Hypex

Questions buyers ask

Hard questions, direct answers

Written for the people who sign: CFOs, compliance officers, and owner-operators. No hedging, no marketing gloss. Something missing? Tell us and we will answer it publicly here.

Cost & business model

What it costs, when it is due, and what happens if nothing recovers.

04 questions
What does this cost, exactly?

Nothing upfront. Hypex bills a flat 15% success fee on dollars the payer actually paid on claims we worked, verified against the payer's own 835 remittance before an invoice exists. You keep 85%. If a denial does not recover, that claim costs you nothing. There are no seat fees, minimums, or subscriptions. The fee basis is gross recovered dollars; partial payments are billed proportionally and takebacks are never billed.

Why a contingency model instead of a fixed SaaS price?

Incentive alignment. A per-seat vendor is paid whether or not you recover anything; our revenue is a strict function of your verified recoveries. If our attribution is wrong or our follow-ups lapse, we earn zero. That structure also removes the procurement conversation: there is no budget line to defend, only a split of money that would otherwise stay written off.

We already have a clearinghouse and an RCM vendor. Why add another vendor?

Hypex replaces nothing and competes with nobody on your stack. Your clearinghouse moves claims; your billing system posts payments. We operate exclusively in the gap after a denial: root-cause attribution, appeal drafting, follow-up escalation, and recovery verification. Industry data shows roughly half of denied claims are never reworked, for lack of staff hours rather than merit. That unworked segment is our entire scope, and it is invisible to vendors paid on claim volume.

How long until we see results?

A pilot on historical denials runs within one to two weeks of signature: upload a de-identified file, review drafted appeals in the browser, record outcomes as payers respond. Automated submission depends on payer and clearinghouse enrollment, typically six to ten weeks, but it runs in parallel, and the pilot delivers value from the first reviewed batch because reviewing drafts requires nothing more than a browser.

Data & security

Where PHI lives, for how long, and how you verify every claim we make.

04 questions
Do you ever see patient data?

Briefly, encrypted, and by design: the same way any Business Associate must. Raw fields land in an encrypted vault with a hardcoded 24-hour self-destruct; while we work your claim they exist only there, and afterward they are gone. PHI has no write path to our database, object storage, or any model context. Downstream work operates exclusively on codes, amounts, dates, and an opaque reference token. Identity re-attaches at your own submission step, on your side.

How can we verify the zero-PHI claim rather than take it on faith?

Our conformance suite is public and forkable. Point it at api.hypexrcm.com and it fires synthetic identifier-shaped probes at every public ingress, asserting nothing identifiable is accepted or stored, then exercises the de-identification engine and fail-closed boundary gate directly. Run it before signing, re-run it quarterly unannounced, and attach the PASS/FAIL output to your security review file. A failing check is a bug we want reported.

How do we know appeals are accurate and not AI fabrications?

Standard appeals contain no generative step at all: they are assembled deterministically from the denial facts and the payer's own policy language, so fabrication is structurally impossible. The optional AI path exists for complex clinical arguments; it cites its source for every assertion, strips statements it cannot trace to provided material, and caps its confidence below auto-submission thresholds when grounding is thin. In every mode, a human approves before anything leaves.

Where is our data hosted, and who can access it?

Data resides in managed cloud infrastructure with encryption in transit (TLS 1.2+) and at rest. Access is tenant-scoped at the query layer: your workspace cannot read another organization's records, and administrative access is role-gated and audit-logged. Machine-to-machine ingestion requires rotating API keys behind IP allowlists. Every human action in the console is written to an append-only, hash-chained audit log your team can export.

For billing companies & clinics

Direct answers for owner-operators evaluating the economics.

03 questions
Is this built for a small billing company like ours?

Yes. Micro-RCMs and independent clinics are a primary audience precisely because denial follow-up is labor they cannot staff. You keep your clients, payer relationships, and BAAs intact; Hypex works behind you on pure contingency. The recommended entry is deliberately small: one payer, one denial category, measured results, then expand at your pace.

How much of our team's time does this require?

Under an hour total for a pilot: provide a de-identified denial export, review drafted appeals (minutes per appeal, side-by-side with the cited rule), and record outcomes as payers respond. No IT project, no portal credentials handed over, no software installed. The operational load sits on our side: chasing payers and tracking deadlines is the system's job, not yours.

What happens when a payer simply ignores our appeals?

Silence triggers an escalation schedule, not a dead queue. Follow-up letters stage automatically at Day 14, 21, and 30, each progressively firmer, ready for your reviewer to send through your normal channel. Filing deadlines are tracked independently with alerts before windows close, so appealable dollars do not silently age out. Most recovery value in this industry lives in disciplined follow-up; that discipline is automated here.

Compliance & liability

The questions hospital compliance officers and CFOs ask first.

05 questions
Could your system submit a false or fabricated claim?

No, and the control is structural rather than procedural. Appeals are built only from the real procedure and diagnosis codes received with the denial; if correct codes are absent, the system holds the appeal rather than substituting one. Every outbound transaction passes completeness checks, and the same claim can never be submitted twice, a duplicate guard enforced at the application layer. These controls protect your compliance exposure first, not merely ours.

Who bears liability if something goes wrong?

Every engagement runs under a signed Business Associate Agreement covering all eight required elements of 45 CFR 164.504(e): permitted uses and disclosures, safeguards, breach reporting, subcontractor flow-downs, individual access, amendment, accounting of disclosures, and return-or-destruction at termination. We will also review and execute your own BAA template. Breach notice follows 45 CFR 164.410: without unreasonable delay, and no later than 60 days after discovery. The architecture makes such events unlikely because there is no durable PHI store to breach.

Are you certified? SOC 2? Audited?

A direct answer: our SOC 2 Type II examination is in progress, and a third-party penetration test is scheduled ahead of any hospital-direct go-live. What we present today is evidence rather than badges: the public conformance suite proving the zero-PHI boundary against production, plus a control matrix mapping every commitment to its enforcement mechanism. We do not display certifications we do not hold; hold any vendor who does to the same standard and ask for the report number.

What prevents automated submission from straining our payer relationships?

Layered safeguards: nothing transmits without completeness checks; double-submission is impossible by construction; auto-submission is off until you enable it; a configurable dollar cap keeps high-value claims with a person regardless of confidence; rollout is staged: one payer, one category, thirty days of remittance observation before expansion. Every threshold is yours to set and audit-log records who set it.

Who owns the data, and what happens if we leave?

You own your data. Hypex retains rights to the platform and to de-identified, aggregated insight (payer behavioral patterns, recovery benchmarks) that cannot be traced to your organization or any patient. That compounding intelligence is what makes each successive appeal stronger. On termination, your de-identified records are returned or destroyed at your election within the contractually agreed window, with a certificate of destruction available on request.

Still deciding? Start with evidence.

Upload a few de-identified denials and see the actual appeal quality before any conversation. No signup for results, nothing to cancel.

Every appeal is human-reviewed or confidence-gated before submission.

Answers last reviewed 2026-08 · terms govern over marketing copy