Why Pediatrics Breaks Automation Built for Adult Primary Care
Almost every patient-communication product sold into medical practices was designed around a single assumption: the person in the chart is the person you talk to. That assumption is false in pediatrics on every single record. The patient is a minor. The communication endpoint is a parent or guardian — frequently two of them, with different phone numbers, different custody arrangements and sometimes different insurance. Every message, reminder, consent and balance in the system is addressed to somebody who is not the person in the chart, and the moment the patient reaches adolescence a privacy dimension appears on top of that.
This is not a nuance you patch later. It is the data model. A vendor demo that shows a voice agent confirming an appointment with "the patient" is showing you an adult primary-care product with a pediatric logo on the slide. The question to ask in the first demo is not how accurate the agent is — nobody can answer that honestly, as we show below — but rather: which record does the agent dial, who decided that, and what happens when there are two guardians and a court order.
The scheduling pattern compounds it. A pediatric calendar runs two interleaved streams: a densely templated well-visit calendar booked months ahead off the periodicity schedule, and same-day sick capacity that must be held open and that collapses in respiratory season. Sibling visits stack into one family appointment. School-year surges load forms and sports physicals into a few weeks. An agent optimising for slot fill without understanding held capacity will happily book well visits into the same-day holds in October and leave you with no sick capacity in December.
This article is operational. It assumes you have already decided that some automation is worthwhile and now need to know the order of operations, who owns each step, what the entry and exit criteria are, what breaks first, and how to roll back. The companion pillar, The Zero-Click Clinic, defines the term we use throughout: a practice where the default administrative path completes without a human click, and humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal or safety decision. It is not an unstaffed practice and should never be sold as one.
The Parent Is the Counterparty: Consent, Identity and Message Design
Three things change when the counterparty is a guardian rather than the patient: who may consent, how you verify identity on an inbound call, and what an outbound message is allowed to contain.
1. Consent is held by someone who is not in the chart
Consent to treatment, consent to be called or texted under the TCPA, consent to recording, and consent to AI involvement in a communication are four different consents held by the guardian, and they are not interchangeable. A practice that captured a phone number on a registration form in 2019 does not thereby hold prior express consent for an AI-voice recall campaign in 2026. Build a consent register keyed to the guardian record, not the patient record, with the date, the channel, the scope and the capture artefact stored — because when a plaintiff's firm asks, a screenshot of a checkbox that no longer exists is not evidence.
2. Identity verification on inbound calls has no clean answer
Adult practices verify with date of birth and a name. In pediatrics the caller is not the patient, so the agent is verifying a relationship, not an identity — and relationships are exactly what practice management systems record badly. Our recommended design: the agent verifies the patient (name plus date of birth), then verifies the caller against a named guardian list on the record, and if the caller is not on that list it does not disclose anything and transfers to a human. It does not attempt to add a guardian. It does not accept "I'm her dad" as an authorisation event.
3. Outbound content must be age-banded
Automated messages to guardians of adolescents should carry no clinical content, no visit reason and no result detail — time and place only — with anything else routed to a human who knows the state's minor-consent rules. Where substance use disorder care is involved, 42 CFR Part 2 stacks on top of HIPAA and its trigger is identification as an SUD patient rather than clinical content, which means a calendar invite or fax cover sheet that names the patient and the program can itself be a disclosure. HIPAA has no analogous rule about the mere fact of association, which is precisely why practices miss this one.
There is a fourth constraint that is easy to overlook because it is not an AI rule at all. 45 CFR § 92.210 imposes an ongoing duty on covered entities to make reasonable efforts to identify uses of patient care decision support tools that employ input variables measuring race, colour, national origin, sex, age or disability, and to make reasonable efforts to mitigate the resulting risk of discrimination. It applies whether or not the tool is AI and whether or not FDA calls it a device. A recall-prioritisation model that uses age bands and insurance type is squarely the kind of thing you should be able to describe in that inventory.
TCPA, AI Voice and Recording Consent: The Sharpest Legal Risk in This Category
If you automate one thing in a pediatric practice it will be the phone and the text channel, because that is where the volume is. That is also where the largest quantified legal exposure in this entire cluster lives, and it is not HIPAA. It is the Telephone Consumer Protection Act.
AI voices are covered.The FCC's Declaratory Ruling FCC 24-17, released February 8, 2024 in CG Docket 23-362, holds that the TCPA's restrictions on an artificial or prerecorded voice encompass current AI technologies that resemble human voices, including voice cloning, and that callers must obtain the prior express consent of the called party absent an emergency or a regulatory exemption. Twenty-six state attorneys general supported that interpretation and may enforce it. There is no "it sounds natural so it is not prerecorded" argument.
The healthcare carve-outs are narrower than the market believes. Under 47 C.F.R. § 64.1200(a)(2), a health-care message from a HIPAA covered entity or its business associate to a wireless number needs prior express consent — not prior express writtenconsent, but not an exemption either. The residential-landline carve-out at § 64.1200(a)(3)(v) does exempt health-care messages from consent, but caps them at one call per day and three calls per week per patient and still requires opt-out handling. The emergency-purposes exception at § 64.1200(f) covers calls made necessary in a situation affecting the health and safety of consumers; appointment reminders and recall campaigns are not that. And anything that includes or introduces an advertisement, or constitutes telemarketing, is outside the carve-out entirely and needs prior express written consent — which is exactly what a "time for sports physicals, book now" blast looks like to a plaintiff.
| Rule | What it requires | Where practices get caught |
|---|---|---|
| Prior express consent, wireless (47 C.F.R. § 64.1200(a)(2)) | Consent before an artificial or prerecorded voice, or an autodialed text, reaches a mobile number — reduced standard for a covered entity's health-care message | Assuming that being a doctor's office is an exemption. It is not. The standard is reduced, not removed |
| Landline health-care exemption (§ 64.1200(a)(3)(v)) | No consent required, but capped at one call per day and three per week per patient, with opt-out honoured | Recall plus reminder plus results callback on the same day breaches the frequency cap without anyone noticing |
| Marketing content (prior express written consent) | Written consent for anything that introduces an advertisement or constitutes telemarketing | Reactivation and service-line campaigns dressed as clinical recall |
| Caller identification (§ 227(d)(3); § 64.1200(b)) | State the identity of the business responsible at the beginning of the message; give a callback number that is not the autodialer's; release the line within 5 seconds of hang-up | Agent opens with a friendly first name and no practice identity |
| Revocation | Accept any reasonable method; treat STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, UNSUBSCRIBE as per se reasonable; honour within 10 business days | Revocation captured in the SMS platform never reaches the voice dialer |
| No post-call opt-out substitute (FCC DA 20-669, 2020) | A provider cannot substitute a post-call opt-out for prior express consent | "They can always press 9 to opt out" as the consent strategy |
One deadline worth diarising. The FCC's "revoke-all" provision — under which a revocation given in response to one type of message applies to all future automated calls and texts from that caller — is not yet in effect. It was originally set for April 11, 2025, delayed to April 11, 2026, and on January 6, 2026 the FCC's Consumer and Governmental Affairs Bureau extended it again to January 31, 2027 (DA 26-12, CG Docket 02-278). So a practice running a voice agent for reminders and a separate marketing text program has until January 31, 2027before one "STOP" must kill both. Build for it now anyway; unifying revocation later is a data-migration project you will not want.
Recording consent is a separate statute in every state at once. A voice agent that records or transcribes is doing exactly what all-party consent statutes cover, and a single national deployment triggers all of them simultaneously. California Penal Code § 632.7 makes it an offense to intercept or intentionally record, without the consent of all parties, a communication involving a cellular or cordless telephone — first offense up to $2,500, repeats up to $10,000. Roughly a dozen states are commonly described as all-party; we are deliberately not publishing the list, because the only consolidated lists we could locate are SEO properties rather than statutory compilations. Cite your own state's statute or say "roughly a dozen, verify yours." Practical rule: play the notice beforeanything is captured, capture affirmative assent, and log it. A parent who calls you has not, by calling, consented to be recorded — and "we only transcribe" is not a safe harbour, because the statutes reach the contents of the communication.
Disclosure Law: What You Must Say, and Which State You Are In
Federal law does not yet require an AI voice agent to announce that it is not human. The FCC adopted an NPRM in CG Docket 23-362 on August 7, 2024 proposing to define an AI-generated call, require disclosure at the outset and require affirmative consent — but as of August 12, 2026 it has not been finalized, and anyone quoting you a finalization date is guessing. What is federal law is caller identity, and it always was.
| Jurisdiction / rule | In force | What it actually requires |
|---|---|---|
| California AB 3030 (Health & Safety Code § 1339.75) | January 1, 2025 | GenAI-generated patient communications pertaining to patient clinical information need an AI disclaimer plus instructions for reaching a human — verbally at the start and end for audio. Exempt if read and reviewed by a licensed human. Expressly excludes scheduling, billing and other clerical matters |
| California AB 489 (B&P §§ 4999.8–4999.9) | January 1, 2026 | AI may not use titles or terms implying that advice is coming from a licensed natural person. Each use is a separate violation. Naming your intake agent "Nurse Ava" is the textbook problem |
| Texas HB 149 (TRAIGA) § 552.051(f) | January 1, 2026 | If AI is used in relation to health care service or treatment, the provider must disclose to the recipient or their personal representative no later than the date service is first provided; emergencies as soon as reasonably possible. Broader trigger than California, with no human-review exemption on its face |
| Texas SB 1188 (Health & Safety Code § 183.005) | September 1, 2025 | A practitioner may use AI for diagnostic purposes if acting within scope regardless of the use of AI, if not otherwise restricted, and if the practitioner reviews all records created with AI — and must disclose the use to patients |
| 45 CFR § 92.210 | In the current CFR as of August 4, 2026 | Ongoing duty to identify patient care decision support tools using race, colour, national origin, sex, age or disability as inputs, and to make reasonable efforts to mitigate discrimination risk. Applies whether or not the tool is AI |
| Colorado SB 26-189 | Substantive duties January 1, 2027 per the enrolled bill's own effective-date section | HIPAA covered entities are carved out of the core ADMT duties to the extent they do business in Colorado, except for employment decisions — but a covered entity must still give patients a general notice of use of advanced technologies, and owes a richer disclosure where ADMT touches financial-assistance eligibility |
For a pediatric practice the AB 3030 boundary is the one to internalise, because it maps almost exactly onto the safe and unsafe halves of your automation plan. An agent confirming Tuesday at 3:15 is a clerical matter and outside the statute. An agent that answers "should I bring her in for this rash?" is a clinical communication and inside it — unless a licensed human read it first. Design the escalation boundary at that line and the disclosure question mostly answers itself.
A federal preemption fight is running in the background. Federal preemption of state AI law is being actively pursued, but nothing has displaced the statutes above, and we are not going to cite an executive order number or a bill number we did not read. Plan against the law as it stands.
Immunizations: A Contested Schedule, VFC Mechanics, Registry Reporting and Coding Traps
Immunization operations are the single largest automation opportunity in a pediatric practice and the one with the most moving legal parts right now. Before you encode a recall rule, understand what you are encoding it against.
The schedule itself is under litigation — build for a moving target
CDC published a revised 2026 childhood immunization schedule on January 5, 2026, approved by the Acting CDC Director in response to a December 5, 2025 presidential memorandum. CDC schedules have always used three recommendation categories — universal, risk-based, and shared clinical decision-making — so nothing structural changed; what the revision did was reallocate vaccines among them. Per the Congressional Research Service, 10 of the 17 vaccines on the 2026 schedule are recommended only for high-risk groups and/or by shared clinical decision-making (three SCDM-only), against 3 of 17with none SCDM-only on the 2025 schedule. Specifically, the revision changed Hepatitis A, Meningococcal ACWY and RSV from a full recommendation to risk-based with SCDM for children not at high risk; moved rotavirus and influenza to SCDM; reduced HPV to a one-dose regimen; and incorporated ACIP's own September 2025 (COVID-19) and December 2025 (Hepatitis B) recommendations.
On March 16, 2026 the US District Court for the District of Massachusetts, in American Academy of Pediatrics v. Kennedy, postponed the effective date of the revised schedule, reverting it to the version in effect as of May 2025, and stayed the appointments of the thirteen ACIP members appointed by the Secretary along with their votes at 2025 ACIP meetings. The government appealed to the First Circuit on April 29, 2026. CRS, as of June 11, 2026, describes the revised schedule as currently stayed with no immediate implications for other federal policies that rely on the schedule — and immediately caveats that depending on actions taken to implement Executive Order 14407, a newly adopted schedule could resemble the revised one.
Executive Order 14407 (May 29, 2026, 91 FR 106) directs CDC and ACIP to review the underlying assessment and update the childhood and adolescent schedules to the extent permissible by law, and directs agencies to align immunization regulations, funding and coverage with the ACIP-recommended schedule; § 2(c) states that immunizations in any category on a revised schedule adopted under it should continue to be covered without cost-sharing by VFC. HHS filed a notice to re-establish ACIP on May 19, 2026 (91 FR 29139), and CRS notes it is unclear whether ACIP has enough active members to carry out the directive. We could not verify anything after June 11, 2026. Treat this as live litigation, state it as of a date, and name the case.
VFC mechanics. Vaccines for Children is a Medicaid-financed, CDC-administered program providing recommended childhood vaccines at no cost to eligible children: those who are Medicaid eligible, uninsured, underinsured and receiving the vaccine at an FQHC or RHC, or American Indian/Alaska Native. The vaccines VFC buys are set by VFC-ACIP Vaccine Resolutions, adopted through a process separate from ACIP's annual vaccine recommendations — which is why CRS concludes that the 2026 schedule revision, unaccompanied by changes to those resolutions, would not appear to affect the vaccines covered under VFC even if it took effect. Per CRS analysis of NIS-Child data, 93% of US children aged 19–35 months were either VFC-eligible or covered by private insurance — one of the few genuinely clean statistics in this market, and worth contrasting with the vendor numbers later in this article.
The operational requirements around VFC — annual provider training, eligibility screening and documentation at every visit, ordering through the state immunization information system, dose-level eligibility reporting, and reporting windows measured in days — come to us from state health department pages rather than a CDC primary, because CDC's own provider pages return access-denied to automated retrieval. Indiana's CHIRP, for example, requires submission within seven business days. Verify your own state's numbers with your state program before you encode a deadline.
Coding traps an agent can catch before submission
The 2026 CMS NCCI Policy Manual, Chapter XI, states that administration of influenza, pneumococcal or hepatitis B vaccine is reported with HCPCS G0008, G0009 or G0010 respectively, and administration of other immunizations not excluded by law with CPT 90460–90461 or 90471–90474depending on the patient's age and physician counselling. The rule that generates rework, in the manual's own words, is that a provider shall report administration of all immunizations other than those three on a single date of service "from either of these 2 code ranges and shall not report a combination of CPT codes from the 2 code ranges."
Two more from the same section: where one or more immunizations and a significant, separately identifiable E/M service are rendered, the administration code and the E/M code with modifier 25 appended may be reported — but if the patient returns another day solely to receive another immunization, only the administration code is reported. And CPT 99211 is not separately reportable with vaccine administration codes 90460–90474, 90480, 90481 or G0008–G0010.
All three are deterministic pattern checks over data the chart already holds. They need no write access, no clinical judgement and no model creativity — which makes them the best first automation in a pediatric practice and the one most likely to survive an audit.
Well-Child Cadence, School and Sports Forms, and the Recall Engine
The AAP/Bright Futures Recommendations for Preventive Pediatric Health Care — copyright 2025, updated February 2025 — sets the visit columns your recall engine is really encoding: prenatal, newborn, 3–5 days, by 1 month, then 2, 4, 6, 9, 12, 15, 18, 24 and 30 months, then annually from 3 years through 21 years. History, physical exam, measurements, behavioural/social/emotional screening and immunization review occur at every visit; developmental screening at 9, 18 and 30 months; autism screening at 18 and 24 months; and maternal depression screening at the 1-, 2-, 4- and 6-month visits.
One honest caveat before you build against it: the file AAP serves today is the February 2025 edition. AAP updates the periodicity schedule annually, so a 2026 edition may exist and we could not confirm it either way. Re-check before you describe your recall rules as current — and again, version the configuration so that confirming it later is a five-minute change.
| Recall stream | Trigger data | Agent action that is safe today | Escalation |
|---|---|---|---|
| Well-child due / overdue | Date of birth against the periodicity schedule, plus last completed well visit | Build the due list, rank it, draft the outreach, place the call or send the message under a logged consent | Any family with two guardians in conflict, or a patient in the adolescent band with clinical content |
| Immunization catch-up | Immunization history against the schedule version in force, with a dated effective-date field | Identify gaps and assemble a worklist for the nurse manager | Anything under a shared clinical decision-making recommendation — that is definitionally a conversation |
| Forms and sports physicals | School-year calendar, prior-year form requests, sports season start dates | Detect the surge, open pre-booked capacity, notify families, track form status to completion | Clinical sign-off on the form itself, always |
| Sick-visit demand | Same-day call volume, held slot utilisation by hour | Answer, triage-by-protocol to a human, book only into slots the practice designated as agent-writable | Any symptom description. Symptom triage is not an administrative workflow |
| Sibling stacking | Guardian record with multiple active patients | Detect the opportunity and offer a family block for a human to confirm | Booking the block itself, until you have measured that the agent gets it right |
Forms deserve their own note because they are high-volume, usually non-covered, and universally hated. They are also the cleanest automation in the practice: the agent tracks which form was requested by which school for which child, whether the required visit has happened, whether the immunization record satisfies the school's requirement, and where the form is in the signature queue. None of that touches clinical judgement. The clinician still signs — and the signature is precisely the boundary that keeps the workflow safe, for the same reason CMS gives for record entries.
Top 10 Patient Communication & Voice Agent Platforms — Ranked on What Is Verifiable
This is the category a pediatric practice buys first, so it is the category we ranked. Read the methodology before the table; the exclusions are the reason the table is worth anything.
Methodology — what we scored, what we refused to score, and when we checked
- Checked: August 12, 2026. Vendor claims were re-fetched that day. Everything in this table is a snapshot of a public record that moves weekly.
- Scored on: Publicly named EHR/PM integrations (companies, not product SKUs); published compliance posture (BAA, SOC 2, HITRUST, ISO); pricing transparency; whether the product is a true conversational voice agent or voice-adjacent; and corporate stability from public record — funding, ownership, acquisitions, disclosed incidents and litigation.
- Excluded by design: accuracy, containment, resolution: We could not locate a single independent, head-to-head benchmark of commercial healthcare voice AI agents as of August 12, 2026. Every such figure in this market is vendor-published, with no disclosed methodology, sample or auditor — and the denominators are not comparable to each other. Scoring accuracy would mean ranking marketing.
- Not a benchmark: The report widely circulated as an industry benchmark is published by Digital Health Insights, fielded by Global Surveyz and sponsored by a vendor in this category; it is a survey of senior healthcare leaders, not measured agent performance. Separately, Best in KLAS is a customer-satisfaction survey of purchasers — a real signal about buyer happiness, never a measurement of agent accuracy, containment or resolution.
- Compliance negatives are bounded: Where we write "not published where we looked," we mean exactly that. Homepage fetches miss un-rendered badges and linked trust centres — one vendor here operates a trust centre that returned an error to our fetcher. We never write that a vendor has no BAA.
- No fake precision: Tiers, not scores. A 9.4/10 built on unverifiable inputs is a decoration.
- How to re-check: Open each vendor's own security or trust page, ask in writing whether they execute a BAA and which product features are in scope, and ask the write-path question in the next section. Then re-read this table's date.
Tier 1 — best-documented public record. These vendors publish enough for a buyer to verify something without a sales call. That is the whole claim.
| # | Platform | What it is | Named EHR/PM integrations (published) | Published compliance posture | Pricing | Corporate record | Pediatric caution |
|---|---|---|---|---|---|---|---|
| 1 | Luma Health | Patient access platform with layered AI agents (Conversational Agent / AI Navigator, inbound-fax Document Flow Agent) | Epic, Oracle Health, MEDITECH, eClinicalWorks, athenahealth, NextGen, Greenway, Nextech — named in Luma's own release | Strongest published posture in the set: HITRUST CSF r2, SOC 2 Type II annually, ISO/IEC 27001:2022, TX-RAMP Level 2, EU-US DPF. Source is Luma's own security page, search-summarized rather than read directly; a public BAA offer was not separately verified | Not published; contact sales | Private; $130M Series C (FTV Capital, Nov 2021), ~$160M total. Acquired Tonic Health from R1, announced November 12, 2025. A widely circulated "April 2026 $16M Series B" is a mis-dated recycling of a 2019 round — ignore it | Breadth is the risk: you are buying a platform, so scope the pediatric workflows explicitly rather than assuming the guardian model is handled |
| 2 | Weave (NYSE: WEAV) | All-in-one communication and payments platform for small and mid-size practices, with an acquired AI receptionist | Not verifiable from the primary pages we could read; the pricing page shows vertical tabs but names no PM/EHR | Not verified in this pass | The only published price we found in seventeen candidates: starting from $199 per month, with Pro/Elite/Ultimate plans requiring a quote | Public company. Acquired TrueLark (AI receptionist) for $35M — $25M cash plus $10M equity — closed May 19–20, 2025. TrueLark no longer exists as a standalone purchase | Small-practice fit is genuine, but confirm what the AI receptionist writes back into your PM system and under whose credentials |
| 3 | Artera (formerly WELL Health, renamed October 2022) | Unified patient communication (text, email, IVR, webchat) with an agent layer. Messaging-first; voice is one channel | None named publicly — the site says only "integrations with major EHRs." The absence is the finding | States SOC 2 Type 2, HITRUST Certified, HIPAA Compliant and FedRAMP on its homepage, plus "we do not use identifiable PHI/PII to train our models." Self-asserted; certificates not independently retrieved | Not published. A third-party page quoting an annual figure is affiliate SEO content — do not use it | Private; $65M growth investment led by Lead Edge Capital announced December 3, 2025; company states $100M CARR. Do not confuse it with WELL Health Technologies (TSX: WELL), a separate Canadian company | A messaging-first platform is a poor fit if your actual problem is the ringing phone in October |
Tier 2 — strong product record, thinner public verification. Real conversational voice agents with real funding, where at least one thing a buyer needs is not published.
| # | Platform | What it is | Named EHR/PM integrations (published) | Published compliance posture | Pricing | Corporate record | Pediatric caution |
|---|---|---|---|---|---|---|---|
| 4 | Assort Health | Healthcare-native voice-first AI across scheduling, intake, referrals, document processing, refills, eligibility and payments | Epic and athenahealth, described as native, in the company's own release; listed on the athenahealth Marketplace, though we could not read the listing's read/write scope | Not published where we looked — /security returned 404 and we found no trust page. Report it as a verification gap, not as an absence of controls | Not published | Private; $120M Series C led by Menlo Ventures announced June 24, 2026 at a $1.2B valuation, over $222M raised. The fastest-scaling entrant in the category | The vendor's public case studies are adult specialty groups; ask for a pediatric reference with a guardian data model, in writing |
| 5 | Hyro | Agentic voice and chat for health systems, combining LLMs with proprietary small language models and healthcare knowledge graphs | Epic, named in its funding release. No other EHR named in any primary source we could reach; its integrations page returned an error to our fetcher | Not verifiable — the security page returned an error. Its own releases claim HIPAA compliance only | Not published | Private; $45M growth round announced October 21, 2025 led by Healthier Capital, with Norwest, Define Ventures, Bon Secours Mercy Health and ServiceNow Ventures; $95M total. Note that a customer health system is also an investor | Health-system tilt. An independent five-provider pediatric group is not this product's centre of gravity |
| 6 | Phreesia VoiceAI (NYSE: PHR) | Intake, registration and payments platform; VoiceAI launched September 2, 2025 as an AI phone agent for inbound calls and outbound campaigns with routing to staff or on-call | None named — the launch release says only "with supported EMRs" | Not verified from a primary Phreesia page in this pass | Not published for VoiceAI | Public company, ownership from public record. Two disclosed items a buyer should weigh: the ConnectOnCall breach (Phreesia acquired ConnectOnCall in October 2023; intrusion February–May 2024, 914,138 individuals notified December 2024) and a securities class action in D. Del., class period May 2025–March 2026, which is not about VoiceAI | Intake-heavy fit is good for pediatrics; the disclosed incidents are a diligence item, not a disqualifier — ask what changed |
| 7 | Zocdoc — "Zo by Zocdoc" | AI phone assistant for inbound scheduling with unlimited concurrency and escalation with context; scheduling-scoped | None named — the release says only "lightweight phone and EHR integration" | Not verified | The most transparent pricing model in the set, though not a rate: "no time-based charges or license fees: practices only pay when Zo successfully manages an appointment," and "no upfront fees, implementation costs, or long-term commitments." The per-appointment rate is not published | Private. Launched May 1, 2025 after piloting with marketplace customers from Q3 2024; the release states that organizations do not have to be Zocdoc Marketplace customers to use Zo | Scheduling-only scope means it will not touch recall, forms or registry work — which may be exactly what you want first |
Tier 3 — credible, early, or narrower than the marketing suggests. Each of these can be the right answer for a specific practice; none should be bought without the questions in the red-flags section.
| # | Platform | What it is | Named EHR/PM integrations (published) | Published compliance posture | Pricing | Corporate record | Pediatric caution |
|---|---|---|---|---|---|---|---|
| 8 | Hello Patient ("Mia") | AI agents across calls, texts and chat: scheduling, insurance verification, intake, bill pay, no-show reconnection, recall | The longest published list among venture-stage entrants — but read its composition. Medical-practice systems named: ModMed, AdvancedMD, NextGen, eClinicalWorks, Veradigm, athenahealth. Also listed: AVImark and Cornerstone (veterinary), Zenoti (spa/med-spa) and Ottehr (open-source EHR) | Site states HIPAA Compliant and displays a SOC badge; we located no explicit BAA offer, and HITRUST appears as badge imagery only — do not describe it as HITRUST certified | Not published | Private; $22.5M Series A announced around September 2025 | The veterinary and spa systems in the integration list are a reminder to verify depth per system, not to count logos |
| 9 | Notable | Broad AI operations platform across patient access, RCM, care ops and contact centre, including a voice agent module — not a voice-first product | None named on the pages in this category's research; the site references a Connector Hub without naming EHRs | Footer badges show SOC 2 (AICPA) and ISO 27001:2022; HITRUST and a public BAA offer not verified | Not published | Private; roughly $116M raised across three rounds with the last disclosed round a Series B in November 2021 — no disclosed round in about four and a half years. That is the single most decision-relevant fact for a practice signing a multi-year contract. No evidence of layoffs or shutdown: say "no new round disclosed," not "in trouble" | Its homepage carries a literal accuracy percentage. Treat every such figure as marketing, per the methodology above |
| 10 | Parakeet Health | LLM-native voice agents for physician-practice call centres — scheduling, billing, outreach, 24/7, multilingual | None named; its own FAQ says only that it integrates directly with healthcare systems to read and write scheduling data | No BAA, SOC 2 or HITRUST statement located on the FAQ we fetched — but the FAQ links a trust centre that returned an error to our fetcher, so certifications may well be published there. Not published where we looked | Not published; markets a pay-for-performance model with no rate | Private; $3M seed closed October 15, 2024 led by Canvas Ventures; roughly 16 employees as of May 2026. Partnerships announced November 2025 | Sixteen people and $3M against a competitor's $222M is the honest risk story. Credit where due: its FAQ makes no numeric performance claims at all — a vendor that declines to invent a statistic |
The seven we cut, and exactly why
- 1.Prosper AI: Real product with a distinguishing payer-side outbound leg, cut for evidence hygiene: its homepage carries the most aggressive unsourced claims we encountered in the category, including a QA accuracy figure and a call-abandonment drop, and it runs a large content operation that ranks its own competitors. Never cite a vendor listicle about vendors.
- 2.Simbie AI: Names an impressive EHR list — which also contains an apparently nonexistent system. The sloppy list is itself the finding; treat the whole list as unaudited marketing until the vendor confirms each integration in writing.
- 3.Arini: Dental-only by design. Excellent fit for a DSO, wrong category for a pediatric practice.
- 4.Klara: Owned by ModMed since February 2022. It unifies text, chat, calls and transcribed voicemail into one thread — conversational messaging plus voicemail transcription, not an agent that holds a conversation and books. A communication tool owned by an EHR vendor also has an obvious incentive gradient, and its non-owner integrations run over interfaces that vendor does not control.
- 5.Solutionreach: Its AI voice product, Stella, is described on its own homepage as "your AI-powered voicemail replacement." That is a voicemail catcher, not an inbound voice agent — a category-defining distinction. Its results figures carry the company's own disclaimer that results depend on various factors and are not guaranteed; quote the disclaimer alongside any figure.
- 6.Dialpad: General-purpose UCaaS. It is the only vendor in the set with a publicly offered, self-serve BAA on all paid accounts — genuinely better than the healthcare-native field on that one axis — but no published EHR/PM integration and no published statement of which AI features fall inside BAA scope. An agent that cannot read or write the schedule can only route a call, not resolve it.
- 7.SmileSnap: Virtual consult intake for dental and orthodontic practices, not a phone product, and roughly four employees. Included only to explain the cut: a four-person company is not a defensible dependency for your phone line.
One structural point that belongs in every buying conversation: the vendors above are not the only things moving. Roll-ups are consolidating this category — Memora Health was absorbed into Commure in December 2024, and Commure raised $70M at a reported $7B post-money valuation on May 19, 2026, which makes it a plausible acquirer of anyone on this list. Ask what happens to your contract and your data on a change of control, and get the answer in the agreement rather than in the demo.
True Voice AI vs Templated Reminder Messaging — the Cheapest Way to Be Oversold
This distinction is verifiable without a single statistic, which is why we lead with it. There are three tiers in this market and they are priced as though there were one.
| Tier | What it actually is | How to test it in a demo |
|---|---|---|
| A. Conversational voice agent | Answers a ringing line, understands free speech, completes the task, writes to the PM/EHR, and escalates with context | Interrupt it mid-sentence with an unrelated question. Then ask it to change a booking it just made. Then hang up and call back and see whether it remembers |
| B. Voice-adjacent | Catches overflow or voicemail, transcribes, routes — does not transact | Ask what happens when the caller wants to book. If the answer is "a staff member picks it up from the thread," you are buying Tier B |
| C. Templated outbound messaging | Scheduled SMS, email or IVR reminders and recall from templates, with no comprehension | Reply to the reminder with a question. Silence is the answer |
Tier C is decades-old technology and should be priced accordingly. Tier B is useful and honest when the vendor says so plainly — one vendor in our roster describes its own product as a voicemail replacement, which is more candour than most. Tier A is the thing under discussion when a practice says "AI agent," and it is the tier where the write-path question below decides whether the product can actually finish a job.
The statistics we refuse, and why naming them helps you
You will be shown numbers. Here are the ones we will not print as fact, each because we chased it and it did not survive: $200 per no-show and $150 billion a year in missed appointments, both of which trace to a single 2017 byline by a scheduling vendor's CMO with no methodology; any phone-abandonment benchmark used to sell voice agents; "42% of incoming calls missed" (a study of 7,000 calls across 22 practices that we could not locate an origin for — no author, no publication, no date, no journal); "23% of calls go unanswered" attributed to a Talkdesk healthcare report that does not appear to exist under that name, and which some pages simultaneously attribute to a different organisation — a statistic with two different claimed parents has no parent; and any AI accuracy rate presented as neutral, because every one in this market is vendor-published.
The single best worked example is a vendor ROI page we reviewed that stacks nine or ten statistics on one screen: a per-missed-appointment dollar figure attributed to a transit-software company; a $150 billion total effectively unattributed; an abandonment-rate range with no attribution at all; and six separate figures each cited to a company selling the fix. Two items on that page are legitimate — a newspaper report on a national health service line and a case study from a call-analytics firm that does not sell to US practices — and we say so, because the point is accuracy, not dunking. Read any ROI page that way and you will not need us.
And the one we will name specifically because it is instructive: a customer testimonial published by a vendor in its own product launch stating that "our abandonment rate has dropped to zero." One clinic, no baseline, no measurement period, no definition of abandonment, no independent verification. An abandonment rate of exactly zero is not a plausible steady-state measurement of anything.
The only trustworthy benchmark for your practice is your own baseline. Pull 60–90 days of your own carrier or phone-system call detail records before you sign — total inbound, answered, abandoned, average speed to answer, after-hours volume, repeat callers within 24 hours — and make the vendor commit contractually to reporting the same fields post-deployment, on your data, not theirs.
The Write-Path Constraint — and the Registry That Is Not on the Rail at All
This is the single most important architectural fact in the cluster, and it is the one most consistently glossed over in demos. Certified API access under § 170.315(g)(10) is read-only. ASTP/ONC's own test method states it: read services allow authenticated and authorized third-party applications to view electronic health information through a secure API, and those services specifically exclude write capabilities where third-party applications would be able to create or modify EHI.
Read services include those that allow authenticated and authorized third-party applications to view EHI through a secure API. These services specifically exclude "write" capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.
— ASTP/ONC, Standardized API for Patient and Population Services test method
So in your EHR, an agent can be guaranteed only to read demographics, problems, medications, allergies, results, notes and coverage, to search, and to export in bulk. Everything else — booking the appointment, updating the immunization record, filing the form, writing the note, posting the payment — is not covered by certification and exists only if that EHR vendor chose to build it, chose to expose it, and chose to let your vendor use it. That is a commercial arrangement, and it can be revoked, throttled or repriced.
Do not overstate the constraint either: some EHR vendors voluntarily publish write-capable FHIR resources, and the documented write surface is narrow and resource-specific rather than nonexistent. The federal trajectory is also moving — ASTP/ONC's HTI-5 proposed rule, published December 29, 2025, states an aim to move beyond read-only interactions in future API requirements. It remains a proposed rule as of today. Write access is on the federal agenda; it is not a right.
The exact question to put to your EHR representative, in writing
"Which FHIR resources can a third-party application create or updatein my instance? Is that through a certified API or a proprietary one? What does it cost? Does it require your approval per vendor? And if the answer is 'no API', is the integration performing robotic process automation under a named user's credentials?"
That last clause is the one that matters operationally. At least one platform vendor in this market states plainly that it uses "APIs, RPA, HL7, and more" to get data into the right fields. RPA is a robot typing into the EHR's user interface on a service account. It breaks when the UI changes, it is often invisible in the audit log as a system action, and it attributes the agent's actions to whichever human's credentials it runs under — which collides directly with 45 CFR § 164.312(a)(2)(i), where unique user identification is required, not addressable. An agent needs its own identity, not a borrowed clinician login.
And then there is the registry. Writing to a state immunization information system is not a § 170.315(g)(10) capability at all. It is a state-by-state HL7 interface with its own onboarding, and the state registry is the system of record for the reportable event. Three buckets, and every proposed pediatric automation belongs in exactly one:
| Bucket | What it covers in a pediatric practice | Availability |
|---|---|---|
| 1. Read-and-reason | Well-child due lists from the periodicity schedule and immunization history; catch-up gap detection; code-range conflict detection before submission; missing VFC eligibility screen detection; dose-versus-inventory reconciliation; forms status tracking | Available now on any certified EHR. This is where a pediatric practice should start and where most of the value is |
| 2. Write (vendor-discretionary) | Booking and rescheduling, charge posting, note filing, order entry, problem-list and immunization-record updates | Requires a commercial integration on the EHR vendor's terms, or RPA, or a human. No certification requirement compels any vendor to offer it |
| 3. Outside the health-IT rail entirely | State immunization registry submission; school and district portals; some payer and Medicaid portals | Each is its own integration, none is standardized, and the reportable event is legally the registry's |
The Human-in-the-Loop Boundary, Written Down Before You Deploy
Write this table into your implementation plan and into your vendor agreement. The categories are not preferences; most of the "never" rows have a statute behind them.
| Decision | Agent alone | Agent drafts, human commits | Never the agent | Authority |
|---|---|---|---|---|
| Answer an inbound scheduling call and book into a designated slot | Yes, within agent-writable slot types and with logged consent and disclosure | — | — | 21 U.S.C. § 360j(o)(1)(A) — administrative support is outside the device definition by statute |
| Build a well-child or immunization catch-up recall list | Yes | — | — | Same administrative exclusion; the list is a computation over existing chart data |
| Send an outbound automated call or text to a guardian | Only against a logged, in-scope consent record with revocation checked at send time | Any new campaign template, before first send | Any recipient whose consent cannot be evidenced | 47 U.S.C. § 227(b)(3); 47 C.F.R. § 64.1200 |
| Answer a clinical question from a parent | No | Yes, if a licensed human reads and reviews before it goes out | Autonomous clinical answers | Cal. Health & Safety Code § 1339.75; FDA CDS criteria at 21 U.S.C. § 360j(o)(1)(E) |
| Symptom triage / level-of-care recommendation | No | Protocol-driven routing to a licensed human, with the human deciding | A specific directive output under time pressure | FDA 2026 CDS guidance — a specific preventive, diagnostic or treatment directive fails Criterion 3; FDA weighs automation level and time-criticality under Criterion 4 |
| Vaccine administration coding suggestion | Pre-submission conflict detection and flagging | Code selection and claim submission | Attesting to the claim | CMS NCCI Policy Manual Ch. XI; 42 CFR § 424.36 |
| Sign or attest to a record entry | No | No | Never, in any configuration | CMS Program Integrity Manual Ch. 3 § 3.3.2.4 — practitioner concurrence is explicitly required for AI-captured entries |
| Submit a dose to the state immunization registry | No | Reconcile and produce an exception list for a human to submit | Autonomous registry submission | IIS submission is a state HL7 interface outside § 170.315(g)(10); the registry is the system of record |
| Complete or sign a school, camp or sports form | Track status, assemble the packet, chase the missing document | — | Clinical sign-off | The signature is a licensed act; entities have no professional rights, privileges or powers (e.g. Cal. B&P § 2400) |
| Add or change a guardian relationship on a record | No | Yes, with staff verification against a document | Inferring a relationship from a caller's assertion | Practice policy plus state minor-consent and custody law |
| Release records or results | No | Yes, under existing release-of-information policy | Autonomous release, especially for adolescent patients or Part 2 records | 45 CFR § 164.502; 42 CFR § 2.12 |
One caution about relying on the middle column. FDA's own 2026 town-hall material discusses automation bias — the propensity of humans to over-rely on a suggestion from an automated system, producing errors of commission and omission, and worsening under time pressure. Pair that with the Nature Communications finding that injections can be non-obvious to human observers, and "a human reviews it" stops being a blanket answer and becomes a design requirement: the reviewer must be given the material they need to actually review, with the time to do it.
The Sequenced Implementation Path — Phases, Owners, Entry and Exit Criteria
This is a 20-week path for a two-to-eight-provider pediatric practice. Each phase has an owner, an entry condition, an exit condition and a stated failure response. Phases overlap deliberately; the gate is the exit criterion, not the calendar.
Phase 0 — Baseline and consent inventory (Weeks 1–2)
Owner: Practice administrator. Entry: an executive sponsor named and one clinical champion identified. Work: pull 60–90 days of your own phone system's call detail records (total inbound, answered, abandoned, speed to answer, after-hours volume, repeat callers within 24 hours); export the guardian contact model and count how many patients have two guardians, conflicting numbers or a custody flag; inventory every existing consent artefact by channel and date. Exit: a written baseline document and a consent register with a defensible capture artefact for each entry. If it fails— if you cannot produce the CDR data — stop. A practice that cannot measure its phone today cannot evaluate a vendor's effect on it tomorrow, and every number you are later shown will be the vendor's.
Phase 1 — Legal boundary map (Weeks 2–4)
Owner: Administrator with outside counsel. Entry: Phase 0 baseline complete. Work: written TCPA consent policy by channel and content type; a recording and transcription notice script; a state disclosure matrix for every state you have patients in; a revocation-handling specification that spans voice and SMS as one list; and the § 92.210 decision-support inventory entry. Exit: counsel signs the consent policy and the notice script. If it fails — if counsel cannot get comfortable with outbound — deploy inbound-only and revisit. Inbound answering carries a fraction of the TCPA exposure.
Phase 2 — Write-path determination (Weeks 3–6)
Owner: IT or EHR liaison. Entry: shortlist of two or three vendors. Work: put the write-path question from the previous section to your EHR representative in writing and to each vendor in writing; ask each vendor which integration method they will use in your instance and whether any part of it is RPA under a named user's credentials; ask each for a BAA and for a written statement of which product features are in scope under it. Exit: a written answer from the EHR vendor and from each finalist. If it fails — if no one will answer in writing — that is your answer. Proceed read-only or change vendors.
Phase 3 — Read-only pilot, one workflow (Weeks 5–9)
Owner: Front-desk lead, with the clinical champion on escalations. Entry: BAA executed; consent policy live; disclosure and recording notice in the call script; agent has its own unique identity in every system it touches. Work: one workflow only. Our default first pick is after-hours and overflow inbound answering with human-confirmed booking, plus read-only recall list generation. Exit: four consecutive weeks with deflection measured against the Phase 0 baseline; repeat-contact-within-72-hours tracked; zero unconsented recordings in a sampled audit; escalation transcripts reviewed daily for the first two weeks and weekly after. If it fails — if repeat contact rises — the agent is deflecting, not resolving. Narrow the scope rather than tuning prompts.
Phase 4 — Write enablement and immunization reconciliation (Weeks 9–14)
Owner: Clinical operations or nurse manager. Entry: Phase 3 exit met and a documented write interface exists. Work: enable booking into a restricted set of agent-writable slot types that explicitly excludes same-day sick holds; add immunization reconciliation as a read-only comparison producing an exception list; add pre-submission coding conflict detection for the 90460/90471 range rule, the 99211 bundling rule and modifier 25. Exit: write success rate and orphan-draft rate instrumented and stable for three weeks; exception lists resolved within one business day; no drift between chart and registry beyond an agreed threshold. If it fails — flip the write flag off. The read-only mode must be a configuration toggle, not a redeployment, and you should have tested that toggle before you needed it.
Phase 5 — Forms, recall and consented outbound (Weeks 13–18)
Owner: Practice administrator. Entry: consent register complete for the target cohort; counsel-approved campaign template. Work: school and sports forms tracking to completion; well-child and catch-up outreach to consented guardians only, with revocation checked at send time and frequency capped below the landline limits regardless of line type; age-banded content policy enforced. Exit: campaign audit showing every recipient traceable to a consent record, and a suppression list that is honoured across both voice and SMS. If it fails — if a single recipient cannot be traced to a consent record — suspend the campaign that day. This is the phase with seven-figure exposure.
Phase 6 — Steady state and quarterly audit (Week 17 onward)
Owner: Compliance lead or administrator. Work: quarterly review of the agent's audit log under 45 CFR § 164.312(b); re-verification of the recall configuration against the immunization schedule version actually in force; a re-read of each vendor's trust page; and a change-of-control check. Exit: a dated one-page attestation from the administrator that the boundary table still describes what the system does. That document is what makes the next audit short.
What Breaks First in a Pediatric Deployment — Detection Signal and Rollback
These are the pediatric-specific failure modes, in roughly the order we see them. Each row gives the signal that tells you it is happening and the rollback that stops it the same day.
| Failure mode | Why pediatrics specifically | Detection signal | Rollback |
|---|---|---|---|
| Message goes to the wrong guardian | Two guardians, different numbers, custody terms that no PM system encodes | Complaint log tagged "wrong recipient"; a weekly report of patients with more than one active guardian contact receiving automated messages | Pin automated outbound to a single staff-verified guardian per patient; route all second-guardian contact to a human |
| Adolescent confidentiality leak | Automated content addressed to a guardian may disclose what state minor-consent law protects | Audit of outbound message bodies for patients in the adolescent band; any message containing a visit reason or result | Disable clinical content for the adolescent band immediately — time and place only, or human handling |
| Same-day sick capacity disappears | Held slots are the practice's shock absorber and an optimiser will fill them | Held-slot utilisation measured at 8:00 a.m. daily; a drop below your floor two days running | Remove sick-hold slot types from the agent-writable set; re-enable only after slot-type restrictions are proven |
| Siblings booked separately | Families expect one trip; the agent books per patient | Same-guardian, same-week, multiple-booking report | Send family bookings to a human queue until the pattern is measured as correct |
| VFC eligibility screen missed on agent-created visits | Screening and documentation is required at every dose; a new booking path can bypass a form staff normally complete | Doses administered with no documented eligibility screen, run weekly | Block the agent from creating vaccine-only visit types until the screen is enforced in the booking path |
| Chart and registry drift | Registry submission is outside the certified rail and often lags | Weekly reconciliation exception count trending up; any exception older than your state's reporting window | Registry submission stays human; agent output reverts to an exception list only |
| RPA write path breaks after an EHR update | Screen automation is brittle by construction and the failure is silent | Write success rate, orphan-draft count, and a canary transaction run every morning | Flip the read-only toggle; queue writes for staff; do not let the agent retry blindly |
| Consent and revocation drift | Voice and SMS often live in different systems with different suppression lists | Nightly diff of the SMS STOP list against the voice dial list; any non-zero difference | Suspend outbound entirely until the lists are unified. This is the failure with statutory damages attached |
| Recall logic points at a superseded schedule | The 2026 schedule is stayed, under appeal, and subject to executive-branch revision | Configuration version and effective date displayed on the recall report itself; a monthly check by the medical director | Freeze outreach for affected vaccine families; revert to the prior configuration version |
| Untrusted text reaches the agent | Inbound faxes, school forms and portal messages are unauthenticated text arriving as instructions | Escalation transcripts sampled for anomalous instruction-like content; any agent action with no matching human request | Keep the agent read-only on any channel carrying externally authored documents; treat this as blast-radius reduction, never as a solved problem |
Red Flags in Vendor Selection
- 1.An accuracy, containment or resolution percentage offered as neutral evidence: No independent benchmark exists in this category. Ask for the denominator, the sample, the date range and the auditor. There will not be one. A vendor that acknowledges that plainly has told you something useful about how it will behave later.
- 2."We integrate with Epic" used to mean "we write to Epic": Certified API access is read-only. Ask which resources the product creates or updates in your instance, over which interface, and whether the EHR vendor has approved it.
- 3.No written answer on RPA: If any part of the write path is screen automation under a named user's credentials, you need to know before go-live, because it changes your audit log, your breakage profile and your § 164.312(a)(2)(i) posture.
- 4."HIPAA-compliant AI" as a product property: HIPAA attaches duties to covered entities and business associates, not to software. The correct formulation is "used under a BAA covering these subcontractors, with these controls." Ask for the BAA and ask which features are in scope under it — that second question is where general-purpose platforms get quiet.
- 5.A clinical-sounding agent persona: In California, AI use of terms indicating that advice is being provided by a licensed natural person is a per-use violation with licensing-board jurisdiction. "Nurse" anything is a bad name for your intake agent.
- 6.Consent handled as a checkbox in the vendor's UI: Ask where the consent artefact is stored, whether you can export it, and how revocation propagates across voice and SMS. You are the defendant, not them.
- 7.Recording enabled by default with notice "in the terms": All-party consent statutes require consent from the parties to the call, not acceptance of a terms page. The notice must play before capture.
- 8.A pediatric demo that models the patient as the contact: Ask to see the guardian data model, the second-guardian handling and the adolescent content policy. If those are roadmap items, you are the pilot.
- 9.Case studies denominated in production dollars with no denominator: How many practices, over what period, net of what, against what counterfactual? Dollar-value case studies with no denominator are not evidence, and this category is full of them.
- 10.No answer on change of control: This category is consolidating, and the roster above has already changed hands: TrueLark into Weave (2025), Klara into ModMed (2022), Tonic into Luma (2025), Memora into Commure (2024). We found no shutdown among the ten. The cautionary case sits in an adjacent category, not this one — after a private-equity roll-up, one healthcare automation vendor's standalone services were discontinued for portfolio reasons with customers reportedly given roughly 90 days to migrate, which is trade-outlet reporting rather than a company statement. Nothing public suggested that product had failed; the exposure was a cap-table risk, not a technology risk. Put continuity terms in the agreement.
- 11.A vendor citing its own competitor listicle: Several vendors in this space run content operations that rank their competitors. Those pages are marketing, and so are the third-party "pricing" pages that quote figures no vendor has published.
Limitations, Cost and Timeline
Everything above is bounded by what we could verify on August 12, 2026. Here is what we could not, stated plainly, because a limitation you know about is worth more than a confident sentence you cannot check.
- The current Bright Futures edition: The file AAP serves today is the copyright 2025, February 2025 update. AAP revises annually and a 2026 edition may exist; we could not confirm it either way.
- The litigation status: We could not verify anything in American Academy of Pediatrics v. Kennedy after the CRS publication date of June 11, 2026, including any ACIP re-establishment or CDC action under Executive Order 14407. Check the docket.
- VFC operational mechanics: CDC's own provider pages return access-denied to automated retrieval. Screening documentation, ordering, wastage rules, dose-level eligibility reporting and the compliance-visit regime come from state health department pages, not a CDC primary.
- Vendor compliance postures: For several vendors we found no BAA, SOC 2 or HITRUST statement at the URLs we checked. That is a discoverability finding about the public record, not a statement about the vendor's actual controls — one vendor here publishes a trust centre that simply returned an error to our fetcher.
- Prices: One published price exists in this entire category — Weave's starting-from figure — plus two vendors that publish a pricing model without a rate. Every dollar figure you find on a third-party "pricing" page for these products is affiliate or competitor content.
- The all-party consent state list: The only consolidated lists we could locate are SEO properties. We will not publish a twelve-state list as verified; cite your own state's statute.
- Colorado's effective dates: The enrolled SB 26-189 sets January 1, 2027 for the substantive duties with a few narrow subsections effective upon passage, and published analyses of the dating differ. Read the bill at leg.colorado.gov before you rely on a date. We also found a secondary claim that the act is under legal challenge that the Colorado Attorney General's own page does not support — we do not repeat it.
- Federal AI-call disclosure: The FCC's AI-disclosure NPRM is not finalized and we found no finalization date. Federal caller-identity requirements are law; a federal "I am an AI" requirement is not, yet.
- Prompt injection through practice channels: The peer-reviewed evidence covers patient dialogue and medical imaging. We found no published study of injection through patient portal messages, referral faxes or payer portals in a live practice. Extrapolating to your fax line is reasoning, not evidence — and prompt injection is unsolved, so design for blast-radius reduction rather than prevention.
What this costs and how long it takes.These are Frenchy Digital's published engagement ranges, identical across every article in this cluster.
| Engagement | Range | Timeline |
|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks |
| Single-workflow agent (intake, scheduling, recall, documentation) | $28k–$70k | 4–9 weeks |
| Multi-workflow platform with EHR/PM integration | $70k–$180k | 9–16 weeks |
| Enterprise / multi-site / regulated build (audit logging, HITL, SOC 2 posture) | $180k–$420k+ | 14–24 weeks |
Senior-led delivery at $150–$225/hour; ongoing retainers $2,500–$9,500 per month; a 30-day post-launch warranty; a written fixed-price phased proposal within 5 business days of a discovery call; and full source-code and IP ownership transfers to you. Frenchy Digital is a senior-led Black-owned Los Angeles agency. Most pediatric practices with two to eight providers land in the single-workflow band for a first deployment — inbound answering plus recall list generation — and reach the multi-workflow band only when registry reconciliation and forms automation come into scope.
If you want a grounded read on whether an agent fits your practice — including an honest answer when it does not — book a free 60-minute discovery call at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601. You leave with a written scope and a fixed-price phased proposal within 5 business days.
Get a Straight Answer on AI Agents for Your Pediatric Practice
Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned LA agency. We map your guardian data model, consent and recording posture, EHR write path and registry interface — then send a written scope and a fixed-price phased proposal within 5 business days.
Planning an AI Agent Build for Your Pediatric Practice?
Book a free 60-minute discovery call with Frenchy Digital. We map your guardian data model, your consent and recording posture, your EHR write path and your registry interface — then send a written scope and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 147 U.S.C. § 227 — Restrictions on the use of telephone equipment↗
- 247 C.F.R. § 64.1200 — Delivery restrictions↗
- 3FCC Declaratory Ruling FCC 24-17, CG Docket 23-362 (AI voices under the TCPA)↗
- 4FCC DA 26-12, CG Docket 02-278 — revoke-all extension to January 31, 2027↗
- 5FCC NPRM — Implications of AI Technologies on Protecting Consumers from Unwanted Robocalls↗
- 6FCC DA 20-669 — post-call opt-out does not substitute for prior express consent↗
- 7California Penal Code § 632.7 — recording cellular and cordless communications↗
- 8California AB 3030 — GenAI patient communications disclaimer (Health & Safety Code § 1339.75)↗
- 9California AB 489 — Health Advice From Artificial Intelligence (B&P §§ 4999.8–4999.9)↗
- 10Texas HB 149 (TRAIGA) — enrolled text, § 552.051(f)↗
- 11Texas SB 1188 — Health & Safety Code § 183.005, AI in the electronic health record↗
- 12Colorado SB 26-189 — bill page and enrolled text↗
- 1345 CFR § 92.210 — Nondiscrimination in the use of patient care decision support tools↗
- 1445 CFR § 164.312 — HIPAA technical safeguards (access control, unique user ID, audit controls)↗
- 1545 CFR § 160.103 — definition of business associate↗
- 1642 CFR § 2.12 — applicability of the substance use disorder confidentiality rules↗
- 17CMS Medicare Program Integrity Manual, Ch. 3 § 3.3.2.4 — signature requirements↗
- 1842 CFR § 410.26 — services and supplies incident to a physician's service↗
- 1921 U.S.C. § 360j — administrative-support exclusion and the CDS criteria↗
- 20FDA — Clinical Decision Support Software guidance (landing page)↗
- 21FDA — CDS final guidance town hall transcript, March 11, 2026↗
- 22Congressional Research Service R48982 — The 2026 Childhood Immunization Schedule (June 11, 2026)↗
- 23AAP / Bright Futures — Recommendations for Preventive Pediatric Health Care (Feb 2025 update)↗
- 24ASTP/ONC — Standardized API for Patient and Population Services test method (read-only)↗
- 2545 CFR § 170.404 — API conditions of certification, registration timeframes↗
- 26ASTP/ONC HTI-5 proposed rule — deregulatory actions (proposed, not final)↗
- 27Unified Agenda RIN 0945-AA22 — HIPAA Security Rule NPRM, final action projected July 2027↗
- 28Luma Health — acquisition of Tonic Health, November 12, 2025 (named EHR integrations)↗
- 29Assort Health — $120M Series C announcement, June 24, 2026↗
- 30Hyro — $45M growth round, October 21, 2025↗
- 31Artera — $65M growth investment, December 3, 2025↗
- 32Phreesia — VoiceAI launch release, September 2, 2025↗
- 33Zocdoc — launch of Zo by Zocdoc (pricing model stated, no rate published)↗
- 34Weave — pricing page, starting from $199 per month↗
- 35Weave completes TrueLark acquisition, May 2025↗
- 36Hello Patient — published integration list↗
- 37Notable — trust and platform claims↗
- 38Parakeet Health — FAQ (read and write scheduling data; trust centre linked)↗
- 39Solutionreach — Stella described as an AI-powered voicemail replacement↗
- 40Dialpad — sign a Business Associate Agreement (self-serve BAA)↗
- 41Digital Health Insights — 2026 Healthcare AI Agent Benchmark Report (vendor-sponsored survey)↗
- 42PatientAgentBench (Vatanparvar et al., arXiv:2607.25485) — benchmarks models, not products↗
- 43Lee RW et al., Vulnerability of LLMs to Prompt Injection When Providing Medical Advice, JAMA Netw Open 2025↗
- 44Clusmann J et al., Prompt injection attacks on vision language models in oncology, Nat Commun 2025↗
- 45Keona Health — missed-call ROI page (worked example of laundered statistics)↗

