Architecture

Device-agnostic is an architecture, not a marketing word

It means the billing engine, the threshold engine, and the audit trail do not know or care which vendor produced a number. It means adding a source is a configuration change, not a product roadmap item. And it means we can say no to a source without breaking anything.

Layer 1

Ingest

Four paths, in descending order of preference.

Aggregator API
One integration covering the connected-device long tail. Fastest path to breadth, and the right default for cuffs, scales, oximeters, and consumer wearables.
Direct manufacturer interface
Required for the sources that matter most and are never in an aggregator: PAP therapy data, CGM, inhaler sensors, specialty assays.
HL7v2 and FHIR
Lab results and EHR context. Merged onto the timeline, never counted toward a device-supply line, because labs are not physiologic monitoring.
Camera and screen measurement
Where no sensor exists. Oculomotor tasks, photophobia thresholds, goniometry, gait, tapping, luminance staircases. This is most of neurology and most of rehabilitation, and it is the reason a Bluetooth-only platform cannot run half this catalog.
Layer 2

Normalize and label

Every reading lands with a provenance record: source, device identity, clearance status for the measured parameter, timestamp, and a billable-or-context flag set at ingest.

The flag is not advisory

A context-only source cannot be rolled into a device-supply claim line by any user at any permission level. This is the single most important control in the platform, because consumer-wearable data creeping into billable lines is the fastest route to a repayment demand.

Units, sampling windows, and personal baselines are computed on ingest. Thresholds evaluate against the patient's own baseline wherever the absolute number is unreliable, which for pulse oximetry and for anything camera-derived is always.

Layer 3

Decide

A threshold without an owner is a liability. Every rule in the platform carries a named clinician, a response clock, an escalation path if the clock expires, and a required disposition. Programs with time-critical thresholds will not activate until the escalation contact is configured and a test page has been acknowledged.

Alert fatigue is a design failure, so thresholds are tuned per condition rather than globally, and the platform reports firing rates per rule so you can see which one is training your staff to ignore it.

Layer 4

Account

Counters, not judgment.

  • Transmitted-day counter selects the device-supply code at day 30.
  • Management timer, attached to actual review sessions, selects the 10-minute or 20-minute management code.
  • The interactive communication is timestamped, and the claim line will not release without one.
  • Mutually exclusive pairs are enforced structurally, not by warning banner.
  • Single-owner lock per episode prevents the duplicate-billing pattern that OIG has flagged repeatedly.

What Gathermed is not

Not a billing company. We do not submit claims, we do not take a percentage of collections, and we do not hold HCPCS codes. We produce the record that supports a claim the practice submits. That separation is deliberate: it keeps our incentives out of the coding decision, which is the correct place for them to be and also the only architecture that survives diligence.

Device fleet

Cellular first. And the cuff outlives the patient episode.

The patients remote monitoring serves best are the least likely to pair Bluetooth, maintain WiFi, or keep an app updated. So the default kit is cellular: the device ships already provisioned, transmits over LTE-M from first use, and requires nothing from the patient except using it. No pairing ceremony, no smartphone requirement, no home network. Take it out of the box, take the reading, and the data is on the timeline before the visit ends.

What cellular buys you clinically

Day-one transmission instead of a setup call. A working program for the rural, the elderly, and the unphoned — which is most of the Medicare population you enrolled this for. Store-and-forward when coverage drops, so a dead zone costs latency, not the transmitted day. And because the device talks to us directly, silence is a signal: the platform sees battery, signal strength, and last-contact per serial, and flags a quiet device while the 16-day economics of the month can still be rescued — not at day 31 when the supply line has already died.

Full control of every serial, remotely

The fleet console is not a spreadsheet of MAC addresses. Per device, remotely: bind and unbind against a patient, suspend attribution without unbinding, deactivate the SIM, mark lost or unreturned and stop the supply counter that moment, push firmware, and see custody history end to end. Kits are assembled and QA'd per program, and every state change is a logged event with an actor — the same audit spine as everything else on the platform.

This strip is the unit economics of the program. A cuff that serves one patient and retires into a drawer costs what it costs. A cuff that cycles — returned, wiped, re-kitted, rebound — divides its cost across every episode it serves, and the platform is built to run that loop deliberately rather than by accident.

The cycle, as the platform runs it

Bind. Serial to patient, under an order, against a diagnosis. The binding window opens now and 99453 setup attaches to this episode.
Transmit. Readings post to the bound patient's timeline. The transmitted-day counter runs toward the supply code.
Unbind. Discharge, graduation, or non-use. The window closes with a timestamp. The counter stops. The claim record is already complete.
Sanitize. Stored readings and patient identifiers are wiped from the device. The wipe is a logged event, not a hope.
Re-kit. Battery, cuff wear, calibration check, fresh instructions. Failures leave the fleet here, not in a patient's home.
Rebind. Same serial, next patient, new episode. The passport above is this loop, run twice in one quarter.

Attribution is structural, not procedural

A reading posts to a patient only if its timestamp falls inside that patient's binding window for that serial. Readings from an unbound device — the courier window, the shelf, the patient who kept using the cuff after discharge — land in quarantine with the device's custody record, visible and unbillable. No workflow, no training, and no permission level can attach them to the wrong chart.

Why this is the control that matters

Device reuse is where monitoring programs quietly go wrong: patient B's readings on patient A's claim is not a clerical error, it is a false claim. Cycling hardware is only good economics if the attribution boundary is physically incapable of leaking across it. That boundary is enforced in the data model, which is the only place it cannot be worked around.

Intelligence

AI where it earns its place

The spine of this platform is deterministic on purpose: counters pick codes, thresholds fire because a number crossed a line, attribution follows a binding window. Money and safety live there, and they stay model-free. AI works the soft tissue around that spine — it predicts, drafts, ranks, and proposes. Every output it produces is labeled as drafted, carries its sources, and requires a human signature before it touches a chart, a claim, or a patient.

Transmission-risk forecast
Operational · no clinical claim
By day 8, the model flags the patients unlikely to reach 16 transmitted days and ranks the outreach list. Paired with fleet telemetry, it turns a quiet cuff into a phone call on day 9 instead of a dead supply line on day 31. This is the highest-value use of AI in remote monitoring, and it never touches a clinical decision.
Management-note drafting
Clinician signs · the timer stays honest
Drafts the monthly management narrative from the timeline: what fired, what was done, when the interactive communication happened. The clinician edits and signs. Time-based codes bill actual time, so the draft never inflates a minute — it converts documentation time into review time and produces the note an auditor reads without wincing.
Alert triage
Reorders · never silences
Ranks the morning queue: these three firings resemble the start of a decompensation pattern, those nine look like cuff misuse. The threshold still fires deterministically, still routes to its named owner, still runs its clock. AI may reorder the queue. It may not decide a firing didn't matter.
Patient check-ins
Scripted boundaries
Conversational collection of patient-reported outcomes, plain-language device help, and adherence nudges tuned to the patient's own pattern rather than a generic reminder schedule. Anything that approaches clinical advice routes to the care team, with the conversation attached.
Quarantine reconciliation
Suggest-only
When readings land in quarantine from an unbound device, the model proposes what happened — these four readings match a known patient's rhythm and the courier window. A human confirms or rejects. The suggestion engine sits on top of the attribution boundary and has no ability to move it.
Audit narrative
Prose over the packet
The defense packet exists as structured events. On demand, AI writes the patient-month as the narrative a reviewer reads first, with every sentence citing the events underneath it. The packet is the evidence; the narrative is the cover letter.
Kept out, by design

The four places a model will never run

A model that is right 99 percent of the time is impressive in a demo and a repayment demand in a claims run. These four run on counters and windows because they have to produce the same answer every time, show their work, and survive an audit two years later.

Kept out 01

Code selection

The transmitted-day counter picks the device code. The timer picks the management code. Mutually exclusive pairs are enforced structurally. There is no probability anywhere in that path, and there never will be, because the counter can be re-run in front of an auditor and a model cannot.

Kept out 02

Threshold firing

A threshold fires because a number crossed a line a clinician set, and it routes to a named owner with a response clock. "The model suppressed it" is not a defensible disposition, so suppression is not a capability. Triage ranks what fired; it cannot unfire anything.

Kept out 03

The billable-or-context flag

Set at ingest from device clearance status for the measured parameter, not inferred from the data. Consumer-wearable readings creeping into billable lines is the fastest route to repayment, and a classifier that guesses the flag is the same risk with better marketing.

Kept out 04

Attribution

A reading posts to a patient because its timestamp falls inside that patient's binding window for that serial. No model votes on identity. The quarantine assistant proposes; the binding window disposes. That order never reverses.