Overview
Work
Everything with an owner, ordered by what it costs to leave it.
Triage an email AI
Paste an email you're not sure what to do with. The local AI reads it - nothing leaves this computer, and tells you what it's about, what's being asked, any dates, and whether it should become a task.
Email review
Threads somebody sent you, that nobody answered back.
Muted senders
Threads from these never appear for review again.
| Pattern | Muted by | When |
|---|
Claims to fix
Denied claims that were never finished, and how long is left to file.
Data integrity
Where this app disagrees with the record, or holds what it should not.
What raises a flag here â–¾
Exclusion screens providers and staff against the OIG list. An NPI match is certain; a name-only match says so, because names are shared and the OIG disambiguates by date of birth, which this app deliberately does not hold.
Exposure scans this database for the 18 HIPAA identifiers. Mismatch compares providers, and the practice's own group NPI, against NPPES. Contradiction is your data disagreeing with itself: a facility with no CMS locality, a plan with no payer ID, a credential that expired while still marked active.
All four clear themselves once the source is fixed. Nothing here is closed by hand, which is what makes the counts worth reading.
What counts as PHI
Every file import is scanned, and if any of these 18 HIPAA identifiers show up a “PHI detected†flag is raised above. Almost all of this app holds no patient data at all: payers, contracts, fees, staff, suppliers and denial totals are about the business, not about people. The one exception is Claims to fix, which keeps your own claim numbers so a biller can open them. If a payer or CPT export ever includes patient columns, delete it and re-export without them.
What's coming due
Every dated thing that lapses if nobody renews it, on one timeline.
What lands here, and when it becomes work â–¾
The task closes itself when the renewed date is recorded, so nothing here needs chasing twice.
Attestations and portal logins
Payer portals (UHC, Availity) and directories that make you re-confirm your data on a cadence, no expiry date, easy to forget. Record when you last did each one; the radar schedules the next. Hit Attested today whenever you complete one.
| Portal / attestation | For | Every | Last done | Next due |
|---|
Open positions
What you are advertising, and who is still live on each.
Applicants
People, not postings. Somebody who applied before is recognised the moment you type their email, whichever position it was for. Rejection reasons come from a fixed list, because a reason written by hand is the riskiest thing this app could keep.
Employees
Who works here, and what paperwork is on file for them.
Providers
Every clinician who bills or holds privileges.
Credentials
Licences, registrations and identifiers, and when each one runs out.
| Credential | Holder | Line | Identifier | State | Expires | Status | Document |
|---|
Payer enrollment
Who you are contracted with, and whether claims can actually reach them.
| Payer | AddVal category | Status | Payer ID | Our PTAN / ID | Complete | Revalidation | Claims | ERA | EFT | Elig |
|---|
Fee analysis
What each insurance company pays you, next to what Medicare pays for the same work.
How this is worked out â–¾
The amount comes from what the insurer actually paid, in your 371.05 export, never from the price list stored in eCW. That list holds the Medicare rate for every insurer, so reading it would compare Medicare with itself and report about 100% for everybody.
Where the government publishes no price for a procedure, what Medicare actually paid you for it stands in instead, and the page says how often that happened rather than hiding it.
Plans and contracts
Every plan an insurer sells, and which of your contracts it is paid under.
How a contract is identified â–¾
The payer ID is a fact off the claim; the plan name is a label somebody typed. Grouping on the name split one brand across twelve rows and hid its real weight.
Product type keeps a negotiable commercial contract apart from Medicare Advantage, whose rates CMS sets for you.
Leak finder
Money that looks like it is being lost the same way over and over, and what would stop it.
How this is worked out â–¾
Three things side by side that nothing else shows together: what each insurer pays, the refusals that keep repeating, and whether you are actually enrolled with them. eCW, the clearinghouse and your own records each hold one piece.
Counted for the latest complete year, so this tab and Denial insights can never quote different figures for the same thing.
Contract scorecard
Which contracts are worth reopening, judged against what your other insurers pay you.
How this is worked out â–¾
Both are worked out over everything you billed that insurer, and busier codes count for more, so a code you filed twelve times cannot swing a contract.
Two comparisons run here. Against Medicare says whether a price is high or low in general, and it is the only fair test for a government plan, because the government sets that price. Against your other insurance companies decides what is worth reopening, because that is who an insurer competes with. A contract can look fine against Medicare and still be the worst one you hold.
Each row is one contract, identified by the insurer's own payer ID and product type, not by a plan name somebody typed. The dollar figures size the conversation. They are not money anyone owes you.
Pre-visit and pay
What a visit should pay, before you do it.
How this is worked out â–¾
What this plan has paid you before for the same work, shown next to the Medicare rate. It is not a quote for the patient: their share comes out of that figure, and only checking their coverage on the day confirms it.
Needs prior authorization
Your PA reference, grouped by payer: the codes each one requires a prior auth for, so the team routes them before it's too late. Every entry keeps its source and last-checked date. Add or Import your payer's official list, and confirm on the portal before relying on it.
Day-before schedule prep (SOP)
The repeatable routine you run the day before clinic, so anyone can do it. This holds the process only - the per-patient checks happen in eCW. Edit the steps to match how you work.
Coverage rules
What an insurer will not cover, so you find out before you bill it and not after.
What a rule holds, and the two clocks â–¾
Every rule carries where you read it and when, so a write-off questioned a year from now is answered with a source and not a memory. A rule on the payer covers every plan it sells.
| Payer / plan | CPT | Coverage | Note / what to do instead |
|---|
Timely filing windows
How long you have to file, per payer. This is what separates a claim worth fixing from one to write off.
Blank is the honest answer until you know. A wrong default throws away claims you could still file.
| Payer | File within | Appeal / corrected within | Source | Checked |
|---|
Two different clocks, and mixing them up costs money
Timely filing runs from the date of service and governs getting the claim in at all. Appeal or corrected-claim windows run from the remittance, and are usually much shorter. A claim can be comfortably inside its filing limit and already too late to appeal.
Your contract can override the published manual. A participating provider agreement often sets its own filing limit, and that is the one that binds. When the number in your agreement differs from the payer's public policy, record the agreement and say so in the note.
These change. That is why every row carries a link and a checked date: when a write-off is questioned a year from now, the answer should be a source, not a memory.
Denial insights
Refused claims somebody can still do something about, and how long is left to act.
How this is worked out â–¾
Denials come from the CPT-level denial report. The paid volume that makes a rate meaningful comes from your fee export, which is why both matter.
Ordinary write-offs are set aside. A code denied five times and paid six hundred is noise, not a rule.
Ledger
One line per invoice or payment, and where the money came from.
What an entry carries â–¾
This is the book everything else reads: Annual budget and Trends are both rolled up from here, so a figure you disagree with is always traceable to a line somebody entered.
Click any entry to edit or delete it. Claims income is recomputed when a claims line changes, rather than being typed twice.
This month
Bills to pay
Setup
Recurring vendors, and how each one is paid
Paste an invoice email
Trends and forecast
Where this year lands, if the rest of it looks like the last one.
How the forecast is worked out â–¾
Scaling last year's shape rather than averaging the months means the forecast respects your seasonality: a quiet December stays quiet.
Set a goal and the page says the gap and what each remaining month has to carry to close it.
Annual budget
Money in against money out, month by month.
How this is worked out â–¾
Every figure is rolled up from entries in the Ledger, so nothing here is typed twice and the budget cannot drift from what was actually recorded.
All aggregate. No patient detail reaches this page, or the table underneath it.
Hospital and surgical privileges
Where your providers may operate, and when each place reappoints them.
| Facility | Location | Privileges | Reappointment | Status | Next step |
|---|
What each column means
Privileges is the provider's medical-staff category at that hospital, in plain terms: Active: full member, can admit and treat patients there. Courtesy: occasional use, limited involvement, not a full staff member. Consulting: consults on cases but does not admit. Provisional: initial probation period a new member serves before Active. Affiliate / Telemedicine / Honorary: non-admitting, remote, or retired categories. None: no privileges on file at this facility.
Status is where your record stands, shown by color: In good standing privileges verified and on file, nothing to do. Pending waiting on the hospital (application in, or a reappointment not back yet), the ball is in their court. Action needed something is on you to do. This turns on automatically whenever an open task is linked to the facility (use New task on its row), and clears itself when that task is done. Inactive no longer active at this facility.
Reappointment is when the hospital re-verifies the provider's privileges, usually every two years. The date on the left is when the current cycle started; the one on the right is when it is due. Renewals warns you ahead of it.
Documents
Licences, privilege letters, CMS correspondence, certificates. Dropped here they are stored, downloadable by anyone with access, and, for PDFs with a text layer - read for dates and identifiers. Nothing is written to a record until you approve it.
| Document | Type | Attached to | Read | Uploaded |
|---|
Who to call
Named people with direct numbers, gathered from correspondence. Always take a reference number and note the date, payers routinely deny a call happened.
| Organisation | Person | Role | Phone | Notes |
|---|
Forms and links
Public pages you look things up on: state boards, CMS forms, exclusion checks. Links rather than stored PDFs, because credentialing forms get reissued and a saved copy quietly goes out of date. Anything you sign into lives in Records, Access directory. Payer-specific portals live on each payer row (Payers tab → click a payer).
| Link | Type | What it is for | Checked |
|---|
Blank forms and internal documents
Upload blank/reusable forms, the employee handbook, and internal papers so staff can find and print them from here. These are reference files, not patient records, not HR files.
Billing cheatsheet
Look up a denial code and read what to do about it. Also modifiers, eCW how-tos and the claim-review checklist. Type a code or a keyword.
Practice locations
Every address you bill from, which every payer record must match exactly.
| Name | Address | Group NPI | PTAN | Phone | Status |
|---|
Vendors
Who you buy from and pay, and how to reach them.
Access directory
Every system the practice logs into, and who owns it.
What this list is for â–¾
A password-manager export is a flat wall of hostnames. Sorting it into categories, payer portal, clearinghouse, payroll, banking, turns it into something you can hand to somebody else, and it makes the next question answerable: which of these should this job title actually have?
Sort into categories shows you every guess before it changes anything, and never overwrites a category you set yourself. To see the gaps for one person, open their employee card and read the access review.
Audit trail
Every change in the app, who did it, when, and what. Newest first.
| When | Who | Action | Record | Detail |
|---|
Playbooks
The practice's SOPs and how-tos, so a process can be run by anyone, not just whoever keeps it in their head. Search a topic, or add your own. Great for onboarding and delegating.
Responsibilities
Who owns which recurring duty, how often, and who backs them up, so nothing falls through when someone's out, and delegation is explicit.
| Responsibility | Owner | How often | Backup (covers the owner) | Notes |
|---|
Coverage matrix
Every responsibility against every employee, so you can see at a glance who owns what and where you have no backup. Set owners and backups on each employee's card (Employees tab).
Intake: paste anything, the app files it
Notes, a price list, vendor contacts, an SOP stuck in Google Keep. Paste it below and press Sort it out. The app breaks it into pieces, suggests where each one belongs, and shows you the list before saving anything. Nothing is filed until you say so. Use it while setting up, or later for whatever got missed.
What belongs here
Loose knowledge. Things that live in someone's head, a sticky note, or a doc nobody opens. Not spreadsheets.
- Playbooks · how something gets done: SOPs, policies, opening and closing routines, job descriptions
- Cheatsheet · things you look up: self-pay prices, code lists, denial-reason notes
- Vendors · a supplier, with its rep, email and phone
- Contacts · a named person at a payer, facility or vendor
- Duties · who is responsible for what, and how often
Spreadsheets go somewhere else
The AddVal tracking report, a fee schedule, an eCW denial or revenue export: use the Import button on the matching tab instead (Payers, Fee analysis, Denial insights). That reads your columns properly and updates the records you already have. Intake would chop the same file into text blocks and make a mess.
Never patient information
No names, dates of birth, addresses, member numbers or diagnoses. Not on this screen, and not anywhere else in the app.
Denied claims are the one place patient work shows up, and even there the app never sees a patient: the Scrubber on your own computer swaps each real claim number for a code like WL-7F3A91 before anything is sent, and the list matching codes back to claims stays on that computer. So a claim can be worked on here without this app, or anyone hosting it, ever holding something that points at a person.
About and Help
What every part of this app does, and how it keeps patient data out. Search a feature or a question, or browse the sections below.
Mailboxes the sweep reads
Every address Email review pulls from. No passwords are kept here, only which mailboxes are in scope. Removing one stops future sweeps and leaves anything already reviewed in place.
| Address | Label | Scope | Status | Reviewed |
|---|
Your profile
The name shown in the sidebar and against every change you make.
My access
The systems you can sign into and the username you use on each. Yours only, collapsed so it stays out of the way. The practice-wide list of systems lives in Records, Access directory.
Where the sensitive paperwork lives
This app deliberately holds no social security numbers, dates of birth or bank details. Those documents stay in Drive, under its own sharing controls and the HIPAA agreement you already have with Google. Record the folders here so nobody has to go hunting, and so a new person can be told once.
You can paste either a Google Drive web address, or a folder on your own computer such as G:\My Drive\HR if you use Drive for Desktop. A web address opens for anyone; a folder on your computer opens only on yours, through the Scrubber.
Which document goes where
In this app: business paperwork with no patient or personal identifiers in it. Licences, certificates, payer contracts, privilege letters, blank forms. Anything attached to a staff record is locked to administrators automatically.
In Drive: anything carrying a social security number, a date of birth, bank details, or a patient's name. I-9, W-4, direct deposit, offer letters, and any document that arrived with patient information on it.
The rule that keeps this simple: if losing the file would matter to a person rather than to the business, it belongs in Drive. Each provider, facility and payer record can also carry its own folder link, on the record itself.
Practice setup
The guided first-run walkthrough, practice profile, specialties, and your first provider. Re-run it anytime to review those basics.
Practice name and logo
Shown in the sidebar and on the sign-in screen. The logo is stored inside the database, no separate file to lose.
Weekly digest
A "what needs you" email sent every Monday morning, overdue and upcoming renewals, attestations coming due, and a count of what's waiting in the app. Renewal detail carries no patient data, so it's safe for every admin. Sent by the scheduled task on the office PC using the same mailbox credential as the daily scan.
Your password
Rename categories
Change what these are called on screen. The underlying values never change, so renaming can never orphan a record.
Tell everyone an update is coming
Locks every open screen with "Update ongoing, please wait" until you lift it, or until it runs out on its own. Nobody is signed out and nothing is lost.
Sign-in accounts
Who can log into Opselia, and how much they see. Admin sees everything. Manager can edit but identifiers marked sensitive stay masked. Viewer is read-only.
| Username | Name | Role | Staff record | Added |
|---|
Mailbox readers
A reader runs on a computer in the practice, signs into the mailbox there, and sends back what it finds. Mail is never forwarded and the mailbox password never leaves that machine.
Backups
The whole database is copied every night to storage that is separate from the app, so a bad import or a deletion can be undone.
About
Everything lives in app/data/credentialing.db. Back up that one file and you have backed up the whole system.