Ventures · Blog

Start With the Bill

Working out the theory of the successful patient-agency company

Marcus A. Thomas

For twenty years, patient-owned health data companies have failed, and the purest "own your data" version has never scaled at all. The reason is an ordering the usual post-mortem hides: agency can't be the first thing a business monetizes. It has to attach to a trusted, computable object that already sits inside a workflow with its own urgency and budget. The medical bill is that object: the one place where a person's crisis and an employer's budget point at the same data, already computable and already theirs to direct.

The graveyard

Patient-oriented health data companies fail at a rate that has nothing to do with the quality of their ideas. Personal health records, consented-data platforms, patient data networks, health record banks: for two decades they have been discontinued, acquired below their ambition, or quietly stalled. Google Health and Microsoft HealthVault had platform-scale backing and were shut down anyway.1 LunaDNA gave people literal ownership shares in exchange for their data and wound down without ever building the demand ownership was supposed to unlock.2 23andMe assembled one of the largest consumer genomic datasets in the world, went bankrupt, and the governance of all that data turned out to be whatever a bankruptcy court said it was.3

The usual post-mortem lists the causes: trust, regulation, business model, interoperability. The list is right. What bothers me is that it’s unordered, and I’ve come to think the ordering is the whole thing. There’s a second fact I can’t explain away. The purest version of the idea has the individual as sole principal and the firm as a neutral custodian, brokering access on the person’s behalf the way a bank holds money. As far as I can tell, no one has ever built that version at durable scale.4 That absence is the finding. It’s most of why the data economy hasn’t reorganized around individual agency, and any theory I’d trust has to account for it.

Three roles the word “patient” hides

Any data business assigns three roles, and there’s no law that they land on the same party. The principal governs the data: decides who gets it, for what, and can revoke. The supplier is the person the data is about. The paymaster funds the business. In an ordinary hospital data sale the provider is principal and supplier and the buyer is paymaster, and nobody’s confused about which is which.

The pure patient-agency model collapses all three onto the individual at once. The patient governs the data and supplies it. In the versions that hurt most, the health record banks that made people pay to keep custody of their own records, the patient is asked to fund the whole thing too. Separate the roles and you can see exactly where it breaks. The patient is a fine principal and a fine supplier, and a terrible paymaster. The need is episodic and the benefit indirect, so a business running on the patient’s money has no engine. “Own your health data” names no job to be done this week, and money doesn’t attach to a mission statement.

The first requirement is negative: get the paymaster off the patient. Leave the individual as principal and supplier, where those roles actually work, and find the money where the money already is.

The prohibition

Patient agency cannot be the first thing a business monetizes. The first monetizable object has to be a trusted, computable state object: some representation of clinical or financial reality that a real workflow can query and transact against. And that object has to sit inside a workflow that already has urgency, a budget, and institutional users. Only then does agency become economically useful as well as ethically attractive. Agency can be the constitutional principle of the company from day one; what it can’t be is the thing the business stands on. It’s inert except as a governance layer over something already transactable.

As a prohibition this forbids something specific, which is what lets it be wrong: nobody durably monetizes patient-governed health state with the patient as paymaster, and nobody does it with the buyer as paymaster either, unless a trusted, computable substrate exists first. That’s a standing bet against every consented-data marketplace that ran on consent alone, and every personal-record business that asked the patient to fund custody.

There is a rival explanation, boring and strong: consumer health is just a bad business. Low frequency, high stress, fragmented records, and the budget and urgency both sit with the institution rather than the person. If that’s the whole story, my talk of computable state is decoration and the only lesson is “sell to institutions.” The graveyard fits both readings. A company that led with agency and died is what my prohibition predicts, and it is also just a consumer-health company that died. The survivors don’t separate them either: the patient-mediated companies that lived drifted exactly where the boring reading says the money lives, toward life-sciences evidence generation, with agency demoted to an acquisition channel.5 History can’t decide it. The one thing that can is a prediction neither the graveyard nor the survivors test: that a trusted, computable substrate, built first, is what makes patient agency valuable on top of it. So the whole question becomes where that substrate comes from.

Where the bill meets urgency and budget

The prohibition wants a workflow with urgency and budget. My instinct was to look inside an institution, because “own your health data” names no job to be done this week. But that’s the trap in the phrasing. It’s true of health data in general. It is not true of one slice: the bill.

The financial side of care arrives as a mess: bills, the explanation-of-benefits statements insurers send after each claim, denials, deductibles, provider balances, pharmacy costs, payment plans, surprise charges. For anyone with real medical spend, that is no abstraction. It is acute and dollar-denominated, and it lands in the mailbox demanding answers to four questions: what happened, what do I owe, what can be challenged, and what help is there. That is a job to be done this week, and the urgency I thought lived only in the hospital is pointed straight at the individual.

The budget is sitting next to it. Employers pay a huge share of employee health costs and have a poor view of what employees go through inside the system. The facts are scattered across insurers, third-party administrators, pharmacy benefit managers, and providers, along with the employee’s own bills, and the employer leans on those same parties to summarize the data needed to judge them. Employers who self-fund their plans, paying claims out of their own pocket rather than buying insurance, carry fiduciary pressure to do better.6 Benefit design is an annual cycle with real money and a hard deadline. That is a standing institutional budget aimed, for once, at understanding and reducing what the individual actually experiences.

So the object I want is trusted, computable billing and benefits state: a durable record of care, cost, payment, denial, benefit use, and financial exposure that follows the person across providers, insurers, employers, and vendors. Built for the employee, turned under governance into aggregate evidence for the employer. And the three roles land where the theory says they have to: employee is principal and supplier, employer is paymaster, the patient never pays. The bill is the one place where the individual’s own crisis and an institution’s own budget point at the same object. I don’t have to borrow the workflow from the hospital; I can build it around the person.

Why the bill escapes the trap

The objection I take most seriously is one I’ve made myself. Patient-authorized aggregation has a signature failure: access without authority. The person can pull portals, PDFs, and feeds into a nice viewer, and none of it is computable state. Apple is the cleanest case: trust, distribution, privacy credibility, and patient-side aggregation at a scale nobody before reached, pulling clinical records onto the device under the person’s control.7 It is still a viewer over documents. It is not a canonical, queryable state that a market can transact against. The question is why employee-directed billing state isn’t the same failure in a benefits costume.

The answer is the claim I’m really betting the company on: adjudicated claims data is already computable in a way clinical narrative is not. A clinical record is document-centric. Making it computable means interpreting it at ingest, and that is the hard, trusted work that seems to require sitting inside the provider. A claim is different. Adjudication is the insurer’s own processing of the claim: deciding what was billed, what is allowed, what it paid, what the patient owes, and how the deductible applies, all recorded under standard codes with dates, provider identifiers, and denial reasons. By the time a claim exists, the payer has already done this work. It arrives structured. The interpretation burden is light, because the party with every incentive to get it exactly right, the one writing the check, already carried it.

And it’s reachable through the individual’s own rights. Federal rules now make regulated payers expose claims, encounter, and cost data to patients through third-party apps; newer rules add prior-authorization data; there are standard profiles for consumer-directed exchange of the explanation of benefits.8 The person has a right of access regardless. So I can assemble the substrate patient-side, from the individual’s own federally guaranteed access, without a provider in the critical path. This is the one domain where the data is both already computable and already the individual’s to direct. If claims reached through patient access turn out to be as messy and non-computable as clinical documents, the whole thing folds back into the viewer problem. That is the bet.

The employer as paymaster, without the surveillance

The account the employee holds does five things on day one, before any network exists, because they already have the raw material. It shows what was billed, allowed, and paid, and what they may owe. It flags mismatches between the bill and the explanation of benefits, along with duplicates and overcharges. It triages denials and helps appeal where there’s a real path. It tracks the deductible and out-of-pocket max. And it surfaces the employer benefits they’re entitled to and didn’t know to use. It’s a benefit for the employee first. And every reconciled bill, caught error, and unused benefit is, in aggregate, an unconflicted signal to the employer about where the plan is failing people.

Routing the money through the employer creates the adversary I most have to design against: the employer itself. The feared abuse is not sale to a data broker downstream. It is the use of health information in employment, promotion, discipline, compensation, and termination decisions. So the answer can’t be a promise; it has to be built in. Patient-level data moves only when the individual directs it. That covers anything shaped around one person, even after de-identification, because dates, diagnoses, and rare conditions still leave a person-shaped row. Without direct employee consent and direction, the employer gets thresholded, purpose-reviewed, aggregate answers to real benefit-design questions and nothing else: no raw export, minimum cell sizes, small-cohort suppression, query logging, a hard bar on employment use. De-identification is a risk control, not a license to hand out row-level data, and HIPAA’s de-identification standard is the floor this design sits above.9 The employee can see every source connected and every use their data was put to. That visible boundary is the product: it is what lets an employer improve benefits without building a surveillance tool.

The renewable cohort

The part I care about most sits one layer up, in activation. The platform surfaces unmet need in aggregate; an employer or benefit creator funds a program; the platform finds the eligible people inside the governed state layer, privately notifies them, records their choice, measures the outcome in aggregate. The sponsor never sees the eligible list. The person can ignore, decline, or accept, and identity and scoped records move only after they say yes.

This is the renewable cohort, and it’s the piece no static asset can copy. A de-identified extract is frozen: the people in it are gone as principals, and there is no one on the other end to re-contact. A provider-side platform can refresh the record, but the individual isn’t the governance subject and can’t be asked. Only a durable principal, someone who stays a real party with a standing consent channel, makes the group re-contactable. A buyer can come back for a new contribution under fresh consent without ever learning who anyone is. What finally convinced me that the agency isn’t decoration is that it constitutes the revenue: the thing a buyer pays extra for and the thing that makes the individual a principal are the same thing. That answer doesn’t depend on my choosing to be virtuous; it falls out of what the asset is.

Where I’m exposed

The employee account has to be worth paying for on its own. The bet is that a per-employee-per-month product, billing defense for the employee and benefit intelligence for the employer, clears its price before any network density exists. If the day-one value isn’t real, the network never forms and none of the rest matters. That is the bet most likely to be wrong, and the first one I have to prove.

Everything rests on one bet about adjudicated claims data: that when it’s reached through patient-access rights, it is computable and complete enough to defend a bill and feed benefit design. Payer feeds see adjudication but can miss the provider’s side of billing: balances, statements, payment plans, cash-pay charges. Provider billing feeds are uneven. If the accessible data is thinner than I need, the substrate is weaker than I’m claiming.

Moving the paymaster to the employer buys me a committed budget at the price of the surveillance adversary. The governance has to hold as a design rather than a policy, through acquisitions and control changes, or the trust the whole account depends on is gone in one bad headline.

None of these is fatal, and all of them are things a live company tells me rather than a memo settles. Which is the point of building it instead of only arguing about it.

From the bill to everything

Billing is the beachhead because it is the easy case: natively computable, natively the individual’s to direct. It isn’t the ceiling. As the account earns trust and the network fills in, the same governed, employee-controlled state can widen from billing to the rest: clinical records, labs, images, the longitudinal picture. And that’s what changes what the renewable cohort is worth. Once the substrate is full clinical state under durable individual governance, the cohort matters to the buyers who pay the most for it: life-sciences and real-world evidence, where a re-contactable, consent-renewable, phenotyped cohort is worth far more than a frozen extract.

That is what the ordering buys. Agency was never the thing to monetize first. Sequenced after the substrate, it is what makes the asset renewable. And the sequence starts with the bill.

Footnotes

  1. Google discontinued Google Health in 2011, citing an inability to scale adoption beyond tech-enthusiast users; Microsoft HealthVault shut down in November 2019. Both had platform-scale backing and still could not turn a patient-controlled record container into durable behavior.

  2. LunaDNA offered contributors equity — ownership shares in the company, via an SEC-qualified offering — in exchange for their data, and wound down in 2024. The mechanism granted ownership without ever creating the aggregated, phenotyped, buyer-relevant demand that would have made the data worth owning.

  3. 23andMe’s 2025 bankruptcy put governance of one of the largest consumer genomic datasets in the hands of the bankruptcy process, making concrete the risk that consumer-genomics consent is only as durable as the company’s solvency.

  4. Health record banks, health data cooperatives, the “bank of individuals’ data,” and personal health data spaces are described across a decade of literature as necessary and promising, and each remains conceptual or pilot-stage. See e.g. Hafen, Kossmann & Brand, “Health Data Cooperatives — Citizen Empowerment,” Methods of Information in Medicine 53 (2014).

  5. PicnicHealth collects and structures patient-mediated records for real-world evidence and moved further toward life-sciences evidence generation with its acquisition of AllStripes; Human API ended inside LexisNexis Risk Solutions, where consent became a smoother ingestion layer for underwriting. Both are the predicted shape of survival: agency demoted to an acquisition channel where institutional budgets already sit.

  6. The U.S. Department of Labor holds that many employers sponsoring self-funded or partially self-funded group health plans exercise discretionary authority and are therefore fiduciaries, depending on plan structure and function — a source of real pressure to evaluate benefits on better evidence than vendor self-reports.

  7. Apple’s Health Records on iPhone lets users authenticate to participating health systems and pull clinical records onto the device under individual control — patient-side aggregation at real scale, but a governed viewer over documents rather than a canonical, queryable clinical state with a buyer-facing query engine.

  8. CMS’s Interoperability and Patient Access rule requires regulated payers to expose claims, encounter, and cost data to patients through third-party applications; CMS-0057-F adds prior-authorization data for impacted payers; and HL7’s CARIN Consumer Directed Payer Data Exchange defines the explanation-of-benefits profiles for consumer-directed claims exchange. Counsel should perform a full legal analysis before any launch; this is the direction of the plumbing, not legal advice.

  9. HHS guidance holds that the HIPAA Privacy Rule does not restrict use or disclosure of de-identified data, and describes de-identification via Expert Determination and Safe Harbor. The point here is the opposite of reassuring: de-identification lowers risk but does not convert a person-shaped row into a third-party asset, so the governing rule stays patient-direction, and the design sits deliberately above this floor.