The Most Valuable Data in MedTech Is the DataYour Commercial Team Isn’t Allowed to See

After thirty years in healthcare technology — on the provider side, the manufacturer side, and now running a company that manages prior authorizations at scale — I’ve come to a conclusion that sounds like a contradiction:

The single most commercially valuable dataset in medical technology is the one your commercial team is least allowed to look at.

Every prior authorization your program touches produces evidence: which payers approve, which deny, which denials get overturned, how long the fight takes, and where in the appeal ladder the case finally clears. For a device in a nascent market — a young Category I code, an emerging procedure — that evidence is the difference between a rep saying “coverage is improving, trust me” and a rep saying “carriers that denied this procedure last year now approve it, and when they deny first, denials are frequently overturned on appeal.” One of those sentences is evidence. The other is noise. (And evidence is all it is — a description of where a market has moved, never a promise about any patient’s case. I’ll come back to why that distinction is the entire discipline.)

But that evidence is born inside protected health information. And so, at most manufacturers, it stays locked in an operations database, summarized once a quarter into a slide nobody in the field ever sees. The industry’s most persuasive proof points die in compliance quarantine.

I don’t accept that trade-off anymore. Recently, my team built something that proves you don’t have to. But before I describe the architecture, I owe you the two questions every access program should be able to answer in one breath — because if it can’t, the dashboard is premature.

Who pays, who benefits — say it out loud

Manufacturer-funded access support has a long regulatory history, and the Office of Inspector General has been explicit about the risk at its center: services that relieve a physician practice of a burden and expense can constitute remuneration under the federal Anti-Kickback Statute when they are linked to referrals. OIG said so directly in the prior-authorization context more than fifteen years ago, and its 2023 General Compliance Program Guidance still frames the questions the same way: who was selected and why, what value changed hands, and could it skew a clinical decision.

So here is how this category stays honest, stated in public rather than filed in a drawer — four rules we treat as architecture, not etiquette:

First, the named beneficiaries of access work are the patient and the product’s access — never a practice’s bottom line. We do not market relieved workload, saved staff hours, or absorbed administrative burden to practices, because OIG guidance treats exactly that framing as potential remuneration when tied to referrals.

Second, appeals are initiated on clinical merit and payer-policy grounds — never to build a statistic. The moment an appeal exists to feed a dashboard, the dashboard is measuring your misconduct.

Third, program funding structures are designed with, and periodically re-reviewed by, healthcare regulatory counsel against OIG guidance — before the first case, not after the first question.

Fourth, access intelligence describes markets. It never rewards referrals. Evidence of where coverage is moving is a legitimate commercial asset; a subsidy aimed at the people who order your product is not, and the difference is the whole game.

If those four sentences sound restrictive, consider what they buy: a dataset your compliance officer will defend instead of quarantine. That is the asset.

A denial is rarely the end of the road

Start with what the data actually shows when you follow it honestly. The American Medical Association’s latest physician survey found that 95% of physicians say prior authorization delays access to necessary care, and nearly a third report that requests are often or always denied. Physicians experience prior authorization as a wall. That experience is real — and it is also incomplete.

Because a denial is rarely the end of the journey. One patient can generate a chain of linked cases — pre-authorization, then first-level appeal, then second-level, then external review — each step re-establishing clinical medical necessity and health-plan policy compliance until the plan approves, or the physician or patient chooses to withdraw. When you track that full journey, two numbers emerge that most organizations never compute.

The gap between first-pass approval and eventual approval. Case-level approval rates systematically understate the truth, because each appeal recycles the same patient back into the denominator. In our de-identified, aggregated program experience — and I’ll flag every such figure in this article as an illustrative observation across engagements, never any single client’s data — patient-level approval can run materially above the case-level rate, gaps on the order of twenty points. If you only report case-level, you are underselling your own program.

What I call the hurdle multiplier. The number of cases worked per patient to clear payer denials. This is not a demand metric — I want to be precise about this, because it’s tempting to spin it positively. Every extra case exists because a payer said no. It is a burden metric: it quantifies the administrative weight a payer’s denial posture places between a patient and an approved procedure, and the delay that patient endures while the ladder gets climbed. Named honestly, it becomes one of the most powerful numbers in the program — because it makes the overturn rate mean something.

In a nascent-code market, the overturn rate is your strongest market-access evidence. Not the promise that payers will come around — the documented, aggregate record that they already are, carried into the field with the guardrails above intact.

And I’ll be transparent about how those hurdles get cleared: AI is in the fight — policy matching, appeal assembly, medical-necessity documentation support at scale, every payer-facing and clinical work product reviewed and approved by a qualified person before it goes anywhere. Our results are partly an AI story, and pretending otherwise would be its own kind of spin. How we govern that gets a section of its own, below.

Why this data stays locked up — and the two ways companies get it wrong

Prior authorization outcomes live inside PHI. Names, member IDs, dates of service, diagnoses. HIPAA governs every byte, and it should.

Faced with that, organizations pick one of two failure modes. Some share nothing — the evidence stays in operations, the field runs on anecdotes, and the market development investment never compounds.

Others share recklessly — a spreadsheet forwarded to a rep “just this once,” a screenshot with a patient name half-cropped, a report that was never designed for its audience. The first failure wastes the asset. The second one can end careers.

There is a third path, and it requires a mindset shift more than a technology: compliance as architecture, not appendix.

What compliance-embedded design actually looks like

Most analytics projects design the dashboard first and send it to legal at the end. We inverted that. Every de-identification decision, every access boundary, every suppression rule was designed into the artifact — visible on the page it governs, so the builders, the reviewers, and the users all see the same rules. And the whole structure rests on a foundation HIPAA actually names: the data is de-identified under the Privacy Rule’s recognized standard — documented, independently assessed, and periodically re-validated — not merely “scrubbed” and hoped over.

The principles:

1. Permission before pipes. The right to de-identify, aggregate, and use the data is established in the BAA and client agreement before a single row moves. An engine without the entitlement is just a breach with a UI.

2. Random tokens, never derived identifiers. Patient journeys are stitched on surrogate tokens generated independently of any name, MRN, or SSN — and the standard has three parts, so we honor all three: the token is not derived from the patient’s information, the key is held separately and never disclosed, and the token is used for no other purpose.

3. Relative time, never dates. “Day 0, +12 days, +27 days” tells the whole clinical-journey story. A date of service never needs to appear.

4. Minimum cell sizes, enforced live — at every altitude. Any slice below eleven cases is suppressed and folded into its parent — consistent with the small-cell suppression convention CMS applies to Medicare data releases — and the threshold travels with every view, including provider-level views, where small territories would otherwise narrow the population. The suppression is visible, teaching the rule every time someone drills down. Engineered this way, residual re-identification risk is driven to the very small level the standard demands — and then re-assessed, because “impossible” is a word no honest data steward uses.

5. Aggregates with synthetic archetypes. When someone clicks a cohort of several hundred patients, they see the cohort’s profile — counts, rates, turnaround — plus one clearly labeled illustrative journey that is a synthetic composite constructed from aggregate patterns, never a lightly disguised real patient. The moment you list individuals, you’ve rebuilt the problem you were solving.

6. Right altitude for the right role. Leadership sees region-to-provider drill-downs under its permission scope and the client’s contract; a rep sees territory aggregates and case status under a narrower one. Row-level security isn’t an IT setting — it’s the compliance model expressed in software.

7. One vocabulary, one source of truth. Every number on every page reconciles to the same executive report leadership already trusts, and internal CRM jargon never leaks into client-facing language. (We eliminated the word “cancelled” entirely — a system artifact that implied something clinically untrue. The honest words were “denied,” “withdrawn,” and “open.”)

None of this is exotic. All of it is discipline — the platform’s design and operation as of this writing, maintained under a compliance program that audits it, which is the only honest way to publish a control.

And here’s what surprised me: when the compliance rationale sits on the same page as the chart it governs, compliance stops being the department that says no and becomes the reason the client trusts the number.

The same architecture governs our AI

I can’t write about access intelligence in 2026 without addressing the technology on both sides of the fight — because AI is now reported on both sides. Physicians increasingly report concern, captured in the AMA’s latest survey coverage, that payers are deploying AI to drive systematic, batch denials; regulators and legislators are examining that question. I won’t adjudicate it here. I’ll tell you what we do about the asymmetry, whatever that inquiry concludes: where denials arrive at machine speed, we use governed AI so that well-founded appeals can answer at machine speed — with a human leading every agent. The goal isn’t an arms race. It’s restoring balance for the patient on the other end of the case file, and for the integrity of the coverage process itself.

And let me be precise about what we’ve built, because AI claims are where credibility goes to die. We have not trained a proprietary foundation model, and I’m not going to imply otherwise. What we have built — and continue to improve — is PA-specific intelligence on top of governed platforms: payer-policy knowledge bases, decision logic, and models configured and refined on years of authorization outcomes.

Agentic AI is no longer a model question. The question that matters now is deployment: how that intelligence gets put to work, under whose lead, inside what boundaries. That is where the differentiation lives, and it’s a claim I can substantiate on any given Tuesday.

And the boundaries are the same ones you just read. Governing AI is not a policy memo at A3i; it is architecture. Agents inherit the exact constraints our dashboards live under — de-identified data where the work allows it, minimum-necessary scope always, automatic suppression — and every payer-facing or clinical work product is reviewed and approved by a qualified person before it leaves the building, with clinical content under clinician oversight, and carries that person’s name.

We deliberately do not say “human in the loop,” a phrase that reduces the person to a checkpoint in the machine’s process. We say human-led: every agent works for a person, and the person answers for the work. That’s why we are upskilling every A3i employee into a power user of digital labor — people who lead teams of internal agents the way managers lead staff. We audit for shadow tools relentlessly, because a governance model you don’t verify is a press release. AI doesn’t replace our people. It promotes them. (How that reshapes an org chart is a story for its own article.)

One engine, two surfaces

The last insight is about audiences. The executives who commission access intelligence will delegate it within a week — that’s not cynicism, it’s how executive time works. So we built one PHI-free data engine with two faces: a leadership console for drill-down analysis on the desktop, and a rep companion designed for a phone — because a rep’s real moment of need is the hallway outside a physician’s office, sixty seconds before the conversation.

And because that hallway is exactly where evidence can quietly turn into overpromise, the rep surface carries its own standing guardrail, on every screen: what it shows are historical, aggregate outcomes — evidence of where a market has moved, never a prediction or promise of coverage for any patient — and the clinical decision always belongs to the physician. Same engine. Same numbers. Same compliance rules. Different altitude, different device, different job.

Access intelligence is a category, not a byproduct

Here is where I’ll plant a flag. For twenty years, prior authorization data has been treated as operational exhaust — something you generate while doing the “real” work of getting cases approved. I believe it is a commercial data category in its own right: access intelligence. Evidence of where coverage is viable, where denials are being overturned, and what burden stands between a patient and an approved procedure — de-identified, aggregated, and delivered to the people who can act on it, on the surface where they act, inside the guardrails that keep it evidence rather than inducement.

The manufacturers who figure this out will walk into physician offices with proof while their competitors walk in with promises. And the partners who can deliver it compliantly — with the de-identification architecture, the data-use rights, the funding discipline, and the suppression rules built in and said out loud — will be the ones trusted to do it.

The most valuable data in medtech has been sitting in the case file all along. The craft is in setting it free without ever setting the patient’s information free with it — and without ever letting the asset become the inducement.

Jorge Amaro is the Founder, President & CEO of A3i Health, a healthcare technology company specializing in prior authorization management, revenue cycle management, and market access services for medical technology manufacturers. His thirty-year career spans both sides of the access equation — provider-side and manufacturer-side leadership roles including DaVita, Genentech, Amgen, and Access MediQuip — before founding A3i. He is a Fellow of the American College of Healthcare Executives (FACHE), a Past President of ACHE Central Florida, and completed Harvard Medical School Executive Education’s Artificial Intelligence in Healthcare program (2026).

Disclosures. This article is for general information and thought leadership; it is not legal advice. Nothing here guarantees any coverage, authorization, or appeal outcome; payer decisions vary by plan, policy, and clinical facts, and clinical decisions rest with treating physicians. Figures identified as illustrative reflect de-identified, aggregated program experience across engagements, not any single client’s data. A3i’s de-identification methodology, data-use rights, and program funding structures are maintained under its compliance program with healthcare regulatory counsel and are re-reviewed periodically.

Sources. American Medical Association 2026 prior authorization physician survey (fielded Dec 2025; reported May 2026) — 95% of physicians report PA delays access to necessary care; 32% report requests often or always denied. AJMC coverage of the AMA survey (July 2026) — physician concern regarding payer AI tools and batch denials. HHS Office for Civil Rights, Guidance Regarding Methods for De-identification of PHI (45 C.F.R. § 164.514). HHS-OIG Advisory Opinion 10-13 (prior-authorization services and remuneration). HHS-OIG General Compliance Program Guidance (Nov. 2023).

Next
Next

From Customer to Chief Growth Officer: A3i Health Welcomes Mark Wright