-identified aggregates only — never per-practice or per-claim data — and any cohort below 11 practices is suppressed, so no group is ever identifiable.
Where your data never goes.
Never used to train models
Your data is never used to train AI models — ours or our providers'. It is processed to do your work, then governed by the agreed retention terms.
Never sold or shared
PHI is never sold, rented, or shared with third parties for advertising or any purpose outside delivering the service to you.
Never on uncontrolled hardware
Production PHI lives only inside HIPAA-eligible, access-controlled AWS infrastructure — not on laptops, personal drives, or unmanaged hosts.
Never beyond covered services
Data flows are designed to stay within services covered by a Business Associate Agreement — including the Bedrock path that drafts your appeals.
Bring your security review.
We'd rather walk your team through the architecture up front. Ask for our security overview, BAA template, and data-flow diagram.