whoami --clinic
Your clinic is running AI everywhere it shouldn’t. And nowhere it should.
./adoption --report
source: Incredible Health, 2026 State of Nursing Report, 2,240 US nurses
AMA Physician AI Sentiment Report, February 2026
twelve months before that survey the nurse figure was 15%
Read those three bars together and you have the whole problem. Your staff went and adopted AI on their own, far faster than anyone above them decided anything about it. So it ended up running in the places nobody approved, and missing from the places it would genuinely help.
Fixing that takes two steps, and they only work in this order.
audit --phase=1
Step one. Find out what is actually running.
It is never what the org chart says. Once the real list exists, every item on it gets made defensible: covered by an agreement, governed by a written rule, and understood by the people using it. This has to come first, because you cannot safely build anything on top of a system nobody has looked at.
- complete ai inventorySanctioned tools, plus the shadow AI your staff picked up quietly. Gathered so nobody gets in trouble for admitting it.
- coverage verificationPer tool and per product tier. A one-page matrix: every AI-touching product, the plan you are on, whether an agreement covers it, and the date verified.
- written ai policyShort enough that your staff read it and your attorney does not have to translate it.
- staff training90 minutes. Six scenarios your team will recognize on sight, including the prior auth paste and the one where the AI is confidently wrong. Quiz, certificates, rule sheet for the break room.
- state disclosureTexas TRAIGA, California AB 3030, and whatever your state does next. Your disclosure language gets written and mapped to the messages it applies to.
- incident and reviewWhat happens when the AI is wrong, who reviews what before it reaches a patient, and how that review gets recorded.
with the real list in hand and the coverage verified, the second step becomes safe to take
deploy --phase=2 --stack=owned
Step two. Put AI where it should have been all along.
The same people pasting patient details into a chatbot are doing work that a properly built tool could take off their hands. So we build that tool, inside software your practice already pays for. Nothing new gets purchased and nobody signs a new contract.
- find the bottlenecksFirst we work out where the hours are going, and which of them can safely be handed to a tool. Six hours a week on prior auth at a $32 loaded rate is roughly $10,000 a year sitting inside one person’s calendar.
- agents on your covered stackOne workflow at a time, with your SOPs as the knowledge base and your escalation rules built in. Staff add the documents. They never have to learn to write a prompt.
- clinic ai context profileYour appeal letters open with your practice name, cite the payer policy numbers your billing team uses, and escalate to a named person. An agent built for the practice across town would get all three wrong.
- portable by designThat profile moves with you if you ever change platforms, so none of this is a lock-in. I will hand you the file whenever you ask for it.
- measured, then re-measuredBaseline before, again at 90 days, then quarterly. Hours reclaimed against loaded hourly cost. If the number does not move, you will see that too.
- sequenced, not dumpedThe first agent goes to whatever your team dreads most. The fastest way to kill adoption is starting with something nobody cared about.
what follows is one of those agents, running
./agent prior-auth --play
One agent. Forty-four seconds.
Prior authorization appeals, because the pain is obvious and the hours are easy to count. It is one of many. Watch it thinking about the task your clinic dreads most. That one works the same way.
building that did not require buying anything. it almost never does
check-coverage --interactive
You already own most of what you need.
Most clinics are one contract line and one setting away from a compliant path.
your office runs onselect one
The rule underneath all of it: the product tier determines coverage, not the brand name. The same vendor can be compliant on one plan and prohibited on another. That distinction is where most clinics go wrong, and it costs nothing to get right.
step one used to be good practice. over the last eighteen months it stopped being optional
git log --regulatory --oneline
Three of these have already happened.
Clinics adopted AI faster than anyone could regulate it. That window has closed, and most of the closing is already behind you.
- 2025-01*
California AB 3030 takes effect
Generative AI clinical communications need a disclaimer and a route to a human, unless a licensed provider reviews the message first. Scheduling, billing and reminders are exempt. Most practices using AI in the portal have never mapped which is which.
- 2025-01*
HIPAA Security Rule overhaul proposed
It would mandate annual risk analysis, universal MFA and encryption at every practice size, with no more small-practice flexibility. It is not law today.
- 2025-09*
Joint Commission and CHAI publish the framework
Responsible Use of AI in Healthcare, with playbooks and a voluntary certification program now rolling out. You do not need to be accredited to work from it, which makes it usable by an independent clinic.
- 2026-01*
Texas TRAIGA takes effect
Providers must disclose AI use in treatment, and a licensed practitioner must review AI diagnostic output and keeps final clinical authority. In Texas your disclosure language and review records are regulated artifacts now.
- HEAD>
you are here
- ~2027o
HIPAA Security Rule final expected
Not a surprise, which is why the cheap time to prepare is before it lands rather than in the ninety days after.
so: both steps, one person, every price published below
cat rate-card.txt
start here / costs nothing
AI Exposure Scorecard: FREE
30 minutes / same-day deliverable
Thirty minutes. We go through your architecture and I score it live: twelve items across tools in use, coverage, human review and training, with your three highest-risk items ranked and what each costs to fix. You keep the page the same day, hired or not.
BOOK THE SCORECARDlaunch-bundle / recommended start
Launch Bundle
govern and build, one engagement
bought separately: $10,000 / $11,900
START HERE- Everything in the Foundation Assessment
- Staff AI Training Workshop, 90 minutes, certificates on file
- Custom Clinic AI Context Profile, portable across platforms
- Your first working agents, built on the stack you already own
- Three months of Governance Partner included
- I take over your AI vendor relationships from day one
- Baseline ROI measurement so you can prove what changed
foundation-assessment
Foundation Assessment
one-time / the full audit
- Complete AI inventory, including shadow AI
- Coverage verified per tool and per product tier
- Written AI governance policy sized for your practice
- State disclosure compliance review
- Incident process and human-review rules
- Prioritized findings memo and a walkthrough
- About two hours of your staff time in total
governance-partner
Governance Partner
monthly / your fractional AI officer
Three-month term, renewing automatically. Cancel with 30 days notice before any renewal.
- Weekly leadership meeting on governance and active builds
- Named contact on your AI vendor accounts. I read the terms before renewal
- Every new tool reviewed before it touches a patient
- Continuous agent development, not a one-time handoff
- Inventory, policy and training records kept current
- Quarterly ROI re-measurement
- I answer the payer, carrier and partner AI questionnaires
- staff-ai-training$1,20090 minutes, six scenarios, quiz, certificates, break-room rule sheet.
- clinic-context-profile$1,500A structured profile of your practice, portable across platforms.
- vendor-selection-sprint$950One decision, with the coverage question answered before you sign.
- annual-reassessment$1,500What changed in your stack, and what changed in the law.
whoami --verbose
john lewis / founder
Everywhere it shouldn’t and nowhere it should are usually two different purchase orders. A compliance firm writes the policy and leaves. An AI shop builds something nobody verified. Neither one is around in month four when a vendor quietly revises their terms, and neither one answers when your carrier asks who is overseeing this.
I do both halves because they are the same job. The day work is health data operations: making sure a number traces back to the chart it came from, and that the trail holds when somebody walks it. Governance is that discipline pointed at systems that change monthly and document themselves badly. Building the agents is the same problem from the other side, deciding what a tool may do before it does it.
I came to this from inside a clinic rather than from consulting, which is why I ask how a tool behaves at 4:45 on a Friday rather than how it demos. That is usually where the split shows. The AI people rarely know what a clinic day costs. The compliance people often cannot build the thing that would fix it.
So what you are hiring is one person who reads the terms, writes the policy, trains the staff, builds the agent, and picks up the phone when your malpractice carrier asks how you oversee any of it.
- roleHealth Data Operations
- certAssessing and Implementing AI and Machine Learning in Healthcare, HIMSS
- licenseRegistered Nurse
- scopeIndependent practices, 2 to 50 providers
- modeRemote-first, Austin, TX
man clinical-ai-governance
Isn’t the free scorecard just a sales call?
Thirty minutes, and you keep the completed page the same day, hired or not. What it is not is a free full assessment. The real audit takes days, so the free version is scoped to what I can honestly do in half an hour: find the obvious exposure and tell you how big the rest looks.
Do we need to buy a new AI platform?
Usually not, and I will tell you before you pay me anything. Most clinics already pay monthly for a platform that can carry this safely once coverage is verified and it is set up properly. Buying something new is the exception, and that is what the Vendor Selection Sprint is for.
Our staff aren’t doing this. Are you sure?
I would be glad to be wrong. But nurse AI use went from 15% to 44% in a single year, and only 8% say their employer has any AI strategy. The tools are free, they are on everyone’s phone, and they solve a real problem. Nobody reports it because there is no rule saying they should and no safe alternative to switch to. That is a design problem, not a discipline problem.
Our EHR vendor says their AI is compliant. Isn’t that enough?
Vendor compliance and your compliance are different things. They are responsible for their product. You are responsible for which tier you bought, how it is deployed, who reviews the output, what staff do when it is wrong, and what you disclose to patients. It also does nothing about the consumer chatbot open in another tab.
Are you a lawyer? Is this legal advice?
No, and no. I build the operational program: inventory, coverage verification, policy, training, oversight, then the AI itself. Where a question is genuinely legal I say so and route it to counsel. My work makes those conversations shorter, because the facts are already documented.
What is a Clinic AI Context Profile?
A structured profile of your practice: services, policies, voice, guardrails, escalation rules. It loads into whichever platform you use, and it is the difference between generic output and output that sounds like your clinic. Portable, and I will hand you the file if you ask.
Will training actually change anything?
It is the highest-leverage item on the list. In the 2026 State of Nursing data, nurses whose employer trained them were far likelier to save an hour or more a day, and one in five said a tool arrived with no explanation at all. Handing people software is not deployment.
How does the Governance Partner term work?
Three months to start, then automatic renewal so nothing lapses mid-build. Cancel with 30 days notice. The floor exists because the first month is mostly setup, and governance that stops in week four is worse than not starting. By month three we are shipping agents rather than writing policy.
Do you work remotely?
Yes, remote-first by design, which keeps the fees flat. On-site is available for multi-site groups, quoted after the scorecard call.
./scorecard --free --30min
Find out what your clinic is actually running.
Thirty minutes on a call. We score your setup together, and you keep the completed AI Exposure Scorecard the same day, whether or not we ever work together.
I answer every email within one business day.