Executive Brief · For Healthcare Leaders

AI Could Transform Healthcare Operations. PHI Is Why It Hasn't.

From coding to prior auth to research, the highest-value AI work in healthcare touches protected data, which is why it's been blocked. The way through: AI that does the work without ever seeing the patient.

01Healthcare has the most to gain from AI — and the most to lose

The AI companies serving healthcare have proven the clinical upside: ambient scribes that document the visit, imaging AI that flags the stroke, precision-medicine platforms that match patients to trials. Those tools live inside applications you've vetted, and they should keep doing what they do.

But the operational middle of healthcare (coding, prior auths, denials, referrals, receivables) has barely been touched. Not because AI can't do the work. Because every screen in that work holds protected health information, and nobody could responsibly let a model read it.

Prior authorization, claims denial, and healthcare breach measures
The operational prize and the breach stakes are one and the same.

The biggest operational prize and the highest breach stakes are one and the same: the value is locked behind the PHI.

02Two lanes of healthcare AI

Clinical AI to keep and operational AI to unlock
Two lanes of healthcare AI.

03What the co-workers actually do

  • Coding and billing. Draft CPT/DRG coding from documentation, scrub claims before submission, and classify denials by root cause so the upstream fix happens, not just the rework.
  • Prior authorization. Pull the worklist, chase status across payer portals, assemble the clinical-documentation packet, and queue it for a named person's approval. Auths that don't slip mean surgery dates that don't slip: operational speed is a health outcome.
  • Accounts receivable. Match remittances to accounts, work the aging report portal by portal, and draft appeal packets for one-click human approval.
  • Patient communication. Draft condition-aware responses, reminders, and instructions, personalized to the patient's situation. Your staff review and send them, and identifiers stay masked from the model throughout.
  • Referral intake. Read the fax queue, match or create the record, check eligibility, and draft the outreach. Today, 30–50% of referrals are never completed, and every one of them is missed care.
  • Trend analysis for operations. Analyze de-identified utilization and demand patterns to inform supply inventory, staffing, and production planning. This is the analytics your teams wanted but could not run on real data.
  • Research on real records. Analyze actual studies and clinical data with personal identifiers redacted at the screen layer, unlocking work your privacy office currently has to refuse.

04The blast-radius argument

In late 2025, Anthropic disclosed that it had disrupted the first reported large-scale cyber-espionage campaign orchestrated by an AI agent: a state-sponsored group used an AI coding agent to run 80–90% of the attack autonomously, from reconnaissance and exploit development to credential harvesting and exfiltration, against roughly thirty organizations, at thousands of requests per second.

That was one vendor's disclosure, but the exposure is general. Application and cloud infrastructure, however well built, was never designed to withstand adversaries operating at AI speed and AI scale. Healthcare has been the most expensive breach target for fourteen consecutive years, and the attacks are about to get faster and cheaper to mount.

You can't perimeter your way out of that. What you can control is the blast radius: if the environment an attacker reaches holds tokens instead of patient data, the perfect attack exfiltrates nothing worth having. That is the design principle underneath RedactSure. PHI is masked at the screen layer before any model sees it, real values resolve only on approved destinations, and the audit trail itself holds no patient data. The architecture is aligned with PHI data-minimization requirements from the first design decision: the safest record is the one that was never exposed.

05Shadow AI is already in your buildings

While the sanctioned path doesn't exist, staff improvise. In our conversations with provider organizations, including a health services organization with thousands of employees, the pattern repeats: acceptable-use policies on paper, no technical controls in practice, and employees pasting notes and records into personal AI tools nobody can see or audit. A ban produces invisibility, not safety. The fix is one sanctioned door that is more capable than the shadow tools, while generative-AI category blocking on the web gateway you already own closes every other door.

06Where to start

One workflow, one department, 60 days. Prior-auth follow-up and denial appeals are the proven candidates: the pain is weekly, the hours are measurable, and the approval stays with your staff. Baseline the cycle time in week one, then let the numbers make the case to your board: hours returned, denials worked that were being written off, zero PHI exposure events.

Thirty minutes on one workflow you pick.

We come with questions, not a pitch deck. Bring your revenue-cycle lead and your security lead: the architecture was built to survive both of their hardest questions.

Book a workflow conversation →
Chris Sowa is a founder of RedactSure and a former CEO of AI companies — he started his first years before ChatGPT existed. He was previously an AI Leader at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.

Sources

  1. American Medical Association, Prior Authorization Physician Survey — 39 prior authorizations per physician per week; ~13 hours of physician and staff time.
  2. Published 2024–25 revenue-cycle denial benchmarks — 11.8% initial denial rate; ~$57 administrative cost to rework a denial; 35–60% of denied claims never reworked.
  3. IBM, "Cost of a Data Breach: The Healthcare Industry" (2025) — $7.42M average healthcare breach cost; costliest industry for 14 consecutive years.
  4. Anthropic, "Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign" (November 2025) — 80–90% of attack tasks executed autonomously against ~30 organizations.
  5. Published referral-management benchmarks — 30–50% of outpatient referrals never completed.