ZKELETON
// Product

HARROW.

Run the structural screen before the batch leaves your environment.

A deterministic engine that implements the high-risk-diagnosis-code logic OIG published in its audit toolkit, adapted to current-year submissions. It screens a claims batch before submission, flags codes that lack the corroboration the pattern expects, attaches a cryptographic receipt to every flag, and routes the medical call to your certified coders. No model in the decision path: same rows in, same answer out, every run.

demo on request · synthetic data only · no PHI anywhere

// The walkthrough

The argument, in eight frames.

Where HARROW runs, whose logic it executes, what crosses the seam to your coders, and what it refuses to do.

EXHIBIT · 8 FRAMES · SELF-GUIDED
Open the walkthrough 8 frames · about 3 minutes

// The division of labor

Human judgment. Deterministic machine. No model in between.

The engine reads structure and stops at the seam. Every finding crosses it carrying a receipt; the medical call is a person's. A batch that cannot be screened cleanly returns a refusal, not a guess.

DETERMINISTIC · MACHINEHUMAN · JUDGMENTHANDOFFREGISTERED INPUTSClaims batchE11.9 · I63.9 · J44.1Facility claimsCode listsDETERMINISTIC ENGINErev-lockedPREFLIGHTDERIVESCREENOIG A-02-23-01020no model · no clock · no randomnessreads structure, never a chartFLAG · I63.9NO_FACILITY_CORROBORATIONreceipt sha256…CERTIFIED CODERchart in handdecides medicineREFUSEDunreconciled feed · incomplete batcha refusal is an output, not a failure

same rows in, same answer out. Every finding replays byte for byte.


// Why this exists

Regulators already named the pattern.

In December 2023, OIG published a toolkit naming eight high-risk diagnosis-code groups, with the code lists and the SQL it uses to find them. In May 2026, OIG reported that CMS potentially overpaid MA organizations roughly $462 million on acute stroke codes; in the audited sample, 97 of 97 were unsupported. Its recommendation to CMS: build a prepayment check for exactly this pattern.

CMS now audits every MA contract, every year. The pattern gets looked at either way. The only variable is whether that happens before or after submission. HARROW is that check, run on your side of the submission.

$462M
OIG A-02-23-01020 · acute stroke
97/97
sampled codes unsupported
~550
MA contracts audited annually

// Two lanes, one engine

Prospective screen. Gated retrospective.

// PRE-SUBMISSION STRUCTURAL SCREEN

The toolkit's acute-stroke pattern, adapted to the current model year and run over a pending batch: an acute-stroke code with no facility corroboration where the pattern expects it gets flagged before it goes out. Adapted code lists ship labeled PENDING_CRC until an independent certified risk-adjustment coder ratifies them. No real data runs before that review clears.

// TOOLKIT REPRODUCTION

The published payment-year-2019 logic run against your historical data. Gated by design: it does not execute without your counsel-approved review protocol, because retrospective findings create obligations that belong on your terms, not a vendor's. Every artifact it produces carries the protocol's stamp.

Both lanes produce the same artifact: a Structural Pattern Review, with flagged counts over stated denominators, coder workload, and a “what this cannot tell you” block naming what was not assessed.


// From batch to receipt

Every step refuses before it guesses.

DETERMINISTIC · MACHINE.01PREFLIGHT.02DERIVE.03SCREEN.04FINDINGS.05REPLAYREFUSEDunreconciled feed · incomplete batcha refusal is an output, not a failure
.01

Preflight

Your extract is parsed against a published spec and reconciled to control totals. Preflight produces no findings, by construction: you see data quality before anything is screened, with rejects listed line by line.

.02

Lane derivation

Data-quality grades decide which lanes are allowed to run. An unreconciled feed or an incomplete batch does not produce findings; it produces a refusal with a named reason.

.03

Structural screening

Deterministic predicates over registered code lists, executed as data. No model, no wall clock, no randomness anywhere in the path. The engine reads structure; it never reads a chart.

.04

Findings with receipts

Every flag is content-addressed, carries a closed reason code and a three-way confidence split, and routes to a certified coder. Codes sourced from chart review are stratified out and routed with their chart locator.

.05

Review and replay

The run closes with the Structural Pattern Review and a replay bundle: pinned engine and pack versions, hashed inputs, and two root hashes over results and the adjudication ledger. Your team re-runs it on your own hardware and checks the bytes match.


// The artifact

Every flag carries a receipt.

A receipt states the fact, the evidence universe that was checked, the negative evidence found, the reason code, and the routing. It carries the input hashes and version pins needed to reproduce it byte for byte. What it never carries: a medical opinion, or a prediction about any audit.

The three-way confidence split is the honesty mechanism. Structural confidence can be high while clinical adequacy and audit outcome stay marked not assessed, because the machine did not assess them. That line is on every receipt.

PACKzk.stroke.screen · sy2025 / py2026 · PENDING_CRCFACTProfessional claim submitted I63.9 (acute ischemic stroke)EVIDENCESubmission universe + facility claims, service-year window: no qualifying facility encounter foundREASONAT-RISK · NO_FACILITY_CORROBORATIONCONFIDENCEstructural: high · clinical adequacy: not assessed · audit outcome: not assessedROUTINGCertified coder review, chart in hand, before submissionREPLAYsha256 input hashes · engine + pack versions pinned · re-run reproduces byte-identically

Receipts prove structure and lineage. They do not assert medical necessity, and they never predict an audit outcome.


// How it proves itself

Built to be distrusted.

You should not have to take a vendor's word for any of this, so nothing requires it.

An independent reference implementation

The engine is checked against a second implementation of the same logic, built in a different language with no shared code. Every screening stage must produce identical row sets in both. Tests are mutation-verified: break a rule and the suite fails; restore it and the suite passes.

Deterministic replay

Every run emits a replay manifest. Re-running it reproduces the result hashes exactly; tamper with one input file and verification fails naming that file. An auditor does not have to trust the report. They can re-derive it.

Falsifiable in front of you

In the demo, you edit a corroborated control case yourself: delete its facility claim and the verdict flips to AT-RISK with a new input hash, computed offline. Reset it and the original hash returns. Same rows in, same answer out is a claim you test, not one you are told.

An independent coder gate

The adaptation from OIG's published payment-year lists to the current model year is a set of documented coding judgments. Those judgments are reviewed by an independent certified risk-adjustment coder before any production run, and the engagement pays the same whether the reviewer agrees or decisively rejects.


// The falsifiability demo

Break the control yourself.

A corroborated synthetic control: one professional claim carrying the acute-stroke code I63.9, and a same-service-year facility claim that corroborates it. Remove the facility claim and the structural verdict flips to AT-RISK, and the input-row hash, computed here in your browser, changes with it. Reset and the original hash returns.

// SYNTHETIC CONTROL MEMBER · NOT REAL DATACORROBORATED
ClaimTypeDxService yr
PROF-4021Office / professionalI63.92025
IP-4022Inpatient facilityI63.92025

Original rows · input hash

computing…

Current rows · input hash

computing…

differs from the original

PACKzk.stroke.screen · sy2025 / py2026 · PENDING_CRCFACTProfessional claim submitted I63.9 (acute ischemic stroke)EVIDENCESame-service-year facility claim IP-4022 carries I63.9REASONCORROBORATED · FACILITY_CORROBORATION_FOUNDCONFIDENCEstructural: high · clinical adequacy: not assessed · audit outcome: not assessedROUTINGCertified coder review, chart in hand, before submissionREPLAYcomputing… · engine + pack versions pinned · recomputed offline

Same rows in, same answer out. Edit the rows and both the verdict and the hash change, computed here in your browser with nothing leaving the page. The engine reads structure; a certified coder decides the medicine.

same rows in, same answer out · no network call, no model in the path


// Where it runs

Your browser first. Your walls always.

// PREVIEW · IN YOUR BROWSER

The demo runs entirely client-side on synthetic data. The page is served with a policy that refuses outbound network requests; open the network tab and watch it stay empty. Nothing to install, nothing to security-review, no BAA to negotiate before you have seen it work.

// PRODUCTION · IN YOUR ENVIRONMENT

Production is an offline container your team runs inside your own infrastructure, preflight first. Inspect the layers: no network primitives inside. No payer data is accepted outside that container, and no PHI reaches us. Ever.


// What it does not do

Structure is the machine's job. Medicine is your coders'.

It does not predict any audit outcome, and it does not compute a compliance verdict. Flags mean one thing: the structure the published pattern expects was not found, so a person should look.

It does not read charts or judge medical necessity. Every uncertain case routes to a certified coder with the evidence attached.

v1 covers the acute-stroke pattern. The remaining published groups are staged: acute MI, embolism, four cancer groups, and the 3,780 published mis-keyed code pairs.


One screen run over a de-identified batch, inside your environment. If the number is small, you learned that cheaply. If it is not, you found it before submission.

// Contact · read by the founder

Talk to Zkeleton.

Requests are reviewed manually. Program-integrity, compliance, and design-partner inquiries are prioritized.

Opens your email client — nothing is stored on this site. Or write directly: akkenyaku@zkeleton.com