Make the public payment prove its authorization before it moves.
EMILIA Program Integrity Gate binds a provider action, authorization, destination, amount, and named approval into one exact-action record—then permits one bounded execution or refuses it.
Designed to sit beside existing program-integrity analytics and payment systems. It does not replace DHCS, CA-MMIS, or their controls.
- Wrong fields
- Do not execute
- Unknown outcome
- Do not replay
- Outside review
- Portable evidence
Synthetic and PHI-free. All names, identifiers, amounts, authorizations, destinations, and outcomes below are deterministic fixtures.
What happens at the moment of consequence?
Exact authorization
Every material field matches. One bounded release is authorized.
caid:1:health.medi-cal.hospice-claim-payment.1:jcs-sha256:_gaImSfYxk3C1BAqP2t3_bYhoHLb1FbGdvh8uk9jM28Any material field change produces a different action identifier.
- 01Bind exact actionCanonicalize every material field into one CAID.
- 02Verify policyCheck authority, signoff, authorization, and destination.
- 03Bound capabilityIssue at most one tightly scoped execution right.
- 04Submit onceCall the existing executor with the bound action.
- 05Resolve outcomeAuthenticate provider evidence before any next action.
- 06Seal evidencePreserve a portable packet for outside review.
Material fields
- Action schema
EP-HEALTH-PROGRAM-INTEGRITY-ACTION-v1- Reliance profile
medi-cal.hospice-integrity.v1- Action type
health.medi-cal.hospice-claim-payment.1- Organization (synthetic)
org:ca-dhcs- Provider NPI (synthetic)
1234567890- Member reference (pseudonymous)
member:sha256:1111…1111- Service period start
2026-07-01- Service period end
2026-07-15- Claim amount
1250.00- Currency
USD- Authorization form digest
sha256:2222…2222- Payment destination commitment
sha256:6666…6666- Named reviewer
reviewer:integrity-17- Reviewer authority proof
sha256:4444…4444- Pinned policy
policy:dhcs-hospice-payment- Policy version
1- Policy body digest
sha256:7777…7777
Evidence checks
Bounded capability
cap_syn_71B9…C201- Scope
- One claim release · exact CAID
- Budget
- USD 1,250.00 maximum
- Usage
- 1 of 1 consumed
- Expiry
- 2026-07-23 14:36 UTC
The timeout is a state—not permission to try again.
The agency does not have to take the operator’s word for it.
The packet carries the exact action, policy decision, bounded capability, executor outcome, and evidence-chain head. An authorized reviewer can preserve it and verify it outside the application.
- version
- emilia.program-integrity.packet.v1
- policy
- policy:dhcs-hospice-payment@1
- challenge
- chlg_syn_20260723_1430_00421
- verifier
- offline-compatible
- fixture
- true
- phi
- false
- decision
- authorized
- action_caid
- caid:1:health.medi-cal.hospice-claim-payment.1:jcs-sha256:_gaImSfYxk3C1BAqP2t3_bYhoHLb1FbGdvh8uk9jM28
- receipt_digest
- sha256:9999999999999…999999999999
- capability
- cap_syn_71B9…C201
- executor_outcome
- executed
- evidence_head
- sha256:aaaaaaaaaaaaa…aaaaaaaaaaaa
A consequence-control demonstration, not a fraud detector.
This browser fixture does not make eligibility, coverage, medical-necessity, provider-sanction, or payment decisions. It demonstrates how an agency can make existing decisions exact-action bound, single-use, fail-closed, and independently reviewable before a consequential action executes.
Test one protected workflow for 60 days.
Start in observe mode beside the existing program-integrity and payment stack. Exercise valid, missing, mismatched, replayed, revoked, and indeterminate cases, then give the portable packet to a separate authorized reviewer.
Scope an observe-mode pilot