ARDIA PRECISION HEALTHGoverned AI for healthcare revenue & precision care
360° view · Pillar 4

PulmoIQ

PulmoIQ is a browser-side persona label for pulmonary and sleep reimbursement support that today routes to Ardia's shared TARA prompt on Google Gemini, grounded only in retrieved PubMed literature rather than any pulmonary coverage-policy or GOLD/GINA corpus; the framing is coherent and honestly labelled, but defensibility is currently absent — no proprietary model, no data asset, no guideline corpus and no customer to defend — and the reasoning layer is a third-party API any competitor can call. Company context: Ardia Precision Health, founded December 2025, Dallas-Fort Worth, pre-revenue — 0 customers, 0 pilots, 0 signed BAAs or DUAs, $0 revenue, $0 raised. No real patient data is processed anywhere in this module.

◐ modelled target Engine · Google Gemini, verified by direct probe of https://www.ardiahealthlabs.com/api/run on 2026-09-01: GET returns {"ok":true
CPT 94010, 94060, 94070 (spirometry, bronchodilator responsiveness, bronchospasm provocation)CPT 94617 / 94618 / 94619 (exercise and bronchospasm testing)CPT 94726 / 94727 / 94728 (lung volumes by plethysmography, gas dilution, oscillometry)CPT 94729 (DLCO, add-on; requires a valid base code)CPT 94640 / 94644 / 94645 / 94664 (inhalation treatment and inhaler technique)CPT 94760 / 94761 / 94762 (pulse oximetry - bundled status)CPT 94625 / 94626 (pulmonary rehabilitation; reported to have superseded G0424 - verify against the current codeset)CPT 95012 (FeNO)CPT 95806 / 95810 / 95811 (home sleep test; attended PSG; PSG with PAP titration) and HCPCS G0398 / G0399 / G0400CPT 71271 + G0296 (low-dose CT lung cancer screening and shared decision-making visit)CPT 82803 (arterial blood gas - the one CLIA-regulated test in the set)CPT 99490 / 99487 / 99489 (CCM), 99424-99427 (PCM), 99453-99458 (RPM), 98975-98981 (RTM, respiratory)ICD-10-CM J44 COPD family, J43.9, J42, the J45 asthma family, J96, G47.33, R06.02, Z87.891, F17.2NCD 240.2 (Home Use of Oxygen), NCD 240.4 (CPAP for OSA), NCD 240.4.1 (Sleep Testing for OSA)MAC Local Coverage Determinations and paired Billing & Coding Articles for pulmonary function and sleep testing (jurisdiction-specific; no public JSON API - hand-verified snapshot with a revision date required)CMS NCCI Procedure-to-Procedure edits, NCCI Policy Manual Chapter 11, and Medically Unlikely Edits (quarterly)X12 5010 837P/837I, 835 with CARC/RARC external code lists, 270/271, 276/277, 278CMS-0057-F Interoperability and Prior Authorization Final Rule (FHIR PARDD APIs, 1 January 2027)HL7 FHIR R4 / US Core / USCDI; HL7 Da Vinci CRD, DTR and PAS; SMART on FHIR and CDS HooksLOINC (spirometry observations, pre/post-bronchodilator), SNOMED CT, RxNorm - numerals to be pulled from current releases, not recalledGOLD Report and GINA (copyrighted; educational download is not a commercial redistribution licence)ATS/ERS 2022 interpretive standards and GLI reference equationsFD&C Act 520(o)(1)(B) administrative-support exclusion (21st Century Cures 3060); 520(o)(1)(E) CDS exclusion and FDA's September 2022 CDS final guidance21 CFR 868.1840 (diagnostic spirometer), 21 CFR 868.1890 (predictive pulmonary-function value calculator), 21 CFR 812.2(b) abbreviated IDEHIPAA 45 CFR 160.103 (business associate), 45 CFR 164.514(b) de-identification (Safe Harbor / Expert Determination), 45 CFR 46.102(e) not-human-subjects determinationTexas SB 1188 (US data residency, AI disclosure, practitioner review) and TRAIGA / HB 149ONC/ASTP HTI-1 Predictive DSI source attributes, 45 CFR 170.315(b)(11)HEDIS SPR / PCE / AMR; CMS-HCC risk adjustment for J44.x (HCC number differs between model versions - verify)

Where it sits in the platform

Pillar 4 — pulmonary and respiratory care (asthma, COPD, PFT and sleep). It is the intended, but entirely unbuilt, respiratory feeder into Pillar 5 (elder care: Aria, Ardia One, Cadence): no interface, data flow or shared model exists today; Aria runs its own engine path and Cadence is a standalone activity classifier on the public UCI HAR dataset, not a fall detector. It is conceptually analogous to the Pillar 1 and 2 reimbursement reasoning of precision medicine and molecular and genomic diagnostics (denial logic applied to CPT 94xxx/95xxx rather than 81xxx), but shares nothing with MolecuIQ in practice — molec and pulmo resolve to different engine paths, no code, prompt or corpus is common, and MolecuIQ's denial reasoning is itself an unmeasured live demo with no published accuracy. It has no policy relationship to Pillar 3, the 2027 PAMA/CLFS rate cliff: PFTs are paid under the Physician Fee Schedule and OPPS, not the Clinical Laboratory Fee Schedule — even though PulmoIQ shares Meridian's engine path. Toxicology (ToxIQ) sits on the same roster and, notably, runs MolecuIQ's prompt.

Status, stated precisely

The only thing live is Ardia's generic TARA persona under a PulmoIQ label, emoji and accent colour. Nothing pulmonary-specific — system prompt, curated corpus, deterministic code engine, eval set — exists. Verified: posting model "pulmo" to https://www.ardiahealthlabs.com/api/run returns {"error":"bad_model"}; studio.html rewrites pulmo to tara before sending. Maturity ladder applied honestly: MEASURED = nothing in this module (the only measured artefacts company-wide are Cadence's 95.45% held-out accuracy and Meridian's unit-tested PAMA arithmetic, both company-reported and not independently reproduced); LIVE DEMO = the shared TARA path this label calls, which runs but has no published accuracy; MODELLED TARGET = everything PulmoIQ claims to be. The company's own /models page has labelled PulmoIQ "live demo" while its /pulmonology blueprint labels the same thing "Modelled target". The blueprint is the honest label and the two must be reconciled. Work with no located implementation should be labelled ROADMAP, not "in build".

Shared engine path — read this first.

YES — state this first in any investor or diligence setting, because it is trivially checkable. PulmoIQ is not a separately trained model. Ardia's Studio routes ten named models through four engine paths: ENGINE_MODEL = {molec:'molec', toxiq:'molec', pulmo:'tara', meridian:'tara', aria:'aria', lumen:'lumen'}. PulmoIQ and Meridian both resolve to the TARA engine key, and ToxIQ runs MolecuIQ's prompt. PulmoIQ and Meridian are therefore the same server-side prompt, the same Gemini call and the same retrieval pipeline, differing only in browser label, emoji and accent colour.

PulmoIQ inherits whatever TARA's reasoning quality is — which is itself unmeasured, with no eval set, no benchmark and no published accuracy for any persona. Shared routing means changes to TARA propagate to PulmoIQ and Meridian untested and unmonitored: there is no per-persona regression suite, so one prompt regression or one silent "-latest" model roll can degrade three products at once with nothing to detect it. That is engineering economy, not validated leverage, and it is the strongest technical risk in the company.

A related asymmetry a buyer will hit: genuinely deterministic CLFS/PAMA arithmetic exists in models/meridian/clfs.py and is mirrored by a client-side calculator on model-pama.html, but it is not wired into the Studio answer path, so a Meridian question in the Studio is answered by Gemini reasoning as TARA. A buyer meets two different Meridians. PulmoIQ, sitting on that same path, has no deterministic component at all — not even one that exists off-path. Any Studio trace depicting live tool calls for PulmoIQ that do not execute should be relabelled "illustrative — scripted" immediately; it is an FTC-flavoured exposure, not an aesthetic one.

01

What it is, and who it is for

The problem

Two pains. PulmoIQ addresses neither in code today.

PAIN 1 - the pulmonary reimbursement grind. Pulmonary function testing is high-volume, low-dollar and heavily edited: CPT 94010 spirometry, 94060 with bronchodilator responsiveness, 94726-94729 lung volumes, diffusion and oscillometry, 94617-94619 exercise and bronchospasm testing, 94640-94645 inhalation treatment, 94664, 94625/94626 pulmonary rehabilitation (reported to have superseded G0424 - verify against the current codeset), and the sleep set 95806/95810/95811 plus HCPCS G0398-G0400. The failure modes commonly reported in pulmonary billing literature are component and bundling conflicts between spirometry codes, add-on codes billed without a base, MUE overages, frequency limits on serial testing, missing pre/post-bronchodilator values in the note, an ICD-10 not on the MAC's covered list, bundled oximetry billed separately, and prior-authorisation documentation failures in sleep. These are hypothesised failure modes drawn from published guidance and domain reading. They are not findings. Ardia has never processed a claim, an 835 or a denial file, has run no customer-discovery interviews, and holds no DUA. Every specific edit, modifier indicator and bundling status must be validated against the current-quarter NCCI PTP and MUE tables before use; Ardia holds no NCCI table, no MUE lookup and no coding corpus.

The economics are the difficulty. Commonly cited industry rework estimates run roughly $25 per straightforward correction and $100+ per full appeal - unsourced here, and they vary widely by study and year. Office spirometry allowables are in the low-to-mid tens of dollars; the figure must be pulled from the published MPFS rather than recalled. Appealing a fifty-dollar line is often value-destroying. The dollars that could justify software sit in sleep studies, pulmonary rehabilitation, home oxygen under NCD 240.2, and the COPD care-management codes - amounts unsourced here and requiring MPFS/OPPS APC verification.

PAIN 2 - longitudinal trend blindness in COPD and asthma. Real, undisputed, and precisely the pain FDA regulates as a device. Ardia has correctly deferred it.

Who buys it

Assumed, not validated. Ardia has never quoted a price, never run a discovery interview and never run a deal. Everything below is a hypothesis about who would pay, held at that confidence.

REIMBURSEMENT LANE. Independent pulmonology group (4-15 physicians, often an in-office PFT lab): economic buyer is the practice administrator or physician-owner; user is the billing/AR specialist; champion is whoever re-keys appeal letters. Discretionary cheque size and sales-cycle length are unknown to Ardia - any figure quoted is a placeholder pending discovery. Freestanding and hospital-affiliated sleep centres (AASM-accredited; US count in the low thousands, figure not sourced here) are the segment where dollars per study make an ROI case arithmetically easier. Hospital pulmonary service lines cannot be served at all today: no BAA, no SOC 2, no HITRUST, no pen test, HIPAA control matrix self-graded 2 of 15, and an AI-governance committee now standard in that review.

Pulmonary and sleep RCM outsourcers are plausibly the highest-leverage channel, on the untested reasoning that one contract reaches many practices - offset by the fact that outsourcers run their own vendor-security and AI-governance reviews, frequently stricter than a small practice's. The idea that a billing company can hand over de-identified 837/835 corpora under a DUA and skip a BAA is a hypothesis, not a cleared path: Ardia has signed zero DUAs, and data arriving as de-identified must satisfy HIPAA Safe Harbor or expert determination, which Ardia's own Sentinel cannot presently deliver because it does not reliably redact plain personal names. Counsel review is required before this is presented as a route around a BAA.

MA plan and ACO risk-adjustment and HEDIS work is a possible adjacency worth testing, not a validated thesis: different data rights, different product surface, a security-gated nine-to-eighteen-month sale, no sizing and no buyer conversation.

Any engagement touching real patient data requires a BAA Ardia cannot sign. A first engagement must be synthetic.

Clinical & domain context

Regulatory note governing this entire dimension: Ardia is administrative and decision-support software, NON-DIAGNOSTIC, not an FDA-regulated medical device. Nothing here is or may be presented as clinical guidance. Every clinical threshold below is unretrieved model recall, not sourced from GOLD, GINA or ATS/ERS documents - no such corpus exists in the product - and each must be verified against the current publications before it appears in external material or is encoded in any rule.

COPD and asthma - obstructive airway disease - plus the sleep-disordered-breathing adjacency that shares the same billing department. Prevalence and cost-of-illness figures require named, dated sources before use: COPD prevalence (CDC BRFSS), asthma prevalence (source not cited), COPD direct medical cost around $24B/year (CDC, older dollars). None are Ardia-generated, and no TAM model is built on them here.

Diagnosis of COPD rests on spirometry, with a post-bronchodilator FEV1/FVC ratio establishing persistent airflow limitation, severity graded on FEV1 percent predicted, and a symptom-plus-exacerbation assessment scheme; blood eosinophil count is used to select patients for inhaled corticosteroid benefit. Predicted values increasingly use GLI reference equations, with the ATS/ERS 2022 standard moving interpretation toward z-scores - a live, unsettled question that matters enormously for any automated interpretation claim. In asthma, GINA moved away from SABA-only reliever therapy toward ICS-formoterol, and severe-asthma phenotyping gates biologics on eosinophils, FeNO and IgE, which is the genuine precision-medicine touchpoint tying pulmonary care back to molecular diagnostics.

ICD-10 families a future rules engine would need to encode - none is encoded today; there is no code set, mapping table or rules engine in the product - include the J44 COPD family, J43.9, J42, the J45 asthma severity family, J96, G47.33, R06.02, Z87.891 and F17.2. Diagnosis specificity is widely cited as a frequent driver of medical-necessity denials on PFT claims. Ardia has no data with which to rank causes.

02

How it actually works

Architecture, end to end

What actually happens today, end to end.

INPUT. The user opens the Studio, selects the PulmoIQ card and types free text. The browser rewrites the model key before the request leaves the page - ENGINE_MODEL maps pulmo to tara - and POSTs to /api/run. Posting model "pulmo" directly to the API returns {"error":"bad_model"}. There is no PulmoIQ model server-side. Input is capped at 6,000 characters. Attachments are dead in two independent places: the API returns {"error":"uploads_disabled"}, and the Studio hardcodes attachments to an empty array, so a chosen file is read to base64 and discarded. Image, X-ray and MRI analysis does not work. The product discusses imaging REPORT TEXT a user types in; it never sees an image.

DE-IDENTIFICATION. Sentinel regex-redacts before anything leaves the function. On probe, structured identifiers - SSN, phone, MRN, dates, ZIP, email - were redacted. No recall or precision has been measured, there is no test corpus, and plain personal names are NOT reliably detected: "John Smith" reached the model. Sentinel must not be described as a de-identification control.

RETRIEVAL. Two paths. A curated CMS Local Coverage Determination matcher, whose eight policies are all molecular or toxicology - two (L35025, L38045) verified to resolve on cms.gov, the rest unverified, with no revalidation process for a corpus that is revised continuously. And live PubMed and ClinicalTrials queries. A pulmonary GOLD/COPD query DID return two real, linked PubMed citations (PMID 40050074, PMID 38032494). So pulmonary answers are grounded in retrieved PubMed literature - not in a curated GOLD/GINA corpus, which is not built, and not in any pulmonary coverage policy, of which the corpus holds none.

REASONING. Google Gemini. Fast tier serves gemini-flash-lite-latest in about three seconds; Scholar serves gemini-flash-latest in about fifty-four. There is no PulmoIQ system prompt and no pulmonary rule set.

GATES. Six deterministic gates return on every call, and a failure withholds the answer entirely - verified in production.

What data flows where

TODAY: public Studio, no BAA, synthetic text only.

ENTERS: up to 6,000 characters of typed text. Nothing else. Attachments are refused at the API and discarded in the browser - no imaging, no PDF, no document. No FHIR, no HL7v2, no X12, no device or wearable data.

REDACTED: Sentinel strips structured identifiers and returns the count and categories to the caller, a genuinely good transparency property. It does not reliably strip plain personal names.

LEAVES THE PERIMETER: a keyword query to NCBI E-utilities and ClinicalTrials.gov, public and unauthenticated; and the redacted full text plus grounding block to Google's Gemini API. This is NOT a no-PHI-by-construction guarantee. Because Sentinel misses names, any name a user types can egress to those endpoints and to the model provider.

RESIDENCY AND STATE AI OBLIGATIONS: Texas SB 1188 data-residency requirements and TRAIGA apply to Ardia. The Gemini call is this module's only cross-perimeter hop, and its processing region is neither documented nor contractually pinned. No BAA, no DPA, no residency commitment with the model provider. Open compliance gap.

MODEL PINNING: the served model id resolves a "-latest" alias, so Google can roll the model forward silently - no version change, no changelog, no eval harness to detect it. For output destined for a claims appeal, that is an unmanaged reproducibility and governance risk.

LOGGING: the handler is reported to suppress its own per-request logging. That does not establish client IP and path are never written - platform, CDN and hosting logs sit above it, unaudited. Treat request logging as unknown, not absent.

RETENTION: unresolved. No server-side persistence was observed at Ardia's layer, but absence of evidence is not a guarantee, and downstream retention under consumer endpoint terms is the real exposure. CORS is pinned to the site origin; that is not an access control - the endpoint is unauthenticated and callable by any non-browser client. Correct posture: no PHI, ever, under any framing.

Standards & policy it works to

CODE SETS. CPT pulmonary diagnostic: 94010 spirometry; 94060 spirometry with bronchodilator responsiveness; 94070 bronchospasm provocation; 94617/94618/94619 exercise and bronchospasm testing; 94726 plethysmographic lung volumes; 94727 gas dilution/washout; 94728 oscillometry; 94729 DLCO as an add-on; 94640-94645 inhalation treatments; 94664; 94760-94762 oximetry, bundled status; 94625/94626 pulmonary rehabilitation; 95012 FeNO. CPT sleep: 95806 unattended home sleep test, 95810 attended polysomnography, 95811 with PAP titration, plus HCPCS G0398-G0400. Adjacent: 71271 low-dose CT lung cancer screening with G0296, and 82803 arterial blood gas - the one CLIA-regulated test in the set. Care management, the under-exploited surface: 99490/99487/99489 CCM, 99424-99427 PCM, 99453-99458 RPM, 98975-98981 RTM. ICD-10-CM: the J44 and J45 families, J43.9, J42, J96, G47.33, R06.02, Z87.891, F17.2. LOINC, SNOMED CT and RxNorm for interoperability - specific numerals deliberately not asserted; pull them from current releases.

POLICY INSTRUMENTS. Start with the national ones, which are stable and citable and do not vary by MAC: NCD 240.2 home oxygen, NCD 240.4 CPAP, NCD 240.4.1 sleep testing. Then MAC Local Coverage Determinations and their Billing and Coding Articles, which differ by jurisdiction and have no public JSON API, so they must be a hand-verified snapshot with a revision date. NCCI Procedure-to-Procedure edits, NCCI Policy Manual Chapter 11 and Medically Unlikely Edits are deterministic, downloadable, quarterly CMS data and are the highest-value, lowest-risk thing this module could ship - no LLM required. X12 5010 837P/837I, 835 with CARC/RARC, 270/271, 276/277, 278. CMS-0057-F mandates FHIR prior-authorisation APIs from 1 January 2027, with HL7 Da Vinci CRD, DTR and PAS as the standards-native rails for exactly this job.

GOLD and GINA are copyrighted. Free download for educational use is not a commercial redistribution licence - an unbudgeted blocker on the guideline-corpus work item.

NOT RELEVANT, and the pillars must not blur here: MolDX, DEX Z-codes and PAMA/CLFS rate setting. PFTs are paid under the Physician Fee Schedule and OPPS. PulmoIQ shares Meridian's engine path and none of Meridian's policy surface.

How it lands in a real customer

How PulmoIQ would actually land, in descending order of realism.

PATH A - the billing-company and clearinghouse path, the only one a one-engineer company can ship in 2026. Batch 837P out and 835 in, by SFTP or clearinghouse API. PulmoIQ parses CARC/RARC by claim line, classifies root cause deterministically, and emits an appeal packet plus a worklist. No EHR integration, no write-back, no latency requirement, and the buyer already has the data moving. It also yields the training corpus. Do this first.

PATH B - order-time necessity checking inside the EHR. A SMART on FHIR app with CDS Hooks firing on order-select, returning a card that says this order as documented will likely deny under your MAC's policy and why. The standards-native way is HL7 Da Vinci CRD and DTR with PAS for submission, and CMS-0057-F forces impacted payers onto FHIR prior-auth APIs by January 2027 - the rails are being built by regulation whether Ardia participates or not. Strategically correct, and 18-24 months plus an enterprise security review away.

PATH C - device and modality integration for the longitudinal record. PFT systems mostly speak HL7 v2 ORU^R01 into the EHR, the cleanest tap point. Sleep systems, home spirometers and consumer platforms each mean a separate contract and BAA. No wearable measures FEV1.

PATH D - the elder-care bridge. Respiratory tracking feeding Aria and Ardia One is the one integration no pure-play RCM or pulmonary AI vendor can copy, because they do not own both ends. Entirely unbuilt: no interface, no shared data model, no ingestion. It is also closest to the FDA line - any sustained-low-SpO2 rule triggering clinical action is arguably a device function.

TECHNICAL REALITY: /api/run is one synchronous serverless function with a hard timeout, a 6,000-character cap, no queue, no retry and no job model. Batch 835 processing needs a worker; CDS Hooks need a sub-second p99 an LLM call cannot meet.

03

Proof, and the honest state of it

Evidence today

MEASURED - nothing in PulmoIQ. No accuracy figure, no benchmark, no eval set, no coding-accuracy sample, no denial-classification F1, no baseline comparison. Company-wide there are exactly two measured artefacts and neither is PulmoIQ: Cadence's 95.45% held-out accuracy and macro-F1 0.9545, subject-independent, on the public UCI HAR dataset - company-reported, not independently reproduced, and explicitly not a fall detector; and Meridian's deterministic CLFS/PAMA arithmetic, which is unit-tested in models/meridian/clfs.py and mirrored by a client-side calculator. The "34/34 tests passing" figure is likewise company-reported. The caveat reflects directly on PulmoIQ: that CLFS engine is not wired into the Studio answer path, so a Meridian question there is answered by Gemini as TARA. PulmoIQ, on that same path, has no deterministic component at all.

LIVE DEMO - the shared TARA conversational path this label calls. It runs. On a pulmonary denial question it produces a competently structured answer, six of six gates pass, and it does not invent an LCD number. That is a real, checkable behaviour. It is also, precisely, what a general-purpose model does when asked a coding question.

MODELLED TARGET - everything PulmoIQ claims to be: the deterministic necessity and coding engine, the NCCI PTP and MUE validator, the 835 CARC/RARC parser, the curated GOLD/GINA corpus, FHIR and home-spirometer ingestion, air-quality feeds, the longitudinal record.

ASPIRATIONAL AND GATED: exacerbation prediction and any PFT or imaging interpretation - correctly identified as regulated SaMD and disabled rather than quietly shipped.

THE HONEST ZEROS, unsoftened: 0 customers, 0 pilots, 0 signed BAAs, 0 signed DUAs, $0 revenue, $0 raised, 0 real patient records processed, 0 clinical outcomes, 0 published accuracy for any persona. Founded December 2025, Dallas-Fort Worth, pre-revenue.

One correction to earlier drafts: pulmonary queries do NOT return zero sources. They return real PubMed citations. The honest gap is that the grounding is literature retrieval, not coverage policy or guideline text.

How we will produce the first real number

The concrete plan to produce the first non-zero number.

GOLD SET. From one pulmonary or sleep billing partner under a DUA: 20,000-50,000 de-identified 837P lines paired with their 835 remittances over twelve months, restricted to 94010, 94060, 94726-94729, 94625/94626, 95806, 95810, 95811 and G0398-G0400. From these, sample 1,000 denied lines with final adjudicated outcomes - the denominator that matters - stratified by CPT and payer.

WHO LABELS IT. Two credentialed coders, independently, ideally CPC with CPMA, assigning each denied line a root cause from a fixed CARC/RARC-by-CPT taxonomy and the corrective action taken. A third adjudicates disagreements. Report Cohen's kappa. If kappa is below 0.6, the taxonomy is broken and no model result means anything - fix that before proceeding. Ardia has no clinical or coding credential in-house; this cannot be self-labelled.

COMPARATORS. Three, all run on the identical held-out split: the partner's existing claim scrubber or clearinghouse edit engine, which is the real incumbent; an unmodified frontier model given the same input and no Ardia wrapper; and the deterministic NCCI PTP and MUE checker alone with no LLM.

PRE-REGISTERED METRIC. Macro-F1 on root-cause classification over the held-out denied set, plus precision at the chosen operating point for the will-deny flag, because false flags consume biller time and destroy adoption. Pre-register the analysis plan, the split and the operating point publicly before running anything.

KILL CRITERION, stated in advance and honoured. If PulmoIQ does not exceed the unmodified frontier model by at least 0.10 absolute macro-F1 with a bootstrap 95% CI excluding zero, and the deterministic checker alone captures 80% or more of the recoverable dollars, then the LLM layer contributes nothing. In that case PulmoIQ is shut down as a product, merged back into TARA as a prompt template, and Ardia ships the rules engine alone. Second kill: if predicted preventable denials fall below the price-breakeven effect size in the pricing dimension, no buyer can rationally pay.

What a sceptic can check right now

Every claim here is checkable in under five minutes. Run these.

  1. THE ENGINE IS GEMINI, NOT CLAUDE. GET https://www.ardiahealthlabs.com/api/run returns {"ok":true,"provider":"gemini","gated":false}. A dormant call_anthropic path exists in the code but Gemini is checked first and answers. Any site copy naming Claude as the running engine is stale.
  1. THERE IS NO PULMOIQ MODEL. POST /api/run with {"model":"pulmo"} returns {"error":"bad_model"}. For contrast, tara, molec, aria and lumen answer.
  1. PULMOIQ IS RELABELLED TARA IN THE BROWSER. Fetch /studio and grep ENGINE_MODEL: {molec:'molec', toxiq:'molec', pulmo:'tara', meridian:'tara', aria:'aria', lumen:'lumen'}. Ten named models, four engine paths.
  1. THE TIERS SERVE DIFFERENT MODELS AND NEITHER IS PINNED. Fast returns model_id gemini-flash-lite-latest in roughly three seconds; Scholar returns gemini-flash-latest in roughly fifty-four. Both are "-latest" aliases that can roll forward silently.
  1. PULMONARY QUERIES DO RETURN SOURCES - and they are literature, not policy. A GOLD/COPD query returned two real PubMed citations with working links: PMID 40050074 and PMID 38032494. Contrast a molecular query, which returns real CMS Local Coverage Determinations with working cms.gov links such as L35025 and L38045. That is the honest shape of the gap: literature retrieval works, and there is no curated GOLD/GINA corpus and no pulmonary coverage policy behind it.
  1. SIX GATES, AND A FAILURE WITHHOLDS THE ANSWER. Every call returns non_diagnostic, safety_escalation, scope_of_practice, de_identification, honesty and human_in_the_loop, each with a reason. Cite-or-abstain and policy-override are enforced in retrieval and answer-binding and are not gates.
  1. IMAGING IS DEAD TWICE OVER. Any attachment returns {"error":"uploads_disabled"}, and the Studio hardcodes attachments to an empty array, so a chosen file is read to base64 and discarded.
  1. SENTINEL MISSES NAMES. Structured identifiers redact on probe; "John Smith" reached the model.
  1. WHAT A SCEPTIC CANNOT VERIFY, and should be told: Cadence's 95.45% and the 34/34 test count are company-reported and were not independently reproduced. Every file-level claim about the repository is repo-reported.

Where it breaks

Read this first. None of it is softened.

  1. PULMOIQ IS A PROMPT WITH A LABEL. Exactly that. Not a model, not a fine-tune, not a corpus. Posting model "pulmo" returns bad_model; the Studio works only because the browser rewrites pulmo to tara. There is no PulmoIQ system prompt and no pulmonary code path server-side. Anyone with curl proves this in seconds.
  1. IT SHARES ITS ENGINE PATH WITH MERIDIAN; ten named models collapse to four paths company-wide. One prompt regression or one silent model roll degrades three products at once, with no eval harness to detect it. That is the strongest technical risk in the company.
  1. THE MODEL ID IS NOT PINNED - it resolves a "-latest" alias, so the served model can roll forward silently. An answer destined for a claims appeal is not reproducible.
  1. NO CURATED GOLD/GINA CORPUS EXISTS, and the coverage-policy corpus holds zero pulmonary policies. Pulmonary answers rest on retrieved PubMed literature - real citations, but literature is not coverage policy and never says what a MAC pays.
  1. SENTINEL DOES NOT CATCH NAMES. For a module whose intended input is a clinical note, that is the worst gap available. It blocks an honest BAA, every pilot, and all revenue.
  1. IMAGING DOES NOT WORK, disabled twice over. It discusses a typed report; it never sees an image.
  1. LLM OUTPUT IS NON-DETERMINISTIC AND A CODING ANSWER MUST BE AUDITABLE. The gates are deterministic; the answer is not, and the answer is the product. Coding belongs in a rules engine; the shipped architecture inverts that.
  1. THE ADVERTISED LANE'S UNIT ECONOMICS ARE UPSIDE-DOWN: the six-physician case shows benefit below software cost.
  1. NOTHING IS MEASURED - no eval set, no accuracy, no frontier-model baseline.
  1. ONE ENGINEER, FIVE PILLARS; this pillar has the least server-side code.
  1. GOLD and GINA are copyrighted; the corpus may need an uncosted licence.
04

Regulation, liability and data

Regulatory posture

THE TWO-LANE DISCIPLINE IS THE BEST THING HERE. It needs sharper reasoning than the marketing carries.

LANE 1 - reimbursement, and why it is not a device. The exclusion is FD&C Act section 520(o)(1)(B), added by 21st Century Cures section 3060: software for administrative support of a health care facility, including billing and claims processing, is not a device. Drafting a necessity note, checking an NCCI edit and drafting an appeal citing a documented diagnosis sit inside it. Two conditions keep it there, both enforced in code rather than copy: never assert a diagnosis, only attribute one to the record (the non_diagnostic gate); and require human review and signature before filing (the human_in_the_loop gate). That a failed gate withholds output entirely converts a policy statement into an engineering control - the strongest verified diligence answer Ardia has.

WHY THE CDS EXCLUSION IS NOT AVAILABLE. PulmoIQ should never lean on section 520(o)(1)(E). Prong (i) excludes software analysing a signal from a signal acquisition system, and a spirometer produces exactly that. FDA's September 2022 CDS guidance narrowed the independent-review prong so tightly that an opaque risk score does not qualify. Routing prediction through a 510(k) rather than arguing CDS is legally correct.

LANE 2 - the gated lane. Interpreting a PFT or predicting an exacerbation is Class II SaMD; see 21 CFR 868.1840 and 868.1890. Predicates already exist, helping the pathway and hurting differentiation. Budget 18-36 months and low-single-digit millions. CLIA does not touch spirometry, DLCO or polysomnography; arterial blood gas is the exception.

HIPAA: Ardia becomes a Business Associate the moment PHI flows, and the conduit exception does not cover content analysis. Two BAAs are required, not one - practice and model provider - and neither exists. Control matrix self-graded 2 of 15. Texas SB 1188 imposes data residency, AI disclosure and practitioner review; TRAIGA adds intent-based prohibitions, AG enforcement with a cure period, and a sandbox worth investigating.

When it is wrong, who is holding the bag

"Non-diagnostic" does not dissolve liability. It moves it from FDA to CMS, OIG and contract law, which for a lab-adjacent billing product is the harder surface, not the easier one.

Trace the harm pathway. PulmoIQ drafts a medical-necessity narrative or a redetermination letter. All six gates pass - they check posture, not truth. No gate verifies that a cited policy is current, that a cited PMID supports the proposition it is attached to, or that the CPT-to-ICD-10 linkage is the one the MAC actually covers. A human biller signs the redetermination, and that signature attests the submission is true and complete. If the citation is wrong, stale or misapplied, the false statement is now the signer's, made to a federal payer.

That is False Claims Act territory, with knowledge-standard exposure where a pattern of unverified AI-drafted appeals could be characterised as reckless disregard. It is also OIG territory: urine drug testing is a named OIG enforcement priority, and the same engine path that drafts a pulmonary appeal drafts a toxicology one. Payers have begun flagging AI-drafted appeals; a template signature invites scrutiny of the whole batch.

The practical blocker sits earlier. A lab or practice compliance officer running a seven-element compliance programme must be able to say the tool was validated, its outputs are auditable and its errors are monitored. PulmoIQ has no eval set, no accuracy number, a non-pinned model that can change silently, and non-deterministic output. Honestly briefed, a competent compliance officer cannot approve it into the appeal workflow.

And indemnification sits nowhere. Ardia has never written a customer contract - no limitation of liability, no indemnity, no warranty disclaimer, no AI-specific carve-out, no insurance. There is no tech E&O or cyber policy on file. The first customer contract will be negotiated by a party with counsel against a company that has none, and the default position for a $0-revenue vendor is unlimited exposure it cannot fund.

What data it needs to be validated

What is needed to move PulmoIQ from demo to evidence, cheapest first. The ordering matters more than anything else in this dossier, because there is one engineer and no capital.

TIER 0 - FREE, NO AGREEMENT, AVAILABLE THIS WEEK. The CMS Physician and Other Practitioners Public Use File and the Part B National Summary Data File give provider-level volumes and allowed amounts for the 94xxx and 95xxx codes at zero cost, converting market sizing from arm-waving into arithmetic. Add the quarterly NCCI PTP and MUE files, the MPFS payment files, the OPPS addendum for facility sleep codes, the CARC/RARC code lists, and the three national NCDs. All downloadable, deterministic, unit-testable, and no lawyer required.

TIER 1 - DE-IDENTIFIED CLAIMS FROM A BILLING PARTNER. Under 45 CFR 164.514(b) expert determination or Safe Harbor, a corpus of paired 837P/835 pulmonary claim lines is not PHI and needs a data-use agreement rather than a BAA - a materially shorter legal path. Target 20,000-50,000 pulmonary lines over twelve months, yielding roughly 2,000-5,000 denied lines with adjudicated outcomes. That is enough for a real denial taxonomy, a held-out test set and the first honest accuracy number this module has ever had. Caveat that must not be skipped: Ardia cannot itself perform the de-identification to that standard today, so the partner or a qualified third party must, and it must be documented.

TIER 2 - CMS Limited Data Set via ResDAC under a DUA if no partner materialises. Real cost, months of turnaround, and an LDS retains dates and geography so it is not de-identified data. Pursue only if Tier 1 fails.

TIER 3 - PHI under two BAAs for a pilot. The second BAA, with the model provider, is the item nobody has flagged and it gates the whole pilot.

TIER 4 - the prediction lane: thousands of patients, hundreds of adjudicated events, IRB approval, a locked model. Series A work, correctly deferred.

05

The business around it

Market & economics

Disease burden is context, not TAM. PulmoIQ does not touch treatment cost; it touches billing accuracy on a narrow slice of it. Any prevalence figure used in a deck needs a named source and year.

THE TAM THAT MATTERS, bottom-up, assumptions labelled as assumptions. US pulmonologists number roughly 12,000-14,000 (figure requires sourcing). At $500 per provider per month the entire seat market is about $84M a year; at ten percent penetration, roughly $8M. AASM-accredited sleep centres number in the low thousands; at $1,500 per site per month across 2,500 sites, about $45M a year, or $4.5M at ten percent. Hospital service lines and IDTFs might add $50-100M of theoretical seat value. Total serviceable US market: credibly $150M-$250M, not billions, implying a $10-25M revenue business at maturity.

That carries a strategic conclusion an investor will reach anyway, so say it first: PulmoIQ is a wedge and a cross-pillar feature, not a standalone venture-scale company. Its value to Ardia is that it shares an engine path with Meridian and a patient with Aria.

THE ROI ARITHMETIC, DONE TWICE, because the first one fails. A six-physician group with an in-office PFT lab: assume 12,000 billable PFT lines a year, an eleven percent initial denial rate, and roughly $50 average allowable - about $66,000 of annual exposure. Assume half are appealable and sixty percent of those are recovered, plus avoided rework labour: roughly $30,000 of annual benefit against $36,000 of software at $500 per provider per month. The deal does not close. This is the most important economic finding in the module: per-claim PFT reimbursement is too small to support an appeals-based per-seat model. A sleep centre running 1,200 studies a year at a materially higher realised amount per study inverts that arithmetic. The strategic redirect is explicit - lead with the sleep lab and the pulmonary rehabilitation programme, not the spirometry room. Every input above is an assumption, not observed data.

Price, cost and margin

One model, chosen and defended: per-site subscription, $1,500 per month per sleep centre or per pulmonary-rehabilitation programme, $18,000 a year, annual term, no contingency and no per-claim fee. Contingency is rejected outright - twenty percent of a recovered fifty-dollar spirometry line is ten dollars, which does not cover the human review the gates require. Per-seat pricing is rejected because the six-physician arithmetic is upside-down. Per-site is chosen because it prices to the denominator that carries real dollars per encounter and because it is defensible without PHI-dependent recovery accounting Ardia cannot audit.

COST TO SERVE. Gemini Flash-Lite list pricing is roughly $0.10 per million input tokens and $0.40 per million output (approximate; verify against current published rates). A grounded call runs about 3,000 input and 1,000 output tokens: roughly $0.0007, well under a tenth of a cent. Scholar tier on Flash costs several times that and is still under a cent. At twenty calls a day a site consumes about 600 calls a month - under one dollar of inference against $1,500 of revenue. Inference gross margin exceeds 99%. Inference is not the cost. Real COGS is human support, coder-in-the-loop review during onboarding, and quarterly NCCI, MPFS and LCD corpus maintenance - realistically $200-400 per site per month at small scale, so a defensible steady-state gross margin near 75%.

BUYER ARITHMETIC, expressed as required effect size rather than promised savings, because the effect size is unmeasured. At $18,000 a year against a realised amount per sleep study in the high hundreds, breakeven is roughly 21 additional studies paid per year. For a centre running 1,200 studies, that is under two percent. Anything above that is return. State it exactly that way to a buyer: this is what the tool must do to be worth its price. Whether it does is the open question the evaluation is designed to answer, and the same 1.8% threshold is the pricing kill criterion.

Competition & honest differentiation

Named, real, and mostly ahead.

GENERAL RCM AND DENIALS AI, any of which could add a pulmonary edit pack in a sprint: Optum, which owns Change Healthcare and therefore sees the 835s; Solventum, the incumbent in hospital coding; Nuance; Waystar; Experian Health; Availity; R1 RCM; Ensemble; Infinx; Rivet. None will bother until the segment is proven, which is the only window this module has.

AUTONOMOUS CODING, well funded and shipping with published accuracy at named health systems: CodaMetrix, Nym Health, Fathom, SmarterDx. They are the standard PulmoIQ gets measured against the moment anyone asks how accurate it is. Today's answer: unmeasured.

PRIOR AUTH AND MEDICAL NECESSITY: Cohere Health, Anterior, Basys.ai. Cohere has already done the thing PulmoIQ describes - encode criteria and adjudicate necessity - with real payer contracts.

PULMONARY-SPECIFIC, where the direct threat lives: ArtiQ ships cleared automated pulmonary-function interpretation; EnsoData ships cleared AI polysomnography scoring in hundreds of sleep labs; Somnoware sells sleep-lab workflow plus billing into precisely the buyer this module's economics point to. Add the PFT device incumbents and the home-spirometry and inhaler-adherence vendors.

GUIDELINE RETRIEVAL: UpToDate, Elsevier ClinicalKey AI, OpenEvidence, Atropos. If the pitch is retrieve GOLD/GINA and cite it, these companies have already won that, with licensed content Ardia does not have and has not begun negotiating.

AND THE COMPETITOR NOBODY LISTS: an unmodified frontier model. A biller with a $20-a-month subscription plausibly gets a comparable answer. Nobody has tested this. Until PulmoIQ retrieves something a general model cannot - the MAC-specific policy, the current quarter's NCCI table, the practice's own denial history - there is no product.

HONEST DIFFERENTIATION, narrow but real: deterministic gates that withhold output on failure, verified in production, with the ledger returned to the caller; the code-enforced two-lane FDA discipline, stated publicly before anyone forced it; and cross-pillar reach into elder care. Absent: any data, accuracy, distribution, evidence or regulatory asset.

06

Where it goes next

Roadmap and the one unlock

Sequenced, with the unlock named. This reorders the published plan, which spends scarce engineering hours on the wrong things.

WEEK 1 - HONESTY REPAIRS, hours not days, before the next investor conversation. Relabel any scripted Studio trace as illustrative rather than live. Reconcile the two status labels the site carries and settle on modelled target, running via the shared TARA engine. State the shared engine path on the PulmoIQ page itself - saying it first beats being caught. Clean the stale eight-gate docstring. Either register pulmo as a real server-side key, or stop calling it a model.

WEEKS 2-6 - THE DETERMINISTIC ENGINE, on free public data, no BAA, no partner, no lawyer. Fix the code-matching regex so 9xxxx CPT codes can match at all. Load NCD 240.2, 240.4 and 240.4.1 with the discipline used for MolDX. Hand-verify pulmonary and sleep LCDs for the largest MAC jurisdictions. Ingest the quarterly NCCI PTP and MUE files for the 94xxx/95xxx range and ship a unit-tested, LLM-free bundling checker - the first thing PulmoIQ could legitimately call measured. Write a deterministic 835 parser. Pin the model id and stand up a regression suite across all four engine paths.

MONTHS 2-5 - THE DATASET, the real unlock. Sign one pulmonary or sleep billing company to supply a de-identified 837/835 corpus under a DUA. Build the held-out eval set. Publish the first accuracy number, benchmarked against a frontier model, even if unflattering.

MONTHS 4-9 - REPOSITION THE ECONOMICS. Lead with sleep centres and pulmonary rehabilitation, add care-management codes, position against the January 2027 FHIR prior-auth deadline.

MONTHS 6-12 - Fix Sentinel's name detection before any BAA conversation. Start both BAAs in parallel. Move the matrix off 2 of 15.

THE SINGLE HIGHEST-LEVERAGE ACTION: one de-identified corpus from one billing partner. No BAA, no IRB, no capital - and it produces the taxonomy, the eval set, the first measured number and the design partner at once.

07

Risks and open questions

Risk register

  • SHARED-ENGINE REGRESSION, the strongest technical risk in the company: PulmoIQ, Meridian and (via molec) ToxIQ ride four engine paths for ten named models, with no per-persona regression suite and no eval harness. One prompt change or one silent model roll degrades three products at once, undetected.
  • UNPINNED MODEL ID: the served model resolves a "-latest" alias, so Google can roll the model forward with no version change and no changelog. Output that would enter a CMS redetermination is not reproducible - a governance defect, not a nuance.
  • MISREPRESENTATION RISK: any Studio trace that animates tool calls PulmoIQ does not make (air-quality lookups, GOLD retrieval, NCCI checks) is FTC Section 5 deceptive-advertising exposure and a diligence-credibility bomb. Relabel it 'illustrative - scripted' before the next demo.
  • CLAIM-vs-CODE GAP: presenting unbuilt data fusion (FHIR, HealthKit/Health Connect, home spirometry, air-quality feeds) in the present tense is the fastest way to lose a technical diligence. Zero of them are implemented.
  • GROUNDING MISMATCH: pulmonary answers are grounded in PubMed literature, not coverage policy. The curated LCD corpus holds zero pulmonary policies and there is no curated GOLD/GINA corpus. A biller asking what their MAC pays gets literature, which does not answer the question.
  • DE-IDENTIFICATION FAILURE ON NAMES: Sentinel does not reliably redact plain personal names. For a module whose intended input is a clinical note, this blocks an honest BAA, which blocks every pilot, which blocks all revenue.
  • DOUBLE-BAA BLOCKER: a pilot needs two BAAs - the design partner and the model provider - and neither exists. The second is not on the published plan.
  • LIABILITY WITHOUT INDEMNIFICATION: Ardia has never written a customer contract. No limitation of liability, no indemnity, no warranty disclaimer, no tech E&O or cyber cover, against False Claims Act and OIG exposure that lands on the signer and, contractually, could land on Ardia.
  • UNIT-ECONOMICS INVERSION: the six-physician appeals case shows roughly $30k of modelled benefit against $36k of software. The advertised lane loses money for the buyer as scoped.
  • NON-DETERMINISM IN AN AUDITABLE DOMAIN: a coding recommendation that varies between identical runs cannot be defended to a MAC auditor. The gates are deterministic; the answer is not, and the answer is the product.
  • NO BASELINE, NO MEASUREMENT: nobody has tested whether PulmoIQ beats an unmodified frontier model on any pulmonary task. Until retrieval provides something a general model lacks, there is no product.
  • COPYRIGHT ON THE GUIDELINE CORPUS: GOLD and GINA are copyrighted; commercial retrieval requires a licence negotiation that has not started and is not budgeted.
  • COMPETITIVE PRE-EMPTION IN THE GATED LANE: cleared automated PFT interpretation and cleared AI polysomnography scoring already exist in production. A 2027-2028 510(k) arrives after the predicates and the incumbents.
  • OPERATIONAL FRAGILITY: one synchronous serverless function, a 6,000-character cap, no queue, no retry, no job model. Adequate for a demo; nowhere near batch 835 processing or sub-second CDS Hooks.
  • IMAGING IS ADVERTISED-ADJACENT AND DEAD: uploads are disabled at the API and discarded in the browser. Any implication that PulmoIQ reads chest imaging is false.
  • KEY-PERSON AND ATTENTION RISK: one engineer across five pillars, and this is the pillar with the least server-side code - evidence it is losing the internal competition for hours.
  • MARKET-SIZE RISK: bottom-up, roughly $150M-$250M of serviceable US seat value, implying a $10-25M business at maturity. PulmoIQ is a wedge and a cross-pillar feature, not a standalone venture-scale company, and should be pitched that way first.

Open questions — decisions still to make

  • Is PulmoIQ a product or a positioning surface? If it stays a browser label over TARA, say so publicly and pitch it as cross-pillar leverage. If it is meant to be a product, register a real server-side 'pulmo' model with a pulmonary system prompt and a pulmonary corpus. The current middle position - marketed as a model, returning bad_model on the API - is the worst of both.
  • Which Google endpoint does production actually call - a HIPAA-eligible enterprise endpoint under a Google Cloud BAA, or the consumer AI Studio API? This single fact determines whether a PHI pilot is three months or twelve months away, and it can be answered today.
  • Will the model id be pinned, and will a regression suite be built across all four engine paths before any further feature work? Without it, every product on the TARA path is one silent roll away from a quality change nobody sees.
  • Spirometry room or sleep lab? The ROI arithmetic says the sleep centre closes and the pulmonology PFT lab does not. Is the founder willing to lead with sleep and pulmonary rehabilitation rather than the spirometry story the site currently tells?
  • Can one pulmonary or sleep billing company be persuaded to supply a de-identified 837/835 corpus under expert determination - a DUA, not a BAA? This is the single highest-leverage unblocked action available, and everything measurable depends on it.
  • Should the deterministic NCCI/MUE checker ship BEFORE any further LLM work? It is free public data, unit-testable, would give PulmoIQ its first genuinely measured claim, and it contradicts the current architecture in which the LLM does the coding.
  • Will GOLD and GINA grant a commercial retrieval licence, or should the corpus be rebuilt from public-domain CMS policy (NCD 240.2/240.4/240.4.1, MAC LCDs, NCCI, MUE) plus primary literature - free, safer, and arguably more useful for the reimbursement lane?
  • Does Sentinel's name gap get fixed with NER, a curated name list, or by never accepting free-text notes at all? The last option is cheapest and may be the right product decision.
  • Is the prediction lane worth keeping on the roadmap, given cleared competitors already hold that ground? A reseller or partnership may deliver the capability years earlier at a fraction of the cost.
  • Who drafts the first customer contract, and what limitation of liability, indemnity and AI-specific disclaimer will Ardia insist on? Related: does Ardia buy tech E&O cover before the first pilot, and at what price?
  • Should CMS-0057-F and HL7 Da Vinci CRD/DTR become the explicit technical strategy? It is a dated regulatory tailwind aimed exactly at PulmoIQ's stated job, and the current positioning ignores it.
  • Is the payer-side thesis - HEDIS SPR/PCE/AMR gap closure and HCC capture for J44.x - a bigger business than provider-side appeals? Larger cheque, longer sale, and absent from the current framing.
  • Who owns the reputational fix for any scripted Studio trace, and when does it ship? It is hours of work and the highest-severity item on this list.

The other 360° views