For years, healthcare organizations have used fax and mail to send the clinical documents needed to support insurance claims.
That process is beginning to change.
A new US Centers for Medicare & Medicaid Services final rule establishes the first HIPAA-adopted standards for electronic healthcare claims attachments. The rule covers supporting materials such as medical records, clinical notes, imaging, telemedicine documentation, and laboratory results. It also establishes standards for electronic signatures.
The rule took effect on May 26, 2026. Covered entities must comply by May 26, 2028. CMS estimates that replacing manual attachment processes with standardized electronic transactions will save the healthcare industry about $781 million annually.
Removing the fax machine is meaningful progress.
But digitizing a bad workflow does not automatically create a good one.
The attachment is only one part of the journey
A claims-attachment workflow begins before a document is transmitted.
Someone has to identify what information the payer needs. Another system or person must locate the correct document, confirm that it belongs to the right patient and claim, check that it contains the necessary evidence, and send it through the correct channel.
After submission, staff need to know whether the attachment was received, rejected, or considered insufficient.
The new standards make consistent electronic exchange possible. They do not, by themselves, resolve every human and operational decision surrounding that exchange.
This is where workflow design matters.
A well-designed claims-attachment product should help users answer five questions:
- What information has been requested?
- Which document satisfies that request?
- Does the document contain unnecessary or sensitive information?
- Was the attachment successfully delivered?
- What action is required if it is rejected?
Without clear answers, organizations may replace fax queues with digital work queues that are just as difficult to manage.
Where AI could help
Standardized electronic exchange creates an opportunity to use AI for narrow administrative tasks.
Potential uses include:
- Classifying incoming requests.
- Finding candidate documents in the patient record.
- Extracting relevant dates, procedures, or clinical facts.
- Detecting missing information before submission.
- Suggesting which document best matches a request.
- Summarizing why an attachment was rejected.
- Prioritizing cases that need human review.
These are possible design opportunities, not CMS requirements. The final rule establishes transaction, attachment, and electronic-signature standards. It does not require organizations to use AI.
That distinction matters.
An AI system should not silently decide that a particular document is sufficient or send a broad section of a patient record merely because it appears relevant.
The safer pattern is assisted preparation:
- The system interprets the request.
- It identifies one or more candidate documents.
- It explains why each document may be relevant.
- A qualified user reviews the selection.
- The product checks required fields and permissions.
- The user approves the final submission.
- The system records what was sent, by whom, and when.
AI reduces search and preparation time. Human approval remains visible and accountable.
Minimum necessary should shape the experience
Claims attachments can contain sensitive health information. A product that makes transmission easier must also make over-disclosure harder.
The interface should show users exactly what will be sent before approval. It should support redaction or document selection where appropriate, identify duplicate attachments, and warn when a document contains information outside the requested scope.
An audit view should preserve:
- The payer’s request.
- The claim associated with it.
- The documents considered.
- The final attachment submitted.
- The approving user.
- The electronic-signature status.
- Delivery acknowledgements.
- Corrections or resubmissions.
These are not glamorous features. They are the foundations of a trustworthy administrative workflow.
Exceptions deserve first-class design
The typical product demo shows a successful submission.
Operational teams spend much of their time dealing with everything else.
A robust attachment workflow should explicitly handle:
- No matching document found.
- Multiple plausible records.
- Patient or claim mismatches.
- Missing signatures.
- Unsupported formats.
- Failed transmissions.
- Duplicate requests.
- Requests for information that may be excessive.
- Rejections without a clear explanation.
Each exception needs an owner, a visible status, and a safe next action.
“Something went wrong” is not sufficient. The interface should explain whether the user needs to correct data, choose another document, obtain authorization, or contact the payer.
Do not confuse claims attachments with prior authorization
The final rule is limited to healthcare claims attachments.
CMS considered prior-authorization attachments during rulemaking but did not finalize standards for them in this rule, citing potential misalignment with other standards and interoperability work. CMS says it will continue evaluating alternatives. CMS final-rule fact sheet
Product teams should therefore avoid treating claims attachments and prior authorization as one interchangeable workflow.
They may share documents and interface patterns, but they have different transaction contexts, requirements, and implementation timelines.
The real opportunity
The compliance deadline may be in 2028, but organizations should use the preparation period to study the current workflow now.
Map where staff search, wait, re-enter information, switch systems, or resort to manual follow-up. Measure rejection and resubmission patterns. Test whether users can understand attachment requests without relying on institutional knowledge.
Then introduce automation at the points where it reduces friction without hiding responsibility.
The fax machine may finally be leaving healthcare claims administration.
The organizations that benefit most will not merely replace it with an electronic transmission. They will redesign the entire experience around clarity, controlled automation, privacy, and recoverable exceptions.
That is the difference between digitizing paperwork and improving healthcare operations.