"Send us three months of bills" is the short version. This is the long one: exactly what an audit needs, every format we take, and the four ways to move the files — from a one-time upload link to an authenticated API your systems call on a schedule.
The governing principle: you don't change your formats, and you don't build anything. Normalizing disparate carrier and ben-admin output is the work we do — it isn't a prerequisite you have to satisfy first. If you can export it or already receive it, we can almost certainly read it.
The three inputs
An audit is a comparison. To recompute a bill line we need what coverage was, what the carrier charged, and what the contract says it should cost. That's three inputs:
| Input | What it is | Why the audit fails without it |
|---|---|---|
| Enrollment | Your census or eligibility extract — member, plan, tier, effective and termination dates, and any salary or volume fields for life/disability. | This is the source of truth we recompute from. Without effective dates we can't detect a tier change the carrier missed. |
| Carrier bills | The list bills themselves — last three months to start, then one per month. | This is what we recompute against. Three months because retro corrections and rate drift only prove out across consecutive bills. |
| Rate & rule basis | Rate sheets and the billing rules in your carrier contracts. Details below. | Without it we can flag internal inconsistency, but we can't tell you the carrier is wrong — only that it disagrees with itself. |
The rate and rule basis — the input people forget
Enrollment and bills are obvious. The third input is the one that gets left out of the first email, and it's the one that determines whether we can say "the carrier owes you $367.50" instead of "this line looks unusual."
Concretely, we're asking for whatever you have that establishes the correct answer:
- Rate sheets by plan and tier, with effective dates — including the renewal rates and the date they took effect. Mid-year renewals are a common source of drift.
- The proration rule in each carrier contract. Full-month, daily proration, the 15th-of-month rule, and first-of-following are all legitimate and produce four different correct premiums for the same person. We need to know which one you actually agreed to.
- Rate basis for volume-rated coverage — per $100 vs. per $1,000 of coverage, rounding conventions, age-band tables, and guarantee-issue caps. This is where a 900% overcharge hides.
- Retro adjustment terms — the credit window (60 days, 90 days, two cycles) and any cap on retroactive terminations. This sets the clock on what's still recoverable.
- Fees billed alongside premium — admin fees, PEPM charges, and how they're calculated.
Formats we accept
We normalize to a canonical model on our side, which means the list of formats we take is long and boring by design:
| Category | What we handle |
|---|---|
| Delimited & spreadsheet | CSV, TSV, pipe-delimited, fixed-width, XLS, XLSX — including multi-tab workbooks, merged header rows, and the report-style layouts carrier portals produce. |
| EDI | 834 enrollment (all common carrier variants), 820 premium payment/remittance, and 835 remittance advice where premium and claims reconciliation overlap. |
| Ben-admin exports | Native extracts from bswift, Employee Navigator, PlanSource, Selerix, Ease, and similar — standard export or custom column set, either is fine. |
| Structured data | XML, JSON, and direct database extracts if you'd rather send a query result than a report. |
| PDF and paper bills | Native-text and scanned PDF list bills, processed through document extraction with a human verification pass. See below. |
When the bill isn't data
A meaningful share of carriers — particularly on ancillary lines — still deliver a list bill as a PDF, or as a portal screen you print. That's not a reason to exclude the carrier from the audit, and it's usually where the errors are densest, precisely because nobody can spreadsheet it.
Those bills go through document extraction to recover the line items, then a verification step where extracted totals are reconciled back to the printed page totals before anything enters the audit. If a page won't reconcile, it's flagged as unverified rather than silently included — a wrong number is worse than a missing one.
Onboarding a format we haven't seen
New carrier layouts are routine, not exceptional. The process:
- You send one real file. Not a spec, not a sample we have to request three times — the actual file you already receive.
- We build the map from that file's columns to our canonical model, including the quirks: repeated headers, subtotal rows, footnote markers in amount columns, a member identifier that changes shape halfway down the file.
- We reconcile to the bill total before the map is accepted. If our parsed lines don't sum to the carrier's stated total, the map is wrong and we fix it — that check is non-negotiable and automatic.
- The map is reused every month after. Format onboarding is a first-cycle cost, not a recurring one.
A standard delimited or Excel bill is typically same-day. An unusual PDF layout or a carrier-specific EDI variant takes longer. Either way it happens inside the first audit cycle, and it isn't billed as a separate implementation project.
Four ways to move the files
Start at whatever level your organization is comfortable with. Most engagements begin at level 1 and move to level 2 or 3 once the audit is a standing monthly item.
Per-client secure upload link
We issue a time-limited, write-only upload link scoped to your engagement. Nothing to install, no account to create, no credentials to manage. Drag the files in.
SFTP — yours or ours
Drop files on our SFTP endpoint with key-based authentication, or let us pull from the SFTP or secure share your team already runs for carrier files. Most operations teams already have this plumbing; we fit into it rather than adding another one.
Direct container access
If your files already live in Azure Blob Storage, Amazon S3, or Google Cloud Storage, we read from a dedicated, scoped-down container using short-lived credentials you issue and can revoke. No copy step, no second system of record.
REST API and automated pulls
An authenticated REST endpoint for submitting enrollment and bill files and retrieving completed audit results as structured JSON — so exceptions land in your own system rather than a workbook someone re-keys. Webhook notification on audit completion, and scheduled pulls from a source you designate.
What happens the moment a file lands
Before any analysis, every delivery goes through the same intake checks, and you hear from us if something fails:
- Completeness — row counts and control totals against the file's own trailer or stated totals.
- Reconciliation — parsed line items must sum to the carrier's bill total.
- Continuity — this month's population compared against last month's, so a truncated export gets caught as a data problem instead of being reported to you as 400 terminations.
- Coverage — enrollment and bill populations aligned, so we can tell you what isn't on the bill, which is its own category of finding.
What we don't need
Minimum necessary is a HIPAA principle and also just good practice. We don't need claims detail, diagnosis or procedure information, clinical records, or banking and payment credentials to audit a premium bill. If your standard export includes fields outside what the audit requires, tell us and we'll suppress them on ingest rather than store them.
Start with one group
You don't need to solve any of this in advance. Send one group's last three months of bills and the matching enrollment extract, in whatever form you already have them, and we'll tell you what we can read, what we're missing, and what the first cycle would find.