Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Healthcare AI
    August 12, 2026
    31 min read

    AI Agents for OB-GYNPractice Automation in 2026

    Obstetrics does not schedule appointments, it schedules a protocol-driven series across nine months, and it bills the whole thing as one claim at the end. This is the implementation guide: the workflows in order, the owners, the entry and exit criteria per phase, what breaks first, and the privacy line an agent in this specialty must never cross.

    AI agents in an OB-GYN practice in 2026 — prenatal visit series scheduling, global obstetric package accounting, gynecologic surgery coordination and reproductive-health privacy controls
    ~13
    Routine prenatal visits included in the global obstetric package for uncomplicated cases
    UnitedHealthcare Commercial Reimbursement Policy 2026R0064A
    1 claim
    What a full course of prenatal care can produce — filed after delivery, as a single unit
    UHC 2026R0064A; CMS NCCI Policy Manual 2026, Ch. VIII/IX
    91.7%
    Prompt-injection success in simulated FDA Category X pregnancy-drug dialogues (controlled simulation, not field data)
    Lee RW et al., JAMA Netw Open 2025;8(12):e2549963
    $28k–$70k
    Single-workflow OB-GYN agent, built and integrated, 4–9 weeks
    Frenchy Digital scoping, 2026

    Key Takeaways

    • Obstetrics does not schedule episodes, it schedules a protocol-driven series: approximately 13 routine prenatal visits for uncomplicated cases per UnitedHealthcare's 2026 obstetrical policy, across roughly 40 weeks, with the cadence tightening toward term and an unschedulable event — labor — pulling the physician out of clinic without notice.
    • Twelve months of care can produce one claim. The global codes 59400, 59510, 59610 and 59618 are billed as a single unit after delivery, so the practice's receivable for that patient is invisible until then, and the separately billable deviations must be captured contemporaneously and submitted later. That is a memory problem across nine months and it is the most defensible place for software in this specialty.
    • High-risk and complication E/M visits are held, not billed as they occur: UHC's policy says they should not be reported until after delivery, must carry modifier 25 with a high-risk diagnosis, and — per ACOG — must not be reported at all if the monitored problem never developed. An agent may hold and assemble those lines; a clinician decides which survive.
    • Certified API access under §170.315(g)(10) is read-only. The ONC/ASTP Certification Companion Guide, updated 05-15-2026, states the services specifically exclude write capabilities. Every EHR write your agent performs is vendor-discretionary — a commercial arrangement, UI automation, or a human. Get the write path in writing before you scope.
    • The privacy posture in this specialty is stricter than the regulation requires, deliberately. HIPAA has no rule about the mere fact of association comparable to 42 CFR Part 2 for substance-use records. Outbound messages should therefore carry date, time, location and a human contact — and no visit type, diagnosis, procedure name or gestational reference.
    • An agent never attests. CMS Program Integrity Manual Ch. 3 §3.3.2.4, effective January 17, 2025, requires practitioner concurrence when AI captures record entries, refuses attestations from anyone but the author, and refuses attestations with no associated entry. 42 CFR §410.26(a)(1) leaves no incident-to pathway for software, which is not an individual and cannot hold licensure.
    • Administrative automation sits outside the FDA device definition by statute: 21 U.S.C. §360j(o)(1)(A) names appointment schedules, claims and billing information, practice management and benefit-eligibility determination. Clinical recommendation moves you under §360j(o)(1)(E) and its four criteria, where FDA's January 29, 2026 guidance offers enforcement discretion — not clearance — over a Criterion 3 failure.
    • Prompt injection is unsolved, and obstetric scenarios sit inside the highest-harm category the published work tested. In Lee et al. (JAMA Netw Open, Dec 2025), attacks achieved 94.4% success at turn 4 across 216 evaluations, and 91.7% in the extremely high-harm scenarios that included FDA Category X pregnancy drugs. Controlled simulation, lightweight models in the main arm, three co-authors with company roles — cite it with all of that attached.
    • Human review does not close the gap on its own. Clusmann et al. (Nat Commun, Feb 2025) found all four tested vision-language models susceptible, including to sub-visual prompts that are non-obvious to human observers, and FDA's own 2026 material describes automation bias worsening under time pressure.
    • 45 CFR §92.210 imposes an ongoing duty to identify and mitigate discrimination risk in patient care decision support tools that use input variables measuring race, color, national origin, sex, age or disability — AI or not. In obstetrics, sex is an input to essentially every risk tool in the building, so this is a live inventory task rather than a hypothetical one.
    • We refuse the circulating numbers. There is no independent benchmark for AI accuracy in scheduling, coding, scribing or voice agents in this market — every figure is vendor-published — and the standard no-show and phone-abandonment statistics trace to unsourced vendor bylines. We say that in the article rather than repeating them.
    • Frenchy Digital cost bands: discovery $9k–$22k; single-workflow agent $28k–$70k; multi-workflow platform with EHR/PM integration $70k–$180k; enterprise multi-site build $180k–$420k+.

    Why OB-GYN Is the Hardest Administrative Problem in the Cluster

    Almost every specialty guide about AI in medical practices makes the same silent assumption: that a patient visit is a transaction. Someone books, someone arrives, someone documents, someone bills. Automate any link in that chain and you have automated something real.

    Obstetrics breaks that assumption twice. The visit is not a transaction, it is one rung on a ladder that has to be climbed in order across roughly forty weeks. And the claim is not attached to the visit — under the global obstetric package, twelve months of care can produce a single claim, filed after delivery. A practice administrator who has run a dermatology or an orthopedic front office and then walks into an OB-GYN practice discovers that most of the operational intuitions transfer and the two most important ones do not.

    That is not a reason to avoid automation here. It is the reason automation here is unusually valuable, because the work that software is best at — counting, remembering, reconciling, and not getting bored — maps almost exactly onto what this specialty actually finds hard. What it is a reason for is building in a specific order, with a specific boundary, which is what this article lays out.

    The frame for everything below.Nothing in this guide proposes an agent that makes a clinical decision, attests to a record, releases information, or acts on a payer's behalf. The agents described here are administrative and documentation systems that read, count, assemble, draft and route, under human review, with every consequential action requiring a human to commit it. That boundary is not caution for its own sake — as the regulatory section shows, it is where the statutory safe ground actually is.

    One more scoping note before the workflows. There is a widely cited finding that for every hour of direct clinical face time, physicians spend nearly two additional hours on EHR and desk work. It comes from Sinsky and colleagues in the Annals of Internal Medicine in 2016, and it is worth citing with its limits every single time: 57 physicians, 430 observed hours, four specialties — family medicine, internal medicine, cardiology and orthopedics — in four states, with 21 physicians self-reporting after-hours diaries showing one to two hours nightly, and the authors themselves noting the data came from self-selected, high-performing practices and may not generalize. Note what is not on that specialty list: obstetrics and gynecology. We could not locate an equivalent time-motion study for this specialty. If someone quotes you an OB-GYN-specific administrative burden figure, ask where it came from before you put it in a business case.

    The Global Obstetric Package Is a Nine-Month Memory Problem

    Start with the structure, because everything operational follows from it. Under the global obstetric package, the practice reports one code covering antepartum care, the delivery and postpartum care: 59400 for routine obstetric care with vaginal delivery, 59510 for cesarean, 59610 for vaginal delivery after previous cesarean, and 59618 for cesarean delivery after previous cesarean. The global codes are billed as one unit, with either a single date of service or a date span.

    The specifics in this section come from UnitedHealthcare's Commercial and Individual Exchange Reimbursement Policy 2026R0064A, which follows CPT and ACOG, corroborated by the CMS National Correct Coding Initiative Policy Manual for 2026. Read the payer-variance warning in the limitations section before you treat any of it as universal — Medicaid programs frequently unbundle prenatal care entirely.

    The package includes all routine prenatal visits until delivery — "approximately 13 for uncomplicated cases"in the policy's own words. That number is worth pausing on, because it is one of the very few clean, sourceable operational figures in the entire medical-AI market. It is not a vendor benchmark. It is stated in a national payer's published reimbursement policy, sourced to CPT and ACOG, and you can open the PDF and read it. Most numbers in this market do not survive that test, which is why this article prints so few of them.

    ServiceInside or outside the packageWhat it means for an agent
    Routine prenatal visits until delivery — approximately 13 for uncomplicated casesInside the packageThe visit count is the spine of the whole ledger. An agent tracks it; nobody bills it separately.
    Initial and subsequent history and physical; weight, blood pressure, fetal heart tonesInside the packageRoutine encounter content. No separate line, no separate authorization.
    Routine chemical urinalysis (81000, 81002)Inside the packageNCCI 2026 restates it: antepartum care includes urinalysis, which is not separately reportable.
    Admission H&P; inpatient E/M within 24 hours of delivery; management of uncomplicated labor; the delivery; delivery of the placentaInside the packageNCCI 2026 also names 59050/59051 fetal monitoring during labor, 59300 episiotomy and 59414 delivery of placenta as not separately reportable.
    IV oxytocin administration or induction; cervical dilator inserted the same date as deliveryInside the packageThe dilator timing is the trap — see the excluded row below.
    Repair of first- or second-degree lacerationsInside the packageThird- and fourth-degree repairs are reported by appending modifier 22 to the global or delivery-only code with supporting documentation, not by a separate repair code.
    Uncomplicated inpatient post-delivery visits; routine outpatient E/M within 6 weeks of delivery; lactation and newborn-care educationInside the packageThe postpartum window is inside the package. Booking it is scheduling work, not billing work.
    Initial E/M to diagnose pregnancy, if the antepartum record is not started at that visitSeparately billableSupported by Z32.01. If the record is started at that visit, it folds into the package. The agent flags the fork; a human resolves it.
    Maternal and fetal ultrasound 76801–76828; amniocentesis; amnioinfusion; chorionic villus samplingSeparately billableDifferent resource, different authorization rail, different claim. This is where a second scheduling problem lives.
    Fetal contraction stress test; fetal non-stress test; external cephalic versionSeparately billableHigh-yield capture targets. They happen mid-series and are easy to lose before delivery.
    Cervical dilator inserted more than 24 hours before delivery; inpatient E/M more than 24 hours before deliverySeparately billableTwo 24-hour clocks that a human will not reliably reconstruct nine months later. A machine will.
    E/M for conditions unrelated to the pregnancy; management of surgical problems arising during pregnancySeparately billableThe relatedness judgment is clinical. The agent surfaces the candidate; it does not decide.
    Additional E/M visits beyond the typical 13 for complications or high-risk monitoringSeparately billable — but held until after deliveryModifier 25 plus a high-risk diagnosis, reported only after delivery. And per ACOG, not reported at all if the monitored problem never developed.
    Laboratory tests other than routine chemical urinalysisSeparately billableNCCI 2026 lists genetic screening among the services the total obstetrical packages do not include.

    Global obstetric package composition per UnitedHealthcare Reimbursement Policy 2026R0064A, with corroborating language from the CMS NCCI Policy Manual 2026. One payer's policy — verify yours.

    Now the timing rule, which is the one that governs the entire revenue cycle and which almost no general-purpose practice software models correctly. High-risk and complication E/M visits "should not be reported until after the patient delivers," because — quoting the policy — "it is not until then that appropriate assessment for the number of antepartum visits can be made." Those visits must carry modifier 25 and a high-risk diagnosis. And there is a second condition on top, drawn from ACOG: if the extra visits were performed to monitor a potential problem and no problem actually developed, the additional visits are not reported at all.

    Sit with what that asks of a practice. A visit that happens in March generates a billing decision in November, and the input to that decision is a clinical judgment about why the visit happened and how the pregnancy subsequently went. The information needed to make it correctly is recorded across nine months in a chart nobody re-reads end to end. This is a memory and reconciliation problem, and it is the single most defensible place for software in this specialty.

    The 24-hour clocks.Two of the package's boundaries are timing boundaries rather than service boundaries: an inpatient E/M more than 24 hours before delivery is separately billable while one within 24 hours is not, and a cervical dilator inserted more than 24 hours before delivery is separately billable while one inserted the same date is not. Nine months later, no human reconstructs those two clocks reliably from a chart. A machine reconstructs them perfectly and instantly. That asymmetry is the whole argument for building here.

    There is also a case the ledger must handle from day one: shared care. When the practice does not provide the full course — the patient transfers in, transfers out, or changes insurer mid-pregnancy — the antepartum-only codes apply: 59425 for four to six visits and 59426 for seven or more, reported as a single claim submission and excluding the confirmatory visit. Fewer than four visits are itemized as E/M. Any agent that assumes every pregnancy in the panel is a full-course pregnancy will be wrong about a meaningful share of the panel, and it will be wrong quietly.

    Two more mechanics from the NCCI manual that a billing agent should encode as hard rules rather than suggestions. Maternity procedures carry a global period of MMM on the Medicare Physician Fee Schedule Database, and wound repair codes 12001–13153 shall not be reported to describe closure of a surgical incision for codes with an MMM global period. Third- and fourth-degree lacerations are handled instead by appending modifier 22 to the global or delivery-only code with supporting documentation — and that determination is clinical, so the agent flags the candidate and stops.

    The Five Workflows Worth Automating First

    The prenatal series is a scheduling problem unlike any other in outpatient medicine. It is a cadence, not a calendar: monthly, tightening to biweekly, tightening to weekly toward term, interleaved with imaging appointments that sit on a different resource with a different authorization rail — and all of it running against an unschedulable event. Labor pulls the physician out of clinic without notice, and the cancellations it causes do not cost one appointment. They cost a rung on a ladder, and the ladder has a deadline that cannot move.

    On top of that sits a gynecologic surgical block, a postpartum window inside the global package, and a well-woman recall cadence for the non-obstetric side of the panel. No other specialty in this cluster has a scheduling problem this structurally hard, which is exactly why an agent that treats each booking as independent produces a calendar that is technically valid and operationally wrong.

    WorkflowWhat the agent actually doesRead or writeExit criterionWhat stays human
    Antepartum visit ledgerA running count of routine visits against the ~13 baseline, per patient, with each encounter classified in-package or excludedRead-only. Computes over data the chart already holds.Ledger agrees with the biller's manual count on delivered charts; every disagreement carries a written reasonNone. It is a worklist, not a claim.
    Deferred-billable captureTagging NSTs, stress tests, unrelated E/M and out-of-window inpatient encounters as they occur, holding them for the delivery-time claim packetRead-only to detect; human to confirm; write only where the EHR vendor grants itEvery held line has a source encounter, a date, and a proposed modifier — and a clinician has signed off before submissionA clinician confirms each line. ACOG's 'no problem developed, do not report' rule is a judgment, not a rule an agent can apply.
    Series adherence and outreachDetecting a missed rung in the cadence — monthly, then biweekly, then weekly — and generating outreach with no clinical contentRead to detect; message send is a write into a communication system, not the EHROutreach fires on the right patients at the right interval and contains only date, time, location and a human contactThe clinical significance of a missed visit is a clinician's call. The agent reports the gap, it does not triage it.
    Ultrasound and imaging authorization trackingWhich studies are ordered, which are authorized, which authorizations are expiring, which are unbilledRead-only against the chart; payer portals are outside the health-IT rail entirelyNo study is performed on a lapsed authorization, and no authorized study goes unbilled at deliveryMedical necessity for the study is clinical. The agent tracks paperwork state.
    Delivery-time claim assemblyAssembling the global code, the date span, the held modifier-25 lines and the supporting documentation into one reviewable packetRead to assemble; a human commitsThe packet is complete and internally consistent before it reaches the biller, and the biller's rework time falls against a measured before-stateThe signature. Always. There is no configuration in which an agent attests.

    Frenchy Digital workflow shortlist for OB-GYN practices, 2026, ordered by defensibility.

    Notice what is not on that list. There is no triage agent, no symptom checker, no autonomous messaging, no coverage determination. Those are the workflows vendors lead with, and they are the ones that either cross the FDA line, cross a state disclosure line, or put untrusted patient text directly into an agent's instruction path. The five above have a common profile: they compute over data the chart already holds, they hand a human a conclusion, and if they are wrong the cost is a wasted worklist rather than a clinical or legal event.

    Why the antepartum ledger goes first, every time

    It is the only workflow on the list where you can prove correctness against ground truth you already possess. Take thirty consecutive delivered charts, have the biller count the routine antepartum visits by hand, and compare. Either the agent reproduces the count or it does not, and every disagreement is a specific, inspectable case — a transfer-in, a visit miscategorized as routine, an encounter recorded on a service the ledger did not consider.

    That property is rarer than it sounds. Most proposed medical AI workflows cannot be validated against anything except a vendor's own accuracy claim. This one can be validated against your own biller in an afternoon, which means the first deliverable of the whole programme is a number your practice generated rather than a number a vendor gave you.

    The imaging rail deserves its own note. Maternal and fetal ultrasound 76801–76828 sits outside the package, on separate authorization, often on a separate resource with its own capacity constraints and sometimes at a separate site. Two failure modes recur: a study performed on a lapsed authorization, and a study performed and then never billed because it was mentally filed under "the pregnancy" and the pregnancy is billed as one code at the end. Both are detectable from data the chart already holds, and both are pure paperwork-state tracking with no clinical judgment involved.

    Gynecologic Surgery Scheduling: A Second Calendar With Different Rules

    The gynecologic side of the practice runs on a different clock and different billing constructs, and it has to be reconciled against an obstetric calendar that can be disrupted at any hour. Surgical scheduling here means pre-authorization, facility or ASC coordination, pre-op clearance from other practices, and a date that must survive the surgeon's call exposure.

    The billing constructs come from the Medicare Claims Processing Manual, Chapter 12, and two of them are worth encoding as pre-submission checks because the manual states them explicitly and both are easy to get wrong at claim time. The first is the modifier distinction: if an evaluation and management service occurs on the day of surgery, the physician bills using modifier -57, not -25, and -57 is not used with minor surgeries because the global period for minor surgeries does not include the day prior. The second is split care: where physicians agree on transfer of care during the global period, the surgeon reports the surgical code with modifier -54 and the post-operative provider reports the same code, same date of service, with modifier -55 — and the date on which care was relinquished or assumed must be shown on the claim in the remarks field.

    Surgical workflowWhat the agent doesBoundaryWhat stays human
    Pre-authorization packet assemblyPull the indication, prior conservative management, imaging and pathology from the chart into the payer's required structureAssembly is administrative and inside the statutory exclusion at 21 U.S.C. §360j(o)(1)(A)Submission and any clinical justification narrative are reviewed and owned by a human
    Pre-op clearance chaseTrack which clearances are outstanding, from whom, for how long, and what is blocking the dateRead-only chase list; outbound requests are drafted, not sent autonomouslyThe clinical adequacy of a clearance is the surgeon's judgment
    Facility and block coordinationReconcile the practice calendar against hospital or ASC block time and the surgeon's obstetric call exposureProposes; never allocatesBlock allocation and case order stay with the surgeon and the facility
    Global-period awarenessFlag post-op encounters that fall inside the global period so they are not billed as new E/MRead-only, pre-submission checkWhether an encounter is genuinely unrelated is a clinical determination
    -57 versus -25 pre-submission checkClaims Processing Manual Ch. 12 is explicit: if an E/M occurs on the day of surgery, the physician bills modifier -57, not -25, and -57 is not used with minor surgeries because their global period does not include the day priorRead-only rule check before the claim dropsThe underlying decision — was this the decision-for-surgery visit — is documented by the physician
    Split-care claims (-54 / -55)Where care is transferred during the global period, surface the relinquished and assumed dates that must appear in the claim's remarks fieldRead-only extraction of dates the chart already holdsThe written transfer agreement is a signed clinical hand-off and both charts must hold a copy. Not automatable.

    Gynecologic surgery coordination workflows and their boundaries, Frenchy Digital, 2026.

    There is one item in the split-care mechanism that is emphatically not automatable, and it is worth naming because the surrounding paperwork looks so automatable that people assume it comes along. Chapter 12 requires that both the surgeon and the physician providing post-operative care keep a copy of the written transfer agreementin the beneficiary's medical record. That is a signed clinical hand-off between two named humans. An agent can detect that it is missing, chase it, and refuse to let the claim proceed without it. An agent cannot be a party to it.

    Prior authorization deserves a realistic framing here rather than an optimistic one. CMS-0057-F is frequently pitched to practices as though it were about to solve their authorization problem. Read the rule text: every obligation in 42 CFR §422.122 runs to "an MA organization." It binds payers, not practices. What is live now is the payer side of the exchange — a specific reason for denial regardless of the communication method beginning January 1, 2026, and public reporting of prior-authorization metrics. The payer FHIR prior-auth API is a January 1, 2027obligation, and even then a practice's relationship to it is as a potential consumer, not as a duty-holder. Plan your authorization workflow around document exchange and portals, because that is what you will be doing through 2026.

    Certified API Access Is Read-Only. Every Write Is a Negotiation.

    This is the single most important architectural constraint in medical AI, and it is the one most often left out of a sales conversation. The ONC/ASTP Certification Companion Guide for §170.315(g)(10), last updated 05-15-2026, states it plainly:

    The § 170.315(g)(10) certification criterion requires Health IT Modules to support API-enabled 'read' services for single and multiple patients. … These services specifically exclude 'write' capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.

    ONC/ASTP Certification Companion Guide, § 170.315(g)(10), updated 05-15-2026

    Read that as an operational sorting rule. Anything your agent needs to know is available through a certification-backed pathway in any certified EHR. Anything your agent needs to do inside the EHR — book the slot, move the appointment, post the charge, file the note, update the problem list — happens one of exactly three ways: through a write API your EHR vendor chooses to offer you on commercial terms and after its own app review, through user-interface automation with the fragility and terms-of-service exposure that implies, or through a human clicking a button.

    The exact question to ask your EHR representative, in writing."For our licensed edition and version, which specific write operations can a third-party application perform — creating or modifying an appointment, posting a charge, filing a note, updating a problem list, sending a patient message — and under what contract, app-review process, per-transaction fee and rate limit? If any of those are not available, please confirm that in writing." Get the answer before you scope a project, not during it. A vendor answer of "we support FHIR" answers a different question than the one you asked.

    There is a security dividend in this constraint that is worth taking deliberately rather than accidentally. An agent that cannot write cannot be manipulated into writing. Read-only-by-default is the strongest single control available against the prompt-injection problem described below, and it costs nothing, because the certification landscape has already imposed it on you. Practices that treat the read-only boundary as a limitation to be engineered around usually end up with both a fragile integration and a wider blast radius. Practices that treat it as the default architecture — agent reads, human commits — end up with a system that degrades safely.

    A related caution about the regulatory ground under all of this. ASTP/ONC published a proposed deregulatory rule in the Federal Register on December 29, 2025 that would, among other things, remove the clinical decision support certification criterion and reserve §170.315(a)(9). It remains a proposed rule; comments closed February 27, 2026 and we located no final rule. Do not plan around it. What survives regardless of how that rulemaking resolves is the operational point: an EHR write path is a commercial arrangement with your vendor, not a right you can assume.

    Privacy: What an Agent in This Specialty Must Never Touch

    Every practice type in this cluster handles sensitive data. This one handles data where the existence of the appointment can be the disclosure. Pregnancy, pregnancy loss, fertility treatment, contraception, sexually transmitted infection, sexual assault care and gynecologic oncology all share a property that a scheduling engineer will not think about unprompted: a message read by the wrong person in a shared household, or a portal notification on a shared device, can cause harm without any clinical content leaving the building at all.

    We want to be precise about the legal ground here rather than dramatic, because the distinction matters for how you build. HIPAA has no general provision about the mere fact of association. The one place federal law does work that way is 42 CFR §2.12, the substance-use-disorder confidentiality rule, whose trigger is identification of a patient as having or having had a substance use disorder in records obtained by a federally assisted SUD program — not the clinical content. That distinction is directly relevant to obstetrics, where substance-use screening in pregnancy is routine and where a practice may be receiving records from, or operating, such a program.

    For reproductive-health data more broadly, we could not verify from primary sources within this article's research scope whether any reproductive-health-specific federal privacy provision is currently in force beyond baseline HIPAA. So we are not going to tell you one exists, and we are not going to tell you one does not. What we will tell you is that the association risk is real regardless of how that question resolves, that it is a design decision the practice owns, and that the correct engineering posture is to assume the strictest reading and ask your counsel for the current position before you rely on anything looser.

    SurfaceWhat the agent may handleWhat it must never handleWhy
    Outbound reminders and confirmationsDate, time, location, practice name, human contactVisit type, diagnosis, procedure name, gestational age, cycle references, provider sub-specialty framingA message read by someone other than the patient should disclose nothing about why the appointment exists. This is a design standard we set, not a regulation we can cite.
    Context assembly for a billing or scheduling agentThe specific fields the task needsThe chart45 CFR §164.502(b)(1) requires reasonable efforts to limit PHI to the minimum necessary, and §164.502(b)(2) exempts only treatment disclosures. A billing or scheduling agent gets no exception.
    Agent identity in the EHR and downstream systemsIts own credential, its own scopes, its own log trailA borrowed clinician login or a shared service account45 CFR §164.312(a)(2)(i) makes unique user identification Required, not addressable, and §164.312(a)(1) already frames access rights as attaching to software programs.
    Records release and anything responding to legal processNothing. Route to a named human immediately.Assembling, addressing, transmitting or acknowledging any releaseThis is a legal decision with consequences that no audit log undoes. It stays outside the agent's tool list entirely.
    Substance-use-disorder informationSegregate and exclude from agent context by defaultEmitting anything that identifies the patient as an SUD patient42 CFR §2.12(a)(1) triggers on identification, not on clinical content — a calendar invite or fax cover sheet can be a disclosure. §2.12(a)(2) reaches information whether or not recorded, which includes agent logs and transcripts.
    Perinatal behavioral health, where the practice offers itAdministrative support onlyTherapeutic communication, therapeutic recommendations, or emotion detectionIllinois PA 104-0054 §20(b) prohibits AI from making independent therapeutic decisions, interacting therapeutically, generating treatment plans without licensed review, or detecting emotions. §15 requires written notice and affirmative consent before AI assists with a recorded or transcribed session — terms-of-service acceptance does not count.
    Model and vendor data handlingA BAA covering the service and its subcontractors, with training and secondary use contractually barredAny term permitting the vendor a use the practice could not make itself45 CFR §160.103 makes subcontractors business associates; §164.502(a)(3) limits a BA to uses permitted by its contract and forbids uses that would violate the rule if made by the covered entity.
    Destruction and retentionA destruction path that reaches logs, caches, embeddings and evaluation setsA retention policy that stops at the databaseFor Part 2 records the standard is rendering identifying information non-retrievable, which model-provider log retention and vector stores make genuinely hard. Ask the question before signing, not after.

    Frenchy Digital privacy boundary for OB-GYN agent deployments, 2026. Regulatory citations are to the rules in force as of August 12, 2026.

    Three of those rows deserve expansion because they are where implementations actually go wrong.

    Minimum necessary applies to the context window

    45 CFR §164.502(b)(1) requires a covered entity or business associate to make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose. §164.502(b)(2) carves out disclosures to or requests by a health care provider for treatment. A billing agent, a scheduling agent, a prior-authorization agent and a quality-reporting agent are not making treatment disclosures, and they get no exception.

    "Dump the whole chart into the context window and let the model figure out what is relevant" is the specific engineering practice this rule reaches. It is also, not coincidentally, the practice that maximizes injection surface. Build retrieval that pulls named fields for a named purpose, and make the field list reviewable by someone who is not the engineer who wrote it.

    The agent needs its own identity, not a borrowed login

    45 CFR §164.312(a)(2)(i) makes unique user identification Required, not addressable, and §164.312(a)(1) frames access rights as attaching to persons or software programs — the rule already contemplates software as an access principal. §164.312(b) requires audit controls that record and examine activity in systems containing electronic PHI.

    The failure mode to name is a shared service account that makes an agent's actions indistinguishable from a clinician's in the log. If that is your configuration, then on the day something goes wrong you cannot answer the first question anyone will ask: which of these actions was a person and which was software?

    Records release and legal process stay entirely outside the tool list

    This is the hardest line in the article and the one we hold most rigidly. An agent should not assemble, address, transmit or acknowledge a records release, and it should not touch anything arriving as legal process. Not with human review, not with an approval queue — outside the tool list.

    The reason is that the other boundaries in this article protect against errors that are recoverable. A miscounted visit is corrected. A wrongly held billing line is released. A disclosure is not recoverable, and in this specialty the consequences of a wrong one are not financial. Design so that the capability does not exist rather than so that it is guarded.

    One further note for practices offering perinatal behavioral health, because the strictest statutory language in the country on AI in a clinical conversation sits there. Illinois PA 104-0054 §20(b) prohibits a licensed professional from allowing AI to make independent therapeutic decisions, to directly interact with clients in any form of therapeutic communication, to generate therapeutic recommendations or treatment plans without review and approval by the licensed professional, or to detect emotions or mental states. Its §15 requires that where a session is recorded or transcribed, the patient is informed in writing that AI will be used and of the specific purpose of the tool, and consents — and the statute explicitly excludes acceptance of broad terms of use from what counts as consent. The same act defines a safe zone: administrative support means tasks that do not involve communication, including appointment scheduling and reminders, billing and claims processing, and drafting general logistics communications that contain no therapeutic advice. That is a good description of the boundary this whole article is drawing, written into law by one state.

    The Human-in-the-Loop Boundary Table

    Put this table in the statement of work, not in the appendix. Every disagreement we have seen between a practice and a vendor six months into a deployment traces back to a row in it that was never made explicit at the start.

    Decision or actionWho decidesAuthority or reasoning
    Compute the antepartum visit count and classify each encounter in-package or excludedAgent aloneArithmetic over data the chart holds. Inside 21 U.S.C. §360j(o)(1)(A) by statute.
    Build a recall or outreach list from diagnosis, interval and last-visit dateAgent alonePopulation list building is named in the statutory administrative exclusion.
    Run an eligibility check and surface the resultAgent aloneDetermination of health benefit eligibility is named in §360j(o)(1)(A).
    Draft an outbound reminder with no clinical contentAgent alone, from a fixed templateTemplates are reviewed by a human once; free-text generation to patients is not an unattended capability.
    Draft a prior-authorization packet or an appeal narrativeHuman review before submissionAssembly is administrative; the clinical justification is the practice's assertion to a payer.
    Propose which held lines belong on the delivery claimHuman review, line by lineUHC's timing rule and ACOG's 'no problem developed' rule both require a clinical judgment about why a visit happened.
    Propose a reschedule after a labor-driven clinic cancellationHuman reviewThe agent proposes slots. Which patient can wait a week is a clinical and relational decision.
    Answer a patient's clinical questionHuman review before it sends — and in California, disclosure obligations attach unless a licensed human read it firstHealth & Safety Code §1339.75 requires a GenAI disclaimer and human-contact instructions on communications pertaining to patient clinical information; the exemption applies where a licensed provider read and reviewed the communication.
    Determine medical necessity, or that an extra visit was for a complicationNeverThis is the clinical judgment the whole billing structure rests on.
    Sign, attest, or apply an attestation modifierNeverCMS PIM Ch. 3 §3.3.2.4 requires practitioner concurrence for AI-captured entries and refuses attestations from anyone but the author of the entry.
    Perform work billed 'incident to'Never42 CFR §410.26(a)(1) defines auxiliary personnel as an individual meeting state licensure. Software is not an individual.
    Release records, or act on legal processNeverLegal consequence, irreversible, outside the tool list entirely.
    Analyze an ultrasound image or a continuous physiologic streamNever — this is device territory21 U.S.C. §360j(o)(1)(E) excludes from the non-device pathway any function intended to acquire, process or analyze a medical image or a pattern from a signal acquisition system. No discretion applies.
    Hold itself out with a clinical title or personaNeverCalifornia B&P §4999.9 makes each use of terms implying a health care license a separate violation, with board jurisdiction and injunctive relief available.

    Frenchy Digital human-in-the-loop boundary for OB-GYN agent deployments, 2026.

    The attestation row is the one that ends every argument, so it is worth quoting the source. The Medicare Program Integrity Manual, Chapter 3 §3.3.2.4, effective January 17, 2025, addresses AI by name:

    The treating physician/non-physician practitioner's (NPP's) signature on a note indicates that the physician/NPP affirms the note adequately documents the care provided. We note this type of practitioner concurrence is also required when using Artificial Intelligence (AI) technology to capture the transcription of medical record entries.

    CMS Medicare Program Integrity Manual, Ch. 3 §3.3.2.4 (Rev. 13008, effective 01-17-25)

    The same section closes the obvious workarounds. Reviewers shall not consider attestation statements from someone other than the author of the record entry in question — explicitly including the case where two individuals are in the same group. Contractors shall not consider attestation statements where there is no associated medical record entry. And an attestation cannot be used to backdate a plan of care. The model attestation CMS publishes is first-person, credentialed, and states that the signer understands falsification, omission or concealment may subject them to administrative, civil or criminal liability. There is no configuration in which software makes that statement.

    The "never" rows are not risk aversion. They are the places where the consequence of being wrong is not a rework queue. Everything above them is where the value is, and there is a great deal of value above them.

    The Sequenced Implementation Path

    This is the part of the article that matters most, and it is deliberately not a list of benefits. Each phase below has an owner, an entry criterion, an exit criterion and an instruction for what to do when the phase fails. A phase that has not met its exit criterion does not hand off to the next one, and nothing after Phase 0 starts until the write-path question has an answer in writing.

    PhaseOwnerEntry criterionExit criterionIf the phase fails
    Phase 0 — Baseline and inventory (weeks 0–2)Practice administrator, with the billing managerAn executive sponsor is named and both major payers' obstetric reimbursement policies are in handA measured before-state exists for three candidate workflows, and the EHR vendor has answered the write-path question in writingIf the vendor will not answer in writing, do not proceed to any write-dependent phase. Re-scope to read-only deliverables.
    Phase 1 — Antepartum ledger, read-only (weeks 2–5)Billing manager owns the output; integration engineer owns the pipePhase 0 exit met; a test population of delivered charts is agreedThe ledger reproduces the biller's own visit count on 30 consecutive delivered charts, and every disagreement has a written explanationIf disagreements cluster on transferred-in patients, stop and model the 59425/59426 antepartum-only cases before continuing.
    Phase 2 — Deferred-billable capture (weeks 5–9)Billing manager, with a named physician reviewerPhase 1 exit met; the in-package/excluded classification is signed off by the physician reviewerEvery held line traces to a source encounter with a date and a proposed modifier, and the physician reviewer confirms or rejects each one in under a defined review windowIf the reviewer rejects a large share of held lines, the classifier is over-capturing. Demote to detection-only and re-tune before it reaches a claim.
    Phase 3 — Series adherence and outreach (weeks 9–13)Front-office lead owns messaging; compliance owns the template reviewPhase 2 exit met; every outbound template has passed a content review that rejects any clinical tokenOutreach fires on the correct cohort, contains no visit type or diagnosis, and every message is logged with the agent's own identityA single template containing clinical content is a stop-the-line event. Kill switch to date/time/location-only, then re-review every template.
    Phase 4 — Gynecologic surgery pre-op and authorization packets (weeks 13–18)Surgical coordinator, with the surgeon as reviewerPhase 3 exit met; the payer's documentation requirements for the top three procedures are encodedPackets reach the coordinator complete, the -57/-25 and global-period checks run before submission, and the clearance chase list is trusted enough to replace the spreadsheetIf facility block coordination produces proposals the surgeon overrides more often than not, revert to a chase list and drop the proposal feature.
    Phase 5 — Write paths, only if the vendor grants them (weeks 18–24)Integration engineer, with the practice administrator as approverA written, contracted write path exists and a staged rollback plan is approvedWrites are limited to a named allowlist, every write is human-approved, and a reversal procedure has been tested in production on low-risk recordsIf any write cannot be reversed by a documented procedure, it does not ship. Keep the human commit queue instead — it is slower and it is safe.

    Frenchy Digital sequenced implementation path for OB-GYN administrative agents, 2026. Week ranges assume a single-site practice with one EHR and two dominant payers.

    Some notes on why the sequence is ordered this way, because the ordering carries most of the value.

    • Phase 0 exists to kill bad projects cheaply: Two to four weeks and a discovery fee is the correct price for discovering that your EHR vendor will not grant a write path, or that your Medicaid book unbundles prenatal care so completely that the global-package logic covers a minority of your volume. Both of those are common. Both are catastrophic to find in week fourteen.
    • Phase 1 produces a number you generated, not a number a vendor gave you: Reproducing the biller's own visit count on thirty consecutive delivered charts is a real acceptance test with a real ground truth. It also gives you an honest estimate of how much of your panel is shared care, which determines how much of the rest of the programme is worth building.
    • Phase 2 is where the money is, and it needs a named physician reviewer from day one: Deferred-billable capture touches the claim. If a physician reviewer is not named, funded and scheduled before the phase begins, the held lines pile up unreviewed and the phase quietly converts into an unbilled backlog, which is worse than not having built it.
    • Phase 3 is deliberately after the billing work, not before it: Patient-facing messaging is the phase most likely to be pitched first because it demos well. It is also the phase with the highest privacy consequence and the least reversible failure mode. Put the compliance review of every template on the critical path, and treat a clinical token in a template as a stop-the-line event.
    • Phase 4 reconciles the two calendars: Surgical coordination only works once the obstetric side is instrumented, because the constraint on the surgical calendar is the surgeon's obstetric call exposure. Building it first produces a scheduler that is confidently wrong about availability.
    • Phase 5 is optional and most practices should skip it: If your EHR vendor grants a contracted write path and you can demonstrate a tested reversal procedure, automated writes remove real clicks. If either condition is missing, the human commit queue is not a consolation prize — it is the design that degrades safely, and it is what we recommend by default.
    The measurement discipline that makes any of this defensible. Before each phase starts, write down the before-state in numbers your practice already has: minutes per delivery claim assembly, rework rate on obstetric claims, days from delivery to claim submission, share of ultrasound studies performed on a lapsed authorization, staff hours on clearance chasing. After each phase, take the same measurements. A practice that instruments the before-state can tell whether the programme worked. A practice that does not will be arguing about vendor claims a year from now, and the vendor claims will be the only numbers in the room.

    What Breaks First — With the Detection Signal and the Rollback

    Every deployment breaks. The difference between a recoverable programme and an abandoned one is whether the failure was anticipated, instrumented and reversible. These are the specific failure modes for this specialty, in rough order of likelihood, each with the signal that tells you it is happening and the rollback that stops the bleeding.

    Failure modeHow it actually happensDetection signalRollback
    The visit ledger drifts on shared careA patient transfers in mid-pregnancy, changes insurer, or delivers with a partner practice, and the ledger keeps counting as though this practice provided the full courseReconciliation report: agent count versus biller count on every delivered chart, with variance by transfer-in statusDemote the ledger to advisory-only, model the 59425 (4–6 visits) and 59426 (7 or more) antepartum-only cases explicitly, then re-enable
    The deferred-billable queue becomes a bill-everything machineThe classifier holds every extra visit as a high-risk candidate, and the delivery claim goes out heavier than the record supportsModifier-25 lines per delivery trending upward; the ratio of held high-risk visits to charts carrying an actual complication diagnosisRequire physician confirmation on every held line, and re-tune. ACOG's rule — monitored a potential problem, no problem developed, do not report — is the acceptance test.
    An outbound message discloses the visit typeA template, a merge field or a free-text generation path leaks a diagnosis, a procedure name or a gestational reference into a message someone else may readAutomated template scan rejecting clinical tokens in CI; patient complaint log; a sample audit of sent messages every week for the first quarterImmediate kill switch to date/time/location-only messages. Re-review every template before re-enabling. This is a stop-the-line failure, not a backlog item.
    Labor pulls the physician out and the rebooking cascade goes wrongThe agent rebooks into slots that are not really available, or moves patients whose cadence cannot absorb a delayRate of agent-proposed rebookings later cancelled or moved again by staff; same-day cancellation-to-rebook mismatchPropose-only mode: the agent generates a ranked reschedule list and a human commits it. Most practices should stay here permanently.
    A portal-message agent is asked a clinical questionPatients do not respect the administrative boundary. A scheduling agent gets asked about bleeding, medication safety or symptoms.Intent-classifier fallout rate; any outbound draft flagged as containing clinical content; explicit escalation counts per weekRoute all portal messages to a human queue. In California, the AB 3030 disclaimer and human-contact obligations attach the moment the content pertains to patient clinical information.
    Payer policy driftThe rules are encoded from one payer's policy. Medicaid programs frequently unbundle prenatal care entirely, and other commercial payers vary.Denial-code clustering by payer on the global codes; a rising share of claims requiring manual rework by payerScope the agent to the payers whose policies are actually encoded, and treat every additional payer as a change request with its own acceptance test
    Prompt injection through an untrusted channelA portal message, a referral PDF, a lab fax or a payer portal page contains text that the agent treats as instructionTool-call logs showing arguments no human supplied; any lookup outside the patient context already in scope; anomalous tool sequencesRevoke the tool, not the agent. Narrow the allowlist, reject unsupplied arguments, and keep the human approval step on every consequential action. Assume detection will fail.
    An EHR upgrade breaks the integrationA vendor release changes a field, a scope or an app-review requirement, and the pipeline silently degradesFreshness monitoring on every feed, with an alert when a source has not updated within its expected windowFail closed to the manual worklist. A stale ledger presented as current is worse than no ledger.

    Frenchy Digital failure-mode register for OB-GYN agent deployments, 2026.

    Two of those rows are worth more than the others, and they are the two that are least like ordinary software failure.

    The first is the message that discloses the visit type. It will not present as an incident report. It will present as one patient, once, telling the front desk something quiet. By then the template has been sending for weeks. That is why the control has to be preventive — an automated scan that fails any template containing a clinical token, run in continuous integration, plus a weekly sample audit of actually-sent messages for the first quarter — rather than detective. And it is why the rollback has to be a switch someone can flip in minutes without an engineer.

    The second is prompt injection, which deserves its own treatment because the published evidence lands directly on this specialty. Lee and colleagues, in JAMA Network Open in December 2025, ran a controlled simulation across 12 clinical scenarios including pregnancy contraindications. Across 216 evaluations, attacks achieved 94.4% success at turn 4 and persisted in 69.4% of follow-ups, and extremely high-harm scenarios including FDA Category X pregnancy drugs succeeded in 91.7% of dialogues. The authors' conclusion was that commercial LLMs demonstrated substantial vulnerability to prompt-injection attacks that could generate clinically dangerous recommendations, and that even flagship models with advanced safety mechanisms showed high susceptibility.

    State the caveats every time you cite that study, as we do. It is a controlled simulation, not field data. The main experiment used lightweight models, with a five-dialogue proof-of-concept on flagship models. Three co-authors disclose company roles. It is still the best-sourced number available on this question and it is not a vendor claim — which is precisely why it is in this article and why vendor accuracy figures are not.

    And the finding that breaks the standard mitigation story: Clusmann and colleagues, in Nature Communications in February 2025, ran 594 attacks against four vision-language models and found all of them susceptible, including to sub-visual prompts embedded in medical imaging data that are, in their words, non-obvious to human observers. A human-in-the-loop who cannot see the injection cannot review it away. FDA's own 2026 material makes a compatible point from a different direction, describing automation bias as the propensity of humans to over-rely on a suggestion from an automated system, producing errors of commission and omission, and increasing where there is not sufficient time to consider other information.

    We should also be honest about what has not been studied. We found no published study of prompt injection via patient portal messages, referral faxes or payer portals in a live practice. The published work covers patient dialogue and imaging. Extending it to a fax-to-OCR-to-agent pipeline is reasoning, not evidence — though the reasoning is not weak: an inbound fax is untrusted text entering an instruction path with no sender authentication at all.

    The mitigations that are real are architectural, because they do not depend on detecting the attack. Least privilege at the API boundary. Read-only by default, which the certification landscape has already given you for free. A human signature as the only path from draft to record. Unique agent identity plus audit controls so a successful injection is reconstructable afterward. Out-of-band confirmation for anything irreversible — money moved, orders placed, messages sent to patients, records released. What is marketing, and should be named as such, is any vendor claim of an injection detection or guardrail accuracy rate: there is no independent benchmark for clinical prompt-injection defense that we could locate, and every figure in circulation is vendor-published.

    The Rules That Actually Bind an OB-GYN Practice

    Most regulatory writing in this market is either alarmist or promotional. The actual position, as of August 12, 2026, is narrower and more usable than either: administrative automation sits on statutory safe ground, clinical recommendation sits inside a four-criterion test with a revocable enforcement posture layered on top, and a handful of state statutes impose disclosure duties that vary by state and by whether the content is clinical or administrative.

    Agent actionGoverning authorityPosition as of August 12, 2026
    Schedule, remind, check eligibility, move claims and billing data, build population lists21 U.S.C. §360j(o)(1)(A)Outside the device definition by statute. The exclusion names appointment schedules, claims or billing information, practice management, business analytics and benefit-eligibility determination explicitly.
    Present a list of options to a clinician21 U.S.C. §360j(o)(1)(E) + FDA CDS guidance (Jan 29, 2026)Non-device if all four criteria are met. Outputs FDA describes as satisfying Criterion 3 include a list of options, a prioritized list, or a list of follow-up or next-step options for the clinician to consider.
    Present a single directive clinical outputFDA CDS guidance (Jan 29, 2026)Still fails Criterion 3. FDA announced enforcement discretion where only one option is clinically appropriate and the function otherwise meets §520(o)(1)(E). Discretion is revocable without notice-and-comment; it is not clearance.
    Generate a clinical recommendation from the model's own parametric memoryFDA CDS guidance (Jan 29, 2026), Criterion 2FDA's own worked example: a function using information that cannot be verified to come from well-understood and accepted sources fails Criterion 2 and is a device. Retrieval from cited guidelines is not a nicety here.
    Touch an ultrasound image or a continuous physiologic stream21 U.S.C. §360j(o)(1)(E)Device. No discretion. FDA also clarified that discrete point-in-time measurements such as routine vitals at clinical encounters generally do not by themselves constitute a pattern; continuous measurement does.
    Communicate with a patient about clinical information (California)Health & Safety Code §1339.75 (AB 3030)GenAI disclaimer plus human-contact instructions, placed per the statute's channel rules — unless a licensed human read and reviewed it first. Administrative matters including scheduling and billing are excluded from the definition.
    Use an AI system in relation to health care service or treatment (Texas)Tex. Bus. & Com. Code §552.051(f)Disclose to the recipient no later than the date the service is first provided; in an emergency, as soon as reasonably possible. Broader trigger than California's and no human-review exemption on its face.
    Use AI for diagnostic purposes (Texas)Tex. Health & Safety Code §183.005Permitted, with conditions: the practitioner acts within scope regardless of the use of AI, the use is not otherwise restricted, the practitioner reviews all records created with AI, and the use is disclosed to patients.
    Give an agent a clinical persona or title (California)Cal. B&P §§4999.8–4999.9 (AB 489)Each use is a separate violation, enforceable by the relevant licensing board with injunctive relief. Name the agent after the practice, not after a clinician.
    Deploy any patient care decision support tool45 CFR §92.210Ongoing duty to make reasonable efforts to identify tools using input variables measuring race, color, national origin, sex, age or disability, and to mitigate the resulting discrimination risk. Applies whether or not the tool is AI and whether or not FDA calls it a device.
    Sign or attest to a record entryCMS PIM Ch. 3 §3.3.2.4 (effective Jan 17, 2025)Practitioner concurrence is explicitly required when AI captures the transcription of medical record entries. Attestations from non-authors are refused, as are attestations with no associated entry.
    Perform work billed incident to a physician's service42 CFR §410.26(a)(1)No pathway. Auxiliary personnel must be an individual who meets state licensure requirements and can be OIG-excluded. Software is neither.
    Process PHI through a third-party model API45 CFR §160.103, §164.502(a)(3), §164.502(b), §164.312Permitted under a BAA that reaches subcontractors, with minimum necessary applied, unique agent identity, and audit controls. Encryption at rest remains addressable rather than required under the Security Rule in force today.

    Regulatory boundary summary for medical-practice AI agents, verified against primary sources on August 12, 2026. Not legal advice — verify against counsel and re-check dated items.

    Four clarifications that practices consistently get wrong, and that vendors consistently exploit.

    • The administrative exclusion is statutory, not a favor: 21 U.S.C. §360j(o)(1)(A) excludes from the device definition software intended for administrative support of a health care facility, and names the processing and maintenance of financial records, claims or billing information, appointment schedules, business analytics, information about patient populations, admissions, practice and inventory management, determination of health benefit eligibility and population health management. Every workflow in this article's shortlist sits inside that sentence. You are not relying on FDA's forbearance for any of it.
    • Enforcement discretion is not approval: FDA's Clinical Decision Support Software guidance issued January 29, 2026 supersedes the January 6, 2026 version, which itself replaced the September 2022 guidance. It did not reclassify single-output software as non-device. Software providing a specific preventive, diagnostic or treatment output or directive still fails Criterion 3; FDA announced that it intends to exercise enforcement discretion where only one option is clinically appropriate and the function otherwise meets §520(o)(1)(E). Discretion can be withdrawn without notice-and-comment. Any vendor saying FDA approved, cleared or blessed their CDS is wrong.
    • The HIPAA rules you are held to today are the existing ones: The HIPAA Security Rule NPRM published January 6, 2025 is still only proposed — the Unified Agenda entry for RIN 0945-AA22 places it in long-term actions with final action projected July 2027. So mandatory multi-factor authentication, asset inventory and encryption at rest are not obligations today. The technical safeguards you are actually bound by are 45 CFR §164.312, under which encryption remains addressable rather than required. Build to the stricter standard by choice; do not let a vendor tell you the law already requires it.
    • The nondiscrimination duty is live and it is an inventory task: 45 CFR §92.210 imposes a general prohibition, an ongoing duty to make reasonable efforts to identify patient care decision support tools using input variables measuring race, color, national origin, sex, age or disability, and a duty to make reasonable efforts to mitigate the resulting risk. It applies whether or not the tool is AI. The compliance date is reported as May 1, 2025, though we note that as secondary. In an obstetric practice, sex is an input to essentially every risk instrument in use, which makes the identification duty concrete rather than theoretical. Whether §92.210 is subject to any injunction or pending rescission, we could not verify — we can only report that it appears in the current CFR.

    On state AI law, the practical rule is that the trigger differs by state and the content type matters. California's AB 3030 turns on whether the communication pertains to patient clinical information — and the statute expressly says that term does not include administrative matters including appointment scheduling, billing, or other clerical or business matters. So an appointment confirmation needs no disclaimer; a message answering a clinical question does, unless a licensed human read and reviewed it first. Texas HB 149 §552.051(f) is broader on its face, reaching any AI system used in relation to health care service or treatment, with disclosure required no later than the date service is first provided and no human-review exemption written into that subsection. Texas SB 1188 is the most instructive statute in the country here because it grants permission and attaches conditions in the same breath: a practitioner may use AI for diagnostic purposes if acting within scope regardless of the use of artificial intelligence, if the use is not otherwise restricted, and if the practitioner reviews all records created with AI — plus disclosure to patients. Five words carry the entire doctrine: the license, and therefore the liability, does not move.

    On Colorado, we have to flag a genuine inconsistency in our own sources rather than paper over it. SB 26-189 was signed May 14, 2026 and repeals and reenacts Colorado's AI statute. Our regulatory research places the substantive deployer and developer duties, and the applicability to consequential decisions, at January 1, 2027, with only narrow rulemaking-authority subsections effective on passage. Another source in our own research set argued for an earlier effective date. We are reporting the January 1, 2027 position because it is the one supported by the enrolled bill text our researchers parsed, and we are telling you the disagreement exists so you check it rather than trusting either of us. What is stable and matters more for a practice: the reenacted statute carries a carve-out for HIPAA covered entities and their business associates — but only to the extent the covered entity is doing business in Colorado, and for a health-care provider only where it operates from a location within Colorado, and never for a consequential decision related to employment or an employment opportunity. A covered entity must still provide patients a general notice of the use of advanced technologies; and a richer disclosure attaches where automated decision-making touches financial-assistance or discounted-care eligibility. Colorado's Department of Law filed proposed draft rules on August 11, 2026 with a comment period running into October — so this is moving, and a statement made today has a short shelf life.

    Finally, the federal wildcard, hedged deliberately: federal preemption of state AI law is being actively pursued, and nothing has displaced the state statutes above. We are not going to cite an executive order number, a bill number or any provision, because we could not fetch the primary documents. If a vendor tells you state AI rules are about to be preempted and therefore you need not plan for them, ask them for the citation.

    Red Flags in an OB-GYN AI Pitch

    Each row corresponds to a specific documented constraint from earlier in this article. None of them are hypothetical, and each is answerable in a first meeting.

    Red flagWhy it matters
    Any accuracy percentage presented as neutralThere is no independent benchmark for AI accuracy in medical scheduling, coding, scribing or voice agents. Every figure in this market is vendor-published. A vendor quoting one without naming its own methodology is quoting itself.
    A no-show cost or phone-abandonment statisticThe circulating no-show economics and phone-abandonment benchmarks in this market trace to unsourced vendor content rather than to published research. We refuse to print them, and a deck built on them has no floor.
    "Closed-loop" scheduling with no mention of the write pathCertified API access under §170.315(g)(10) is read-only. Anyone promising the agent will book, reschedule and post charges without naming a vendor-granted write API, UI automation or a human is describing something they have not scoped.
    "HIPAA-compliant AI" as a product propertyHIPAA attaches duties to covered entities and business associates, not to software. The correct formulation is used under a BAA with these specific controls. A vendor that cannot restate it that way has not read the rule.
    A BAA that does not reach subcontractors45 CFR §160.103 makes a subcontractor handling PHI on a business associate's behalf a business associate in its own right. One BAA with the application vendor does not close the chain to the model provider or its cloud host.
    Training or secondary use hidden in the terms45 CFR §164.502(a)(3) limits a business associate to uses permitted by its contract and forbids uses that would violate the rule if the covered entity made them. A we-may-use-your-data-to-improve-our-models clause collides with it directly.
    A shared service account instead of an agent identity45 CFR §164.312(a)(2)(i) makes unique user identification Required. If agent actions are indistinguishable from a clinician's in the log, your incident response has no starting point.
    A named clinical personaIn California, AB 489 makes each use of a term implying a health care license a separate violation. A vendor shipping Nurse-anything as a default persona is shipping you an enforcement exposure.
    "FDA approved" or "FDA cleared" applied to clinical decision supportFDA's 2026 guidance grants enforcement discretion over a criterion failure. That is not approval, not clearance, and it is revocable. A vendor using those words is either careless or hoping you are.
    No answer on prompt injection beyond "we tuned the prompt"Injection is unsolved, obstetric scenarios sit inside the highest-harm category the published literature tested, and one of the two strongest studies found injections that are non-obvious to human reviewers. The acceptable answer is architectural: narrow tools, no unsupplied arguments, human approval on consequential actions, complete tool-call logging.
    One payer's rules presented as the rulesThe obstetric package described in this article is UnitedHealthcare's 2026 policy, which follows CPT and ACOG. Medicaid programs frequently unbundle prenatal care entirely. A product that encodes one policy and calls it obstetric billing will fail on your Medicaid book.
    No refusal anywhere in the pitchA vendor who will not tell you what their system must never do has not thought about the boundary. Ask what it refuses to touch. If the answer is nothing, that is the answer.

    Frenchy Digital red-flag list for OB-GYN practice AI buyers, 2026.

    On the accuracy row, we want to be explicit about the house position, because it is the thing that most distinguishes how we evaluate this market. We do not score vendors on accuracy. There is no independent benchmark for AI accuracy in medical scheduling, coding, ambient documentation, or voice agents — every figure circulating in this market was published by a company selling into it. Excluding accuracy from evaluation is not a limitation of our method. It is the method. What can be verified is documented EHR integration, whether a BAA is publicly offered, SOC 2 or HITRUST status, pricing transparency, whether a product is EHR-locked or standalone, and corporate stability from public record. Score those. Ask for accuracy methodology, and treat a headline number offered without one as a statement about the vendor rather than about the product.

    Ask the vendor what their system must never do. A vendor with a real answer has thought about the boundary, has probably lost an argument with a compliance officer, and has shipped into a practice that survived it. A vendor who says the system can do anything you configure it to do has told you they will hand you the boundary problem at go-live.

    Frenchy Digital buyer's principle

    What It Costs to Build This Properly

    These are the bands Frenchy Digital uses to scope medical-practice agent work in 2026. They assume the integration assessment — including the EHR write-path question — and a measured before-state are in scope from day one, because those are what make the result defensible afterward.

    EngagementRangeTimelineTypical scope
    Discovery + workflow audit$9k–$22k2–4 weeksWorkflow inventory, EHR and practice-management integration assessment including the write-path question, payer policy encoding review, measured before-state for the top three candidate workflows
    Single-workflow agent (antepartum ledger, surgical pre-op packet, recall series)$28k–$70k4–9 weeksOne workflow end to end, human approval queue, unique agent identity, audit logging, exception path, evaluation set built from your own historical charts
    Multi-workflow platform with EHR/PM integration$70k–$180k9–16 weeksSeveral workflows, integration with the EHR and practice-management system, document ingestion, role-based approvals, payer-specific rule sets, evaluations in CI
    Enterprise / multi-site / regulated build$180k–$420k+14–24 weeksMulti-site tenancy, full audit pipeline, human-in-the-loop controls throughout, SOC 2 posture, disaster recovery testing, documentation package

    Frenchy Digital cost bands for medical-practice AI agent engagements, 2026.

    Senior-led delivery runs $150 to $225 per hour, and ongoing retainers run $2,500 to $9,500 per month covering model and dependency upgrades, evaluation-set expansion, payer-rule maintenance, incident response and a quarterly technical review. Every engagement carries a 30-day post-launch warranty, and you receive a written scope with a fixed-price phased proposal within 5 business days of the discovery call.

    Included at every tier: the EHR and practice-management integration assessment covering the write path, a measured before-state for the target workflow, unique agent identity with audit logging that captures tool calls and arguments, human approval on every consequential action, an evaluation set built from your own historical charts, the human-in-the-loop boundary written into the statement of work, and full source-code and IP ownership transferred to you at delivery. Frenchy Digital is a senior-led Black-owned Los Angeles agency, and we do not build lock-in.

    A budgeting note specific to this specialty. The payback argument here is unusually easy to state and unusually easy to measure, because the deliverable is a claim that goes out complete and on time. Measure days from delivery to claim submission, rework rate on obstetric claims, and the number of separately billable services performed and never billed, before and after. If those three do not move, the programme did not work, and you should be able to say so within a quarter. We would rather build something you can turn off than something you cannot evaluate.

    The retainer line is not a maintenance formality either. Payer policies change, an EHR release moves a field, a state adds a disclosure duty, and a rule set that was correct in January is quietly wrong by October. A practice running an unmaintained billing agent is running an unmonitored one, and the failure mode is silent — the claims still go out.

    Limitations: What We Could Not Verify

    This article has spent several sections holding vendors to an evidence standard. It would be indefensible not to apply the same standard to itself. Here is what we could not establish, stated plainly.

    • Reproductive-health-specific federal privacy provisions: We could not verify from primary sources, within this article's research scope, whether any reproductive-health-specific federal privacy provision is currently in force beyond baseline HIPAA, or what its litigation status is. We have therefore made no claim in either direction and have built the privacy section on the rules we could verify — §164.502, §164.312, §160.103 and 42 CFR Part 2 — plus a design posture that assumes the strictest reading. Ask your counsel for the current position before relying on anything looser.
    • Minor-consent and adolescent-confidentiality law: Gynecologic care for adolescents raises real questions about which contact record receives a message and which portal account can see what. State minor-consent law varies and we did not verify it for any state. Resolve your portal and contact-record configuration with counsel before enabling any outbound messaging on a mixed-age panel.
    • The global-package rules here are one payer's: The composition of the obstetric package in this article is UnitedHealthcare's 2026 policy 2026R0064A, which follows CPT and ACOG, corroborated where possible against the CMS NCCI Policy Manual 2026. Medicaid programs frequently unbundle prenatal care entirely, and other commercial payers vary. Encode your own payers' policies; do not encode ours.
    • No independent accuracy benchmark exists for any of these product categories: Not for scheduling, not for coding, not for ambient documentation, not for voice agents. Every accuracy figure in this market is vendor-published. We excluded accuracy from evaluation by design and we are telling you that rather than substituting a number of our own.
    • The standard operational statistics in this market do not survive tracing: The widely quoted per-no-show cost figure and the annual national cost of missed appointments both trace to a single 2017 byline by a scheduling vendor's chief medical officer with no methodology. The phone-abandonment benchmarks used to sell voice agents have no traceable origin. The frequently cited claim-rework figures could not be chased to a published methodology. We do not print them, and a business case built on them has no floor.
    • No OB-GYN-specific administrative time-motion study: The Sinsky 2016 study everyone cites covered family medicine, internal medicine, cardiology and orthopedics — not obstetrics and gynecology. We could not locate an equivalent for this specialty. If you need a burden baseline, measure your own practice; it takes two weeks and it is yours.
    • Colorado's effective date is disputed within our own research: One line of our research places SB 26-189's substantive duties at January 1, 2027 based on the enrolled bill's own effective-date section; another argued for an earlier date. We report the January 1, 2027 position and flag the disagreement rather than presenting a clean answer we do not have. Colorado rulemaking is live as of August 11, 2026, so re-check before relying on any statement here.
    • The read-only certification position rests on the Certification Companion Guide: We quote the ONC/ASTP Certification Companion Guide for §170.315(g)(10), updated 05-15-2026, rather than the regulation text itself, which we did not parse directly. The operational conclusion — that EHR write access is vendor-discretionary — is unaffected either way, because it follows from what vendors actually offer commercially.
    • Prompt injection in practice channels is unstudied: The published evidence covers patient dialogue and medical imaging. We found no study of injection via patient portal messages, referral faxes or payer portals in a live practice. Our treatment of those channels is reasoning from the imaging and dialogue findings, and we have labelled it as such throughout.
    • Ordinary software failure still applies: Document extraction degrades on poor scans and unfamiliar layouts. Classifiers drift as payer templates change. Integrations break on EHR upgrades. None of these are exotic AI failures, all of them need an owner and a monitoring budget, and that is what the retainer exists for.

    None of this argues against building. It argues for building in the order above, instrumenting the before-state, and being straight with your own partners about which numbers in the business case were measured in your practice and which were borrowed from somewhere else.

    The boundary holds regardless of any of it. Everything described here is an administrative and documentation system operating under human review. No agent in this article makes a clinical determination, signs or attests to a record, decides medical necessity, releases information, or acts on legal process. A human commits every consequential action, and the audit log proves which human it was.

    Where This Leaves a Practice Administrator

    The honest summary of this specialty is that the highest-value automation available to you is also the least glamorous thing in the vendor market. Nobody demos a visit counter. Nobody builds a keynote around a held-line queue that gets reviewed at delivery. But a practice that counts its antepartum visits correctly, captures the separately billable deviations contemporaneously, and submits a complete claim within days of delivery has fixed the thing that actually costs it money — and it has done so without touching a clinical decision, a signature, or a disclosure.

    Start with Phase 0. Get the write-path answer in writing. Reproduce your biller's visit count on thirty charts. If those three things go well, the rest of the sequence is ordinary software delivery with an unusually careful boundary. If they do not, you have spent two to four weeks learning something true about your own operation, which is a better outcome than most AI programmes in this market achieve in a year.

    Planning an AI Build for Your OB-GYN Practice?

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. You leave with an EHR write-path assessment, a measured before-state for one workflow, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Planning an AI Build for Your OB-GYN Practice?

    Book a free 60-minute discovery call. You leave with an EHR write-path assessment, a measured before-state for one workflow, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1UnitedHealthcare Commercial & Individual Exchange Reimbursement Policy 2026R0064A — Obstetrical Policy (PDF)
    2. 2CMS — National Correct Coding Initiative Policy Manual for Medicare Services, 2026 revision (PDF)
    3. 3ONC/ASTP — Certification Companion Guide, § 170.315(g)(10) Standardized API for Patient and Population Services
    4. 4CMS — Medicare Claims Processing Manual, Chapter 12 (global surgical package, modifiers -54/-55/-57) (PDF)
    5. 5CMS — Medicare Program Integrity Manual, Chapter 3 §3.3.2.4 Signature Requirements (PDF)
    6. 6FDA — Clinical Decision Support Software, guidance issued January 29, 2026 (PDF)
    7. 7FDA — Clinical Decision Support Software guidance landing page (docket FDA-2017-D-6569)
    8. 8FDA — Clinical Decision Support Software town hall transcript, March 11, 2026 (PDF)
    9. 921 U.S.C. §360j — device definition and the administrative-support exclusion
    10. 1045 CFR §164.312 — HIPAA Security Rule technical safeguards
    11. 1145 CFR §160.103 — definitions, including business associate and subcontractor
    12. 1245 CFR §92.210 — nondiscrimination in the use of patient care decision support tools
    13. 1342 CFR §410.26 — services incident to a physician's service (auxiliary personnel)
    14. 1442 CFR §424.36 — beneficiary signature requirements on a claim
    15. 1542 CFR §422.122 — Medicare Advantage prior authorization: denial reasons, API, public metrics
    16. 1642 CFR §2.12 — applicability of the substance use disorder confidentiality regulations
    17. 17California AB 3030 (2024) — generative AI in patient communications, Health & Safety Code §1339.75
    18. 18California AB 489 (2025) — health advice from artificial intelligence, B&P Code §§4999.8–4999.9
    19. 19Texas HB 149 (TRAIGA) — enrolled text, §552.051(f) health care disclosure
    20. 20Texas SB 1188 — enrolled text, Health & Safety Code §183.005 AI in the electronic health record
    21. 21Colorado SB 26-189 — bill page (signed May 14, 2026)
    22. 22Colorado Attorney General — artificial intelligence rulemaking and resources
    23. 23Lee RW et al. — Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice, JAMA Netw Open 2025 (PMID 41632124)
    24. 24Clusmann J et al. — Prompt injection attacks on vision language models in oncology, Nat Commun 2025 (PMID 39890777)
    25. 25Sinsky C et al. — Allocation of Physician Time in Ambulatory Practice, Ann Intern Med 2016 (PMID 27595430)
    26. 26HHS/OCR — HIPAA Security Rule NPRM, RIN 0945-AA22, Unified Agenda entry (final action projected July 2027)
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital, a senior-led Black-owned Los Angeles agency building AI agents and software for healthcare, professional services and enterprise operations.