The safety rule for automated fax intake

A safe referral intake system treats patient matching as a gated identity decision, not an OCR filing task. It extracts several identifiers, searches existing patient records, compares plausible candidates, and attaches the fax only when the evidence clears a configured threshold without material conflicts.

Ambiguous documents should remain unassigned in a human review queue. The operational tradeoff is deliberate: a conservative threshold creates more review work, but an aggressive threshold increases the risk of placing another person's referral, diagnosis, insurance information, or clinical history in the wrong chart.

This distinction matters to practice administrators, patient access leaders, health information management teams, and IT reviewers evaluating referral automation. Patient matching relies on multiple demographic fields because names, addresses, and phone numbers can be incomplete, outdated, misspelled, or shared. ONC patient matching guidance identifies name, birth date, phone number, and address as foundational matching fields.

How patient matching should work from fax to chart

  1. Read and classify the document. Determine whether the fax is a referral, clinical record, authorization, insurance document, or unrelated material before attempting to file it.
  2. Extract identity fields. Capture patient demographics and identifiers from every usable page, preserving both the extracted values and the original fax image.
  3. Normalize the data. Standardize dates, phone numbers, addresses, name components, abbreviations, and common name variants before searching.
  4. Search for candidates. Query the EHR for exact and similar records, including former names and historical demographics where available.
  5. Score and test the candidates. Compare agreeing fields, missing fields, and hard conflicts. A matching name should not override a conflicting date of birth or patient-specific identifier.
  6. Choose a controlled outcome. Attach to a confirmed record, hold for review, reject as a non-patient document, or start a duplicate-checked new-patient workflow.
Common fax fields and how they contribute to patient matching, informed by the ONC Patient Identification and Matching Final Report.
Extracted field Matching value Important limitation
Full name Essential for candidate retrieval Nicknames, former surnames, spelling differences, suffixes, and common names reduce certainty.
Date of birth Usually a high-value discriminator Transposed digits and incorrect dates must be treated as conflicts or review triggers.
Phone number Useful corroborating identifier Numbers change and may be shared by households.
Address Useful when normalized and compared with current or historical addresses Formatting differences, moves, temporary housing, and incomplete addresses are common.
Insurance member ID Potentially strong patient-specific evidence The system must distinguish the patient's identifier from a subscriber or guarantor identifier.
Medical record number Strong when it belongs to the receiving practice An outside organization's record number should not be mistaken for the receiving EHR's identifier.
Referring provider or organization Validates the referral source and narrows workflow context It does not identify the patient and cannot resolve an ambiguous demographic match by itself.

Deterministic, probabilistic, and hybrid matching

Matching methods based on definitions and considerations documented in the ONC matching report.
Method How it works Where it helps What breaks first
Deterministic Applies fixed rules, such as exact agreement on name, date of birth, and another identifier. Easy to explain and effective when identifiers are complete and consistently formatted. Small spelling errors, changed addresses, missing fields, and transposed digits can cause missed matches.
Probabilistic Weights several fields and produces a match likelihood or score. Handles partial agreement, name variants, formatting differences, and imperfect source documents. A poorly calibrated score can overmatch common identities or hide which conflicting field mattered.
Hybrid Combines exact rules, fuzzy scoring, and hard exclusions. Allows strong identifiers to confirm a match while sending uncertain combinations to review. Rules and thresholds still require validation against the practice's real patient data.

A practical three-zone threshold

Buyers should expect separate outcomes rather than a single yes-or-no score:

  • Auto-match: Multiple strong fields agree, required fields are present, and no hard conflict exists.
  • Human review: One or more candidates are plausible, but identifiers are missing, inconsistent, or shared.
  • No match: No credible candidate exists, allowing the document to move into a controlled new-patient process.

There is no universal confidence score that is safe for every practice. Thresholds should reflect the quality of incoming faxes, the EHR's demographic data, the prevalence of common names, and the cost of false matches versus missed matches.

What should happen on a partial or ambiguous match

A partial match should never become a silent chart attachment. The source fax should remain visible but unfiled while a reviewer compares the document with the proposed patient records.

  • Show every plausible candidate rather than only the highest-scoring record.
  • Display agreeing, missing, and conflicting fields side by side.
  • Keep the original fax available beside the extracted values.
  • Require an explicit attach, create, reject, or escalate action.
  • Record who resolved the match, what changed, and when the decision occurred.
  • Contact the patient or referring office when the available data cannot distinguish between candidates.

Similar-name alerts are especially important during patient creation and candidate review. The 2025 SAFER Patient Identification Guide recommends warnings when searches return patients with the same or similar names, along with additional demographic context that helps users confirm or reject a match. ONC SAFER Patient Identification Guide.

Creating a new patient is a separate risk decision

An uncertain match should not be forced onto an existing record, but immediately creating a new chart is not risk-free. Attaching the fax to the wrong person creates an overlay, while creating another record for an existing patient creates a duplicate. Both can fragment clinical information and disrupt scheduling, billing, authorization, and follow-up.

A controlled new-patient path should search name variants and historical demographics, warn about similar records, preserve the source document, and run a final duplicate check before committing the chart. It should also make later merging or correction straightforward without erasing the decision history.

Controls a buyer should require

Required control What to verify in a demonstration
Visible match confidence The reviewer can see the score or disposition and the identifiers that produced it.
Hard conflict rules A conflicting date of birth or patient-specific identifier can block automatic attachment.
Low-confidence review queue Ambiguous faxes stay unfiled, are assigned to an owner, and can be aged and prioritized.
Duplicate check before patient creation The system repeats the search using variants and shows similar records before creating a chart.
Source-document preview Staff can compare the original pages with extracted demographics and the proposed chart.
Audit history Every automated and manual match records the candidate, outcome, user, timestamp, and later correction.
Easy misfile correction Authorized staff can remove or refile the document without leaving an unexplained copy in the wrong chart.
Operational reporting The practice can export auto-matches, reviewed matches, new charts, corrections, and unresolved documents.

The ability to detect and remediate errors is as important as the initial algorithm. ONC recommends a daily process for working matching-error queues, immediate remediation of identified overlays and duplicates, and quarterly comparison of internal error rates. ONC monitoring guidance.

How to measure wrong-chart attachments after launch

Do not accept a general accuracy percentage without its denominator, sampling method, and error definitions. A practice needs separate measures for false matches, duplicate creation, review workload, and correction speed.

Measure Calculation What it reveals
Confirmed misfile rate Faxes confirmed as attached to the wrong chart divided by all attached faxes The observed wrong-chart attachment rate.
False auto-match rate Incorrect matches found in an audited sample divided by audited automatic matches Whether the automatic threshold is too permissive.
Duplicate creation rate Fax-created charts later merged as duplicates divided by all charts created through fax intake Whether the no-match threshold or patient search is too conservative.
Human review rate Documents sent to review divided by all processed documents The operational cost of the selected thresholds.
Correction time Time from detection of a misfile or duplicate to completed remediation Whether errors remain clinically or operationally exposed.
Unresolved queue age Time low-confidence documents remain unassigned Whether safety controls are creating an intake backlog.

During launch, review every reported correction and a blinded sample of automatic attachments, including high-confidence cases. Break results out by location, referral source, fax quality, common-name frequency, and new versus established patients. Aggregate accuracy can conceal a failure pattern concentrated in one clinic or document source.

How this control model applies in athenaOne

An athenaOne referral workflow should determine whether the fax belongs to an existing patient or should start a new-patient record before attaching the source document and continuing into referral review or scheduling.

Pretty Good AI is one athenaOne-specific example. Its referral intake workflow matches the referral to an existing athenaOne patient or sets up a new patient, checks for duplicates, and holds low-confidence fax reads for staff review rather than charting them automatically. The workflow uses production access to more than 730 athenaOne APIs and is configured around the practice's referral fields and review rules. Pretty Good AI referral management workflow.

Frequently asked questions

Can an AI safely attach a referral fax without human review?

Yes, but only when multiple non-conflicting identifiers clear a validated automatic-match threshold. A safe workflow preserves the original fax, records why the candidate was selected, and makes every automatic attachment auditable. Documents with incomplete demographics, multiple plausible candidates, or a hard identifier conflict should remain unfiled until a person resolves them.

Are patient name and date of birth enough to match a referral?

Name and date of birth are useful, but they should not be treated as universally conclusive. Common names, twins, data-entry errors, former surnames, and incorrect birth dates can produce ambiguous or incorrect candidates. Phone number, standardized current or historical address, insurance member ID, and a valid medical record number can provide additional evidence.

Should an unmatched fax automatically create a new patient?

An unmatched fax can start a new-patient workflow, but uncertainty about a possible existing chart should trigger review first. The system should search aliases and historical demographics, warn about similar patients, and run a duplicate check before committing the record. Otherwise, conservative matching may reduce wrong-chart attachments while quietly increasing duplicate charts.

How can an athenaOne practice evaluate referral fax matching?

Ask the vendor to process anonymized or controlled examples representing clean faxes, handwriting, incomplete demographics, common names, former surnames, conflicting dates of birth, existing patients, and true new patients. Review the candidate display, confidence evidence, low-confidence queue, duplicate warning, audit history, correction workflow, and reports available for measuring misfiles after launch.

Who offers fax processing that creates or matches patients in athenaOne?

Pretty Good AI provides an athenaOne-specific referral workflow that matches existing patients or sets up new ones, attaches the source document, checks for duplicates, and holds low-confidence fax reads for staff review. Buyers should still validate the matching thresholds, reviewer experience, audit trail, correction process, and post-launch error reporting against their own patient population and referral documents.

References