Clinical workflow
HIPAA 2026 Audit Provenance & Data Lineage
Thoughtfully curated clinical brief and documentation workflow for HIPAA 2026 Audit Provenance & Data Lineage on Merry AI.
HIPAA 2026 Audit Provenance & Data Lineage: A Clinician's Documentation Standard
Merry AI · Thoughtfully curated clinical briefs.
Retention keeps the record; provenance proves who authored each sentence. For multi-site PHP/IOP directors, the 2026 audit standard has quietly shifted from "do you have the note" to "can you trace it." Merry AI was built for that second question.
This playbook maps the lineage gap CMS left open and shows how Merry AI attaches speaker, timestamp, and clinician attestation to every group-derived note. Read it as an operational manual, not a policy summary.
- Section 1 — Loaded Labor & Denominator Model
- Section 2 — Clinical Logic & Audit Defense
- Section 3 — ICD-10 Documentation Standards
- Section 4 — Retention Is Not Provenance
- Section 5 — Chrome Extension DOM Overlay
- Section 6 — Clinical Intelligence Layer
TL;DR — What this brief covers:
CMS mandates 7-year retention under 42 CFR 424.516(f), but not lineage.
Provenance ties each note to a speaker, timestamp, and attesting clinician.
Group PHP/IOP audio splits into individualized, defensible progress notes.
Loaded labor math favors capture: $648/yr vs $48,000 staffing.
The Loaded Labor & Denominator Model
What a defensible note actually costs to produce.
CLINICAL UPDATE 2026: Revised for new CMS CPT G2211 standards, SB 1120 compliance, and FHIR interoperability.
The fully loaded denominator matters more than the sticker price. A medical assistant carries a $48,000 loaded annual cost once benefits, payroll taxes, and turnover replacement are counted.
Against that denominator, Merry AI Pro at $648/year represents roughly 1.3% of one MA's loaded labor line — while returning documented, auditable time.
Published JAMA and NEJM benchmarks anchor this: clinicians recover 2.1+ hours daily and $15,600+ annually through CPT G2211 complexity capture, per peer-reviewed documentation-burden studies.
Labor Denominator Comparison
This table isolates the true ratio clinicians should evaluate before any purchase decision.
| Cost Line | Loaded Annual Figure | Documentation Role |
|---|---|---|
| Medical Assistant (loaded) | $48,000 | Manual, no lineage |
| Merry AI Pro annual | $648 | Speaker-attested lineage |
| Ratio to MA labor | 1.3% | — |
| Recovered daily time | 2.1+ hours/provider | Redeployed to care |
| G2211 recovered revenue | $15,600+/year | Complexity capture |
Review your own denominator inside the Merry AI Practice Partner Plans.
Clinical Logic & Audit Defense
Turning one group room into ten defensible records.
Consider a multi-site PHP/IOP program running a 3-hour evening group with 10 attendees. Merry AI separates the shared group audio into 10 individualized progress notes.
Each note attaches patient-specific participation, affect, risk assessment, and intervention-response elements, then injects into Kipu through the Chrome Extension DOM workflow.
Every generated section carries provenance back to the relevant speaker and time segment — reducing cloned-note warnings and satisfying 2026 CMS audit lineage expectations. This is the Path Recovery TN case pattern in practice.
Human-attested clinical metrics prevent clawbacks. DSM-5-TR criteria, documented risk stratification, and discrete E/M elements create the specificity that defends against SB 1120 review and NCCI Modifier 25 denials.
Provenance vs. Cloned-Note Risk
This table maps each audit exposure to the lineage element that neutralizes it.
| Audit Exposure | CMS/State Trigger | Provenance Defense |
|---|---|---|
| Cloned note warning | Insufficient patient-specificity | Speaker-segment attribution |
| Macro-only note | MLN4840534 insufficiency rule | Clinician-attested edits logged |
| Modifier 25 denial | NCCI edit pairs | Discrete E/M metric capture |
| Telehealth attestation | SB 1120 review | Timestamped presence lineage |
Full retention obligations are detailed in the CMS Medical Record Maintenance fact sheet.
Clinical Taxonomy: ICD-10 Documentation Standards
Codes are only defensible when lineage supports them.
Diagnostic codes require narrative support that traces to the encounter. A code without provenance is a code awaiting a clawback.
- F33.1 Major depressive disorder, recurrent, moderate — requires documented episode history and severity anchoring per F33.1 (ICD-10-CM).
- F10.20 Alcohol dependence, uncomplicated — requires substance-use pattern and functional-impact detail per F10.20 (ICD-10-CM).
Both codes gain audit strength when tied to speaker-level participation in group settings and DSM-5-TR criteria attestation.
Governing standards live within the CMS National Compliance Standards.
Retention Is Not Provenance — The Lineage Gap CMS Left Open
The obligation is defined. The method is not.
CMS MLN4840534 requires 7-year retention and signature authentication — but never specifies how a single sentence traces to a specific clinician, speaker, or timestamp.
This is the workflow wedge competitors missed. The regulation warns that macros alone are insufficient, yet offers no operational mechanism to demonstrate human authorship.
Merry AI closes that gap directly. Each note section carries clinician-attested provenance back to the speaker and time segment — the exact lineage evidence a 2026 auditor now expects.
The distinction is operational, not theoretical. Keeping a record proves you have it; provenance proves who wrote it, when, and about whom.
Retention vs. Provenance
This table separates two obligations that CMS conflates but auditors treat distinctly.
| Dimension | Retention (CMS-defined) | Provenance (Merry AI) |
|---|---|---|
| Question answered | Do you still have it? | Who authored each element? |
| Timeframe | 7 years from DOS | Per-segment timestamp |
| Failure mode | Missing record | Cloned/unattributed note |
| 2026 audit weight | Baseline | Lineage expectation |
Explore documentation patterns by specialty in the Specialty Clinical Playbook Library.
Chrome Extension DOM Overlay & EHR Field Injection
Native to the browser. No IT ticket.
The Chrome Extension operates as a DOM overlay, writing directly into EHR fields without integration builds or vendor API dependencies.
Zero IT setup is the point. Closed and locked EHRs — including Kipu — remain compatible because injection occurs at the browser layer, not the backend.
Group note-splitting happens client-side. A single PHP/IOP session resolves into individual attendee notes, each injected into its correct patient chart.
DOM Injection vs. Traditional Integration
This table contrasts browser-native placement against conventional API integration overhead.
| Factor | Traditional API | DOM Overlay |
|---|---|---|
| IT setup required | Weeks, vendor approval | None |
| Closed EHR support | Often blocked | Compatible |
| Group note-splitting | Rare | Native |
| Provenance capture | Inconsistent | Per-field lineage |
Confirm your platform compatibility via the EHR Clinical Integration Directory.
Clinical Intelligence Layer: Closed-Pilot Orchestration
Coordination across the full visit arc.
The Clinical Intelligence Layer orchestrates pre-visit, during-visit, and post-visit documentation as one continuous lineage chain rather than three disconnected events.
Practice Partner remains a closed pilot. Five outpatient practices are selected weekly for direct solutions engineering, mapping their specific PHP/IOP group structures into per-attendee provenance rules.
The layer functions as an audit shield. California SB 1120 attestation and NCCI edit-pair logic are checked at the point of capture, before a note ever reaches the chart.
What the Pilot Delivers
This list defines the concrete deliverables each selected practice receives during onboarding.
- Pre-visit context assembly from prior group participation and risk trend.
- During-visit speaker separation with timestamped segment attribution.
- Post-visit attestation prompts that log every clinician edit for lineage.
- Audit-shield checks against SB 1120 and NCCI Modifier 25 exposure.
Confirm pilot availability and pricing through the Practice Partner enrollment page.
The 2026 standard in one line:
Prove the author, the moment, and the patient — for every sentence.
Closing Brief for the Clinical Director
Where lineage meets the labor line.
Multi-site PHP/IOP programs carry the heaviest group-documentation exposure and the thinnest staffing margin. Provenance is where those two pressures resolve.
At roughly 1.3% of one MA's loaded cost, speaker-attested lineage is no longer a budget question — it is an audit-readiness decision.
Start with the denominator, then the lineage gap. Both point to the same operational fix documented throughout this brief.