AWS Public Sector Blog

Category: Security, Identity, & Compliance

Fewer than 5 percent of radiologists review their own billing codes, compared to roughly 90 percent of primary care physicians. That gap has consequences: Over the past decade, it has contributed to nearly 50 percent reimbursement losses in radiology. In radiology, radiologists' adjacent personnel must translate every image read into standardized International Classification of Diseases, 10th Revision (ICD-10) codes that drive billing, follow-ups, and quality reporting. When those codes are unverified or poorly documented, the results are billing delays, claim denials, and delayed patient care. The University of Miami Health System (UHealth) partnered with AWS and AWS Partner Quantiphi to build a generative AI coding solution on Amazon Bedrock called Hurricode. The solution puts radiologists back in the loop, achieving approximately 92 percent coding accuracy, projecting a 34 percent revenue increase, and reducing manual effort by roughly 40 percent. The University of Miami Leonard M. Miller School of Medicine is Florida's first medical school and home to the Sylvester Comprehensive Cancer Center, the highest-ranked cancer center in Florida for cancer care in 2026. The Department of Radiology performs over 1 million procedures annually across eight specialized divisions. Quantiphi is an AWS Premier Tier Services Partner and AWS 2025 Public Sector Global Generative AI Consulting Partner of the Year. When manual coding can't keep up The UHealth radiology team faced a set of interconnected problems. The sheer volume of manual reporting fueled clinician fatigue. The department's legacy natural language processing (NLP) coding tool reached only 58–77 percent accuracy. It lacked the precision, scalability, and speed that modern diagnostic workflows demand, producing inconsistent ICD-10 code mapping and driving medical necessity denials. A lack of transparency compounded the inconsistency. The team needed defensible code identification in the form of clear, understandable rationales behind every ICD-10 prediction. Without it, clinicians couldn't trust or validate the output, and the department couldn't meet its compliance and audit requirements. UHealth serves a complex oncologic and tertiary care population where actionable incidental findings (AIFs) such as lung nodules, pulmonary emboli, and fractures demand timely follow-up. This makes accurate, well-documented coding a patient safety issue as much as a financial one. Building a radiologist-in-the-loop workflow on AWS To solve these challenges, UHealth and Quantiphi designed a solution with radiologists, studying their exact workflow to understand where AI could reduce friction without disrupting clinical judgment. The result is Hurricode, a generative AI–powered coding assistant built on Amazon Bedrock. Hurricode uses Amazon Bedrock to generate ICD-10 code suggestions with associated reasoning from transcribed radiology reports. Radiologists review and confirm the codes through a custom interface, a self-attestation process that takes less than 30 seconds per study. This radiologist-in-the-loop approach maintains clinical-grade accuracy while reducing manual effort by approximately 40 percent. The solution also accelerates upstream insurer verification (pre-authorization) for recommended further imaging, which occurs in 11–27 percent of advanced imaging studies. By surfacing accurate, well-documented codes earlier in the workflow, Hurricode helps streamline the pre-authorization process. The project began with a strategic assessment, roadmap, and proof of concept (PoC). The pipeline ingests, pre-processes, and passes radiology reports and the ICD-10 code directory to a fine-tuned model. Hurricode is the first solution to flag pertinent negative findings (PNFs)—conditions that have been ruled out, such as bleeds or fractures—improving documentation quality and supporting more complete clinical records. Future plans include surfacing AIFs for tracking, scheduling, and pre-authorization through the University of Miami No Findings Left Behind™ provenance network. Figure 1: ICD-10 Coding Automation Workflow for Radiology Reports How the solution comes together on AWS The following AWS services power the Hurricode solution: Amazon Bedrock — Foundation models including Amazon Titan Text Embeddings and Anthropic Claude for phrase extraction, code generation, and AIF identification Amazon SageMaker — Development and fine-tuning of the embedding model Amazon OpenSearch Service — Stores vectors for semantic search AWS Lambda — Orchestrates data ingestion and RAG (Retrieval Augmented Generation) pipeline Amazon EC2 — Additional compute Amazon S3 — Stores raw inputs, processed text, and web assets Amazon DynamoDB and Amazon RDS — Manage application and structured metadata Amazon CloudFront and Amazon Cognito — Deliver web application more securely, integrated with University of Miami single sign-on Figure 2: AWS Cloud Architecture for AI-Powered Medical Coding System Clinical-grade results at scale Hurricode has delivered measurable improvements across coding accuracy, operational efficiency, and clinical documentation: Approximately 92 percent coding accuracy, up from 58–77 percent Approximately 40 percent reduction in manual effort Radiologists spend less than 30 seconds per advanced imaging study Projected approximately 34 percent revenue increase through optimized revenue cycle management and advanced authorization Additional upside from CMS Quality Payment Program quality metrics Physician attestation improves documentation of PNFs in more than 50 percent of patients Projected 10–25 percent uplift in AIF follow-up through the No Findings Left Behind initiative Aims to reduce findings lost to follow-up from the industry norm of 20–40 percent to under 5 percent Strengthens metrics including length of stay, risk adjustment factor (RAF), and hierarchical condition category (HCC) reporting Scalable beyond 1 million advanced imaging reports (CT, MRI, PET) per year "The first-of-its-kind solution we developed with Quantiphi at the University of Miami, Hurricode, will particularly improve quality and safety, identify actionable findings in at-risk patients, and enable other proactive measures that we feel will profoundly contribute to the rapidly expanding field of preventive radiology." — Dr. Alexander M. McKinney, chair of the Department of Radiology at the University of Miami Figure 3: Hurricode AI Platform: Intelligent Radiology Findings and Clinical Integration Hub What's next In the next phase, UHealth plans to automate the transfer of key EHR data into required documentation for more timely and compliant processes. The team also plans to expand Hurricode beyond radiology into pathology, interventional neurosurgery, and cardiology. To explore how generative AI on Amazon Bedrock can transform your organization's workflows, connect with Quantiphi or visit the AWS Generative AI Innovation Center. About the authors Figure 4: Professional Headshot - Giorgia Rematska Giorgia Rematska, PhD Giorgia Rematska, PhD, is a principal architect and machine learning specialist at Quantiphi with over 7 years of expertise in traditional ML, deep learning, and generative AI. She has led initiatives including automated medical document processing, ICD-10 code prediction, and model distillation for privacy-preserving NLP. Figure 5: Professional Headshot - Rakesh Raghu Rakesh Raghu Rakesh Raghu is a senior partner solutions architect at AWS who helps AWS Partners design and build scalable, more secure cloud solutions for public sector customers. He specializes in cloud networking and connectivity and works on migrating workloads to AWS and architecting generative AI solutions. Figure 6: Professional Headshot - Shane Knisley Shane Knisley Shane Knisley is a partner solutions architect with AWS Worldwide Public Sector (WWPS) who helps partners and public sector customers design more secure, compliant workloads across AWS commercial and government Regions. He has over 20 years of IT and cybersecurity experience with deep expertise in RMF and FedRAMP processes.

How UMiami and Quantiphi optimized radiology coding with Amazon Bedrock

The University of Miami Health System (UHealth) set out to close that gap in both downstream and upstream directions. Working with Amazon Web Services (AWS) and AWS Partner Quantiphi, the UHealth Department of Radiology built a generative AI coding solution on Amazon Bedrock that pairs AI with a radiologist attestation workflow, delivering clinical-grade accuracy while replacing error-prone manual processes.

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Continuous monitoring under FedRAMP 20x: Replacing annual assessments with persistent validation

Under legacy Federal Risk and Authorization Management Program (FedRAMP) Rev5, continuous monitoring meant monthly deliverables and annual assessments. Under FedRAMP 20x, it means persistent, automated validation where the status of your security posture is always known. In this post, we operationalize that model using AWS Security Hub, AWS Config conformance packs, Amazon GuardDuty, Amazon Inspector, and Sigma detection rules to build an always-on monitoring architecture.

From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS

From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS

This post provides a decision framework and technical guidance to help database administrators and architects navigate the transition facing Amazon Web Services (AWS) customers who run workloads on Amazon Relational Database Service (Amazon RDS) Custom for Oracle.

Building supply chain multi-agent workloads in AWS GovCloud (US)

Building supply chain multi-agent workloads in AWS GovCloud (US)

This post shows how to build that on Amazon Web Services (AWS) using Amazon Bedrock, deployed in AWS GovCloud (US). You’ll deploy a working multi-agent workload, see how a supervisor coordinates specialized agents through the Converse API in Amazon Bedrock, and learn which AWS GovCloud (US) details break patterns copied from commercial Regions.

AWS expands its Defending Digital Campaigns offering for the 2026 election cycle

AWS expands its Defending Digital Campaigns offering for the 2026 election cycle

This post describes the program for the 2026 cycle, the services it covers, and how eligible campaigns and committees can enroll. Since AWS first joined DDC in 2020 and expanded the offering in 2022 and again in 2024, eligible campaigns and committees of any size and on either side of the aisle have used these services to protect the data, identities, and applications they rely on through Election Day.

A person is holding a cell phone and typing on a laptop. The laptop screen shows a green lock symbol. Concept of security and protection

How to secure communications beyond encryption with AWS Wickr

Read this post to learn about AWS Wickr, a messaging and collaboration service that protects messaging, calling, file sharing, screen sharing, and location sharing with 256-bit end-to-end encryption (E2EE). Wickr combines advanced security for sensitive communications, administrative controls for user and policy management, and data retention for auditing and regulatory needs.

What HCLS security teams can do this quarter to close the execution gap

What HCLS security teams can do this quarter to close the execution gap

Most security teams know what’s needed to defend their organization. Regulatory guidance is available, threat intelligence sharing has increased, and risks are well-documented. So why are healthcare and life sciences (HCLS) groups, from commercial payors to public health systems, still facing recurring incidents or falling behind in protecting sensitive information? The answer is the execution gap: the space between knowing what to do and the ability to get it done.

https://app.asana.com/1/8442528107068/project/1207199896111772/task/1215597699950048?focus=true

How ITHAKA built an on-demand PDF remediation pipeline on AWS

In this post, we describe how ITHAKA and Amazon Web Services (AWS) collaborated to build an on-demand PDF accessibility pipeline that remediates documents when users need them, serving researchers while using nonprofit resources responsibly. For organizations managing a large document collection under accessibility compliance deadlines, this post shows there is an affordable, practical path forward that doesn’t require converting an entire library upfront.

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

In this post, we walk through how OSM partnered with Sierra-Cedar, an AWS Premier Consulting Partner, to design, build, and deploy FileVault—a secure file transfer solution powered by AWS Transfer Family and Amazon Simple Storage Service (Amazon S3)—while preserving the user experience that state employees already knew and trusted.

Digital Earth Africa and AWS are making satellite data work for Africa

Digital Earth Africa and AWS are making satellite data work for Africa

Amazon Web Services (AWS), through the Open Data on AWS and Amazon Sustainability Data Initiative (ASDI) programs, became a foundational collaborator from the outset, hosting Digital Earth Africa’s data on AWS infrastructure in Cape Town, South Africa, and enabling African users to access and analyze petabytes of satellite data at a speed and scale that would otherwise be out of reach.