Posted on
May 14, 2026
Scribing.io vs. Nabla: Clinical Depth & Technical Security Audit for Compliance Officers
Scribing.io vs. Nabla: Clinical Depth & Technical Security Audit — The 2026 Operations Playbook for CMIOs
What Entry-Level AI Scribes Miss: The Billing-Grade Documentation Gap Payers Actually Audit
Scribing.io Clinical Logic: Handling COPD Exacerbation with Same-Day Nebulizer — Before and After
The Pertinent-Negative Gap: Why "Clean Summaries" Fail Denial Defense
Technical Reference: ICD-10 Documentation Standards for High-Audit Diagnoses
Security Architecture Comparison: PHI Flow, Encryption, and Audit Trails
AMA 2026 Transparency Mandates: A CMIO's Compliance Checklist
Book a 15-Minute Workflow Audit
What Entry-Level AI Scribes Miss: The Billing-Grade Documentation Gap Payers Actually Audit
The AMA's June 2026 Annual Meeting report warns of "opaque model reasoning" and "confabulations in generative models" used in clinical documentation. That language is diplomatic. For CMIOs managing revenue integrity across a multi-specialty organization, the operational translation is blunt: an AI scribe that summarizes a visit without capturing denial-defense documentation is a revenue liability, not a productivity tool.
Scribing.io exists because this distinction—between a readable summary and a reimbursement-defensible note—is the fault line where organizations hemorrhage revenue. Every ambient AI vendor markets time savings. Almost none of them address the documentation elements that payers algorithmically audit on 99214 claims, modifier 25 same-day procedure encounters, and the increasingly scrutinized G2211 add-on code. Scribing.io's specialty-tuned reasoning engine was built to close exactly this gap, and the architecture differs fundamentally from the entry-level summarization models that competitors—including Nabla—deploy.
Here is the specific failure chain that entry-level summarizers introduce when they "glaze over" high-acuity clinical detail:
Documentation Elements Audited for E/M Level 4 (99214) and Modifier 25 Claims | |||
Required Element | What Payers Audit For | Entry-Level Scribe Output (Nabla-Class) | Scribing.io Output |
|---|---|---|---|
Pertinent Negatives in ROS | Explicit denial of related symptoms (e.g., dyspnea: no fever, no chest pain, no hemoptysis) to evidence problem complexity under the 2023+ E/M MDM table | Omitted or generalized ("ROS otherwise negative") | Discrete ROS- section with symptom-specific denials, timestamped to encounter |
Data Reviewed / Ordered | Documentation of independent interpretation or review of prior results (PFTs, labs, imaging) that informed clinical reasoning | Occasionally mentioned in narrative; rarely structured | Structured "Data Review" block citing specific prior results with date references |
MDM Justification | Explicit linkage between number/complexity of problems, data reviewed, and risk of management to justify MDM level | Implied within assessment/plan; not auditor-parseable | Discrete MDM-Justification section mapping to AMA MDM table columns |
Separate E/M for Modifier 25 | Separately identifiable History, Exam, and MDM distinct from the minor procedure performed per CMS NCCI guidelines | Not generated; evaluation and procedure blended into one narrative | Auto-prompted "Separate E/M Justification" section when CPT minor procedure detected |
G2211 Longitudinal Complexity | Verbiage establishing ongoing relationship with complexity-driving chronic condition per CMS PFS final rule | Not surfaced | Auto-flagged with compliant longitudinal verbiage when qualifying condition is addressed |
The 2023+ E/M framework eliminated history and exam "bean counting" in favor of Medical Decision Making (MDM) as the dominant element. This should have simplified documentation—but it actually raised the bar for what gets documented. Payers now focus their audit lens on whether the note demonstrates the complexity of problems addressed through pertinent negatives, data interpretation, and explicit risk articulation. A clean narrative summary that reads well to a clinician but lacks these discrete, auditor-readable elements is the precise vulnerability that drives downcodes and modifier denials.
For organizations running Epic, this gap is compounded by how structured data flows between the ambient scribe and the EHR. Entry-level tools often drop documentation into a single free-text block that bypasses Epic's discrete data fields entirely—making CDI queries and quality measure extraction unreliable. Scribing.io's Epic Integration maps each documentation section (ROS-, Exam, MDM-Justification, Separate E/M Justification) to discrete Epic SmartData elements, ensuring downstream CDI, quality reporting, and audit workflows consume structured data rather than parsing free text.
Competitors who position their AI scribes as "time-saving summarizers" miss the point. The clinical note is not merely a record of what happened—it is the legal and financial instrument that justifies reimbursement. Scribing.io treats it as such.
Scribing.io Clinical Logic: Handling COPD Exacerbation with Same-Day Nebulizer — Before and After
This scenario represents the single most common pattern of revenue leakage in family medicine and pulmonology practices using entry-level AI scribes. It is the centerpiece of every Scribing.io clinical demo because it exposes every documentation gap in one visit.
Before: Entry-Level AI Scribe (Nabla-Class Summarizer)
A family medicine clinic uses an entry-level ambient scribe for a same-day visit. The patient is a 64-year-old male with COPD on triple therapy (ICS/LABA/LAMA) presenting with worsening dyspnea over three days. The clinician performs an evaluation, decides to escalate the inhaler regimen, and administers a nebulizer treatment (CPT 94640) in-office.
The AI-generated note:
"Patient presents with shortness of breath. History of COPD on triple therapy. Lungs with diffuse wheezing bilaterally. Nebulizer treatment administered with improvement. Plan: step up to Breztri, follow up in 2 weeks, return if worsening."
This note is clinically accurate as a summary. It is also indefensible under audit:
No negative ROS: No documentation of absent fever, absent chest pain, absent hemoptysis, absent lower extremity edema—symptoms whose absence distinguishes a moderate exacerbation from a life-threatening presentation and justifies problem complexity.
No data review: The clinician reviewed prior PFTs from 8 months ago and noted declining FEV1 trend; she checked today's pulse-ox at 91% on room air and compared it to a baseline of 95%. None of this appears in the note.
No separate MDM for the evaluation vs. the procedure: The E/M service (evaluation leading to inhaler escalation) and the nebulizer treatment (94640) are blended into one paragraph. A payer auditor sees no separately identifiable evaluation.
No G2211 context: This patient has been managed longitudinally for COPD with escalating complexity, but the note provides no verbiage establishing that relationship.
Result: The payer downcodes from 99214 to 99213 (losing approximately $40–$55 per visit depending on payer mix) and denies modifier 25 on the nebulizer (losing approximately $93–$105). Total loss on this single visit: ~$148. The clinic experiences 19 similar denials in a single month across its COPD, diabetes, and CKD patient panels. Cumulative 30-day loss: $2,800–$4,500.
After: Scribing.io Specialty-Tuned Reasoning Engine
The same visit, same clinician, same conversation. Scribing.io's ambient listener processes the encounter through its specialty-tuned clinical reasoning model. Here is the output, section by section, with the clinical logic that generated each element.
Step 1 — Discrete ROS- Section:
ROS Pertinent Negatives: Denies fever/chills. Denies chest pain. Denies hemoptysis. Denies lower extremity edema. Denies orthopnea. Denies diaphoresis. Denies recent travel or immobilization.
Logic: The engine detects "dyspnea" + "COPD" + "exacerbation" and activates a pulmonary-specific pertinent negative map. It listens for explicit denials in the conversation and, critically, surfaces the absence of high-risk red-flag symptoms that the clinician addressed verbally but that a summarizer would compress into silence. Each negative is output on a discrete line—not buried in narrative—so that a payer auditor or algorithmic claim scrubber can parse it without interpretation.
Step 2 — Discrete Exam with Quantitative Data:
Lungs: Diffuse expiratory wheezing bilaterally, no crackles, no rhonchi. No accessory muscle use. SpO2 91% on room air (baseline 95% per 11/2025 visit). No cyanosis.
Logic: The engine pulls baseline vital signs from the EHR integration layer (see EHR Compatibility for supported data pull configurations) and juxtaposes them against today's values. This delta—95% → 91%—is the quantitative evidence that transforms "shortness of breath" from a subjective complaint into a documented physiologic deterioration, supporting higher problem complexity in MDM.
Step 3 — Discrete Data Review Section:
Reviewed PFTs from 10/2025: FEV1 52% predicted (down from 61% in 03/2025). Reviewed pulse oximetry trend: 95% (11/2025) → 93% (02/2026) → 91% (today). CXR from 01/2026 reviewed: hyperinflation, no infiltrate, no effusion.
Logic: Under the AMA MDM data table, each independent interpretation of prior external data counts as a Category 1 data point. Scribing.io's reasoning engine identifies prior test results referenced during the encounter and outputs them with dates and values—structured for both clinical utility and audit defense. Entry-level summarizers either omit these entirely or mention them in passing within the assessment, where they are invisible to audit algorithms.
Step 4 — MDM-Justification Section:
MDM Level: Moderate (99214). Problems addressed: 1 chronic illness with severe exacerbation (COPD exacerbation, J44.1)—meets "chronic illness with severe exacerbation" threshold. Data: Independent review of prior PFTs and pulse-ox trend (Category 1 data point); review of prior external CXR (Category 1 data point). Risk: Prescription drug management—escalation from current triple therapy to Breztri Aerosphere with assessment of drug-drug interaction risk.
Logic: This section maps directly to the three MDM columns defined in the CMS E/M documentation guidelines: (1) number and complexity of problems, (2) amount and/or complexity of data, (3) risk of complications. The engine cross-references the documented pertinent negatives and data points to auto-populate this mapping. A payer auditor can verify the 99214 level in under 30 seconds—compared to the 3–5 minute interpretive exercise required when MDM is implied within a narrative.
Step 5 — Separate E/M Justification Section (Modifier 25):
The evaluation and management service today is separately identifiable from CPT 94640 (nebulizer treatment). The E/M decision—to escalate the long-term inhaler regimen based on declining PFT trend and worsening oxygenation—is clinically distinct from the therapeutic nebulizer administered for acute symptom relief. The E/M involved independent data review, risk assessment for medication change, and longitudinal care planning that would have occurred regardless of whether the nebulizer was administered.
Logic: When the engine detects a minor procedure CPT code (94640, 17000-series, 11100-series, etc.) co-occurring with an E/M service, it auto-generates this section. The key phrase—"would have occurred regardless of whether the [procedure] was administered"—is the audit-defense standard articulated in CMS NCCI policy. No entry-level summarizer produces this because it requires counterfactual clinical reasoning: understanding what the visit would have looked like without the procedure. This is not summarization. It is inference.
Step 6 — G2211 Flag with Compliant Verbiage:
G2211 applicable: This visit addresses COPD (J44.1), a condition for which this physician provides ongoing, longitudinal management. The medical decision-making today accounts for the inherent complexity of a chronic condition with progressive decline requiring iterative therapy escalation, consistent with the requirements of G2211.
Logic: G2211 is valid only when the visit involves "an ongoing relationship with complexity-driving chronic conditions." The engine checks the patient's problem list for qualifying chronic conditions, confirms the visit addresses one of them substantively (not incidentally), and outputs the required longitudinal verbiage. This add-on code was first payable in January 2024, and CMS has increased audit scrutiny each year since—making auto-compliant documentation essential rather than optional.
Outcome: 99214 paid at first submission. Modifier 25 on 94640 paid. G2211 add-on paid. The clinic's RCM team used Scribing.io's timestamped, auditor-ready rationale to appeal the 19 prior denials from the entry-level scribe period—without exposing raw audio. Result: $4,300 recovered in 30 days. 70% reduction in post-visit note edits. Zero compliance flags on subsequent payer audits.
The Pertinent-Negative Gap: Why "Clean Summaries" Fail Denial Defense and How Specialty-Tuned Reasoning Solves It
The AMA's 2026 report calls for "transparency and explainability" in AI clinical tools. What the report does not address—and what no competitor documentation framework currently solves—is the specific downstream revenue consequence of AI-generated notes that omit pertinent negatives.
This is the core anchor truth: Nabla's entry-level models, and ambient scribes architecturally similar to them, produce notes that "glaze over" high-acuity details because their summarization models are optimized for narrative coherence, not for the discrete evidentiary elements that payers require.
A pertinent negative is not a nice-to-have. Under the 2023+ E/M MDM table, the number and complexity of problems addressed is determined partly by the clinician's documented differential reasoning. When a patient presents with dyspnea and the clinician documents that the patient denies chest pain, denies hemoptysis, and denies lower extremity edema, those negatives accomplish two things simultaneously:
Clinically, they narrow the differential and evidence the clinician's cognitive work—consistent with what JAMA's 2023 analysis of documentation quality metrics identifies as markers of diagnostic rigor.
For reimbursement, they demonstrate that the problem addressed is more complex than a straightforward presentation—supporting a "moderate" or "high" complexity MDM determination.
When an AI scribe omits these negatives because its model is trained to produce concise, readable summaries, the note implicitly downgrades the documented complexity of the visit. The payer auditor—human or algorithmic—sees a straightforward presentation and applies a lower MDM level. This is not a theoretical concern; it is the mechanism behind the CERT program's finding that insufficient documentation remains the leading cause of improper E/M payments.
Scribing.io's approach is architecturally different. The reasoning engine maintains a specialty-specific negative symptom map for high-audit chief complaints. When the ambient listener detects "dyspnea" in a COPD patient, it activates a pulmonary-specific pertinent negative checklist and listens for—or flags for the clinician to address—the denial of related symptoms. These are output in a discrete ROS- section that is:
Auditor-readable: Separate from the narrative, with each negative on its own line
Timestamped: Linked to the encounter timestamp so RCM can reference it in denial appeals without exposing raw audio—a critical distinction given HIPAA minimum necessary requirements
MDM-mapped: Automatically cross-referenced to the MDM justification section so the auditor can trace the logic from symptom denial → problem complexity → MDM level
This documentation architecture is what separates a scribe that saves time from a scribe that protects revenue. The AMA's 2026 policy advocates for transparency in AI decision support; Scribing.io delivers transparency in AI documentation output, which is the layer where revenue integrity is won or lost.
Technical Reference: ICD-10 Documentation Standards for High-Audit Diagnoses
CMIOs responsible for clinical documentation integrity (CDI) need their AI scribe to generate notes that support ICD-10 specificity at the point of care—not downstream through CDI queries that add days to the revenue cycle. The following high-audit diagnoses require documentation elements that entry-level summarizers routinely omit.
ICD-10 Documentation Requirements for High-Audit Codes | |||
ICD-10 Code | Required Documentation Specificity | Common Entry-Level Scribe Failure | Scribing.io Capture Method |
|---|---|---|---|
J44.1 requires explicit documentation of "exacerbation" (not just "worsening symptoms") and distinction from J44.0 (with acute lower respiratory infection). E11.65 requires concurrent hyperglycemia documentation with a glucose value or A1c exceeding target. N18.31 requires staging (stage 3a) with eGFR documentation. | Notes state "COPD flare" without the word "exacerbation"; diabetes documented as "uncontrolled" without specifying hyperglycemia vs. other manifestation; CKD staged as "stage 3" without substage differentiation. | Specialty terminology mapping converts clinician vernacular ("COPD flare," "sugars are high") to code-specific language. The engine auto-appends staging data from EHR lab results and flags when documentation lacks the specificity needed for code assignment. | |
R06.02 is a symptom code that should be used as the primary code only when no underlying etiology is established. When COPD is confirmed, J44.1 should be primary and R06.02 should be secondary or omitted. Documentation must clearly indicate whether dyspnea is a symptom of the established condition or a separate finding. | Entry-level scribes often list R06.02 as the primary assessment code because "shortness of breath" appears in the chief complaint, while burying the COPD exacerbation context in the narrative—leading to claim rejections for insufficient specificity or inappropriate primary diagnosis assignment. | Scribing.io's ICD-10 reasoning layer distinguishes symptom codes from etiology codes and suggests primary/secondary ordering based on the documented clinical context. When J44.1 is supported by the note content, it is surfaced as the primary code candidate with R06.02 repositioned as a secondary symptom code or excluded per CMS ICD-10 coding guidelines (Chapter-specific guideline I.A.13: codes that describe symptoms integral to the confirmed diagnosis should not be additionally coded). |
The pattern across all three high-audit diagnoses is identical: entry-level summarizers reproduce clinician vernacular, while payer auditors and coding algorithms require code-specific terminology. A clinician says "COPD flare"; the coder needs "COPD with acute exacerbation." A clinician says "kidney function is down"; the coder needs "CKD stage 3a, eGFR 48." A clinician says "sugars are high"; the coder needs "type 2 diabetes with hyperglycemia, fasting glucose 247."
Scribing.io's terminology mapping layer performs this translation in real time, during the encounter, so the note arrives in the EHR already coded to maximum specificity. This eliminates the CDI query loop—which, according to ACDIS benchmarks, averages 2.3 days from query to physician response—and accelerates the revenue cycle by ensuring first-pass claim accuracy.
Security Architecture Comparison: PHI Flow, Encryption, and Audit Trails
Clinical depth is irrelevant if the ambient AI platform cannot pass a CMIO's security review. The 2026 landscape demands more than a signed BAA and a checkbox for "HIPAA compliant." CMIOs need to trace every byte of PHI from the microphone to the EHR and verify that the platform's architecture does not introduce unacceptable risk.
Security Architecture: Scribing.io vs. Entry-Level Ambient Scribe Platforms | ||
Security Dimension | Entry-Level Platform (Nabla-Class) | Scribing.io |
|---|---|---|
Audio Processing Location | Cloud-based; audio transmitted to third-party LLM provider for transcription and summarization | On-device preprocessing with encrypted payload to Scribing.io's dedicated HIPAA-compliant inference cluster; no raw audio persists post-processing |
Encryption in Transit | TLS 1.2/1.3 (standard) | TLS 1.3 with certificate pinning; mTLS for EHR API connections |
Encryption at Rest | AES-256 (standard) | AES-256 with customer-managed encryption keys (CMEK) option for enterprise deployments |
Audio Retention Policy | Variable; some platforms retain audio for model training unless explicitly opted out | Zero audio retention post-transcription. Configurable ephemeral processing with cryptographic deletion verification |
Audit Trail Granularity | Login/logout events; document creation timestamps | Full PHI access log: who accessed what data element, when, from which device, with what clinical justification. Exportable to SIEM (Splunk, Sentinel) via syslog or API |
Third-Party LLM Dependency | Relies on OpenAI, Anthropic, or Google APIs for core inference—introducing a sub-processor with independent data handling policies | Proprietary inference stack. No PHI leaves Scribing.io's infrastructure boundary. No third-party LLM sub-processor in the PHI data path |
SOC 2 Type II | Varies by vendor; some hold Type I only | SOC 2 Type II certified with annual re-attestation; report available under NDA |
The third-party LLM sub-processor issue deserves specific attention. When an ambient scribe platform sends audio or transcript data to OpenAI's API or a comparable service for inference, it introduces a sub-processor whose data handling policies are governed by a separate agreement that the healthcare organization does not directly control. The HHS guidance on cloud computing and HIPAA requires that all entities handling PHI be covered by a BAA—but the practical enforceability of a BAA with a general-purpose LLM provider processing millions of non-healthcare requests on shared infrastructure remains an open compliance question that most CMIOs prefer not to test in front of OCR.
Scribing.io eliminates this risk vector by running its entire inference stack—transcription, clinical reasoning, section generation, ICD-10 mapping—within its own HIPAA-compliant infrastructure. No PHI crosses to a third-party LLM. This architectural decision costs more to build and operate, but it produces an audit trail that a CMIO can present to their compliance officer, their board, and OCR with complete confidence.
AMA 2026 Transparency Mandates: A CMIO's Compliance Checklist
The AMA's 2026 Annual Meeting codified several policy positions on AI in clinical documentation that, while not yet regulatory mandates, signal the direction of future CMS rulemaking and commercial payer requirements. CMIOs should treat these as pre-regulatory compliance targets. Here is each position reframed as an operational checklist item:
AMA 2026 AI Transparency Positions: Operational Compliance Checklist | |||
AMA Position | Operational Requirement | Entry-Level Scribe Compliance | Scribing.io Compliance |
|---|---|---|---|
"AI tools must provide transparent and explainable outputs" | Each AI-generated documentation section must be traceable to specific encounter data (audio segment, EHR data pull, or clinician input) | Output is a monolithic summary with no traceability to source | Each section tagged with source attribution: "from encounter audio [timestamp]" or "from EHR data pull [field, date]" |
"Clinicians must retain authority to review and modify AI outputs" | AI-generated notes must be presented as editable drafts with clear delineation of AI-generated vs. clinician-authored content | Draft presented for signature; AI-generated content not visually distinguished from clinician edits | AI-generated sections marked with visual indicator; clinician edits tracked as separate audit trail entries; final note reflects both layers |
"AI systems should not introduce confabulations into clinical records" | Platform must have hallucination detection/prevention mechanisms with measurable accuracy metrics | No published confabulation rate or detection mechanism | Clinical assertion verification against EHR problem list, medication list, and lab results. Flagged discrepancies require clinician confirmation before note finalization. Published confabulation detection accuracy available under NDA |
"Data used by AI tools must be protected consistent with HIPAA" | Full PHI data flow documentation, no third-party sub-processors outside BAA coverage, audio retention policies compliant with minimum necessary | Variable compliance; third-party LLM sub-processor introduces risk | Full compliance; see Security Architecture section above |
These positions align with the broader regulatory trajectory visible in ONC's Health IT regulatory framework and the White House Blueprint for an AI Bill of Rights. CMIOs who select ambient AI platforms meeting these requirements today avoid the migration cost—and the documentation gap exposure—of switching platforms when compliance becomes mandatory.
Book a 15-Minute Workflow Audit: Quantify Your Documentation Gap
Reading this playbook identified the problem. The next step is quantifying it for your specific practice or health system.
Book a 15-minute Workflow Audit and we'll run a side-by-side on your last 10 Level 4 + procedure encounters:
Identify where negative ROS and Separate E/M Justification would have prevented downcodes and modifier 25 denials
Generate a payer-ready Denial Defense Bundle using Scribing.io's auditor-ready rationale format
Produce a security trace (PHI flow, encryption, audit logs) mapped to your EHR
Zero commitment. BAA-backed sandbox. Results in 72 hours.
→ Schedule your Workflow Audit at Scribing.io
If you are currently evaluating Nabla or a similar entry-level ambient scribe, request this audit before signing. The $4,300 in 30-day recovery demonstrated in the COPD scenario above is the conservative end of what multi-provider practices recover when they switch from summarization to specialty-tuned clinical reasoning. Your last 10 L4 encounters will tell you exactly where you stand.



