Service

Healthcare Back Office Teams

Trained staff for the administrative side of a US practice: provider credentialing and payer enrollment, eligibility and benefits verification, prior authorization follow up, scheduling, patient intake and front desk cover. Coding and claims are handled separately and we say plainly how.

The admin side is where a practice quietly loses money

Nothing here is glamorous and all of it is expensive to get wrong A provider who is not enrolled cannot bill. An eligibility check nobody ran becomes a denial six weeks later. A prior authorization that sat in a queue becomes a cancelled procedure and an angry patient. A phone nobody answered becomes an appointment booked somewhere else. None of this needs a clinician and most of it does not need anyone sitting in your building.

We are honest about where the line sits There are three tiers of this work and they are not the same. One touches no patient data at all. One touches patient data and therefore runs under a signed agreement with real safeguards. One needs a credentialed coder and we do not staff it by default. Most agencies blur those together. We would rather you knew which is which before you sign anything.

Tier 1 : Provider data work with no patient data in it

This is provider information, not patient information. No name, no diagnosis, no claim. It sits outside the protected health information rules entirely, which means you can hand it over without a business associate agreement and without waiting on a compliance review.

  • Payer enrollment and re-enrollment: commercial panels, Medicare and state Medicaid, with the applications assembled, submitted and chased until an effective date exists in writing
  • DataSpring profile build, maintenance and re-attestation. This is the platform most people still call CAQH, and the provider portal most practices log into; keeping attestation current is the single most common reason an application stalls
  • Medicare enrollment and revalidation through PECOS, including the move to PECOS 2.0, plus NPPES records kept accurate for type one and type two NPIs
  • Primary source verification packets, licence, DEA and board certification expiry tracking, and a calendar that chases the renewal before the payer notices it lapsed
  • Hospital privileging and reappointment paperwork, malpractice certificates, W-9s, group rosters and location adds
  • Directory information kept current with each plan. The ninety day verification duty sits on the plan, not on you, but the plan can only verify what you gave it, and a wrong address in a directory is a patient who never arrives
  • Payer contracting admin: fee schedule requests, contract copies, renegotiation packets prepared for whoever actually makes the decision

Tier 2 : Patient facing admin under a signed agreement

This work touches protected health information and we do not pretend otherwise Eligibility checks, authorisations, scheduling and the front desk all involve a patient name, a date of birth, a member number and often clinical detail. That makes anyone doing it a business associate. It needs a signed business associate agreement, least privilege access on accounts you create, named people rather than a pool, trained staff and an audit trail. What it does not need is a coding credential, because nobody here is assigning a code.

  • Eligibility and benefits verification before the visit: active coverage, plan type, copay, deductible remaining, out of pocket position, visit limits, referral requirement and whether your provider is genuinely in network for that plan rather than that carrier
  • Prior authorization: requirement checked, clinical documentation assembled from what the provider gives us, submission, status chased, approval logged against the procedure and the expiry diaried
  • Denied authorisations worked properly: the rule now requires payers to give a specific reason for a denial, so the appeal is written against that reason rather than a guess
  • Referral coordination in and out, specialist scheduling, and records requested and tracked so the visit is not wasted
  • Scheduling and calendar management, waitlist working, reminders, confirmations and rescheduling the no shows instead of writing them off
  • Patient intake: forms out ahead of the visit, demographics and insurance captured and checked, cards imaged, consents collected
  • Front desk and phone cover: inbound calls, the overflow your staff never get to, portal messages and the voicemail box that fills up by lunchtime
  • Good faith estimates prepared for uninsured and self pay patients who ask for one, which is a live requirement, unlike the co provider element that remains under enforcement discretion
  • Patient balance questions, payment plan setup and statement queries, with payment authority staying with you

Tier 3 : Coding and claims

We do not staff this by default and here is the honest reason Assigning a diagnosis or procedure code is a judgement call with legal weight behind it. Done wrong it is not a rejected claim, it is a compliance problem. The people who do it properly hold a certification such as CPC from AAPC or CCS from AHIMA, and that is the floor the industry works to. Putting an uncertified person on it would be cheaper for a month and expensive for a year.

If you need it we will try to source it Tell us the specialty and the volume and we will look for a dedicated credentialed coder for your account rather than folding it into a general pool. We will also tell you plainly what has to be in place first: a signed business associate agreement, a HIPAA compliant working environment with access control and logging, and a named certified person whose credential you can verify yourself. If we cannot find the right person for your specialty we will say that instead of putting somebody near it and hoping.

What we will not do Promise a collection rate, take payment authority, or sign anything that says a coder is certified when they are not.

Rules we work to rather than around

  • Prior authorization changed for a lot of payers at the start of 2026. Decisions are now due in 72 hours for urgent requests and seven calendar days for standard ones, denials have to carry a specific reason, and payers have to publish their own authorization metrics. The electronic authorization interfaces follow at the start of 2027. All of that gives you something to hold a payer to, and our people are trained to use it
  • The HIPAA Security Rule update proposed at the end of 2024 has not been finalised and is currently scheduled for 2027. We are not going to tell you we are compliant with a rule that does not exist yet. We work to the rule as it stands and we track the proposal
  • Good faith estimates are required for uninsured and self pay patients who request one. The convening and co provider piece sits under enforcement discretion pending further rulemaking, so we prepare what is actually required and note what is not
  • Directory accuracy: the periodic verification duty belongs to the plan. The provider duty is to submit updates when a network agreement starts or ends, when information changes, or when asked. We work to the provider duty

Systems we work inside

Yours, on accounts you create and control. Practice management and records in Epic, athenahealth, eClinicalWorks, NextGen, Tebra, AdvancedMD, Practice Fusion and DrChrono. Eligibility and authorisation through Availity, Waystar, Change Healthcare under Optum, and the payer portals directly where no clearinghouse route exists. Credentialing in DataSpring, PECOS, NPPES, state Medicaid portals and credentialing platforms such as Modio, Medallion, Verifiable, symplr and CredentialStream. Scheduling, phones and patient messaging in whatever you already run.

How the arrangement works

Delivered or placed Hand the function over and we run it with a lead responsible for the output, or place the coordinator inside your team on your hours and your systems while we stay responsible for their quality and their cover. Either way there is a named person and a trained backup, not an anonymous pool.

Controls Signed agreements at company and individual level, a business associate agreement wherever patient data is involved, least privilege access on accounts you create, named staff, separation between whoever enters and whoever reviews, and restricted working environments where the data calls for it. We do not take payment authority and we do not sign clinical documentation.

Start small One coordinator on credentialing, or one on eligibility, is a normal way to begin. It proves the process before anything larger is agreed.

Two ways to run the admin

Pick one, or run both The administrative side of a practice can be staffed by trained coordinators, moved into systems that check and chase by themselves, or run as both. Where patient data is involved the rules decide part of the answer for us, and we work to them rather than around them.

A coordinator on the account

A named person who owns the outcome, works your queue daily and picks up the phone when a payer is being difficult.

  • Payer enrollment and credentialing applications chased until an effective date exists in writing
  • Prior authorization submissions, appeals written against the payer's stated reason, and expiry tracking
  • The calls, the portals with no interface, and every payer that still wants a fax
  • Scheduling, waitlist working and the front desk overflow nobody gets to
  • Anything that needs reading a clinical note before acting on it

A system doing the checking

The repeatable checks and chasing built once inside the software you already pay for, and handed over as yours.

  • Batch eligibility checks run against tomorrow's schedule instead of one patient at a time
  • Alerts when coverage is inactive, a plan changed or a deductible position moved
  • Licence, DEA, board certification and re-attestation expiry reminders that fire before the lapse
  • Authorization status pulled from the portals on a schedule rather than by memory
  • Reporting on denials by reason and by payer so the pattern is visible

Both together

The usual answer. The system does the checking and the chasing, the coordinator handles the exceptions and every conversation a patient or a payer would notice being automated.

  • We watch a person run the process before automating any of it
  • Nothing that needs a clinical judgement is handed to a rule
  • The coordinator reviews what the system produced rather than producing it

Where automation stops Coding decisions, clinical documentation and anything a payer requires from a named person stay with people. Automation removes the repeat lookups and the reminders, which is where the hours actually go.

Frequently asked

Do you handle medical coding and claims?

Not by default. Assigning diagnosis and procedure codes is a judgement call with legal weight, and the people who do it properly hold a certification such as CPC from AAPC or CCS from AHIMA. If you need it, tell us the specialty and the volume and we will try to source a dedicated credentialed coder for your account. We will also tell you what has to be in place first: a signed business associate agreement, a HIPAA compliant environment, and a named certified person whose credential you can verify yourself. If we cannot find the right person for your specialty we will say so rather than put somebody near it and hope.

Which of this work needs a business associate agreement?

Anything involving a patient. Eligibility, prior authorization, scheduling, intake and front desk all touch protected health information, so they need a signed business associate agreement and the safeguards that go with it. Provider credentialing and payer enrollment do not, because that is provider data rather than patient data, which is why most practices start there.

Are your staff HIPAA trained?

Yes, and it is refreshed rather than done once at induction. Access is least privilege on accounts you create and control, work happens in restricted environments where the data calls for it, and there are named people on your account with an audit trail rather than an anonymous pool. We will not claim compliance with the proposed Security Rule update, because that rule has not been finalised.

Can you get our providers enrolled with payers faster?

We can remove the delays that are ours to remove: an incomplete application, a lapsed attestation, a missing document, a follow up nobody made. What we cannot do is speed up the payer, and anyone promising you a date is promising something they do not control. What you get from us is an application that is right the first time and somebody chasing it on a schedule.

Do you work inside our systems or your own?

Yours. You create the accounts and set the permissions, which means you can see exactly what was done and switch it off in one click. We work in Epic, athenahealth, eClinicalWorks, NextGen, Tebra, AdvancedMD and the rest, and in Availity, Waystar and the payer portals for eligibility and authorisations.

What happens when the person on our account is away?

Somebody trained on your account covers. That is the difference between this and hiring one remote assistant, and it is built in rather than arranged on the day. The process lives in documentation you own, not in one person's head.

Can any of this be automated instead of staffed?

The checking and the chasing can. Batch eligibility against tomorrow's schedule, expiry reminders for licences and re-attestation, authorization status pulled from the portals on a schedule, and denial reporting by reason and payer are all better as systems you own. The calls, the appeals, the exceptions and anything needing a clinical note read stay with a coordinator. Coding decisions are never handed to a rule.

All Apex Automation Team FAQs →