July 23, 2026
.jpg)
Steve Palma on why controls aren't self-validating, where regional health plans are losing vendor attention, and what the AI label is hiding.
Q: Let's start with the obvious question. The industry is racing toward pre-pay and AI-driven prevention. Is post-pay auditing becoming obsolete?
That prediction has been around for fifteen years, and improper payments haven't gone down. CMS still reports more than $100 billion in overpayments annually. So no. But I want to be careful, because the question sets up a false rivalry.
Pre-pay is essential. It's the best tool we have for enforcing what a plan already knows, consistently and at scale. The issue is what pre-pay can't do, through no fault of its own. Claims have to be adjudicated in 14 to 30 days, and complexity doesn't compress into 30 days. The errors that survive pre-pay are the ones nobody has understood yet. You can't create a rule for something you haven't discovered — and for some of what surfaces in post-pay, there may never be a clean rule to write.
Those errors can only be found after payment, because that's the first time a claim can be seen in full context. Contract language, benefit design, state carve-outs, claim system configuration, how a provider billed over time. That's a category of error only post-pay data mining can catch.
Q: You use the word "depth" a lot at Penstock. What does depth actually mean in an audit?
Depth means we don't stop at the first answer. Ever.
Here's the reality of this market. The largest payment integrity firms are hyper-focused on pre-pay. But that model leaves post-pay stagnant. Run the edits, apply the rules, report the findings, repeat the next month. You're getting the standard concept library, not the investigation. Plans are feeling the effects.
Depth is the opposite. It's following an anomaly through the data long enough to understand whether there's something underneath it. Sometimes the first query doesn't give you the answer. It gives you the next question. We audited claims seven vendors had already reviewed and found $4.8 million. Why? Because we were looking for causes, not matches against known error types. For a regional plan, those dollars can be the difference between red and black.
Q: What should a health plan leader take from that?
That controls are not self-validating. Most plans have controls. Authorization requirements, validation processes, edits, rules engines. The question isn't "do we have a control for that?" It's "do our paid claims prove the control is working?"
Those are very different questions. We regularly find claims that moved through payment despite indicators that should have stopped them. The control existed. It just wasn't doing what everyone assumed. In payment integrity, the most expensive words are "we thought the control was working."
Q: How do pre-pay and post-pay actually work together in a well-run program?
As a loop. Pre-pay executes on what's known. Post-pay discovers what isn't, then feeds the discovery back upstream into edits, configuration fixes, policy clarifications, provider education. Post-pay is the research and development function for pre-pay. Recovery is the beginning. Prevention is the outcome.
A program where those two functions don't talk to each other can look busy but never improve. Same controls running, same errors recurring.
Q: What separates a finding that changes something from a finding that just gets disputed?
Defensibility and explainability. A finding grounded in plan policy and contract language, documented clearly enough that claims, IT, compliance, and finance can all understand it, drives change. A finding that can't withstand scrutiny just creates appeals, provider friction, and rework.
This matters more to CFOs than the industry admits. Recoveries feed reserves and forecasts. A $5 million recovery nobody can explain gets discounted. A defensible pattern that drives an upstream fix becomes financial leverage. Gross recoveries and financial impact are not the same number.
Q: Everyone in this space is talking about AI right now. Where does it actually fit in with this work?
Carefully, is the honest answer.
You can't walk a conference floor without seeing "AI-powered" on every booth. Some of that's real. A lot of it is the same rules engines that existed five years ago with a new label. The label has become noise. And I say that as someone whose company is building AI deep into how we work, so this isn't a technology skeptic talking.
Here's what we've learned doing that work. The individual capabilities aren't the story. Almost anyone can bolt a model onto one step of the process and call it AI. The hard part is connecting the whole workflow end to end, with feedback loops, so what the system learns in one place makes it smarter everywhere else.
And the judgment part is non-negotiable. Health plans should be nervous about AI making deterministic payment decisions with no human in the loop. There's real exposure there, and the industry is starting to see it play out. Our position has always been the same: the technology surfaces and accelerates, and experienced auditors decide. AI can put ten thousand leads in front of you. It takes a person who understands contracts, coding, and policy to determine which of those is a defensible finding, and which is just a flag.
So I'm not cautious about AI. I'm cautious about AI that's bolted on instead of built in. When the system learns from everything it touches and an auditor stands behind every finding, that's not a label. That's a capability. That's what we're building.


.jpg)