Why Urgent Care Is Not a Scheduled Practice
Every other article in this cluster starts from a calendar. Dermatology has procedure blocks, physical therapy has a plan of care that repeats three times a week, OB-GYN has a visit series that runs for forty weeks. Urgent care has none of that, and the absence is the entire design brief. Arrivals are a stochastic process with strong hour-of-day, day-of-week and seasonal effects. The operational levers are staffing to a forecast and managing the queue, not filling slots and chasing no-shows.
That single structural fact moves the automation targets. Recall campaigns, waitlist backfill, reminder cadences and slot optimisation — the standard demonstration reel for a patient communication platform — either do not apply here or apply only to the small scheduled corner of the business. What matters instead is door-to-door time, the honesty of your queue communication, eligibility and payment at the point of service because there is no pre-visit window in which to verify benefits, occupational medicine contracts, and result callbacks to patients you have no ongoing relationship with.
The variance point deserves an uncomfortable admission up front, because it determines what you should expect to buy. Staffing forecasts are genuinely hard — not merely unautomated, but a forecasting task rather than a workflow task. An agent that reads your chart data and drafts a document is doing something structurally different from a model that predicts Saturday evening arrivals in flu season. Vendors blur those two together constantly. Keep them separate in your own head, in your requirements document, and in your contract.
A number we will not print, and why
Door-to-door time is the metric urgent care operators actually manage, so it is the metric a vendor will quote at you. We could not verify a single door-to-door benchmark at source. The benchmarking data belongs to the industry association and sits behind membership, and every public citation we chased — “under 30 minutes”, “the industry average is X” — resolved to a vendor blog restating it rather than to a primary dataset with a methodology, a sample and a denominator.
So we name the metric and refuse the number. This is not pedantry. If you buy against an unsourceable benchmark, you have no way to tell whether your result is good, and the vendor controls both the goalpost and the scoreboard. Measure your own door-to-door distribution from your own timestamps across a full seasonal cycle, and make that your benchmark.
The same refusal applies to the phone statistics that get used to sell voice agents into this market. Every commonly cited abandonment benchmark traces back to vendor content, a dead attribution or a report that does not exist. So do the no-show economics figures that circulate in scheduling software marketing. We do not print them, and neither should your business case. What can be said honestly is mechanical: an agent with unlimited concurrency cannot produce a hold queue for the calls it handles. That is arithmetic, not a result — and it says nothing about whether those calls were resolved.
The Workflow Map: What Is Automatable Today
Start with the five workflows that consume the most administrative labour in a walk-in centre. They are not the five a software demo will show you, because three of them are invisible from outside the building.
- 1.Unscheduled arrival intake: Registration, insurance capture and consent for a patient the system has never seen, at a rate that varies hourly and seasonally. This is first-contact data entry under time pressure, repeated all day.
- 2.Queue and room management: Controlling door-to-door time, with online check-in or save-my-spot diverting some arrivals into a pseudo-schedule that must be reconciled against true walk-ins in real time.
- 3.Eligibility and payment at the point of service: There is no pre-visit window in which to verify benefits. Whatever verification happens, happens while the patient is standing at the desk.
- 4.Occupational medicine contracts: Employer-paid pre-employment physicals, drug screens, injury care and DOT medical examinations — billed to employers, not payers.
- 5.Follow-up and result callbacks: Cultures, imaging over-reads and other pending results on patients with no ongoing relationship, no established communication preference and often no portal account.
Now sort every candidate automation into one of three buckets and say out loud which one it is. This is the discipline that separates a workable plan from a demo. The bucket determines the integration cost, the failure mode and whether the thing is even possible without a commercial negotiation.
| Bucket | What it means | Urgent care examples |
|---|---|---|
| 1. Read-and-reason (available now, any certified EHR) | Computes over data the chart already holds and hands a human a conclusion. No write, no commercial negotiation, no vendor discretion. | Result-callback worklists; pending-culture and over-read tracking; occ med panel due-lists; charge-capture completeness checks before the claim drops; identifying encounters missing a required consent artifact. |
| 2. Write (vendor-discretionary) | Creating or modifying anything in the EHR or practice-management system. Requires a commercial integration on the EHR vendor's terms, UI automation, or a human. | Creating the encounter from online check-in; updating the coverage record after eligibility; filing the discharge document; posting the point-of-service payment; closing the result loop in the chart. |
| 3. Outside the health-IT rail entirely | Systems with their own onboarding, their own credentials and no interoperability standard between them and your EHR. | FMCSA National Registry for DOT exams; employer occ med portals; drug-screen laboratory portals; workers' compensation claims administrators; your own telephony and SMS platform. |
Applied to urgent care, the honest split looks like this. Automatable today: pre-arrival registration and insurance capture from online check-in; real-time wait estimates computed from your own data; eligibility verification at check-in; discharge instruction delivery; result-callback worklists; employer invoicing and occ med panel tracking. Not automatable on any health-IT rail: DOT examination result submission, which goes to the FMCSA National Registry by the next calendar day, on FMCSA's own system, by the certified examiner — an individual credential, not the clinic's. Genuinely hard rather than merely unautomated: the staffing forecast.
The Write Path: Certified API Access Is Read-Only
This is the single most important architectural constraint in outpatient AI, and it is the one most consistently glossed over in a sales cycle. Certified API access does not give anyone the right to write into your EHR. ONC/ASTP says so in its own certification companion guide for §170.315(g)(10), last updated 15 May 2026:
The § 170.315(g)(10) certification criterion requires Health IT Modules to support API-enabled ‘read’ services for single and multiple patients. … These services specifically exclude ‘write’ capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.
— ONC/ASTP, Certification Companion Guide, §170.315(g)(10), updated 05-15-2026
Read that against the urgent care workflow list and the consequence is immediate. An agent can be guaranteed to read demographics, problems, medications, allergies, results, notes and coverage, and to export in bulk. Everything a walk-in centre actually wants closed — creating the encounter from an online check-in, updating the insurance record after a real-time eligibility response, filing the discharge instruction document, posting the point-of-service payment, marking the pending culture as communicated — is not covered by certification. It exists only if that EHR vendor chose to build it, chose to expose it, and chose to let your vendor use it.
Do not overstate the constraint either. Some EHR vendors voluntarily publish write-capable FHIR endpoints. Epic's public developer documentation at fhir.epic.com documents create support on resources including DocumentReference, Observation, QuestionnaireResponse, AllergyIntolerance, Condition, Communication and BodyStructure, and update support on a narrower set. The documented write surface is narrow and resource-specific rather than a general right to modify the record — but it is real, and for a document-filing or questionnaire-response workflow it may be exactly what you need.
Where an API write does not exist, the write happens by robotic process automation: a robot typing into the EHR's user interface. Vendors rarely volunteer this. One of the few that states it plainly is Notable, whose integrations page describes its method as “APIs, RPA, HL7, and more” to get data into the right fields. That is the most useful integration disclosure in the category, and it should change how you evaluate everyone else — because if a vendor claims bidirectional sync with your EHR and will not tell you which mechanism produces each write, you are being asked to accept an undisclosed dependency.
The exact question to ask your EHR representative
Send this in writing, and keep the reply. It is the cheapest de-risking available to you and it takes one email.
Which FHIR resources can a third-party application create or update in my instance? Is that through a certified API or a proprietary one? What does it cost, and is there a per-transaction fee? Does it require your approval per vendor, and how long does that review take? And if the answer is that no write API exists for this workflow, is the integration performing UI automation under a named user's credentials?
That last clause matters more than it looks. An RPA write executed on a staff member's login appears in the EHR audit trail as that person's action. If you cannot distinguish agent activity from human activity in your own logs, you have lost the ability to investigate an incident — and HIPAA's unique user identification requirement at 45 CFR §164.312(a)(2)(i) is a required implementation specification, not an addressable one.
The trajectory may change. ASTP/ONC's HTI-5 proposed rule retains §170.315(g)(10) and states an aim to move beyond read-only interactions in future API requirements, and it proposes removing the “third party seeking modification use” condition from the information-blocking Infeasibility exception — the condition developers have used to limit write access. As of 12 August 2026 it remains a proposed rule with no final action located. Write access is on the federal agenda. It is not a right today, and no architecture should be built on the assumption that it will be one by the time you go live.
Registration and Discharge: The Two Volume Workflows
If you automate two things in an urgent care centre, automate the front door and the back door. Registration and discharge are where the labour is, where the variance hits hardest, and where the compliance surface is thinnest. Everything in between — the clinical encounter itself — is not yours to automate and should not be on the roadmap.
Registration: move the work before the door
The registration problem in urgent care is that it is first-time data capture on an unknown patient, performed at the moment the clinic is busiest, by the person who is also answering the phone and taking payment. Nothing about that ordering is necessary. Online check-in already diverts some arrivals into a pseudo-schedule; the automation opportunity is to make that diversion carry real work rather than just a place in line.
- Structured capture, not free text: Demographics, reason for visit, guarantor, employer (which routes occ med correctly from the first keystroke), and insurance card images captured and parsed before arrival.
- Eligibility before the patient is standing there: A 270/271 eligibility transaction fired on the submitted coverage, with the response and any discrepancy surfaced to the front desk as a short exception list rather than a full record.
- Consent and financial policy delivered and logged: The artifact and its timestamp are the deliverable. An agent that collects consent but cannot evidence when and how it was collected has produced nothing you can defend.
- Duplicate detection before the chart is created: Walk-in populations generate duplicates at a rate scheduled practices do not see. Matching on read-only data before any write is proposed prevents the most expensive registration error there is.
- An explicit exception queue: Coverage not found, name mismatch, minor without a guardian, workers' comp claim number missing. These route to a human by design, and the size of that queue is your real automation rate.
Note what is missing from that list: any promise that the chart gets created automatically. Creating the encounter is a write, and whether it is available to you is a question for your EHR vendor, not for the agent vendor. Design the registration agent so that its output is a complete, validated packet that a human commits in seconds — and if a write path turns out to be available, committing it becomes a configuration change rather than a re-architecture.
Discharge: the workflow with the clearest payback and the sharpest edges
Discharge in urgent care is a delivery problem wrapped around a clinical artifact. The clinician decides what the instructions say. Everything after that — rendering them in the patient's language, delivering them on the channel the patient can actually receive, confirming receipt, scheduling nothing but pointing at the right follow-up resource, and queuing the result callback for the culture that has not returned yet — is administrative work an agent can carry.
The sharp edges are three. First, the content is clinical, so in California a generative-AI-authored communication pertaining to patient clinical information falls under AB 3030 unless a licensed human read and reviewed it — and the human-review exemption is written into the statute precisely so that a reviewed message needs no disclaimer. Second, the delivery channel is regulated: an outbound text or automated call is a TCPA event, not a courtesy. Third, the follow-up loop is where urgent care differs from primary care most starkly — you are calling a patient who has no relationship with you, may not recognise your number, and has no incentive to call back. An agent that fires one message and marks the task complete has automated the appearance of a callback, not the callback.
One further constraint that urgent care hits harder than most outpatient settings: 42 CFR Part 2. The restriction triggers on records that would identify a patient as having or having had a substance use disorder, not on clinical content. An agent that emits an appointment confirmation, an eligibility check, a fax cover sheet or a portal message that names the patient and identifies a federally assisted substance use disorder programme can constitute a Part 2 disclosure even though nothing clinical left the building. HIPAA has no analogous rule about the mere fact of association. If your centre has any programme that could be in scope, that determination belongs in the design phase, not in the incident review.
Queue, Door-to-Door Time and Wait Communication
Wait communication is the most attractive and most misunderstood automation in urgent care. It looks like a messaging problem. It is actually three problems stacked: a forecasting problem (what is the wait), a legal problem (may we send this), and a clinical-governance problem (who decides the order of the queue). Getting any one of them wrong turns a nice patient-experience feature into an operational liability.
1. The estimate is a model output, so treat it like one
A wait estimate is a prediction, and predictions have error distributions. Publish ranges rather than point values, state the refresh cadence explicitly, and — this is the part almost nobody builds — log every estimate you send alongside the actual door-to-door time that followed. Review the gap weekly for the first quarter. If your estimates are systematically optimistic, you are manufacturing walkouts and one-star reviews with an automation you paid for. If they are systematically pessimistic, you are turning away revenue.
The estimate model is also the piece most sensitive to seasonality. A model fitted in May behaves differently in respiratory season, when arrival rate, acuity mix and staffing all move at once. Plan an explicit re-baselining before your first winter, and give it an owner.
2. Every outbound message is a TCPA event
The FCC confirmed in Declaratory Ruling FCC 24-17 (released 8 February 2024) that the TCPA's restrictions on artificial or prerecorded voice encompass current AI technologies that resemble human voices, including voice cloning, and that callers must obtain the prior express consent of the called party absent an emergency purpose or a regulatory exemption. Twenty-six state attorneys general supported the interpretation and may enforce it.
The exposure is not theoretical. 47 U.S.C. §227(b)(3) creates a private right of action for actual damages or $500 per violation, whichever is greater, trebled to $1,500 per violation for willful or knowing violations. There is no cap and no injury requirement, and each call and each text is a separate violation. An outbound campaign to five thousand patients without valid consent is $2.5 million at the base rate.
- Wireless numbers are not exempt: Under 47 C.F.R. §64.1200(a)(2) a health care message from a HIPAA covered entity or its business associate needs prior express consent — not prior express written consent, but not nothing. "We are a clinic, the TCPA does not apply" is the most expensive wrong belief in this category.
- Residential landlines have a volume cap: §64.1200(a)(3)(v) exempts health care messages from the consent requirement but caps them at one call per day per patient and three per week, with opt-outs still honored.
- Emergency purposes will not cover you: §64.1200(f) covers calls made necessary in a situation affecting the health and safety of consumers. A wait-time update is not that.
- Marketing is outside the carve-out entirely: Anything that introduces an advertisement or constitutes telemarketing needs prior express written consent, healthcare or not. Occ med business development messaging to an employer contact list is the trap here.
- Caller identity disclosure is already law: §227(d)(3) and 47 C.F.R. §64.1200(b) require an artificial or prerecorded voice message to state clearly at the beginning the identity of the business responsible, provide a telephone number, and release the line within five seconds of hang-up.
- Revocation must be honored within 10 business days: STOP, QUIT, END, REVOKE, OPT OUT, CANCEL and UNSUBSCRIBE are per se reasonable revocation methods. The broader "revoke-all" provision — one revocation killing all automated contact from the caller — was extended again by the FCC's Consumer and Governmental Affairs Bureau on January 6, 2026 (DA 26-12) to January 31, 2027. Build for it now anyway.
One more channel-level constraint that catches national deployments: recording. A voice agent that records or transcribes patient calls is doing exactly what all-party consent statutes cover, in every state at once, from a single deployment. California Penal Code §632.7 makes it an offense to intentionally record a communication involving a cellular or cordless telephone without the consent of all parties, with a first-offense fine up to $2,500 and up to $10,000 for repeat offenses. Roughly a dozen states are commonly described as all-party consent jurisdictions, but the only consolidated lists we located were search-optimised content properties rather than legal sources — so verify your own state and any state you take calls from, and do not rely on a list from a vendor. Play the notice before anything is captured, capture affirmative assent, and log it.
3. Ordering the queue is triage, and triage is not administrative
There is a strong temptation to let the system reorder the waiting room. Resist it, for two independent reasons.
The first is FDA's clinical decision support analysis. Software for administrative support of a health care facility is excluded from the device definition by statute at 21 U.S.C. §360j(o)(1)(A) — scheduling, claims and billing handling, eligibility determination, practice management, population lists. Once software recommends about prevention, diagnosis or treatment, it sits in §360j(o)(1)(E) and must clear four statutory criteria. FDA stated at its 11 March 2026 town hall that in determining whether a function meets Criterion 4 it considers both the level of automation and the time-critical nature of the clinician's decision making, because “in situations that require urgent action, automation bias increases because there is not sufficient time for the user to adequately consider other information.” That is a consideration in FDA's analysis rather than a test that settles the question — but urgent care is, definitionally, the time-pressured setting it describes. A recommendation surfaced inside a thirty-second decision is in a worse posture than the same recommendation surfaced in an asynchronous inbox.
The second reason is a rule that is already binding and is usually missed. 45 CFR §92.210 prohibits discrimination through the use of patient care decision support tools, and imposes an ongoing duty to make reasonable efforts to identify uses of such tools that employ input variables measuring race, color, national origin, sex, age or disability, and to make reasonable efforts to mitigate the resulting risk. It applies whether or not the tool is AI and whether or not FDA calls it a device. A queue-ordering algorithm is squarely within it. If you build one, you own an inventory-and-mitigation obligation you probably did not budget for.
The defensible design is narrow and useful: the agent surfaces facts about the queue — who has been waiting longest, whose registration is incomplete, which rooms are turning over, which patients have unacknowledged results pending — and a licensed human decides who goes back. That is administrative support in the statutory sense, and it captures most of the operational value.
Occupational Medicine: The Book Nobody Automates
Occupational medicine is the exception inside the exception. Everything else in urgent care is unscheduled; employer physicals are scheduled, and they are the predictable revenue that stabilises the rest of the week. The book is invoiced directly to employers with no claim, no payer and no denial. It is frequently the most profitable part of the centre, and essentially no clinical software models it — which is why most centres run it on spreadsheets, email and the memory of one long-tenured coordinator.
That combination — high margin, high predictability, low software coverage — makes occ med the most under-rated automation target in this entire cluster. The work is list management, document assembly and invoicing, none of which requires a clinical judgement and most of which never touches the EHR at all.
| Occ med workflow | Bucket | What an agent can carry |
|---|---|---|
| Employer panel tracking | Read-and-reason | Which employees are due for which screen, under which contract, at which contracted price; who is overdue; which panel components are incomplete. |
| Scheduling employer physicals | Vendor-discretionary write (or a standalone scheduler) | Proposing slots and assembling the pre-visit packet; committing the booking depends on your write path. |
| Document assembly for an employer file | Read-and-reason | Collecting the completed components, flagging what is missing before the file goes out, and drafting the transmittal. |
| Employer invoicing | Outside the health-IT rail | Generating the invoice against the contracted rate table, reconciling it to services delivered, and chasing it — this is accounts receivable, not revenue cycle. |
| DOT examination result submission | Outside the health-IT rail, and credentialed | Nothing. This is performed by the certified medical examiner on FMCSA's system under their own credential. |
| Drug screen chain of custody | Outside the health-IT rail | Status tracking and exception surfacing only; the custody artifacts themselves are governed by the laboratory's process. |
DOT medical examinations: the hard rules, verbatim from the regulation
49 CFR §391.43 is unusually specific, and every clause of it constrains what software may do.
- Who may examine: The examination must be performed by a medical examiner listed on the National Registry of Certified Medical Examiners. A licensed ophthalmologist or optometrist may perform only the vision portion; a certified VA medical examiner may examine only veteran operators.
- Next-day electronic reporting: Beginning June 22, 2018, by midnight local time of the next calendar day after the examiner completes an examination, the examiner must electronically transmit the results to FMCSA via the National Registry.
- The monthly zero report: If the examiner performs no examinations in a calendar month, that fact must be reported by the close of business on the last day of that month. This is the obligation most commonly missed, and it is exactly the kind of calendar-derived reminder an agent should own.
- Three-year retention: Each completed Medical Examination Report and a copy of each certificate must be retained on file at the medical examiner's office for at least three years from the date of examination, available to FMCSA on request.
- The 45-day pending clock: If further information is needed, the examinee must be told it is due within 45 days, and the pending status is reported to FMCSA.
- The forms: The certificate is Form MCSA-5876; the results form is MCSA-5850.
The design conclusion is clean. An agent may watch the clocks — next-day transmission, monthly zero report, 45-day pending, three-year retention — and escalate before each one expires. It may assemble the file and check its completeness. It may not perform the submission, because the submission is an act by a named credentialed individual on a federal system that has no interoperable rail into your EHR.
A note on employer communications and the TCPA, because occ med invites the mistake. Messaging an employer's HR contact about renewals, new service lines or panel pricing is business development. If it introduces an advertisement or constitutes telemarketing it needs prior express written consent, and no healthcare carve-out applies. Keep the occ med outreach list, the clinical patient list and the marketing list in three separate systems with three separate consent states, and make the separation architectural rather than procedural.
The Contract-Mix Problem (Not the Payer-Mix Problem)
Urgent care runs three fundamentally different revenue systems in one building, and any automation that assumes a single claims rail will silently mishandle two of them.
- 1.Commercial and Medicaid claims: At S-code or evaluation-and-management rates the centre often does not control, adjudicated on the standard X12 rails, with denials and appeals.
- 2.Self-pay at posted prices: A retail transaction with a price list, collected at the point of service, with no payer and no adjudication — and with price-transparency expectations attached.
- 3.Employer contracts: Invoiced directly, no claim, no payer, no denial, no remittance advice. This is accounts receivable in the ordinary commercial sense and it does not belong in your revenue cycle tooling at all.
The billing constructs on the claims side deserve care, and we mark our confidence honestly. Coding publishers describe HCPCS S9083 as a global fee for urgent care centres and S9088 as an add-on for services provided in an urgent care centre, with place of service 20 identifying an urgent care facility. S-codes are not recognised by Medicare, which pays the evaluation and management service. Some commercial and Medicaid plans require S9083 instead of the E/M, contractually converting a level-based visit into a flat fee; others reject both as informational and want itemised CPT/HCPCS coding. We were unable to fetch a named payer's policy document to confirm any specific plan's position, so treat all of the above as the shape of the problem and verify it against your own contracts.
Two more structural notes. First, prior authorisation is a small part of urgent care compared with the specialties in this cluster, so the CMS-0057-F story is mostly background here: its obligations bind payers rather than practices, the FHIR prior-authorisation APIs are a 1 January 2027 obligation, and what is live in 2026 is decision timeframes, specific denial reasons and public metric reporting. Your relationship to that rule is as the recipient of a denial reason and, from 2027, as a potential consumer of a payer's API. Second, eligibility at the point of service is the highest-leverage claims-side automation you have, precisely because there is no pre-visit window — and it is a read transaction, which puts it in the easiest bucket.
How electronic is the rail you are automating onto?
The industry index most often cited on this question reports that roughly 40% of prior authorizations were fully electronic in its 2024 transaction data, and puts the remaining industry-wide savings opportunity from full electronic adoption at about $21 billion. Claims and eligibility transactions are already almost entirely electronic; attachments are not.
Two disclosures belong with those figures every time they are used. First, the organisation publishing the index converted from nonprofit to for-profit in January 2026 and is owned by shareholder companies affiliated with health plans; it rebranded from CAQH to DataSpring on 8 June 2026. It is an industry benchmark, not an independent one. Second, the only figure we confirmed on the organisation's own page is the $21 billion; the rest is search-summarised. For an urgent care centre the practical reading is narrow and useful: eligibility is a mature electronic transaction you can automate against with confidence, and document-shaped exchange is not.
One risk worth naming because it sits under all three revenue systems at once: concentration in the clearinghouse layer. The February 2024 Change Healthcare cyberattack ultimately affected a reported 192.7 million individuals, a figure UnitedHealth revised upward from earlier interim counts, and it disrupted claims submission across the industry for weeks. When you design an urgent care automation stack, ask what happens to registration, eligibility and charge capture if a single upstream vendor is unavailable for a fortnight — and make sure the answer is a documented manual path that staff have actually rehearsed.
The Human-in-the-Loop Boundary
Every implementation needs this table written down, agreed by the medical director and the administrator, and enforced in configuration rather than in training. The principle is simple: clinical judgement, billing attestation and anything with legal or safety consequence stays human. The value of writing it down is that it converts an argument into a setting.
| Action | Boundary | Authority or reason |
|---|---|---|
| Capture registration data, verify eligibility, move claims data, manage inventory, build worklists | Agent may act alone | 21 U.S.C. §360j(o)(1)(A) excludes administrative support of a health care facility from the device definition outright. |
| Send an appointment or wait-time update on an administrative matter | Agent may act alone, within consent | California AB 3030 expressly excludes administrative matters including scheduling and billing from its definition of patient clinical information. TCPA consent still governs the channel. |
| Draft a discharge instruction, a result-callback message or any patient communication about clinical information | Human review before send | AB 3030 requires a GenAI disclaimer and human-contact instructions unless a licensed human read and reviewed the communication first. |
| Order the waiting-room queue by acuity | Never automated | This is triage. FDA weighs automation level and time-criticality under Criterion 4, and 45 CFR §92.210 imposes an identify-and-mitigate duty on patient care decision support tools. |
| Recommend a level of care, a disposition or a treatment | Never automated | A specific preventive, diagnostic or treatment output or directive fails FDA's Criterion 3; enforcement discretion is a revocable posture, not an exclusion, and never a clearance. |
| Perform work billed 'incident to' a physician's service | No pathway exists | 42 CFR §410.26(a)(1) defines auxiliary personnel as an individual meeting state licensure. Software is not an individual and cannot be licensed. |
| Sign or attest to a medical record entry | Never — non-delegable | CMS Program Integrity Manual Ch.3 §3.3.2.4 requires practitioner concurrence when AI technology captures the transcription of medical record entries, and refuses attestations from anyone but the entry's author. |
| Release records, move money, or place an order | Out-of-band human confirmation | Irreversible actions need a confirmation step outside the agent's own channel. This is design reasoning, not a cited rule — label it as such internally. |
| Adopt a clinical-sounding name or persona | Prohibited in California | AB 489 makes each use of a term implying a health care license by an AI system a separate violation, with licensing board jurisdiction. Naming your intake agent after a clinical role is a per-use violation there. |
Two disclosure obligations are worth restating for urgent care specifically, because the setting interacts with them. Texas HB 149 §552.051(f), in force since 1 January 2026, requires that where an artificial intelligence system is used in relation to a health care service or treatment, the provider disclose to the recipient or their personal representative not later than the date the service is first provided — except in an emergency, where disclosure follows as soon as reasonably possible. Urgent care is the setting most likely to rely on that emergency clause, and least likely to have a documented process for the after-the-fact disclosure it requires. Build the process.
Texas SB 1188 (Health & Safety Code §183.005), in force since 1 September 2025, is the clearest statutory statement in the country of where liability sits. A practitioner may use AI for diagnostic purposes if the practitioner acts within the scope of their license “regardless of the use of artificial intelligence”, the use is not otherwise restricted by law, and the practitioner reviews all records created with AI consistent with Texas Medical Board standards — and must disclose the use to patients. Five words carry the whole doctrine: the license, and therefore the liability, does not move.
The HIPAA mechanics that apply to an agent, specifically
Four provisions do most of the work, and none of them is new. A model provider processing PHI is a business associate under 45 CFR §160.103, and so is the agent-framework vendor in front of it, and so is that provider's own cloud host — as a subcontractor business associate requiring a downstream agreement. A single BAA with the application vendor does not close the chain. §164.502(a)(3) then limits a business associate to uses its contract permits and forbids uses the covered entity itself could not make, which is the clause a “we train on your data” term collides with.
Minimum necessary under §164.502(b) applies to what an agent assembles into its context, and the treatment exception at §164.502(b)(2)(i) does not cover a registration, eligibility, billing or reporting workflow — so “dump the whole chart into the context window” is precisely the practice the rule reaches. Finally, §164.312(a)(1) already frames access rights as attaching to persons or software programs, §164.312(a)(2)(i) makes unique user identification a required specification, and §164.312(b) requires audit controls. Read together: an agent needs its own identity, not a borrowed clinician login, and a shared service account that makes agent actions indistinguishable from a human's is the compliance failure to name in your own design review.
The Sequenced Implementation Path
What follows is the order we build in, with an owner per phase, an entry criterion, an exit criterion, and what to do when a phase fails. Phases are independently cancellable by design. If you cannot name the owner, the phase is not ready to start.
Five people need to be in the room before Phase 0 starts, and the absence of any one of them is the most reliable predictor of a stalled implementation: the practice administrator who owns the schedule and the budget, the medical director who signs the human-in-the-loop boundary, the front-office manager who will live with the exception queue, the billing manager who owns the contract rule table, and the occupational medicine coordinator whose book is usually the most valuable and least documented part of the operation. In a multi-site group, add whoever owns telephony — because consent state, call recording notices and revocation handling all live in that system rather than in the EHR.
| Phase | Weeks | Owner | Exit criterion |
|---|---|---|---|
| 0 — Baseline and boundary | 1–3 | Practice administrator, with the medical director signing the boundary table | A measured baseline and a signed human-in-the-loop table exist on paper. |
| 1 — Write-path determination | 2–4 (overlaps 0) | Practice administrator + IT lead | Written answer from the EHR vendor on which resources a third party may create or update, and by what mechanism. |
| 2 — Pre-arrival registration agent | 4–9 | Front-office manager | 80% of online check-ins produce a complete validated packet; exception queue is stable and staffed. |
| 3 — Discharge and result-callback delivery | 3–6 | Clinical operations lead + medical director | Every clinical-content message is human-reviewed before send; delivery and receipt are logged. |
| 4 — Occ med panel and clock tracking | 4–8 | Occupational medicine coordinator | Zero missed FMCSA next-day or monthly-zero deadlines over a full month; invoice reconciliation matches services delivered. |
| 5 — Wait estimate and queue visibility | 4–8 | Clinic manager | Estimate error distribution measured against actual door-to-door time for 4 consecutive weeks; no queue reordering by software. |
| 6 — Steady state and re-baselining | Ongoing | Named retainer owner | Quarterly review of drift, consent state, contract rule table and estimate calibration. |
Phase 0 — Baseline and boundary (weeks 1–3)
Entry criterion: an executive sponsor exists and has budget authority. Owner: practice administrator, with the medical director co-signing the boundary table.
- 1.Measure door-to-door time from your own timestamps: Arrival, registration complete, roomed, provider contact, discharge, departure. Distribution, not average — the tail is the business problem. Owner: clinic manager.
- 2.Pull 60–90 days of call detail records: Total inbound, answered, abandoned, speed to answer, after-hours volume, repeat callers within 24 hours. Owner: IT lead.
- 3.Inventory the three revenue systems: Claims by contract, self-pay volume at posted prices, and the occ med book by employer. Most centres discover the occ med number is bigger than they thought. Owner: billing manager.
- 4.Write and sign the human-in-the-loop boundary table: Use the table above as a starting point and adapt it. The medical director signs it. Owner: administrator.
- 5.Inventory patient care decision support tools already in use: 45 CFR §92.210 imposes an ongoing identify-and-mitigate duty that exists whether or not you buy anything new. Owner: compliance officer.
Exit criterion: a written baseline document and a signed boundary table. If the phase fails — usually because the timestamp data does not exist or is unreliable — stop. Do not proceed to a build. Fix the measurement first; without a baseline you cannot detect regression later, and you will be arguing about outcomes with anecdotes.
Phase 1 — Write-path determination (weeks 2–4)
Entry criterion: Phase 0 baseline underway. Owner: practice administrator with the IT lead.
Send the written question from the write-path section above to your EHR and practice management vendors. Ask the same question of any agent vendor you are evaluating, and compare the two answers — the mismatch between what a vendor claims it can write and what the EHR says it permits is the single most predictive signal in the whole evaluation. Also ask each vendor, in writing, whether they will sign a business associate agreement covering the specific service and its subcontractors, because not one vendor in this category publicly states that it offers one.
Exit criterion: a written answer naming the mechanism (certified API, proprietary API, HL7 interface, RPA, or human) for every intended write. If the phase fails — no answer, or an answer that amounts to “we make it work” — re-scope every downstream phase to draft-and-human-commit. That is a smaller build, it is cheaper, and it is often the right permanent answer.
Phase 2 — Pre-arrival registration agent (weeks 4–9)
Entry criterion: write path known; online check-in exists or is being built in this phase. Owner: front-office manager.
- 1.Structured pre-arrival capture: Demographics, employer, guarantor, reason for visit, insurance card capture. Deliberately include employer — it is what routes occ med correctly from the first keystroke.
- 2.Real-time eligibility on submission: 270/271 against the submitted coverage, with the response reduced to an exception list rather than a data dump. Minimum necessary applies: an eligibility workflow is not a treatment disclosure and gets no exception under 45 CFR §164.502(b).
- 3.Duplicate detection before any write is proposed: Match on read-only data. A duplicate chart created at 6pm on a Friday costs more to unwind than the entire week's automation saved.
- 4.Consent and financial policy delivery with a logged artifact: The timestamp and delivery evidence are the deliverable, not the consent text.
- 5.Commit step, sized to the write path: Either a human commits a validated packet in seconds, or a vendor-approved write API commits it with a reconciliation job behind it. Never RPA without reconciliation.
Exit criterion: 80% of online check-ins produce a complete validated packet requiring no rework, the exception queue has a stable size and a named staffer, and registration-related door-to-door time has not regressed against the Phase 0 baseline. If the phase fails, the usual cause is that the exception queue is larger than the labour saved. Narrow the scope to the highest-volume payer and the single most common visit reason, re-measure, and expand only from a working core.
Phase 3 — Discharge and result-callback delivery (weeks 3–6, can run parallel to 2)
Entry criterion: the medical director has approved the review workflow. Owner: clinical operations lead, with the medical director owning content approval.
Build the delivery rail first and the drafting second. Channel selection, consent state, language handling, delivery confirmation and the retry ladder are all administrative and can be validated with templated content before any generative drafting is switched on. When drafting is added, every clinical-content message passes a licensed reviewer before send — which is both the AB 3030 exemption and the only defensible control given what the prompt-injection literature says about non-obvious manipulations.
Exit criterion: 100% of clinical-content messages carry a reviewer identity and timestamp; delivery and receipt are logged; the result-callback worklist closes with a documented outcome per item rather than a send event. If the phase fails — reviewers rubber-stamping, evidenced by review times that are implausibly short — pause drafting, revert to templates, and redesign the review step. A reviewer accepting everything in under a second has documented the absence of review, not its presence, and your own telemetry will say so.
Phase 4 — Occupational medicine panel and clock tracking (weeks 4–8)
Entry criterion: the employer contract rate table has been extracted into a maintained structured form. Owner: occupational medicine coordinator.
- 1.Contract and panel model: Employer, contract, panel composition, contracted price per component, cadence. This is the artifact the whole phase depends on and it usually does not exist yet.
- 2.Due and overdue lists: Which employees are due for which screen, per contract, with lead time.
- 3.Regulatory clock watching: FMCSA next-calendar-day transmission, the monthly zero report, the 45-day pending clock, and three-year retention. The agent escalates; the certified examiner acts.
- 4.File completeness checks before transmittal: Read-and-reason over what has been collected against what the contract requires.
- 5.Invoice generation and reconciliation: Against the rate table and services actually delivered, with a variance report a human signs off.
Exit criterion: a full calendar month with zero missed FMCSA deadlines and an invoice variance report reconciling to services delivered. If the phase fails, it will be because the contract rate table was wrong. Go back to the contracts, not to the software.
Phase 5 — Wait estimate and queue visibility (weeks 4–8)
Entry criterion: at least one full quarter of clean Phase 0 timestamps. Owner: clinic manager.
Publish estimates as ranges, internally first. Run in shadow mode — computing and logging estimates without showing them to patients — for a minimum of four weeks, and only expose them externally once the error distribution is known and acceptable to the operator who will answer for it. Under no circumstances does this phase include software reordering the queue.
Exit criterion: four consecutive weeks of measured estimate error against actual door-to-door time, reviewed and accepted. If the phase fails — error too wide, or systematically optimistic — keep the estimate internal as a staffing signal. An internal estimate that helps the charge nurse is worth having even when it is not good enough to publish.
Phase 6 — Steady state and re-baselining (ongoing)
Owner: whoever holds the retainer, named in the contract. Quarterly: review estimate calibration; re-verify the contract rule table against renegotiated agreements; audit consent state and revocation handling; re-run the §92.210 inventory; confirm that the write path has not changed under you after an EHR upgrade; and re-check the state law positions, which have been moving faster than annual review cycles accommodate.
What Breaks First, How You Detect It, How You Roll Back
These are the failure modes specific to a walk-in centre, in roughly the order we see them appear. Each one needs a detection signal that is measured automatically and a rollback that someone has rehearsed. A rollback that exists only as a paragraph in a runbook is not a rollback.
| Failure mode | Detection signal | Rollback |
|---|---|---|
| Silent write-path breakage (RPA broken by a UI change) | Hourly reconciliation job comparing agent-asserted writes against what the chart actually holds; alert on any mismatch above threshold. The reconciliation must not run inside the system performing the write. | Disable the write, fail over to the human commit path, and re-run the day's packets manually. Keep a staffed manual path warm for the first 90 days. |
| Exception queue outgrows the labour saved | Daily exception count and median time-to-clear, trended against the Phase 0 registration baseline. | Narrow the agent's scope to the highest-volume payer and visit reason. Re-expand only after two stable weeks. |
| Wait estimates drift optimistic in a demand surge | Rolling comparison of estimate versus actual door-to-door time, segmented by hour and day; walkout rate as a secondary signal. | Widen the published range, then revert to internal-only estimates. Do not tune the model during a surge. |
| Consent state diverges from the messaging system | Daily reconciliation of opt-outs across every outbound channel; any revocation older than 10 business days still receiving messages is a P1. | Suspend all automated outbound on the affected channel until reconciled. TCPA exposure accrues per message. |
| Reviewer rubber-stamping on clinical-content messages | Per-message review dwell time and override rate. Implausibly short reviews with near-100% acceptance is the pattern. | Revert to templated content, retrain, redesign the review UI so the reviewer must interact with the substance. |
| Untrusted input reaches an agent with privileges (fax, portal message, outside record) | Anomaly detection on agent actions that deviate from the workflow's expected action set; unique agent identity in the audit log so actions are attributable. | Revoke the agent's credentials, quarantine the ingest channel, reconstruct from audit logs. Reduce privileges before restoring service. |
| Part 2 exposure through a routine administrative artifact | Pre-send scan for any outbound artifact that names a patient and identifies a program in scope; sampling audit of sent items. | Halt the affected message class, review with counsel, and re-scope the agent's sending permissions by program. |
| Occ med clock missed (FMCSA next-day or monthly zero report) | A calendar-derived alert that escalates before the deadline, not a report that notices afterward. | Manual submission by the certified examiner, plus a written cause analysis. This clock has a regulator attached to it. |
| Contract rule table goes stale after a renegotiation | Quarterly diff of the rule table against executed contracts; variance alerts on expected-versus-actual reimbursement by contract. | Freeze charge-side logic to human review until the table is corrected. Never let a model infer contract terms from historical claims. |
| Upstream vendor outage (clearinghouse, eligibility, telephony) | Synthetic transaction monitoring per dependency, with a status page that staff can see from the front desk. | Documented manual path per dependency, rehearsed at least twice a year. The 2024 Change Healthcare disruption is the reason this line exists. |
Cost, Timeline and Honest Payback Math
These are our figures, published so that you can compare them with anything else you are quoted. They are the same across every article in this cluster.
| Engagement | Range | Timeline |
|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks |
| Single-workflow agent (registration, discharge delivery, occ med tracking) | $28k–$70k | 4–9 weeks |
| Multi-workflow platform with EHR/PM integration | $70k–$180k | 9–16 weeks |
| Enterprise / multi-site / regulated build (audit logging, HITL, SOC 2 posture) | $180k–$420k+ | 14–24 weeks |
Senior-led at $150–$225/hr. Retainers from $2,500–$9,500/month covering monitoring, revalidation, re-baselining and incident response. A 30-day post-launch warranty on every engagement. A written fixed-price phased proposal within 5 business days of the discovery call. Full source-code and IP ownership transfers to you at delivery.
On payback: build the model from labour hours you can observe, not from a benchmark. Count the minutes your own staff spend on registration per patient, multiply by your own volume, apply your own loaded wage, and discount heavily for the exception queue — because the exception queue is real work that does not disappear. Then subtract the ongoing cost honestly: platform fees, integration fees, per-transaction charges where they exist, and the retainer. What is left is your payback, and it will be less dramatic than any vendor deck and more durable than any of them.
One economy-wide figure deserves specific treatment because it is used constantly in this category: the roughly one trillion dollars a year attributed to US healthcare administrative work. It traces to real academic work on administrative spending as a share of national health expenditure — but that spending sits overwhelmingly inside insurers and hospital systems. It is not an addressable market for a six-provider urgent care centre, and any vendor presenting it as your opportunity is making a category error you should name out loud in the meeting.
Limitations: What We Could Not Verify
This section is the point of the article. Everything above rests on sources we fetched; here is what we could not, stated plainly so you can weigh it.
- No independent benchmark exists for administrative AI agents: We searched for randomized, peer-reviewed or third-party evaluations of multi-step administrative agents in medical practices and located none as of August 12, 2026. Every accuracy, automation-rate, containment and resolution figure in this market is published by the vendor that benefits from it. Accuracy is therefore excluded from every comparison we make, by design.
- No door-to-door time benchmark could be verified at source: Industry benchmarking data sits behind association membership; every public citation resolved to vendor content. We name the metric and refuse the number.
- Urgent care S-code payer policies: The S9083/S9088 and place-of-service 20 constructs come from coding publishers and payer-policy summaries. We were not able to fetch a named payer's policy PDF to confirm any specific plan's position. Verify against your own contracts.
- The read-only characterization rests on ONC/ASTP's companion guide: We quote the Certification Companion Guide for §170.315(g)(10), updated May 15, 2026, directly. We did not separately parse the regulatory text of the criterion itself. Nothing we found contradicts the characterization.
- Colorado's enforcement pause, as distinct from its statute: Two wrong versions of Colorado circulate and we refuse both. The statute is settled: SB 24-205 did take effect — its start date was pushed from February 1 to June 30, 2026 — and SB 26-189, signed May 14, 2026, repeals and reenacts it effective January 1, 2027 under the enrolled bill's SECTION 5. SB 26-189 carries a safety clause at SECTION 6, so the August 12, 2026 date on the legislature's site, a banner covering bills passed without one, does not apply to it. What we could not verify at source is the enforcement posture: on April 27, 2026 a federal court is reported to have granted a joint motion in which the Attorney General stated he does not intend to enforce SB 24-205 until rulemaking concludes. We did not fetch that order and we name no case. For a walk-in centre the operative point is the carve-out — HIPAA covered entities are excluded from the core sections from January 1, 2027, except for consequential decisions about employment, which is the part an urgent care group hiring at scale should actually read.
- Whether any vendor in this category signs a BAA: Not one vendor we reviewed publicly states that it offers a business associate agreement. That is a finding, not an accusation. Ask in writing and keep the answer.
- Vendor security posture: Absence of a security page at a conventional URL is a discoverability finding, not proof a vendor publishes nothing — at least one vendor we checked publishes its SOC 2 Type II on a blog post rather than a trust page. Site-search the vendor's own domain before drawing a conclusion, and never publish an absolute compliance negative about a named company.
- Pricing: We located no published price for any agent platform sold into medical practices. In the adjacent patient-communication category exactly one vendor publishes a starting price. Everything else is contact-sales, and we will not estimate.
- Prompt injection outside the studied channels: The peer-reviewed literature covers patient dialogue and medical imaging. We found no published study of prompt injection via patient portal messages, referral faxes or payer portals in a live practice. Extrapolating to those channels is analysis, not evidence, and we have labelled it as such.
- FDA said nothing new about generative AI: The 2026 CDS guidance addresses neither AI specifically nor patient-facing tools. Do not read it as FDA blessing generative AI in clinical workflows, and do not let a vendor read it that way either. Enforcement discretion is a revocable posture, not a clearance.
- The HIPAA Security Rule NPRM is still only proposed: Published January 6, 2025; the Unified Agenda entry for RIN 0945-AA22 places it in long-term actions with final action projected July 2027. The 2003 Security Rule as amended in 2013 governs today, which means encryption at rest is still addressable rather than required — a fact much of the market writes as though it has already changed.
Red Flags When Buying
Each row pairs the signal with why it matters. None of these requires technical expertise to check — they are questions an administrator can ask in a first call.
| Red flag | Why it matters |
|---|---|
| A published accuracy, containment or resolution rate presented as neutral | No independent benchmark exists in this category. A rate with no denominator, no defined comparator and no third-party auditor is a marketing input, not a measurement. |
| Cannot say which mechanism performs each EHR write | Certified API access is read-only. If they will not distinguish API from HL7 from RPA in writing, you are accepting an undisclosed dependency that can break silently. |
| RPA running under a named staff member's credentials | Agent actions become indistinguishable from human actions in your audit trail, which defeats HIPAA's required unique user identification and your ability to investigate anything. |
| 'HIPAA-compliant AI' offered as a product property | HIPAA attaches duties to covered entities and business associates, not to software. The meaningful sentence is 'used under a BAA with these specific controls', and there is no OCR guidance defining a compliant AI product. |
| Will not commit in writing to signing a BAA covering subcontractors | The model provider's own cloud host is a subcontractor business associate. A single BAA with the app vendor does not close the chain. |
| Vague or absent terms on training and retention of your data | A business associate may use PHI only as its contract permits, and may not use it in a way the covered entity itself could not. That clause is exactly what a 'we improve our models with your data' term collides with. |
| Sells symptom triage or level-of-care recommendation into a walk-in setting | A specific diagnostic or treatment directive fails FDA's Criterion 3, and time-critical, highly automated workflows are the hardest place to argue a clinician independently reviewed the basis for a recommendation. |
| Proposes an agent that orders the waiting room | Queue prioritization is a patient care decision support tool under 45 CFR §92.210, with an ongoing identify-and-mitigate duty attached, and it is triage. |
| Quotes an industry door-to-door or phone-abandonment benchmark | Neither is verifiable at source. A vendor quoting one is either not checking or is counting on you not to. |
| Claims a guardrail or injection-detection effectiveness rate | No independent benchmark for clinical prompt-injection defense exists. Every figure we found traced to a security or AI vendor. |
| Cannot report repeat contact within 72 hours | Deflection is not resolution. If the only metric is calls handled, you cannot tell a solved problem from a deferred one. |
| A roll-up owner with overlapping product lines | Product consolidation risk is real and it is a cap-table risk rather than a technology risk. At least one prior-auth and RCM automation product in this market was withdrawn from standalone sale for portfolio reasons after an acquisition, with customers given a short migration window. |
| Names your agent something that implies a clinical license | In California each such use is a separate violation under AB 489, with licensing board jurisdiction and injunctive exposure. |
One more question that reframes the entire evaluation, and it is not about the agent vendor at all: what does your own EHR already ship, when, and at what price? The EHR vendors moved into the agent layer during 2025 and 2026 — Epic demonstrated named agents and previewed a no-code agent-building platform at HIMSS in March 2026; athenahealth launched agentic text and voice patient-communication tools in February 2026 alongside an embedded ambient scribe, which is reported to be delivered through routine updates at no additional cost, though we could not verify that claim from the vendor's own release; eClinicalWorks positions an agentic front-office product alongside its ambient scribe. Two caveats keep this honest: Epic is a health-system EHR that a small independent centre generally cannot buy, and native agents are locked to their EHR by definition. What is genuinely left over for a third party is workflow breadth and multi-system orchestration — phones, faxes, employer portals, payer portals — that the EHR does not touch. That is exactly where urgent care's occupational medicine book and queue communication live.
Working With Frenchy Digital
Frenchy Digital is a senior-led, Black-owned agency in Los Angeles. We build administrative agents for regulated environments, which mostly means we spend the first two weeks arguing you out of the parts that should stay human and the next several building the parts that should not.
- Baseline before build: Every engagement opens with a measured baseline of your own door-to-door distribution, call detail records and revenue-system inventory. If the data to measure it does not exist, fixing that is the first deliverable — and we will tell you if the honest answer is not yet.
- Write-path determination as a gate, not an assumption: We send the EHR question with you and we scope against the written answer. If the answer is read-only, we design draft-and-human-commit and quote the smaller number.
- Senior engineers only: No junior staffing on regulated builds. The person designing your reconciliation job is the person who has built one before.
- Fixed-price phased scope: A written scope and fixed-price phased proposal within 5 business days of the discovery call. Every phase is independently cancellable, with the entry and exit criteria written into the contract.
- Compliance controls ship as deliverables: Unique agent identity, audit logging, reviewer dwell-time capture, reconciliation jobs and the rollback runbook are part of the build, not a later add-on.
- Your counsel decides the legal questions: We build the evidence pipeline and hand over the file. State disclosure obligations, Part 2 scope, recording consent and BAA terms belong to your compliance officer and healthcare counsel.
- Full ownership transfer: Source code, prompts, configurations and infrastructure accounts transfer to your organisation at delivery under clean work-for-hire terms. No lock-in.
- 30-day warranty and optional retainer: Every engagement carries a 30-day post-launch warranty; retainers from $2,500 to $9,500 per month cover monitoring, re-baselining, revalidation and incident response.
Book a discovery call at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601. If all you want is the workflow map and the phase plan, ask for it on the call — we will walk through it whether or not you hire us to build anything.
Map Your Urgent Care Workflows Before You Buy Anything
Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned LA agency. You leave with a written workflow map, a phase plan with owners and exit criteria, and a fixed-price proposal within 5 business days.
Map Your Urgent Care Workflows Before You Buy Anything
Book a free 60-minute discovery call with Frenchy Digital. You leave with a written workflow map, a phase plan with owners and exit criteria, and a fixed-price proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1ONC/ASTP — Certification Companion Guide, §170.315(g)(10) Standardized API for Patient and Population Services (updated 05-15-2026)↗
- 2eCFR — 49 CFR §391.43, Medical examination; certificate of physical examination↗
- 3Cornell LII — 47 U.S.C. §227 (Telephone Consumer Protection Act)↗
- 4Cornell LII — 47 C.F.R. §64.1200 (delivery restrictions, health care message provisions)↗
- 5FCC — Declaratory Ruling FCC 24-17, AI-generated voices under the TCPA (Feb 8, 2024)↗
- 6U.S. Code — 21 U.S.C. §360j(o), software functions excluded from the device definition↗
- 7FDA — Clinical Decision Support Software, final guidance (issued January 29, 2026)↗
- 8FDA — CDS Final Guidance Town Hall transcript (March 11, 2026)↗
- 9CMS — Medicare Program Integrity Manual, Pub. 100-08, Chapter 3 (signature requirements, §3.3.2.4)↗
- 10eCFR — 42 CFR §410.26, services and supplies incident to a physician's professional services↗
- 11eCFR — 45 CFR §164.312, HIPAA Security Rule technical safeguards↗
- 12eCFR — 45 CFR §160.103, definition of business associate↗
- 13eCFR — 45 CFR §92.210, nondiscrimination in the use of patient care decision support tools↗
- 14eCFR — 42 CFR §2.12, confidentiality of substance use disorder patient records↗
- 15California Legislature — AB 3030 (Health & Safety Code §1339.75), GenAI patient communications↗
- 16Texas Legislature — HB 149 (TRAIGA), enrolled text including §552.051(f)↗
- 17Texas Legislature — SB 1188, Health & Safety Code §183.005 (AI in the electronic health record)↗
- 18California Legislature — AB 489, health advice from artificial intelligence↗
- 19Lee RW et al. — Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice, JAMA Netw Open. 2025;8(12):e2549963↗
- 20Clusmann J et al. — Prompt injection attacks on vision language models in oncology, Nat Commun. 2025;16:1239↗
- 21Federal Register — HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025)↗
- 22eCFR — 42 CFR §422.122, Medicare Advantage prior authorization requirements (CMS-0057-F)↗
- 23ASTP/ONC — HTI-5 proposed rule fact sheet (proposed, not final as of August 2026)↗

