The short version
- AI drafts the codes and checks payer rules. Your coder owns every case.
- Seven questions decide the vendor: inputs, integration, human review, credentials, PHI handling, denials by category, correction loop.
- The right tool with oversight cuts claim errors and protects the revenue cycle. The wrong one buys compliance exposure and rework.
- Get every answer in writing before you sign — the demo is not the contract.
- → What AI coding actually does in a dermatology practice — and what it can’t own
- → Questions 1–2: What the system reads, and how it gets your data
- → Questions 3–4: Human review on every case, and CPCD-credentialed derm coders
- → Question 5: De-identification vs. pseudonymization — where HIPAA exposure hides
- → Questions 6–7: Denial rates by code category, and the correction loop
- → The bottom line on AI coding for derm practice managers
What AI coding actually does in a dermatology practice — and what it can’t own
AI coding is being pitched as an autopilot for the billing office. It isn’t one. What the good tools actually deliver is a draft: they read the op note or encounter documentation, propose the CPT codes, ICD-10s, modifiers, and units, and check the result against the payer’s coverage rules before the claim leaves the building. Useful. Fast. Still a draft.
The finished product — coding that gets paid and survives an audit — belongs to your coder. The human is the source of truth. AI speeds the process up; it does not own it. A vendor telling you otherwise is selling you something you should not buy.
We run this model inside our own dermatology billing operation: eyes on every coded case, no exceptions. The tool proposes. The coder disposes.
Questions 1–2: What the system reads, and how it gets your data
Number one: what does your system actually read? Make them name the inputs — op reports, SOAP notes, problem lists, structured EMR fields. That answer tells you how hard the tool leans on your documentation quality and where your prep work starts. A system that only reads structured fields misses the excision depth your provider dictated in free text. Missed depth, wrong code, denied claim.
Number two: how does the system get our data? The integration matters as much as the algorithm. API into the EMR, manual file exports, or embedded in your PM platform — three very different amounts of friction. Generally speaking, the cleaner the integration, the fewer documentation gaps break the output. Manual exports mean a staffer is now part of the algorithm. Budget for that.
Get both answers before anyone shows you an accuracy number. Their accuracy was measured on their documentation. Not yours.
Questions 3–4: Human review on every case, and CPCD-credentialed derm coders
Number three: is a human coder required on every case? Binary. If claims can route to the payer without a coder’s eyes, walk away. Ask for the workflow diagram, not the pitch deck — the pitch deck has never had a claim denied.
Number four: who maintains the coding logic, and what are their credentials? You want CPCD-certified coders (the credential AAPC issues specifically for derm coders) with real payer policy scar tissue, plus a stated cadence for updating the logic as CPT changes. Derm coding turns over every January. A model maintained by generalists is guessing at this year’s modifiers with last year’s rules.
Get the credentials and the update cadence in writing. Vague answers here predict vague codes later.
Question 5: De-identification vs. pseudonymization — where HIPAA exposure hides
Number five: how are you handling PHI — and is it actually de-identified? Ask whether patient data is truly de-identified before it reaches the model — ideally a narrow language model (NLM) built for coding, not a general-purpose LLM — or whether the vendor is leaning on pseudonymization: swapping identifiers for codes that re-link to the original patient.
Pseudonymization is not HIPAA de-identification. If the record can be re-linked, it’s PHI with a costume on. HHS recognizes two paths — Safe Harbor (strip the 18 identifier types) or Expert Determination — and re-linkable masking is neither. The HHS de-identification guidance is the standard a breach investigation measures you against, and “the vendor said it was fine” is not a defense that has ever worked.
Put the question in writing. Require the answer in writing. If the compliance story lives only in a sales call, so does your defense.
Questions 6–7: Denial rates by code category, and the correction loop
Number six: what’s your denial rate by code category? A blended number tells you nothing — a 95% clean claim rate means a 5% denial rate, and the only question that matters is which codes live in the 5%. Make them break it out: E&M, surgical, cosmetic vs. medical, biopsies, excisions. Derm’s mix is its own animal. A tool tuned on primary care will not hold up on yours.
Number seven: what happens when the AI gets it wrong? Every system misses; the correction loop is what separates tools from liabilities. How are errors flagged. How fast do they resolve. Does your coder’s feedback train future output. A vendor with a real loop earns a second conversation. A vendor whose answer is “the AI just learns” has answered a different question than the one you asked.
Score both answers against your own denial data before you sign. Your revenue cycle already knows which categories bleed.
The bottom line on AI coding for derm practice managers
AI coding is not going away. The practices that vet it now beat the ones that ignore it — and the ones that adopt it blind. Right tool plus oversight: fewer claim errors, faster coders, a protected revenue cycle. Wrong tool: compliance exposure, rework, and denials that cost more to fix than they would have cost to prevent.
This framework first ran as our guest article in ADAM’s Executive Decisions in Dermatology, Summer 2026 issue (pp. 44–45) — written for the administrators sitting through these pitches every week.
Ask the questions. Require the answers. And never let any system — AI or otherwise — pull human expertise out of the center of your coding process.
Frequently asked questions
What does AI medical coding software actually do?
AI medical coding software reads clinical documentation (operative reports, SOAP notes, encounter data) and drafts proposed coding — CPT codes, ICD-10 diagnoses, modifiers, and units — then checks that proposed coding against the payer’s coverage and reimbursement rules before claim submission. In a compliant workflow it functions as an assist layer for credentialed coders, who review and own every coded case; it does not replace them.
Does AI coding replace medical coders?
No. In a compliant workflow, a human coder reviews every case before the claim routes to the payer. AI coding tools expedite code proposal and payer-rule checking, but the credentialed coder remains the source of truth. Any vendor workflow that allows claims to reach a payer without human review is a compliance and revenue risk.
What is the difference between de-identification and pseudonymization under HIPAA?
De-identification under HIPAA removes identifying information so data cannot be traced back to a patient, using either the Safe Harbor method (removal of 18 identifier types) or Expert Determination. Pseudonymization replaces identifiers with codes that can be re-linked to the original patient — it is reversible, and it is not HIPAA-compliant de-identification. AI coding vendors should process truly de-identified data, not re-linkable masked data.
What is the CPCD certification?
The CPCD (Certified Professional Coder in Dermatology) is a specialty coding credential issued by AAPC specifically for dermatology coders. It validates expertise in dermatology CPT and ICD-10 coding, including biopsies, excisions, destructions, Mohs surgery, and dermatology-specific modifier use. Vendors building AI coding logic for dermatology should have CPCD-certified coders maintaining that logic.
What questions should I ask an AI medical coding vendor?
Seven questions: (1) What data does the system actually read? (2) How does it integrate with our EMR? (3) Is a human coder required to review every case? (4) What are your team’s coding credentials and specialty training? (5) Is patient data truly de-identified — not just pseudonymized — before it reaches the model? (6) What is your denial rate broken down by code category? (7) What is the error-correction loop when the AI gets it wrong?
Not sure where your revenue cycle stands?
If your clean claim rate or days in AR aren’t where they should be, that’s a conversation worth having. We’ll look at your numbers and tell you straight.
This article explains how these codes tend to get paid — it is not coding, billing, or legal advice. Some of the codes here are bundled into the main procedure, or fall into grey areas that vary by payer. Before billing anything in a grey area, confirm it with your own coding and compliance team and the current guidance from your specialty society, Medicare (CMS), and AMA CPT. When in doubt, don’t bill it.