AI & Safety

Assistive AI, with the clinician in control.

Every AI surface in PatientTrac drafts, summarizes, and flags for a licensed professional to review — it never decides. Model keys stay server-side; clinical judgment stays with the clinician.

PatientTrac uses AI to reduce documentation and administrative burden across the network, not to practice medicine. AI-assisted summaries, drafts, alerts, and suggestions are produced for clinician review; API keys remain server-side; clinical decisions remain with licensed professionals. Founded in 1998, the platform was rebuilt cloud-native with these guardrails designed in, not bolted on.

Server-Side AI Clinician Review Required Non-Diagnostic Patient AI Human-in-the-Loop Coding Hash-Chained Audit EN/ES/FR
Built for

Safety that everyone can see.

The same guardrails serve the people who rely on them — the clinicians who review AI output, the teams accountable for compliance, and the patients on the other side of a message.

Clinicians reviewing AI-assisted drafts
Compliance & privacy officers
Coding & revenue-cycle teams
Security & IT administrators
Patients using Companion
Leadership evaluating AI risk
How the guardrails work

Five guardrails around every AI surface.

Each one is a mechanism in the platform, not a policy on a page.

01

Server-side only — keys never in the browser

AI runs behind the server, so model credentials are never exposed to the client or the patient's device.

  • Model API keys remain server-side, never in the browser
  • AI calls are brokered by the server, not the client
  • PHI sent to models is governed by the same access controls as the record
  • No third-party model key ever ships to a device
02

Assistive drafts & flags for clinician review

AI proposes; the licensed professional disposes — nothing AI writes becomes part of the record without human review.

  • AI-assisted summaries, drafts, alerts, and suggestions for clinician review
  • Clinical decisions remain with licensed professionals
  • Output is a starting point a clinician edits, accepts, or discards
  • AI is never an autonomous decision-maker
03

Patient-facing AI is non-diagnostic & non-prescriptive

Companion's patient-facing assistant supports recovery conversations without diagnosing or prescribing.

  • Non-diagnostic and non-prescriptive by design
  • Grounded in the patient's care plan, not open-ended medical advice
  • Routes questions and concerns to the care team
  • Directs emergencies to local emergency services
04

Human-in-the-loop coding

AI helps capture the documentation elements relevant to downstream coding review — it does not code the visit for you.

  • Captures documentation elements relevant to downstream coding review
  • The E/M level is not surfaced to the provider during documentation
  • Coding decisions stay with qualified billing and coding staff
  • Supports revenue-cycle workflows; does not guarantee coding outcomes
05

Audit of AI access

Every AI touch of protected health information is recorded on the same tamper-evident trail as the rest of the record.

  • AI access to PHI is written to a hash-chained audit trail
  • Who, what, and when are captured for review
  • The same tamper-evident audit layer as all PHI access
  • Row-Level Security governs what any AI process can read
From request to record

The path of an AI draft.

Every AI surface follows the same four steps — a server-side call, an assistive result, a clinician's review, and an audited record of the access.

01

Server-side call

The request is brokered by the server, so the model API key never reaches the browser or the patient's device. What any AI process may read is governed by Row-Level Security.

02

Assistive result

The model returns a draft, summary, suggestion, or flag — a starting point for a person, never a clinical decision.

03

Clinician review

A licensed professional edits, accepts, or discards the output. Nothing the AI produces enters the record unreviewed.

04

Audited access

The AI's access to PHI is written to the hash-chained audit trail — who, what, and when — on the same tamper-evident layer as every other PHI access.

Across the network

One guardrail model, every connected app.

AI surfaces sit on the same shared record and one encounter_id as the rest of the network — so the same server-side, clinician-reviewed, audited model applies whether AI is drafting a note, summarizing intake, or answering a recovering patient.

Forge

Revenue-cycle and scheduling drafts — AI-assisted suggestions a biller reviews before anything is submitted.

Learn more
Profiler

Intake summaries — AI condenses a trilingual pre-visit questionnaire into a draft the clinician reviews.

Learn more
Mind

Neurobehavioral documentation support — assistive summaries and drafts, with clinical scoring and decisions left to the clinician.

Learn more
Revela

Cosmetic Surgery & Beauty EMR — assistive operative and post-op documentation drafts, reviewed by the surgeon.

Learn more
Continuum

Perioperative note drafts — assistive documentation across the episode, reviewed before it enters the record.

Learn more
Companion

Patient-facing recovery assistant — non-diagnostic, care-plan-grounded, routing to the care team and emergencies to local services.

Learn more
Guardrails, app by app

The same limits, in each product.

How the server-side, clinician-reviewed, audited model shows up as concrete mechanisms inside each connected app.

Forge

Forge — scheduling & revenue cycle

  • AI pre-visit intake returns a clinician summary, suggested ICD-10, and red-flag triage that pre-fills the encounter for the clinician to confirm
  • No-show risk and smart-scheduling slots are suggestions the scheduler weighs, not automatic actions
  • AI-drafted appeals and patient-proposal narratives are reviewed by billing staff before anything is sent
Revela

Revela — surgical safety

  • The AI surgical-safety screen is built on validated risk scores — Caprini, STOP-Bang, RCRI, ASA — surfacing graded safety flags for the surgeon to review
  • Contraindications, drug interactions, and missing pre-op items are flagged; the surgeon is the decision-maker and the system is the safety net
  • Server-side AI drafts notes and PROMs insights; PHI is scrubbed server-side before it reaches a model
Mind

Mind — rating-scale alerts

  • The longitudinal rating-scale engine scores validated instruments and fires safety alerts — for example, PHQ-9 item-9 to a care-team alert
  • Scale interpretation and clinical decisions stay with the clinician; the engine surfaces, it does not decide
  • The E/M level is never displayed during documentation — it is computed downstream at the billing layer
Continuum

Continuum — perioperative drafting

  • A server-side Edge function drafts the operative note in real time as documentation progresses, with dictation cleanup
  • ICD-10-CM and CPT coding suggestions and drug-interaction checks are presented for review, not applied automatically
  • AI surgical flags augment standard calculators; the Universal Protocol time-out and clinical judgment remain the surgeon's
Companion

Companion — patient-facing assistant

  • Non-diagnostic and non-prescriptive: it never diagnoses and never changes medications or doses, offering general education grounded in the patient's own care plan
  • Patient-reported check-ins surface red-flag alerts to the care team when thresholds are crossed; emergencies are directed to local emergency services
  • AI document extraction is gated by patient review — the patient edits or soft-voids with a required reason before anything is accepted
Profiler

Profiler — intake summaries

  • Adaptive AI-branching intake is condensed into a draft summary the clinician reviews
  • Suggested codes and triage flags pre-fill the encounter, but the clinician confirms before anything is relied upon
  • Runs on the shared record, so the same server-side and audit guardrails apply to intake
The line we don't cross

What our AI does — and never does.

Stated as mechanisms and limits, not promises: what AI produces for review, and the clinical acts it never performs.

Server-Side AI · Clinician Review

How AI works here

AI-assisted summaries, drafts, alerts, and suggestions for clinician review; API keys remain server-side; clinical decisions remain with licensed professionals.

Patient-facing AI in Companion is non-diagnostic and non-prescriptive, grounded in the care plan, routes patients to the care team, and directs emergencies to local services.

Explicit Limits

What AI never does here

PatientTrac's AI does not diagnose, does not determine severity, does not select treatment, does not guarantee coding, and does not prevent adverse events. Those remain clinical acts and human judgments.

AI supports documentation and revenue-cycle workflows and does not guarantee reimbursement; the E/M level is not surfaced during documentation.

Why it's different

Guardrails you can point to.

Plenty of software claims to be "AI-powered." PatientTrac states exactly where AI helps and exactly where it stops: server-side keys, clinician review on every clinical surface, a non-diagnostic patient assistant, human-in-the-loop coding, and an audit trail over AI access to PHI. Founded in 1998 and rebuilt cloud-native, it treats AI as an assistant to licensed professionals — never a replacement for them.

See the guardrails in a live encounter.

Walk through where AI drafts, where a clinician reviews, and how every AI touch of PHI is audited across the connected apps.