Zeebrafish
AI
← Back to home
Trust & data handling
Where we actually stand today — not the polished version.
Read this first
We'd rather tell you the truth than sound impressive.

Zeebrafish AI is in private beta. This page exists because "trust us" isn't good enough for Medicare and Medicaid finance data, and it shouldn't be. Below is exactly what's true today, what we're actively building, and what's still on the roadmap — no marketing gloss.

⚠️
During private beta, please upload Public Use Files or de-identified data only
We are not yet HIPAA-certified end-to-end across every vendor in our pipeline (see the table below). Until that work is complete, do not upload files containing patient-identifiable information — member-level PHI, MBI numbers, names paired with dates of birth, or similar. CMS Public Use Files, synthetic test files, and de-identified extracts are safe to use.

How analysis works today
Upload → automated pipeline → plain-English report.

Your file is uploaded through our intake form, picked up automatically, read by an AI model, and returned as a plain-English report by email, with a logged record for audit purposes. The honest caveat: our AI model currently reads file content directly and interprets fixed-width positions and codes using instructions, not a hardcoded parser. For narrative summaries this is low-risk; for exact dollar figures and codes, we're actively closing that gap — see the status list below.

Live
Automated intake, analysis, and delivery
File upload, AI-generated plain-English analysis, email delivery, and audit logging are fully automated end to end.
Live
No default AI model training on your data
We use Anthropic's commercial API, which by contract does not use your submissions to train its models — different from consumer chat products.
In progress — this week
Deterministic parsing layer before AI narration
A hardcoded, unit-tested parser that reads fixed-width positions and code dictionaries directly from published CMS record layouts, so the AI narrates verified structured data instead of interpreting raw file positions itself. Starting with MMR and 835 files.
In progress
Signed BAAs across every vendor in the pipeline
Anthropic will sign a BAA on our plan today. Our form, automation, and logging vendors require upgrading to their compliance-tier plans first — see the table below for current status per vendor.
Planned
Automated PHI-pattern screening on upload
A lightweight scan for common PHI patterns (SSNs, MBI numbers, name+DOB pairs) as a safety net before a file is ever processed.
Planned
Migration off shared no-code infrastructure
Moving to a dedicated backend with tenant isolation and encryption at rest, ahead of onboarding customers who need to submit real PHI.

Who touches your data
Every vendor in the pipeline, and their current compliance tier.
VendorRoleCurrent status
Fillout Intake form + temporary file storage HIPAA/BAA status not yet publicly confirmed — verifying directly with their team.
Make.com Automation / pipeline orchestration Offers a BAA on their Enterprise plan; we are not yet on that tier.
Anthropic (Claude) AI analysis Commercial API — no training on your data by default; BAA available at our plan tier.
Airtable Submission logging / audit record BAA available only on Enterprise Scale plan; we are not yet on that tier.
Namecheap Private Email Email delivery Standard business email hosting; compliance tier not yet evaluated.

Zeebrafish AI produces a first-pass analyst read to accelerate your team's review. It is not a substitute for a CMS-certified reconciliation, an audit opinion, or legal/compliance sign-off — and it isn't a replacement for your own controls.

Questions

If you're evaluating Zeebrafish AI for your team, or doing technical or compliance diligence, email analysis@zeebrafish.com — happy to walk through architecture, current gaps, and our timeline in detail.