Read this first
We'd rather tell you the truth than sound impressive.
Zeebrafish AI is in private beta. This page exists because "trust us" isn't good enough
for Medicare and Medicaid finance data, and it shouldn't be. Below is exactly what's true
today, what we're actively building, and what's still on the roadmap — no marketing gloss.
⚠️
During private beta, please upload Public Use Files or de-identified data only
We are not yet HIPAA-certified end-to-end across every vendor in our pipeline (see the
table below). Until that work is complete, do not upload files containing
patient-identifiable information — member-level PHI, MBI numbers, names paired with
dates of birth, or similar. CMS Public Use Files, synthetic test files, and de-identified
extracts are safe to use.
How analysis works today
Upload → automated pipeline → plain-English report.
Your file is uploaded through our intake form, picked up automatically, read by an AI model,
and returned as a plain-English report by email, with a logged record for audit purposes.
The honest caveat: our AI model currently reads file content directly and interprets fixed-width
positions and codes using instructions, not a hardcoded parser. For narrative summaries this is
low-risk; for exact dollar figures and codes, we're actively closing that gap — see the status
list below.
Live
Automated intake, analysis, and delivery
File upload, AI-generated plain-English analysis, email delivery, and audit logging are fully automated end to end.
Live
No default AI model training on your data
We use Anthropic's commercial API, which by contract does not use your submissions to train its models — different from consumer chat products.
In progress — this week
Deterministic parsing layer before AI narration
A hardcoded, unit-tested parser that reads fixed-width positions and code dictionaries directly from published CMS record layouts, so the AI narrates verified structured data instead of interpreting raw file positions itself. Starting with MMR and 835 files.
In progress
Signed BAAs across every vendor in the pipeline
Anthropic will sign a BAA on our plan today. Our form, automation, and logging vendors require upgrading to their compliance-tier plans first — see the table below for current status per vendor.
Planned
Automated PHI-pattern screening on upload
A lightweight scan for common PHI patterns (SSNs, MBI numbers, name+DOB pairs) as a safety net before a file is ever processed.
Planned
Migration off shared no-code infrastructure
Moving to a dedicated backend with tenant isolation and encryption at rest, ahead of onboarding customers who need to submit real PHI.
Who touches your data
Every vendor in the pipeline, and their current compliance tier.
| Vendor | Role | Current status |
| Fillout |
Intake form + temporary file storage |
HIPAA/BAA status not yet publicly confirmed — verifying directly with their team. |
| Make.com |
Automation / pipeline orchestration |
Offers a BAA on their Enterprise plan; we are not yet on that tier. |
| Anthropic (Claude) |
AI analysis |
Commercial API — no training on your data by default; BAA available at our plan tier. |
| Airtable |
Submission logging / audit record |
BAA available only on Enterprise Scale plan; we are not yet on that tier. |
| Namecheap Private Email |
Email delivery |
Standard business email hosting; compliance tier not yet evaluated. |
Zeebrafish AI produces a first-pass analyst read to accelerate your
team's review. It is not a substitute for a CMS-certified reconciliation, an audit
opinion, or legal/compliance sign-off — and it isn't a replacement for your own controls.
Questions
If you're evaluating Zeebrafish AI for your team, or doing technical or compliance diligence,
email analysis@zeebrafish.com
— happy to walk through architecture, current gaps, and our timeline in detail.