HPI-CT — Healthcare Control Intelligence Platform · prototype

Start from your operational problem — denials, improper payments, CMS-audit survival, encounter-data quality, fraud — and the platform maps every answer back to COSO, the Green Book, FRMG, OIG guidance and the CFR underneath. Framework in the engine room, operational problem in the storefront. One self-contained file, same 07_Exports data, cross-linked. DRAFT for review; public-source, personal-capacity. Generated 2026-08-04.

What do you need to do?

Pick your operational problem below. Each answer is powered by the same connected control model underneath — every recommendation traces back to COSO, the Green Book, the Fraud Risk Management Guide, OIG guidance and the CFR. You work the problem; the framework does the bookkeeping.

New here? 1 Set your entity profile 2 Take the baseline assessment 3 Review your gaps & the controls that close them

Under the hood — the control library that powers the answers

Your current progress live from the Assessment & Maturity tabs

Updates from the entries you make on the Assessment and Maturity tabs (starts at 0 until you answer). Saved in your browser.

What's inside

One self-contained file over the whole platform — the control library, the data sources that feed each control, the diagnosis matrix, the enforcement-case evidence, the interactive assessment & maturity model, and the intelligence graph that connects them. Every number is read from the shared 07_Exports data, so the views can't drift apart.

Controls library (the master crosswalk) · Data-source registry (what feeds each control) · Control-failure diagnosis matrix (flag → scheme → fix) · Case-to-control evidence (DOJ-coded universe + state-derived patterns) · the v3 baseline assessment & maturity rollup · and the Intelligence knowledge graph. From a control you can reach its data sources and the schemes it addresses; from a case you can reach the control that closes it; from the graph you can find requirements with no control at all.

Controls library

All controls from every module. Click a control to expand its regulatory basis, workflow detail, the data sources that feed it (click to jump), and the diagnosis families it fixes.

Data-source registry

The external data each control consumes. "Consumed by" control IDs are clickable — jump straight to the control.

Control-failure diagnosis matrix

A detection flag your system raised → the implied scheme → the HPI-CT control that fixes it (click the control chip to jump).

Case-to-control evidence — DOJ-coded universe

Recurring fraud patterns from the coded DOJ case base, each mapped to the control area that closes the loophole.

State-enforcement-derived patterns → the new controls

A separate layer (kept out of the DOJ-coded universe by design). Each 2026 state case drove a new control — click the control chip to jump to it.

Baseline assessment — the v3 questionnaire

The actual questionnaire your organization completes — all questions across the eight HPI-CT modules. Answer each with the option that matches reality (you never pick a score); a hidden key maps your answer to 0–3. Pick a Scoring mode at the top of the questionnaire: Self-reported (answer-first) scores your answers as given and keeps the evidence fields hidden until you want them; Evidence-validated then caps each score by how verifiable your basis is — a self-produced document supports at most 2; only system-generated, independent, or re-performable evidence reaches 3, and only when its provenance is source-obtained or re-performable (or a subject-provided document that is independently verified); an unverified verbal assertion caps at 1. Don't know scores 0. Your entity profile scopes questions in/out and sets targets. Answers save in your browser. Draft — confirm framework mappings against primary sources.

Evidence ladder (max score): Oral 1 · Documentary 2 · System / Independent / Re-performable 3.
Entity profile (scopes the questionnaire & sets targets)

Maturity by module

Weighted 0–3 maturity per module, colored by band, from your answers.

By internal-control component

Your answers rolled up to the five COSO / Green Book components.

Questionnaire

Grouped by module → sub-area. Choose which modules to assess and optionally hide questions that don't apply to your profile. Answers auto-save in this browser.

Two ways to score, one source of truth. The Assessment tab is the primary questionnaire (224 questions, evidence-aware) and produces its own maturity, fraud-risk & OIG rollups. This tab is a lighter standalone maturity scorer (148 core requirements, quick 0–3) plus the COSO/Green Book principle lens. Use it for a fast read or the principle view; use the Assessment for the evidence-graded, of-record score.

Cross-domain maturity rollup

Score each domain's requirements 0–3 (same weighted model as the module Assessment sheets: 0 None · 1 Ad hoc · 2 Partial · 3 Full). Domain % = Σ(score×weight) ÷ Σ(3×weight); the overall rollup weights every domain by its own maximum. Bands: 1 Initial <30% · 2 Developing 30–49% · 3 Defined 50–69% · 4 Managed 70–89% · 5 Optimized ≥90%. Scores save in your browser. Draft — confirm against the module workbooks.

Maturity by domain

Weighted maturity % per module, colored by band.

Principle-level maturity & fraud / OIG-readiness lens

The same 0–3 scores, re-aggregated onto the COSO 2013 / GAO Green Book 17-principle spine and the FRMG and OIG 7-element overlays the v3 modules carry. Fraud-risk readiness = weighted maturity over FRMG-tagged questions; OIG-readiness = over OIG-element-tagged questions. Updates live as you score below. Draft — mappings mirror the module workbooks; confirm against primary sources.

By COSO / Green Book principle

Governance-level principles with no operational-module question (e.g. P5, P6) live in the Module 00 hub.

By internal-control component

Rolled up to the five COSO components.

Per-requirement scoring

Executive report — one page for leadership

Combines the baseline assessment, the maturity model, and your biggest gaps — each gap linked to the controls that close it. Everything reads live from your saved answers. Draft — self-reported unless evidence-validated mode is on; confirm before external use.

Scores by COSO component

Top gaps → the controls that close them

Lowest-scoring answered modules first. Recommended controls are drawn from the same module (preventive first) and respect your entity profile. Click a control to open it in the library.

Your Tier 0 starting set

Scoped to your entity profile and, once you have answered anything, ordered by where you scored weakest. Preventive controls first — the case base puts 63.6% of alleged dollars in the enrollment and authorization stages, so that is where a starting set earns its keep.

Deployment options — overlay, don't overhaul

The toolkit runs beside existing systems as controls, reports and checklists — no data migration, no core-system change. Pick the cheapest tier that fits what you already own; most organizations start at Tier 0 or 1 and move up only when a specific need justifies it. Draft — confirm figures against primary sources.

TierModelWhat it usesNew costLegacy impact
0Run-as-is (start here)Excel modules + this HTML, opened locally or on a shared drive~noneNone
1Microsoft 365 overlaySharePoint/Teams + Excel Online + Power BI + Power Automate~none if M365 already licensedNone
2Read-only analytics overlayExisting claims/EHR extracts + existing BI/SQL tools; turns the "Analytics: Yes" controls onLowRead-only, no write-back
3Workflow attachExisting ticketing/GRC/EHR tasks + connectors/RPALow–moderateAdditive only
4Import into owned GRC platformArcher / AuditBoard / MetricStream already in houseSunk costNone

Principles that keep cost & disruption low

  • Overlay, never replace — sits beside legacy systems; no data migration.
  • Read extracts, don't integrate live — analytics run on scheduled exports, not write-integration.
  • Reuse licenses already paid for — M365 / existing BI / owned GRC carry the load first.
  • Control-as-report / control-as-checklist — every control is an artifact a person or existing tool can produce.
  • Phase by risk — start with the highest-risk domain module, prove value, expand.
  • Keep humans in the loop on any analytic influencing a coverage or denial decision (e.g., state AI rules effective 2026).

Suggested rollout

Days 1–30 (Tier 0): pick the highest-risk domain, run the assessment, review applicable controls & gaps with compliance.
Days 31–60 (Tier 1): move assessment & dashboard into M365; assign control owners; start collecting evidence.
Days 61–90 (Tier 2): stand up 2–3 analytics-driven controls as read-only reports on existing extracts; expand to the next module.

Where this can go deeper — a transaction-level control-check (advisory)

A natural extension of Tier 2: run an actual claim, a provider/KYC package, or a documentation upload through the codifiable controls and return a per-control pass / fail / needs-review scorecard — flagging exactly which controls are missing. Deterministic controls (NCCI PTP/MUE edits, PA/UTN-on-claim, proof-of-delivery present, signature/order on file, exclusion-list & enrollment screening, coverage code vs NCD/LCD applicability) can be checked automatically. Judgment controls (documentation sufficiency, cloned notes) can be flagged for review but not hard-passed. Kept as a pre-payment / pre-submission advisory overlay — not an inline blocking edit — preserving the no-overhaul, low-liability posture.

Intelligence — the control knowledge graph

The same controls, requirements, processes, risks, frameworks and evidence — seen as one connected graph instead of tabs. This is the Healthcare Control Intelligence layer: it answers questions a document library can't. Click one of the questions in the “Ask the graph” panel below (e.g. “which regulatory requirements have no preventive control?”), then click any node to inspect it. These are curated questions for now; free-text natural-language querying is a planned enhancement. Runs in the browser; no server, no PHI. Draft — confirm mappings against primary sources.

One connected model over data that already exists: Requirements → Controls → Process · Risk · Framework · Evidence. Ask questions a document library can't — e.g. "which regulatory requirements have no preventive control?" Runs in the browser; no server, no PHI.

Ask the graph

Type to search & highlight matching nodes, or pick a question below.

Graph — click any node for detail

Requirement Preventive Detective Corrective Lifecycle stage Business process Enforcement theme
Pick a query on the left, then click nodes to inspect the requirement, control, evidence and framework anchors.
Prototype over the HPI-CT exports (). Counts reflect the machine-readable export layer. This view proves the knowledge asset is connected and generative — Layers 1–5 and 10 are a schema-expansion and content-scaling problem, not a greenfield build. Not legal advice; not an official standard.

More intelligence

Companion analytics that live beside the graph — public data, no PHI. Opens in a new tab; the interactive version is a Power BI report published into this tab (swap the link when built).

LEIE Exclusion Intelligence →

What actually gets providers excluded (OIG List of Excluded Individuals/Entities), each cause mapped to the HPI-CT control that screens for it — plus the Power BI deployment path. Prototype; illustrative figures until the live LEIE file is bound.

Open the LEIE view →