Your data. Your environment. Your terms.
Zkeleton builds a private environment inside your own VPC where your data finally works for you. Raw PHI never leaves. Core systems are never touched.
Receiving the data is not the same as using it.
The Payer-to-Payer Data Exchange mandate requires every US payer to receive five years of member clinical history by January 1, 2027. Most payers will build pipes to ingest this data for compliance. The data itself remains unstructured, unmatched, and unmerged with claims or authorization context.
What your plan gets.
Six outcomes on one spine, in the order they arrive: what runs today, what we build with design partners, and where the ladder ends.
Pre-Submission Evidence Control
See which submitted codes your own evidence supports, before an auditor does. Deterministic triage, receipts on every finding, your coders make every call.
Evidence Lineage & Receipts
Every transformation of your data accounted for: what carried, what changed, what was lost. Replayable by you, without us in the room.
Audit Response & Replay
When CMS asks how a number was produced, reproduce it. Same inputs, same rules, same answer, with the chain of evidence attached.
Vendor & Feed Accountability
Know what every vendor feed and migration did to your data, and prove where it broke, before the dispute.
Complete, Defensible Risk Capture
Capture the risk your evidence actually supports, both directions. No coded diagnosis without support; no supported diagnosis left uncoded.
The Payer-Owned Data Environment
One governed environment inside your walls where your data works for you. Vendors compute inside; raw data never leaves; control and governance are yours.
The same spine carries the workloads a unified record makes possible: fraud and waste review with full clinical context, HEDIS measures against unified member data, context-aware prior authorization, and payer-owned models that run inside the bubble and never leave your walls.
A parallel flow in your own VPC.
Ingest from compliance
Zkeleton attaches to your existing CMS-0057 data stream. No new external connections. No new data rights.
Normalize and match
Raw clinical data is normalized against a common schema and matched to your member records with confidence scoring. Low-confidence matches are quarantined for review — never silently merged.
Unify with history
Matched clinical data merges with your claims and prior authorization history into a single dataset inside the bubble.
Payer-owned analysis
The unified data lives inside a bubble in your VPC. Your teams use it for their own analytics. Intelligence leaves the bubble. Raw clinical data does not.
The environment opens
Once the dataset exists, the bubble becomes a place others connect to, on your terms.
HARROW: the payer-owned record is already running.
A payer's record of itself lives in fragments: claims with one vendor, eligibility with another, prior years in a TPA's extract. Each copy is partial, and where they overlap they disagree. HARROW reconciles those fragments into one lineage-complete, receipted record the payer owns, over the systems already running, inside a boundary the payer or its sponsor controls.
Every value walks back to the rule that produced it, the raw source bytes it came from, and a hash you can recompute. Where no rule can decide between sources, the record carries the disagreement instead of an answer. Deterministic rules, no model in the decision path; unresolved exceptions route to human review with the machine evidence intact.
briefing on request · synthetic data only · no PHI anywhere
Receipts prove lineage and reproducibility — not clinical truth, and never an audit outcome.
What your environment can host.
Built to shrink your vendor list, not join it: capabilities you currently rent as extracts become workloads you own. Once the bubble exists, it becomes the place others come to work — on your terms, at your pace, with every byte logged.
Opaque extracts become governed exports. Your current stack performs better on higher-fidelity data, and you finally see what leaves.
Vendors bring their compute inside the bubble. Results leave. Data never does.
Device and digital-health makers contribute member-consented data and prove outcomes on your own population before you cover them.
Research that today runs on a broker's copy of your data runs inside your walls instead — you approve the study, queries come in, only aggregates leave.
Four asymmetric choices.
Payer-owned data
The unified dataset is your asset. It resides in your infrastructure under your control. Zkeleton operates on it. Zkeleton does not hold it.
Payer-owned VPC
The entire system runs inside your virtual private cloud. Zkeleton is a guest in your infrastructure, not a landlord holding your data in our cloud.
Payer does nothing new
We operate on the data flow you are already mandated to build. No new operational lift. No changes to adjudication, MLR reporting, or audit trails.
One-sided upside
Upside accrues to the payer: fraud catch, risk accuracy, AI enablement. Transformation cost and architectural burden stay with Zkeleton. The bubble runs beside adjudication, not through it. No critical-systems rewrite at pilot.
We are not building an exchange network. Exchange networks aggregate clinical data through shared pipes in a vendor cloud. Zkeleton runs inside each payer's own VPC. No shared pipes. No vendor cloud. No data leaving payer control.
Reconciled, lineage-complete data — provenance on every merge — is why this works and why it cannot be copied: every alternative architecture pushes complete data into shared or core systems, which is exactly what payers are right to refuse.