TL;DR
A group of 30+ physicians was losing over a thousand hours a year to visit notes, billing codes, and compliance reports, and the reports were still going out late, with a fine attached to every miss. They could not use a normal AI tool, because patient records can’t be sent to another company’s servers. We built a private AI that runs only on their own computers, with no internet connection, and gave it three jobs. Since launch in March 2026, every compliance report has gone out on time, and by late August the group had avoided $450K in fines, on track to pass $500K by year’s end.
Context and users
The group has more than 30 physicians plus billing and compliance staff. Three groups of people touched the problem:
- Physicians, who wrote visit notes after hours and had no interest in becoming compliance experts.
- Billing staff, who fixed coding mistakes after the fact.
- The compliance lead and the owner, who saw the fines land and had no way to get ahead of them.
The problem, and how we found it
The owner’s first description was “we need AI for our paperwork.” The assessment turned that into something specific. Over the first conversations we mapped where the hours went and where the money leaked. Two things stood out:
- The fines came from lateness and gaps, not from bad care. Compliance reports were assembled by hand from records spread across the practice, so they slipped past deadlines or went out incomplete. Each slip cost money.
- The hours came from three places: drafting visit notes, checking billing codes, and assembling those reports. Everything else was noise.
There was also a hard constraint that ruled out every off-the-shelf option: patient information could not leave the building. Any design that sent data to a cloud model was dead on arrival, no matter how good the demo looked.
Hypothesis
If an AI running entirely inside the practice drafted the notes, checked the codes, and assembled each compliance report ahead of its deadline, with a staff member reviewing before anything went out, the group would stop paying late-filing fines and give physicians most of those hours back, without changing how anyone already worked.
Scope, specs, and prioritization
I scoped the build to three jobs and said no to everything else in the first version:
| Shipped in v1 | Deferred |
|---|---|
| Draft each visit note from the physician’s inputs | Patient-facing chat or scheduling |
| Check billing codes and flag likely mistakes | Anything touching the phone system |
| Assemble each compliance report before its deadline | Automated submission without human review |
Two specs mattered more than the rest:
- Air-gapped, full stop. The system runs on the group’s own hardware with no internet connection. Not “encrypted in transit.” None.
- A person signs off. The AI drafts and assembles; a staff member reviews before a note is filed or a report is sent. This kept the physicians and the compliance lead in control and made adoption an easier conversation.
The order of the three jobs was a prioritization call: compliance reports first, because that’s where the fines were; billing checks second, because errors there also cost money; notes third, because that was the biggest time sink but the lowest dollar risk.
Key decisions and tradeoffs
- On-site over cloud. We gave up the convenience and raw capability of hosted models for a system the owner could point at and say “the data is in that room.” For a healthcare buyer, that sentence was worth more than any benchmark.
- Review step over full automation. Slower per report, but it meant we could launch without waiting for the group to trust the system blindly. Trust came from watching it be right.
- Three jobs over a platform. Every extra feature would have delayed the compliance fix, which was the thing actually costing money.
What shipped
Andres designed and built the system: a private AI on the group’s own computers, designed around HIPAA and the group’s compliance rules, connected to the records and templates the staff already used. My job during the build was to keep the scope honest, run the check-ins with the owner and compliance lead, and define what “working” would mean before launch.
Metrics and outcomes
| Before | After (Mar–Aug 2026) | |
|---|---|---|
| Compliance reports filed on time | Regularly late or incomplete | Every report on time since launch |
| Fines and penalties | Ongoing | $450K avoided in five months; $500K+ projected by year end |
| Physician paperwork hours | 1,000+ hours a year | Handled by the AI, reviewed by staff |
| Patient data leaving the building | n/a | Zero |
The number I cared most about was the first row. The dollars follow from it.
What I’d do differently
- Baseline harder. We knew fines were “a lot”; I’d have pulled the exact twelve-month total before kickoff so the after number had a cleaner comparison.
- Instrument the review step. How often staff changed the AI’s draft would have been a useful quality signal from week one. We added it later.
- Plan the second wave earlier. Once the reports were on time, the group immediately asked what else the system could do. A lightweight roadmap would have saved a scramble.
My role vs. the team
I owned the assessment, the problem definition, the scope and its sequencing, the client relationship, and the success metrics. Andres owned the architecture and the build. The group’s compliance lead owned the review process and, honestly, the adoption.
“Seriously, I don't know how we worked before these guys. My doctors and billers can actually take on more patients now. It freed up a lot of my billers' time, and my doctors went from doing paperwork to actually seeing patients.”