Overview
The Plan
Five moves at a time, what each was worth the day it opened, and what it reads now.
How a move gets here, and who closes it ▾
Facts close, judgement proposes. A move raised from a measurement closes itself: the check that opened it is run again, and when it stops finding anything the move is reached. That is not a second opinion about whether the work was done, it is the same measurement taken again.
Everything else waits for a person and says so on the row. A growth move can never close itself, because nothing in your data will ever say you opened an optical shop.
A move never reopens. The same problem coming back comes back as a new move with a new baseline, because "you fixed this and it broke again" is a different sentence from "you never fixed this".
Email review
Threads somebody sent you, that nobody answered back.
Summaries quote real email, and can name a person
Social security numbers, bank details and passwords are stripped automatically; names are not, and cannot be. Read before you import, and rewrite anything personal in your own words.Filters
What you have told Opselia
Corrections you made on a thread, kept and applied to the next one like it. Each says how many times it has been used.
| Mail like this | Opselia | Used | Last |
|---|
Muted senders
Threads from these never appear for review again.
| Pattern | Muted by | When |
|---|
Read the filed mail again
For when the rules have been fixed since a message arrived. Every message still waiting in Email review is read again with the rules as they are now, and anything that turns out to be an invoice is listed with its vendor, amount and due date already filled in.
No bills are created and nothing is deleted. A message somebody has already decided on is left exactly as it is, and so is any figure you typed yourself.
Start the mail over
For when the mail in here was collected by a version of the app that got it wrong. Everything is read again from scratch, correctly threaded, and each conversation is judged as it lands. You are shown the numbers before anything is deleted.
- Deletes
- Every thread in Email review. Every task that came from one, including edited ones, they were made from conversations that were split or misread.
- Keeps
- Every task you wrote yourself or that came from a finding, a renewal or an import. Bills, the ledger, vendors, providers, enrollments, documents.
- Then
- Run readHistory in your Gmail script to read the last 60 days back in. Opselia cannot reach into your mailbox to do it.
Data integrity
Where this app disagrees with the record, or holds what it should not.
What raises a flag here ▾
Exclusion screens providers and staff against the OIG list. An NPI match is certain; a name-only match says so, because names are shared and the OIG disambiguates by date of birth, which this app deliberately does not hold.
Exposure scans this database for the 18 HIPAA identifiers. Mismatch compares providers, and the practice's own group NPI, against NPPES. Contradiction is your data disagreeing with itself: a facility with no CMS locality, a plan with no payer ID, a credential that expired while still marked active.
All four clear themselves once the source is fixed. Nothing here is closed by hand, which is what makes the counts worth reading.
What counts as PHI
Every file import is scanned, and if any of these 18 HIPAA identifiers show up a “PHI detected” flag is raised above. Almost all of this app holds no patient data at all: payers, contracts, fees, staff, suppliers and denial totals are about the business, not about people. The one exception is Claims to fix, which keeps your own claim numbers so a biller can open them. If a payer or CPT export ever includes patient columns, delete it and re-export without them.
What has been sent to the model
Every call, which part of the app made it, and how much went. The text itself is never recorded, here or anywhere. Withheld counts the identifiers the scrubber removed before the call left.
What she has asked the outside world ▾
When your own records cannot settle something, what a denial code means, which specialties may bill a procedure, she can read the published rules and cite them. She writes the question herself, from the codes on the record. Nothing anybody types is sent to a search engine, and no answer is shown unless it arrives with a page behind it.
What's coming due
Every dated thing that lapses if nobody renews it, on one timeline.
What lands here, and when it becomes work ▾
The task closes itself when the renewed date is recorded, so nothing here needs chasing twice.
Attestations and portal logins
Payer portals (UHC, Availity) and directories that make you re-confirm your data on a cadence, no expiry date, easy to forget. Record when you last did each one; the radar schedules the next. Hit Attested today whenever you complete one.
| Portal / attestation | For | Every | Last done | Next due |
|---|
Positions
Positions
Every position you have posted, open or not. The status is yours to set: nothing here can tell that a job board stopped advertising.
Applicants
People, not postings. Somebody who applied before is recognized the moment you type their email, whichever position it was for. Rejection reasons come from a fixed list, because a reason written by hand is the riskiest thing this app could keep.
Employees
Who works here, and what paperwork is on file for them.
The HR folders
Opselia can keep the HR folders herself: one per person, the same subfolders for everybody, and the folder they sit in saying whether they work here. Built beside whatever you keep by hand, empty, filling from the day you switch it on.
A tree Opselia builds is one she can read, write and reorganise afterwards. That is the whole reason this exists rather than her reading your existing folders: the permission is Google's narrowest, so she can only ever open what she made.
Providers
Every clinician who bills or holds privileges.
Credentials
Licenses, registrations and identifiers, and when each one runs out.
| Credential | Holder | Line | Identifier | State | Expires | Status | Document |
|---|
Payers
Everything about one insurance company in one place: the plans it sells, whether claims reach it, what it will not cover, and how long you have.
Bulk editing, imports, and the state of the rule book
Every payer row, as a grid
| Payer | AddVal category | Status | Payer ID | Our PTAN / ID | Complete | Revalidation | Claims | ERA | EFT | Elig |
|---|
Every plan, by contract
Plans and contracts
Every plan an insurer sells, and which of your contracts it is paid under.
How a contract is identified ▾
The payer ID is a fact off the claim; the plan name is a label somebody typed. Grouping on the name split one brand across twelve rows and hid its real weight.
Product type keeps a negotiable commercial contract apart from Medicare Advantage, whose rates CMS sets for you.
The rule book across all payers
Coverage rules
What an insurer will not cover, so you find out before you bill it and not after.
What a rule holds, and the two clocks ▾
Every rule carries where you read it and when, so a write-off questioned a year from now is answered with a source and not a memory. A rule on the payer covers every plan it sells.
| Payer / plan | CPT | Coverage | Note / what to do instead |
|---|
Timely filing windows
How long you have to file, per payer. This is what separates a claim worth fixing from one to write off.
Blank is the honest answer until you know. A wrong default throws away claims you could still file.
| Payer | File within | Appeal / corrected within | Source | Checked |
|---|
Two different clocks, and mixing them up costs money
Timely filing runs from the date of service and governs getting the claim in at all. Appeal or corrected-claim windows run from the remittance, and are usually much shorter. A claim can be comfortably inside its filing limit and already too late to appeal.
Your contract can override the published manual. A participating provider agreement often sets its own filing limit, and that is the one that binds. When the number in your agreement differs from the payer's public policy, record the agreement and say so in the note.
These change. That is why every row carries a link and a checked date: when a write-off is questioned a year from now, the answer should be a source, not a memory.
What each procedure earns
By payer and plan, or by code, set against Medicare's rate for the same work in the same place.
Every contract, scored in full
The other two leaks: refusals that repeat, and what the data cannot see
What another specialty could bill ▾
A provider with two taxonomies can be paid under both, but only where the enrollment, the setting and the documentation allow it. She lists the codes that specialty is normally paid for, marks the ones you already bill, prices them at your own Medicare locality, and says what would have to change first. It is a shortlist to check with each payer, never a promise of payment.
How this is worked out ▾
The amount comes from what the insurer actually paid, in your 371.05 export, never from the price list stored in eCW. That list holds the Medicare rate for every insurer, so reading it would compare Medicare with itself and report about 100% for everybody.
Where the government publishes no price for a procedure, what Medicare actually paid you for it stands in instead, and the page says how often that happened rather than hiding it.
Billing dashboard
Before the visit
What a visit should pay, before you do it.
How this is worked out ▾
What this plan has paid you before for the same work, shown next to the Medicare rate. It is not a quote for the patient: their share comes out of that figure, and only checking their coverage on the day confirms it.
Needs prior authorization
Your PA reference, grouped by payer: the codes each one requires a prior auth for, so the team routes them before it's too late. Every entry keeps its source and last-checked date. Add or Import your payer's official list, and confirm on the portal before relying on it.
What the remittances say
Read straight off the payers' own 835 files, so this is their statement rather than ours: what they allowed, what they actually sent, and what they left with the patient. Nobody exports anything for this. It arrives when they pay.
Denial insights
Refused claims somebody can still do something about, and how long is left to act.
Paste a denial code and Opselia will say what it means CO-109, PR-204, CO-97 M80…
How many goes it takes to get paid which denials to fix on the first submission, rather than sixty days later
How this is worked out ▾
Denials come from the CPT-level denial report. The paid volume that makes a rate meaningful comes from your fee export, which is why both matter.
Ordinary write-offs are set aside. A code denied five times and paid six hundred is noise, not a rule.
Ledger
Vendors by month
Select the transactions on your bank's page and copy them. Include the heading row, the one with Deposits and Withdrawals on it, if you can: without it the direction has to be worked out from the running balance, and where it cannot be worked out nothing is read rather than guessed.
Your own bank accounts, so a statement can tell money moved from money spent
Most of what leaves an account is often not spending: it is moved to another account you own, paid to the owner, or repaying a loan. Naming them here lets this page say which is which instead of offering all of it as expenses. Only the last four digits and what you call them are kept.
The last four digits are what your bank prints on a transfer line. Where it prints none, this page reads the word you typed on the transfer instead, so one you labelled OVERHEAD is counted as overhead even on a line that names no account. Money paid to the owner, to a contractor or on a loan is added to the ledger as an expense; for those, give the account the same name as the vendor your ledger already uses and the rows land on it.
This month
Bills
Setup
Recurring vendors, and how each one is paid
Paste an invoice email
Below this line: nothing. The recurring-vendor grid and Paste an invoice open from Setup when you need them, and the doubts that used to sit here are the reasons on the rows above.
Budget and forecast
The year so far, and where it lands if the rest of it looks like the last one.
How this is worked out, and how honest it is ▾
Every figure is rolled up from entries in the Ledger, so nothing here is typed twice and the budget cannot drift from what was actually recorded.
Scaling last year's shape rather than averaging the months means the forecast respects your seasonality: a quiet December stays quiet. It assumes the rest of the year behaves like the last one, adjusted for growth so far: no new provider, no lost contract, no one-off event.
Spending is only as complete as the ledger, so treat the cost forecast as a floor while bills are still arriving. All aggregate. No patient detail reaches this page or the tables underneath it.
Surgery and lenses
The consignment, what has come off it, and whether the surgery fees for those cases have arrived. No patient is named anywhere on this page.
Revenue by code
What every code earned, month by month, in money actually received. Type a code or a procedure name in the filter above to find one.
Hospital and surgical privileges
Where your providers may operate, and when each place reappoints them.
| Facility | Location | Privileges | Reappointment | Status | Next step |
|---|
What each column means
Privileges is the provider's medical-staff category at that hospital, in plain terms: Active: full member, can admit and treat patients there. Courtesy: occasional use, limited involvement, not a full staff member. Consulting: consults on cases but does not admit. Provisional: initial probation period a new member serves before Active. Affiliate / Telemedicine / Honorary: non-admitting, remote, or retired categories. None: no privileges on file at this facility.
Status is where your record stands, shown by color: In good standing privileges verified and on file, nothing to do. Pending waiting on the hospital (application in, or a reappointment not back yet), the ball is in their court. Action needed something is on you to do. This turns on automatically whenever an open task is linked to the facility (use New task on its row), and clears itself when that task is done. Inactive no longer active at this facility.
Reappointment is when the hospital re-verifies the provider's privileges, usually every two years. The date on the left is when the current cycle started; the one on the right is when it is due. Renewals warns you ahead of it.
Sheets
Work that is a list rather than a thing. Opselia writes the sheet, so she can read it back: nobody reports progress and nobody remembers to upload it.
Documents
Licenses, privilege letters, CMS correspondence, certificates. Dropped here they are stored, downloadable by anyone with access, and, for PDFs with a text layer - read for dates and identifiers. Nothing is written to a record until you approve it.
| Document | Type | Attached to | Read | Uploaded |
|---|
Your own forms
Upload a form your practice already uses. Opselia reads the questions off it, you check what it found, and from then on it can be filled in here and printed with your logo on it for everyone to sign.
Who to call
Named people with direct numbers, gathered from correspondence. Always take a reference number and note the date, payers routinely deny a call happened.
| Organisation | Person | Role | Phone | Notes |
|---|
Forms and links
Public pages you look things up on: state boards, CMS forms, exclusion checks. Links rather than stored PDFs, because credentialing forms get reissued and a saved copy quietly goes out of date. Anything you sign into lives in Records, Access directory. Payer-specific portals live on each payer row (Payers tab → click a payer).
| Link | Type | What it is for | Checked |
|---|
How each payer takes a reconsideration or an appeal
Portal, fax or mail, where, which form and by when, read from each payer's own provider pages. The billing board shows the payer's row on every claim and puts the address on the letter.
| Payer | Level | How and where | Deadline | Source |
|---|
Blank forms and internal documents
Upload blank/reusable forms, the employee handbook, and internal papers so staff can find and print them from here. These are reference files, not patient records, not HR files.
Billing cheatsheet
Look up a denial code and read what to do about it. Also modifiers, eCW how-tos and the claim-review checklist. Type a code or a keyword.
Practice locations
Every address you bill from, which every payer record must match exactly.
| Name | Address | Group NPI | PTAN | Phone | Status |
|---|
Vendors
Who you buy from and pay, and how to reach them.
Two records for one company?
Access directory
Every system the practice logs into, and who owns it.
What this list is for ▾
A password-manager export is a flat wall of hostnames. Sorting it into categories, payer portal, clearinghouse, payroll, banking, turns it into something you can hand to somebody else, and it makes the next question answerable: which of these should this job title actually have?
Sort into categories shows you every guess before it changes anything, and never overwrites a category you set yourself. To see the gaps for one person, open their employee card and read the access review.
Audit trail
Every change in the app, who did it, when, and what. Newest first.
| When | Who | Action | Record | Detail |
|---|
Playbooks
The practice's SOPs and how-tos, so a process can be run by anyone, not just whoever keeps it in their head. Search a topic, or add your own. Great for onboarding and delegating.
Day-before schedule prep
The repeatable routine you run the day before clinic, so anyone can do it. This holds the process only: the per-patient checks happen in eCW. Edit the steps to match how you work.
Responsibilities
Who owns which recurring duty, how often, and who backs them up, so nothing falls through when someone's out, and delegation is explicit.
| Responsibility | Owner | How often | Backup (covers the owner) | Notes |
|---|
Coverage matrix
Every responsibility against every employee, so you can see at a glance who owns what and where you have no backup. Set owners and backups on each employee's card (Employees tab).
Intake: drop everything, the app works out what it is
Notes, a price list, vendor contacts, an SOP stuck in Google Keep, a fee schedule, last quarter's denial export. Drop the pile in or paste it below. Each file is read, identified by what is actually in it, and sent where it belongs. Nothing is filed until you have seen the list and said so.
Drop the whole pile
There is no sorting to do first. A spreadsheet is recognized by its column headings and handed to the importer that reads that shape properly, the same one behind the Import button on its own tab. Anything that is prose is broken into pieces and filed as knowledge.
- Allowed and paid amounts by code goes to Fee analysis
- Denial reasons by code goes to Denial insights
- Money by code and month goes to Revenue by code
- Enrollment status per payer goes to Payers, and filing windows to Payers · filing windows, which is the rule book on the same tab
- Dates, amounts and a payee goes to the Ledger
- Everything written down becomes a playbook, cheatsheet, vendor, contact or duty
What it cannot place, it says so and leaves alone rather than guessing. Nothing is saved, moved or imported until you press the button on the list it shows you.
Never patient information
No names, dates of birth, addresses, member numbers or diagnoses. Not on this screen, and not anywhere else in the app. A file carrying them is flagged by name before anything is sorted, and saving it is refused.
Denied claims are the one place patient work shows up, and even there the app never sees a patient: the Scrubber on your own computer swaps each real claim number for a code like WL-7F3A91 before anything is sent, and the list matching codes back to claims stays on that computer. So a claim can be worked on here without this app, or anyone hosting it, ever holding something that points at a person.
About and Help
What every part of this app does, and how it keeps patient data out. Search a feature or a question, or browse the sections below.
What Opselia can and cannot do
- Reads the mail that arrives and files what it is about
- Raises a task when the records show something is wrong
- Withdraws that task when it stops being true
- Looks over the whole practice each morning and says what she found
- Reads a spreadsheet back once your team has filled it in
- Changing any record: it is written only once you press it
- Closing a task on judgement rather than on a fact
- Every email she drafts. Nothing is ever sent by her
- Importing a year of money from a budget sheet
- Send an email. There is no outbound path she can reach
- Read a patient's name, date of birth or record number. Those columns are refused before she is asked, and a file carrying them is refused in your browser
- Delete a record, or empty a table
- See your mail bodies, your documents or your audit trail when querying
- Reach anything outside this practice's own database
Every call she makes to a model is listed below, with how much text went and how many identifiers were removed on the way.
Mailboxes the sweep reads
Every address Email review pulls from. No passwords are kept here, only which mailboxes are in scope. Removing one stops future sweeps and leaves anything already reviewed in place.
| Address | Label | Scope | Status | Reviewed |
|---|
Your profile
The name shown in the sidebar and against every change you make.
My access
The systems you can sign into and the username you use on each. Yours only, collapsed so it stays out of the way. The practice-wide list of systems lives in Records, Access directory.
Where the sensitive paperwork lives
This app deliberately holds no social security numbers, dates of birth or bank details. Those documents stay in Drive, under its own sharing controls and the HIPAA agreement you already have with Google. Record the folders here so nobody has to go hunting, and so a new person can be told once.
You can paste either a Google Drive web address, or a folder on your own computer such as G:\My Drive\HR if you use Drive for Desktop. A web address opens for anyone; a folder on your computer opens only on yours, through the Scrubber.
Which document goes where
In this app: business paperwork with no patient or personal identifiers in it. Licenses, certificates, payer contracts, privilege letters, blank forms. Anything attached to a staff record is locked to administrators automatically.
In Drive: anything carrying a social security number, a date of birth, bank details, or a patient's name. I-9, W-4, direct deposit, offer letters, and any document that arrived with patient information on it.
The rule that keeps this simple: if losing the file would matter to a person rather than to the business, it belongs in Drive. Each provider, facility and payer record can also carry its own folder link, on the record itself.
Practice setup
The guided first-run walkthrough, practice profile, specialties, and your first provider. Re-run it anytime to review those basics.
Practice name and logo
Shown in the sidebar and on the sign-in screen. The logo is stored inside the database, no separate file to lose.
What arrives in each mailbox
An email address is one of the eighteen identifiers HIPAA protects, so where a patient might write, Opselia records nothing about senders it does not already know. That is the careful default and it is wrong for a mailbox patients never use: it hides mail from applicants and staff, who write from ordinary personal addresses like everybody else. Only you can say which is which.
Which tabs you want
Tick anything you do not use and it stops appearing in the sidebar. Nothing is deleted and nothing is lost: the screen and its records stay exactly as they are, and unticking brings the tab straight back.
Google Drive
Lets Opselia read the team's denial worklist on its own, every hour, with nobody's computer switched on. Until this is connected the same sheet still works the way it does now, through the Scrubber watching a folder.
What Opselia is asking for
- Only files it made itself. The permission is Google's narrowest,
drive.file. Opselia cannot open anything else in your Drive: not your patient exports, not your contracts, not a folder somebody shares with you. That is enforced by Google, not promised by us. - Three columns of the worklist. The label beside each claim, the note your team wrote, and its own status column. It asks Google for those three by name and receives those three.
- Never the claim number, and never a patient. The sheet carries the eCW claim number because your billers cannot work a claim without it. Opselia does not ask for that column, and refuses to run a read that would.
- One column written back. Its own. It never edits a note, never reorders a row, and never adds one.
- Yours to take back. The sign-in is against your Google account in your own
Cloud project. You can remove Opselia at
myaccount.google.com/permissionswithout asking us, and Disconnect below hands the permission back as well as forgetting it here.
The daily email
One message a morning, to you, listing what moved on its own and what is waiting. It is not sent when there is nothing to say, because a mail that arrives every day saying "all clear" is one people stop opening.
Opselia builds it and cannot send it. It has no mail credential and is not getting one, which is the whole reason the reader lives inside your own Gmail. The script there sends this, as the practice, to the addresses below. It only ever sends inside the practice: anything Opselia writes for an outsider is left as a draft.
Your password
Revenue by CPT code
The collections-per-code export from your practice management system. Feeds Revenue by code and the top-codes reading on Budget and forecast.
Rename categories
Change what these are called on screen. The underlying values never change, so renaming can never orphan a record.
Tell everyone an update is coming
Locks every open screen with "Update ongoing, please wait" until you lift it, or until it runs out on its own. Nobody is signed out and nothing is lost.
Sign-in accounts
Who can log into Opselia, and how much they see. Admin sees everything. Manager can edit but identifiers marked sensitive stay masked. Viewer is read-only.
| Username | Name | Role | Staff record | Added |
|---|
Mailbox readers
A reader runs on a computer in the practice, signs into the mailbox there, and sends back what it finds. Mail is never forwarded and the mailbox password never leaves that machine.
Backups
The whole database is copied every night to storage that is separate from the app, so a bad import or a deletion can be undone.
About
Everything lives in app/data/credentialing.db. Back up that one file and you have backed up the whole system.