Penguin Ai automates the full prior authorization lifecycle for healthcare payers - delivering faster approvals, lower costs, and audit-ready compliance beyond CMS-0057-F.
Penguin Ai - Intelligent Utilization Management for Healthcare Payers
Penguin Ai enables healthcare payers to cut administrative costs, accelerate authorization turnaround, and deliver superior decision consistency by combining intelligent AI automation with human-in-the-loop oversight at every step.
The platform ingests structured and unstructured clinical data to automate intake, validate requests, and support adjudication - aligning decisions with CMS guidelines, payer policies, and clinical criteria. The result is full lifecycle automation that goes beyond CMS-0057-F compliance.
About Penguin Ai
Founded in 2024 and backed by $25M in funding, Penguin Ai is a healthcare software company headquartered in Palo Alto, California. The team is focused exclusively on workflow automation for health insurance payers and providers, bringing deep expertise in healthcare AI and clinical operations to the prior authorization challenge.
Core Capabilities
Authorization Rules and Decision Support
Evaluate requests against payer rules, benefit design, CMS NCD/LCD, and clinical criteria
Automate triage, apply approval logic, and classify requests into approve, deny, or review
Generate medical necessity recommendations with transparent rationale
Workflow Orchestration and Integration
Integrate with UM systems via APIs and EDI (278) transactions
Route cases dynamically based on rules, SLAs, and documentation gaps
Track request status across lifecycle stages with configurable notifications for approvals, denials, and follow-ups
Compliance and SLA Management
Enforce payer policies, NCQA and URAC regulations, and clinical guidelines with built-in validation
Track SLAs and trigger escalations for aging or non-compliant requests
Maintain audit-ready documentation aligned to CMS guidelines
Key Benefits for Healthcare Payers
Reduce administrative costs - Automate manual intake, triage, and adjudication workflows to lower operational overhead
Accelerate authorization turnaround - AI-driven decision support enables faster processing with high-confidence auto-approvals
Improve decision accuracy and consistency - Healthcare-native NLP combined with payer-specific policy logic ensures reliable outcomes
Strengthen compliance and audit readiness - Explainable rationale tied to CMS guidelines, payer policies, and clinical criteria
What Sets Penguin Ai Apart
Beyond CMS-0057-F: Automates the full prior authorization lifecycle, not just interoperability requirements
Healthcare-Native AI + Policy Logic: Combines clinical NLP with payer-specific rules for accurate, consistent decisions
Explainable and Audit-Ready: Transparent rationale aligned to CMS guidelines and payer policies
Automation with Control: High-confidence auto-approvals with human review for complex cases
Security and Data Handling
Penguin Ai is designed for HIPAA-aligned processing of protected health information. The platform operates within AWS infrastructure leveraging encryption in transit and at rest, network isolation, and role-based access controls to safeguard PHI throughout the authorization workflow.
AWS Deployment
Penguin Ai is designed for secure, scalable enterprise deployment on AWS. The platform integrates with existing payer infrastructure including EDI (278) workflows, provider portals, and Utilization Management systems to enable rapid adoption without disrupting current operations.
Who Should Use Penguin Ai
Penguin Ai is built for healthcare payers seeking to modernize prior authorization operations - including health plans, managed care organizations, and third-party administrators looking to reduce costs, improve turnaround times, and maintain regulatory compliance across their authorization workflows.
Get Started
To schedule a discovery call, request a guided demo, or discuss a pilot engagement, contact the Penguin Ai team at hello@penguinai.co. The team will work with you to scope integration requirements and define a path to production deployment.
Highlights
Automated Intake and Adjudication: Penguin Ai ingests structured and unstructured clinical data across EDI (278), API, and document workflows to automate the full prior authorization lifecycle. The platform evaluates requests against payer rules, benefit design, CMS NCD/LCD, and clinical criteria to classify requests into approve, deny, or review - delivering high-confidence auto-approvals while routing complex cases for human review.
AI-Driven Decision Support with Compliance Built In: Healthcare-native NLP combined with payer-specific policy logic ensures accurate, consistent authorization decisions aligned to CMS guidelines, NCQA and URAC regulations. Explainable rationale provides audit-ready documentation, while built-in SLA tracking and escalation triggers keep operations compliant and on schedule.
Scalable AWS Deployment with Enterprise Integration: Designed for secure, HIPAA-aligned enterprise deployment on AWS, Penguin Ai integrates with existing Utilization Management systems, EDI (278) transactions, and provider portals. Dynamic case routing, configurable notifications, and lifecycle tracking enable payers to modernize prior authorization operations without disrupting current infrastructure.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract pricing combines two charges. You pay a recurring monthly subscription fee to access the utilization management platform. On top of that, you pay a transaction fee tied to activity, so this portion scales with your usage volume. The subscription covers ongoing access, while the transaction fee grows or shrinks with how much you process. Together they form a base-plus-usage structure: a predictable monthly cost plus variable charges that track workload across prior authorization, concurrent review, retrospective recovery, appeals, and grievance workflows.
Top-of-mind questions for buyers
What activity does the transaction fee count?
The transaction fee ties to case processing across utilization management workflows. This includes prior authorization requests, concurrent reviews, retrospective intake, appeals, grievances, and external review coordination. Each case moving through the platform can generate a charge, so this fee grows with the volume your team processes.
How do the monthly subscription fee and transaction fee combine on my bill?
Both charges apply together on the same invoice. The monthly subscription fee is a fixed recurring cost for platform access. The transaction fee is variable and tracks your case volume. For high-volume operations, transaction charges tend to drive the larger share, while the subscription stays steady each month.
Does my cost change if my case volume rises or falls?
The monthly subscription fee stays the same regardless of volume. The transaction fee moves with activity. When you process more cases across prior auth, concurrent review, retro, or appeals, transaction charges rise. When volume drops, that portion shrinks. There is no automatic tier upgrade involved.
www.penguinai.co
Helpful?
Vendor refund policy
All fees are non-refundable. Either party may terminate for an uncured material breach (30 days' written notice, including non-payment) or if a party ceases operations. Termination ends platform access and future fees but does not refund pre-paid or unused fees. The sole exception: if Penguin Ai terminates in response to a third-party intellectual property claim, it will refund pre-paid, unused fees for the terminated portion of the term.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Product overview
A HIPAA-aware backend service that automates Prior Authorization (PA) and Utilization Management (UM) review. It ingests clinical documentation, performs OCR and PHI-aware extraction, evaluates cases against medical-necessity guidelines using large language models on Amazon Bedrock, and produces reviewer-ready determinations, letters, and analytics.
Key capabilities: PA intake and processing, longitudinal patient summarization, inpatient and concurrent review, automated determination letters, dashboards and turnaround-time analytics, and built-in content guardrails with PHI/PII redaction.
The service exposes a REST API (OpenAPI/Swagger) and runs from a single container image in two roles: an API server and one or more background workers.
Product at a glance
Runtime: FastAPI + Uvicorn (Python 3.11), non-root container
Listening port: 7000/tcp (HTTP, behind a TLS-terminating load balancer)
Health endpoint: GET /health (unauthenticated, no PHI)
API docs: GET /docs, GET /redoc
State: stateless - all persistent data lives in external, buyer-owned AWS services
Prerequisites
Provision the following in your own account and supply their coordinates via environment variables:
OCR service (e.g., Amazon Textract) - text extraction from clinical PDFs/images
Enterprise identity provider (OAuth 2.0 / SAML SSO) - sign-in and role mapping
Amazon ECS or EKS + Application Load Balancer - runtime and HTTPS termination
Enable Bedrock model access in the deployment Region, and keep DocumentDB, Redis, and S3 in the same VPC/Region as the compute.
Deployment (high level)
Subscribe to the product and pull the container image from Amazon ECR (URI and tag shown on the product's Launch page).
Provision the prerequisites in Section 3.
Store secrets (database/Redis passwords, identity-provider client secret, OCR key, JWT signing keys) in AWS Secrets Manager or SSM Parameter Store, and inject them as environment variables. Never bake secrets into the image.
Deploy on ECS or EKS:
Run one API service (container port 7000) behind an ALB with health check path /health.
Run one or more worker services (same image, worker command) to process background tasks.
Attach an IAM task role / IRSA with least-privilege access to Bedrock, S3, Secrets Manager, and KMS (Section 9).
Verify: confirm the service is healthy, then:
curl https:///health # -> {"status":"ok","service":"...-api","version":"1.0.0"}
Open https:///docs for the API reference, and complete an SSO sign-in to confirm end-to-end authentication.
Scale by running additional API and worker containers behind the load balancer.
Configuration (high level)
Configuration is entirely environment-variable driven. The main groups are:
Datastore: MONGO_URL (TLS + retryWrites=false), or host/user/password/db.
Cache and broker: REDIS_HOST, REDIS_PORT, REDIS_PASSWORD, REDIS_SSL.
Storage: AWS_REGION, AWS_BUCKET_NAME.
AI / Bedrock: Claude model/inference-profile ARNs and model names.
Authentication: identity-provider client ID/secret/tenant and JWT signing keys (JWT_SECRET_KEY, SECRET_KEY) with configurable token lifetimes.
OCR: OCR service endpoint/key.
Security and ops: CORS allow-list, security headers/CSP, PHI_TMPDIR, log level, and CloudWatch metrics export.
Optional feature flags gate modules such as inpatient review, letter generation, and intelligent allocation; leave them at defaults unless enabling a specific capability.
Data, sensitive information and encryption
Where data is stored - the container holds no durable data:
In transit: TLS everywhere - ALB terminates HTTPS to clients; DocumentDB connections enforce TLS; enable in-transit encryption for Redis (REDIS_SSL); all AWS SDK calls use HTTPS.
At rest: enable AWS KMS encryption on DocumentDB, S3, ElastiCache, and Secrets Manager when you provision them.
Decryption: the app uses no proprietary encryption. Managed services transparently decrypt for the container's IAM role; JWTs issued by the API are signed (not encrypted) with JWT_SECRET_KEY and verified per request.
Credentials and rotation
Store all credentials in Secrets Manager / SSM and rotate on a regular cadence (align to your security policy, typically 90 days or less):
JWT signing key / app secret (JWT_SECRET_KEY, SECRET_KEY) - rotating invalidates outstanding tokens; roll API and workers together.
DocumentDB / Redis passwords - use managed rotation and redeploy so all services pick up the new value.
Identity-provider client secret and OCR key - rotate before expiry; overlap old/new during cutover.
AWS access: use IAM task roles / IRSA - avoid long-lived access keys.
Procedure: update the secret -> rolling redeploy of API + all workers -> confirm health -> revoke the old value.
DocumentDB (system of record): enable automated snapshots + point-in-time recovery; restore to a new cluster and repoint the connection string. Required indexes are re-created automatically at startup.
S3: enable versioning (and optional cross-Region replication for DR).
Redis: treated as ephemeral; in-flight work is re-driven from DocumentDB state.
Because the container is stateless, DR is: restore DocumentDB + S3, redeploy the image, repoint environment variables.
Health monitoring:
In the ECS/EKS console, confirm running count = desired count and tasks/pods are healthy (the container has a built-in health check and the ALB checks /health).
Call GET /health for a fast liveness signal (it does not probe downstreams, so downstream slowness never falsely marks the API down).
Enable CloudWatch metrics export (token usage, cost, latency, decisions, guardrails) and send container logs to CloudWatch Logs (logs are PHI-safe).
Recommended alarms: unhealthy target hosts, service running-count below desired, DocumentDB/Redis CPU and connections, and Bedrock throttling/error rate.
Service quotas, IAM and pricing
Service quotas - request increases proactively via Service Quotas:
Amazon Bedrock per-model requests-per-minute and tokens-per-minute is the primary scaling constraint.
Also monitor ECS/Fargate tasks, DocumentDB instances/connections, ElastiCache nodes, and OCR TPS.
IAM (least privilege, task role / IRSA): bedrock:InvokeModel* on the configured models; s3:GetObject/PutObject/ListBucket/DeleteObject on the configured bucket(s); secretsmanager:GetSecretValue / ssm:GetParameter* and kms:Decrypt on the relevant resources; CloudWatch PutMetricData / log permissions when enabled. The execution role additionally needs ECR pull and secret-read permissions.
Pricing - software is billed through AWS Marketplace at the listed rate. You separately pay standard AWS rates for the infrastructure you run it on: ECS/EKS compute, DocumentDB, ElastiCache, S3, Amazon Bedrock per-token inference (usually the largest variable cost), OCR, load balancer, Secrets Manager, and CloudWatch. Estimate with the AWS Pricing Calculator; Bedrock token spend and compute/DocumentDB sizing dominate total cost.
Security and compliance (PHI)
This product processes Protected Health Information. To operate it in a HIPAA-eligible manner: execute an AWS Business Associate Addendum and use HIPAA-eligible services; enable KMS encryption at rest and TLS in transit; run all containers and data stores in private subnets exposing only the ALB; restrict the container security group so port 7000 is reachable only from the load balancer; keep the container non-root; scope IAM to least privilege; retain the DocumentDB audit trail per policy; and keep input/output guardrails and PII redaction enabled in production.
Upgrades and release notes
Upgrades are a rolling image replacement with no data migration (indexes are ensured idempotently at startup):
Review release notes for the target version and any new required environment variables.
Snapshot DocumentDB and confirm S3 versioning before upgrading production.
Pull the new image tag and roll out the API and all worker services to the same version.
Verify health and run a smoke test. Roll back to the prior image tag if needed - rollback is immediate since no destructive migration runs.
Release notes (v1.0.0 - initial release): PA/UM API with OCR, Bedrock-powered extraction and guideline evaluation, patient summarization, inpatient/concurrent review, determination letters, analytics, and governance guardrails; hardened non-root container with PHI-safe temp handling and TLS-enforced database connectivity. Future releases are labeled Critical (security), Important, or Optional.
Support
This product is provided by Penguin AI. For product support, questions, or issues, contact support@penguinai.co. AWS infrastructure issues are handled through AWS Support. A running instance serves its interactive API reference at /docs and /redoc.
For technical support, onboarding assistance, deployment guidance, or general inquiries, contact the Penguin Ai team via email at support@penguinai.co.
Getting Started
After subscribing, reach out to the support team to schedule an onboarding session. The team will work with you to scope integration requirements, configure payer-specific policy rules, and define a deployment plan tailored to your environment.
Ongoing Support
The Penguin Ai team provides assistance with platform configuration, EDI (278) integration, UM system connectivity, troubleshooting, and general product questions. For issues requiring escalation, the team will coordinate resolution and provide status updates.
Requesting a Demo or Pilot
Healthcare payers interested in evaluating Penguin Ai can request a guided demo or discuss a pilot engagement by contacting support@penguinai.co. The team will walk through the platform capabilities, discuss your specific use case, and outline next steps.
Refunds and Billing
For questions about billing, subscription management, or refund requests, contact support@penguinai.co with your AWS account details and subscription information.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Penguin Ai automates CPT, ICD-10, and HCPCS code assignment from clinical documentation using healthcare-trained AI with human-in-the-loop oversight for providers.
Penguin Ai automates HCC coding and risk adjustment for healthcare payers, delivering RAF accuracy, compliance, and revenue capture with explainable AI.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.