PATIENTTRAC INSIGHTS

Clinical intelligence.Evidence, perspective and connected care.

PatientTrac Insights examines the clinical, operational and technology decisions shaping connected care.

PatientTrac Insights · Newsweek AI Impact Health Awards · PatientTrac Comparison

Every Access Leaves a Line

Of the ten categories in Newsweek's inaugural AI Impact Health Awards, Data Privacy & Security may be the one health systems watch most closely. Its judges were asked to look for demonstrable safeguards for patient privacy, secure data governance, regulatory compliance, responsible AI controls and transparency in how models are used.

That standard describes what this network was built to prove. It can show a patient every person who opened their record.

A patient calls the practice with a simple question: who has looked at my record?

The staff member pulls up the answer, and it's a list. Every access was written down as it happened, and each entry is linked to the one before it, so no line can be quietly changed.

Was every one of those accesses necessary?

That list has a legal name. The HIPAA Security Rule at 45 CFR 164.312(b) requires covered entities to put in place mechanisms that record and examine activity in systems holding electronic health information.

Why does that belong in a conversation about outcomes? Because care depends on honesty, and honesty depends on trust. A patient who worries about who can see their record may hold back the detail that changes a diagnosis. That's an inference, but anyone who works in behavioral health or sensitive surgical care will recognize it.

The network starts from a conservative premise: keep the record in one governed place and make every access visible. Row-level security applies on every table, and each organization is sealed off from the others. The audit log is hash-chained. Staff sign in with multi-factor codes. AI model keys stay on the server, never in the browser. There are workflows for release of information and for accounting of disclosures, the very request that patient just made. And the data can leave with the patient or the practice through standard health-information export.

Even the AI is narrow on purpose. Companion's patient assistant stays inside the patient's own care plan and hands clinical questions back to the care team. A narrow assistant is harder to manipulate and less likely to say something harmful to someone who is frightened.

There's a quieter point here for anyone thinking about where lasting value sits. The same judging criteria ask for evidence that robust security enables trustworthy, scalable adoption across health systems. Read plainly, health systems want proof of auditability before they let AI touch patient records across an entire enterprise. Privacy that rests on promises has to be taken on faith. Privacy that rests on mechanisms can be inspected by a patient, an auditor or a regulator. And the ability to take the data elsewhere, counterintuitively, makes organizations more willing to commit their entire clinical operation to one record.

So when you evaluate any health technology, try the patient's phone call. Can the system answer it completely, and can you trust the answer?

Every Access Leaves a Line