Submitted by: Blaine Warkentine, MD — Founder, SolvingHealth (Boulder, Colorado). We operate a physician review network (ClinicalSwipe) and open verification infrastructure for clinical AI outputs (HashCare). We disclose this interest plainly: we build the kind of accountability tooling this comment recommends, and everything we propose below can be implemented by anyone, using open methods, without any product of ours.
A distinct, consistently identified payment category for software-based services with algorithmic analyses is the right first step, and maintaining CY2026 payment continuity during the transitional year is reasonable.
The program-integrity concern the rule identifies with subscription- and per-use ("per-click") arrangements is fundamentally an evidence problem: today, nothing in the claim proves that a distinct algorithmic analysis of a distinct patient study actually occurred for each billed unit. The proportionate answer is a verifiable record per billed use, not a payment haircut. Transparency infrastructure already exists upstream of the claim: under ONC's HTI-1 final rule, certified health IT must expose thirty-one source attributes for predictive decision support interventions — yet nothing in that framework binds a specific model version to a specific paid claim line, which is precisely where program integrity lives once a category scales. The gap sits between two federal frameworks and is inexpensive to close at specification time. We recommend that CMS, in developing the comprehensive SaMS methodology (and, if feasible, as voluntary reporting during the CY2027 transitional period), require or encourage a tamper-evident, third-party-verifiable record for each billed SaMS service comprising: (a) a cryptographic content hash of the analyzed input and of the algorithmic output (the content itself never needs to leave the facility — a SHA-256 fingerprint suffices and contains no PHI); (b) the algorithm identity and version; (c) a timestamp; and (d) where the code descriptor includes clinician interpretation (for example, CPT 75577, "...with interpretation and report by a physician or other qualified healthcare professional"), the reviewing clinician's NPI, verifiable against NPPES. Such records cost effectively nothing to generate, can be validated by a MAC, UPIC, or OIG auditor without trusting the vendor's own logs, and directly answer the rule's observation that current systems offer "only limited transparency." A published, freely usable working definition of verifiable review along these lines exists (hashcare.com/real-review, version 1.0, itself integrity-protected by content hash); we offer it as a starting point, not as a proprietary standard — any equivalent open method serves the same purpose. To make the "verifiable without trusting the vendor" property concrete rather than asserted: we operate a small public registry of such fingerprints whose daily root is timestamped into the Bitcoin blockchain via the open OpenTimestamps standard, and we have published the complete recipe (hashcare.com/prove) by which any party — including CMS staff — can, in four commands and without any account, node, or trust in us, recompute the registry's root from the public fingerprint list and check its timestamp against a specific Bitcoin block. The point is not our registry; it is that per-use provenance for algorithmic services is already cheap, open, and independently checkable with existing tools — the comprehensive methodology can rely on it.
Outcome-conditioned payment for algorithmic services requires knowing, per claim, which algorithm version analyzed which study, and who (if anyone) interpreted it. Absent per-use provenance, outcomes attribution across rapidly versioned software is guesswork. We urge CMS to treat provenance requirements not as a program-integrity afterthought but as the foundation of the outcomes-aligned framework it intends to build. We also caution against conditioning payment on assertions that human review, by itself, improves accuracy: the published evidence on human-AI teaming is mixed. What review verifiably provides is accountability — a licensed, identifiable professional answerable for the determination. Where CMS relies on clinician involvement (as several SaMS code descriptors do), that involvement should be measurable (for example, sampled independent double-review with disclosed agreement statistics) rather than presumed.
CMS proposes O1 as an OPPS indicator. The clinical work of an algorithmic analysis is identical regardless of the site of service. As procedures migrate to ASCs under the IPO phase-out this same rule advances, we encourage CMS to address SaMS payability in the ASC setting in the final rule or the comprehensive framework, consistent with the site-neutrality logic CMS applies elsewhere in this rule.
We support inclusion of the ACP eCQM in the hospital outpatient setting, including its numerator credit for pre-existing directives and documented discussions. As the IPO phase-out moves complex procedures outpatient, the HOPD encounter is increasingly the right moment for advance care planning; measuring it will drive the documentation infrastructure patients need.
Thank you for the opportunity to comment. We would welcome the chance to provide technical detail on any of the above.