Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Cardiology Operations
    August 12, 2026
    30 min read

    AI Agents for Cardiology PracticesRPM, Device Data and Documentation in 2026

    A sequenced implementation guide for practice administrators: the remote monitoring thresholds that govern the money, the line an agent may not cross when it triages device data, and ten ambient documentation platforms ranked on attributes you can actually verify.

    AI agents in a cardiology practice — remote patient monitoring operations, device clinic workflow, and ambient clinical documentation in 2026
    0
    Independent accuracy benchmarks for any named ambient AI scribe
    OHSU/MedStar, Mayo Clin Proc Digital Health, Oct 2025 — products anonymised
    76.3%
    Of ambient scribe errors were omissions, not fabrications
    OHSU/MedStar five-platform simulated-encounter evaluation, 2025
    Jan 1, 2026
    New RPM codes 99445 and 99470 took effect; tiers are not additive
    CY2026 PFS final rule, 90 FR 49396–49397
    Read-only
    Scope of certified API access under 45 CFR 170.315(g)(10)
    ASTP/ONC Certification Companion Guide, updated 05-15-2026

    Key Takeaways

    • Cardiology runs three schedules — physician clinic, equipment-constrained diagnostic testing, and a device clinic whose appointments arrive as transmissions. Remote monitoring inverts the usual model: work arrives continuously and has to be pulled into billable, documented calendar-month episodes.
    • Two new RPM codes, 99445 and 99470, took effect January 1, 2026 for services with fewer than 16 days of data transmission and fewer than 20 minutes of interactive communication per month. CMS states in the CY2026 final rule that the day tiers and the minute tiers are not additive and are not a base-and-add-on structure. A practice that does not track days and minutes per patient per month cannot bill correctly at any volume.
    • We print no Medicare dollar figure for any RPM code. The circulating per-code averages all trace to remote-monitoring vendors publishing 2026 billing guides. The authoritative source is PFS Addendum B, which we did not fetch — so we say that instead of estimating.
    • An agent may order a device-alert worklist. It may not classify clinical significance. Software analyzing a pattern or signal from a signal acquisition system is a device under 21 U.S.C. 360j(o)(1)(E), with no discretion available — and in FDA's own worked example, a future-risk cardiovascular model becomes a device that remains under FDA oversight the moment the prediction horizon is the next 24 hours.
    • No independent, named-vendor accuracy benchmark exists for ambient AI scribes. The two studies that measured correctness anonymised the products; the trial that names products measured time and burnout. Our Top 10 therefore scores integrations, verifiable compliance, pricing transparency, evidence posture and corporate record — and excludes accuracy by design.
    • Omission is the dominant scribe failure mode: 76.3% of errors in the OHSU/MedStar evaluation, 54–83% in the MedStar instrument-validation study. Negation errors are the cardiology-specific danger, because a dropped negative in a review of systems inverts the record and is the hardest error class for a clinician to catch.
    • The signature is the attestation. CMS's Medicare Program Integrity Manual Chapter 3 section 3.3.2.4 names AI explicitly and requires practitioner concurrence for AI-captured entries, and bars attestation by anyone other than the author. There is no configuration in which an agent attests.
    • Certified API access under 45 CFR 170.315(g)(10) is read-only. Every EHR write is a commercial arrangement with your EHR vendor, not a certification right — which makes read-only-by-default the cheapest and strongest security control you can adopt.
    • Frenchy Digital scopes this work from $9k–$22k for discovery through $180k–$420k+ for regulated multi-site builds, senior-led at $150–$225/hr, with full source-code and IP ownership transferred to the client.

    Cardiology Runs Three Schedules, Not One

    Most automation advice written for medical practices assumes one calendar with slots in it. Cardiology does not work that way, and every implementation that treats it as though it does fails in the same place.

    A cardiology practice runs three schedules simultaneously. There is a physician clinic, which is the smallest part of the calendar relative to the work it generates. There is a diagnostic testing schedule — echocardiography, stress testing, nuclear and CT imaging — constrained by equipment, by technologist availability, and by patient preparation requirements, with very high no-show sensitivity because a missed nuclear stress test wastes a dose and not merely a slot. And there is a device clinic, whose appointments are not appointments at all. They are transmissions, and they arrive whether or not anyone is rostered to receive them.

    ScheduleConstrained byWhat flows through itThe operational trap
    Physician clinicProvider timeNew consults, follow-ups, transition-of-care visits after a hospitalization the practice did not scheduleStandard slot mechanics; the smallest part of the calendar by volume of work generated
    Diagnostic testingEquipment and technologistEchocardiography, stress testing, nuclear and CT imaging — each with its own prep constraints and frequently its own prior authorizationHigh no-show sensitivity: a missed nuclear stress test wastes a dose, not just a slot
    Device clinicNothing — transmissions arrive unscheduledImplantable-device interrogations and continuous physiologic streamsWork arrives whether or not staff are rostered; it must be pulled into calendar-month episodes to be billable

    The three schedules a cardiology practice runs concurrently. Frenchy Digital operational framing.

    Add a fourth pressure that is easy to miss on an org chart: a large share of cardiology's ambulatory volume is transition-of-care follow-up after a hospitalization the practice did not schedule and often did not know about. Demand arrives from outside the building, on someone else's discharge timeline.

    The inversion that defines the specialty. Remote monitoring reverses the normal relationship between schedule and work. In a standard clinic, you fill slots and work arrives. In remote monitoring, the work arrives continuously and must be pulled into billable, documented calendar-month episodes. Automation that does not understand that direction of flow will optimise the wrong thing.

    There is one piece of long-standing evidence about physician time that is worth citing here precisely because cardiology is inside its sample, and worth citing carefully because it is old. Sinsky and colleagues, publishing in Annals of Internal Medicine in 2016, observed that for every hour of direct clinical face time, physicians spent nearly two additional hours on EHR and desk work. The study observed 57 physicians across 430 hours in four specialties — family medicine, internal medicine, cardiology and orthopedics — in four states, with 21 physicians keeping after-hours diaries that showed one to two hours nightly. The authors themselves note the data came from self-selected, high-performing practices and may not be generalizable. It is a 2016 study. We cite it as the origin of a number everyone repeats, not as a current measurement, and we would encourage you to do the same.

    Everything that follows in this article concerns administrative and documentation workflows under explicit human governance. Nothing here proposes that software make a clinical decision. The boundary is not a philosophical preference; it is statutory, and section four of this article maps it precisely.

    The Monitoring Economy: RPM Codes, Device Codes and the Thresholds That Govern Them

    The thing outsiders get wrong about remote patient monitoring is that they see a data problem and assume more data is better. Billing-wise the opposite is closer to true. RPM pays on calendar-month episodes with day and minute thresholds, and the 2026 restructure made those tiers explicitly mutually exclusive rather than additive. A practice that collects transmissions without tracking, per patient per month, how many days of data arrived and how many minutes of management time were documented cannot bill correctly at any volume.

    The scarce resource is documented clinician time. It is not device data.

    What actually changed on January 1, 2026

    The CY2026 Physician Fee Schedule final rule, at 90 FR 49396–49397, states it directly. Verbatim from the rule:

    For CY 2026, the CPT Editorial Panel created two new RPM codes to describe RPM services that describe less than 16 days of data transmission per 30-day period and less than 20 minutes of interactive communication per month: CPT codes 99445 and 99470. The CPT Editorial Panel also made edits to specify the minimum days of data transmission per 30-day period for CPT code 99454.

    CY2026 Medicare Physician Fee Schedule final rule, 90 FR 49396–49397

    The original family — 99453, 99454, 99457 and 99458 — remains current for 2026. Any article that lists only those four is working from a 2025 model of the world.

    CodeWhat it describes2026 statusThe operational consequence
    99453In the remote-monitoring family CMS finalized for 2026. We print no descriptor: CPT descriptor language is copyrighted and the rule text we read does not restate itStill current for 2026Read the descriptor out of the 2026 CPT codebook before you configure any logic against this code
    99454The 16-to-30-day data-transmission codeStill current; the CPT Editorial Panel edited it for 2026 to specify the minimum days of data transmission per 30-day periodNot additive with 99445 — you bill one or the other for the month
    99445The 2-to-15-day data-transmission codeNew — effective January 1, 2026Created for RPM services with less than 16 days of transmission and less than 20 minutes of interactive communication per month
    99457Treatment management, first 20 minutesStill current for 2026Requires interactive communication with the patient, which is defined as synchronous contact; not additive with 99470
    99470Treatment management, first 10 minutesNew — effective January 1, 2026Choose the most appropriate code for the time documented that calendar month
    99458The code the rule names when more than 20 minutes of treatment management is needed after 99457 or 98980 is billedStill current for 202698981 is its counterpart on the other code family

    The 2026 remote physiologic monitoring code structure. Descriptors are summarised; exact CPT descriptor language is copyrighted, and CMS states it is adopting all descriptors, guidelines, prefatory language and parenthetical changes made to the Remote Monitoring section of the 2026 edition of the CPT codebook.

    The combination rule is the part that breaks spreadsheets. CMS spells it out, verbatim:

    The 2 to 15 day codes (99445, 98984, 98985, and 98986) and 16 to 30 day codes (99454, 98976, 98977, 98978) are not additive and are not a base and add-on code structure. Billing practitioners would only bill for one of those codes for the appropriate number of days of data transmission per 30 days. In addition, the treatment management services describing the first 10 minutes (99470 and 98979) and first 20 minutes (99457 and 98980) are also not additive. Billing practitioners would choose the most appropriate code for the time spent that calendar month. In instances where more than 20 minutes of treatment management is needed after either 99457 or 98980 is billed, 99458 or 98981 can be used.

    CY2026 Medicare Physician Fee Schedule final rule, 90 FR 49396–49397

    Read that as an engineering specification, because that is what it is. Per patient, per calendar month, you need two counters and one decision: days of transmission resolving to exactly one code, and documented management minutes resolving to exactly one base code plus zero or more add-ons. That is a state machine, and it is precisely the kind of arithmetic an agent should be doing over data your chart already holds.

    We are not printing a payment amount, and here is why.Per-code dollar figures for 99445 and 99470 are circulating widely. Every instance we chased traces to a remote-monitoring vendor publishing a 2026 billing guide — companies that sell the service the number is meant to justify. One of those sources, Rimidi, is not even an independent commentator any more: it was acquired by Health Recovery Solutions in March 2026, and its founder became the acquirer's chief medical officer. The authoritative figures live in Physician Fee Schedule Addendum B, which we did not fetch. So we say that, rather than repeat a vendor's arithmetic. Build your ROI model from your own remittance data.

    There is a second fact about these codes that almost nobody reports, and it should shape how much capital you sink into an RPM programme this year. The rule states that none of the RPM codes — 99091, 99474, 99470, 99457 and 99458 — met the minimum survey requirements established by the RUC, that the RUC recommended they be resurveyed after one year, and that all RPM codes are expected to be reviewed at the January 2028 RUC meeting. The 2026 valuations rest on inadequate survey data and are scheduled to move. Plan for revaluation; do not build a five-year model on a two-year price.

    The device clinic: a different code family with a weaker evidentiary base

    Implantable-device remote monitoring runs on its own codes: 93294, 93295 and 93296 for pacemaker and ICD or CRT-D remote interrogation across the professional and technical components, 93297 and 93298 for implantable loop recorders and insertable cardiac monitors, with 93299 in the same family. We are deliberately not telling you which of those codes is the professional component and which is the technical one — our sources group them without splitting them, and a code table that guesses is worse than one that abstains.

    CodeWhat it describesVerification level in our sources
    93294Pacemaker and ICD/CRT-D remote interrogation. Our sources group 93294, 93295 and 93296 as covering the professional and technical components; they do not tell us which code carries which, so we do not assign them🟡 secondary sources only
    93295Same family and same caveat🟡 secondary sources only
    93296Same family and same caveat🟡 secondary sources only
    93297Implantable loop recorder / insertable cardiac monitor, remote🟡 secondary sources only
    93298Implantable loop recorder / insertable cardiac monitor, remote — our sources pair 93297 and 93298 without splitting them🟡 secondary sources only
    93299In the same family; our sources say nothing more specific about it🟡 secondary sources only

    You will hear three rules stated confidently about this family: a 90-day minimum interval for pacemaker and ICD remote interrogation, a 30-day minimum monitoring period, and mutual exclusivity of 93294 and 93295. Those rules appear consistently — but every source we could locate was a remote-monitoring service vendor or a device manufacturer. We checked the 2026 CMS NCCI Policy Manual directly and it contains no entry for 93294 through 93299 at all.

    So: describe the 90-day interval as commonly applied and attribute it to the vendors who publish it, or leave it out of your configuration logic entirely and have a human make the call. Do not encode it in an agent as though it were a CMS rule. If your billing depends on it, get it in writing from your MAC.

    One more structural fact worth having on the whiteboard: cardiology sits in the heart failure cohort of the Ambulatory Specialty Model, a mandatory Innovation Center model running five performance years from January 1, 2027 through December 31, 2031, with a threshold of 20 or more attributed episodes from the relevant episode-based cost measure in the eligibility year. It carries two-sided risk and is scored partly on meaningful use of certified EHR technology — which is the one place where an interoperability and agent story legitimately attaches to a payment model rather than merely to internal efficiency. Note that the ±9 percent figures in the rule text describe MIPS, not the ASM; do not let a vendor attribute them to the model.

    Who Is Clinically Responsible for Data an Agent Triaged

    This is the question a cardiology practice must answer before it buys anything, and it has a sharper legal edge here than in any other outpatient specialty. The reason is that cardiology's highest-volume data is a signal, and federal law treats signals differently from text.

    Start with what is unambiguously permitted. 21 U.S.C. §360j(o)(1)(A) excludes from the device definition, by statute, software intended for

    administrative support of a health care facility, including the processing and maintenance of financial records, claims or billing information, appointment schedules, business analytics, information about patient populations, admissions, practice and inventory management, analysis of historical claims data to predict future utilization or cost-effectiveness, determination of health benefit eligibility, population health management, and laboratory workflow

    21 U.S.C. §360j(o)(1)(A)

    That sentence covers scheduling the echo, checking eligibility, assembling the prior-auth packet, tallying transmission days, building the recall list and assembling the monthly documentation packet. An agent doing those things is outside the device definition by statute, not by FDA grace. That distinction matters, because grace can be withdrawn.

    Now the other side. §360j(o)(1)(E) governs software that supports or provides recommendations to a clinician, and it is available only if the function is not intended to acquire, process or analyze a medical image, an in-vitro diagnostic signal, or a pattern or signal from a signal acquisition system. Cardiac telemetry is a signal from a signal acquisition system. An implantable device stream is a signal from a signal acquisition system. Software that analyses one of those is a device, and there is no enforcement discretion pathway around it.

    FDA sharpened the boundary in its 2026 Clinical Decision Support guidance with a clarification that is directly on point for remote monitoring: discrete, episodic or intermittent point-in-time physiological measurements — routine vital signs obtained at discrete clinical encounters is FDA's own example — generally do not, by themselves, constitute a pattern. Streaming or continuous measurement does. A blood pressure cuff reading uploaded once a day is on a different side of that line from a continuous rhythm strip, and your architecture should reflect it.

    FDA's own cardiology example, and why it is the most useful paragraph in the guidance

    The 2026 guidance works through a cardiovascular example that maps onto a real RPM product. Software that predicts the risk of a future cardiovascular event from weight, smoking history, blood pressure and a BNP result fails Criterion 3 if it emits a single output — but FDA has stated it intends to exercise enforcement discretion where only one option is clinically appropriate and the function otherwise meets all the section 520(o)(1)(E) criteria.

    Change one variable — make the prediction horizon the next 24 hours — and FDA's position changes: the function fails Criterion 4 and is a device that remains under FDA oversight. Add variant genomic data without established relevance and it fails Criteria 1 and 2. Same underlying model. Three different regulatory outcomes, driven by horizon and inputs.

    Two things follow for a buyer. First, ask any RPM analytics vendor what its prediction horizon is and what inputs it consumes, and get the answer in writing — those two facts, not the marketing, determine which side of the device line the product sits on. Second, write it as enforcement discretion in your own policy documents, never as exemption or approval. Discretion is revocable without notice-and-comment; a statutory exclusion is not. FDA has not approved, cleared or blessed any ambient scribe or clinical decision support product, and any vendor using those words about a discretion policy is telling you something untrue.

    FDA also moved automation bias and time-criticality into the Criterion 4 analysis in 2026. In its own words at the March 2026 town hall, FDA considers both the level of automation and the time-critical nature of the clinician's decision making when determining whether the clinician can independently review the basis for a recommendation, and it defines automation bias as the propensity of humans to over-rely on a suggestion from an automated system, producing errors of commission or of omission. Read the qualifier carefully: these are considerations FDA weighs, not a test that settles the question. In every device example in the guidance that turns on time-criticality, the time-critical workflow is paired with a specific or directive output. A list of options surfaced under time pressure is not automatically a device.

    The defensible design conclusion, written as analysis rather than as a rule: the more autonomous and the more time-pressured the workflow, the harder it becomes to claim the clinician is independently reviewing anything. An agent that surfaces a recommendation inside a thirty-second decision is in worse regulatory shape than the same recommendation surfaced in an asynchronous inbox. In a device clinic, that argues for asynchronous review queues over real-time interruptive alerts, on regulatory grounds as well as clinical ones.

    There is one more federal duty that catches remote monitoring specifically and is routinely missed. 45 CFR §92.210 prohibits discrimination through the use of patient care decision support tools, and imposes an ongoing duty to make reasonable efforts to identify tools that employ input variables measuring race, colour, national origin, sex, age or disability, and to mitigate the resulting risk. It applies whether or not the tool is AI and whether or not FDA calls it a device. An RPM risk-stratification model with age or sex as an input is squarely inside that inventory duty. Reported compliance date is May 1, 2025; the rule appears in the current CFR as of August 2026, and we make no assertion about any pending challenge to it.

    The practical rule for a device clinic. An agent may order a worklist. A named clinician opens every alert regardless of where the agent placed it, and the queue position appears nowhere in the medical record. Ordering is an administrative act over metadata. Interpreting the signal is a clinical act over a device-regulated input. Write that distinction into the configuration, not just the policy binder — a policy nobody can enforce technically is a policy that will be violated on a busy Friday.

    Echo, Stress and Nuclear: The Scheduling Problem Nobody Models Correctly

    Diagnostic scheduling in cardiology is not slot-filling. It is a constraint-satisfaction problem with four dimensions that most scheduling software collapses into one.

    • Equipment: The nuclear camera, the treadmill and the echo machine are separate resources with separate throughput. A slot is not a slot.
    • Staff: Sonographers, nuclear technologists and stress-test supervision are distinct credentials. Availability is the binding constraint far more often than room time.
    • Preparation: Fasting, caffeine restriction, beta-blocker holds and medication timing all have to happen before the patient arrives, on the patient's side of the wall where you have no direct control.
    • Authorization: Advanced imaging is frequently authorized through a delegated benefit manager on a different timeline from the clinical decision that prompted it.

    The no-show economics are also different from a clinic visit and are the reason this workflow justifies its own agent. A missed nuclear stress test does not merely leave a slot empty — it wastes a dose. The unit of loss is consumable, not just temporal.

    This is the moment to name a number we will not print. The medical-practice AI market runs on a figure of roughly two hundred dollars per no-show, frequently paired with an annual national loss figure in the hundreds of billions. Both trace to a single 2017 byline written by the chief medical officer of a scheduling vendor, with no published methodology. We chased it and refused it in an earlier cluster and we refuse it here. It is not that the number is too high or too low; it is that no one can tell you what it measures. If a vendor builds your business case on it, ask for the methodology and watch what happens. The same applies to every phone-abandonment benchmark used to sell voice agents — the seven-percent-abandonment and eighty-five-percent-never-call-back figures have the same problem.

    Your own number is obtainable and better. Count completed studies against scheduled studies by modality for three closed months, price the consumable waste for nuclear separately from the staffed-time waste for echo, and you have a defensible baseline that also happens to be the exit criterion for Phase 2 of the implementation path below.

    What a scheduling agent can defensibly do in cardiology today

    • Deliver and confirm modality-specific prep: Fasting windows, caffeine restriction, medication holds — delivered on a schedule tied to the study type, with a confirmation event recorded. Confirmation, not just delivery, is the metric.
    • Detect prep failure before the patient travels: An unconfirmed prep with 24 hours to go is a reschedule decision, not a no-show waiting to happen. This is read-and-reason work and needs no write access.
    • Maintain a modality-aware waitlist: A cancelled nuclear slot cannot be filled by an echo patient. The waitlist has to be typed by resource, which is exactly the modelling error generic scheduling tools make.
    • Assemble the imaging prior-auth packet: Pull the clinical documentation the payer's criteria require, flag what is missing, and hand a human a complete submission. Assembly is read-and-reason; submission is a write path.
    • Sequence transition-of-care follow-up: When a discharge summary arrives from a hospitalization the practice did not schedule, the agent can build the follow-up task with the right window and the right modality attached.

    On prior authorization, one regulatory clarification saves a lot of wasted effort. CMS-0057-F binds payers, not practices. Every obligation in 42 CFR §422.122 runs to a Medicare Advantage organization. Live in 2026: a specific reason for denial regardless of communication channel, decision timeframes of 7 calendar days standard and 72 hours expedited under §422.568 and §422.572, and public reporting of prior-auth metrics. The FHIR prior-authorization API is a January 1, 2027 obligation on the payer. Commercial and ERISA plans are not covered at all. If your imaging authorization pain is commercial, this rule changes nothing for you — and a vendor selling you a CMS-0057-F readiness project for a commercial book is selling you a rule that does not apply.

    The Write-Path Constraint, and the Exact Question to Ask Your EHR Rep

    This is the single most important architectural fact in this whole subject area, and it is the one most consistently omitted from vendor conversations. ASTP/ONC's certification companion guide for 45 CFR §170.315(g)(10), the standardized API criterion every certified EHR must meet, states it plainly:

    The § 170.315(g)(10) certification criterion requires Health IT Modules to support API-enabled ‘read’ services for single and multiple patients. … These services specifically exclude ‘write’ capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.

    ASTP/ONC — Standardized API for Patient and Population Services, certification companion guide

    Certified API access is read-only. Every write an agent performs into your EHR — booking the slot, filing the note, posting the charge, updating the device-clinic record, adding to the problem list — happens through one of exactly three mechanisms, and none of them is a certification right:

    1. 1.A vendor-discretionary write API: A commercial arrangement with your EHR vendor, on that vendor's terms, subject to its app-review process, often with per-transaction fees and its own upgrade cadence.
    2. 2.UI automation: Robotic process automation or a browser push driving the interface a human would drive. It works until the interface changes, and it fails quietly when it does.
    3. 3.A human: Copy-paste, or a staff member executing the action the agent prepared. Slower, and the only one of the three with a clean audit story by default.
    Sort every proposed automation into three buckets before you price it. Read-and-reason — anything that computes over data the chart already holds and hands a human a conclusion: RPM day and minute tallies, missing-document detection, recall lists, packet assembly. Available now, on any certified EHR. Write — booking, charge posting, note filing, order entry. Vendor-discretionary, always. Outside the health-IT rail entirely — payer portals, benefit-manager portals, device-manufacturer monitoring platforms. Each is its own integration and none is standardized. A specialty guide that promises closed-loop automation without saying which of those three it means is selling something.

    Read-only-by-default is also, and not coincidentally, the strongest security control available to you, and it is free. An agent that cannot write cannot be manipulated into writing.

    Six questions for your EHR account rep — ask them in writing, in this order

    1. 1.Do you permit this specific vendor to write to our chart?: Not "do you support integrations." Name the vendor. The answer is per-vendor and per-module, and it is a commercial decision your rep may need to escalate.
    2. 2.Through what mechanism?: A documented write API, an app-programme partnership, or the vendor driving your UI? If it is the third, say so in the contract, because it changes your upgrade risk profile.
    3. 3.What does it cost, per transaction and per year?: Write access is frequently priced separately from the integration itself. Get both numbers before you sign with the downstream vendor.
    4. 4.What happens at the next platform upgrade?: Ask for the vendor's compatibility commitment and its notice period. RPA breaks on upgrades and it breaks silently.
    5. 5.Can the agent hold its own credential?: 45 CFR §164.312(a)(2)(i) makes unique user identification required, not addressable, and §164.312(a)(1) already frames access rights as attaching to software programs. A shared service account that makes agent actions indistinguishable from a human's is a compliance failure, not a convenience.
    6. 6.Do you ship a native ambient scribe, and is it included?: athenahealth put athenaAmbient into user testing from February 2026 and delivers it at no additional cost through routine updates; Epic announced a built-in ambient charting tool in February 2026. If your EHR includes one, the first question is not which of thirty-five startups is best. It is why you would pay a third party at all.

    One live regulatory watch item, stated as what it is. ASTP/ONC published a proposed deregulatory rule on December 29, 2025 that would, among other things, remove the clinical decision support certification criterion and reserve §170.315(a)(9). Comments closed February 27, 2026 and we located no final rule. It is a proposal. Nothing in it is binding, and nothing in it changes the read-only scope of (g)(10) today.

    Top 10 Ambient AI Scribe & Clinical Documentation Platforms

    Read this before the table. Accuracy is not scored, and that is deliberate. No independent, named-vendor accuracy benchmark exists for ambient AI scribes. The two independent evaluations that measured output correctness both deliberately anonymised the products — Platforms A through E in one, Product A and Product B in the other — so no accuracy figure can honestly be attached to a named product. The one randomized trial that names products measured documentation time and burnout, and its only accuracy measure was a clinician self-rating on a five-point scale. Every accuracy percentage circulating in this market is vendor-published. Any listicle that ranks scribes by accuracy percentage is republishing vendor marketing with a number attached. We therefore score integrations, verifiable compliance posture, pricing transparency, evidence posture and corporate record — attributes a buyer can independently confirm — and we exclude accuracy by design.

    Methodology — what was scored, what was excluded, and when it was checked

    • Checked on: 2026-08-12. Vendor pages, trust centres, funding announcements and peer-reviewed studies were read on that date. Anything in this category can change in a week.
    • Scored: Publicly named EHR integrations; whether compliance artefacts (SOC 2, ISO 27001, BAA, sub-processor list, audio retention) can be verified before a sales call; pricing transparency, meaning a price published on the vendor's own site; independent evidence, meaning non-vendor-funded, non-vendor-authored evaluation; and corporate record from public filings, releases and reputable trade reporting.
    • Excluded — accuracy: No independent benchmark exists. Every figure in the market is vendor-published on a vendor-selected sample against a vendor-defined notion of correctness. Including it would import marketing into a ranking.
    • Excluded — customer-satisfaction rankings as quality evidence: KLAS Best in KLAS and KLAS Spotlight measure how customers feel. They are reported below as facts about market standing, never as accuracy.
    • Excluded — third-party price estimates: If a price is not published by the vendor, the cell says not published. We do not estimate and we do not infer. Several widely circulated per-provider prices trace to review blogs, at least one of them authored by a direct competitor.
    • How to re-check this yourself: Open the vendor's own pricing page, its trust centre, and PubMed. If the trust centre names no certification, that is your finding. If PubMed returns nothing with the product's name in it, that is also your finding.
    • What this ranking is: An opinion built on verifiable inputs, expressed as an order with stated trade-offs. There are no decimal scores, because not every input is public and fake precision would be worse than none.
    RankPlatformPublicly named EHR integrationsCompliance you can verify before a sales callPublished pricingIndependent evidence and market standing
    1NablaEpic, athenahealth (named on the vendor site); Nabla Connect as a general integration layerSOC 2 Type II and ISO 27001 both explicitly claimed as obtained certifications on the public security page; trust portal publishedNot published — no price on the pages we fetchedThe only product with a statistically significant independent RCT result on its named product: −9.5% time-in-note vs control in the UCLA NEJM AI trial (95% CI −17.2% to −1.8%; P=0.02). That is time, not accuracy
    2AbridgeEpic (deep, longstanding partnership); named health-system deployments include Kaiser Permanente/TPMG, Yale New Haven, Sutter Health, University of Chicago Medicine, CHRISTUS, MemorialCare, The Christ HospitalTrust Center publicly lists SOC 2 Type 2, SOC 2 Type 1, HIPAA, CCPA, TX-RAMP, WCAG. HITRUST and ISO 27001 are not listed; no explicit public BAA statement foundNot published — contact sales onlyThe most-studied product in the category, but read the designs: the JAMA Network Open study is pre/post, not randomized, and two Abridge executives are among its authors. #1 Best in KLAS 2026 Ambient Speech (94.7) — a customer-satisfaction ranking, not an accuracy test
    3Microsoft Dragon CopilotEpic, athenahealth, MEDITECH (named by Microsoft). Nurse workflows US-only; radiology in US previewNo SOC 2 or HITRUST statement on the product page we fetched; BAA availability not stated on that pageNot published — the page says contact usThe only large enterprise scribe with an independent RCT result on its named product, and the result was null on the primary endpoint: −1.7% time-in-note (95% CI −9.4% to +5.9%; P=0.66). Burnout and task-load secondaries did improve
    4athenahealth athenaAmbientBuilt into athenaOne — native, so the write path is not a commercial negotiationInherits your existing athenahealth agreement; one vendor, one BAA, one wind-downDelivered at no additional cost through routine updates, per athenahealth's announcementNone independent. Ranked here on structure, not evidence: in user testing from February 2026, and the only entry on this list where the write path is not vendor-discretionary
    5FreedNone named. Ships an EHR push that sends notes into any browser-based EHR with one click on Premier and above — read that as a browser push, not a certified integrationStates HIPAA compliance, SOC 2 Type 1 and 2, HITECH, and an organization-wide BAA as an included feature on Group plans. The only vendor here that answers the audio-retention question in publicPublished: Starter $39/mo, Core $79/mo, Premier $104/mo promotional against a $119 list price; Groups are custom. 7-day trial, no cardNone independent. Ranked on verifiability, not evidence — its FAQ states audio is temporarily saved until note summaries and quality checks complete, then automatically deleted
    6Sunoh.aiAllscripts, Amazing Charts, athenahealth, Cerner, eClinicalWorks, Epic, Medtech, ModMed, NextGen — the longest publicly named list on this tableStates plainly that a Business Associate Agreement is included. No SOC 2 statement found. Runs on Microsoft AzurePublished: $149 per user per month, described as a limited-time price against a regular price of $199. Single plan, no tiersNone independent. Part of the eClinicalWorks/healow family — an EHR-family product, not an independent vendor
    7SukiEpic, Oracle Health, athenahealth, MEDITECH — described on the vendor site as the four leading EHRsSOC 2 Type 2 and HIPAA stated. HITRUST and ISO 27001 not claimed; no public BAA statement foundNot published — routes to sales. The $299/$399 figures circulating in review blogs are not vendor-published; we refuse themNone independent. Not named in any study in the evidence section. Ownership: no acquisition, merger or rebrand found as of 2026-08-12, but not verified against a corporate filing
    8Commure (incl. Augmedix, Athelas)Claims 60+ EHRs; none is named on the page we fetched. Named customers: North East Medical Services, HCA Healthcare, Dignity Health, Tenet HealthSOC 2 Type II stated. No HITRUST; no public BAA statementNot published — contact salesNone independent. Raised $70M at a $7B post-money valuation announced May 2026, per its own release, on top of an earlier $200M growth financing. Conflict worth knowing: Commure publishes competitor reviews that rank well in search — do not source competitor facts from it
    9DeepScribeiKnowMed, OncoEMR, Epic. Named oncology customers including Tennessee Oncology, Texas Oncology, Ochsner Health, Florida Cancer SpecialistsSOC 2 and HIPAA stated. No HITRUST; no explicit public BAA statementNot published — contact salesNone independent. Now positioned as purpose-built for oncology, not general practice — a repositioning a cardiology buyer should weigh. Its 98.8/100 figure is a 2025 KLAS Spotlight, a small commissioned satisfaction study, and is not comparable to a 2026 Best in KLAS ranking
    10Heidi HealthNo EHR partner named on the pricing page; EHR integration is listed as a paid add-onHIPAA page and trust centre exist, but we could not extract a specific SOC 2 Type II or ISO 27001 attestation or a plain BAA statement. Treat certification status as unconfirmed, not absentTier names published (Free, Clinician, Practice, Evidence) with no USD prices. A free tier exists. Open the page yourself before quoting tiers — the rendering is inconsistentNone independent. $65M Series B led by Point72 Private Investments closed October 2025 at a reported $465M valuation, roughly $100M raised in total

    Ranked on verifiable attributes as checked on 2026-08-12. Accuracy is excluded by design — see the methodology block above.

    PlatformOwnershipFunding on the public recordContract-risk note
    NablaIndependent, French-founded$70M Series C announced June 17, 2025; $120M raised to date, per the vendor's own postWas the named product in the 2024 Whisper-hallucination reporting; says it replaced Whisper with its own model — a vendor claim with no independent replication
    AbridgeIndependent$300M Series E led by a16z with Khosla, announced June 24, 2025; roughly $830M raised to date, per Fortune; $5.3B valuation reported by trade press, not stated by AbridgeNamed as the tool in two active consent class actions. The defendants are the health systems, not the vendor — which is precisely why a practice must care
    Microsoft Dragon CopilotMicrosoft, via the Nuance acquisitionNot applicableDAX Copilot was rebranded and merged into Dragon Copilot in March 2025. If a vendor or a listicle still says DAX Copilot in 2026, it is working from stale material
    athenahealth athenaAmbientathenahealthNot applicableOnly worth evaluating if you are already on athenaOne. Otherwise it is not a product you can buy
    FreedIndependentFunding and ownership not verified in this passNothing about its funding or ownership is disclosed publicly, so there is no corporate record here to assess — the trade-off for real published pricing and a stated BAA
    Sunoh.aiAffiliated with eClinicalWorks / healowNot applicableAn older $1.25-per-visit usage price appeared in 2024 marketing and no longer appears on the site. If you find it in an old article, it is stale
    SukiTreat as independent; not verified against a corporate filingNot disclosed on the sitePublishes category explainers that rank well in search. A vendor's explainer is marketing, not a source
    CommureGeneral Catalyst-backed; Augmedix acquired for ~$139M all-cash, closed October 2, 2024 and delisted from Nasdaq; earlier merger with Athelas$70M at a $7B post-money valuation, May 2026; earlier $200M growth financingDo not describe Augmedix as an independent vendor — it is a wholly-owned subsidiary
    DeepScribeIndependent; active as of mid-2026Roughly $37M raised across three rounds, per aggregator sourcesThe smallest funding base of the major names. For a multi-year contract that is a legitimate durability question, and the Robin Healthcare shutdown shows the risk is real
    Heidi HealthIndependent, Melbourne, Australia$65M Series B, October 2025; roughly $100M raised in totalIts CEO Tom Kelly responded to Epic's launch: “Heidi was built as an AI partner for clinicians first, not as a feature embedded within an EHR.”

    Corporate record and contract risk. Funding figures are as announced by the company or as reported by named outlets; where a valuation is trade-reported rather than company-stated, we say so.

    Deliberately not ranked, and why

    • Ambience Healthcare — not shortlisted on verifiability grounds: A $243M-Series-C-stage enterprise vendor whose public site says it is trusted and fully certified while naming zero certifications, whose /security page returns a 404, and which publishes accuracy percentages instead. That is not an allegation of non-compliance — it may hold every certification. It is a verifiable statement about what a buyer can confirm before a sales call, and our rule is: do not shortlist a vendor whose compliance posture you cannot verify without talking to sales.
    • Corti — infrastructure, not a product a practice can buy: A developer platform selling medical ASR, coding and an agent framework to EHR vendors and virtual-care platforms. It publishes the strongest compliance list we found anywhere in this category and real usage-based pricing, but a cardiology practice cannot buy it and use it. Ranking it against Freed would be a category error.
    • Doximity Scribe — free, and the business model is the disclosure: Free to verified US clinicians since July 2025, with no direct EHR integration — notes are copied manually. It is free because the parent company monetises clinician attention elsewhere. That is a legitimate trade for some solo clinicians and a non-starter for a practice that needs an auditable write path.
    • Epic's built-in ambient charting tool, Oracle Health Clinical AI Agent, NextGen Ambient Assist: Epic announced a built-in ambient charting tool in February 2026 that listens during appointments, drafts documentation and prepares orders. The source never gives it a product name and pricing is not published, so we do not name it. Oracle's and NextGen's native offerings rest on trade coverage only. All three matter enormously to the practices already on those platforms and none can be ranked on public facts.
    • Robin Healthcare — the cautionary entry: An ambient charting and reimbursement vendor that quietly ceased operations in autumn 2024, with employees reporting roughly three days' notice. Use it for one purpose: to make sure your contract has a data-export and wind-down clause before you sign.
    • Otter.ai and general-purpose notetakers — a clean, sourced no: Not clinical products. Subject to active litigation alleging recording and use of private conversations without consent, including third parties, with the defendant's motion to dismiss fully briefed and oral argument set for August 2026. A BAA is reportedly available only at enterprise tier. They are not designed for PHI and they sit inside exactly the consent theory being pleaded against health systems.

    Two vendors on this list legitimately span categories. Commure sells autonomous coding and revenue-cycle automation alongside documentation, and Abridge ships coding and revenue-cycle features. We rank both here, in documentation, and point you to our companion article on prior-authorization and revenue-cycle automation for the other half of the evaluation, so that the two rankings stay distinct rather than double-counting the same vendor.

    The finding hiding inside the pricing column.Of every vendor we examined, only four publish a US price at all: Freed, Sunoh, Corti and Doximity (free). Heidi publishes tier names with no prices. Everything else is contact-sales. That is not a minor inconvenience — it means the category's price discovery happens entirely inside sales conversations, which is why third-party review blogs fill the vacuum, and why several of the figures those blogs publish are written by competitors. Say plainly to any vendor: we do not evaluate products whose price we learn only after four calls.

    What the Studies Measured, and How Ambient Scribes Actually Fail

    This section exists because the gap between what was measured and what gets quoted is, in this category, enormous. Clinician burnout and clinician satisfaction are not accuracy. Time in note is not accuracy. Star ratings are not accuracy. A customer-satisfaction ranking is not accuracy. Every headline claim in this market is one of those things.

    StudyDesignWhat it measuredHeadline result, with intervalsThe caveat that changes the reading
    UCLA Health RCT (NEJM AI, Dec 2025)Randomized, three arms, 238 outpatient physicians across 14 specialtiesChange in log writing time-in-note; burnout and task-load secondariesNabla −9.5% (95% CI −17.2% to −1.8%; P=0.02); DAX −1.7% (95% CI −9.4% to +5.9%; P=0.66, not significant)Accuracy was self-reported only, on a five-point scale (DAX 2.7, Nabla 2.8; P=0.68)
    University of Wisconsin RCT (NEJM AI, Dec 2025)24-week stepped-wedge, individually randomized, 66 practitioners, 71,487 notesPractitioner well-being; documentation timeWork exhaustion/disengagement −0.44 (95% CI −0.62 to −0.25; P<0.001); documentation time −0.36 h/day (95% CI −0.55 to −0.17)Professional fulfillment +0.14 is characterised as nonsignificant by the authors. The vendor is not named in the abstract
    OHSU / MedStar simulated encounters (Mayo Clin Proc Digital Health, Oct 2025)Five platforms, anonymised A–E, against 14 simulated ambulatory encountersCorrectness of key clinical elements; transcript error propagation26.3% of key elements contained errors (95% CI 17.0–31.0%); 19.5% of transcript errors propagated into the note; only 35.8% of key elements were correct across all five platformsThe best accuracy evidence that exists — and it deliberately withholds product names
    MedStar / Georgetown instrument validation (JMIR, Jan 2025)Two commercial products, named only as Product A and Product BError taxonomy across 44 draft notes127 errors; 70% of notes contained at least one error; mean 2.9 errors per note; omissions were 83% of Product A errors and 54% of Product B errorsAlso anonymised. The authors note omissions are the hardest error for a clinician to catch
    Kaiser Permanente / TPMG programme evaluationLargest deployment evaluation; 7,260 physicians across roughly 2.5 million encountersPhysician star ratings, PDQI survey, free-text commentsOf encounters that were rated (14% of them), 47% five-star, 31% four-star, 7% one or two star; PDQI survey mean 4.35/5 across 1,252 responsesReported problems: tracking multiple speakers, omitted information, erroneous assumptions. The widely quoted hours-saved figure is a model output from the deploying system, not a controlled measurement
    JAMA Network Open multicentre QI study (Oct 2025)Pre/post quality improvement, not randomized; 263 clinicians across six health systemsBurnout, cognitive task load, after-hours documentationBurnout 51.9% → 38.8% (aOR 0.26; 95% CI 0.13–0.54); after-hours documentation −0.90 h/weekNote accuracy was not measured. Two Abridge executives are among the authors

    The independent and quasi-independent evidence base for ambient documentation, as of August 2026.

    Three readings from that table deserve to be stated in plain language, because they are the ones vendors do not volunteer.

    First: the strongest evidence in the category found the market-leading enterprise product produced no statistically significant reduction in note-writing time. The UCLA trial randomized 238 outpatient physicians across 14 specialties into three arms. Nabla achieved −9.5% on the primary endpoint (95% CI −17.2% to −1.8%; P=0.02). DAX achieved −1.7% (95% CI −9.4% to +5.9%; P=0.66). One of those crosses zero comfortably. That is not an argument against ambient documentation — it is an argument for measuring your own deployment rather than assuming the category's marketing applies to you.

    Second: read the secondary outcomes with their intervals, not as point estimates. On the UCLA trial's well-being measures, DAX's physician task load (−39.9; 95% CI −71.9 to −7.9) and work exhaustion (−0.32; 95% CI −0.55 to −0.08) intervals exclude zero. Nabla's corresponding intervals (−31.7; 95% CI −63.8 to +0.4 and −0.23; 95% CI −0.46 to +0.01) include it. Both products improved the Mini-Z score with intervals excluding zero. Presenting only the point estimates reverses which product looks better on well-being versus on time, which is exactly why both sets of numbers belong in any honest comparison.

    Third: the study most often cited as proof that ambient AI cuts burnout is a pre/post survey with vendor executives among its authors. The JAMA Network Open multicentre study reports burnout falling from 51.9% to 38.8% (aOR 0.26; 95% CI 0.13–0.54) across 263 clinicians at six health systems. It is a quality-improvement study, not randomized. Note accuracy was not measured. One author was senior director of clinical success at the vendor, another was its chief clinical officer during the study, and a third sat on its research advisory committee. That does not invalidate the finding. It does mean the finding should never be introduced as though it were an independent trial.

    One more, on the Wisconsin trial, because it is a small lesson in reading abstracts honestly. Work exhaustion and disengagement fell by 0.44 points (95% CI −0.62 to −0.25; P<0.001) — a real result. Professional fulfillment rose 0.14 points (95% CI 0.004 to 0.28) with a nominal P of 0.04, and the authors themselves characterise that as nonsignificant. We print their characterisation, not our own reading of the P value. The vendor is not named in the abstract, so we cannot tell you which product produced either result.

    The statistic that mutated in transit — a worked example

    You will encounter the claim that AI scribe errors appear in 70% of notes and that 44% of them are clinically significant. It is half true and half invented.

    The 70% is real: the MedStar and Georgetown instrument-validation study found 127 errors across 44 draft notes, with 70% of notes containing at least one error. The 44% is almost certainly a mangling of “44 draft notes.” The paper describes an error taxonomy — omissions, additions, wrong output, irrelevant or misplaced text — and we found no clinical-significance percentage in it.

    Use the 70% with its citation. Refuse the 44%. And treat this as a template: when a compound statistic circulates, one half of it is usually load-bearing and the other half is usually a sample size that grew a percent sign.

    A short list of category figures we chased and will not print: a hallucination rate of roughly one to three percent across leading systems, and a variant claiming approximately seven percent — both appear only in SEO aggregator blogs with no citation to any study. Thirteen to sixteen minutes saved per day, and a thirty-one percent reduction in burnout — aggregator summaries with no attached study. The real, citable numbers are the ones in the table above. And the widely quoted hours-saved figure from the largest deployment evaluation is a model output produced by the deploying health system's own programme evaluation, not a controlled measurement; it is usable with that framing and never as “studies show.”

    Documented failure modes: omissions, negations and hallucinated content.

    The popular fear about AI documentation is fabrication. The measured reality is that omission is the dominant failure mode, and omission is worse, because it is far harder to catch.

    • Omissions dominate: 76.3% of errors in the OHSU and MedStar five-platform evaluation were omissions, with medication errors the most common single type. In the MedStar instrument-validation study, omissions were 83% of one product's errors and 54% of the other's.
    • Why omissions are the hard class: The authors state it directly: catching an omission requires the clinician to recall a detail from the encounter that the note simply does not mention. Every other error type puts something wrong on the page for a reviewer to notice. An omission puts nothing there.
    • Errors propagate: Roughly 19.5% of raw transcription errors survived into the finished note (95% CI 6.6% to 28.8%). The transcript layer and the note layer are not independent.
    • Harm potential is measurable and non-trivial: A mean of 3.0 errors per simulated case had potential to cause moderate-to-severe harm (95% CI 0–4, range 0–21 across cases). Print both intervals as the paper does; the 0–21 is the observed range, not a confidence interval.
    • Platform choice changes the chart: Only 35.8% of key clinical elements were captured correctly by all five platforms tested. Which product you buy materially changes what ends up in the record.
    • Negation errors — the cardiology-specific danger: The UCLA trial explicitly named negation-detection errors alongside omissions and pronoun-resolution failures. In a cardiac review of systems, a dropped 'no' inverts the record: no chest pain becomes chest pain, denies syncope becomes syncope.
    • Speaker attribution fails in crowded rooms: Pronoun-resolution failures in the UCLA trial; difficulty tracking multiple speakers in the largest deployment's quality-assurance programme. Cardiology encounters very often include a spouse or adult child. Assume this failure mode applies to you.

    Hallucinated content: what was actually reported, and what remains unverified

    Associated Press reporting in October 2024, together with academic work, found that OpenAI's Whisper speech-recognition model invented content that was never spoken. Reported figures include hallucinations in nearly every one of roughly 26,000 transcripts in one researcher's analysis, a University of Michigan researcher finding hallucinations in 8 of 10 audio transcriptions, and computer scientists finding 187 hallucinations across more than 13,000 clear audio snippets. Invented content included medications and unprompted racial commentary. These figures come to us through several re-reporting outlets rather than from the original wire piece, which we could not retrieve — treat them as reported, not as measured by us.

    The reporting implicated medical transcription specifically, naming a scribe vendor built on Whisper and used, per that reporting, by 30,000-plus clinicians across dozens of health systems, having transcribed roughly seven million medical visits. A separate criticism was that the product deleted the source audio, leaving no way to verify a note against what was actually said.

    That vendor has responded that it built a proprietary speech-to-text model trained from a Whisper baseline on roughly 7,000 hours of proprietary medical audio, and that across the 187 known hallucination-inducing samples its model produced zero hallucinations under three passes of human review. That is a vendor claim. No independent replication exists. Peer-reviewed work corroborating that Whisper hallucinates on non-speech audio does exist independently of the news story.

    The practical instruction: ask every vendor, in writing, whether source audio is retained and for how long. If audio is deleted immediately, nobody can ever audit a disputed note against the encounter — including you, in a malpractice matter. If it is retained indefinitely, you have created a new discovery target and a new breach surface. Neither answer is automatically wrong. Not having the answer is.

    There is a further failure mode that has no reliable detection signal, and we would rather say so than sell you a control that does not exist. Prompt injection is unsolved. A controlled simulation published in JAMA Network Open in December 2025 ran 216 evaluations across twelve clinical scenarios and found injection attacks achieved 94.4% success at turn four and persisted in 69.4% of follow-ups, with extremely high-harm scenarios including FDA Category X pregnancy drugs succeeding in 91.7% of dialogues. A proof-of-concept against flagship models showed 100% vulnerability for two of them across five dialogues each and 80% for a third. The caveats matter: it is a controlled simulation rather than field data, the main experiment used lightweight models with only a small proof-of-concept on flagships, and three co-authors disclose company roles.

    Worse for the standard mitigation story, work published in Nature Communications in February 2025 ran 594 attacks against four vision-language models in oncology and found all of them susceptible, with sub-visual prompts embedded in medical imaging data causing harmful output while remaining non-obvious to human observers. A human-in-the-loop who cannot see the injection cannot review it away. Pair that with FDA's own automation-bias language and “we have a human in the loop” stops being a complete answer.

    For a cardiology practice the exposed channels are inbound faxes, referral PDFs, portal messages and payer or device-manufacturer portals — unauthenticated text entering a system that treats text as instruction. We should be honest that this is reasoning by extension: we found no published study of prompt injection via patient portal messages, referral faxes or payer portals in a live practice. The absence of evidence is itself the reportable fact. Treat mitigation as blast-radius reduction — least privilege at the API boundary, read-only by default, unique agent identity, audit controls, out-of-band confirmation for irreversible actions — and refuse any vendor's injection-detection accuracy rate, because no independent benchmark for clinical prompt-injection defence exists either.

    Who Attests to an AI-Drafted Note — the Section That Matters Most

    If you read one section of this article before signing anything, read this one. Everything else is engineering. This is the part that determines who is personally liable when a note is wrong.

    CMS has answered the question directly, in a document that names artificial intelligence explicitly. Medicare Program Integrity Manual, Chapter 3, §3.3.2.4, on signature requirements:

    NOTE: When a scribe is used by a provider in documenting medical record entries (e.g., progress notes), CMS does not require the scribe to sign/date the documentation. The treating physician/non-physician practitioner's (NPP's) signature on a note indicates that the physician/NPP affirms the note adequately documents the care provided. We note this type of practitioner concurrence is also required when using Artificial Intelligence (AI) technology to capture the transcription of medical record entries.

    CMS Medicare Program Integrity Manual (Pub. 100-08), Chapter 3, §3.3.2.4

    That single note is the whole ambient-documentation compliance story. The AI does not sign, and its non-signature is fine — because the practitioner's signature is doing the attesting for both. An AI scribe has the documentary status of a human scribe: it drafts, the clinician authenticates.

    The same section closes every workaround. Reviewers shall not consider attestation statements from someone other than the author of the medical record entry in question — explicitly including cases where two individuals are in the same group, where one should not sign for the other. Contractors shall not consider attestation statements where there is no associated medical record entry. And an attestation cannot be used to backdate a plan of care. On electronic signatures, the individual whose name is on the alternate signature method and the provider bear the responsibility for the authenticity of the information attested to.

    CMS even publishes a model attestation statement, and its wording tells you everything about where liability sits. It is first-person, it is credentialed, and it ends: “I do hereby attest that this information is true, accurate and complete to the best of my knowledge and I understand that any falsification, omission, or concealment of material fact may subject me to administrative, civil, or criminal liability.” Note the word omission in a statement signed by a physician about a note drafted by a system whose dominant failure mode is omission. That is not a coincidence you can contract away.

    The defensible practice-level rule. The signature is the attestation. If a physician signs a note containing an omitted negative or an invented exam finding, the physician is the author of that error. Nothing in any vendor contract transfers that. Design your workflow so the signature is a genuine review event with time on the clock — not a batch action at 7pm across nineteen notes.

    Two related boundaries follow from the same principle. There is no “incident to” pathway for AI-performed work: 42 CFR §410.26(a)(1) defines auxiliary personnel as any individual acting under supervision who has not been OIG-excluded and who meets applicable state licensure requirements. Software is not an individual, cannot be excluded, and cannot hold licensure. Whatever an agent does is either an administrative task requiring no licensure, or a task whose professional component was performed by a named licensed human. And artificial entities have no professional powers at all — California Business & Professions Code §2400 states that corporations and other artificial legal entities shall have no professional rights, privileges, or powers, with §2052(b) extending unlicensed-practice liability to anyone who aids or abets. The exposure never lands on the agent. It lands on the practice and on the individuals who deployed it.

    Consent to record: the live legal risk, and it is not theoretical

    Two putative class actions are active against health systems — not against the vendor — over ambient recording. A proposed class action filed around November 26, 2025 in San Diego alleges a system recorded doctor-patient conversations without consent, with reporting referencing more than 100,000 patients. A second, filed in the U.S. District Court for the Northern District of California on April 7, 2026, names three health-system defendants and pleads the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, the Unfair Competition Law, the federal Wiretap Act and common-law intrusion upon seclusion. The plaintiffs' theory is that the violation occurs at the moment of interception, so a downstream privacy policy does not cure it. These details come from law-firm and trade analysis; we did not fetch the dockets.

    The allegation practices should study hardest is from the first complaint: that the software auto-inserted statements into charts asserting that the patient had been advised of recording and had consented, when the patient says they were never asked. A consent checkbox defaulted on inside the tool is not patient consent — it is a fabricated record of consent, which is a materially worse problem than having no record at all.

    Consent for ambient recording is governed by state wiretap and eavesdropping statutes, which are separate from HIPAA. HIPAA permits the use under a business associate agreement; a BAA is not consent. Sources disagree on how many states require all-party consent — the count varies between eleven and twelve depending on how hybrid states are treated — so we will not print a number. California Penal Code §632 is the concrete example, and it is the provision pleaded in both suits.

    Layer on the state disclosure duties that are already in force, because they attach to the practice rather than to the vendor. California's AB 3030, effective January 1, 2025, requires a generative-AI disclaimer and human-contact instructions on communications pertaining to patient clinical information — with two exits that matter operationally: the requirement does not apply if the communication is read and reviewed by a licensed or certified human provider, and “patient clinical information” expressly excludes administrative matters including appointment scheduling and billing. So your appointment-confirmation agent needs no disclaimer; an agent answering “should I be worried about this palpitation?” does, unless a licensed human read it first. Texas HB 149 §552.051(f), in force since January 1, 2026, is broader on its face: where an AI system is used in relation to health care service or treatment, the provider must disclose to the recipient no later than the date the service is first provided, with no human-review exemption written into it. Texas SB 1188 §183.005 permits practitioners to use AI for diagnostic purposes provided they act within their licence regardless of the use of artificial intelligence, review all records created with AI, and disclose the use. Those five words — regardless of the use of artificial intelligence — are the entire doctrine. The licence, and therefore the liability, does not move. And California's AB 489, effective January 1, 2026, makes it a per-use violation for AI to hold itself out with terms implying a health-care licence: naming your intake agent “Nurse” anything is a violation each time it is used.

    The Human-in-the-Loop Boundary Table

    Every implementation needs this written down before the first line of code, signed by the medical director and the compliance lead, and enforced in configuration rather than in a policy binder. Clinical judgement, billing attestation, and anything with legal or safety consequence stay human. Here is the cardiology version.

    Decision or actionAutonomy permittedWho commits itGoverning authority
    Schedule or reschedule an echo, stress or nuclear study; send and confirm prep instructionsAgent may complete; exceptions route to a humanFront-office lead owns the exception queue21 U.S.C. §360j(o)(1)(A) — administrative support of a health care facility, excluded from the device definition by statute
    Check eligibility, move claims and billing data, assemble a prior-auth packetAgent may complete; a human submitsAuthorization coordinator21 U.S.C. §360j(o)(1)(A)
    Accumulate RPM transmission days and documented management minutes per patient per monthAgent may complete — it is arithmetic over data the chart already holdsRCM manager reviews the ledger before any claim is builtRead-and-reason only; available through certified read APIs
    Order the device-alert worklist by administrative attributesAgent may order the queueDevice-clinic clinician opens every alert regardless of rankDesign boundary. Ordering is not interpreting — write the constraint into the configuration
    Classify an arrhythmia or device alert as clinically significantNeverClinician only21 U.S.C. §360j(o)(1)(E) — analyzing a pattern or signal from a signal acquisition system is a device; no enforcement discretion
    Predict a cardiac event within the next 24 hoursNeverNot a permissible agent function without device clearanceFDA's own worked example: the same risk model that gets enforcement discretion for future risk fails Criterion 4 when the horizon is 24 hours
    Present a list of guideline-based follow-up or next-step options to a clinicianAgent may presentClinician decides and documents21 U.S.C. §360j(o)(1)(E) — non-device if all four criteria are met and the clinician can independently review the basis
    Draft the clinical note from the encounterAgent draftsThe authoring clinician signsCMS Medicare Program Integrity Manual Ch. 3 §3.3.2.4 — practitioner concurrence required for AI-captured entries
    Sign or attest to a note, or attest to a claimNever, in any configurationThe author-clinician personallyCMS PIM Ch. 3 §3.3.2.4 bars attestation from anyone other than the author of the entry; 42 CFR §424.36 governs the beneficiary signature on the claim
    Answer a patient's question about clinical information in writingAgent draftsA licensed human reads it before it goes out, or the message carries the required disclaimerCal. Health & Safety Code §1339.75 (AB 3030) — the human-review exit removes the disclaimer requirement; scheduling and billing are excluded from the definition of patient clinical information
    Perform any component of work billed incident to a physician's serviceNeverA licensed individual42 CFR §410.26(a)(1) — auxiliary personnel means any individual meeting state licensure. Software is not an individual
    Present itself to a patient with a clinical title or personaNeverNot applicableCal. B&P Code §4999.9 (AB 489) — each use is a separate violation; naming your agent Nurse anything is the concrete failure
    Release records, send outbound patient messages, or move moneyAgent drafts; irreversible actions require out-of-band confirmationNamed human, loggedDesign reasoning, not a cited rule — label it that way in your own policy

    Human-in-the-loop boundaries for a cardiology practice. Authorities are cited so you can defend each row to an auditor rather than to a vendor.

    Three implementation notes about this table, learned the expensive way.

    The agent needs its own identity. 45 CFR §164.312(a)(2)(i) makes unique user identification required, not addressable, and §164.312(a)(1) requires access policies allowing access only to those persons or software programs granted access rights — the rule already contemplates software as an access principal. A shared service account that makes agent actions indistinguishable from a human's is the specific compliance failure to design out. It also makes the audit-log review in Phase 6 impossible, which means you would not detect the failures in the next section either.

    Minimum necessary applies to context windows. 45 CFR §164.502(b)(1) requires reasonable efforts to limit PHI to the minimum necessary for the intended purpose, and the treatment exception at §164.502(b)(2)(i) does not cover a billing, scheduling, prior-auth or quality-reporting agent. Retrieval context assembled for an RPM billing agent is not a treatment disclosure. “Dump the whole chart into the context window” is the practice this rule reaches.

    The business associate chain does not stop at the app vendor. Under 45 CFR §160.103 a model provider processing PHI is a business associate, the agent framework in front of it is a business associate, and the model provider's own cloud host is a subcontractor business associate requiring a downstream BAA. A single BAA with your scribe vendor does not close that chain. And §164.502(a)(3) limits a business associate to uses permitted by its contract — that is the clause a “we improve our models using your data” term collides with. Ask for the sub-processor list in writing. One major vendor's trust centre lists a foundation-model provider as a data sub-processor; that is a fact you want to know before signature, not after.

    One last honest note about the whole concept. “HIPAA-compliant AI” is not a product property. HIPAA attaches duties to covered entities and business associates, never to software. There is no OCR guidance defining a compliant AI product — every checklist claiming otherwise that we examined was a vendor blog. Rewrite the phrase in your own documents as “used under a BAA, with these named controls,” and you will immediately be able to tell which vendors can answer and which cannot.

    The Sequenced Implementation Path

    This is the reason the article exists. Not a list of benefits — an order of operations, with an owner per phase, an entry criterion, an exit criterion, and a written answer to what you do when the phase fails. Weeks overlap deliberately; the dependencies, not the calendar, are what matter.

    The sequencing principle is simple and it is the opposite of how most practices buy: start with the ledger, not the scribe. The RPM threshold ledger is pure read-and-reason work, needs no write access, produces a number your CFO can verify against a manual count, and tells you within five weeks whether your data is even in a computable state. The scribe is the workflow with consent exposure, an attestation surface and a vendor-discretionary write path. Doing the easy, verifiable, high-value thing first is how you earn the organisational credibility to do the hard one.

    PhaseWeeksOwnerEntry criterionExit criterionIf the phase fails
    Phase 0 — Baseline and consent postureWeeks 0–2Practice administrator + compliance leadExecutive decision to evaluate, and access to three closed months of dataWritten baseline covering: RPM-enrolled patients with the per-patient distribution of transmission days and documented minutes; device transmission and alert volumes; echo/stress/nuclear utilisation and no-show rates; and a recording-consent memo signed by counsel for every state you operate inStop. Without the baseline you cannot size the work, prove a benefit, or detect the drift that this article's what-breaks-first section is about
    Phase 1 — Read-only RPM threshold ledgerWeeks 2–5RCM manager + integration engineerCertified API credentials issued to a unique agent identity, not a borrowed clinician loginThe ledger reconciles to an agreed tolerance against a manual count on a 30-patient sample across one full calendar month, and the audit log shows zero attempted writesThe data is not in the chart in a computable form. Fix source capture — device feeds, time documentation templates — before writing any more software
    Phase 2 — Diagnostic-scheduling agentWeeks 5–9Front-office leadPrep protocols documented per modality, and a written list of which bookings a human must executePrep-completion rate for nuclear and stress studies no worse than baseline; same-day cancellation rate not up; every booking action traceable to a human or to a vendor-permitted write path with an audit recordRevert to the existing scheduling process and keep only the read-only reminder and waitlist functions. Do not fix a booking-quality problem by adding more autonomy
    Phase 3 — Ambient documentation pilot, one session typeWeeks 8–14Physician champion + compliance leadSigned BAA covering subcontractors, a written answer on audio retention, a live recording-consent script, and unique agent identity in the audit log100% of pilot notes signed by the authoring clinician; a blinded review of 30 notes against the encounter finds no unresolved omission of a negative cardiac finding or a medication; per-clinician edit rates recorded as a baselineReturn that clinician to dictation. Do not expand to a second session type while a single unresolved omission class is open
    Phase 4 — Device-alert worklist orderingWeeks 12–18Device clinic lead + medical directorA written, signed statement that the agent orders a worklist and never classifies clinical significanceNo alert exceeds its documented review SLA; a monthly reconciliation shows every high-priority alert was opened by a named clinician; queue position appears nowhere in the clinical recordFlatten the queue to chronological order. A chronological queue with a human reading it beats a clever queue nobody can audit
    Phase 5 — Prior-auth packet assembly for advanced imagingWeeks 16–24Authorization coordinatorA payer inventory separating Medicare Advantage plans, which carry the 2026 decision timeframes and denial-reason duties, from commercial and ERISA plans, which do notPacket completeness rate, median time-to-submission, and structured capture of every denial reason receivedKeep the packet assembly, drop the submission automation. Assembly is read-and-reason; submission is a write path you may not control
    Phase 6 — Governance, permanentlyFrom week 20, monthlyCompliance leadPhases 1–5 in production with audit logging onA monthly review covering audit logs, override and edit rates, drift in the RPM day and minute distributions, the §92.210 discrimination-risk inventory, and a quarterly re-verification of every vendor compliance claim you relied on at purchaseThere is no rollback from governance. If the review stops happening, the deployment has already failed and nobody has noticed yet

    Sequenced implementation path for a cardiology practice. Owners are roles, not people — but each role must be a named person before the phase starts.

    Phase 0 in detail — the baseline nobody wants to do and everybody needs

    Two to four weeks of unglamorous counting determines whether the next twenty weeks are measurable. The deliverable is a single document containing:

    1. 1.The RPM distribution: For three closed calendar months: per enrolled patient, days of data transmission received and minutes of management time documented. Not averages — the distribution. You are looking for the shape near the tier boundaries.
    2. 2.The device-clinic load: Transmissions received, alerts generated, alerts opened, and the time from alert to clinician review. If you cannot produce the last of those, that gap is your first finding.
    3. 3.Diagnostic utilisation by modality: Scheduled versus completed studies for echo, stress and nuclear separately, with same-day cancellation and no-show broken out, plus the consumable cost of a wasted nuclear study.
    4. 4.The documentation baseline: Time from encounter to signed note, per clinician, and the current after-hours pattern. Without it you cannot claim a documentation benefit later, and you will be asked to.
    5. 5.The consent memo: A written position from counsel on ambient recording for every state you operate in, plus the exact script and the exact logged event that will constitute consent. This gates Phase 3 entirely.
    6. 6.The vendor compliance file: For every vendor under consideration: the BAA, the sub-processor list, the SOC 2 report, and a written answer on audio retention. If a vendor will not provide these before signature, that is your answer about the vendor.

    A word on Phase 3's exit criterion, because it is the one practices try to negotiate. “A blinded review of 30 notes against the encounter finds no unresolved omission of a negative cardiac finding or a medication” sounds strict. It is calibrated to the evidence: 70% of draft notes in the instrument-validation study contained at least one error, omissions were the dominant class, and medication errors were the most common single error type in the simulated-encounter evaluation. You are not testing whether the product is good. You are testing whether your encounter conditions — your room acoustics, your accompanying family members, your clinicians' speech patterns — produce the error class that would matter most in your specialty. Thirty notes is a small enough sample to actually complete and a large enough one to surface a systematic problem.

    And a word on what not to sequence early. Do not start with an outbound patient-facing conversational agent. It carries the disclosure duties, the persona restrictions, the injection exposure and the consent surface all at once, and it produces the least verifiable benefit. Every phase above is either internal or human-committed at the boundary. That is not timidity; it is the order that lets you prove something before you risk something.

    What Breaks First, How You Detect It, and How You Roll It Back

    Every failure below has been designed for in the phases above. They are listed here separately because a deployment plan that names its failure modes in advance is the difference between an incident and a crisis.

    Failure modeDetection signalRollback
    Month-end threshold chasingA spike in interactive-communication events in the last three business days of the month; documented minutes clustering just above a tier boundaryRemove the countdown from the clinical view. Move threshold reporting to a weekly RCM report that never reaches a clinician mid-encounter
    Omitted negatives in the noteSampled blinded review counting notes where a stated negative — no chest pain, no syncope, no orthopnea, no PND — is absent from the note but present in the encounterReturn the affected clinician to dictation and require a structured negative checklist in the template until two consecutive clean review cycles
    Speaker attribution failuresReviewer-flagged pronoun errors and content attributed to the wrong speaker. Cardiology sees this constantly because a spouse or adult child is in the roomRestrict ambient capture to single-speaker segments, or disable it for visits with an accompanying caregiver, until the vendor demonstrates otherwise on your own recordings
    Queue order treated as triageA chart or an incident review in which queue position is offered as the reason an alert was opened lateFlatten to chronological. Remove the priority score from every surface a clinician sees
    Consent driftAn audit query comparing the consent-event timestamp to the recording start timestamp, run weekly. Any recording that starts first is a findingHard technical block: recording cannot start without a logged consent event. This is a configuration change, not a training issue
    Write-path breakage after an EHR upgradeA silent divergence between encounter count and filed-note count. Alert on the ratio, not on errors — RPA and browser pushes fail quietlyFall back to human filing with a daily reconciliation report until the vendor confirms the path is restored in writing
    Prompt injection through inbound unstructured textThere is no reliable detection signal, and we will not pretend otherwise. Faxes, referral PDFs, portal messages and payer portals are unauthenticated text entering a system that treats text as instructionReduce blast radius rather than claim a fix: read-only by default, least privilege at the API boundary, unique agent identity, audit controls, and out-of-band confirmation for anything irreversible

    Cardiology-specific failure modes with their detection signals and rollbacks. Every rollback should be executable by one named person in under an hour.

    The first row deserves elaboration because it is the one unique to this specialty and the one most likely to become a compliance problem rather than merely an operational one.

    Month-end threshold chasing is the cardiology failure mode. The moment an agent can count days and minutes, somebody starts treating the countdown as a work order. The telemetry signature is unmistakable: a spike in interactive-communication events in the final three business days of the month, and a distribution of documented management minutes that clusters just above a tier boundary rather than spreading naturally. That pattern is visible in your own data, which means it is also visible to anyone who audits your data, and it reads exactly as service driven by billing rather than by clinical need. The fix is architectural, not motivational: the countdown never appears in a clinical view. Threshold reporting goes to a weekly RCM report that a clinician never sees mid-encounter.

    The second and third rows — omitted negatives and speaker attribution — are the reason Phase 3 has a blinded review rather than a satisfaction survey. Clinicians will tell you the notes are good. Every study in this article that asked clinicians how they felt got a positive answer, and every study that measured the notes found errors. Both things are true simultaneously. Your review process has to measure the note, not the mood.

    The sixth row — silent write-path breakage — is where the read-only constraint becomes an operational reality rather than a legal footnote. If your scribe files notes through UI automation or a browser push, an EHR upgrade can break it without producing a single error message. Alert on the ratio of filed notes to encounters, not on error counts. A ratio that drifts from 0.99 to 0.94 over a week is the only signal you will get.

    And the seventh row is the one where we decline to offer you a detection signal, because none exists that we can defend. Prompt injection through inbound unstructured text has no reliable detector, vendor claims to the contrary have no independent benchmark behind them, and the peer-reviewed finding that injected prompts can be non-obvious to human observers means the human reviewer is not a detector either. What you can do is reduce blast radius: read-only by default, least privilege at the API boundary, a unique identity so a successful injection is reconstructable after the fact, and out-of-band confirmation before anything irreversible. Frame it that way internally too. A control that reduces damage is honest. A control that claims to prevent the attack is not.

    Cost, Timeline, and Working With Frenchy Digital

    These are our actual engagement bands, and they are the same across every article in this cluster because the work is scoped the same way regardless of specialty. What changes in cardiology is which workflow you start with, not what it costs to build one.

    EngagementRangeTimelineWhat it buys in a cardiology practice
    Discovery + workflow audit$9k–$22k2–4 weeksBaseline the three schedules, the RPM ledger gap and the consent position
    Single-workflow agent (RPM ledger, scheduling, prior-auth assembly, documentation)$28k–$70k4–9 weeksOne workflow, one owner, one exit criterion
    Multi-workflow platform with EHR/PM integration$70k–$180k9–16 weeksWhere the write-path negotiation with your EHR vendor actually happens
    Enterprise / multi-site / regulated build (audit logging, HITL, SOC 2 posture)$180k–$420k+14–24 weeksMulti-site device clinics, formal governance, evidence for an auditor

    Senior-led delivery at $150–$225 per hour. Ongoing retainers from $2,500 to $9,500 per month covering monitoring, revalidation after EHR and code-set changes, audit-log review and incident response. Every engagement carries a 30-day post-launch warranty. You receive a written, fixed-price, phased proposal within 5 business days of the discovery call, and full source-code and IP ownership transfers to you at delivery — we do not build businesses on your switching costs.

    Frenchy Digital is a senior-led, Black-owned agency based in Los Angeles. The people who scope your build are the people who build it.

    How we would sequence a cardiology engagement

    1. 1.Discovery and workflow audit ($9k–$22k, 2–4 weeks): The Phase 0 baseline above, delivered as a document you own: the RPM distribution, device-clinic load, modality utilisation, documentation baseline, consent position and vendor compliance file. Several practices stop here and implement internally. That is a legitimate outcome and we will tell you when it is the right one.
    2. 2.First workflow build ($28k–$70k, 4–9 weeks): Almost always the RPM threshold ledger, because it is read-only, verifiable against a manual count, and produces a number the practice can act on in the first closed month after go-live.
    3. 3.Platform build ($70k–$180k, 9–16 weeks): Scheduling, prior-auth packet assembly and documentation integration together, including the write-path negotiation with your EHR vendor — which is a commercial conversation, and one we will have alongside you rather than instead of you.
    4. 4.Regulated or multi-site build ($180k–$420k+, 14–24 weeks): Multi-site device clinics, formal human-in-the-loop controls, unique agent identity across systems, immutable audit logging and the evidence package an auditor or a payer would ask for.

    Book a discovery call at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601. If what you want is the Phase 0 baseline design so your own team can run it, ask on the call and we will walk you through it whether or not you hire us.

    Limitations: What We Could Not Verify

    Naming the gaps is more useful to an operator than papering over them. Here is everything material we could not establish while writing this, stated plainly.

    • No independent accuracy benchmark exists for any named ambient scribe: The two studies that measured correctness deliberately anonymised the products, so no accuracy figure can be attached to a named vendor. We do not know which platforms were A through E, or which products were A and B.
    • We could not identify the vendor used in the Wisconsin randomized trial: It is not named in the abstract, so one of the two strongest results in the category cannot be attributed to a product you could buy.
    • Public BAA statements are largely absent: We found none on the pages we fetched for Abridge, Microsoft Dragon Copilot, Nabla, Suki, DeepScribe or Commure. Only Sunoh (BAA included) and Freed (organization-wide BAA on Group plans) state it publicly. That is an observation about disclosure, not about whether a BAA is available.
    • HITRUST is claimed by no vendor we examined: If a comparison article tells you a scribe is HITRUST-certified, that claim is unverified as far as our checking goes.
    • Ambience's certifications are claimed but unnamed: The site says trusted and fully certified and names nothing; its /security page returns a 404.
    • Heidi's certification status, BAA and USD pricing could not be extracted: Its trust centre and HIPAA page returned effectively empty content to automated fetch, and its pricing page renders tiers inconsistently. Open it yourself before quoting anything about it.
    • Epic's built-in ambient charting tool has no confirmed product name and no published pricing: The only source we have describes the capability without naming the product. We will not invent a name for it, and we cannot tell you what it costs.
    • Oracle Health Clinical AI Agent and NextGen Ambient Assist rest on trade coverage only: No vendor page was fetched for either.
    • No Medicare payment amounts for any RPM code: The authoritative figures are in PFS Addendum B, which we did not fetch. Every circulating per-code dollar figure we chased came from a remote-monitoring vendor's billing guide.
    • The device-monitoring billing intervals are vendor-sourced: The 90-day interval, the 30-day minimum monitoring period and the mutual exclusivity of 93294 and 93295 appear only in vendor and manufacturer material. The 2026 NCCI Policy Manual contains no entry for 93294 through 93299.
    • We could not confirm the current corporate status of several RPM-adjacent vendors: A search on 2026-08-12 surfaced no acquisition, rename or shutdown for Octagos, Rhythm360, medxpertservices, Prevounce, ThoroughCare or Tenovi — but a negative search result is not a confirmation. Rimidi is confirmed acquired by Health Recovery Solutions in March 2026.
    • No definitive all-party-consent state list: Sources disagree, with counts of eleven and twelve and disagreement centred on hybrid states. We name California §632 as the concrete example and refuse a count.
    • No published court judgment exists on liability for an AI-drafted clinical note: The active litigation is about recording consent, not note accuracy. Anyone telling you how courts will treat an AI-drafted note is speculating.
    • Colorado's enforcement pause rests on law-firm reporting, not on the docket: The statutory picture itself is settled, and we state it rather than hedge it. SB 24-205 did take effect — its start date was pushed from February 1 to June 30, 2026 — so it is on the books today. SB 26-189, signed May 14, 2026, repeals and reenacts it effective January 1, 2027 under the enrolled bill's SECTION 5, applying to consequential decisions made on or after that date, and it carries a safety clause at SECTION 6 — so the August 12, 2026 date on leg.colorado.gov, a site-wide banner for bills passed without one, does not apply to it. What we could not verify at source is the enforcement posture: on April 27, 2026 a federal court is reported to have granted a joint motion in which the Attorney General stated he does not intend to enforce SB 24-205 until the rulemaking process has concluded. We did not fetch that order and we cite no case number. For a cardiology practice the operative point is the carve-out: HIPAA covered entities are excluded from the core sections from January 1, 2027, except for consequential decisions about employment, and owe patients a general notice that advanced technologies are in use.
    • No published study of prompt injection via portal messages, faxes or payer portals in a live practice: The peer-reviewed evidence covers patient dialogue and medical imaging. Our extension to fax and portal channels is reasoning, not a finding, and we label it as such.
    • The HIPAA Security Rule NPRM is still only proposed: Final action is projected for July 2027 on the Unified Agenda. The 2003 Security Rule as amended in 2013 governs today, which means encryption at rest is still addressable rather than required — a fact much of this market writes as though it had already changed.

    Red Flags When Buying a Documentation or Monitoring Vendor

    Each row below is a specific, checkable behaviour rather than a vibe. Run the list before the second sales call.

    Red flagWhy it matters, and what to ask instead
    Publishes an accuracy percentageThere is no independent benchmark in this category. Ask for the sample, the denominator, the definition of a correct note and the adjudication method, in writing. Silence is the answer
    Cannot say whether source audio is retained, and for how longIf audio is deleted immediately, no one can ever audit a disputed note against the encounter. If it is retained indefinitely, you own a new discovery target
    Will not put the BAA, the SOC 2 report and the sub-processor list in front of you before signatureDo not shortlist a vendor whose compliance posture you cannot verify without a sales call. One well-funded enterprise vendor on our roster says it is fully certified and names zero certifications
    Claims HITRUST certificationNo vendor we examined claimed HITRUST. If a listicle says a scribe is HITRUST certified, that claim is unverified
    Cites a KLAS score as evidence of accuracyKLAS Best in KLAS and KLAS Spotlight are customer-satisfaction instruments. Also refuse any side-by-side of a 2026 ranking and a 2025 commissioned spotlight — different years, different instruments
    Quotes a competitor's price from its own blogAt least one major vendor runs a large SEO operation publishing reviews of its competitors. Several top search results for competitor pricing are written by a competitor
    Calls a browser push or a copy-paste an integrationAsk which EHR it writes to, through what mechanism, under what agreement, and what happens at the next EHR upgrade
    Has no wind-down or data-export clauseAn ambient charting vendor ceased operations in autumn 2024 with roughly three days' notice to staff. Ask what happens to your notes and your audio if the company disappears
    Prices your RPM ROI using a dollar figure per codeEvery per-code dollar figure circulating for the 2026 RPM codes traces to a remote-monitoring vendor's billing guide. The authoritative source is PFS Addendum B
    Suggests the agent can attest, co-sign or auto-finalizeCMS names AI and requires practitioner concurrence. A vendor that does not know this does not know the compliance surface of its own product
    Recommends a general-purpose meeting transcriberGeneral-purpose notetakers are not designed for PHI, carry no BAA below enterprise tiers, and are the subject of active wiretap-statute litigation on exactly the consent theory being pleaded against health systems

    Vendor red flags for ambient documentation and remote-monitoring software. Checked against the vendor landscape as of 2026-08-12.

    One meta-red-flag worth stating separately, because it shapes everything you will read while researching this purchase: in the medical-practice AI market, almost every circulating operational statistic was published by a company selling software to the specialty it describes. That is true of the no-show cost figures, the phone-abandonment benchmarks, the RPM per-code dollar amounts, the device-interrogation billing intervals, and every scribe accuracy percentage in existence. When we could not find a non-seller source, we said so in this article rather than filling the gap. Apply the same test to whatever you read next: who published this number, and what do they sell?

    The three questions that decide the purchase. Does my EHR already include an ambient scribe, and at what cost? Will my EHR vendor permit this specific vendor to write to the chart, through what mechanism, and at what price? Can I get the BAA, the sub-processor list, the SOC 2 report, the audio-retention answer and a wind-down clause in writing before I sign? Everything else in the evaluation is preference. Those three are structural, and a vendor who cannot answer all three in writing has told you the answer.

    A closing note on what the zero-click clinic actually means, since this article is part of a cluster built around the idea. It is not an unstaffed practice and it must never be sold as one. It is a practice where the default administrative path completes without a human click, and where humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal or safety decision. In cardiology that means the ledger runs itself, the prep goes out and comes back confirmed, the packet assembles, the note drafts — and a named clinician still opens every alert and still signs every note. The point of removing the clicks is not to remove the people. It is to spend them where the statute, the payer and the patient actually need them.

    Start With the Ledger, Not the Scribe

    Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned LA agency. You leave with a written phase plan for your RPM, device-clinic and documentation workflows, and a fixed-price phased proposal within 5 business days.

    Start With the Ledger, Not the Scribe

    Book a free 60-minute discovery call with Frenchy Digital. You leave with a written phase plan for your own RPM and documentation workflows, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1Federal Register — CY2026 Medicare Physician Fee Schedule final rule, full text (90 FR 49266)
    2. 2GovInfo — CY2026 PFS final rule PDF (FR-2025-11-05)
    3. 3ASTP/ONC — Standardized API for Patient and Population Services, §170.315(g)(10) certification companion guide
    4. 4CMS — Medicare Program Integrity Manual, Chapter 3 (signature requirements, §3.3.2.4)
    5. 5FDA — Clinical Decision Support Software, final guidance (issued January 29, 2026)
    6. 6FDA — Clinical Decision Support Software final guidance town hall transcript (March 11, 2026)
    7. 7U.S. Code — 21 U.S.C. §360j(o), software functions excluded from the device definition
    8. 8eCFR — 42 CFR §410.26, services incident to a physician's service
    9. 9eCFR — 45 CFR §164.312, HIPAA technical safeguards
    10. 10eCFR — 45 CFR §160.103, business associate definition
    11. 11eCFR — 45 CFR §92.210, nondiscrimination in the use of patient care decision support tools
    12. 12eCFR — 42 CFR §422.122, Medicare Advantage prior authorization requirements
    13. 13PubMed — Ambient AI Scribes in Clinical Practice: A Randomized Trial (NEJM AI, UCLA Health)
    14. 14PubMed — Pragmatic RCT of Ambient AI to Improve Health Practitioner Well-Being (NEJM AI, Wisconsin)
    15. 15PMC — Evaluating the Quality and Safety of Ambient Digital Scribe Platforms Using Simulated Ambulatory Encounters
    16. 16PMC — Accuracy and Safety of AI-Enabled Scribe Technology: Instrument Validation Study (JMIR)
    17. 17PMC — Use of Ambient AI Scribes to Reduce Administrative Burden and Professional Burnout (JAMA Network Open)
    18. 18The Permanente Federation — Quality assurance informs large-scale use of ambient AI clinical documentation
    19. 19PubMed — Allocation of Physician Time in Ambulatory Practice (Sinsky et al., Ann Intern Med 2016)
    20. 20PubMed — Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice (JAMA Netw Open)
    21. 21PubMed — Prompt injection attacks on vision language models in oncology (Nature Communications)
    22. 22Alston & Bird — Your AI Scribe May Be Taking Notes, and Plaintiffs Are Too
    23. 23HIPAA Journal — Lawsuit alleges AI platform illegally recorded patient-clinician conversations
    24. 24Abridge — Trust Center
    25. 25Microsoft — Dragon Copilot product page
    26. 26Nabla — Security page (SOC 2 Type II, ISO 27001)
    27. 27Freed — Pricing and FAQ (published prices, audio retention)
    28. 28Sunoh.ai — Pricing (published price, BAA included)
    29. 29Suki — Product site (EHR integrations, SOC 2 Type 2)
    30. 30Ambience Healthcare — Series C announcement
    31. 31SEC — Augmedix 8-K exhibit on the Commure merger
    32. 32MedCity News — Ambient scribe startups and Epic's built-in charting tool (Feb 2026)
    33. 33TechTarget — athenahealth unveils AI-native EHR capabilities (athenaAmbient)
    34. 34KLAS Research — Best in KLAS, Ambient Speech 2026
    35. 35Federal Register — ASTP/ONC HTI-5 proposed deregulatory rule (Dec 29, 2025)
    36. 36DeepScribe — product site (named integrations, oncology customers, 2025 KLAS Spotlight)
    37. 37Heidi Health — pricing page (tier names published, no USD prices)
    38. 38Commure — Scribe product page (named customers, SOC 2 Type II claim)
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital, a senior-led Black-owned Los Angeles agency building AI agents and custom software for healthcare operators.