Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    Implementation Blueprint
    August 12, 2026
    31 min read

    The Zero-Click Clinic:An AI Agent Blueprint for 2026

    A practice where the default administrative path completes without a human click — and humans are deliberately routed to the exceptions and to every clinical, billing, legal and safety decision. Here is the 90-day build, the order to automate in, what never to automate, a ranked platform table that refuses to score accuracy, and payback math that survives scrutiny.

    AI agents running the administrative workflows of a primary care practice in 2026 — intake, eligibility, documents, authorizations and recall, with humans routed to exceptions
    Read-only
    What certified EHR API access guarantees — every write is vendor-discretionary
    ASTP/ONC §170.315(g)(10) Certification Companion Guide, updated 05-15-2026
    0
    Independent benchmarks of AI agent platforms for medical practices, searched 2026-08-12
    Frenchy Digital vendor research, August 12, 2026
    40
    Prior authorizations per physician per week, self-reported
    AMA 2025 Prior Authorization Physician Survey (n=1,000), released May 13, 2026
    $28k–$70k
    Single-workflow agent build, 4–9 weeks
    Frenchy Digital scoping bands, 2026

    Key Takeaways

    • A zero-click clinic is a practice where the default administrative path completes without a human click, and humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal or safety decision. It is not an unstaffed practice and must never be sold as one.
    • Certified EHR API access under §170.315(g)(10) is read and search only. Every write an agent performs — booking, filing, posting, updating — is vendor-discretionary. This is the architectural constraint that decides what your project can actually deliver.
    • Automate in order of reversibility, not in order of visibility. Pre-visit readiness first, phones last. The most visible workflow is the most brittle, and starting there puts your first failure in front of patients.
    • Signature and attestation are never automatable. CMS names AI explicitly: practitioner concurrence is required for AI-captured medical record entries, and reviewers may not consider an attestation from anyone other than the entry's author.
    • No independent benchmark exists for this vendor category. Every accuracy, resolution and touchless rate in the market is vendor-published, so our Top 10 excludes accuracy from scoring by design and ranks on verifiable public attributes instead.
    • Not one vendor in this category publicly states that it offers a business associate agreement. That is a finding, not an oversight — get the BAA in writing before any pilot data moves.
    • Frenchy Digital cost bands: discovery $9k–$22k; single-workflow agent $28k–$70k; multi-workflow platform with EHR/PM integration $70k–$180k; enterprise or multi-site regulated build $180k–$420k+.

    What the Zero-Click Clinic Actually Is

    A zero-click clinic is a practice where the default administrative path completes without a human click, and humans are deliberately routed to the exceptions and to every clinical, billing-attestation, legal or safety decision.

    Read that definition twice, because two words carry the entire idea and both of them get lost in the marketing. The first is default. The zero-click clinic is not a clinic where nothing is clicked; it is a clinic where the ordinary, unremarkable, high-volume path — the eligibility check that resolves cleanly, the fax that belongs to an obvious patient, the recall list that computes itself — reaches its end without anyone touching it. The second is deliberately. The exceptions are not what fell through. They are what you routed to a human on purpose, because a human is the right answer.

    Say this out loud before your first vendor call. A zero-click clinic is not an unstaffed practice, and it must never be sold as one. Any vendor pitching headcount elimination is describing a different product from the one this article describes, and a business case built on a reduction in force will not survive its first quarter. The staffing change is a change in composition, not in count. We return to it in detail below.

    This matters because primary care and family medicine sit at the exact point where the volume is highest and the margin per encounter is thinnest. A family medicine practice runs the widest administrative surface of any specialty in ambulatory care: it schedules everything, refers to everyone, receives documents from every direction, chases records it did not generate, manages chronic-disease recall across a whole panel, and absorbs the prior-authorization burden of every referral it makes. Nothing about that is clinically interesting, and all of it is expensive.

    The scale of the desk work is not new information. Sinsky and colleagues, writing in Annals of Internal Medicine in 2016, observed that for every hour of direct clinical face time, physicians spent nearly two additional hours on EHR and desk work. That study should be cited with its limits every time: 57 physicians, 430 observed hours, four specialties, four states, with the authors themselves noting the data came from self-selected, high-performing practices and may not be generalizable. It is a decade old and it is not a current measurement. It is quoted here for one reason only — because it is one of the very few numbers in this field that can be chased to a named, dated, fetchable source, which is more than can be said for almost anything a vendor will show you.

    On the authorization side, the AMA's 2025 Prior Authorization Physician Survey, fielded among 1,000 practicing physicians and released on May 13, 2026, reports that physicians complete an average of 40 prior authorizations per week, that prior authorization consumes an average of 13 hours of physician and staff time each week, that 40 percent of physicians employ staff dedicated exclusively to prior-authorization tasks, that 94 percent say it contributes to burnout, and that 74 percent report denials have increased over the past five years. That is a self-reported physician survey and should be described as one. It is still a real instrument with a real sample and a published release, which distinguishes it from most of what circulates.

    We refuse statistics nobody can source, and we say so in the article. Naming a number as untraceable is more useful to an operator than repeating it. You will see us do this repeatedly below — with the vendor accuracy rates, with the per-no-show costs, and with the return-on-investment figure that turns out to have no origin at all.

    Frenchy Digital, house rule for the healthcare cluster

    This article is the pillar of a ten-article implementation series. The nine specialty guides that follow it — dermatology, physical therapy, eye care, OB-GYN and the rest — assume this definition and do not contradict it. If you read only one section here, read the boundary table.

    Phase 0: Measure Before You Buy Anything

    The single most common reason a practice cannot tell whether its AI deployment worked is that it never wrote down what things were like before. This is not a philosophical point. It is the difference between a renewal conversation you win and one you lose, and it takes two weeks.

    Seven measures. Each has a method, an owner and a reason. Take them before you sit through a demo, because a demo changes what you think your problems are.

    MeasureHow to take itOwnerWhy this one
    Inbound call volume and what each call was forPhone system report plus a two-week tally sheet at the front desk, categorised into no more than eight reasonsFront-desk supervisorYou cannot tell whether a voice agent worked. Every abandonment benchmark sold with voice agents in this market is unsourceable, so your own before-number is the only one that means anything.
    Time from patient request to booked appointmentTimestamp of first contact minus timestamp of the created appointment, sampled across 100 consecutive requestsPractice administratorThis is the metric a scheduling agent is supposed to move, and almost nobody records the numerator today.
    Eligibility exceptions per 100 scheduled visitsCount of visits where coverage was wrong, missing or changed at check-inBilling leadPre-visit readiness is the highest-yield first workflow in primary care, and this is its scoreboard.
    Prior authorizations initiated, pending over 7 days, and abandonedWorklist export, weekly snapshot for four weeksBilling leadThe AMA's 2025 physician survey puts self-reported volume at 40 per physician per week. Your own number will differ, and yours is the one that matters.
    Documents received by fax or portal, and hours spent routing themFax server log plus a one-week time diary from whoever routes themOffice managerDocument intake is the workflow most often underestimated and most often the largest single time sink outside documentation.
    After-hours documentation time per clinicianEHR usage report, four-week average, plus a self-report cross-checkMedical directorIf you cannot state this number today, you cannot claim later that software changed it.
    Staff overtime hours and temp-agency spend, by month, trailing twelve monthsPayroll exportPractice administratorThis is the line item that actually moves if the project works. Revenue lift is a much harder claim to defend.

    The Phase 0 baseline set for a primary care practice — Frenchy Digital engagement standard, 2026.

    Two notes on method. First, take the measures with the crudest instrument that works. A tally sheet taped to the front desk for two weeks produces a more defensible number than a dashboard you configure for a month and never validate. Second, take them again at day 90 using exactly the same method. Changing the instrument between the before and the after is the most common way a genuinely successful project ends up unprovable.

    Why your own numbers are the only ones worth having.The benchmarks circulating in this market are, almost without exception, published by companies selling software to the practices they describe. The oft-quoted cost-per-no-show and the national missed-appointment total both trace back to a single byline by a scheduling vendor's chief medical officer, with no methodology attached. The phone-abandonment benchmarks used to sell voice agents are the same shape. We do not print them, and neither should your business case.

    There is one industry-scale figure worth knowing, and it comes with a disclosure. The Index report published by DataSpring — the organisation formerly known as CAQH, which converted from nonprofit to for-profit in January 2026 and rebranded on June 8, 2026, and is owned by shareholder companies affiliated with health plans — puts the remaining industry savings opportunity from full electronic transactions at $21 billion, on 2024 transaction data released in February 2026. That is an industry benchmark, not an independent one, and the ownership matters. We cite it with the disclosure attached, which is the only responsible way to use it.

    The Read-Only Ceiling on Every EHR Write

    This is the single most important architectural fact in medical practice automation, and most buyers discover it after the contract is signed.

    Certified API access under 45 CFR §170.315(g)(10) is read and search only. ASTP/ONC's own Certification Companion Guide, updated May 15, 2026, states it without ambiguity:

    Read services include those that allow authenticated and authorized third-party applications to view EHI through a secure API. These services specifically exclude 'write' capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.

    ASTP/ONC, Certification Companion Guide for §170.315(g)(10)

    What that guarantees you, in any certified EHR, is the ability to read demographics, problems, medications, allergies, results, notes and coverage; to search; and to export in bulk. What it does not guarantee is everything that makes automation feel like automation: booking the appointment, writing the note, filing the document, updating the insurance record, placing the order, posting the payment. Each of those exists only if your EHR vendor chose to build it, chose to expose it, and chose to let your agent vendor use it. It is a commercial arrangement, not a certification right.

    Do not overstate the constraint either. Epic voluntarily publishes some write-capable FHIR APIs, documenting create support on resources including DocumentReference, Observation, QuestionnaireResponse, AllergyIntolerance, Condition, Communication and BodyStructure, and update support on several of the same. The documented write surface is narrow and resource-specific, but it is not empty. The honest description is that write access exists in patches, at each vendor's discretion, and you must find out which patches you have before you design a workflow that depends on them.

    The exact question to put to your EHR representative, in writing

    Send this sentence and ask for a written reply. It is the most valuable email you will send during the whole project.

    "Which FHIR resources can a third-party application create or update in my instance, is that through a certified API or a proprietary one, what does it cost, does it require your approval per vendor, and if the answer is 'no API', is your integration doing RPA under a named user's credentials?"

    If you get a verbal answer, a slide, or a promise to follow up, treat the answer as no and design the workflow to end at a human commit step. That is not pessimism; it is the difference between a project that ships and one that stalls in week eleven.

    Where the vendor cannot get an API write, the write happens by robotic process automation — a robot typing into the EHR's user interface on a service account. Notable is, to its credit, the one vendor in this category that says so plainly on its own integrations page, describing its method as using APIs, RPA, HL7 and more to get data into the right fields. That candour is a reason to trust the vendor and a reason to ask harder questions, both at once. RPA breaks on UI changes, is usually invisible in the EHR audit log as a system action, and attributes actions to whatever human's credentials it runs under — which collides directly with the requirement for unique user identification at 45 CFR §164.312(a)(2)(i), a required specification rather than an addressable one.

    Two things follow, and they shape everything downstream. First: an agent can always decide and draft; it cannot always commit. Design for that asymmetry rather than against it. Second: read-only-by-default is not merely a compliance posture, it is the strongest available security control and it is free. An agent that cannot write cannot be injected into writing.

    The trajectory is moving, slowly. ASTP/ONC's HTI-5 proposed rule, published in the Federal Register on December 29, 2025, retains §170.315(g)(10), states an aim to move beyond read-only interactions in future FHIR API requirements, and proposes to remove the third-party-seeking-modification-use condition from the Infeasibility exception — the condition EHR developers have used to limit write access. The comment period ran into late February 2026 and we located no final rule as of today. Write access is on the federal agenda. It is not a right today.

    The Order to Automate In, and Why

    Sequence is the decision that most determines whether a zero-click programme succeeds, and it is the decision most often made backwards. Practices automate the workflow that annoys them most, which is almost always the phones. Phones are the worst possible starting point.

    The correct ordering principle is reversibility first, visibility last. Start where the work is high volume and low variance, where everything the agent needs is already in the chart, where the output is a worklist rather than an irreversible action, and where failure means a human doing today's job manually. Finish with the workflows that patients see and that commit irreversible actions.

    OrderWorkflowEHR access neededFailure mode if it goes wrongWhy it sits here
    1Pre-visit readiness — eligibility, coverage discrepancy flags, missing-document detection, packet assemblyRead-onlyA worklist. Nothing irreversible happens.Highest volume, lowest variance, fully computable from data the chart already holds, and the failure mode is a human doing today's job.
    2Inbound document and fax triage — classify, extract, attach to the right patient, route to the right queueRead + a filing write, or a human filing stepA staff member files it manuallyLarge, unglamorous, and the extraction is checkable by the person who receives it. Note that inbound faxes are untrusted text, which is why this workflow needs the injection controls described below.
    3Recall and gap-closure outreach — overdue chronic-care follow-ups, preventive intervals, lapsed patientsRead-only to build the list; messaging rail to sendSuppress the campaignThe list is computable and auditable before anything is sent. Start with a small cohort and a human approving the send.
    4Prior authorization packet assembly — gather the clinical evidence, pre-fill the form, flag what is missingRead-onlyThe coordinator assembles it as beforeAssembly is administrative and excluded from the device definition by statute. Submission and the medical-necessity assertion stay human.
    5Scheduling actions — book, reschedule, waitlist backfillWrite requiredReturn to the manual queueThis is where the write-path question becomes unavoidable. Do not sequence it first, because you may discover after purchase that your EHR will not permit it.
    6Ambient documentation — encounter capture and note draftingDraft only; the clinician signsClinician dictates or typesDeliberately late. It is a clinician-behaviour change, not an administrative one, and it needs the trust you build in phases one through five.
    7Voice — inbound phone answering and call deflectionRead + writeCalls roll to staffLast, always. Most visible, most brittle, most exposed to disclosure law, and the workflow where a bad week is witnessed by every patient who calls.

    Recommended automation sequence for a primary care practice — Frenchy Digital, 2026.

    Notice how much of this list runs on read-only data. That is deliberate. Every workflow in positions one through four can be built and proven before you have resolved the write-path question with your EHR vendor, which means you can be delivering value in week seven while the commercial conversation about write access is still running. Practices that sequence the other way spend their first two months in a procurement negotiation with nothing live.

    Why not the phones first? Three reasons, all structural. Voice needs write access to be useful, so it is blocked by the hardest dependency. Voice is the most heavily regulated surface, because a spoken interaction triggers disclosure obligations that an internal worklist does not. And voice failure is public: a bad week on the phones is witnessed by every patient who calls, while a bad week on document triage is witnessed by one staff member who fixes it. Put your first failure somewhere it can be absorbed.

    The 90-Day Implementation Path

    This is the plan we run. Six phases, each with a named owner, an explicit entry criterion, an explicit exit criterion, and a written answer to the question every plan avoids: what do you do when this phase fails?

    Ninety days is enough to get two workflows live and measured in a practice of five to twenty providers. It is not enough to rebuild the front office, and any plan that promises otherwise is describing a demo.

    Phase and weeksObjectiveOwnerEntry criterionExit criterionIf the phase fails
    Phase 0 — Weeks 1–2Baseline and boundaryPractice administratorA named executive sponsor and a decision that this is a project, not a pilotSeven baseline measures written down, dated and signed; a one-page workflow map; a shortlist of no more than three candidate workflowsIf you cannot produce the baseline in two weeks, stop. A practice that cannot measure the before-state cannot evaluate the after-state, and every vendor conversation from here is unfalsifiable.
    Phase 1 — Weeks 3–4Paperwork, identity and the boundary tablePrivacy officer or compliance leadBaseline signed offExecuted BAA covering the vendor and its named subcontractors; the agent provisioned with its own unique identity, not a borrowed clinician login; the human-in-the-loop boundary table signed by the medical directorIf the vendor will not sign a BAA before pilot data moves, the project ends here. This is not a negotiation; it is 45 CFR 160.103.
    Phase 2 — Weeks 5–7One workflow, read-only, shadow modeOperations lead with the integration engineerBAA executed and read API credentials issuedTwo consecutive weeks in which the agent's output is produced in parallel with the human's, agreement is measured daily, disagreements are reviewed by name, and no PHI egress exception is recordedIf agreement is unstable after three weeks, the problem is almost always the workflow definition, not the model. Redefine the workflow before you change vendors.
    Phase 3 — Weeks 8–10Turn on the default path with an exception queueFront-desk supervisorShadow-mode exit criteria met and the rollback trigger written downThe default path completes without a human click for the agreed cohort; the exception queue is drained to zero every day by a named owner; the rollback has been rehearsed once, deliberately, in daylightIf the exception queue is not being drained daily, turn the workflow off. An undrained queue is not automation, it is a backlog nobody has noticed yet.
    Phase 4 — Weeks 11–12The write-path decision and the second workflowPractice administrator with the EHR vendor representativePhase 3 stable for two weeksA written answer from your EHR vendor on which FHIR resources a third party may create or update in your instance, at what cost and under whose approval; a recorded decision for each write — certified API, vendor API, RPA, or humanIf the EHR vendor will not answer in writing, assume the answer is no and design the workflow to end at a human commit step. Never let this question be resolved by a slide.
    Phase 5 — Week 13Measure against the baseline and decideExecutive sponsorTwo workflows live for at least three weeksThe seven baseline measures re-taken with the same method; a written continue, expand or roll-back decision; a named owner for each live workflow with an on-call pathIf the measures did not move and you cannot explain why, roll back. A project that cannot explain its own result will not survive the first staffing change.

    The 90-day zero-click implementation path — Frenchy Digital delivery standard, 2026.

    Three details in that table are doing more work than they appear to. The first is shadow mode in Phase 2. Running the agent in parallel with the human for two full weeks, and reviewing disagreements by name rather than in aggregate, is the cheapest quality signal available and the one most often skipped under schedule pressure. The disagreements are where you learn that your workflow definition, not the model, is the problem.

    The second is rehearsing the rollback in daylight before Phase 3 exits. A rollback that has never been practised is a document, not a control. Turn the workflow off deliberately on a quiet Tuesday, watch the manual path absorb it, time how long the switch takes, and write the number down. You will use it.

    The third is that the write-path decision sits in Phase 4, not Phase 0. This is counterintuitive and it is intentional. Asking your EHR vendor the write question is easy; getting a written answer takes weeks and is easier to obtain once you are a live customer of an integration rather than a prospect. Do the read-only workflows first and let the commercial conversation run in parallel.

    What we insist on before any workflow goes live

    Four artifacts, none of them optional, all of them cheap compared to the incident they prevent: the agent has its own unique identity and appears in the audit log as itself; a named human owns the exception queue and drains it daily; a written rollback trigger exists with a named owner and a rehearsed procedure; and the workflow's completion is instrumented at the destination system rather than in the agent's own success log.

    If a vendor tells you these will slow the launch, they are correct, and it is the right trade. Every practice we have seen abandon an AI deployment abandoned it after an incident it could not explain, not after a feature it did not get.

    The Human-in-the-Loop Boundary

    The boundary is not a philosophy. It is a table, it is signed by your medical director, and it is enforced in the software. Here is ours, with the authority for each line, because a boundary without a citation is an opinion that erodes under commercial pressure.

    Decision or actionBoundaryAuthorityImplementation note
    Schedule, remind, verify eligibility, move claims data, manage inventory, build population listsAgent may act alone on the default path21 U.S.C. §360j(o)(1)(A) — excluded from the device definition by statuteLog every action under the agent's own identity. This is the zero-click surface.
    Draft a patient communication about clinical informationAgent drafts; a licensed human reads and reviews before it goes outCal. Health & Safety Code §1339.75(b) — human review removes the disclaimer requirementIf you skip the review, the disclaimer and human-contact instructions become mandatory in California.
    Present a list of clinical options to a clinicianAgent may, if all four criteria in §360j(o)(1)(E) are metFDA CDS guidance, issued January 29, 2026The clinician must be able to independently review the basis. Cite sources in the output, not just conclusions.
    Emit a single specific preventive, diagnostic or treatment directiveNot a default-path action. Treat as out of scope for administrative automation.Fails Criterion 3; enforcement discretion only where a single option is clinically appropriateEnforcement discretion is revocable. Do not build a business on it.
    Generate a clinical recommendation from the model's own parametric memory rather than retrievable guidelinesNeverFDA's own worked example of a function that fails Criterion 2 and is a deviceThis is the single most important design rule for LLM agents in clinical proximity.
    Touch a medical image, an IVD signal, or a continuous physiologic streamNever21 U.S.C. §360j(o)(1)(E) — device, no discretion availableDiscrete point-in-time vitals at a clinical encounter generally do not, by themselves, constitute a pattern; streaming does.
    Sign or attest to a medical record entryNeverCMS Program Integrity Manual Ch. 3 §3.3.2.4 — practitioner concurrence required for AI-captured entriesThe signature is the commit point. Make it the only path from draft to record.
    Perform work billed incident to a physician's serviceNever42 CFR §410.26(a)(1) — auxiliary personnel means an individual meeting state licensureThere is no incident-to pathway for AI-performed work. Any professional component was performed by a named human or it was not performed.
    Hold itself out with a clinical title or credentialNeverCal. B&P Code §4999.9 — each use is a separate violationNaming your intake agent after a nurse is a per-use violation in California. Name it after the practice instead.
    Conduct therapy or any therapeutic communicationNeverIllinois PA 104-0054 §20 (WOPR Act) — prohibited outright, including through internet-based AIIllinois also bars AI from detecting emotions or mental states, and requires written consent for AI-assisted session transcription.
    Decide eligibility for financial assistance or discounted careHuman review path required, with disclosureColorado SB 26-189, new CRS §6-1-1708(3)(d)–(e), from January 1, 2027Disclose the ADMT's role, the data relied on, and how to request correction and meaningful human review.
    Release records, move money, or send a message to a patient cohort at scaleOut-of-band human confirmation before executionDesign reasoning, not a cited rule — label it as such internallyIrreversibility, not sensitivity, is the right trigger for a confirmation step.

    The human-in-the-loop boundary for administrative AI agents in a US medical practice, as of August 12, 2026.

    Three lines deserve expansion, because they are the ones vendors push hardest against.

    The administrative exclusion is statutory and it is broad. 21 U.S.C. §360j(o)(1)(A) excludes from the device definition software intended for administrative support of a health care facility, including the processing and maintenance of financial records, claims or billing information, appointment schedules, business analytics, information about patient populations, admissions, practice and inventory management, analysis of historical claims data to predict future utilization or cost-effectiveness, determination of health benefit eligibility, population health management, and laboratory workflow. Scheduling, eligibility, claims handling, referral logistics, inventory, population lists — an agent doing those things is outside the device definition by statute, not by FDA grace. This is the sentence that makes the zero-click clinic legally coherent.

    The moment an agent recommends, four criteria apply. §360j(o)(1)(E) makes a recommending function non-device only if it does not acquire, process or analyze a medical image, an in-vitro diagnostic signal or a pattern from a signal acquisition system, and if it displays or analyzes medical information, supports or provides recommendations to a health care professional, and enables that professional to independently review the basis for those recommendations. The Clinical Decision Support Software guidance issued January 29, 2026 — which supersedes a January 6, 2026 version, which in turn replaced the September 2022 guidance — did not change that. Software providing a specific directive output still fails Criterion 3. What FDA announced is enforcement discretion over that failure. The guidance's own wording at page 10 turns on there being only one clinically appropriate option; at FDA's March 11, 2026 town hall the same policy was described with the word recommendation. Same policy, different noun — quote whichever document you are actually citing, and do not put the town hall's noun in the guidance's mouth. Write it as enforcement discretion, never as approval or clearance, because discretion is revocable without notice-and-comment and an exclusion is not.

    The signature never moves. This is the cleanest rule in the entire regulatory stack, and CMS names AI explicitly. The Medicare Program Integrity Manual, chapter 3, §3.3.2.4, effective January 17, 2025, states that the treating practitioner's signature on a note indicates that the practitioner affirms the note adequately documents the care provided, and adds that this type of practitioner concurrence is also required when using Artificial Intelligence technology to capture the transcription of medical record entries. The same section makes the model attestation first-person and credentialed, with an express acknowledgement of administrative, civil or criminal liability, and forbids reviewers from considering an attestation statement from anyone other than the author of the record entry. There is no configuration in which an agent attests. An AI agent may draft, transcribe, suggest and assemble; the signature is the act that converts a draft into a billable, legally operative record, and it is personal, credentialed and non-delegable.

    And there is no incident-to pathway. 42 CFR §410.26(a)(1) defines auxiliary personnel as any individual acting under physician supervision who has not been excluded from federal health care programs and who meets applicable state licensure requirements. Software is not an individual, cannot be excluded by the OIG, and cannot hold a licence. Whatever an agent does is either an administrative task requiring no licensure, or a task whose professional component was performed by a named licensed human. There is no third option, and no vendor configuration creates one.

    Top 10 AI Agent Platforms for Medical Practices

    Before the table, the methodology — because the methodology is the reason to trust the table.

    Methodology: what we scored, what we excluded, and why

    Checked on August 12, 2026.Everything below was read from the vendor's own public pages, its own funding announcements, or a court docket, on that date. Vendor status in this category changes fast enough that a roster more than a quarter old is misleading — re-check every row before you act on it.

    What we scored: publicly named EHR and practice-management integrations, counted as distinct companies rather than product SKUs; publicly documented security posture (SOC 2, HITRUST, ISO 27001, and whether a type or a date is stated at all); pricing transparency; whether the product is standalone or locked to an EHR; buyer fit for an independent medical practice as opposed to a hospital or a payer; and corporate stability from the public record.

    What we excluded, and this is the important part: accuracy. We searched on August 12, 2026 for randomized, peer-reviewed or third-party evaluations of multi-step administrative agent platforms in medical practices and found none. We could not locate a single vendor in this category that publishes an independent audit of its automation-rate claims. Every accuracy figure, automation rate, resolution rate, touchless rate and hours-saved number in this market is produced by the vendor that benefits from it, using its own definitions, on its own customer set, with no denominator disclosed. Accuracy is therefore excluded from scoring by design. Any competing list that ranks these products by accuracy percentage is republishing marketing with a table around it.

    What we could not establish: not one vendor in this category publicly states that it offers a business associate agreement. That is a finding rather than an omission, and it means the BAA must be requested in writing before any pilot data moves. No vendor in this category publishes a price, so every pricing cell reads contact sales.

    How to re-check it: open the vendor's integrations page and count company names, not product names. Open the trust or security page and look for a type and a date, not a badge. Site-search the vendor's own domain before concluding it publishes nothing — one vendor here publishes its SOC 2 Type II attestation on a blog post rather than a security page, which is exactly why a 404 is a discoverability finding and not a verdict. Rankings are opinion built on verifiable inputs. We publish no composite score, because not every input is public and a decimal score would be fake precision.

    #PlatformNamed EHR/PM vendors (distinct companies)Publicly documented security posturePricingWhere it ranks and why
    1NotableNamed EHR/PM vendors: 4 distinct companies (Epic; Oracle Health/Cerner — one vendor; MEDITECH Expanse; athenahealth, listed as both athenaOne and athenaIDX)Trust center lists HITRUST, SOC 2 Type 2, PCI DSS, ISO/IEC 27001:2022. No public BAA statement; no certification dates shown.Contact sales onlyTop of the table on verifiable inputs alone: the joint-highest count of named integrations (level with Adonis, whose four are read off an unlabelled logo strip rather than a named list), the strongest published security posture of any pure-play here, and the only vendor that discloses its integration method honestly — APIs, RPA, HL7 and more.
    2InnovaccerNames no EHR on the pages we fetchedTrust center lists SOC 2 with a HIPAA report, HIPAA, ISO 27001:2022, HITRUST r2 (2025), GovRAMP in progress. No explicit BAA statement.Contact sales onlyBest-documented security posture alongside Notable, and the broadest named agent roster. Ranked with an explicit caveat: see the litigation row in the corporate-record table below.
    3CommureClaims deep integration with 60-plus EHRs but names none of themTrust Center states SOC 2 Type II with the ambiguous wording audited by an independent third party (in progress / certified); HIPAA/HITECH alignment. No HITRUST, no ISO 27001, no explicit BAA statement; documents request-only.Contact sales onlyBroadest product surface in the set — ambient AI, call-centre agents, referral orchestration, RCM, patient engagement. A 60-EHR claim naming zero systems is a scoring negative, not a positive.
    4Assort HealthNamed: Epic and athenahealth (2 distinct vendors), from the company's own Series C pageNo security or trust page located at the conventional URLs on 2026-08-12. Site-search the domain before scoring this — a 404 is a discoverability finding, not proof nothing is published.Contact sales onlyFastest-scaling 2026 entrant by funding, and the one whose security posture we could least verify. That combination is worth naming as a verification gap. Voice-first, so it also touches the patient-communication category.
    5Infinitus SystemsNames Salesforce; names no EHRSOC 2 Type II confirmed on the company's own blog, verified by direct fetch 2026-08-12. No HITRUST, no BAA statement, and the announcement is undated on-page.Publishes a pricing model but no price — platform and license fees plus per-task or per-minute usage, or a subscriptionThe only vendor in the category that discloses how it charges. Ranked here rather than higher because its buyer profile is payers, PBMs, pharma and specialty pharmacy far more than medical practices.
    6TennrNames no EHR or PM system anywhere we could findHomepage shows HIPAA Compliant and SOC II Compliant badges. Badge only: no Type I/II distinction, no HITRUST, no BAA statement, no reachable trust page.Contact sales onlyGenuinely useful shape for primary care — inbound fax and referral packet orchestration — and the weakest published integration disclosure in the top half. SOC II compliant without a type is not an attestation.
    7HyroEpic named in its October 2025 funding release; ServiceNow partnership announced August 5, 2026Its own releases claim only fully HIPAA-compliant. We could not verify SOC 2 Type II or HITRUST from any primary source; the vendor's site is blocked to our fetcher.Not published anywhere we could reachRanked primarily as a patient-communication and voice platform, so it appears here with a pointer rather than a full scoring row. Unverifiable security posture is a legitimate negative, not a neutral.
    8AdonisHomepage integration logos read as Epic, athenahealth, NextGen and Modernizing Medicine — four named, a conservative floor from an unlabelled logo stripFooter shows a HIPAA badge and an AICPA badge implying SOC 2, but the type is not stated. No HITRUST, no BAA statement.Contact sales onlyPrimary home is prior-authorization and revenue-cycle automation rather than general orchestration. Listed here for completeness with a pointer to that category.
    9Candid HealthNames no EHR or PM system; the site says only modern APIs and pre-built integrationsNo compliance claim located on the pages we could read. Site-search the domain before scoring it.Not published; the pricing path 404s and only a demo request is offeredAPI-first claims and billing infrastructure rather than an agent platform a practice operates. Ranked low here because it is the wrong shape for this category, not because it is a weak product.
    10QventusSays its solutions are seamlessly embedded into your EHR but names no EHRNo security or compliance statement located; the conventional trust URL 404s. Site-search before scoring.Contact sales onlyExplicitly not for independent practices. Its products are hospital operations — OR scheduling, perioperative coordination, inpatient capacity — and its named customers are all large systems.

    Top 10 AI agent platforms for medical practices, ranked on verifiable public attributes only. Checked 2026-08-12. Accuracy excluded from scoring by design.

    The second half of the assessment is corporate. A platform that runs your front office is a continuity dependency, and the clearest cautionary tale in this category is not a product that failed but a product that was withdrawn for portfolio reasons after an acquisition. Read the ownership column as carefully as the security column.

    PlatformOwnershipFunding on public recordAdverse findings and caveats
    NotableStandalone, privateReported $100M Series B in 2021 led by ICONIQ Growth at a reported $600M valuation; roughly $123M total raisedWe could not confirm any 2026 round and aggregator data conflicts, so we print no current valuation.
    InnovaccerStandalone; a serial acquirer (Cured and Pharmacy Quality Solutions in 2024, Humbi AI in January 2025)Reported $275M Series F; roughly $675M total raisedIn April 2026 CommonSpirit Health sued Innovaccer for breach of contract over a failed roughly $32M data-consolidation project, alleging it did not deliver the promised unification of patient records and operational data. A separate docket exists: Fallon Community Health Plan, Inc. v. Innovaccer, Inc., D. Mass. 4:2025-cv-13790. These are allegations in pending litigation; the underlying complaint is paywalled and Innovaccer's response was not obtained.
    CommureNot independent in the venture sense: incubated and controlled by General Catalyst. Merged with Athelas; acquired Augmedix for $139M in 2024.$200M in non-dilutive financing from General Catalyst's Customer Value Fund, announced June 19, 2025, repaid from a capped share of the cohort of customers acquired — not equity, and not to be added to a funding totalSerial-acquisition roll-up. A practice buying Commure is buying a portfolio assembled from several companies, and product-line consolidation risk is real.
    Assort HealthStandalone$120M Series C announced June 24, 2026 led by Menlo Ventures at a $1.2B valuation; more than $222M raised in totalIts Series C page carries five outcome metrics we refuse by design — see the methodology block.
    Infinitus SystemsStandaloneRoughly $103M total; $51.5M Series C led by a16zIts marketing claims it outperformed human benchmarks by more than 18 percent. No denominator, no comparator definition, no third party. We refuse it.
    TennrStandalone; founded 2021, New YorkReported $101M Series C led by IVP at a $605M valuation, roughly $162M total across four rounds — note this round is mid-2025, not newNothing adverse found.
    HyroStandalone$45M strategic growth round announced October 21, 2025 led by Healthier Capital, with Norwest, Define Ventures, Bon Secours Mercy Health and ServiceNow Ventures; $95M total raisedRanked No. 677 on the 2026 Inc. 5000. That list ranks self-reported revenue growth, so treat it as corporate-stability colour, never as a quality signal.
    AdonisStandalone; New York, founded 2022Reported $40M Series C announced March 25, 2026 led by Quadrille Capital with General Catalyst and Bling Capital; more than $95M totalNothing adverse found.
    Candid HealthStandaloneReported $52.5M Series C led by Oak HC/FT in February 2025, then a $120M Series D led by Sixth Street Growth announced July 22, 2026; more than $219M totalThe Series D valuation was not disclosed. We print no valuation.
    QventusStandaloneReported $105M Series D led by KKR, announced January 2025, with Bessemer and health-system investors including Northwestern Medicine, HonorHealth and Allina HealthIts published outcome figures are self-reported with no denominator and are refused here as a set.

    Corporate record for the ranked platforms, from public announcements and dockets. Checked 2026-08-12.

    The refusals, named. Several vendors above publish outcome metrics on the very pages we cite. We refuse them and we will tell you which: a 97 percent resolution rate, 79 percent of referrals scheduled without staff intervention, a 115 percent increase in labour capacity, a 5 percent lift in appointment volume, and up to $4.3 million per 100 providers — all vendor-defined, all without denominators. Likewise a claim of outperforming human benchmarks by more than 18 percent, a payer-side claim that up to 90 percent of authorization requests are approved automatically, and a set of hospital-operations figures including a 10x annualised return. None of them are lies; all of them are unfalsifiable. They are excluded here for the same reason a competent auditor excludes an unaudited number.

    Explaining the cuts matters as much as explaining the picks. Seven credible companies are frequently listed alongside the ten above and do not belong in a practice-facing table, each for a reason a buyer can verify.

    CutWhat it doesWho it actually sells toWhy it is not in the Top 10
    LeanTaaSCapacity optimisation for operating rooms, infusion centres and inpatient bedsHospital and infusion-centre scale, delivered with a dedicated engagement team. Majority-owned by Bain Capital since 2022.Cut on buyer fit. Its advertised per-OR, per-chair and per-bed figures are labelled as targets on its own site and are not outcomes.
    Cohere HealthUtilisation management, prior-authorisation decisioning, payment integrity and appealsPayers. The only provider-facing surface is a portal to check authorisation status.Cut on a verifiable reason: a practice cannot buy Cohere as its agent platform. You encounter it on the other side of the table — which is itself the point that your prior-auth agent is increasingly negotiating with another vendor's agent.
    AnteriorAI plus clinician-led review for prior authorisation, payment integrity and risk adjustmentHealth plans, explicitlySame disqualifier as Cohere. Payer-side product, not a practice purchase.
    Hippocratic AIPatient-facing clinical and nurse-style outreach agentsHealth systems and payersCut on category: clinical-adjacent outreach, not administrative orchestration. Its claim of 115 million clinical patient interactions with no safety issues is unauditable by construction — no external adverse-event register exists — and we refuse it.
    AKASARevenue-cycle generative AI sold to health systemsStatus not establishedCut on two grounds: enterprise-only buyer fit, and the fact that we could find nothing fetchable about the company after 2021. Five years of public silence in a market moving this fast is weak evidence of health, not evidence of independence.
    Thoughtful AIAgent personas for eligibility, prior auth, claims scrubbing, denial management and payment postingAcquired by New Mountain Capital and folded into Smarter Technologies with Access Healthcare and SmarterDx in May 2025Cut because the standalone product is being withdrawn. Trade reporting in April 2026 says customers received discontinuation notices for stand-alone services with roughly 90 days to migrate. Treat that timeline as reported by the outlet, not confirmed by the company.
    Olive AIHealthcare automation platformDefunct. Wound down in late 2023; assets sold to Waystar, Humata Health, Availity and BurstIQ.Included only as precedent. Reported totals across its life run roughly $850M to $900M, including a $400M round in July 2021 at a reported $4B valuation. Capital raised is not a continuity guarantee.

    Vendors excluded from the practice-facing Top 10, with the verifiable reason for each cut.

    One more structural point that the Cohere row makes better than any argument could: the payer is automating too.A practice's prior-authorization agent is increasingly negotiating with another vendor's agent on the other side of the table. That does not make automation pointless — it makes the assembly-and-evidence half of the workflow more valuable, and the guess-what-the-payer-wants half less so.

    Your EHR May Already Ship This

    In 2026 the EHR vendors moved into the agent layer, and that changed the buying question. It is no longer which agent platform. It is what does my EHR already ship, when, and at what price — and what is genuinely left over for a third party? Ask that first, because the answer may save you a six-figure procurement.

    EHRNative agent productsTiming on public recordPricing and practical caveats
    EpicArt (clinical assistant and ambient documentation), Penny (revenue cycle — coding, denial appeals) and Emmie (patient-facing, inside MyChart and over conversational SMS) were introduced at its August 2025 user group meeting. Agent Factory, a no-code platform for building your own agents inside Epic, was previewed at HIMSS in March 2026.Penny's fully autonomous coding is stated to roll out starting November 2026, beginning with ED and radiology encounters. No general-availability date for Agent Factory.No price disclosed for any Epic agent. Also note the obvious: Epic is a health-system EHR, and a three-physician independent practice generally cannot buy it.
    athenahealthLaunched agentic text and voice patient-communication tools in athenaOne in February 2026 — 24/7 front-office agents for scheduling and administration — plus athenaAmbient, an ambient scribe built into athenaOne, and Sage, an embedded assistant that reads the chart and answers clinical questions. Self-healing agents that traverse payer portals are also described.athenaAmbient entered user testing in February 2026.athenahealth is reported to deliver athenaAmbient to customers through routine updates at no additional cost. We could not verify this: the primary press release is blocked to our fetcher. It is the single most consequential fact for a small practice weighing a third-party platform, so get it confirmed in writing by your representative before you buy anything.
    eClinicalWorksPositions healow Genie (agentic front office covering paperwork, scheduling and prior authorisations) and Sunoh.ai (ambient scribe) as a digital workforce. A healowIQ product was announced in May 2026.Not disclosedNo pricing disclosed. Our primary source for this was blocked, so treat the product descriptions as reported rather than confirmed.
    NextGen HealthcareNextGen Ambient Assist, which places SOAP notes into the EHR within roughly 30 seconds of the encounter, is the documented native AI product.In marketWe found no 2026 announcement of a NextGen agentic or orchestration platform. The native-agent story is thinner here than at Epic, athenahealth or eClinicalWorks, which is precisely where a third-party platform still has room. Owned by Thoma Bravo since a take-private completed in November 2023.

    Native EHR agent offerings as documented on public record, checked 2026-08-12. Several primary sources in this table were blocked to our fetcher; treat the reported items as reported.

    Epic's Phil Lindemann, quoted in MedCity News's March 2026 coverage of Agent Factory, described the ambition plainly: "Now with Penny, Art and Emmie, you can say, 'I want to redesign an entire process that involves scheduling, referrals and patient experience.'" The same article carries a useful counterweight from Canvas Medical's chief executive Adam Farren, who — in MedCity News's characterisation, not in his own words — applauds Epic's approach but does not think hospitals are ready to take advantage of the platform yet. What he actually said, verbatim: "Show what's possible, and the details matter, and often a narrow job accomplished with an agent is much more impactful than a more complex workflow with broader surface area for error."

    That is the same conclusion this article reaches from a different direction, and it is worth sitting with: even the EHR-native path fails without workflow discipline. A narrow job done reliably beats a broad workflow with more surface area for error, whoever ships it.

    The honest read for an independent practice. If you are an Epic shop, the leftover surface for a third-party agent platform is shrinking, and your first question should be to your Epic representative. If you are on eClinicalWorks, NextGen or athenahealth, what genuinely remains for a third party is workflow breadth and multi-system orchestration — payer portals, faxes, phones, the systems your EHR does not touch. And note the pricing reality: no vendor in either group, native or third-party, publishes a price. Every comparison you make will be against a number you had to ask for.

    What Breaks First: Signals and Rollbacks

    Every deployment breaks. The difference between a practice that keeps its agents and one that rips them out is whether the break was detected by a metric or by a patient. Here are the eight failure modes we see in primary care, each with the signal that catches it early and the rollback that contains it.

    Failure modeWhat is actually happeningDetection signalRollback
    A write path silently stops committingAn EHR or payer-portal UI change breaks the last step of an RPA-based write. The agent reports success; nothing lands.Completed writes per hour measured at the destination system, not in the agent's own log. Alert on a drop, not on an error.Switch the workflow to draft-and-human-commit. Keep the manual path documented well enough that a supervisor can restore it inside an hour.
    The exception queue quietly growsVolume routed to humans exceeds the capacity you staffed for, usually because the agent's confidence threshold was set optimistically.Queue depth at close of business, plotted daily. A queue that has not returned to zero for three consecutive days is the signal.Widen the automation criteria so fewer cases route to humans, or narrow the cohort so fewer cases enter at all. Do not add staff to hide the problem.
    Agreement drifts after a model or prompt changeThe vendor upgrades a model. Behaviour changes. Nobody told you because the vendor does not think of it as a change.A standing sample of cases re-run weekly against a fixed expected-output set, with the agreement rate tracked over time.Pin the previous version if the vendor supports pinning. If it does not, that is a finding you should have discovered in due diligence — put it in the contract at renewal.
    Untrusted text becomes an instructionA fax, referral PDF, portal message or payer-portal page contains text that the agent reads as a command. There is no sender authentication on a fax at all.Tool-call logs that show an action the human never requested, and out-of-scope retrievals. Detection is genuinely hard: a Nature Communications study in 2025 found prompt injections embedded in medical images can be non-obvious to human observers.Reduce blast radius rather than trying to detect the attack. Read-only by default, allowlisted tools, arguments the human did not supply denied by default, and out-of-band confirmation for anything irreversible.
    Attribution collapses in the audit logThe agent runs on a shared service account or a staff member's credentials, so its actions are indistinguishable from a human's.Pull an audit-log export and try to answer who did this for ten agent actions. If you cannot, you have already failed.Provision the agent its own unique identity before anything else goes live. 45 CFR 164.312(a)(2)(i) makes unique user identification required, not addressable.
    Context windows quietly over-fetchThe retrieval layer pulls more of the chart than the task needs because it is easier to build that way.Log what was retrieved, not only what was used, and review the distribution monthly.Scope retrieval by patient, encounter and role before the model sees anything. Minimum necessary under 45 CFR 164.502(b) has no treatment exception for a billing, scheduling or prior-auth agent.
    Patients notice before you doThe agent's tone, its disclosure, or its handling of an emotional call becomes a complaint before it becomes a metric.A named person reviews a fixed sample of agent-handled interactions every week, and complaints are tagged by channel.Route the affected call type back to staff the same day. Voice is the workflow where reputational damage outruns your dashboards, which is why it belongs last in the sequence.
    The vendor withdraws the productNot a technology failure — a cap-table failure. Portfolio consolidation after an acquisition can end a product line that was working fine.Ownership changes, roll-up announcements, and support responsiveness. Watch who owns your vendor, not just what your vendor ships.Contractual data export in a machine-readable format, a documented manual path for every automated workflow, and a written estimate of what a migration would cost, refreshed annually.

    Failure modes, detection signals and rollbacks for AI agents in a primary care practice — Frenchy Digital operations standard, 2026.

    The fourth row deserves its own paragraph, because it is the one where the honest answer is uncomfortable. Prompt injection is not solved. Any agent reading untrusted external input — patient messages, faxes, referral packets, payer portal pages — is exposed, and the correct framing is blast-radius reduction, never prevention.

    The best-sourced evidence is peer-reviewed and it is not comfortable reading. Lee and colleagues, in JAMA Network Open in December 2025, ran a controlled simulation across 12 clinical scenarios and reported that across 216 evaluations, attacks achieved 94.4 percent success at turn four and persisted in 69.4 percent of follow-ups, with extremely high-harm scenarios including FDA Category X pregnancy drugs succeeding in 91.7 percent of dialogues. Its limits must be stated: it is a controlled simulation rather than field data, the main experiment used lightweight models with a small proof-of-concept on flagship models, and three co-authors disclose company roles. Separately, Clusmann and colleagues in Nature Communications in 2025 showed that all four vision-language models tested were susceptible, and — the finding that breaks the standard mitigation story — that sub-visual prompts embedded in medical imaging data are non-obvious to human observers.

    Read those two together and the conclusion is unavoidable: a human-in-the-loop who cannot see the injection cannot review it away. We found no published study of prompt injection via patient portal messages, referral faxes or payer portals in a live practice, and that absence is itself worth stating. What works is architectural and does not depend on detecting the attack: least privilege at the API boundary, read-only by default, the human signature as the only commit path, unique agent identity with audit controls so a successful injection is reconstructable afterwards, and out-of-band confirmation for anything irreversible. Any vendor quoting you an injection-detection accuracy rate is quoting a number it produced itself; no independent benchmark for clinical prompt-injection defence exists that we could locate.

    Staffing: What Actually Changes

    Here is the part vendors skip and the part that determines whether your programme survives its first staffing change. The zero-click clinic does not remove people. It changes what the people do, and the new work is harder than the old work.

    RoleWhat it does todayWhat it does in a zero-click clinicWhat to plan for
    Front-desk generalistAnswering phones, verifying eligibility, retyping demographics, chasing formsOwning the exception queue for one or two workflows, handling the calls the agent routes out, and correcting the agent's misses by nameDenser and less interruptible work. Budget for training, not just for a new job title, and expect the first month to feel worse than the last month before go-live.
    Billing coordinatorAssembling prior-auth packets by hand, re-keying payer portal dataSubmitting, arguing, and making the medical-necessity case — the parts a machine cannot assertAttestation and assertion stay human. Any vendor implying otherwise has not read the signature rules.
    Office managerFirefighting across every workflowRunning the daily queue review, the weekly sample audit and the monthly measure re-takeThis is a new, real, recurring job. If nobody owns it, the deployment degrades quietly. Name the person before go-live.
    ClinicianAfter-hours documentation and inboxReviewing and signing drafts, and handling the escalations the agent routesThe signature is the commit point and it does not move. Sequence documentation late, after the administrative workflows have earned trust.
    Practice administratorVendor management by demoVendor management by contract: BAA scope, subcontractor list, audit-log export, model-version notification, data export on terminationThis is the highest-leverage role change in the whole programme, and the one most practices skip.

    Role changes in a zero-click primary care practice — Frenchy Digital engagement observations, 2026.

    Two honest warnings. The first is that exception work is not residual work. When you automate the eligibility checks that resolve cleanly, what remains for your staff is a residue of cases that are all genuinely hard — no easy ones left to break up the day. We deliberately print no ratio for that split: nobody has measured it independently, and your own Phase 0 baseline will give you a better number than any benchmark on offer. That is a real change in cognitive load, and it is the reason the first month after go-live often feels worse than the month before it. Say so to your team in advance, and staff the queue with someone who is good at hard cases rather than whoever has capacity.

    The second is that the daily queue review is a new job that nobody assigns.Somebody has to look at the exception queue every day, look at the weekly sample, and re-take the measures every month. In practices where this is nobody's explicit responsibility, the deployment does not fail loudly — it degrades quietly over about a quarter, and by the time anyone notices, the manual workarounds have re-established themselves and the software is a line item nobody defends at renewal.

    Honest Payback Math, and What It Costs

    We are not going to give you a return-on-investment figure, and you should be suspicious of anyone who does. The most-repeated ROI number in this market — a 468 percent return on an appointment-scheduling deployment — surfaces only in SEO content farms and has no origin at all. We chased it and found nothing behind it. It is a genuinely useful example of a statistic with literally no source.

    What we can give you is the arithmetic to run against your own Phase 0 baseline. Payback in a primary care practice comes from four places, in descending order of defensibility.

    • Overtime and temp-agency spend: The most defensible line and the easiest to measure, because it appears in payroll rather than in a model. Take the trailing twelve months, and at day 90 compare the same months of activity. This is the number that convinces a partner group.
    • Redeployed capacity, valued honestly: Hours returned to staff are only worth money if those hours go somewhere that generates value or absorbs work you would otherwise have hired for. Value them at the loaded hourly cost of the role, not at a physician's rate, and only count hours you can name a destination for.
    • Avoided rework at the front of the revenue cycle: Eligibility exceptions caught before the visit rather than after it. Measure the count from your baseline and the downstream denial rate for that cause. Note that we deliberately do not use the widely circulated per-rework cost figures — they are unsourceable, and your own denial data is better than a benchmark anyway.
    • Throughput, only if you actually want it: Freed clinician or room time converts to revenue only if there is unmet demand and the clinicians want to see more patients. Both assumptions are frequently false. Test them before you build a case on them.

    What we will not count, and neither should you: an economy-wide administrative-cost estimate presented as your practice's opportunity. The trillion-dollar figure that appears in vendor funding materials covers all administration across the entire health economy, most of it inside insurers and hospitals. It is not an addressable market for a six-provider clinic, and using it as one is how a business case becomes fiction.

    EngagementRangeTimelineTypical scope
    Discovery + workflow audit$9k–$22k2–4 weeksBaseline instrumentation, PHI data-flow map, BAA inventory, human-in-the-loop boundary table, prioritised workflow shortlist
    Single-workflow agent (intake, scheduling, authorization, documentation)$28k–$70k4–9 weeksOne workflow end to end, read-only integration, exception queue, audit logging under a unique agent identity, rollback runbook
    Multi-workflow platform with EHR/PM integration$70k–$180k9–16 weeksSeveral workflows, write-path negotiation and implementation, retrieval scoping, evaluation harness in CI, role matrix, staff redesign
    Enterprise / multi-site / regulated build (audit logging, HITL, SOC 2 posture)$180k–$420k+14–24 weeksMulti-tenant isolation, full audit pipeline, disaster recovery and restoration testing, documentation package, multi-site rollout

    Frenchy Digital cost bands for medical practice AI engagements, 2026.

    Senior-led delivery runs $150 to $225 per hour, and ongoing retainers run $2,500 to $9,500 per month covering model and dependency upgrades, evaluation expansion, incident response and a quarterly review. Every engagement carries a 30-day post-launch warranty, and you receive a written, fixed-price phased proposal within 5 business days of the discovery call. Full source-code and IP ownership transfers to your practice at delivery.

    One budgeting note that surprises people. The compliance and identity substrate — the boundary table, the agent identity, the audit pipeline, the exception queue, the rollback tooling — is largely a fixed cost paid once and reused by every subsequent workflow. The first agent carries all of it. The fourth inherits it and costs a fraction of the first. Practices that sequence their automation get materially better economics than practices that pilot four disconnected vendors in parallel, which is the single most common procurement mistake we are asked to unwind.

    Red Flags in Vendor Selection

    Twelve signals. None of them is proof of a bad product, and each of them should change the questions you ask next.

    Red flagWhy it matters
    A headline automation, resolution or touchless rateThere is no independent benchmark in this category. Every such figure is vendor-defined, on the vendor's own customer set, with no denominator. Ask for the denominator and watch what happens.
    HIPAA-compliant presented as a property of the softwareHIPAA attaches duties to covered entities and business associates, not to software. The correct phrasing is used under a BAA with these controls. The claim is a reliable signal that nobody at the vendor has read the rule.
    A BAA offered only after the pilotThe pilot is when PHI moves. A BAA that arrives later does not retroactively cover what already happened. Not one vendor in this category publicly states that it offers a BAA — so get it in writing before anything moves.
    We integrate with 60-plus EHRs, naming none of themAn unnamed integration count is unverifiable by construction. Ask for three named reference customers on your specific EHR, at your size.
    No answer on which writes are API and which are RPAYou are entitled to know whether a robot is typing into your EHR under a staff member's login. Vendors that answer this plainly are the ones worth talking to.
    Prompt injection described as solved by guardrailsIt is not solved. Peer-reviewed work has demonstrated high attack success rates against commercial models in medical-advice settings, and injections embedded in medical imaging that are non-obvious to human observers. Any guardrail effectiveness rate you are quoted is vendor-published.
    Human-in-the-loop offered as a blanket answerReview is a control only if it is instrumented. Ask to see review time as a distribution, override and rejection rates per reviewer and per model version, and stored edit diffs. A reviewer accepting everything in under two seconds has reviewed nothing.
    Our model is FDA-approved or FDA-clearedFDA's 2026 CDS guidance grants enforcement discretion over a criterion failure. Enforcement discretion is not clearance and is revocable. Ask for a specific clearance number or the specific basis for being outside the device definition.
    Audit logs you can view but not exportYou cannot answer a regulator, a payer audit or a malpractice discovery request from a vendor dashboard you do not control and cannot preserve.
    A quoted return on investmentThe most-repeated ROI figure in this market — a 468 percent return on a scheduling deployment — appears only in SEO content farms and has no origin at all. Build the case on your own baseline or do not build it.
    Vague ownershipAsk who owns the vendor and what else that owner owns. The clearest cautionary tale in this category is a product that was withdrawn for portfolio reasons after a roll-up, not because it failed. Continuity risk here is a cap-table risk.
    A named persona with a clinical titleIn California each use is a separate violation under AB 489. Beyond the law, a patient who believes they spoke to a nurse and did not is a complaint you will not enjoy handling.

    Vendor selection red flags for medical practice AI agent platforms — Frenchy Digital due-diligence standard, 2026.

    The inverse is also worth writing down, because it is short. The vendors worth your time answer the write-path question plainly, name the EHRs they integrate with, publish a security attestation with a type and a date on it, will sign a BAA before the pilot, will let you export your audit logs, and will tell you which of your workflows depend on RPA. Six answers. If a vendor gives you all six in the first two meetings, you are talking to a serious company.

    Limitations: What We Could Not Verify

    This section is the point of the article. Everything above is only as good as what sits behind it, and here is what does not.

    • No independent evaluation of any product in this category exists: We searched on August 12, 2026 for randomized, peer-reviewed or third-party evaluations of multi-step administrative agent platforms in medical practices and found none. What exists in the literature concerns ambient clinical documentation, which is a different category. This is a negative finding, not a fetched fact, and it may change.
    • No BAA disclosure from any vendor: Not one vendor in the ranked table publicly states that it offers a business associate agreement. We could not verify that any of them does or does not. Ask in writing.
    • No prices, anywhere: We located no published starting price from any vendor in this category, native or third-party. Every pricing statement above reads contact sales because that is genuinely all that is public.
    • Security posture we could not confirm: We could not verify SOC 2 Type II or HITRUST from a primary source for Hyro, Assort, Candid, Qventus or LeanTaaS, and Tennr's and Adonis's badges do not state a type. Several of these are discoverability findings rather than proof of absence — one vendor in this set publishes its attestation on a blog post rather than a security page, so site-search the domain before you conclude anything.
    • Named integrations we could not corroborate: Tennr, Candid, Innovaccer, Qventus, LeanTaaS and Infinitus name no EHR at all on the pages we could read. Adonis's homepage logo strip is unlabelled and readings of it differ, so we printed the conservative floor. Re-fetch before relying on any count.
    • athenahealth's no-additional-cost claim: athenaAmbient is reported to be delivered to athenahealth customers through routine updates at no additional cost. The primary press release was blocked to our fetcher and we could not verify it. For a small practice weighing a third-party platform this is the single most consequential fact in the article, and you must confirm it with your own representative.
    • Epic's commercial terms: We could not verify Agent Factory's general availability date, any price for any Epic agent, or Epic's integration and Showroom fees from a primary source. Integration-cost figures circulating in agency blogs have no Epic source behind them and we refuse to print them.
    • Colorado's interim status: SB 26-189 was signed May 14, 2026 and by its own Section 5 takes effect January 1, 2027, applying to consequential decisions made on or after that date, with a narrow set of rulemaking and appropriation provisions effective on passage. Our sources conflict on the operative status of the predecessor statute during the second half of 2026 and on whether the pause on its enforcement is an attorney-general commitment or a court-ordered stay. We state the January 1, 2027 date because it is quoted verbatim from the enrolled bill; treat the interim position as unsettled and take Colorado-specific advice.
    • The 2026 state payer-side wave: A number of 2026 statutes restricting payers' use of AI in utilisation review are reported by law-firm trackers. We did not verify a single one of those bill numbers against primary text, and at least one identifier in the circulating list cannot be looked up as written. We name none of them here.
    • Federal preemption: Federal preemption of state AI law is being actively pursued, but nothing has displaced the state statutes described above. We did not fetch the underlying executive order or bill and we cite no number, scope or provision for either.
    • Litigation is alleged, not decided: The CommonSpirit and Fallon matters involving Innovaccer are pending. The underlying complaint is paywalled, we could not read it, and Innovaccer's response was not obtained. Treat both as allegations.
    • Vendor status decays fast: Two companies in this category were acquired or wound down between 2023 and 2026, and one had its standalone product discontinued for portfolio reasons rather than performance ones. Anything in the ranked table could be stale within a quarter. The date on the table is not decoration.

    None of this argues against building. It argues for building the measurement alongside the agent, sequencing by reversibility, holding the boundary where the law puts it, and being honest inside your own organisation about which numbers are yours and which came from someone selling you something. The practices that get durable value from AI agents are the ones that instrumented the before-state and never let a vendor define the scoreboard.

    Map Your Zero-Click Path in One Call

    Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. Bring your EHR, your vendor list and the workflow you want first. You leave with a baseline plan and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.

    Map Your Zero-Click Path in One Call

    Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned Los Angeles agency. We baseline your workflows and send a written, fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1ASTP/ONC — Standardized API for Patient and Population Services, §170.315(g)(10) Certification Companion Guide
    2. 2ASTP/ONC — HTI-5 Proposed Rule Fact Sheet
    3. 3Federal Register — HTI-5 Proposed Rule, 2025-23896 (Dec 29, 2025)
    4. 421 U.S.C. §360j(o) — Software Functions Excluded from the Device Definition
    5. 5FDA — Clinical Decision Support Software Guidance (issued Jan 29, 2026)
    6. 6FDA — CDS Final Guidance Town Hall Transcript, March 11, 2026
    7. 7CMS — Medicare Program Integrity Manual, Chapter 3 (Signature Requirements, §3.3.2.4)
    8. 842 CFR §410.26 — Services and Supplies Furnished Incident to a Physician's Service
    9. 945 CFR §164.312 — HIPAA Security Rule, Technical Safeguards
    10. 1045 CFR §160.103 — Definitions, including Business Associate
    11. 1145 CFR §92.210 — Nondiscrimination in the Use of Patient Care Decision Support Tools
    12. 12Unified Agenda — HIPAA Security Rule NPRM, RIN 0945-AA22
    13. 1342 CFR §422.122 — Medicare Advantage Prior Authorization Requirements (CMS-0057-F)
    14. 14California AB 3030 — Health & Safety Code §1339.75
    15. 15California AB 489 — Health Advice From Artificial Intelligence
    16. 16Texas HB 149 (TRAIGA) — Enrolled Text
    17. 17Texas SB 1188 — Health & Safety Code §183.005
    18. 18Colorado SB 26-189 — Bill Page
    19. 19AMA — 2025 Prior Authorization Physician Survey (released May 13, 2026)
    20. 20DataSpring (formerly CAQH) — Index Report
    21. 21Lee RW et al. — Vulnerability of LLMs to Prompt Injection When Providing Medical Advice, JAMA Netw Open 2025
    22. 22Clusmann J et al. — Prompt Injection Attacks on Vision Language Models in Oncology, Nat Commun 2025
    23. 23Sinsky C et al. — Allocation of Physician Time in Ambulatory Practice, Ann Intern Med 2016
    24. 24Notable — Platform Integrations
    25. 25Notable — Trust Center
    26. 26Innovaccer — Trust Center
    27. 27Commure — Trust Center
    28. 28Assort Health — Series C Announcement (June 24, 2026)
    29. 29Infinitus — Pricing
    30. 30Infinitus — SOC 2 Type II Announcement
    31. 31MedCity News — Epic Agent Factory at HIMSS 2026
    32. 32Epic on FHIR — API Documentation
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital, a senior-led Black-owned Los Angeles agency building HIPAA-conscious AI automation for medical practices, clinics and healthcare operators.