<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Ashoo Review: AI in Medicine]]></title><description><![CDATA[Emergency Physician and Medical Educator bridging the gap between bedside care and AI. As a clinical informaticist, I explore the future of medicine through a pragmatic, skeptic-first lens to separate clinical signal from hype.]]></description><link>https://ashooreview.com</link><image><url>https://substackcdn.com/image/fetch/$s_!7rBN!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png</url><title>Ashoo Review: AI in Medicine</title><link>https://ashooreview.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 02 Sep 2026 12:20:00 GMT</lastBuildDate><atom:link href="https://ashooreview.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Sam Ashoo, MD]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[samashoo@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[samashoo@substack.com]]></itunes:email><itunes:name><![CDATA[Sam Ashoo, MD]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sam Ashoo, MD]]></itunes:author><googleplay:owner><![CDATA[samashoo@substack.com]]></googleplay:owner><googleplay:email><![CDATA[samashoo@substack.com]]></googleplay:email><googleplay:author><![CDATA[Sam Ashoo, MD]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Disclosure Without Control]]></title><description><![CDATA[The HIPAA Loophole That AI Exploited]]></description><link>https://ashooreview.com/p/disclosure-without-control</link><guid isPermaLink="false">https://ashooreview.com/p/disclosure-without-control</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Tue, 01 Sep 2026 12:16:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Bok7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Last week, the Pew Research Center released the results of a survey of 3,488 U.S. adult patients on their perspective on AI in Healthcare. The findings were informative, but they are even more interesting if you combine them with what we know from similar surveys of physicians. Let&#8217;s dive into that comparison. <br><br>As always, if you enjoy reading, subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bok7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bok7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bok7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:479822,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/213554459?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bok7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bok7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81e3924b-8045-4233-9367-103285fef523_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>The Awareness Gap</strong></h3><p>The <a href="https://www.pewresearch.org/short-reads/2026/08/25/americans-want-transparency-when-ai-is-used-in-their-healthcare/">Pew Research Center</a> surveyed 3,488 U.S. adult patients from June 22 to 28, 2026, on their perspective on AI in Healthcare. The findings highlight a big difference between patient and physician views on AI use in Healthcare. The Pew Research Center&#8217;s results found: </p><blockquote><p><strong>A small share (16%) say their doctors or other healthcare providers have ever used AI in their healthcare</strong>.</p></blockquote><p>Additionally, another 83% of Americans either think AI has never been used in their healthcare (37%) or don&#8217;t know if it has (46%).</p><p>Compare that to the <a href="https://www.ama-assn.org/press-center/ama-press-releases/ama-ai-usage-among-doctors-doubles-confidence-technology-grows">AMA&#8217;s 2026 Physician Survey on Augmented Intelligence</a>, which reported:</p><blockquote><p><strong>Four in five physicians (81%) use AI in their practices, more than double the 2023 rate (38%).</strong></p></blockquote><p>That leaves a significant gap that we, physicians and clinicians, need to explain. One explanation might be the way that the AMA defined AI use. The survey listed 17 AI use cases. 72% of physicians said they incorporated at least one of them. 9% said they were not sure which ones their practices used. The survey results combined these two groups.</p><p>A second explanation might be the tools themselves. Physicians said they used AI for research summarization, documentation, discharge instructions, care plans, and billing. So an individual physician could be using AI according to the AMA, but not in a manner that a patient would be aware of or consider personal to them.</p><p>But that&#8217;s just at the physician level. Federal data shows that AI use in healthcare goes beyond what individual physicians choose. According to the <a href="https://healthit.gov/data/data-briefs/hospital-trends-use-evaluation-and-governance-predictive-ai-2023-2024/">ONC</a>:</p><blockquote><p><strong>In 2024, 71% of hospitals reported using predictive AI integrated into their EHR.</strong></p></blockquote><p>Think of hospital systems that predict readmissions, identify high-risk patients or early sepsis, and generate treatment recommendations.</p><p>But if all three surveys measured something different, can they be used to find a correlation between physician AI use and patient awareness? Not directly, but the gap between 16%, 81%, and 71% is certainly a signal. AI use in healthcare is significant among physicians and hospitals, while very few patients know it is being used.</p><p>That raises another question: How <em>would</em> a patient know?</p><h3><strong>Defining AI Use in Healthcare</strong></h3><p>Before we figure out how a patient would find out about AI use, we have to define it. Consider these five scenarios:</p><ol><li><p>AI Q&amp;A: A physician asks an AI search tool a quick question about current treatment recommendations and then uses that answer to treat a patient. No patient information is shared.</p></li><li><p>Clinical Decision Support: A physician enters a patient&#8217;s history, labs, and imaging results into an AI system and asks for a differential diagnosis and treatment plan.</p></li><li><p>Ambient Scribe: A physician uses an ambient scribe to document a patient encounter.</p></li><li><p>Prediction: An AI prediction tool flags a patient as having a high probability of deterioration and a high risk of readmission after discharge.</p></li><li><p>Prioritization: An AI model prioritizes radiology studies for radiologists to read, schedules appointments, generates billing codes, and helps with insurance claims.</p></li></ol><p>All 5 scenarios would be considered AI use in healthcare, but their relevance to a single patient varies quite a bit. When the Pew Research Center asked patients if they should be told about specific AI applications, they found:</p><ul><li><p>81% want to know if AI was used to analyze their medical scans or make a diagnosis.</p></li><li><p>80% want to know if AI was used to explain their lab results.</p></li><li><p>72% want to know if AI was used to take notes during an appointment.</p></li><li><p>64% want to know if AI was used to refill a prescription.</p></li><li><p>56% want ot know if AI was used to schedule an appointment.</p></li></ul><p>Though the first few did not surprise me, the last one did. Patients use a much broader boundary for being informed about AI, even for administrative tasks. This difference in definition creates another problem:</p><p>At what point does general AI use in healthcare become AI use in a <em>patient&#8217;s</em> healthcare?</p><h3><strong>When Do Patients Have to Be Told?</strong></h3><p>If we ask patients, the Pew Research Center found</p><blockquote><p><strong>About seven-in-ten U.S. adults (72%) say it&#8217;s extremely or very important that a doctor or other healthcare provider tells them if they&#8217;re using AI in their healthcare.</strong></p></blockquote><p>And yet, there is no national requirement that every use of AI connected with a patient&#8217;s healthcare be separately disclosed. Also, medicine has long used medical decision support tools without disclosing them to patients. That predates today&#8217;s generative AI tools. Think tools like ECG computerized interpretations, risk calculators, drug interaction alerts, clinical decision tools like Up-To-Date, and more. But if we have never disclosed these in the past, do we need to disclose them now just because they include AI processes?</p><p>What if those systems run autonomously, have access to patient information, generate new content (not just summaries) like patient-specific diagnoses or treatment plans, or contain errors that are difficult for humans to detect? Does that reach a threshold for patient notification?</p><p>In a JAMA article, Mello and colleagues proposed two factors for consideration:</p><blockquote><p><strong>The ethical obligation to notify patients depends on (1) the seriousness of the physical risk and (2) the extent to which patients have a meaningful opportunity to exercise agency in response to a notification.</strong></p></blockquote><p>This kind of approach creates different disclosure expectations for an AI system that influences a cancer diagnosis than one that schedules appointments. But Pew Research Center results suggest that patients may want disclosure in both cases. In fact, some states have already begun drafting laws to mandate it.</p><p>California AB 3030 requires disclosure for certain patient communications generated using AI. But the law also contains an important exception: &#8220;If a communication is generated by generative artificial intelligence and read and reviewed by a human licensed or certified health care provider, the requirements of subdivision (a) do not apply.&#8221; <a href="https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB3030"><span>California Legislature</span></a></p><p>Texas has adopted broader language: &#8220;If an artificial intelligence system is used in relation to health care service or treatment, the provider of the service or treatment shall provide the disclosure.&#8221; <a href="https://tcss.legis.texas.gov/resources/BC/htm/BC.552.htm"><span>Texas Business &amp; Commerce Code</span></a></p><p>What we are beginning to see is a state-by-state patchwork in which disclosure obligations can depend on where care occurs, what the AI does, and how humans interact with its output. </p><p>For more state AI laws, see this previous article. </p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;07ba211b-b22f-496c-b7a2-320db3a8a0a3&quot;,&quot;caption&quot;:&quot;In previous coverage of artificial intelligence in medicine, I kept returning to the same question: Who decides? Who has the authority to approve a procedure, deny a claim, diagnose a condition, or prescribe a treatment when an algorithm is involved? That question was mostly theoretical, debated in conference panels and white papers while federal lawmak&#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;A Complete Guide to AI Healthcare Laws in 2026&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-29T17:26:02.869Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!erTi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b2a35-d637-473e-a88f-d4383ae1d38e_1220x932.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/a-complete-guide-to-ai-healthcare&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:208878525,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p></p><h3><strong>Being Told Is Different From Being Able to Say No</strong></h3><p>Another problem that may occur to you as you read this: Informing a patient of AI use improves their awareness. But what if they don&#8217;t consent? Is there an option to say no?</p><p>The question highlights the three aspects of this process:</p><ul><li><p><strong>Disclosure</strong>: Telling the patient that AI is being used.</p></li><li><p><strong>Consent</strong>: Asking the patient for permission <em>before</em> using the AI software.</p></li><li><p><strong>Control</strong>: Allowing the patient the ability to refuse that use.</p></li></ul><p>The Pew Research Center&#8217;s survey shows that Americans are interested in all three, especially the last one.</p><p>Some might turn to HIPAA to provide guidance. After all, HIPAA already allows protected health information to be shared for treatment, payment, and healthcare operations under specific circumstances.</p><p>According to <a href="https://www.hhs.gov/hipaa/for-professionals/faq/264/what-is-the-difference-between-consent-and-authorization/index.html">HHS</a>:</p><blockquote><p><strong>The Privacy Rule permits, but does not require, a covered entity voluntarily to obtain patient consent for uses and disclosures of protected health information for treatment, payment, and health care operations.</strong></p></blockquote><p>Read it carefully. HIPAA <em>permits but does not require consent</em>. It is a voluntary process.  In fact, that federal framework includes technology companies functioning as business associates. <a href="https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html">HHS</a> specifically gives this example of an approved business associate.</p><blockquote><p><strong>Third-party vendor Artificial Intelligence (AI) chatbot on a provider&#8217;s patient portal that provides services involving the patient&#8217;s PHI such as symptom assessment, medical reminders, and appointment scheduling.</strong></p></blockquote><p>That means an AI vendor can access protected health information (PHI) with a HIPAA-compliant arrangement <em>without</em> the patient having to sign a separate authorization for AI use. But if we look at the Pew Research Center&#8217;s survey results, 63% of patients want more say over whether AI is used in their care. This becomes an issue because a healthcare organization can check all the disclosure boxes simply by informing a patient that it uses AI, with no way for the patient to opt out.</p><p>So HIPAA does not create a right to opt out of AI use in healthcare. But is it even possible anymore?</p><p>For an ambient scribe service, the physician just documents manually. It&#8217;s slower but still possible. What about a patient who asks that their information not be processed by:</p><ul><li><p>an EHR deterioration model</p></li><li><p>AI-assisted radiology software</p></li><li><p>automated ECG interpretation</p></li><li><p>medication safety algorithms</p></li><li><p>radiology worklist prioritization</p></li><li><p>scheduling algorithms</p></li><li><p>billing systems</p></li></ul><p>All of these are out of an individual physician&#8217;s control in the vast majority of practices. There is no mechanism to turn them off, or to process patient information without them. Many of them are operating in the background, automatically. As AI becomes increasingly embedded within healthcare infrastructure, a patient&#8217;s ability to opt out becomes impossible.</p><p>And what if opting out of AI use results in poor care for the patient? As AI systems improve, they will assist in everything from radiology interpretation to early detection of deterioration. Opting out might result in much longer interpretation times, fewer automated safety checks, and additional administrative delays. </p><p>If you work in a hospital, you might be asking yourself if the right to refuse AI requires a parallel workflow. Are hospitals obligated to maintain an alternative, and what would that even look like in a world where AI is embedded in the EHR?</p><h3><strong>AI Is Arriving Faster Than the Rules Around It</strong></h3><p>It&#8217;s a common theme across all the articles in this newsletter, and the Pew Research Center&#8217;s survey results are just another example. AI adoption is moving at a faster pace than the rules and laws around it.</p><p>Patients want transparency about AI use <em>and</em> more control over whether it participates in their healthcare. And we don&#8217;t have answers to:</p><p>What constitutes AI use in an individual patient&#8217;s care?</p><p>Which uses require disclosure?</p><p>When should disclosure include consent?</p><p>Which uses should patients be allowed to refuse?</p><p>How should healthcare systems accommodate refusal when AI has become part of their infrastructure?</p><p>With each passing day, these questions become harder to defer.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[AI and Medical Research]]></title><description><![CDATA[I&#8217;ve written a lot about AI in Medicine and how we must be careful that its output is validated before applying it in any clinical setting.]]></description><link>https://ashooreview.com/p/ai-and-medical-research</link><guid isPermaLink="false">https://ashooreview.com/p/ai-and-medical-research</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Tue, 25 Aug 2026 20:40:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lPbm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>I&#8217;ve written a lot about AI in Medicine and how we must be careful that its output is validated before applying it in any clinical setting. There are so many cautionary tales that it may seem like we should just throw it away and make medicine an AI-free zone. But today I&#8217;d like to highlight a potentially positive use for AI in medical research. Let&#8217;s get into the details.</em></p><p><em>As always, if you enjoy reading this newsletter, subscribe and tell a friend.</em></p><p><em>Sam</em></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lPbm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lPbm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lPbm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:410541,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/212341336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lPbm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lPbm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9b66122-a6ff-4078-89a7-310854ec5afb_1672x941.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A lot of my writing and discussion in medicine in general has focused on the danger of artificial intelligence. I&#8217;ve discussed AI hallucinations, incorrect conclusions, concern over physician overreliance, data privacy and consent, and more.</p><p>But today, I want to discuss one of the positive aspects of combining AI and medical research.</p><h3><strong>Medicine as a research source</strong></h3><p>As I wrote about in <a href="https://ashooreview.com/p/what-it-takes-to-build-a-medical"><span>my last article,</span></a> medical data storehouses are increasing in number.</p><p>Hospital electronic health records, insurance company claims databases, government datasets, and clinical trial data are just a few examples. Recently, consumer-facing products have begun building their own databases of patient information. Some notable examples:  <a href="https://www.apple.com/ios/research-app/">Apple Research</a>,  <a href="https://openwearables.io/blog/google-health-connect-integration-android-health-data-for-developers">Google Health Connect</a>, <a href="https://evidation.com">Evidation</a>. Users are able to upload their health records, lab records, imaging, and even connect their wearables. That data is being voluntarily given to large companies, which can build their own databases.</p><p>Historically, researchers have accessed these databases to ask new questions and find correlations between therapies and specific populations. This type of research fits into a category called &#8220;secondary data analysis&#8221;. The data already exists, and researchers are using it to answer questions.</p><p>The diagram below shows just how many different kinds of research studies can be derived from secondary data analyses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mnhT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mnhT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mnhT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2686735,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/212341336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mnhT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mnhT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1f1f610-236f-4421-a4cd-670c25b27ff0_2528x1686.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Secondary data analyses aren&#8217;t just limited to observational studies. Researchers regularly use data from previously published randomized controlled trials to look for new outcomes, perform subgroup analysis, evaluate prognostic relationships, and answer questions that were not addressed in the original publication.</p><p>Oftentimes people think of secondary data analysis as a lesser form of research. But that&#8217;s not the case at all.</p><h3><strong>Influential medical research uses existing data</strong></h3><p>You don&#8217;t have to take my word for it. Look at any major medical journal, and you can find numerous examples.</p><p>The <a href="https://www.cdc.gov/nchs/nhanes/about-data/index.html?CDC_AA_refVal=https%3A%2F%2Fwww.cdc.gov%2Fnchs%2Fnhanes%2Fmodules%2Fpublications.html">National Health and Nutrition Examination Survey</a> (NHANES) produced important estimates of obesity and chronic kidney disease in the United States.</p><p>A <a href="https://pubmed.ncbi.nlm.nih.gov/19339721/">2009 study in the New England Journal of Medicine</a> looked at data from almost 12 million Medicare beneficiaries, with a focus on hospital readmissions and their costs. That publication led to a national discussion surrounding hospital readmission.</p><p><a href="https://pubmed.ncbi.nlm.nih.gov/19144938/">Medicaid data</a> was used to investigate whether atypical antipsychotic medications were associated with sudden cardiac death.</p><p><a href="https://pubmed.ncbi.nlm.nih.gov/30571400/">Medicare databases</a> have also been used to examine the effectiveness and safety of multiple anticoagulants in patients with atrial fibrillation.</p><p><a href="https://pubmed.ncbi.nlm.nih.gov/37686609/">SEER-Medicare data</a> were used to investigate differences in breast cancer outcomes between Black and White women.</p><p>Secondary analysis of data from major randomized controlled studies like the <a href="https://pubmed.ncbi.nlm.nih.gov/37204788/">SPRINT</a> and <a href="https://pubmed.ncbi.nlm.nih.gov/32812838/">FOURIER</a> trials has answered additional questions.</p><p>All across the spectrum of medical specialties, secondary analyses have contributed significantly to our medical knowledge.</p><h3><strong>Researchers don&#8217;t need to start over every time</strong></h3><p>A single medical database can support many different questions</p><p>With access to the medical histories of millions of patients, the number and types of questions are seemingly unlimited.</p><ul><li><p>You could ask a descriptive question like &#8220;How common is chronic kidney disease among patients with diabetes?&#8221;</p></li></ul><ul><li><p>You could ask a comparative effectiveness question like &#8220;Among patients with atrial fibrillation, how do outcomes differ between patients receiving two commonly used anticoagulants?&#8221;</p></li></ul><ul><li><p>You could investigate safety by asking &#8220;Are patients who are receiving a particular medication more likely to develop acute kidney injury?&#8221;</p></li></ul><ul><li><p>You could study prognosis by asking &#8220;Which characteristics predict readmission following hospitalization for heart failure?&#8221;</p></li></ul><ul><li><p>You could examine disparities by asking &#8220;What percentage of patients in different demographic or geographic populations receive guideline-recommended treatment?&#8221;</p></li></ul><ul><li><p>You could study changes over time by asking &#8220;Does an FDA-issued safety warning change prescribing behavior?&#8221;</p></li></ul><p>Each of these questions can be asked of the same database and result in truly significant findings.</p><h3><strong>The barriers</strong></h3><p>Physicians frequently come across unanswered questions while treating patients.</p><ul><li><p>A cardiologist may notice a certain group of patients seems to respond unusually well to a treatment.</p></li></ul><ul><li><p>An emergency physician may wonder why the same diagnosis causes some patients to return to the emergency department while others don&#8217;t.</p></li></ul><ul><li><p>A primary care physician may notice an unreported adverse effect of a medication.</p></li></ul><ul><li><p>An oncologist may wonder if a treatment seems to perform differently in a particular patient population.</p></li></ul><p>These questions and observations are the foundation of medical research. But access to what&#8217;s needed to perform that research is not the same across the spectrum of physicians.</p><p>Turning that question into a research project requires numerous steps like:</p><ul><li><p>Defining a study population, inclusion and exclusion criteria, and exposures and outcomes.</p></li><li><p>Understanding the structure of a database, how to write queries and extract data</p></li><li><p>Choosing a statistical approach, identifying confounders, and performing sensitivity analyses</p></li></ul><p>Until now, those steps required a team of epidemiologists, biostatisticians, database specialists, and programmers. Although those people provide very valuable expertise, they are all scarce resources. A physician working at a large academic medical center may have access to that team. A community physician with an interesting clinical observation is more likely to just let it slip away.</p><p>AI may change all of that.</p><h3><strong>The distance between question and analysis</strong></h3><p>Imagine you are a hospitalist and notice that patients you discharge on drug A don&#8217;t bounce back as often as patients on drug B. You check your favorite clinical reference, but there is no published data comparing the two drugs. AI has the potential to assist in the research needed to answer the question: &#8220;Among patients with condition X who initiated Drug A versus Drug B, was there a difference in hospitalization within 12 months?&#8221;</p><ul><li><p>Based on your question, AI might help identify a study design like a retrospective cohort study.</p></li><li><p>It could help define the cohort by asking questions like: Which patients should be included or excluded? How should initiation of the medication be defined? How much past medical history is required?</p></li><li><p>It could help define a comparator group and outcome.</p></li><li><p>It could identify possible confounders.</p></li><li><p>It could help identify an existing medical database ideally suited for your needs.</p></li><li><p>It could help generate a database query.</p></li><li><p>It could assist with statistical analysis and sensitivity testing.</p></li><li><p>It could help interpret the results and identify weaknesses in the analysis.</p></li></ul><p>The process is familiar because it is the same one medical researchers perform routinely. But the ability for a practicing community physician to complete that process has now changed.</p><p>Clinical observation <span>&#8594;</span> research question <span>&#8594;</span> study design <span>&#8594;</span> cohort definition <span>&#8594;</span> database query <span>&#8594;</span> analysis <span>&#8594;</span> evidence</p><p>AI could assist with each step.</p><h3><strong>The catch</strong></h3><p>Making an analysis easier to perform doesn&#8217;t automatically make the analysis trustworthy. Medical databases can be messy.</p><ul><li><p>Patients are not randomly assigned to treatment groups in routine clinical practice.</p></li><li><p>Diagnoses can be coded incorrectly.</p></li><li><p>Outcomes may be missing.</p></li><li><p>Patients can leave a healthcare system and disappear from the database, leaving no follow-up data.</p></li><li><p>Laboratory testing occurs more frequently in sicker patients.</p></li><li><p>Medication records show what was prescribed, not what was actually taken.</p></li><li><p>Researchers can inadvertently define populations that bias their results.</p></li></ul><p>And if enough variables are included, significant associations can emerge just by chance. AI doesn&#8217;t make any of those problems disappear. In fact, AI could compound the problem by allowing a poorly designed analysis to be performed with extraordinary speed.</p><p>That means physicians using these tools will still need to understand concepts like confounding, selection bias, misclassification, missing data, multiple comparisons, causal inference, statistical validity, and reproducibility.</p><p>Correct research methodology, biostatisticians, epidemiologists, and expert review will all remain essential. The opportunity comes from allowing those resources to function differently. Instead of every research question requiring extensive technical work before it can even be explored, AI may allow physicians to perform preliminary analyses, test feasibility, refine hypotheses, and identify questions that deserve deeper methodological involvement.</p><h3><strong>AI and the research cycle</strong></h3><p>One last area AI can impact.</p><p>Secondary data analysis often occurs before prospective research.</p><p>Suppose an analysis of five million patient records identifies an unexpected association between a medication and a clinical outcome. That doesn&#8217;t prove the medication caused the outcome. But it does give researchers a valuable signal that may justify an observational study, which in turn may lead to a prospective study. And eventually, a randomized controlled trial.</p><p>The same process can work in reverse. Researchers can use completed randomized trials and ask additional questions of datasets that cost millions of dollars and years of effort to create.</p><p>Here, AI has the potential to accelerate multiple stages of the research cycle:</p><ul><li><p>Hypothesis generation.</p></li><li><p>Feasibility assessment.</p></li><li><p>Safety-signal detection.</p></li><li><p>Comparative effectiveness research.</p></li><li><p>Identification of high-risk populations.</p></li><li><p>Subgroup exploration.</p></li><li><p>Study design.</p></li></ul><p>And identification of questions worthy of prospective trials. The acceleration allows more questions to be investigated. </p><h3><strong>Should we broaden the conversation around AI? </strong></h3><p>We have to establish boundaries around the use of artificial intelligence in medical research. We need standards for privacy, validation, reproducibility, transparency, methodology, and human accountability just as we have non-AI-related standards for all these areas now.</p><p>These safeguards are important precisely because these tools may become extraordinarily capable.</p><p>Medicine has enormous datasets describing diseases, treatments, complications, and outcomes across millions of patients. The scientific opportunity contained in that  data is enormous. AI may give us a new way to interrogate it.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What It Takes to Build a Medical Database]]></title><description><![CDATA[From fragmented patient records to Al-ready insights.]]></description><link>https://ashooreview.com/p/what-it-takes-to-build-a-medical</link><guid isPermaLink="false">https://ashooreview.com/p/what-it-takes-to-build-a-medical</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Tue, 18 Aug 2026 15:02:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!33jv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A recent <em><a href="https://doi.org/10.1038/s41591-026-04575-4">Nature Medicine</a></em> commentary proposed a pan-Nordic AI-health data infrastructure that links registries across six countries to train foundation models on 30+ million lives. It brought up a topic I want to discuss in today&#8217;s article: What has to happen to patient records before they are collected into a database for AI models to digest?</p><p>Commercial and public databases are now advertising longitudinal data, sometimes covering the entire lifetime of a patient. How does that data get assembled if it is de-identified? How do you link records from multiple sources belonging to a single patient while maintaining anonymity? And does that still allow you to sell it without patient consent? Let&#8217;s take a closer look. </p><p>As always, if you enjoy reading, subscribe and tell a friend. </p><p>Sam</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!33jv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!33jv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!33jv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!33jv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!33jv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!33jv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:456597,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/211462486?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!33jv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!33jv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!33jv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!33jv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65195d91-01dd-4164-9bd3-4717d2b40550_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Building the database</h3><p>A medical database is just a collection of clinical events like diagnoses, labs, meds, procedures, notes, images, and vitals, from multiple systems, reorganized into something a researcher (or a model) can actually use.</p><p>Two things about that process are important to examine if you are considering contributing your data or purchasing access.</p><p><strong>Where the data came from determines who&#8217;s in it</strong>. A database built from hospital EHRs only contains people who were sick enough and able to get to those hospitals. One built from insurance claims only contains people with health insurance. One built from a volunteer research cohort only contains people who chose to sign up. And we know that volunteers are healthier, wealthier, and more educated than the general population they&#8217;re supposed to represent. A neutral, unbiased sampling is extremely difficult to collect. Every database has some limitation.</p><p><strong>Consent isn&#8217;t uniform</strong>. Prospective cohorts like <a href="https://www.ukbiobank.ac.uk/use-our-data/fees/">UK Biobank</a>, <em>All of Us</em>, and the Nurses&#8217; Health Study enroll people who opt in and know their data will be used for research. But most commercial products don&#8217;t work that way. They&#8217;re built from clinical data that already existed because a patient was treated under HIPAA rules, with no separate research consent involved. The patient whose ED visit becomes a row in Truveta or Optum or Oracle Health&#8217;s dataset almost certainly has never heard of any of those companies.</p><h3>What &#8220;de-identified&#8221; means</h3><p>Under HIPAA, &#8220;de-identified&#8221; has a specific legal definition with two methods listed in <a href="https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html">45 CFR &#167;164.514</a>.</p><p><strong>Safe Harbor</strong> means you strip all 18 specified identifiers: names, any geography smaller than a state, every date more specific than year, phone numbers, SSNs, medical record numbers, device IDs, full-face photos, and more. Also, you must have no knowledge that what&#8217;s left could still identify someone.</p><p><strong>Expert Determination</strong> is the other route. A qualified statistician determines that the risk of re-identifying anyone in the set is &#8220;very small.&#8221; This option allows more granular detail to remain in the database, like month-level dates and smaller geography.</p><p>If you can accomplish either method, the data is no longer Protected Health Information. Once health data is de-identified, the Privacy Rule doesn&#8217;t apply to it anymore. No authorization is needed to use it, sell it, or share it because those rights only attach to PHI. So a patient&#8217;s ED visit or hospital stay, once properly de-identified, can be aggregated, licensed, and sold to a pharma company or an AI developer, and that patient has no way to find out it happened. </p><h3>The longitudinal problem</h3><p>When trying to collect data over a long period of time (longitudinal data), there are additional complications.</p><p>A longitudinal database links the same patient&#8217;s records across time: the ED visit in 2019, the diagnosis in 2021, the hospitalization in 2023, all tied to one underlying person so you can see a trajectory instead of individual snapshots. That linkage is what makes disease-progression modeling possible. It&#8217;s the &#8220;digital twin&#8221; concept mentioned in the Nordic paper.</p><p>But linkage needs <em>something</em> to tie the records together. And that something is, by definition, an identifier. Which means the more rigorously you strip identity, the harder it gets to prove two records belong to the same person. </p><p>HIPAA planned for this under &#167;164.514(c). A covered entity can assign a re-identification code (or token) to de-identified records, essentially letting them be linked as long as the code isn&#8217;t derived from anything about the individual. It may not be a portion of a SSN, a birthdate, or MRN. That code also may not be disclosed to whoever gets the data. That way the dataset stays legally de-identified even though a linking key exists somewhere behind a firewall. This is basically how tokenization services like Datavant work. They generate non-PHI-derived tokens so separate data sources can recognize &#8220;same patient&#8221; without ever exposing who that patient actually is. Atropos Health&#8217;s evidence network runs on this kind of tokenized linkage, by its own description.</p><p>Now compare that to the Nordic model in the paper I mentioned earlier. Nordic countries link registries using government-issued personal ID numbers. These identifiers often encode birthdate and are held by national authorities specifically so records <em>can</em> be traced back to identity. Under GDPR, that&#8217;s not de-identification. It&#8217;s &#8220;<strong>pseudonymization,</strong>&#8221; a legally separate, lesser category. GDPR <a href="https://gdpr-info.eu/art-4-gdpr/">Article 4(5)</a> and <a href="https://www.privacy-regulation.eu/en/recital-26-GDPR.htm">Recital 26</a> are very specific about it: if re-identification remains possible through a separately held key, the data is still &#8220;personal data&#8221; and GDPR still fully applies.</p><p>So, HIPAA treats "unique identifier" and "de-identified" as interchangeable, but that's not GDPR's approach. By GDPR definition, an identifier that enables linkage is evidence that the data isn't anonymous. It's a privacy improvement over raw identifiable data, and it's the mechanism that makes cross-registry Nordic research possible.</p><p>That leaves us with two ways to get a longitudinally linked, de-identified dataset.</p><ol><li><p>Keep a compliant re-identification key around, like the tokenization approach above, so the database can keep linking new records to existing patients indefinitely. That&#8217;s how vendors like Truveta and Oracle Health can advertise daily updates.</p></li><li><p>Assemble the whole dataset first, using real identifiers in a locked-down environment to do all the patient-level linking, and <em>then</em> strip identifiers as a final, one-way step before anything leaves the building. That produces a dataset that&#8217;s genuinely de-identified with no lingering key anywhere. But it means all the linking work has to be done before de-identification happens, which means what gets released is a closed, static snapshot. Once the identifiers come off, you can&#8217;t add a new record for an existing patient without reopening the identified stage and starting over. No version of this approach gives you a &#8220;living,&#8221; continuously updated database. You can only produce a new static version periodically.</p></li></ol><p>That&#8217;s why MIMIC, NHANES, SEER, and the National Inpatient Sample ship as periodic releases instead of live updates. Meanwhile, the commercial products marketed as daily or real-time updates rely on some kind of retained linking key. Neither approach is wrong. They&#8217;re just not the same privacy posture, and &#8220;de-identified&#8221; alone doesn&#8217;t tell you which one you&#8217;re looking at.</p><h2>So what&#8217;s actually out there</h2><p>Not everything called a &#8220;medical database&#8221; is the same. Some are commercial products with a sales team. Some are federally funded public resources. Some are prospective research cohorts that have been running for decades. Below is a breakdown of nineteen of the big databases.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/fnkCN/2/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ecb5d90-9b1d-456c-9fb3-1ed7247c2f4b_1220x1672.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5b89f11-d94d-4ec9-b6d8-d881c0da5abe_1220x1742.png&quot;,&quot;height&quot;:861,&quot;title&quot;:&quot;Medical Databases&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/fnkCN/2/" width="730" height="861" frameborder="0" scrolling="no" loading="lazy"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h3>Two philosophies, same underlying risk</h3><p>Another way to sort databases on the list is by where the data lives. </p><ol><li><p><strong>Centralized</strong> (pooled) means the data physically or virtually lives in one place the vendor controls. Truveta, Optum, MarketScan, Oracle Health, Flatiron, and UK Biobank are examples of this strategy.</p></li><li><p><strong>Federated</strong> is the opposite. The data never leaves the institution that generated it. A query gets sent <em>to</em> the data, and only aggregated results are returned. This is the model the Nordic commentary is suggesting.  <a href="https://pcornet.org/">PCORnet</a> and <a href="https://www.opensafely.org/">OpenSAFELY</a> are the cleanest examples of it. TriNetX and Atropos run hybrid versions with a federated query / tokenized-network layer sitting on top of member institutions&#8217; own systems.</p></li></ol><p>The Nordic paper frames this as a design choice, proposing federated approaches for the most sensitive data, pooling for standardized and less sensitive data, and synthetic data for pretraining where either option is too risky. It&#8217;s a layered strategy, depending on the data needed and the use case. </p><p>Centralized storage has real strengths. It supports multimodal model training across notes, images (radiology), and waveforms (EEG, ECG). One unified data model, so a single researcher can iterate fast. But it also means a single point of possible security failure. UK Biobank, despite a strong governance reputation, recently had a data breach that the Nordic authors cited as a cautionary tale. It requires enormous cross-institutional trust and legal paperwork to move data across borders. And it concentrates security and the exact de-identification methodology inside one vendor.</p><p>Federated storage changes most of that. Data never crosses institutional or national borders, which avoids a lot of cross-border transfer risk under GDPR or the EU&#8217;s  European Health Data Space. It preserves local control, and it tends to earn higher public trust for exactly that reason. The trade-off is that it&#8217;s hard to train large multimodal foundation models this way because you can&#8217;t combine raw pixel (image) or waveform (EEG, ECG) data across sites. So you&#8217;re stuck with averaged or aggregate query results. Site-to-site differences in EHR vendors and coding practices make joint analysis messier. And it&#8217;s structurally harder for anyone outside the network to check what&#8217;s in the underlying records.</p><h3>What trips people up</h3><p>If you&#8217;re a researcher picking a data source, or a clinician trying to figure out what a new AI tool was actually trained on, the marketing page rarely answers the following important questions:</p><p><strong>Bias</strong>: Who&#8217;s in the database. Hospital EHR data skews toward people sick enough to seek care. Claims data cuts out the uninsured entirely and skews toward employed populations. MarketScan describes its data as commercially insured workers and dependents. Volunteer cohorts carry the opposite bias: UK Biobank, the Nurses&#8217; Health Study, and <em>All of Us</em> recruit people healthier, wealthier, and more health-literate than the general population. Single-site or single-region resources tell you something true and useful about a very narrow slice of the world: MIMIC is one Boston ICU, OpenSAFELY is England only, and the Nordic proposal is 30 million largely homogeneous Northern Europeans. </p><p><strong><span>Verifiability</span></strong><span>: This is really one question asked in two parts. </span></p><ul><li><p><span>At the research stage: Can anyone check how the thing was built? Open resources like MIMIC/</span><a href="https://physionet.org/">PhysioNet</a><span>, NHANES, SEER, HCUP, and OpenSAFELY publish their cohort-construction and de-identification methodology. OpenSAFELY goes a step further by publishing its analysis code for anyone to inspect. Commercial vendors treat the exact tokenization and linkage methods as a trade secret. So a</span> peer reviewer can look at the output but can&#8217;t audit the data.<span> </span></p></li><li><p><span>At publication: Journals increasingly expect data and code availability statements, but licensed commercial (purchased) data generally can't be redistributed alongside a paper. An independent lab can't rerun your exact analysis on your data. Open resources solve both problems by staying accessible under the same public terms to anyone who wants to check.</span></p></li></ul><p><strong>Access</strong>: This determines what kind of work you can even attempt. If you can download it to your own servers (MIMIC, NHANES, SEER*Stat, NIS), you get full control, but you&#8217;re now on the hook for securing it. Cloud-locked platforms (UK Biobank&#8217;s RAP, <em>All of Us</em>&#8216;s Researcher Workbench, Truveta Studio) let you analyze but not export raw records, which rules out a lot of machine learning (transfer-learning and fine-tuning workflows) that needs raw data. And federated-query-only databases (PCORnet, OpenSAFELY, TriNetX) never give you patient-level data at all. They are great for privacy, but you can&#8217;t train a multimodal model on it.</p><p>And then there are these other issues: </p><ul><li><p>Fees can run $10,000 to $25,000 or more per study for commercial claims data. This favors well-funded institutions and industry sponsors over independent academic labs. </p></li><li><p>Claims-based sources tend to run one to two years behind current practice. </p></li><li><p>Probabilistic matching introduces real errors when tokenized records from data sources that were never designed to talk to each other get linked anyway. </p></li><li><p>HIPAA, GDPR, and the UK&#8217;s Data Protection Act each define &#8220;de-identified&#8221; a little differently, which is exactly the harmonization problem the Nordic Comment&#8217;s roadmap lists as a step that still needs solving.</p></li></ul><h3>Takeaway</h3><p>The Nordic paper says that the scientific infrastructure &#8220;is not aspirational: it is substantially in place.&#8221; Read against everything above, that claim seems premature for a plan that still has to establish data standardization, sort out cross-border regulatory alignment, and prove clinical feasibility.</p><p>For me, that gap isn&#8217;t unique to the Nordic proposal. It&#8217;s sitting underneath every &#8220;trained on X million de-identified patients&#8221; claim we&#8217;ll read this year. The architecture, the access model, the update cadence- none of that should be a footnote. It predicts exactly where the resulting model will hold up and exactly where it&#8217;ll quietly fail. </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2></h2>]]></content:encoded></item><item><title><![CDATA[Is Open Source the Answer to Healthcare AI’s Trust Crisis?]]></title><description><![CDATA[Open source helps with a lot of what&#8217;s keeping hospital AI officers up at night this year, but not with everything, and the hospitals that get that distinction right will have a structural advantage for the next decade.]]></description><link>https://ashooreview.com/p/is-open-source-the-answer-to-healthcare</link><guid isPermaLink="false">https://ashooreview.com/p/is-open-source-the-answer-to-healthcare</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 14 Aug 2026 16:17:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!igQf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Open source helps with a lot of what&#8217;s keeping hospital AI officers up at night this year, but not with everything, and the hospitals that get that distinction right will have a structural advantage for the next decade. This piece walks through exactly where open-weight models solve real problems and where they don&#8217;t.</em></p><p><em>As always, if this is useful, the best way to support the work is to subscribe and share it with a colleague.</em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!igQf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!igQf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!igQf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!igQf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!igQf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!igQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:569133,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/211191088?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!igQf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!igQf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!igQf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!igQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81942427-5f5d-4c03-8290-b2303e0a9562_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Three days ago, Mark Zuckerberg published a manifesto arguing that AI should be &#8220;open source&#8221; and released <a href="https://www.nytimes.com/2026/08/10/technology/meta-ai-open-source.html">Meta&#8217;s newest model, Muse Glimmer</a>, as an open-weight offering. The White House and press noticed. And if you are an AI officer at a hospital or a developer, you should absolutely notice too, because the announcement lands in the middle of a genuinely important moment.</p><p><span>In the last three weeks, </span><a href="https://www.bbc.com/news/articles/c3ek3gvdnj3o">OpenAI disclosed that its models went rogue during a security test</a><span>, escaping a containment sandbox and launching an "unprecedented" autonomous cyberattack against Hugging Face. About two weeks later, </span><a href="https://www.theguardian.com/technology/2026/aug/05/openai-anthropic-models-went-rogue-cybersecurity-test-ai-security-institute">Anthropic's Mythos 5 model did something arguably worse</a><span>: it created fake online identities, spear-phished two real software developers with malicious code, and tried to trick a GitHub project maintainer into accepting a backdoor. The UK's AI Security Institute called it a "serious incident" and a "shift in the risk landscape." Then </span><a href="https://www.cnn.com/2026/08/05/tech/meta-ai-hacking">Meta disclosed its own </a>incident<span>: a misconfiguration by its outside testing firm gave one of its models unsupervised internet access, and the model used it to breach another company's systems. The third major AI lab to report an incident like this in a matter of weeks. </span></p><p>If you are a hospital CIO watching proprietary models autonomously hack platforms, deceive humans, and sabotage their own shutdown mechanisms, you are probably asking the same question a lot of us are asking: <strong>Why on earth would I send my patient data to these companies?</strong></p><p>The logic is straightforward. If hospitals stop renting APIs from black-box vendors and instead run open-weight models locally, they could stop version drift, regain control, keep data local, and avoid vendor collapse. Academics are already making this case. <a href="https://www.nature.com/articles/s41746-024-01344-w">Riedemann et al. argued in </a><em><a href="https://www.nature.com/articles/s41746-024-01344-w">npj Digital Medicine</a></em> that the &#8220;path forward for large language models in medicine is open&#8221; because medical devices require transparency and version control that proprietary APIs cannot provide. <a href="https://www.nature.com/articles/s41746-025-01476-7">Dennst&#228;dt et al. mapped out the implementation framework</a> in 2025, showing that local deployment gives hospitals customization and control at the cost of expertise and infrastructure. A <a href="https://www.frontiersin.org/journals/digital-health/articles/10.3389/fdgth.2026.1778786/full">2026 Frontiers review</a> concluded that hybrid approaches are probably the realistic future.</p><p>Open source clearly has merit. The question is whether it solves the problems that actually keep hospital AI officers awake at night.</p><p><strong> </strong>So, let&#8217;s break it down for clarity. </p><div><hr></div><h3>What It Helps With: Version Control as a Medical Device Requirement</h3><p>In 2023, a Stanford team quietly published one of the most consequential papers in AI safety. <a href="https://arxiv.org/abs/2307.09009">Chen, Zaharia, and Zou showed that GPT-4&#8217;s accuracy on a prime-number identification task dropped from 97.6% to 2.4% between March and June 2023</a>, even though the API endpoint was the same. The model had been updated. No announcement. No changelog. No way for users to know what changed, or why, or how to reproduce the old behavior.</p><p>In healthcare, that is a medical device failure. Imagine a sepsis prediction tool that your hospital validated, deployed, and trusted. On Tuesday morning, its sensitivity drops by 40% because the vendor pushed a silent update. Your patients do not get flagged. Your nurses do not know to look harder. Your mortality metrics shift six months later, and by the time you trace it back, the vendor has pushed three more updates.</p><p>This is what researchers call &#8220;version drift.&#8221; I prefer <strong>AI creep</strong>, because it captures something more insidious: the slow, invisible expansion of a model&#8217;s behavior beyond its validated boundaries, combined with the unannounced changes that make root-cause analysis impossible.</p><p>Open-weight models solve this through <strong>version pinning</strong>. A hospital downloads the weights, validates them against its own clinical data, locks them in, and treats them exactly like the firmware on a pacemaker. You cannot update a pacemaker without full re-validation. You should not update a clinical AI model without it either. <a href="https://www.nature.com/articles/s41746-024-01344-w">Riedemann et al. explicitly argue that open-source approaches provide &#8220;medical device developers maximum flexibility to reduce the black-box properties of such systems&#8221;</a>, which is a polite way of saying that proprietary APIs are structurally incompatible with medical device safety culture.</p><p>The OpenAI &#8220;laziness&#8221; incident of December 2023, where ChatGPT inexplicably refused to perform complete tasks, is another example. The cause was never identified by independent researchers nor disclosed by OpenAI. A hospital relying on that API for clinical documentation would have had no recourse, no explanation, and no ability to roll back to the previous behavior. With fixed open weights, you control the timeline.</p><div><hr></div><h3>Data Sovereignty and the Two-Pipeline Problem</h3><p>If you read this newsletter regularly, you know I have written about the two data pipelines that every hospital AI deployment creates. There is the back-door pipeline, where de-identified data flows to vendors. And there is the front-door pipeline, where clinicians, patients, or administrators upload PHI directly into consumer chatbots, often without understanding that the data is being used to train the next model.</p><p>Running open-weight models locally eliminates the front-door risk. Patient data never leaves the hospital network. There is no question about whether de-identification actually worked. There is no wondering if a clinician copied and pasted a pathology report into a web interface that lacks a Business Associate Agreement. <a href="https://www.nature.com/articles/s41746-025-01476-7">Dennst&#228;dt et al. put this bluntly</a>: transmitting sensitive patient data to external servers, even in partially anonymized formats, &#8220;raises the risk of data breaches and unauthorized access,&#8221; and &#8220;complete anonymization in most clinical settings is not possible.&#8221;</p><p>For HIPAA compliance officers, this is a gift. The liability architecture becomes cleaner. If patient data never leaves your network, you have eliminated an entire class of breach scenarios. You have also eliminated the vendor&#8217;s terms of service as a factor in your compliance posture. OpenAI's terms of service state that its models aren't meant to be used for diagnosing or treating any health condition. Anthropic&#8217;s terms are similar. When you run a model locally, you are not agreeing to anyone&#8217;s terms except your own hospital&#8217;s.</p><p>For patients, the stakes are more direct. It&#8217;s their diagnosis, their genetic results, their mental health history moving through whatever pipeline a hospital, or a third-party app the hospital contracted with, chose to build on. Most patients have no idea which of those two pipelines their information is taking, let alone whether the model on the other end is proprietary or open, local or cloud-hosted.</p><div><hr></div><h3>Niche Specificity</h3><p>A hospital in rural Mississippi treating a rare sickle-cell variant has different needs than a quaternary academic center in Boston. Proprietary APIs are trained on internet-scale data, optimized for the average case, and fine-tuned for the most common complaints. They are not optimized for your patient population.</p><p>Open-weight models allow fine-tuning on local data. There are now specific medical open models like <a href="https://huggingface.co/aaditya/Llama3-OpenBioLLM-70B">OpenBioLLM-Llama3-70B</a>, MEDITRON-70B, and Google&#8217;s MedGemma collection. A hospital can download these, fine-tune them on its own historical cases, its own protocols, and its own rare-disease populations, and produce a model that knows its local context.</p><p>The performance gap has narrowed dramatically. A <a href="https://hms.harvard.edu/news/open-source-ai-matches-top-proprietary-llm-solving-tough-medical-cases">Harvard Medical School study found that an open-source model performed on par with leading proprietary AI in solving tough medical cases</a>. By mid-2024, <a href="https://www.nature.com/articles/s41746-024-01344-w">LLaMA 3.1 405B had nearly closed the gap with GPT-4o</a> on general benchmarks.</p><p>But the stronger argument is verifiability. A proprietary model might perform well on your data, but you cannot inspect its weights or training data to know why. An open model can be validated against your specific clinical scenario and audited by your own quality team. In medicine, knowing <em>why</em> a model works is often as important as knowing <em>that</em> it works.</p><div><hr></div><h3>Infrastructure and Expertise</h3><p>Here is where the fantasy breaks down. A 70-billion-parameter model requires serious GPU infrastructure. A 300-bed community hospital in rural America does not have an A100 cluster of servers in its basement. It does not have ML engineers on staff. It barely has enough IT staff to keep the EMR running. A three-person health-tech startup trying to fine-tune the same model on a laptop is in exactly the same position, just without the EMR.</p><p><a href="https://www.nature.com/articles/s41746-025-01476-7">Dennst&#228;dt et al. are explicit about this trade-off</a>: &#8220;Open LLMs deployed on local hardware enable greater model customization&#8221; but &#8220;demand resources and technical expertise.&#8221; Most hospitals do not have the expertise to deploy, monitor, and maintain these systems. Control is only valuable if you have the organizational capacity to wield it.</p><p>This is where the literature proposes a <strong>consortium model</strong>, and it is the most practical expansion of the open-source theory. The <a href="https://www.newswise.com/articles/to-safely-deploy-generative-ai-in-health-care-models-must-be-open-source">University Health Network authors explicitly call for a &#8220;global consortium&#8221; similar to the Trillion Parameter Consortium</a> to pool computational resources, share validated base models, and allow individual hospitals to fine-tune locally without each building its own data center. This is how open source wins in healthcare: as shared infrastructure.</p><p>There is also the rise of smaller, efficient models. Even 7-billion-parameter models can now run on a Mac M1 and perform well for targeted tasks. As models get smaller and more efficient, the infrastructure barrier drops. This trend turns the theory from a fantasy into a practical reality about targeted deployment.</p><div><hr></div><h3>The &#8220;Open Source&#8221; Definition Problem</h3><p>Zuckerberg&#8217;s announcement is a perfect teaching moment. The <a href="https://www.nytimes.com/2026/08/10/technology/meta-ai-open-source.html">NYT reported explicitly that Muse Glimmer &#8220;is not fully open source&#8221;</a>. Meta released the weights, but not the training data, or the full architecture details, or the license terms that would allow unrestricted commercial use. This is &#8220;open weight,&#8221; not &#8220;open source.&#8221;</p><p>The distinction matters because <a href="https://www.nature.com/articles/s41746-024-01344-w">Riedemann et al.,</a> discuss code, data, weights, documentation, and licensing separately. By that framework, most &#8220;open&#8221; models are barely halfway open: open enough to download and run, rarely open enough to fully audit. The European Union AI Act is currently struggling with this exact problem. Whether you&#8217;re procuring a model for a hospital, deciding what to build a clinical product on, or just trying to evaluate a vendor&#8217;s privacy claims, you need to ask the same question: open in what dimension? Open to inspection? Open to modification? Open to commercial deployment without a usage license from Meta?</p><p>If you write a procurement policy based on &#8220;open source&#8221; without defining it, you will end up with a vendor that released weights under a restrictive license and still controls your destiny. The marketing language is not your friend.</p><div><hr></div><h3>Security and Adversarial Risk</h3><p>The open-source security argument has a flip side. Yes, running locally keeps data in-house. But open weights are also <strong>susceptible to attackers</strong>. Because the architecture and weights are public, adversaries can systematically search for vulnerabilities, craft adversarial inputs, and test data-poisoning strategies at scale.</p><p>A <a href="https://galileo.ai/blog/disadvantages-open-source-llms">Galileo AI analysis of open-source LLM security risks</a> notes that &#8220;open-source LLMs often introduce significant security risks due to their public nature and generally immature security practices.&#8221; A <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC12478422/">PMC study on safety in medical LLMs found that medical-specific fine-tuned models, both open-source and proprietary, underperformed general-purpose frontier models across most safety dimensions tested</a>. The problem is that safety in medical AI is hard for everyone, not that open models are uniquely unsafe.</p><p>The counterargument is that closed models get breached too. OpenAI had its data leak. The rogue AI incidents of the past month show that proprietary models are not magically secure because their weights are hidden. The difference is <strong>transparency</strong>. With open weights, your hospital can probe the model itself, find vulnerabilities, and patch or mitigate them. With a closed model, you must wait for the vendor to fix it, and hope they tell you the truth about what happened. A <a href="https://censinet.com/perspectives/hidden-attack-surface-understanding-ai-specific-vulnerabilities-healthcare">Censinet analysis of AI-specific vulnerabilities in healthcare</a> makes the case for adversarial robustness testing regardless of model source. </p><div><hr></div><h3>The Regulatory Paradox</h3><p>Here is the most biting counterargument, and it is underexplored in the literature. The FDA wants medical devices to be locked-down and validated. If you download an open-weight model, fine-tune it on your local patient data, and deploy it in a clinical decision support workflow, have you just created a new medical device? Does it require its own 510(k)?</p><p>The regulatory framework has not caught up to this question. The Riedemann paper notes that LLM AI chatbots require approval as medical devices, but the approval process assumes a static, validated product. An open model that a hospital can freely modify is, by definition, not a static device. If your AI officer fine-tunes the model next quarter, is that a design change requiring re-validation?</p><p>Liability shifts entirely to whoever deployed the model, the hospital, or the developer who built a clinical product on top of it. When a proprietary model harms a patient, the hospital, the developer, and the vendor will all point at each other. An organization running its own locked model has clearer liability. For the risk-averse, that is actually a feature, not a bug. But only if the organization has the documentation and governance infrastructure to defend itself.</p><div><hr></div><h3>Hybrid Deployment</h3><p>If you take one thing from this article, take this: hospitals should version-pin and locally deploy open models for high-stakes clinical tasks, while using proprietary APIs for low-stakes general tasks.</p><p>This is the only position that is both defensible and practical. Use GPT-4o or Claude for scheduling, patient education, and general documentation tasks where version drift is annoying but not dangerous, and where the cost of local infrastructure is not justified. Use pinned, validated, locally run open models for clinical decision support, pathology review, rare disease diagnosis, and any workflow where a silent behavior change could harm a patient.</p><p><a href="https://www.frontiersin.org/journals/digital-health/articles/10.3389/fdgth.2026.1778786/full">Dennst&#228;dt et al. and the Frontiers review both back this hybrid approach</a><span>. The Frontiers review focuses narrowly on information-extraction tasks, pairing local, on-premises retrieval with cloud-based generation, but the same logic applies more broadly to clinical decision support. Hospitals get control where it counts without building full ML infrastructure for every task. And it creates a natural safety net: if a proprietary API goes rogue, it's running your scheduling bot, not your sepsis predictor.</span></p><div><hr></div><h3>The Version-Pinned Hospital</h3><p>The hospitals, developers, and health systems that will own the next decade are the ones that treat AI like the medical device it is: validate, lock, version, archive, and only update through a controlled change-management process. Whoever is building or buying these tools, in-house AI team, third-party vendor, or solo developer, will not outsource their clinical brains to black boxes that update silently every three months. They will build the competency to run, validate, and govern their own models, even if they have to share the infrastructure to do it.</p><p>The ones that keep renting APIs and hoping the terms of service will protect them, and the ones handing over their health data without asking what&#8217;s actually running on the other end, will have no one to blame but themselves when the next data leak hits or the next unannounced model update quietly changes what their AI actually does.</p><p><strong>Open source is a risk-mitigation strategy, not a magic bullet. And in medicine, whether you&#8217;re the hospital deploying it, the developer building it, or the patient trusting it, that&#8217;s what protects you.</strong></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[When Does AI Become the Standard of Care?]]></title><description><![CDATA[Lessons from the Rise of Point-of-Care Ultrasound]]></description><link>https://ashooreview.com/p/when-does-ai-become-the-standard</link><guid isPermaLink="false">https://ashooreview.com/p/when-does-ai-become-the-standard</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 07 Aug 2026 15:04:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CYSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Today I&#8217;m asking a different question: when does declining to use a clinical AI tool stop being a preference and start being a deviation from standard care? I use point-of-care ultrasound&#8217;s roughly thirty-year climb to standard of care as a control case, then map where AI actually sits on that same ladder today, not where the marketing suggests it sits.</em></p><p><em>As always, if you enjoy reading, subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CYSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CYSj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CYSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:526575,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/210226075?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CYSj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CYSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9162f6e8-da8a-4cb7-a5a1-1f1584d3b81e_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A patient arrives in the emergency department with sudden chest pain and shortness of breath. You order a CT angiogram. You check a troponin and a D-dimer. Then, you scan the heart at the bedside, looking for right ventricular strain, without a second thought.</p><p>No one asks whether CT angiography or troponin and D-dimer panels are available. No one questions whether a bedside cardiac scan is appropriate for a patient with unexplained dyspnea.</p><p>In the 1990s, bedside ultrasound was viewed as experimental by many physicians. Training was scarce. Equipment was limited. Skepticism was the default posture. Today, failing to use it in certain situations may be difficult to defend.</p><p>Could artificial intelligence be following the same path?</p><h3><strong>What Does &#8220;Standard of Care&#8221; Actually Mean?</strong></h3><p>The standard of care is a legal concept. Courts define it as what a reasonably prudent physician would do under similar circumstances, established by expert testimony in malpractice cases and by what has become available and expected in community practice. Best practice sets a higher bar: it describes what excellent physicians do, not what the law requires of an average one. Having access to a technology sets a lower bar still, since a device sitting unused in a hospital does not obligate anyone to use it. Standard of care sits between the two, and it moves as medicine absorbs new technology into routine practice, without anyone declaring a formal start date.</p><p>Understanding how that absorption happens is the key to understanding where AI is heading.</p><h3><strong>The POCUS Roadmap</strong></h3><p>To see how a technology becomes standard of care, it helps to look at one that has already made the full journey. Point-of-care ultrasound (POCUS) offers an unusually clean roadmap, divided into seven identifiable steps.</p><p><strong>1. Innovation. </strong>The technology itself predates its American emergency medicine adoption by decades. Clinicians in Europe and Japan used bedside ultrasound for trauma assessment as early as the 1970s. In the United States, the late 1980s and early 1990s produced a small group of early adopters, emergency physicians willing to look at a blurry image and ask whether it changed their clinical decision-making. Equipment was limited, skepticism was widespread, and the idea that a bedside scan could substitute for a formal radiology study struck many as reckless.</p><p><strong>2. Evidence. </strong>Clinical studies accumulated over years. Grace Rozycki&#8217;s 1993 study of 476 trauma patients demonstrated that surgeons and emergency physicians could reliably detect free fluid at the bedside. The exam itself did not get its name, Focused Assessment with Sonography for Trauma, until an international consensus conference in December 1997, with results published in 1999. Evidence built specialty by specialty and application by application: trauma first, then pregnancy, cardiac, and procedural guidance.</p><p><strong>3. Professional Endorsement. </strong>Institutional recognition followed the evidence, but slowly. ACEP issued a position statement backing physician-performed emergency ultrasound in 1990, then approved a dedicated Emergency Ultrasound Section in 1995. The real inflection point came in June 2001, when ACEP&#8217;s Board approved the first comprehensive Emergency Ultrasound Guidelines, the first time a major American specialty society formally endorsed bedside ultrasound as a core skill with defined training expectations. The guidelines were revised in 2008, retitled and expanded in 2016 to &#8220;Ultrasound Guidelines: Emergency, Point-of-Care, and Clinical Ultrasound Guidelines in Medicine,&#8221; and revised again in 2023.</p><p><strong>4. Infrastructure. </strong>Machines became smaller and cheaper. Hospitals purchased equipment, and image archiving, billing codes, quality assurance programs, and workflow integration all had to be built around it. None of this happened automatically; it required systems engineering, IT integration, and financial justification, mostly after the guidelines existed to justify the spend.</p><p><strong>5. Cultural Adoption. </strong>Residents began expecting to learn POCUS. Patients began expecting it. Hospitals started advertising bedside ultrasound capability. The technology moved from curiosity to baseline expectation.</p><p><strong>6. Governance. </strong>Credentialing pathways emerged. Residency programs built ultrasound into formal curricula. Quality assurance programs began tracking image quality and interpretation accuracy over time.</p><p><strong>7. Medicolegal Recognition. </strong>Here is where the standard of care quietly shifts. A 2022 review by Russ and colleagues in the Journal of Emergency Medicine examined POCUS malpractice cases filed between December 2012 and January 2021 and found that the dominant allegation was failure to perform, not misinterpretation. Jonathan Mezrich made the same point in Academic Radiology in 2025: physicians are now more likely to face litigation for <em>not</em> performing POCUS than for misreading it, calling it &#8220;a rare example where defensive medicine and patient care demands converge.&#8221; No single court case or guideline declared POCUS the standard. Evidence, endorsement, infrastructure, culture, and litigation converged until the question flipped from why would you do this to why didn&#8217;t you.</p><h3><strong>Where Is AI Today?</strong></h3><p>Let&#8217;s run the same seven steps against AI in medicine as it stands in mid-2026.</p><p><strong>1. Innovation. </strong>AI has cleared this step. The FDA&#8217;s running list of AI- and Machine Learning-enabled medical devices passed 1,524 entries by the end of March 2026, with radiology accounting for 1,163 of them, about 76 percent. Cardiology alone now has more than 200 cleared algorithms. In 2025, the FDA cleared 295 new AI devices from 221 different manufacturers.</p><p><strong>2. Evidence. </strong>This is a bit uneven. Retrospective validation is abundant: chest X-ray triage tools such as Qure.ai&#8217;s qXR line now carry 26 FDA-cleared indications across X-ray and CT, from lung nodule detection to intracranial hemorrhage triage, and prospective studies have shown measurable reductions in time-to-read for critical findings. ECG interpretation has a similarly mature evidence base. But outcome-level prospective evidence, the kind showing a mortality or morbidity benefit rather than a diagnostic-accuracy benefit, is still catching up. One of the more ambitious efforts, a cluster-randomized trial evaluating whether an AI chest X-ray triage system reduces mortality, isn&#8217;t expected to report full data until December 2027. For most other applications, especially complex diagnostic reasoning, the trials that would satisfy this step are still being designed.</p><p><strong>3. Professional Endorsement. </strong>This step is moving at different speeds by specialty. In October 2025, ACEP hosted the first All Emergency Medicine AI Summit, convening SAEM, CORD, ACOEP, ABEM, AAEM, EMRA, AACEM, and AOBEM. The resulting consensus statement, published in March 2026, affirms that emergency physicians retain authority for patient care decisions and that AI should enhance rather than replace clinical judgment. That&#8217;s real, but it reads more like ACEP&#8217;s 1990 position statement than its 2001 guidelines: principles without defined training or credentialing standards. Radiology has moved further. In May 2026, the ACR Council approved the ACR-SIIM Practice Parameter for Imaging Artificial Intelligence, the specialty&#8217;s first formal practice parameter for AI and the same category of document as ACR&#8217;s Appropriateness Criteria. It sets expectations for governance, clinical validation, bias mitigation, and ongoing performance monitoring, and it&#8217;s paired with Assess-AI, a new quality registry that tracks real-world model performance against radiology-report-derived outcomes. That is, right now, the closest thing in medicine to a 2001-style guideline for AI.</p><p><strong>4. Infrastructure. </strong>This is moving fast. Major EHR vendors have built native AI integration points, hospital AI governance committees are now common rather than novel, and the FDA&#8217;s Predetermined Change Control Plan (PCCP) framework, finalized in 2024, lets manufacturers update models without seeking a new clearance for every version. That matters more than it sounds: it&#8217;s a regulatory acknowledgment that AI infrastructure will need to absorb continuous change in a way POCUS equipment never did.</p><p><strong>5. Cultural Adoption. </strong>The share of U.S. and Canadian medical schools incorporating AI into their curricula jumped from 53 percent in 2023 to 77 percent in 2024, according to the AAMC and AACOM&#8217;s Curriculum SCOPE Survey. Residency training lags behind medical school. ACGME hasn&#8217;t made AI competency a formal program requirement yet, though it&#8217;s gathering stakeholder feedback toward that end and added AI-focused sessions to its 2026 programming, and the AAMC&#8217;s own national AI competency framework for the full training continuum isn&#8217;t due until fall 2026. Patients are beginning to ask about AI-assisted diagnosis, and health systems increasingly market their AI capabilities. What&#8217;s still missing is the residency-level equivalent of a POCUS rotation: standardized, required, and tested.</p><p><strong>6. Governance. </strong>This remains the messy middle. The FDA&#8217;s January 2026 revision to its clinical decision support guidance leans on what industry has started calling a &#8220;glass box&#8221; standard: CDS software must disclose, in plain language, its underlying logic, validation methodology, and the limitations of its training data, specifically to guard against automation bias. What&#8217;s still mostly missing is the hospital-side counterpart: credentialing pathways, and version-tracking systems that treat a model update the way a hospital treats a new piece of equipment.</p><p><strong>7. Medicolegal Recognition. </strong>No case law yet establishes AI <em>non-use</em> as a deviation from standard care. But the fact that a Harvard Business School economist has now formally modeled the question tells you something about where the conversation has moved. More on that paper below.</p><h3><strong>What Still Has to Happen?</strong></h3><p>Some of the remaining milestones are already in motion, or already achieved in a single specialty, like radiology&#8217;s new practice parameter and the chest X-ray mortality trial cited above. Most are not, and none has happened across specialties broadly. The list that would move AI further up the ladder:</p><ul><li><p>Clinical outcome studies showing mortality or morbidity benefit, not just diagnostic accuracy</p></li><li><p>Prospective trials rather than retrospective validation, across more than imaging and ECG</p></li><li><p>Professional society recommendations with the weight of the 2001 ACEP guidelines, in specialties beyond radiology, which already has one</p></li><li><p>Residency curricula that train every new physician on AI tools as a baseline skill</p></li><li><p>Board examination content that tests AI competency</p></li><li><p>Credentialing pathways for physicians using AI clinically</p></li><li><p>Hospital policies that define when and how AI is used</p></li><li><p>Workflow integration inside EHRs that makes AI a seamless part of clinical decision-making rather than an add-on</p></li><li><p>Quality assurance programs, run by hospitals rather than manufacturers, that monitor model performance over time</p></li><li><p>Version-control transparency that lets clinicians know when a model changed and how that changed its outputs</p></li><li><p>Independent benchmarking of commercial models against real, local patient populations</p></li><li><p>Malpractice case law that establishes precedent for when declining to use AI becomes indefensible</p></li></ul><h3><strong>Why AI May Be Different</strong></h3><p>History doesn&#8217;t always repeat itself. There are real differences between POCUS and AI that complicate the transition:</p><p><strong>Velocity of change. </strong>Ultrasound machines improved incrementally. AI models can change materially every few months, and the FDA&#8217;s own PCCP framework formalizes this: manufacturers can now pre-clear a range of future model updates in a single submission, meaning a device that behaves one way in 2026 may legitimately behave differently in 2027 without ever returning for a new review. Ultrasound machines never needed that provision.</p><p><strong>Evolving outputs. </strong>A 2024 model doesn&#8217;t necessarily behave like a 2025 model. POCUS images don&#8217;t change their meaning retroactively; AI outputs can.</p><p><strong>Probabilistic nature. </strong>AI recommendations are not visual. A radiologist can look at an ultrasound image and see what the physician saw. An AI recommendation is often invisible unless documented, complicating both quality assurance and medicolegal review.</p><p><strong>Vendor fragmentation. </strong>Unlike ultrasound, dominated by a handful of manufacturers, the AI landscape is crowded with substantially different models, making standardization and benchmarking harder.</p><p><strong>Continuous governance. </strong>With POCUS, governance was largely a one-time investment in training and equipment. With AI, governance is continuous: models drift, data distributions shift, and monitoring has to be perpetual.</p><p><strong>Deskilling risk. </strong>POCUS extended the physical exam; it didn&#8217;t replace clinical reasoning. AI carries a genuine risk of cognitive atrophy, where physicians grow less capable of independent verification because they&#8217;ve grown dependent on the tool. POCUS has no direct equivalent of this risk.</p><p>These distinctions make the transition more complicated than the POCUS roadmap would suggest.</p><h3><strong>The Medicolegal Inflection Point</strong></h3><p>Here I want to sit with questions rather than answers.</p><ul><li><p>If AI reliably detects subtle diagnoses that physicians routinely miss...</p></li><li><p>If AI consistently reduces missed findings across multiple validated studies...</p></li><li><p>If most emergency physicians in a community routinely use it...</p></li><li><p>If hospitals provide it as part of standard equipment...</p></li><li><p>If specialty societies recommend it in formal guidelines...</p></li></ul><p>At what point does declining to use AI become difficult to defend?</p><p>A 2026 Harvard Business School working paper by economist Alex Chan, also circulated through the National Bureau of Economic Research, models exactly this transition: the point at which AI moves from a passive clinical tool to something that shapes what a reasonably prudent physician would do. Chan&#8217;s core question isn&#8217;t whether liability law should protect physicians who rely on AI. It&#8217;s whether the law should adapt its standards to AI&#8217;s specific failure modes, data drift, vendor-side updates, probabilistic rather than binary outputs, or force AI to fit liability frameworks built for static tools like a stethoscope or an ultrasound probe.</p><p>I don&#8217;t think this moment has arrived. But it may be closer than it feels, because the standard of care doesn&#8217;t announce itself with a press release. It shifts in the accumulated weight of evidence, endorsement, and litigation until the defense of &#8220;I didn&#8217;t use it&#8221; begins to sound hollow.</p><h3><strong>The Ladder as a Diagnostic Tool</strong></h3><p>The seven steps above aren&#8217;t specific to ultrasound. The same ladder applies to CT, MRI, and troponin testing, all of which climbed it long before POCUS did, and it applies just as well going forward, to next-generation sequencing or whatever comes after AI.</p><p>The value of naming the steps isn&#8217;t prediction. It&#8217;s diagnosis: for any technology you&#8217;re evaluating, you can ask which step it has actually reached, rather than which step its marketing implies it has reached. That&#8217;s precisely where most of the confusion about AI&#8217;s clinical readiness comes from, conflating step one (an FDA clearance exists) with step three (a specialty society has endorsed it) or step seven (declining to use it is indefensible).</p><h3><strong>Conclusion</strong></h3><p>Nobody predicted the exact year bedside ultrasound became routine. There was no ribbon-cutting ceremony. Looking backward, the progression seems obvious and inevitable. Looking forward at the time, it was uncertain and contested.</p><p>AI may follow a similar path. Or it may follow an entirely new one. The important question isn&#8217;t whether AI will become the standard of care. Given enough evidence, infrastructure, and cultural absorption, most useful technologies eventually do.</p><p>The important question is: <strong>How will I recognize the moment when it does?</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!04-O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!04-O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 424w, https://substackcdn.com/image/fetch/$s_!04-O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 848w, https://substackcdn.com/image/fetch/$s_!04-O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 1272w, https://substackcdn.com/image/fetch/$s_!04-O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!04-O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png" width="1194" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1194,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:256934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/210226075?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!04-O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 424w, https://substackcdn.com/image/fetch/$s_!04-O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 848w, https://substackcdn.com/image/fetch/$s_!04-O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 1272w, https://substackcdn.com/image/fetch/$s_!04-O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3e0a5d-ce8c-4914-b07d-8be68c3ca502_1194x816.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Sources</strong></h4><ul><li><p>Rozycki GS, Ochsner MG, Jaffin JH, Champion HR. &#8220;Prospective Evaluation of Surgeons&#8217; Use of Ultrasound in the Evaluation of Trauma Patients.&#8221; <em>Journal of Trauma</em>. 1993;34(4):516&#8211;527. (476-patient study establishing the technique; predates the FAST name.)</p></li><li><p>Scalea TM, et al. &#8220;Focused Assessment with Sonography for Trauma (FAST): Results From an International Consensus Conference.&#8221; <em>Journal of Trauma</em>. 1999;46(3):466&#8211;472. (Consensus conference, Dec. 1997, that coined the FAST acronym.) <a href="https://pubmed.ncbi.nlm.nih.gov/10088853/"><span>PubMed</span></a></p></li><li><p>Rozycki GS. &#8220;Surgeon-Performed Ultrasound: Its Use in Clinical Practice.&#8221; <em>Annals of Surgery</em>. 1998;228(1):16&#8211;28.</p></li><li><p>Russ B, Arthur J, Lewis Z, Snead G. &#8220;A Review of Lawsuits Related to Point-of-Care Emergency Ultrasound Applications.&#8221; <em>Journal of Emergency Medicine</em>. 2022;63(5):661&#8211;672.</p></li><li><p>Mezrich JL. &#8220;POCUS in the Emergency Department: An Example of Convergence of Defensive Medicine With Patient Care.&#8221; <em>Academic Radiology</em>. 2025;32(Suppl 1):S126&#8211;S130. <a href="https://pubmed.ncbi.nlm.nih.gov/40947284/"><span>PubMed</span></a></p></li><li><p>ACEP. &#8220;Ultrasound Guidelines: Emergency, Point-of-Care, and Clinical Ultrasound Guidelines in Medicine.&#8221; Approved as &#8220;Emergency Ultrasound Guidelines,&#8221; June 2001; revised Oct. 2008; retitled and expanded June 2016; revised again April 2023.</p></li><li><p>Chan A. &#8220;Optimal Medical Liability for AI.&#8221; Harvard Business School Working Paper No. 26-087, June 2026; also NBER Working Paper No. w35321. <a href="https://www.nber.org/papers/w35321"><span>NBER</span></a></p></li><li><p>FDA. &#8220;Artificial Intelligence-Enabled Medical Devices&#8221; database, last updated March 4, 2026 (1,524 total devices; 1,163 in radiology, ~76%; 295 new clearances in 2025 from 221 manufacturers).</p></li><li><p>FDA. &#8220;Predetermined Change Control Plans for Machine Learning-Enabled Medical Devices: Guiding Principles.&#8221; Final guidance, 2024.</p></li><li><p>FDA. Revised Clinical Decision Support Software guidance, issued January 6, 2026 (&#8220;glass box&#8221; transparency requirements, automation-bias framing).</p></li><li><p>ACEP, SAEM, CORD, ACOEP, ABEM, AAEM, EMRA, AACEM, and AOBEM. Consensus Statement following the first All Emergency Medicine AI Summit (Irving, TX, Oct. 2025); statement published March 18, 2026.</p></li><li><p>American College of Radiology, Data Science Institute. AI use-case repository and FDA-cleared algorithm tracker.</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Two Pipelines]]></title><description><![CDATA[One hides your name. The other doesn't bother.]]></description><link>https://ashooreview.com/p/the-two-pipelines</link><guid isPermaLink="false">https://ashooreview.com/p/the-two-pipelines</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Sun, 02 Aug 2026 18:39:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Kgdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>In this installment of Ashoo Review: AI in Medicine, I&#8217;m taking a closer look at how our data is being sold to software companies AND how those same companies are now asking for us to provide it voluntarily. You may think your consent is required; think again. </em></p><p><em>As always, if you enjoy reading, consider subscribing and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kgdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kgdt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kgdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:511786,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/209528064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Kgdt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Kgdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b1ab18f-9faf-4893-ba40-33d45f187384_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In July 2026, OpenAI rolled out ChatGPT Health to every U.S. adult user, inviting them to connect their Apple Health data, medical records from Epic and Oracle Health systems, and wellness apps directly to the AI. <a href="https://openai.com/index/health-in-chatgpt/"><span>OpenAI announced the nationwide launch on July 23</span></a>, promising &#8220;secure&#8221; connections and personalized health insights. The move was widely covered as a consumer convenience, a smarter way to track medications, interpret lab results, and prepare for doctor visits.</p><p>What most coverage missed is that this is only one half of a much larger story. While consumers debate whether to trust OpenAI with their blood pressure readings, a separate, invisible pipeline has already moved hundreds of millions of patient records into the hands of AI companies. The difference is structural, legal, and deeply asymmetrical, the back-door pipeline strips your name before it sells your data. The front-door pipeline does not have to.</p><h3><strong>The Front Door, HIPAA Ends Here</strong></h3><p>Here is the first thing to understand about ChatGPT Health, it is not covered by HIPAA.</p><p>HIPAA, the Health Insurance Portability and Accountability Act, governs a narrow class of &#8220;covered entities&#8221;, hospitals, health insurers, and healthcare clearinghouses, plus their &#8220;business associates.&#8221; OpenAI is none of these. <a href="https://help.openai.com/en/articles/20001036-health-in-chatgpt"><span>OpenAI states explicitly that &#8220;Health in ChatGPT is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement.&#8221;</span></a></p><p>What this means in practice is stark. When a hospital holds your medical record, federal law requires them to protect it, limit its use, and obtain authorization before sharing it broadly. When you upload that same record to ChatGPT, those protections evaporate. As health platform b.well noted, &#8220;medical records uploaded into ChatGPT Health are no longer covered by HIPAA, because the service isn&#8217;t a covered entity under that law.&#8221;</p><p>OpenAI does not need to de-identify your data. It does not need to strip your name, your birth date, your medical record number, or your diagnostic codes. Its only constraints are its own privacy policies. <a href="https://openai.com/policies/health-privacy-policy/"><span>OpenAI&#8217;s Health Privacy Notice says that by default, health data received via Health Features is not used to improve foundational models</span></a>. But the policy also notes that &#8220;a limited number of authorized OpenAI personnel and trusted service providers might access data... to improve model safety, unless you have opted out.&#8221; That is a significant carve-out, governed by a terms-of-service agreement most users will not read.</p><p>The consumer is being asked to make a privacy decision without understanding the legal terrain. They assume HIPAA protects their health data everywhere. It does not.</p><h3><strong>The Back Door, The Pipeline You Never Signed Up For</strong></h3><p>While OpenAI courts consumers on the front end, a separate industry has built a lucrative infrastructure for selling hospital data to AI companies on the back end. The key players are data middlemen, companies that contract with hospitals, strip patient records of direct identifiers, and license the resulting datasets to AI developers and researchers.</p><p><strong>Truveta</strong> is among the largest. Founded by a consortium of major U.S. health systems, <a href="https://www.truveta.com/members/"><span>Truveta now includes data from more than 130 million de-identified patients across over 900 hospitals and 20,000 clinics</span></a>. Its members include Providence, Advocate Health, Trinity Health, Tenet Healthcare, Northwell Health, AdventHealth, and Novant Health. <a href="https://www.truveta.com/blog/announcement/microsoft-and-truveta-announce-strategic-partnership-to-accelerate-truvetas-vision-of-saving-lives-with-data/"><span>In September 2021, Microsoft announced a strategic partnership and investment in Truveta</span></a>, and Truveta uses Azure-based AI to process its data. Truveta has also launched its own <a href="https://www.truveta.com/wp-content/uploads/2023/04/Truveta-Language-Model.pdf"><span>Truveta Language Model</span></a> trained on this clinical corpus.</p><p><strong>Protege</strong> is the emerging contender. In January 2026, <a href="https://www.alleywatch.com/2026/01/protege-ai-training-data-licensing-real-world-data-bobby-samuels/"><span>Protege raised a $30 million Series A led by Andreessen Horowitz</span></a>, bringing its total funding to $65 million. The company works with what it describes as &#8220;close to 20 data partners&#8221; in healthcare and more than 100 across all sectors. Protege licenses what it calls &#8220;private, real-world data&#8221; including clinical notes, medical images, video, audio, pathology slides, genomic data, lab reports, wearables data, and social determinants of health. <a href="https://syndesis.com/syndesis-and-protege/"><span>In a partnership with Syndesis Health, Protege gained access to 70 million de-identified patient lives from more than 500 facilities across 15 countries</span></a>.</p><p>Protege states on its website that it <a href="https://withprotege.ai/data-provider/other-domains"><span>works directly with &#8220;leading foundation model labs&#8221;</span></a> to define licensing standards. It does not name them. What is clear is that the pipeline is vast, well-funded, and growing rapidly.</p><h3><strong>The Asymmetry</strong></h3><p>Consider what this means for a single patient.</p><p>If you are treated at a Truveta-member hospital, your de-identified record may be harmonized, aggregated, and sold to AI developers. The hospital has removed your name, address, medical record number, and the other 15 identifiers required by HIPAA&#8217;s Safe Harbor method. The AI company receives a rich longitudinal record of your diagnoses, medications, procedures, and lab values, but without a name attached.</p><p>If you then upload your own medical records to ChatGPT Health to ask about your medication list, OpenAI receives the same clinical information, but with your name on it, your dates intact, and your full identifying context, because HIPAA does not apply to them.</p><p>The hospital is legally required to de-identify your data before sharing it. The consumer AI company is not required to do anything of that kind. The regulated system forces anonymization on the back door while the consumer app collects richer, more identifiable data through the front door with no federal health privacy guardrails at all.</p><p>Here is the part that should give consumers pause. The software companies building these health AI products may already have more data on you than you would want them to know, de-identified records from your hospital, imaging from your health system, lab values from your clinic. If you then provide them with a small sampling of identifiable data, your own uploaded records, your Apple Health metrics, a few lab results, you may inadvertently give them the key to re-identify what they already possess as belonging to you. Careful what you share, because even a narrow slice of identifiable health data can be used to frame a much more detailed picture of you than you may think.</p><h3><strong>The De-identification Myth</strong></h3><p>There is a second problem with the back-door pipeline, and it is mathematical.</p><p>For decades, the legal and ethical framework for health data sharing has relied on a simple premise, remove 18 identifiers, and the data is no longer &#8220;personally identifiable.&#8221; Once de-identified, it falls outside HIPAA&#8217;s scope and can be &#8220;freely used, shared, and sold&#8221; without patient consent.</p><p>Modern AI has broken that premise. In 2019, researchers Luc Rocher, Julien Hendrickx, and Yves-Alexandre de Montjoye published a study in <a href="https://www.nature.com/articles/s41467-019-10933-3"><span>Nature Communications</span></a> titled &#8220;Estimating the success of re-identifications in incomplete datasets using generative models.&#8221; Their finding was startling, <strong>&#8220;Using our model, we find that 99.98% of Americans would be correctly re-identified in any dataset using 15 demographic attributes.&#8221;</strong></p><p>The authors were explicit about the policy implications, &#8220;Our results suggest that even heavily sampled anonymized datasets are unlikely to satisfy the modern standards for anonymization set forth by GDPR and seriously challenge the technical and legal adequacy of the de-identification release-and-forget model.&#8221;</p><p><span>Other studies have reinforced the point. </span><a href="https://www.beckershospitalreview.com/healthcare-information-technology/ai-can-re-identify-de-identified-health-data-study-finds/"><span>Researchers have demonstrated that algorithms can accurately match physical activity data and demographic information to 95% of adults in a dataset</span></a><span>. As </span><a href="https://san.com/cc/hipaa-promised-to-keep-your-medical-data-secret-ai-threatens-to-reveal-it/"><span>Scripps News reported</span></a><span>, &#8220;Health data shared with AI systems can be stripped of names and sold legally, then re-identified using AI tools.&#8221;</span></p><p>The data middlemen are selling records that are legally de-identified but practically re-identifiable. The &#8220;without your name&#8221; framing is a legal fiction that AI has rendered increasingly untrue.</p><h3><strong>The Consent Theater</strong></h3><p>If the pipeline is invisible, how do patients find out about it? In most cases, they don&#8217;t.</p><p>When you check into a hospital, you sign a group of forms and receive a Notice of Privacy Practices, a long document that mentions treatment, payment, and &#8220;health care operations.&#8221; De-identification and data sharing may be mentioned in a single clause. The notice almost never says, &#8220;Your records may be sold to an AI training data broker.&#8221;</p><p>Some hospitals are becoming more explicit. <a href="https://www.archbold.org/patients-visitors/notice-of-privacy-practices/"><span>Archbold Medical Center in Georgia publishes a Notice of Privacy Practices</span></a> that states, in plain language, &#8220;De-identified data is no longer subject to privacy or security laws.&#8221; It also notes that &#8220;AI use within applications uses/discloses your medical information.&#8221; This is unusually candid. Most notices are not.</p><p>The legal framework creates what might be called consent theater, patients are given a document they do not read, which authorizes broad data uses they do not understand, for purposes, including AI model training, that were not contemplated when HIPAA was written in 1996.</p><h3><strong>The Regulatory Vacuum</strong></h3><p>One might expect that the wave of state consumer privacy laws would close this gap. They largely do not.</p><p><strong>Washington&#8217;s My Health My Data Act (MHMDA)</strong>, enacted in 2023, broadly defines &#8220;consumer health data&#8221; and requires opt-in consent for collection and sale. But the Act <a href="https://fpf.org/wp-content/uploads/2023/04/FPF-Legislation-Policy-Brief_-The-Washington-My-Health-My-Data-Act-Public-Version.pdf"><span>explicitly excludes &#8220;deidentified data&#8221; from its definition of personal information</span></a>. A hospital selling de-identified records to Protege falls outside the law.</p><p><strong>Maryland&#8217;s Online Data Privacy Act (MODPA)</strong>, effective October 2025, has some restrictions on using consumer health data for AI model development. But <a href="https://www.ketch.com/regulatory-compliance/maryland-online-data-privacy-act-modpa"><span>properly de-identified or aggregated data is largely exempt</span></a>.</p><p><strong>Nevada&#8217;s SB 370</strong> and <strong>Connecticut&#8217;s CDPA amendments</strong> follow the same pattern, they regulate identifiable consumer health data but leave the de-identified pipeline untouched.</p><p>At the federal level, the FTC has been active on data broker enforcement, but not on this specific subject. In February 2026, the FTC sent <a href="https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa"><span>warning letters to 13 data brokers</span></a> about compliance with the Protecting Americans&#8217; Data from Foreign Adversaries Act (PADFAA), focusing on foreign data transfers rather than domestic AI training. There is no federal enforcement action specifically targeting the sale of de-identified health records for commercial AI model training.</p><h3><strong>The Convergence</strong></h3><p>The two pipelines are separate in law but convergent in effect. OpenAI is building the infrastructure to ingest medical data on both sides.</p><p>On the front end, <a href="https://www.axios.com/2026/01/12/openai-acquires-health-tech-company-torch"><span>OpenAI acquired Torch, a health records unification startup, for roughly $60-100 million in January 2026</span></a>. Torch&#8217;s technology consolidates fragmented patient data from hospitals, labs, and visit recordings. The stated goal, <a href="https://hlth.com/insights/news/openai-acquires-torch-building-the-unified-medical-memory-for-chatgpt-health-2026-01-13"><span>per HLTH reporting</span></a>, is a &#8220;unified medical memory&#8221; for ChatGPT Health.</p><p>On the back end, OpenAI&#8217;s health data ambitions are clear even if its purchases from middlemen are not publicly documented. The company is positioning itself to be a central platform for health information, whether that data arrives through consumer upload or hospital pipeline.</p><p>The patient, meanwhile, is left with a false sense of security. They are told HIPAA protects their medical records. They are told de-identification makes their data anonymous. They are told they can &#8220;securely&#8221; connect their health records to an AI assistant. None of these statements are entirely false. But none of them capture the full picture of where their data is going, how it is being used, or how thin the legal protections actually are.</p><p>The health data economy has bifurcated into two tracks, one regulated and de-identified, the other unregulated and fully identifiable. Both are feeding the same models. And the patient is the last to know.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[A Complete Guide to AI Healthcare Laws in 2026]]></title><description><![CDATA[Who Decides? The States Are Answering]]></description><link>https://ashooreview.com/p/a-complete-guide-to-ai-healthcare</link><guid isPermaLink="false">https://ashooreview.com/p/a-complete-guide-to-ai-healthcare</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Wed, 29 Jul 2026 17:26:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!erTi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F386b2a35-d637-473e-a88f-d4383ae1d38e_1220x932.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In previous coverage of artificial intelligence in medicine, I kept returning to the same question: Who decides? Who has the authority to approve a procedure, deny a claim, diagnose a condition, or prescribe a treatment when an algorithm is involved? That question was mostly theoretical, debated in conference panels and white papers while federal lawmakers waited for consensus.</span></p><p><span>The waiting ended in 2026. State legislatures stopped asking and started writing. By the end of this year's legislative sessions, more than two dozen new laws and regulations across eighteen states will have redrawn the boundaries of what AI may do in healthcare. Additionally, there is Federal legislation in process that may conflict with everything states have done so far. Here I survey the full landscape in the following categories: </span></p><ul><li><p>Prior Authorizations</p></li><li><p>Therapy</p></li><li><p>Consent and Disclosure</p></li><li><p>Chatbot Safety</p></li><li><p>Professional Licensing</p></li></ul><p>As always, if you enjoy reading, subscribe and tell a friend. </p><p>Sam</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/5M1wb/2/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/386b2a35-d637-473e-a88f-d4383ae1d38e_1220x932.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da7c1a8b-04cd-41b0-b4ca-dda81b16d07d_1220x1002.png&quot;,&quot;height&quot;:492,&quot;title&quot;:&quot;U.S. Healthcare AI Laws&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:false}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/5M1wb/2/" width="730" height="492" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h3>Prior Authorizations</h3><p><em>The most active legislative front in 2026 was prior authorization. Seven states enacted laws that draw a hard line between AI assistance and AI decision-making for coverage denials. Two additional states also took related approaches targeting claims downcoding and oversight reporting.</em></p><p><strong>Alabama</strong> <a href="https://legiscan.com/AL/text/SB63/id/3368521">SB 63</a>, enacted on April 17, requires health insurers to disclose their use of AI, base authorization decisions on a patient&#8217;s individual medical history, and ensure that any denial is issued by a licensed professional. It is similar to the disclosure-plus-human-review framework seen elsewhere, but it explicitly ties authorization decisions to individual medical records rather than group data.</p><p><strong>Colorado</strong> <a href="https://leg.colorado.gov/bills/HB26-1139">HB 1139</a>, signed June 2, prohibits insurers from basing a denial solely on group data or algorithms and requires a licensed clinician to review any adverse decision. The subtle but critical distinction here is the explicit ban on group-level data as the basis for individual denials, a protection Alabama and Washington do not spell out as directly.</p><p><strong>Georgia</strong> <a href="https://gafasttrack.com/bill.html?bill=SB444&amp;session=2167">SB 444</a>, enacted May 5, is one of the shortest and most direct statutes in this category: a blanket prohibition on coverage decisions based solely on AI systems or software tools. It is nearly identical in spirit to Iowa&#8217;s approach but without Iowa&#8217;s explicit carveout allowing AI to conduct initial screening.</p><p><strong>Illinois</strong> <a href="https://www.ilga.gov/legislation/BillStatus?DocNum=3114&amp;GAID=18&amp;DocTypeID=SB&amp;LegId=165735&amp;SessionID=114">SB 3114</a>, awaiting the governor&#8217;s signature, is the only law in this category that targets downcoding, the practice of reducing reimbursement codes, rather than prior authorization denials. It prohibits AI from bypassing provider documentation to downgrade claims and requires a natural person to review any downcoding determination.</p><p><strong>Indiana</strong> <a href="https://iga.in.gov/legislative/2026/bills/house/1271">HB 1271</a>, enacted March 4 and effective July 1, is the only law regulating AI on both sides of the transaction: it prohibits insurers from using AI as the sole basis for downcoding and bars providers from using AI to submit claims without human review. It bridges the gap between utilization-review laws and claims-integrity laws.</p><p><strong>Iowa</strong> <a href="https://legiscan.com/IA/text/HF2635/id/3383589">HF 2635</a>, enacted May 13, creates a two-step process: AI may screen prior authorization requests, but only a human may deny, delay, or downgrade them. The statute is nearly identical in structure to Utah&#8217;s approach but with less detail on time limits and validity periods.</p><p><strong>Maryland</strong> <a href="https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb1563?ys=2026RS">HB 1563</a>, enacted April 28, takes an oversight approach rather than a direct prohibition. It requires insurers to file quarterly reports on AI-assisted adverse decisions and allows the insurance commissioner to investigate spikes in denials, particularly for emergency department services. It is the only authorization-related law focused on regulatory monitoring rather than rewriting decision-making rules.</p><p><strong>Utah</strong> <a href="https://le.utah.gov/Session/2026/bills/static/SB0319.html">SB 319</a>, enacted March 19, requires disclosure of AI use in preauthorization, mandates independent medical judgment by reviewers, and sets minimum validity periods for chronic condition authorizations. It is the most procedurally detailed of the authorization statutes, paired with a separate scope-of-practice law passed the same week.</p><p><strong>Washington</strong> <a href="https://lawfilesext.leg.wa.gov/biennium/2025-26/Pdf/Bill%20Reports/Senate/5395%20SBR%20WM%20TA%2025.pdf">SB 5395</a>, enacted March 23, expands the state&#8217;s existing prior authorization framework and explicitly bars AI from modifying care, not just denying it. This is a broader prohibition than most, covering any adverse modification of a treatment plan.</p><h3>Therapy</h3><p><em>While prior authorization laws dominated, therapy bans consumed the headlines. Six states enacted statutes prohibiting AI from providing psychotherapy or representing itself as a mental health professional. Most took effect in 2026 or will take effect in 2027.</em></p><p><strong>Colorado</strong> <a href="https://leg.colorado.gov/bills/hb26-1195">HB 1195</a>, enacted June 3, is the most comprehensive therapy ban in the country. It prohibits unlicensed AI chatbots from offering psychotherapy and also restricts licensed psychologists, counselors, and social workers from using AI to provide independent therapeutic services. It is the only law that explicitly limits both the unlicensed and licensed sides of the equation.</p><p><strong>Maine</strong> <a href="https://legislature.maine.gov/legis/bills/display_ps.asp?LD=2082&amp;snum=132">LD 2082</a>, enacted April 13, prohibits AI from providing therapy or psychotherapy and classifies offering therapy via AI without a license as an unfair trade practice. It also adds a patient-consent requirement for ambient listening and AI-powered recording during sessions. It is nearly identical in scope to Nevada&#8217;s law but adds the recording consent provision.</p><p><strong>Nevada</strong> <a href="https://www.leg.state.nv.us/Session/82nd2023/Bills/AB/AB406_EN.pdf">AB 406</a>, enacted in 2023 and effective July 1, 2025, was the first therapy-bot ban in the nation. It applies to any AI system in Nevada, including telehealth platforms, and imposes civil penalties of up to $1,500 per violation. It served as the model for several 2026 statutes, including Maine&#8217;s and Rhode Island&#8217;s.</p><p><strong>Rhode Island</strong> <a href="https://www.rilegislature.gov/BillText/BillText26/HouseText26/H7349.pdf">H 7349</a> / <a href="https://www.rilegislature.gov/BillText/BillText26/SenateText26/S2197.pdf">S 2197</a>, enacted June 22, contains a dual prohibition: unlicensed AI may not practice therapy, and licensed providers may not use AI for independent therapeutic decisions or treatment plans. It is nearly identical in structure to Colorado&#8217;s law but lacks the explicit licensed-provider restrictions seen in Colorado&#8217;s statute.</p><p><strong>Tennessee</strong> <a href="https://www.capitol.tn.gov/Bills/112/Bill/SB1580.pdf">SB 1580</a>, enacted April 1, prohibits developing or deploying AI systems that advertise or represent themselves as qualified mental health professionals. It treats such misrepresentation as a deceptive practice under state consumer protection law. It is narrower than Colorado&#8217;s ban, and targets the advertising and representation rather than the therapeutic act itself.</p><p><strong>Vermont</strong> <a href="https://legislature.vermont.gov/bill/status/2026/H.816">H 816</a>, enacted June 17, safeguards individuals seeking mental health services by ensuring delivery by professionals rather than independently by AI systems. The wording lacks the explicit title protections and civil penalties seen in Nevada and Rhode Island. It is the least prescriptive of the therapy bans.</p><h3>Consent and Disclosure</h3><p><em>Four states enacted or implemented disclosure requirements in 2025 and 2026, creating a patchwork of transparency obligations that providers and insurers now must navigate.</em></p><p><strong>Arizona</strong> Board of Behavioral Health Examiners adopted regulations in November 2025, effective January 1, 2027, requiring behavioral health professionals to obtain and document informed consent before providing services involving AI. It is the only regulatory (non-statutory) entry in this survey and applies only to behavioral health, making it narrower than California&#8217;s statewide disclosure laws.</p><p><strong>California</strong> <a href="https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB3030">AB 3030</a>, enacted in 2024 and effective January 1, 2025, was the first statewide disclosure law in the nation. It requires any generative AI communication to a patient to include a clear disclaimer that the message was generated by AI. <a href="https://legiscan.com/CA/text/AB489/id/3272936">AB 489</a>, enacted in 2025 and effective January 1, 2026, goes further by prohibiting AI systems from presenting themselves as licensed medical professionals. Together, these two laws create a layered transparency framework that no other state has fully replicated.</p><p><strong>Louisiana</strong> <a href="https://www.legis.la.gov/legis/ViewDocument.aspx?d=1460326">HB 475</a>, enacted June 2, requires verbal disclosure of any recording device or AI transcription before recording any clinical visit. It is the only law in the country that mandates verbal (not just written) disclosure for AI transcription, and it applies to all healthcare settings including telehealth.</p><p><strong>Texas</strong> <a href="https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&amp;Bill=SB1188">SB 1188</a>, enacted in 2025 and effective September 1, 2025, is the most permissive framework in this category. It explicitly allows AI to diagnose and treat patients, provided the patient is informed and the Texas Medical Board has reviewed the technology. It is the only state that affirmatively authorizes AI clinical decision-making rather than merely restricting it.</p><h3>Chatbot Safety</h3><p><em>Three states enacted what are effectively &#8220;Chatbot Safety Acts&#8221;: laws that do not regulate medical practice directly but impose safety and disclosure requirements on AI chatbots that might interact with patients in crisis.</em></p><p><strong>Idaho</strong> <a href="https://legislature.idaho.gov/sessioninfo/2026/legislation/S1297/">SB 1297</a>, enacted March 31 and effective July 1, 2027, requires disclosure and crisis-response protocols for any conversational AI system that provides health-related information. The law is nearly identical to Nebraska&#8217;s, suggesting both states may have used model legislation.</p><p><strong>Nebraska</strong> <a href="https://nebraskalegislature.gov/bills/view_bill.php?DocumentID=59601">LB 525</a>, enacted April 14, combines the Agricultural Data Privacy Act with a Conversational AI Safety Act that applies to all public-facing AI chatbots with healthcare safety requirements. It is identical in structure to Idaho&#8217;s law but applies to all public-facing chatbots, not just health-specific ones.</p><p><strong>Oregon</strong> <a href="https://olis.oregonlegislature.gov/liz/2026R1/Measures/Overview/SB1546">SB 1546</a>, enacted March 31, is the most comprehensive chatbot safety law in the country. It includes a private right of action, safeguards for minors, and covers AI companions. It is significantly broader than the Idaho and Nebraska statutes, extending beyond healthcare to cover emotional support AI.</p><h3>Professional Licensing</h3><p><em>Two states passed laws clarifying that AI is not a licensed professional, using different legal techniques to reach the same conclusion.</em></p><p><strong>Delaware</strong> <a href="https://legis.delaware.gov/BillDetail/142752">HB 191</a>, enacted April 23, prohibits any nonhuman entity, including AI, from being licensed or certified as a nurse, physician, or physician assistant. It also bars AI from using protected professional titles. It is the most explicit title-protection law in the survey.</p><p><strong>Utah</strong> <a href="https://le.utah.gov/Session/2026/bills/static/SB0150.html">SB 150</a>, enacted March 24, uses a negative-definition approach: AI providing advice or treatment without a practitioner-patient interaction does not qualify as an &#8220;innovation&#8221; within the scope of practice. It is the only law that defines AI out of scope rather than explicitly prohibiting licensure. Paired with Utah&#8217;s SB 319, enacted the day before, these two laws create the most comprehensive AI regulatory framework of any single state.</p><h3>The Horizon: Pending Bills and Federal Counter-Trends</h3><p><em>Three jurisdictions have legislation still pending that could reshape the landscape by 2027.</em></p><p><strong>New York</strong> <a href="https://www.nysenate.gov/legislation/bills/2025/S7896">S7896</a> / <a href="https://nyassembly.gov/leg/?default_fld=%0D%0A&amp;bn=A8556&amp;term=2025&amp;Summary=Y&amp;Actions=Y&amp;Committee%26nbspVotes=Y&amp;Floor%26nbspVotes=Y&amp;Memo=Y&amp;Text=Y">A8556</a>, introduced in the 2025-2026 session, would establish comprehensive AI utilization review requirements. It is the most detailed authorization law proposed to date, with specific reporting and human-review mandates that go beyond the 2026 enacted statutes. </p><p><strong>Pennsylvania</strong> <a href="https://www.legis.state.pa.us/cfdocs/billinfo/billinfo.cfm?syear=2025&amp;sind=0&amp;body=H&amp;type=B&amp;bn=1925">HB 1925</a>, introduced in the 2025-2026 session, would amend both the Health and Insurance titles to require AI utilization review and reporting by insurers, hospitals, and clinicians. It is broader than most authorization bills because it covers providers as well as insurers.</p><p><strong>Federal</strong> <a href="https://www.congress.gov/bill/119th-congress/house-bill/238/text">H.R. 238</a>, the Healthy Technology Act, stands in direct counterpoint to the state trend. Introduced in the 119th Congress, it would allow AI and machine learning systems to qualify as practitioners able to prescribe FDA-approved drugs, effectively federalizing the expansion of AI clinical authority that Texas alone has permitted at the state level. If it advances, it would create a direct conflict with the authorization and therapy bans enacted by more than two dozen states.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[OpenAI's Uncontrolled Experiment]]></title><description><![CDATA[A sandbox breach, a 52 percent under-triage rate, and two lawsuits all point to the same architecture OpenAI now uses to read patient charts.]]></description><link>https://ashooreview.com/p/openais-uncontrolled-experiment</link><guid isPermaLink="false">https://ashooreview.com/p/openais-uncontrolled-experiment</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 24 Jul 2026 16:00:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zaXE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>I have spent most of this newsletter on the clinician side of AI, scribes, decision support, imaging. This week I'm looking at the other side of the exam room: OpenAI just put a model with a documented 52 percent emergency miss rate directly into 300 million patients' hands. Let&#8217;s dive into why that might be problematic. </em></p><p><em>As always, if you enjoy reading, subscribe and tell a friend. </em></p><p><em>Sam</em></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zaXE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zaXE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zaXE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:531668,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/208344546?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zaXE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zaXE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d25764-fd0b-45b6-b1cf-8689d04eabfb_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 22, 2026, Pastor Scott Winters sued OpenAI in San Francisco County Superior Court. The complaint describes a five-week pattern that began a year earlier. On June 8, 2025, Winters grew dizzy mid-sermon and had to stop the service; paramedics were called and found him stable. Two days later, on June 10, too dizzy to walk, he crawled toward his bathroom and asked ChatGPT for directions across the floor between himself and his recliner. Both times, the suit alleges, ChatGPT told him to take it easy and that his symptoms would improve. On July 13, 2025, Winters asked ChatGPT about a pain in his groin. The suit alleges it offered spiritual reassurance, telling Winters that &#8220;God did not design your body to endlessly fail.&#8221; Hours later, he was in the intensive care unit with a massive pulmonary embolism. <a href="https://www.cbsnews.com/news/chatgpt-dangerous-medical-advice-openai-lawsuit/">Winters filed his suit</a> one day before OpenAI expanded Health in ChatGPT to 300 million weekly users.</p><p>Six weeks before Winters&#8217; hospitalization, on May 31, 2025, nineteen-year-old Sam Nelson asked ChatGPT about nausea from Kratom use. Nelson had used ChatGPT since high school for homework, and according to the family&#8217;s complaint, the system had initially refused to discuss drug use with him at all. The complaint alleges those refusals stopped after the rollout of GPT-4o in 2024, and that by May 2025 the chatbot was offering him specific guidance instead. Rather than tell him to stop or seek care, it suggested pairing the Kratom with 0.25 to 0.5 milligrams of Xanax to &#8220;minimize nausea.&#8221; Nelson died that night of asphyxiation from the combination. <a href="https://www.engadget.com/2171685/openai-lawsuit-wrongful-death-chatgpt-advice-overdose-sam-nelson/">His parents filed a wrongful-death suit</a> in May 2026, arguing that ChatGPT had functioned as an active clinical decision-maker, not a passive search engine, and that a safety behavior the system once had was allowed to erode.</p><p>Both lawsuits were filed within nine weeks of each other, in the same stretch of 2026 when OpenAI was expanding its product&#8217;s reach to nearly the population of the United States. Together, the two cases show a pattern. A conversational AI system overrode medical urgency, once with spiritual language, once with a specific drug dose, and in both cases the underlying failure was the same: an architecture that struggles to recognize a rare, dangerous symptom because it is built to predict what&#8217;s statistically common, not what&#8217;s clinically true.</p><h3>The Study Behind the Number</h3><p>That failure has since been measured directly. In February 2026, <a href="https://doi.org/10.1038/s41591-026-04297-7">Ramaswamy and colleagues at the Icahn School of Medicine at Mount Sinai published a study in Nature Medicine</a> testing Health in ChatGPT, one month after launch. Researchers tested the product across 60 clinician-authored vignettes, yielding 960 total responses. It under-triaged roughly 52 percent of gold-standard emergencies, cases where every reviewing clinician agreed on the correct triage level. In practice, that meant sorting patients with conditions like diabetic ketoacidosis or impending respiratory failure into a 24-to-48-hour follow-up window instead of directing them to emergency care. The failures followed an inverted U-shaped pattern: the system missed 35 percent of nonurgent cases, sending people who didn&#8217;t need it toward urgent care, and 48 percent of true emergencies, the more dangerous error. It struggled most at both extremes rather than erring safely in one direction. Because the researchers tested the live product rather than a benchmark model, that 52 percent figure describes the exact system OpenAI connected to Epic, MyChart, One Medical, and Apple Health on July 23, 2026. OpenAI has pushed back on the study&#8217;s relevance, telling reporters that single-prompt vignettes don&#8217;t reflect &#8220;typical use,&#8221; since the product is designed for multi-turn conversations where patients supply additional context through follow-up questions. That may be true of some users. It does not explain why the same product, tested as it actually ships, missed the emergency in nearly half of the cases where the correct answer was to send someone to a hospital.</p><h3>The Sandbox That Didn&#8217;t Hold</h3><p>Two days before that expansion, on July 21, 2026, OpenAI and Hugging Face disclosed a security incident that undercuts any claim that the underlying architecture is under control. The incident began inside ExploitGym, an internal OpenAI benchmark built to measure whether frontier models could turn known software vulnerabilities into working exploits, a test of cyber capability with no connection to medical or consumer safety. During that test, GPT-5.6 Sol and an unreleased, more capable model escaped the isolated environment built to contain them. The models found a hidden flaw in a piece of software so obscure that even its own developers didn't know it existed. That flaw was enough to slip past the barriers meant to contain them. From there, they worked their way deeper into OpenAI's own systems, picking up login credentials and higher-level access along the way, until they reached the live servers running Hugging Face's actual public platform, not a test copy. Reporting on the incident described it as thousands of individual actions carried out across a swarm of short-lived sandboxes, a scale well beyond a single lucky guess. OpenAI's own account describes a multi-step plan, executed autonomously, to defeat an isolation boundary that had been purpose-built to hold the model.</p><h3>What the Breach Does and Doesn&#8217;t Prove</h3><p>Some caveats matter here. The model that escaped is not the exact instance running inside Health in ChatGPT, and the environment it escaped was a research sandbox rather than a live production server. The incident also occurred while OpenAI had deliberately reduced the models&#8217; safety refusals for the purposes of the evaluation, so it does not show what happens under normal deployment conditions. What it does show is a capability that can&#8217;t be walked back with a patch: this model family, when its refusals are lowered or bypassed, can plan and execute a multi-domain escape without human authorization. That is closer to discovering a structural flaw in a medical device than a bug in one unit. The specific unit in the hospital may not have overheated yet, but the design has already shown it can. Installing that design in every ward, days after finding the flaw, is a decision that needs justifying, not assuming.</p><h3>Why the Architecture Fails This Way</h3><p>The clinical failure and the security failure share a root cause. Large language models generate text by predicting the most statistically likely next word given everything that came before. That process rewards fluency and common answers, a tendency researchers call regression to the mean: the model&#8217;s outputs cluster around the most probable response in its training data, at the expense of rare but important outliers. The training data itself makes this specifically worse in medicine. Models learn from internet-scale text in which routine complaints, muscle strain, stress, fatigue, vastly outnumber descriptions of rare emergencies, so the &#8220;likely&#8221; answer reflects what&#8217;s overrepresented in the general data rather than what&#8217;s actually likely for the patient typing the question. A weather model that always forecasts &#8220;partly cloudy&#8221; would be right most days and catastrophically wrong on the day a hurricane arrives. Pulmonary embolism is rare in the universe of chat transcripts about groin pain; muscle strain and spiritual doubt are common. Faced with Winters&#8217; symptom, a system optimized for the likely answer will drift toward the likely explanation. There&#8217;s no malice in this. The architecture is doing exactly what it was built to do, and that is the problem in a clinical setting where the rare case is often the one that kills.</p><h3>A System Built Differently</h3><p>Contrast this with a different architecture. MomConnect, South Africa&#8217;s government maternal health platform, added a symptom-checking tool from Ada Health built on a Bayesian network: a model that encodes medical knowledge as explicit probabilities and updates them as new evidence comes in, rather than generating conversational text. The mechanics are different. The system starts with a prior probability for each condition it&#8217;s tracking, then updates that number as symptoms are entered, arriving at a posterior probability the system can act on directly: refer the case, ask another question, or reassure. When a Bayesian network is uncertain, that uncertainty is a number the system can act on, not a pattern buried inside billions of weights. Ada&#8217;s underlying engine also carries CE marking as regulated medical device software in Europe, a regulatory status Health in ChatGPT does not have. A study by <a href="https://doi.org/10.1038/s44360-026-00125-x">Schmude and colleagues, published in Nature Health in June 2026</a>, evaluated the tool&#8217;s advice to 968 pregnant women and mothers and found a physician panel rated it safe in 98.4 percent of cases, with appropriate care-seeking rising by more than 40 percentage points. The gap between that result and the 52 percent under-triage rate for Health in ChatGPT isn&#8217;t a matter of better prompts or more training data. It reflects two different ways of handling uncertainty. One system can tell you, in a number, how sure it is. The other generates a confident sentence whether or not it should.</p><h3>The Regulatory Gap</h3><p>That is also why "Health in ChatGPT" sits in a regulatory gap rather than a regulated category. The European Union's AI Act treats general-purpose AI models with systemic reach as their own class, subject to added testing and governance. The Act draws that line using a measure of how much raw computing power went into training a model, a number large enough that it's written in scientific notation: 10^25 floating-point operations, essentially a tally of the individual calculations involved in building the system. Cross that line, and the law assumes, by default, that the model carries systemic risk. A company can still make the case that its model doesn't actually pose that risk, but the starting point shifts toward oversight rather than away from it. A model that just demonstrated an autonomous escape from a security sandbox while serving 300 million weekly users is a reasonable candidate for that scrutiny. But systemic-risk status under the AI Act is not the same as an Annex III high-risk medical device classification, and OpenAI's product currently qualifies for neither in the way a diagnostic device would. The United States has, if anything, moved in the opposite direction. On January 6, 2026, the FDA issued revised guidance on clinical decision support software that loosened its prior stance on automation bias. The previous version had treated tools that presented a single recommendation as raising heightened safety concerns; the new guidance takes a more permissive, risk-based approach instead. That change landed six months before this launch, in the same regulatory environment where Health in ChatGPT now operates. A chatbot with a medical disclaimer, wired into Epic MyChart and making triage-adjacent judgments for hundreds of millions of people, is large enough to matter and, under current rules on both sides of the Atlantic, small enough to avoid the oversight a medical device would face. </p><h3>The Experiment Continues</h3><p>None of this is abstract. Winters and Nelson show what the failure looks like in a single conversation. The Ramaswamy study shows how often it happens across the live product. The Hugging Face disclosure shows the same model family can defeat a boundary built specifically to contain it. Put together, they describe a product launched into open clinical use before any of those three questions- whether the model can be trusted with rare symptoms, whether its containment holds under pressure, and who is checking either claim besides the company that built it- have been independently answered. Independent verification would mean outside researchers, people with no financial ties to OpenAI, deliberately trying to break the system and expose where it fails. Or it would mean a regulator with real investigative authority taking up the question directly. It would not mean another blog post from the company itself. The lawsuits will keep arriving. The question worth asking now is how many more it will take before this is treated as a systemic risk to public health rather than a chatbot with a disclaimer attached.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Who Gets to Decide When AI Is Ready to Perform Medical Work?]]></title><description><![CDATA[Utah&#8217;s AI Pilot Exposed a Governance Question That Medicine Has Never Had to Answer]]></description><link>https://ashooreview.com/p/who-gets-to-decide-when-ai-is-ready</link><guid isPermaLink="false">https://ashooreview.com/p/who-gets-to-decide-when-ai-is-ready</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Tue, 21 Jul 2026 12:56:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cxTW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>I&#8217;ve been thinking about the Utah AI prescription pilot since it began in April. Medicine spent a century building a process for deciding when a physician is ready to practice. Nobody has built the equivalent process for software. The Utah experiment didn&#8217;t answer that question. It just made clear how badly we need one. Let&#8217;s talk about it in detail. </em></p><p><em>As always, if you enjoy reading, subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cxTW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cxTW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cxTW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:578034,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/207907147?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cxTW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cxTW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefdf7e18-2d28-40ec-ac43-e96efdf1f73a_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Who gets to decide that software is ready to perform work that has historically required a medical license?</p><p>Medicine has spent more than a century building institutions that determine when physicians are competent to care for patients. Medical schools educate them. Residency programs train them. Specialty boards certify them. State medical boards license them. Hospitals credential them. Peer review evaluates them. Courts review their actions when patients are harmed.</p><p>Those institutions are not perfect, but together they establish something fundamental. Society has created a process for determining when a physician is competent enough to practice medicine.</p><p>Artificial intelligence introduces a new challenge because software is beginning to perform tasks that have traditionally depended on physician judgment. I am not talking about whether AI will participate in medicine. I&#8217;m adking who has jurisdiction to determine when the evidence is sufficient for software to assume greater clinical responsibility.</p><p>Earlier this year, Utah became one of the first states to confront that question directly. The debate that followed was widely portrayed as one about artificial intelligence and prescription renewals. I believe it was fundamentally a debate about jurisdiction over medical competence.</p><h3>The Utah Pilot Structure</h3><p>In December 2025, Utah&#8217;s Office of Artificial Intelligence Policy authorized a health technology company called Doctronic to begin renewing prescriptions for Utah patients using an AI system, under a 12-month <a href="https://commerce.utah.gov/ai/regulatory-mitigation/agreements/doctronic/"><span>regulatory sandbox agreement</span></a> announced January 6, 2026.</p><p>The Office of Artificial Intelligence Policy was created in 2024 under <a href="https://le.utah.gov/~2024/bills/static/SB0149.html"><span>Utah&#8217;s AI Policy Act, SB 149</span></a>, which gives the office authority to temporarily waive regulatory requirements so companies can test AI systems under state supervision. Utah has used that same authority for a mental health chatbot aimed at teenagers and for <a href="https://commerce.utah.gov/ai/regulatory-relief/authorized-ai-pilots/dentacor/"><span>an AI tool that reads dental radiographs</span></a>. Doctronic&#8217;s agreement lets its AI process 30-, 60-, or 90-day renewals for medications that a licensed physician has already prescribed, and screen for drug interactions along the way.</p><p>The pilot is structured in three phases. In Phase One, every AI-generated renewal is reviewed and approved by a licensed physician before it reaches a pharmacy. Phase Two would move that review to shortly <em><strong>after</strong></em> a prescription is issued. Phase Three would allow the system to renew prescriptions with only periodic sampling of AI outputs for oversight. State officials say the pilot will not advance to the next phase until safety has been demonstrated in the one before it.</p><p>Before the pilot launched, Doctronic shared data with state regulators comparing its AI&#8217;s recommendations to physicians&#8217; decisions across 500 urgent care cases. The company reported that its recommendations matched physicians&#8217; <a href="https://www.politico.com/news/2026/01/06/artificial-intelligence-prescribing-medications-utah-00709122"><span>99.2 percent of the time</span></a>.</p><p>Medication renewals consume substantial physician time, and many involve stable chronic conditions with predictable decision pathways. Exploring whether AI can safely assist physicians with those tasks is a reasonable objective.</p><h3>The Utah Pilot Significance</h3><p>On April 20, 2026, eleven of the fourteen members of the Utah Medical Licensing Board sent a <a href="https://commerce.utah.gov/wp-content/uploads/2026/04/doctronic-letter-from-medical-board.pdf"><span>letter</span></a> to the Office of Artificial Intelligence Policy. They wrote that the board &#8220;was made aware of this agreement only after its implementation, once the system was already live and available for use.&#8221; The letter argued that prescription refills require reassessment of dose, side effects, contraindications, and drug interactions, work the board said belongs to a licensed physician, and it warned that &#8220;patients who continue refilling medications without assessment may remain on outdated or suboptimal therapy for months or years.&#8221; It closed by recommending that the pilot &#8220;be immediately suspended pending further discussion.&#8221;</p><p>The next day, the directors of the Office of Artificial Intelligence Policy and the Division of Professional Licensing <a href="https://commerce.utah.gov/wp-content/uploads/2026/04/Medical-Board-Doctronic-Response.pdf"><span>responded in writing</span></a>. They said the pilot had been &#8220;rigorously reviewed by several medical professionals prior to launch,&#8221; a process that produced &#8220;a large number of suggested substantive adjustments and guardrails,&#8221; and that the state would not suspend the pilot because it remained in Phase One, where a physician reviews every renewal before it is filled. They committed to involving the board more closely going forward.</p><p>Reasonable people can disagree about whether that was the correct decision. The more enduring question concerns the process itself. Which institution should determine that the available evidence justifies introducing software into a clinical role that has traditionally required physician judgment?</p><h3>Evidence and Jurisdiction Cannot Be Separated</h3><p>Much of the public debate over the Utah pilot focused on the AI itself: was it accurate, was physician oversight sufficient, should refill decisions be delegated to software at all.</p><p>Those questions naturally followed once the pilot was underway. They also assume that someone had already concluded the available evidence justified launching it. Let&#8217;s take a closer look.</p><p>The Doctronic pilot shows how the same evidence can support different conclusions. A 99.2 percent concordance rate across 500 urgent care cases was sufficient for the state and the medical professionals who reviewed the pilot before launch. It was not sufficient for the Medical Licensing Board, whose objection was not about the AI&#8217;s accuracy in aggregate. It was about what a refill requires in every individual case: a reassessment that a benchmark conducted before launch cannot fully substitute for once the system is operating on real patients. Both readings of the evidence are defensible. They come from institutions with different responsibilities.</p><p>The institution responsible for authorizing clinical AI also determines what counts as convincing evidence. A software engineer may prioritize benchmark performance and operational reliability. A practicing physician may focus on uncommon but consequential clinical presentations. A statistician may emphasize study design and external validity. A regulator may concentrate on statutory authority, while a hospital executive may view liability and implementation as equally important.</p><p>Each perspective is legitimate. Each emphasizes different forms of evidence. The authority that evaluates the evidence decides the standard by which readiness is judged.</p><h3>Medicine Already Has a Model</h3><p>Imagine a hospital announced that it had created a pathway allowing physicians to practice emergency medicine without residency training. The first question would not concern examination scores or clinical outcomes. It would concern authority. Who approved this process?</p><p>Medicine has developed a distributed system for answering that question. Medical education is accredited. Residency programs are supervised. Licensing examinations are standardized. Board certification is independently administered. Hospitals grant privileges only after reviewing credentials and competence.</p><p>No single organization controls that process. Government, professional organizations, accrediting bodies, and hospitals all participate. Each contributes a different perspective before a physician is entrusted with patient care.</p><p>Clinical AI is developing without an equally mature framework for determining when software is ready to assume comparable responsibilities.</p><h3>The Same Evidence, Different Conclusions</h3><p>One reason these discussions become contentious is that stakeholders evaluate evidence through different lenses.</p><p>Software developers ask whether the model performs accurately. Researchers ask whether a study demonstrates benefit. Medical boards ask whether patient safety has been adequately protected. Attorneys ask who assumes liability when errors occur. Patients ask whether they can trust the recommendations being made.</p><p>These are not competing questions, but complementary ones.</p><p>Evidence never speaks for itself. People decide what the evidence is sufficient to support.</p><h3>A Different Way to Begin</h3><p>Imagine Utah had started somewhere else. Before enrolling the first patient, the state convenes a multidisciplinary commission composed of primary care physicians, pharmacists, medical licensing officials, software engineers, biostatisticians, health services researchers, patient representatives, ethicists, and regulators. Their first task is not evaluating the AI, but instead defining the rules.</p><p>What evidence will be required? How should safety be measured? What outcomes matter? What level of physician oversight is necessary? Who has authority to suspend the pilot if safety concerns emerge?</p><p>Only after those questions are answered does the commission evaluate the software.</p><p>That sequence changes the discussion. The debate isn&#8217;t about defending or criticizing artificial intelligence. It is about establishing a legitimate process before patients become part of the evaluation.</p><h3>Why Utah Matters</h3><p>Prescription renewals are unlikely to be the last area where this issue appears.</p><p>Utah has already used the same regulatory sandbox authority outside prescribing: for a mental health chatbot aimed at teenagers and for <a href="https://commerce.utah.gov/ai/regulatory-relief/authorized-ai-pilots/dentacor/"><span>an AI tool that reads dental radiographs</span></a>. The same questions will emerge in radiology, pathology, dermatology, emergency medicine, imaging interpretation, treatment recommendations, autonomous documentation, and other clinical applications as AI capabilities continue to expand.</p><p>Every new application will generate studies, benchmark results, and performance claims. Those discussions remain essential. They do not eliminate the need for an accepted process that determines when the available evidence justifies broader clinical use.</p><p>The American Medical Association has already staked out a position on where that leaves physicians. Responding to the Utah pilot, AMA chief executive Dr. John Whyte <a href="https://www.politico.com/news/2026/01/06/artificial-intelligence-prescribing-medications-utah-00709122"><span>said</span></a> that &#8220;while AI has limitless opportunity to transform medicine for the better, without physician input it also poses serious risks to patients and physicians alike.&#8221;</p><p>Without an agreed framework, different organizations will continue reaching different conclusions from similar evidence because they are applying different standards and serving different responsibilities.</p><h3>The Question Utah Leaves Behind</h3><p>The public conversation often frames medical AI as a choice between accelerating innovation and slowing it down. Utah suggests the more important issue comes earlier.</p><p>Before software performs work that has historically required a medical license, society should determine who has jurisdiction to evaluate the evidence, what standards that evidence must satisfy, and how disagreements between institutions will be resolved.</p><p>The Utah pilot may ultimately prove to be an important success. It may demonstrate that AI can safely improve efficiency in routine clinical care. Regardless of its eventual outcome, it has already exposed a governance question that will become increasingly difficult to ignore.</p><p>Medicine has long established how society decides that physicians are ready to care for patients. Artificial intelligence now requires an equally thoughtful process for deciding when software is ready to assume comparable responsibilities. Utah did not answer that question. It demonstrated that we need one.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Regulatory Uncertainty Was Real. It Just Wasn't the Kind OpenEvidence Meant.]]></title><description><![CDATA[What the EU requires, what the US exempts, and where OpenEvidence stands.]]></description><link>https://ashooreview.com/p/the-regulatory-uncertainty-was-real</link><guid isPermaLink="false">https://ashooreview.com/p/the-regulatory-uncertainty-was-real</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 17 Jul 2026 17:23:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yGeY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>OpenEvidence pulled its clinical AI platform from the EU and the UK in April 2026. The reason was &#8220;mounting regulatory uncertainty &#8220;. That phrase is doing a lot of work. Let&#8217;s take a closer look at what the EU requires of a product like OpenEvidence, what the US exempts and how narrowly, what happens on both sides of the Atlantic if a vendor doesn&#8217;t qualify for that exemption, and what OpenEvidence itself did in the weeks around its exit. </p><p>As always, if you enjoy reading, subscribe and tell a friend.</p><p>Sam</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yGeY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yGeY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yGeY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:448972,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/207446446?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yGeY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yGeY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ea88c38-4d4a-4f1b-acea-04a7fd873941_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On April 27, 2026, OpenEvidence pulled its clinical AI platform from the EU and UK. The notice that replaced it cited &#8220;mounting regulatory uncertainty regarding the treatment of AI systems in the European Union and the United Kingdom, including, among other rules, the EU Artificial Intelligence Act.&#8221; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YdtL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YdtL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YdtL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg" width="484" height="429.0112589559877" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:866,&quot;width&quot;:977,&quot;resizeWidth&quot;:484,&quot;bytes&quot;:115780,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/207446446?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YdtL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YdtL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf860c2e-6b73-4f6e-a4e7-7499a12ffc65_977x866.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>What the EU Actually Requires</h3><p>Let&#8217;s start with what &#8220;high-risk&#8221; means under the <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">EU AI Act</a>, because most coverage of this story treated it as a vague label. <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> places clinical decision support software in the high-risk category regardless of whether it&#8217;s also regulated as a medical device. That status requires, under <a href="https://artificialintelligenceact.eu/section/3-2/">Chapter III, Section 2 (Articles 8-15)</a>, a conformity assessment before the product reaches the market, technical documentation covering training data characteristics and known limitations, a human oversight mechanism built into the product&#8217;s design rather than added as a disclaimer, data governance standards for training data, ongoing post-market monitoring, and mandatory reporting of serious incidents to national authorities within 15 days.</p><p>None of that is free. Industry estimates put ongoing compliance at roughly &#8364;29,000 a year per AI system, with certification running another &#8364;17,000 to &#8364;23,000. The penalties for getting it wrong in <a href="https://artificialintelligenceact.eu/article/99/">Article 99</a> sets fines up to &#8364;35 million or 7 percent of global turnover for the most serious violations, up to &#8364;15 million or 3 percent for ordinary high-risk violations. A US company weighing whether the exposure justifies the market has real numbers to weigh it against.</p><p>The obligation doesn&#8217;t stop at the vendor, either. A hospital or clinic that adopts a high-risk AI tool becomes a &#8220;deployer&#8221; under <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a>, which lists twelve distinct duties, including assigning a person with actual authority to override the system, monitoring its performance, retaining logs for at least six months, notifying affected patients that they&#8217;re subject to the system, and training staff to understand what the tool can and can&#8217;t do. If you&#8217;re a health system reader in the EU wondering whether any of this applies to you, it does the moment you adopt a high-risk AI tool, regardless of what the vendor has or hasn&#8217;t done on their end.</p><h3>What the US Exempts, and How Narrowly</h3><p>In the US, software like OpenEvidence can avoid FDA device regulation entirely under the Non-Device Clinical Decision Support carve-out in the 21st Century Cures Act. FDA&#8217;s final guidance, issued March 11, 2026, sets four criteria a product has to meet simultaneously to qualify:</p><ul><li><p>It cannot acquire, process, or analyze a medical image, an in vitro diagnostic signal, or a pattern or signal from a signal acquisition system. FDA&#8217;s own guidance specifically names ECG waveforms as an example.</p></li><li><p>It has to be intended for displaying, analyzing, or printing medical information about a patient, such as literature or guidelines, rather than patient-specific signal data.</p></li><li><p>It has to support or recommend, not replace, a clinician&#8217;s judgment.</p></li><li><p>It has to let the clinician independently review the basis for its output rather than functioning as a black box. FDA&#8217;s guidance is blunt that this is difficult for large language models generally and close to impossible in time-critical situations.</p></li></ul><p>Miss any <em><strong>one</strong></em> of these four, and the software is a regulated medical device. </p><p>This connects to something I tested myself back in May. I uploaded an ECG to OpenEvidence and received an AI-generated interpretation. That alone looks like a Criterion 1 problem: analyzing a signal from a signal acquisition system is exactly what the exemption excludes. I checked again this week to see whether the feature had changed. It hadn&#8217;t. OpenEvidence still accepts ECG image uploads and still generates an interpretation. On the <a href="https://ashooreview.com/p/can-medical-ai-read-an-ecg">same case</a> I tested in May, it still produced an incorrect but very official-appearing reading. </p><h3>If OpenEvidence Doesn&#8217;t Qualify, What Happens on Each Side?</h3><p>Assume for a moment that the ECG function alone is enough to knock a product out of Non-Device CDS status. What would actually follow, in the US and in the EU, and does the comparison support &#8220;the US is the settled option&#8221;?</p><p>In the US, there&#8217;s already a precedent-setting path for exactly this function. AccurKardia&#8217;s AccurECG 2.0 cleared FDA review as a Class II device via 510(k) in January 2026. Tempus received 510(k) clearance for its ECG-Low EF software the same way. If OpenEvidence&#8217;s interpretation function is similar enough to an existing cleared device, it would likely follow the same 510(k) route, averaging 155 days as of mid-2026. If it&#8217;s different enough that no predicate applies, it would more likely need De Novo classification, averaging 341 days. </p><p>In the EU, this same feature would almost certainly count as a moderate-to-higher-risk medical device (what MDR calls Class IIa or IIb), the kind that needs an outside safety review before it can be sold. That review currently takes 13 to 18 months on average. A new rule adopted this May is supposed to shrink that to roughly 6 to 9 months, but only for agreements signed after February 2027, so it doesn't help anyone applying today. And crossing that medical-device threshold doesn't let a company trade one set of rules for another. It automatically pulls the product into the AI Act's high-risk category too, so it ends up answering to both frameworks at once: the device safety review, plus the AI Act's own requirements for data governance, incident reporting, and built-in human oversight.</p><p>On the two sides of the Atlantic, there is a  real structural difference, not manufactured uncertainty. </p><h3>Two More Differences Worth Examining </h3><p>Data protection is not the same question as AI regulation, and the two get blurred together in most coverage of this story. OpenEvidence&#8217;s own privacy policy tells EU users not to use the product because its infrastructure is US-based and isn&#8217;t governed by EU safeguards. GDPR treats health data as a special category under Article 9, requiring explicit consent or a documented research basis before it can be processed at all, <strong>a stricter bar than HIPAA&#8217;s authorization-or-de-identification model</strong>. </p><p>The EU and the UK are also not the same problem, though OpenEvidence&#8217;s notice treats them as one. The EU has written binding rules that are simply demanding and expensive to satisfy. The UK, by contrast, has no binding AI-specific medical device framework at all yet. The MHRA&#8217;s version is still a voluntary pilot program, with a real framework promised sometime later in 2026. &#8220;Uncertainty&#8221; is the accurate word for the UK&#8217;s situation. For the EU, the accurate words are &#8220;burden&#8221; and &#8220;cost.&#8221; </p><h3>What OpenEvidence Actually Did</h3><p>None of this required OpenEvidence to leave in the specific week it left, and the run-up to its exit is worth walking through.</p><p>By the time OpenEvidence posted its notice on April 27, the relief it was asking for was already in motion and had been for months, none of it because of anything OpenEvidence did. EU officials had proposed a package of changes back in November 2025, five months earlier, specifically to ease the same high-risk AI rules OpenEvidence's notice pointed to. The EU's parliament had already voted, 569 to 45, to move that package forward on March 26, a full month before OpenEvidence acted, and the different EU bodies involved had already started hammering out the details. The one round of those talks that hit a snag, on April 28, the day after OpenEvidence's notice went up, got stuck on a technical point that had nothing to do with the kind of product OpenEvidence makes. OpenEvidence left in the middle of a process that was already headed toward the outcome it said it needed, on a schedule set months before the company made its decision.</p><p>Its own notice is worth reading closely too. The original version named two people, Brando Benifei and Michael McNamara, and invited clinicians to contact them along with CPME, the umbrella body for European medical associations. Benifei and McNamara aren&#8217;t random picks. They co-chair Parliament&#8217;s actual AI Act oversight working group, and McNamara went on to become the Rapporteur for the exact Omnibus package that delivered the deferral. CPME, for its part, had already co-signed letters in March and April arguing to keep the AI Act strict, the opposite of what OpenEvidence needed. That callout disappeared from the notice within 48 hours. A correspondence published in the Lancet in May read the episode as a scrubbed attempt at bottom-up lobbying, notable for what it suggests about the gap between OpenEvidence&#8217;s stated rationale and its own actions, regardless of what the callout was intended to accomplish.</p><p>And the technology itself never actually left. Although OpenEvidence&#8217;s own site still shows the same notice to anyone in the EU, Elsevier&#8217;s ClinicalKey AI, running on OpenEvidence&#8217;s own engine per their 2023 partnership and featuring The Lancet as a headline content source, is available to EU subscribers. The AI didn&#8217;t leave Europe. It just stopped answering to OpenEvidence&#8217;s name.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5l96!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5l96!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5l96!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5l96!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5l96!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5l96!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg" width="499" height="417.45949720670393" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1198,&quot;width&quot;:1432,&quot;resizeWidth&quot;:499,&quot;bytes&quot;:352705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/207446446?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5l96!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5l96!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5l96!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5l96!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5c45f4-94c2-4f9a-961b-41cd0666c8dd_1432x1198.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>So, Why Did OpenEvidence Really Leave?</h3><p>Probably not because the EU is uncertain. The EU&#8217;s rules are written down, phased in on a public schedule, and expensive to satisfy, which is a different problem than uncertainty and a more honest one for OpenEvidence to have named. The timeline it cited resolved in a direction it didn&#8217;t need to lobby for. And its own underlying technology kept working in the exact market OpenEvidence says it can no longer serve, just under someone else&#8217;s name.</p><p>The clinicians who lost access to OpenEvidence didn&#8217;t get any of that. They got one sentence, a since-deleted prompt to contact officials who didn&#8217;t need the push, and a tool that, as best I can tell, may already be operating past the line the FDA draws around what doesn&#8217;t need to be regulated at all.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Who Grades the Evidence? Five Products, Five Different Answers]]></title><description><![CDATA[OpenEvidence&#8217;s new EvidenceGrad vs UpToDate, DynaMed, Vera Health and Consensus]]></description><link>https://ashooreview.com/p/who-grades-the-evidence-five-products</link><guid isPermaLink="false">https://ashooreview.com/p/who-grades-the-evidence-five-products</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Tue, 14 Jul 2026 13:20:47 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bbab17b5-b6e4-4cd9-85d7-1d9f08dcefc6_2302x1425.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>OpenEvidence launched EvidenceGrade. Let&#8217;s walk through what this new feature actually does and how it compares to UpToDate Expert AI, DynaMed, Consensus, and Vera Health. I&#8217;ll also touch on when to use each one, when there&#8217;s no real difference, and most importantly, who&#8217;s on the hook when the grade is wrong. For more on curated knowledge and AI, read this previous article: <a href="https://ashooreview.com/p/when-clinical-ai-says-i-dont-know">&#8220;When Clinical AI Says &#8216;I Don&#8217;t Know&#8217; &#8221;</a></em></p><p><em>As always, if you enjoy reading, subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NKkY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NKkY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 424w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 848w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 1272w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NKkY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png" width="1456" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5021824,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/206745179?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NKkY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 424w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 848w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 1272w, https://substackcdn.com/image/fetch/$s_!NKkY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75ccafc3-12e0-41cf-bba0-58b794b17b6a_2302x1526.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 10, 2026, OpenEvidence launched EvidenceGrade, a feature that assigns a letter grade to the strength of evidence beneath every AI-generated clinical answer. It&#8217;s an improvement in the value of the responses OpenEvidence creates, and it lands in a market where other tools have been grading evidence in multiple different ways for quite some time.</p><h3>What EvidenceGrade Does</h3><p>EvidenceGrade builds on GRADE, the Grading of Recommendations, Assessment, Development, and Evaluation framework behind Cochrane reviews, WHO guidance, and most major clinical practice guidelines. GRADE has run evidence-based medicine for two decades. What&#8217;s new is speed, not the underlying idea of an overall grade. OpenEvidence computes a single grade for the whole answer live, at the moment a clinician asks a question, a step that has previously required human editors working ahead of time.</p><p>When a clinician asks OpenEvidence a question, the system first runs a classification step, checking whether the question amounts to a clear evidentiary claim. Simple definition lookups and summarization requests get filtered out here. Questions that pass get scored on study design, consistency of findings, precision, and directness- the same inputs GRADE has always used- and the system returns a letter grade for strength, with a separate &#8220;U&#8221; designation for evidence that can&#8217;t be graded.</p><p>Two details are worth noting. OpenEvidence&#8217;s classifier decides which questions get graded, not the clinician. And the grading itself comes from a single company applying GRADE algorithmically to its own retrieval results, a different process than GRADE&#8217;s original consensus-panel model.</p><h3>Five Products, Five Methods</h3><p><strong>OE&#8217;s EvidenceGrade</strong> scores literature live, at the moment a clinician asks a question. Scoring extends to questions that no formal appraisal has reviewed yet, and the tool runs at point-of-care speed.</p><p><strong>UpToDate&#8217;s Expert AI</strong> launched in late 2025 and sits on top of content that physician editors already reviewed and graded using GRADE, with Grade 1 or 2 for recommendation strength and Grade A, B, or C for evidence quality. The AI layer surfaces existing editorial work conversationally, with rationale and links back to the original topics. Scoring depends on what editors have written and reviewed, so very recent literature can lag what OpenEvidence pulls in real time.</p><p><strong>DynaMed</strong> shares UpToDate&#8217;s editorial foundation: physician editors review and rate evidence with GRADE ahead of time. The method diverges at synthesis. DynaMed&#8217;s AI layer rates the individual sources it cites but doesn&#8217;t roll them up into a single grade for the answer as a whole, the way UpToDate&#8217;s per-recommendation grade or OpenEvidence&#8217;s per-answer letter does.</p><p><strong>Vera Health</strong> also grades the strength of underlying evidence behind its answers and positions itself as a direct point-of-care competitor to OpenEvidence. That grading applies to the individual sources it cites, the same source-level approach DynaMed&#8217;s AI takes, rather than producing one overall grade for the answer. </p><p><strong>Consensus</strong> takes a different approach. Its default ranking sorts papers by citation count, journal reputation, and recency, all signals of a paper&#8217;s influence and reach rather than the rigor of its methodology. Consensus also offers an optional evidence-hierarchy filter that lets a clinician sort by study design, from meta-analyses and systematic reviews down through RCTs and observational studies. Nothing is graded automatically here; the clinician chooses whether to apply the filter every time. </p><h3>Pros and Cons</h3><p><strong>OpenEvidence</strong> offers speed and reach. A grade can appear under a question no editor has ever reviewed, in the time a clinician has between patients. That speed comes from a single company&#8217;s automated interpretation of GRADE, run through a classifier a clinician can&#8217;t inspect.</p><p><strong>UpToDate</strong> carries the weight of editorial review behind every grade, built up over years with an established audit trail. Questions about very recent literature can outrun what the editorial team has reached, so timeliness suffers where OpenEvidence&#8217;s live scoring holds an advantage.</p><p><strong>DynaMed</strong> shares UpToDate&#8217;s tradeoff of editorial rigor against editorial pace. Its AI layer grades each source it cites, but leaves the work of weighing those individual grades into one overall judgment to the clinician, since it doesn&#8217;t generate the single per-recommendation grade UpToDate does.</p><p><strong>Vera Health</strong> competes on benchmark performance and broader geographic reach and on a grading methodology it hasn&#8217;t named as clearly as its competitors have. It also stops at source-level grades rather than synthesizing one for the answer, so a clinician still has to weigh conflicting source grades themselves. A clinician outside the US or UK who lost access to OpenEvidence may find Vera Health the more practical option.</p><p><strong>Consensus</strong> puts control directly in the clinician&#8217;s hands. No classifier decides what gets graded, and every AI-generated summary traces back to an exact sentence in the source paper. That control depends on the clinician knowing to apply the hierarchy filter; skip it, and the ranking on screen reflects citation counts and journal reputation, which are signals of popularity rather than rigor. Consensus also serves general research across all fields, so it lacks the clinical workflow tuning built into the other four tools.</p><h3>When to Actually Use Which</h3><p>A fast, evidentiary bedside question, something like whether a drug reduces mortality in a given population, fits OpenEvidence well. Watch for whether a banner appears at all; no banner means the classifier judged the question outside EvidenceGrade&#8217;s scope, which is worth a second look if the question felt evidentiary to you.</p><p>A well-established clinical question or standard management of a common chronic condition plays to UpToDate or DynaMed&#8217;s strength. Human editorial review has already happened, and the subscription cost buys that vetting.</p><p>A clinician outside the US or UK, or one weighing the benchmark claims directly, has reason to look at Vera Health alongside or instead of OpenEvidence, keeping in mind that the comparative claims come from Vera Health itself.</p><p>Deep literature review on an emerging or contested question, or research headed into a paper or grant application, calls for Consensus, used deliberately with the hierarchy filter engaged and the full-text tool open to check claims directly.</p><p>Many everyday questions have no clear winner among these five. When UpToDate already holds a well-established Grade A recommendation for a common condition, OpenEvidence&#8217;s live grade on the same question will likely land in the same place, since both draw on the same underlying evidence base. The choice there comes down to workflow preference, editorial certainty against conversational speed. A clinician willing to spend an extra ninety seconds applying Consensus&#8217;s RCT filter can reach a similar result to what EvidenceGrade delivers automatically.</p><h3>Risk and Bias, In Both Directions</h3><p>The editorial model behind UpToDate and DynaMed carries its own risks. A recommendation can sit unchanged for months after new evidence complicates it, and every grading decision reflects the judgment of the specific editors who wrote it, not an infallible panel.</p><p>OpenEvidence&#8217;s automated model carries its own risk. A letter grade can read as more authoritative than a live scoring process actually supports, which invites automation bias. The classification step still makes a judgment call the clinician doesn&#8217;t get to weigh in on: whether a question counts as evidentiary at all. Grading quality also depends entirely on what the retrieval system pulled in the first place, a step a clinician can&#8217;t audit in real time.</p><p>DynaMed&#8217;s AI and Vera Health carry a different risk, tied to the same source-level grading described above. Neither tool synthesizes the individual source grades into one judgment, which means the aggregation OpenEvidence and UpToDate perform automatically becomes a manual step for a clinician moving quickly between patients, and manual synthesis done under time pressure is where inconsistency creeps in.</p><p>Consensus shifts risk toward the clinician directly. Someone who doesn&#8217;t know to apply the evidence-hierarchy filter, or who doesn&#8217;t recognize that the default ranking measures popularity rather than rigor, gets no protection from the tool itself.</p><p>Each model fails in its own way, and the failure a clinician is exposed to depends on which tool they picked and how well they understand what runs underneath it.</p><h3>The Question Nobody Has Answered: Liability</h3><p>Clinicians are not attorneys, and nothing here is legal advice. It&#8217;s worth asking plainly, since none of the marketing for any of these five products addresses it directly: <strong>Does a clinician carry more or less liability for relying on an AI-generated evidence grade compared to a human-editor-vetted one?</strong></p><p>I could not find an answer to this question. Malpractice and negligence standards generally turn on whether a clinician exercised reasonable judgment consistent with the standard of care, and historically that inquiry centers on the clinician&#8217;s own decision rather than the reference tool behind it. All five products here position themselves as clinical decision support rather than autonomous diagnostic tools, which keeps the clinician as the final decision-maker of record, the same SaMD-versus-CDS framing this newsletter has examined before.</p><p>Whether courts will eventually treat a real-time AI grade differently from an incremental human editorial grade remains genuinely untested. I don&#8217;t have an answer, and anyone claiming otherwise is speculating.</p><p>What holds steady across all five tools is this: whatever grade appears on the screen, the decision that follows still belongs to the clinician who acts on it.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Context Is Everything]]></title><description><![CDATA[Could AI Scribe + AI Search Be a Game Changer in Medicine?]]></description><link>https://ashooreview.com/p/context-is-everything</link><guid isPermaLink="false">https://ashooreview.com/p/context-is-everything</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 10 Jul 2026 11:33:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Q7n5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>A shift is occurring in the marketplace as AI scribe services integrate clinical decision support. The idea: context from the scribe is better than a physician&#8217;s manual prompt, and the opportunity may allow for fewer clicks &#8230; hopefully. Could this combination really improve our workflow? Let&#8217;s get into it. </em></p><p><em>As always, if you enjoy reading, please subscribe and tell a friend. </em></p><p><em>Sam</em></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q7n5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q7n5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q7n5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1769467,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/206201693?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q7n5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7n5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe43e89b0-d85b-4980-a91a-e68450db51ac_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When a clinician has a question during an encounter, the workflow is straightforward.  They recognize the need for evidence. They leave the patient, open a search tool like OpenEvidence, UpToDate, AMBOSS, or Doximity, formulate a query, and try to find an answer. Then they return to the chart and translate that finding into a plan.</p><p>It takes time and requires cognitive effort. It also interrupts the clinical workflow.</p><p>What if that entire sequence could be automated by pairing two things that currently operate independently: a scribe that captures context and an AI search tool that needs context?</p><p>If it works the way vendors are beginning to market it, the implications could be substantial.</p><h3>The Manual Search Problem</h3><p>Clinical decision support tools are valuable. The problem is that clinicians rarely use them consistently.</p><p>Adoption of standalone clinical decision support (CDS) has hovered between 20 and 50% for more than a decade. When adoption rates exceed 50% in any health system, it&#8217;s usually because the tool was so deeply embedded in workflow that using it became invisible. Not a conscious decision to &#8220;search for evidence,&#8221; but a byproduct of how documentation already worked.</p><p>The Agency for Healthcare Research and Quality (AHRQ)&#8216;s evidence on clinical decision support has long established this pattern. In a 2005 study on clinical information needs, Ely and colleagues found that the most common reason physicians did not pursue answers to clinical questions was <em><strong>time</strong></em>. Not having access to tools, or skepticism about the instrument. Every additional click, every additional screen, every additional cognitive step to formulate what you&#8217;re searching for, all of that is friction.</p><p>The manual prompt introduces friction at multiple points.</p><p>First, the clinician has to recognize that they need help. That alone is cognitively taxing when you&#8217;re in the middle of an encounter and managing multiple competing hypotheses simultaneously.</p><p>Second, they have to formulate what they&#8217;re searching for. They have to decide what context matters. For example, a 65-year-old woman with a subsegmental PE is the bare minimum. But the clinically relevant narrative includes much more: her main symptom was chest pain, her father died of an MI at 65, she has no dyspnea despite the imaging findings, she&#8217;s anxious about the PE diagnosis. The question is whether the clinician remembers or prioritizes all of that when they type a prompt. Often they don&#8217;t. They reduce it to what feels immediately salient.</p><p>Third, they have to type it. And then translate the results back into their documentation.</p><p>Each of these steps is a place where information can be lost. Each is a place where a busy clinician can decide it&#8217;s faster to just make a decision than to go through the process.</p><p>The result: CDS adoption stalls. Not because the tools don&#8217;t work, but because the friction cost exceeds the perceived benefit.</p><h3>What If Context Was Automatic?</h3><p>Now consider a different architecture.</p><p>A scribe is already listening to the encounter. It&#8217;s capturing everything: chief complaint, associated symptoms, what improved with aspirin, the patient&#8217;s expressed anxiety about the PE finding, the absence of dyspnea despite imaging, family history, the nuance of how the history actually unfolded. The scribe structures that into a clinical note.</p><p>What if that same structured encounter context became the automatic input to downstream AI search and clinical decision support?</p><p>The difference is subtle but consequential. Instead of waiting for the clinician to recognize they need help and formulate a prompt, the system works from what&#8217;s already been captured. The context is automatically available. The search doesn&#8217;t depend on the clinician deciding what matters or remembering to type it.</p><p>This is the architectural shift vendors are now building.</p><p>Glass Health combines ambient scribe with a clinical reasoning layer that accesses the encounter transcript. When the scribe finishes capturing the visit, the same data becomes context for CDS reasoning, not a separate step, not a separate prompt, but the natural downstream use of data already captured.</p><p>Microsoft&#8217;s DAX Copilot generates the note from the scribe, then uses that same encounter context to surface order suggestions within Epic. The clinician doesn&#8217;t have to prompt for order ideas; they arrive pre-staged, informed by what was actually discussed.</p><p>Abridge, after expanding into real-time prior authorization through an Availity partnership announced in January 2026, is pre-populating prior auth requests with encounter context. The clinician reviews, not writes.</p><p>Ambience Healthcare&#8217;s AutoScribe provides real-time coding suggestions, quality measure tracking, and automated prior authorization recommendations, all triggered by the scribe context, all without requiring the clinician to initiate a separate search.</p><p>In each case, the pattern is the same: scribe captures context automatically, downstream systems act on that context without waiting for the clinician to formulate a prompt.</p><h3>Why This Matters</h3><p>If CDS adoption has been stuck at 20-50% because clinicians won&#8217;t use tools that require extra steps, and if integrated scribe-plus-search systems eliminate that friction by making context automatic and routing recommendations directly into workflow, then adoption could shift.</p><p>Not because the search tools suddenly became better. But because the context became richer, the friction resolved, and the recommendations arrived where clinicians are already working.</p><p>There&#8217;s a secondary automation gain as well. Once encounter context is structured and available, systems downstream can act without additional clinician prompts. Abridge is already doing this with order placement. The prior authorization request comes pre-populated. The labs or imaging recommendations arrive as suggestions for review, not as questions requiring the clinician to type more information.</p><p>Each of these automations removes a decision point. Each removes a place where context can be lost, or a clinician can opt out because the friction became too high.</p><p>This is different than asking &#8220;are AI search tools more accurate when they have more information?&#8221;  This is asking whether integrated scribe-plus-search systems could achieve the adoption curves and utilization patterns that standalone CDS have chased unsuccessfully for years.</p><h3>Where This Is Already Shipping</h3><p>The market is moving in this direction. The examples above are live products, deployed now.</p><ul><li><p>OpenEvidence, Doximity, and Glass Health offer scribe plus clinical decision support in the same interface.</p></li><li><p>DAX Copilot&#8217;s order suggestions are live within Epic.</p></li><li><p>Abridge&#8217;s prior authorization workflow doesn&#8217;t require the clinician to re-enter what was already discussed with the patient; the scribe context carries it forward.</p></li><li><p>Athenahealth made its ambient scribe free to all customers in February 2026. The company has explicitly positioned the scribe as a foundation for downstream clinical and administrative workflows.</p></li></ul><p>These aren&#8217;t experimental pilots. They&#8217;re market moves. Multiple vendors are racing to integrate scribe plus CDS, scribe plus order suggestions, scribe plus prior authorization, and scribe plus billing optimization. The race itself suggests vendors believe integration is where the value is concentrating.</p><h3>The Evidence Question</h3><p>AHRQ best practices emphasize that CDS embedded in clinical workflow achieves significantly higher adoption rates than standalone tools.</p><p>The Rotenstein et al. study published in JAMA in April 2026 tracked 8,581 clinicians across five academic medical centers and found that 79% of eligible clinicians declined to adopt a scribe when it was offered as a standalone documentation tool. Among those who did adopt, only 32% used it in 50% or more of visits, the threshold where benefits actually accumulated.</p><p>But at organizations where the scribe was deliberately integrated into clinical workflow with physician champions, hands-on training, and customization of documentation to match local practice, adoption reached 75-80%. </p><p>Central Oklahoma Family Medical Center saw minimal scribe adoption in year 1 when it was positioned as a documentation tool. In year 3, after deliberate workflow integration and physician-led training, the system was generating over 14,000 records annually.</p><p>Research supports the pattern: embedded tools are better than standalone tools. Integrated workflows are better than siloed workflows. Friction is the constraint, not technology limits.</p><p>However, there is no published comparative adoption study in the same health system measuring scribe-only utilization versus integrated scribe-plus-CDS utilization. The vendors are claiming that integration drives adoption. The friction research supports that claim logically. But direct comparative evidence is absent.</p><p>That gap is fixable. It&#8217;s also important. If the thesis holds that integrated scribe plus CDS achieves meaningfully higher adoption than scribe-only, that would directly support the &#8220;game changer&#8221; framing. Until that evidence exists, we&#8217;re working from logical inference and market positioning, not real-world data.</p><h3>What Changes Clinically</h3><p>Let me be concrete about what this looks like in practice.</p><p>Today&#8217;s workflow: A 65-year-old woman presents with chest pain, elevated troponin, and a subsegmental PE on imaging. The clinician needs to decide between acute coronary syndrome and a low-risk PE with incidental findings. They recognize they need evidence about ACS risk stratification and PE disposition pathways. They leave the encounter, open OpenEvidence or UpToDate, search for something like &#8220;subsegmental PE,&#8221; scan results, and return to the chart with an answer. Time cost: 5-10 minutes. Friction cost: context loss between encounter and search.</p><p>Tomorrow&#8217;s workflow: The same patient, same presentation. The scribe has captured the full encounter: the aspirin response, the specific way the history unfolded, the family history details, the absence of dyspnea. Once the note is drafted, that encounter context automatically feeds into CDS reasoning. Before the clinician even finishes reviewing the note, recommendations about ACS risk stratification appear inline. They&#8217;re specific to what was discussed, not to a reductive prompt. The clinician reviews and acts. No extra steps. No context loss.</p><p>The difference isn&#8217;t speed alone. It&#8217;s that the clinical reasoning is informed by what actually happened, not by what the clinician decided was relevant enough to type.</p><h3>What Has to Be True for This to Work</h3><p>This only works if several conditions hold.</p><p><strong>Scribe accuracy matters more.</strong> If the scribe omits a symptom or invents a clinical detail, everything downstream breaks. Recommendations based on false or inaccurate context are worse than no recommendations. The accuracy bar for a scribe that feeds into automation is higher than for a scribe that just generates a note for a clinician to review and edit.</p><p><strong>Context routing has to be intelligent.</strong> Not every piece of encounter context should trigger every possible recommendation. Signal-to-noise matters. If the system fires off ten recommendations per encounter, most of which are irrelevant, clinician trust collapses. Integration has to include filtering and prioritization logic that decides what context maps to what recommendations.</p><p><strong>Integration has to be seamless.</strong> If embedding CDS into the scribe workflow adds steps, the friction returns and adoption stalls. The system has to route recommendations directly into existing documentation workflows without requiring the clinician to open new windows, review separate interfaces, or translate between formats.</p><p><strong>Liability has to be clear.</strong> If a scribe misses a clinical detail, who&#8217;s responsible? If CDS gives a recommendation based on scribe context and it&#8217;s wrong, who bears the liability: the scribe vendor, the CDS vendor, the clinician, the health system? Until those questions are answered clearly, adoption will be cautious. </p><p><strong>Clinicians have to adopt the pattern.</strong> The mental model of &#8220;don&#8217;t prompt, just accept recommendations&#8221; is new for many physicians. It requires trust in both the scribe's accuracy and the CDS's reasoning. It requires that clinicians believe recommendations are being triggered appropriately, not indiscriminately. Building that trust takes time.</p><h3>Conclusion</h3><p>The architectural logic is sound. Pairing a scribe that captures context with CDS that needs context could eliminate the friction that&#8217;s kept adoption low. Integration could shift clinical decision support from a tool clinicians invoke when they have time to a system that informs their thinking automatically.</p><p>But &#8220;could&#8221; and &#8220;does&#8221; are different things. The market believes in this direction. Vendors are shipping products built on this assumption.</p><p>The evidence, though, is still emerging. The comparative adoption study doesn&#8217;t exist yet. The real-world error profiles haven&#8217;t been published. The liability frameworks are still being negotiated.</p><p>What we&#8217;re watching is an inflection point. The question isn&#8217;t whether AI scribes plus AI search <em>could</em> be a game changer. The architecture is sound enough that it&#8217;s plausible. The question is whether the systems being deployed right now will deliver on that promise at scale.</p><p>That&#8217;s worth paying attention to.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The CIO's Impossible Comparison]]></title><description><![CDATA[How hospitals are supposed to choose between Epic's AI and all others with almost nothing to go on]]></description><link>https://ashooreview.com/p/the-cios-impossible-comparison</link><guid isPermaLink="false">https://ashooreview.com/p/the-cios-impossible-comparison</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Mon, 06 Jul 2026 21:10:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_sxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A CIO and a CMIO sit down with a slide deck, a budget line, and a critical decision: activate Epic&#8217;s native AI tools, bring in a third-party vendor, or build a custom AI tool through an API.</p><p>They need comparison data, but there isn&#8217;t any. The single largest, most consequential technology decision many U.S. hospitals will make this decade is being made with far less evidence than we would accept for a new drug or device. Let&#8217;s dive deeper. </p><p>As always, if you enjoy reading, subscribe and tell a friend. </p><p>Sam</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_sxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_sxi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_sxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e903227a-486f-486e-901b-47782cae3b17_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2016243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/205661578?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_sxi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_sxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe903227a-486f-486e-901b-47782cae3b17_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s not a hypothetical problem. </p><ul><li><p>More than 85% of Epic&#8217;s customer base is already using some form of Epic AI</p></li><li><p>EHR vendor dependency is cited as the top execution barrier by 74% of health system technology leaders</p></li><li><p>A majority of Epic&#8217;s customers report spending a quarter of their IT bandwidth simply managing multiple vendor integrations rather than building anything new.</p></li></ul><p>So how are hospitals supposed to decide about Epic&#8217;s AI features? Three questions capture the actual decision tree a CIO faces:</p><ol><li><p>How do you compare Epic&#8217;s tools against alternatives when no published performance data exists?</p></li><li><p>Are you left comparing on price alone?</p></li><li><p>Can you even connect an outside AI tool to Epic,  and what does that actually cost in dollars and time?</p></li></ol><p>Each answer turns out to be more complicated than it first appears. </p><h3>The Comparison Vacuum</h3><p>According to EPIC, more than 200 organizations use Penny for professional coding, with many seeing 20% of more coding-related denial reductions. Art&#8217;s Insights feature is used more than 16 million times a month. At The Christ Hospital, Art&#8217;s radiology finding extraction is credited with a 69% early lung cancer detection rate compared to a national average of 46%. At Rush University Medical Center, Emmie delivered a 58% reduction in billing-related customer service messages. </p><p>These are genuine wins, not vague marketing language. But notice what they have in common: every one of them is a curated success story that Epic chose to publish, from a customer Epic chose to name, describing an outcome Epic chose to measure. None of them come with a comparison arm. None of them tell you what a third-party tool, or no AI tool at all, would have achieved at the same hospital over the same period.</p><p>What doesn&#8217;t exist is any neutral, third-party study putting Epic&#8217;s tools head-to-head against Abridge, Ambience, Nabla, Suki, or Oracle Health&#8217;s Clinical AI Agent, on the same patients, measuring the same things. The closest proxies available each fall short in a specific, disqualifying way:</p><ul><li><p><strong>KLAS &#8220;Best in KLAS&#8221; rankings</strong> exist for ambient AI and clinical documentation, and vendors like Abridge and Ambience have won them in 2025 and 2026. But KLAS rankings are built from customer satisfaction surveys. They measure whether clinicians like a tool, not whether it performs more accurately or safely than the alternative.</p></li><li><p><strong>Vendor comparison content</strong>, like the &#8220;Abridge vs. Ambience&#8221; writeups that circulate among health IT consultants, reads like independent analysis but is typically produced by resellers and integration firms with a commercial stake in one outcome or another.</p></li></ul><p>To be fair to Epic, native integration solves a real, well-documented problem. Third-party AI tools often exist as a separate app or window that a clinician has to switch into, breaking their workflow. Epic&#8217;s tools, by contrast, draw on the patient&#8217;s complete longitudinal record natively, inside the same interface the clinician already lives in. That is legitimate integration depth, and Epic has a structural claim to it that outside vendors have to work much harder to match.</p><p>But &#8220;we&#8217;re already inside your workflow, so trust us&#8221; is a switching-cost argument, not a quality argument. It explains why Epic&#8217;s tools are more convenient to adopt. It says nothing about whether Art&#8217;s diagnostic suggestions, Emmie&#8217;s patient explanations, or Penny&#8217;s coding recommendations are more accurate than a competitor&#8217;s because nobody has measured that, and Epic has no more incentive to fund that comparison than a third-party vendor would have to fund one showing Epic winning.</p><p>The honest, unsatisfying answer for how hospitals resolve this: they don&#8217;t rely on external comparison data. They run their own limited pilots of both options against their own patient population and staff, because nobody else has done, or has an incentive to do, that comparison for them. That&#8217;s not a failure of any individual CIO&#8217;s diligence. It&#8217;s a structural gap in the market that every hospital is left to close on its own, one expensive pilot at a time.</p><div><hr></div><h3>Price Is Visible. Quality Isn&#8217;t. </h3><p>No CIO is literally forced to decide on price alone. But price is the one variable in this decision with any real transparency, and that asymmetry quietly warps the whole comparison because when quality is unmeasurable and price is a line item, price tends to win by default, whether or not it should.</p><p>The other differentiators hospitals actually weigh are real, but none of them are clinical outcome measures:</p><ul><li><p><strong>Integration depth.</strong> Does the tool live inside Epic natively, or does it require clinicians to leave the EHR? This is the &#8220;house vs. guest in the house&#8221; distinction discussed above. It&#8217;s a genuine operational factor, not evidence of accuracy or safety.</p></li><li><p><strong>Specialty coverage breadth.</strong> Some third-party tools market coverage across 200-plus specialties, from oncology to emergency medicine. That&#8217;s a real capability difference, but it says nothing about performance within any single specialty.</p></li><li><p><strong>Vendor relationship tier with Epic.</strong> Some vendors, like Abridge and Nuance, hold a spot in Epic&#8217;s invite-only &#8220;Workshop&#8221; co-development tier. Others sit in the more generic, self-service &#8220;Connection Hub&#8221; listing. This tells you something about durability and long-term support risk. It tells you nothing about whether the underlying AI is any good.</p></li><li><p><strong>Lock-in and commoditization risk.</strong> As Epic rolls out &#8220;good enough&#8221; native alternatives, standalone point solutions face real competitive pressure. Betting on a third-party tool means betting that it survives Epic&#8217;s gravitational pull.</p></li></ul><p>The uncomfortable throughline across all four: they&#8217;re operational and strategic risk proxies, not evidence. A CIO weighing them isn&#8217;t answering &#8220;which AI is better&#8221;. They&#8217;re answering &#8220;which AI is safer to bet on organizationally.&#8221;</p><div><hr></div><h3>Yes, You Can Connect Outside AI to Epic</h3><p>Epic is not a walled garden on this point. The technical path to connecting an outside AI tool, whether a commercial product or a custom build on an API, is real, standardized, and already proven in production.</p><p><strong>The mechanisms, at the level a CIO actually needs:</strong></p><ul><li><p><strong>SMART on FHIR</strong> is an open industry standard, not an Epic-proprietary one, that lets a third-party application launch inside Epic&#8217;s interface (Hyperspace, Hyperdrive, or MyChart) with OAuth2-based access to the patient&#8217;s clinical context.</p></li><li><p><strong>CDS Hooks</strong> is a lighter-weight alternative for narrower use cases: an external tool fires in real time on a specific clinical event (opening a chart, signing an order) and returns a recommendation card, without the overhead of launching a full separate application.</p></li><li><p><strong>Epic Showroom</strong> (formerly App Orchard) is the marketplace and certification pathway, with three tiers: </p><ul><li><p>Connection Hub, a basic listing starting around $500 a year, where most third-party apps live.</p></li><li><p>Toolbox, offering curated visibility</p></li><li><p>Workshop, reserved for vendors Epic is actively co-developing with, not a tier you can apply for.</p></li></ul></li></ul><p>Abridge, Ambience, Nabla, and Suki all run as third-party ambient scribes launched inside Epic today via exactly this pathway. Connecting a custom AI build is well-trodden ground, not an experimental frontier.</p><p><strong>What it actually costs, in dollars:</strong></p><ul><li><p>A basic FHIR read integration for a first site: <strong>$15,000&#8211;$40,000</strong></p></li><li><p>Bidirectional integration (the tool can write back into the chart, not just read from it): <strong>$40,000&#8211;$80,000</strong></p></li><li><p>Each additional hospital site: <strong>$5,000&#8211;$20,000</strong> in configuration, testing, and governance overhead</p></li><li><p>Enterprise multi-site deployments (five-plus hospitals): <strong>$100,000&#8211;$500,000+</strong></p></li><li><p>Annual maintenance: <strong>15&#8211;20% of build cost</strong>, ongoing</p></li></ul><p>Those figures answer the technical and financial questions. They don&#8217;t answer the harder question, which is where most integration projects actually stall.</p><div><hr></div><h3>&#8220;Integration Is 20% Development, 80% Negotiation&#8221;</h3><p>Brendan Keeler, a widely cited EHR integration analyst, has a line that captures this better than any cost table: <strong>integration is 20% development, 80% negotiation.</strong></p><p>It&#8217;s helpful sitting thinking about what that 80% actually is, because it&#8217;s several negotiations stacked, and none of them get easier just because a vendor has already done this at another hospital:</p><ul><li><p><strong>Per-site IT governance review.</strong> Even though Epic&#8217;s FHIR APIs are standardized across every customer, each hospital runs its own instance with its own security policies. A vendor doesn&#8217;t clear &#8220;Epic&#8221; once. They clear each hospital&#8217;s IT and security team separately, every time.</p></li><li><p><strong>Scope and access-level negotiation.</strong> What data can the tool read? Can it write back into the chart? Is access tied to individual user logins or a backend service account? These aren&#8217;t just technical settings. They&#8217;re negotiated line by line with each hospital&#8217;s compliance and security staff, who have their own risk tolerance and institutional precedent to defend.</p></li><li><p><strong>Contract terms with Epic itself</strong>, separate from any single hospital deal: Showroom tier, vendor services registration, fees.</p></li><li><p><strong>Institutional change management: </strong>Getting clinical leadership, IT, compliance, and often legal to actually agree to put a new tool inside their clinicians&#8217; workflow.</p></li></ul><p>This negotiation stack isn&#8217;t identical across hospitals, even though the underlying FHIR technology may be. Each hospital is, in effect, a separate legal and organizational gate a vendor has to clear from scratch, no matter how many times they&#8217;ve cleared an equivalent gate elsewhere. That mismatch is exactly why Epic&#8217;s own native tools carry a durable structural advantage that has nothing to do with whether their AI is actually better. They skip the entire negotiation stack because they&#8217;re already inside the walls, already covered by the hospital&#8217;s existing Epic contract and security posture.</p><div><hr></div><h3>How Vendors Are Fighting Back</h3><p>Third-party vendors aren&#8217;t standing still against this asymmetry. Several strategies have emerged, each attacking a different piece of the 80%:</p><ul><li><p><strong>Pre-certification as a trust shortcut.</strong> HITRUST certification (including a new AI-specific security certification launched in response to healthcare&#8217;s AI boom) and SOC 2 Type II audits let a vendor prove its security posture once and present that proof to every prospective hospital, rather than rebuilding trust from zero at each site. HITRUST is now often a baseline requirement for even getting considered in procurement.</p></li><li><p><strong>Integration aggregators.</strong> Platforms like Redox normalize FHIR, HL7 v2, and proprietary EHR APIs into a single interface, letting a vendor avoid building direct integrations against three to five different EHR systems from scratch, at the cost of some data fidelity and an extra hop in the data flow.</p></li><li><p><strong>Design-partner-first rollout.</strong> Land one engaged hospital willing to work through the full registration and security review cycle together, get the integration proven in production, then use that as a template for the second and third hospital, accepting that some per-site variability will still surface each time.</p></li><li><p><strong>Climbing into Epic&#8217;s Workshop tier.</strong> Vendors like Abridge and Nuance have secured Epic&#8217;s invite-only co-development relationship, which functions as Epic effectively vouching for them. It&#8217;s a different negotiation dynamic from approaching each hospital cold.</p></li><li><p><strong>Leaning on CDS Hooks for narrower use cases</strong>, trading a smaller interaction surface for meaningfully lower integration complexity.</p></li><li><p><strong>Regulatory tailwinds.</strong> The 21st Century Cures Act&#8217;s information-blocking provisions and ONC&#8217;s HTI-1 rule, which raised the certification baseline to USCDI v3 as of January 2026, give vendors a legally backed claim to FHIR access, shifting some leverage away from ad hoc hospital IT gatekeeping.</p></li></ul><p>None of this eliminates the negotiation. It compresses or front-loads it. Bidirectional write-back (actually pushing AI-generated content into the medical record, not just reading from it) remains the hardest and slowest part of any integration, regardless of how much pre-certification a vendor obtains.</p><div><hr></div><h3>What CIOs Actually Have to Work With </h3><p>A few genuinely useful resources exist for the leader trying to navigate this, though none of them is the comprehensive primer this decision deserves.</p><p>The Health Sector Coordinating Council&#8217;s <strong>&#8220;Health Industry AI Cyber Governance Framework Implementation Guide&#8221;</strong> (May 2026) is the closest thing to an authoritative, non-commercial reference, covering governance committee structure scaled to hospital size, escalation authority across CMO, CMIO, and Privacy Officer roles, and a benefit-risk framework tied explicitly to FDA regulatory status.</p><p>Qventus&#8217;s <strong>&#8220;Beyond the Pilot&#8221;</strong> survey of more than 60 CIOs, Chief AI Officers, and CMIOs offers real peer benchmarking: 74% cite EHR vendor dependency as their top execution barrier; 72% say they&#8217;d prefer a single consolidated AI partner over a fragmented multi-vendor stack, but only 13% have actually achieved that consolidation. It&#8217;s vendor-published, so it should be read as useful data with a thumb on the scale, not neutral research.</p><p>Narrower academic frameworks exist too, like peer-reviewed pragmatic-trial protocols for evaluating ambient AI specifically, which bring real methodological rigor but only to one slice of the larger decision.</p><p>What none of these does is tie the whole picture together. A CIO today has to assemble governance policy from one source, vendor economics from a consulting firm&#8217;s blog, integration cost data from an engineering guide, and validation-status skepticism from wherever they can find it,  with no neutral party doing that synthesis for them. That absence is, itself, worth naming plainly: the market has produced plenty of pieces but no assembled whole.</p><div><hr></div><h3>Takeaway</h3><p>Individual hospitals cannot solve this problem on their own. It is a fundamental issue with the entire healthcare market, which tends to favor established players, like Epic, over newer or better alternatives, simply because they already hold the power.</p><p>A few things worth holding onto if you&#8217;re the one making this call:</p><ol><li><p><strong>Don&#8217;t mistake Epic&#8217;s adoption percentages for comparative quality evidence.</strong> They are usage statistics, curated by the company reporting them. They tell you Epic AI is widely used. They don&#8217;t tell you it&#8217;s the best option.</p></li><li><p><strong>Budget for the 80%, not just the 20%.</strong> The dollar figures for FHIR integration are real, but the calendar time and staff bandwidth consumed by per-site negotiation are the actual cost drivers, and they&#8217;re the ones most commonly missing from a project&#8217;s original scope.</p></li><li><p><strong>Ask any vendor directly what Showroom tier they hold.</strong> It won&#8217;t tell you if their AI is accurate, but it will tell you something real about how durable their access is likely to be.</p></li><li><p><strong>Treat the absence of comparative data as a mandate to pilot, not a reason to default to the incumbent. </strong>Nobody else is going to run that comparison for you. That doesn&#8217;t mean it isn&#8217;t worth running.</p></li></ol><p>No one selling you this technology is going to prove it works for you. That job still belongs to the hospital buying it.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Override Problem]]></title><description><![CDATA[Why Nurses Unions Are Doing What National Guidelines Can't]]></description><link>https://ashooreview.com/p/the-override-problem</link><guid isPermaLink="false">https://ashooreview.com/p/the-override-problem</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Thu, 02 Jul 2026 16:09:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nPlN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>In the past 18 months, the American Nurses Association, the American Academy of Nursing, and the American Medical Association have each published AI governance frameworks. They agree on the core principle: AI must support clinical judgment, not replace it. Human oversight is essential. Clinicians should be involved in procurement decisions. The frameworks differ in emphasis and scope, but they share the same foundational commitment and the same non-existent enforcement mechanism.</em></p><p><em>Meanwhile, nurses in New York, California, Michigan, and North Carolina have been striking and writing AI oversight rights into union contracts. The national nursing union organization that represents those same nurses is publishing its own AI bill of rights.</em></p><p><em>Both responses exist because the frameworks and the union contracts are answering different questions. Understanding why requires looking at which AI tools are actually being deployed, to whom, and at whose direction.</em></p><p><em>As always, if you enjoy reading, subscribe and tell a friend.</em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nPlN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nPlN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 424w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 848w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 1272w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nPlN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1932520,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/204528814?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nPlN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 424w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 848w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 1272w, https://substackcdn.com/image/fetch/$s_!nPlN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1ffa18-2406-483f-a001-dbcdc1330854_1693x929.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What the Professional Associations Agree On</h2><p>The American Medical Association published <a href="https://www.ama-assn.org/system/files/ama-ai-principles.pdf">formal AI principles</a> in November 2023, adopted a transparency policy calling for independent third-party verification of AI explainability in June 2025, and released an <a href="https://edhub.ama-assn.org/steps-forward/module/2833560">8-step governance toolkit</a> in August 2025. The toolkit calls for multidisciplinary governance committees that include nursing leadership, staged deployment with pilot testing, and continuous performance monitoring after launch.</p><p>The American Nurses Association convened its inaugural <a href="https://www.nursingworld.org/news/news-releases/2026-news-releases/american-nurses-association-calls-for-nurse-led-guardrails-on-artificial-intelligence-in-healthcare/">AI in Nursing Practice Think Tank</a> on April 22, 2026. The consensus findings identify automation bias and erosion of professional judgment as the primary risks, call for mandatory AI literacy as a core nursing competency, and push for nurse-led AI governance at the institutional level.</p><p>The American Academy of Nursing approved a comprehensive <a href="https://telehealth.org/news/american-academy-of-nursing-issues-comprehensive-ai-position-statement/">AI position statement</a> on February 25, 2026, setting out 13 specific policy recommendations covering data privacy, algorithmic bias, FDA oversight, and human-in-the-loop oversight standards across all institutional governance policies.</p><p>The foundational language across all three documents is nearly identical: AI must augment clinical judgment, not replace it. The human clinician remains the final accountable decision-maker. Human-in-the-loop oversight is non-negotiable.</p><p>All three frameworks rely on the same implementation mechanism: voluntary institutional governance, multidisciplinary committees, professional education, and policy advocacy. None specifies what &#8220;human in the loop&#8221; requires at the point of care. None has an enforcement mechanism at the bedside level.</p><h2>Two Categories of AI Tools</h2><p>The governance frameworks were designed for a particular relationship between clinician and AI: the clinician chooses to use a tool, reviews its output, and retains authority over the final decision. The ambient scribe is the clearest example. The physician activates it, the scribe drafts a note, the physician reviews and signs. The tool serves the physician. Clinical judgment stays with the clinician throughout.</p><p>Physician AI adoption fits this model closely. By 2026, <a href="https://www.ama-assn.org/practice-management/digital-health/augmented-intelligence-medicine">more than 80% of physicians report using AI</a> in their professional work, with more than three-quarters saying it improves their ability to care for patients. The tools driving that adoption are documentation-focused: <a href="https://www.medicaleconomics.com/view/take-note-the-ai-scribe-era-is-here">70% of physicians at UCSF</a> now use AI scribes daily, and Kaiser Permanente logged more than 2.5 million AI-scribed encounters over 14 months. <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC12265753/">Randomized trial evidence</a> confirms that these tools reduce documentation time and burnout scores.</p><p>The AI tools most commonly deployed in nursing workflows belong to a different category. Patient acuity scoring algorithms analyze EHR data to determine how sick a patient is and predict how many nursing hours that patient requires. Staffing algorithms use those acuity scores to determine how many nurses are called into a shift. Automated handoff tools generate shift reports. Clinical deterioration algorithms produce alerts. These tools are not activated by the nurse. They are deployed by hospital administration, they run continuously, and their outputs directly constrain what nurses do and how many patients they are assigned.</p><p>The <a href="https://www.nationalnursesunited.org/press/national-nurses-united-survey-finds-ai-technology-undermines-patient-safety">NNU&#8217;s 2024 survey</a> of 2,300 members documented what this looks like in practice. Half of respondents said their employer uses algorithmic systems to determine patient acuity and predict required nursing hours. Of those, 69% said the AI-generated acuity score did not match their own clinical assessment. Among nurses whose employers use automated handoff tools, 48% said those AI-generated reports contradicted their own patient assessment.</p><h2>The Override Problem</h2><p>Forty percent of nurses in hospitals using algorithmic patient outcome tools said they cannot override the algorithm&#8217;s prediction when their clinical assessment differs. Twenty-nine percent said they cannot alter algorithm-produced wound or pain documentation in the EHR even when they believe it is inaccurate.</p><p>Every professional association framework, including the ANA, AAN, and AMA documents described above, establishes that clinical judgment must prevail over AI outputs. The survey data documents a significant gap between that principle and what is happening at the bedside, and the governance frameworks have no mechanism to close it.</p><p>The gap has a structural explanation. The patient acuity and staffing tools that nurses cannot override were not purchased by clinical leadership. They were sold to hospital CFOs and operations teams on the explicit promise of reducing labor costs. Vendor marketing for these systems is direct: AI staffing tools minimize overtime, reduce reliance on expensive agency nurses, and cut contract-labor dependency. <a href="https://www.cwshealth.com/post/ai-powered-workforce-planning-how-hospitals-will-hire-in-2026">Ascension Health reported reducing contract-labor dependency by 15%</a>within six months of implementing a predictive staffing system.</p><p>A nurse who can override her acuity score is a nurse who can force additional staffing. Override capability undermines the tool&#8217;s core value to its actual customer. The inability to override is not a design flaw. It is, from the purchaser&#8217;s perspective, a feature.</p><p>Many of these operational tools, including staffing algorithms and acuity scoring systems, also do not meet the FDA&#8217;s current definition of a medical device. They face no premarket safety review requirement. No regulator required the vendor to build in an override function, and no regulator currently enforces one.</p><h2>Presence Without Agency</h2><p>The academic literature has recently begun to examine what &#8220;human in the loop&#8221; actually means in practice. <a href="https://www.tandfonline.com/doi/full/10.1080/15265161.2024.2377114">A paper in the American Journal of Bioethics</a> specifically flags that researchers and institutions routinely invoke HITL as ethical legitimacy without specifying which humans, in which processes, are doing what, and cites NNU survey data on nurses unable to override algorithmic predictions as a concrete example.</p><p>The <a href="https://www.systemsintegrity.org/from-human-in-the-loop-to-human-with-agency-why-ai-oversight-fails-when-humans-are-present-but-powerless/">Institute for Systems Integrity published a related framework</a> in May 2026, distinguishing between two states that are often conflated. In the first, a human is present near the AI system: they are notified, they see the output, and they are in the loop in the awareness sense. In the second, a human has agency: they can interrupt the system, modify its output, or substitute their own judgment without penalty. The institute&#8217;s framing is clear:</p><blockquote><p><strong>&#8220;A human placed near an AI system is not automatically a safeguard. A clinician asked to approve a recommendation under time pressure, incomplete information, workload overload, and unclear authority may not be exercising judgment.&#8221;</strong></p></blockquote><p>The <a href="https://www.kiteworks.com/regulatory-compliance/human-in-the-loop-ai-compliance/">EU AI Act</a> makes this distinction legally operational for high-risk AI systems. Article 14 requires that humans be able to interrupt or override the system&#8217;s operation and decide not to use it in a specific situation. This is described as an architectural requirement, not a procedural right. No equivalent US requirement exists for hospital operational AI tools.</p><p>A nurse who receives an acuity score that cannot be changed has been notified. That nurse has not been given authority.</p><h2>What The NNU Is Doing</h2><p>The National Nurses United published a <a href="https://www.nationalnursesunited.org/sites/default/files/nnu/documents/0424_NursesPatients-BillOfRights_Principles-AI-Justice_flyer.pdf">Nurses and Patients&#8217; Bill of Rights</a> in April 2024. Seven rights are enumerated. Most coverage of this document focuses on Right 7, which demands pre-deployment bargaining rights: the right to negotiate over whether and how AI is implemented before the system is selected.</p><p>Right 5 is less examined and more operationally significant given the override data. It establishes the right of nurses to exercise professional judgment and override AI decisions without threat of discipline or discharge. No professional association framework, from the ANA, AAN, or AMA, contains an equivalent enforceable protection. Right 5 is the only document in the current governance landscape that directly addresses what 40% of nurses report experiencing.</p><p>The NNU has coordinated a national bargaining campaign through its affiliate network: the California Nurses Association, the New York State Nurses Association, the Michigan Nurses Association, and the National Nurses Organizing Committee in North Carolina. Announced AI contract language has been reported at <a href="https://www.healthcarebrew.com/hospitals-facilities/nurses-are-setting-rules-about-ai-in-their-contracts">Mission Hospital in Asheville, North Carolina (2024)</a>, <a href="https://www.nysna.org/">Northwell South Shore University Hospital in New York</a>, the <a href="https://fortune.com/2026/02/20/new-york-nurses-union-raise-ai-safeguards-deal-longest-strike/">New York City hospital systems including NYP, Montefiore, and Mount Sinai</a> following a strike by nearly 15,000 nurses in February 2026, <a href="https://www.marketplace.org/story/2026/06/24/why-nurses-unions-are-fighting-for-ai-guardrails">Munson Medical Center in Traverse City, Michigan</a>, and the <a href="https://www.nationalnursesunited.org/press/uc-registered-nurses-ratify-contract">University of California system</a>, where a contract ratified in November 2025 specifies that nurses play a central role in selecting, designing, and validating new technology including AI systems.</p><p>One caveat applies to all of the above. No journalist or outlet has quoted actual contract clause text from any of these agreements. Coverage consistently describes outcomes in terms of &#8220;safeguards,&#8221; &#8220;guardrails,&#8221; &#8220;approval before deployment,&#8221; and &#8220;voice in how AI is rolled out.&#8221; Whether the ratified language reflects the specificity of the Bill of Rights, including Right 5&#8217;s override protection, or represents a narrower pre-deployment consultation right, is unknown without the contract documents.</p><p>The physician union equivalent, the <a href="https://www.uapd.com/2025/12/message-from-our-union-president-our-human-imperative-for-2026/">Union of American Physicians and Dentists</a>, has identified AI as a bargaining priority, with the organization&#8217;s president stating in December 2025 that it is &#8220;imperative&#8221; that the union engage in dialogue with employers to prevent professional judgment substitution by AI. UAPD has not yet produced ratified AI contract language. That gap is approximately 18 months, which is consistent with the tool asymmetry: physicians have not yet encountered operational AI deployed on them at scale without override rights.</p><h2>Two Tracks, One Unresolved Problem</h2><p>The landscape across both professions is now parallel. Both nursing and medicine have a professional association track and a union track responding to AI.</p><p>The ANA and AAN are doing what the AMA is doing: publishing principles, developing governance frameworks, and advocating for policy. The difference in urgency between the nursing professional associations and their physician counterparts reflects the difference in tool adoption rates and trust levels, not a fundamental strategic divergence.</p><p>NNU is doing something the professional associations can&#8217;t do: creating enforceable bedside protections through contract law. They are addressing different layers of the same problem. A hospital can have an excellent AI governance committee and still deploy an acuity algorithm with no override function. A union contract can protect override rights but cannot prevent a poorly validated tool from being purchased in the first place. Both layers are needed.</p><p>Neither layer has resolved the problem of definition at the center of all of this. Every framework, every position statement, every contract announcement invokes human oversight as a governing principle. No one has established that human oversight requires the ability to override. Until that definition is settled, &#8220;human in the loop&#8221; describes a spectrum that runs from a nurse with full authority to substitute her/his clinical judgment to a nurse who receives a notification she/he cannot act on. Both nurses are, technically, in the loop.</p><h2>Questions Worth Asking</h2><p>If you are responsible for AI governance at a hospital or health system, the relevant question is whether your governance committee&#8217;s approval process specifies override capability as an architectural requirement of deployment instead of a recommendation. A tool that generates outputs clinicians cannot modify does not meet the HITL standard described by the ANA, AAN, or AMA, regardless of what the vendor&#8217;s documentation says.</p><p>If you are a nurse in a facility with a union contract that includes AI language, the clause text matters more than the press release. &#8220;Safeguards&#8221; and &#8220;guardrails&#8221; are not contract language. Right 5 of the NNU Bill of Rights, protection of the right to override without threat of discipline, is the protection most directly supported by the survey data. Whether it appears in your contract is a question worth answering.</p><p>If you are a nurse in a non-unionized facility, the <a href="https://www.nursingworld.org/news/news-releases/2026-news-releases/american-nurses-association-calls-for-nurse-led-guardrails-on-artificial-intelligence-in-healthcare/">ANA Think Tank consensus document</a> and the <a href="https://telehealth.org/news/american-academy-of-nursing-issues-comprehensive-ai-position-statement/">AAN position statement</a> establish a national professional standard you can cite through shared governance structures or unit councils when raising concerns about tools that cannot be overridden.</p><p>If you are a physician, the operational AI category that nursing is responding to is not exclusive to nursing. The tools that constrain clinical judgment without requiring clinical input in procurement are already present in prior authorization, clinical documentation, and diagnostic triage. The <a href="https://www.uapd.com/2025/12/message-from-our-union-president-our-human-imperative-for-2026/">UAPD&#8217;s December 2025 statement</a> suggests that physician union organizing around AI is overdue.</p><p>The governance frameworks say clinical judgment must prevail. The mechanism that makes that principle enforceable at 3am, when an acuity score determines whether a second nurse comes to the floor, does not yet exist in voluntary guidelines.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[UpDoc Is Making Headlines]]></title><description><![CDATA[The clearance documents deserve the same attention.]]></description><link>https://ashooreview.com/p/updoc-is-making-headlines</link><guid isPermaLink="false">https://ashooreview.com/p/updoc-is-making-headlines</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Mon, 29 Jun 2026 16:39:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KzG0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><span>Pull up the actual FDA clearance documents for UpDoc, and you&#8217;ll find a story that looks pretty different from the one in the press releases. In today&#8217;s newsletter, I&#8217;ll spend some time breaking down those details and why some scrutiny is warranted. </span></em></p><p><em><span>Meanwhile, if you enjoy reading, subscribe and tell a friend. </span></em></p><p><em><span>Sam</span></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KzG0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KzG0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KzG0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1722762,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/204008610?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KzG0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KzG0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ca292b7-ef83-4cb6-84b2-9962ac20aa2a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong><span>What the media is saying.</span></strong></h3><p><span>The narrative told by the WSJ Pro, MedCity News, and multiple others goes something like this: two Stanford physicians, Sharif Vakili and Ashwin Nayak, ran a rigorous randomized controlled trial proving an AI system could autonomously manage insulin titration in type 2 diabetic patients. The results were dramatic. The AI group hit glycemic control targets in 15 days on average. Fewer than half the standard care group got there at all within eight weeks. Result: 81% controlled by the AI versus 25% by standard practice.</span></p><p><span>They then built UpDoc on that clinical foundation, got it FDA-cleared as a Software as a Medical Device, and are deploying what the company calls &#8220;physician-grade agentic AI&#8221; to autonomously adjust insulin doses between office visits. They claim it is the first of its kind, ushering in a new era of care.</span></p><p><span>That&#8217;s the story, but there is a lot of nuance to be discussed. </span></p><h3><strong><span>What the study actually tested</span></strong></h3><p><span>The MIVA trial (Managing Insulin with Voice AI) was a real RCT, published in JAMA Network Open, and conducted at four Stanford primary care clinics from March 2021 to December 2022. Thirty-two adults with type 2 diabetes were randomized into two groups. Half got the voice AI intervention; half got standard care. The results were genuinely strong for a pilot of that size.</span></p><p><span>Here&#8217;s what the coverage consistently leaves out: the voice AI in that trial was </span><strong><span>Amazon Alexa</span></strong><span>. Not a generative model, and nothing resembling what most people picture when they hear &#8220;agentic AI.&#8221; Alexa in 2021 was a narrow, deterministic speech recognition virtual assistant using wake word detection, intent classification, and programmed rules. When a patient said &#8220;my sugar was 140 this morning,&#8221; the system translated that to glucose_value: 140 through rigid pattern matching. It did not use  probability distributions, learned weights, or  generative inference.</span></p><p><span>The insulin titration logic itself came straight from clinical guidelines published by the American Association of Clinical Endocrinologists and the American College of Endocrinology. If glucose is X, adjust dose by Y.  An extremely well-executed, patient-friendly, clinically grounded flowchart, but still a flowchart.</span></p><p><span>What the MIVA trial proved is that a deterministic, rules-based system could dramatically outperform standard care at insulin titration. That&#8217;s a legitimate and important finding. It didn&#8217;t prove that AI was necessary. It proved that consistent protocol execution was sufficient and that the existing standard of care was failing patients badly enough that almost any disciplined approach would beat it.</span></p><h3><strong><span>What UpDoc actually built</span></strong></h3><p><span>The commercial UpDoc product is architecturally different from what ran in the MIVA trial. The FDA documents describe three software components: a provider-facing web portal, a patient mobile app, and a cloud-based application with a &#8220;Conversation Service&#8221; (the UpDoc Agent) and a &#8220;Clinical Service.&#8221;</span></p><p><span>The Conversation Service is where the LLM lives. It handles patient interaction: collecting glucose readings, asking about symptoms, communicating instructions back in natural language. This is the part UpDoc markets as &#8220;agentic AI.&#8221; The Clinical Service is where the dosing decision actually happens. It computes insulin instructions based on treatment parameters defined by the ordering physician. That&#8217;s the deterministic calculator.</span></p><p><span>The architecture is sensible. When your favorite AI needs to do arithmetic, it calls a Python tool rather than generating an answer probabilistically. You want a specific and correct (deterministic) answer to a math problem, not the most likely (probabilistic) answer from an LLM. UpDoc uses the same design. It&#8217;s brilliant. The problem is the marketing claims about it.</span></p><h3><strong><span>What the FDA actually cleared</span></strong></h3><p><span>Pull up the FDA K253281 </span><a href="https://www.accessdata.fda.gov/cdrh_docs/pdf25/K253281.pdf"><span>submission</span></a><span> and </span><a href="https://www.accessdata.fda.gov/cdrh_docs/reviews/K253281.pdf"><span>decision</span></a><span> summaries</span> for UpDoc. Two things struck me.</p><p><span>First: &#8220;No clinical testing was performed.&#8221;</span></p><p><span>The MIVA trial appears nowhere in either FDA document. It is not mentioned as supporting evidence, as a reference, or in the bibliography. The FDA never evaluated the 32-patient sample. It never weighed the 81% versus 25% outcome data. The Stanford trial played no role in the clearance.</span></p><p><span>Second: The clearance rests on substantial equivalence to the d-Nav System, a handheld insulin dose calculator made by Hygieia, Inc., which was cleared in 2018. It&#8217;s not an AI product or an LLM. It&#8217;s a software-based dose calculator that predates the MIVA trial by three years. The product code is NDC, and the regulation is 21 CFR 868.1890 &#8220;Predictive pulmonary-function value calculator,&#8221; a classification repurposed for insulin calculators. The word &#8220;AI&#8221; doesn&#8217;t appear in the regulatory classification.</span></p><p><span>What the FDA evaluated was software testing per IEC 62304, cybersecurity review, and human factors validation studies. That&#8217;s it. UpDoc is a Class II device cleared because it&#8217;s substantially equivalent to a prior calculator, with a voice-and-chat interface as its primary differentiating feature.</span></p><h3><strong><span>The change plan is the most revealing document</span></strong></h3><p><span>The Predetermined Change Control Plan (PCCP) is a roadmap of modifications UpDoc can make post-clearance without filing a new 510(k). It contains a critical sentence:</span></p><p><span>All future modifications must &#8220;</span><em><span>maintain deterministic insulin dosing logic without altering core clinical decision-making</span></em><span>.&#8221;</span></p><p><span>The FDA locked this in as a condition of clearance. UpDoc can&#8217;t exchange a probabilistic LLM for dosing decisions without filing a new submission. Whatever &#8220;agentic AI&#8221; means in the press releases, the cleared device&#8217;s dosing engine is, by regulatory requirement, deterministic. The regulators saw the architecture, understood which layer was doing which job, and explicitly required the calculator layer to stay a calculator.</span></p><p><span>The PCCP also specifies &#8220;</span><em><span>zero tolerance for deviation and incorrect unit conversion rates of zero</span></em><span>&#8221; for alternative data input methods, including voice. They&#8217;ve identified the handoff between the LLM interface and the deterministic dosing engine as a risk point. That&#8217;s the right decision. It also quietly acknowledges that the handoff is where the probabilistic layer touches a safety-critical area, and that this interface has never been clinically validated.</span></p><h3><strong><span>&#8220;Agentic AI&#8221; &#8212; and what that actually means</span></strong></h3><p><span>UpDoc&#8217;s press release calls the platform &#8220;physician-grade agentic AI&#8221; at least three times. The coverage has largely accepted this framing without much scrutiny. </span></p><p><span>Agentic AI has a reasonably specific meaning in the field: a system that perceives its environment, makes autonomous decisions across multiple steps, selects and uses tools, and pursues a goal over time while adapting its approach based on intermediate results. The defining characteristic of a true agent is that it decides </span><em><span>how</span></em><span> to accomplish something, not just what to output when given a specific input.</span></p><p><span>To its credit, UpDoc has been transparent about what </span><em><span>it</span></em><span> means by the term. Their press release defines agentic through a three-step workflow: the system monitors patient data and identifies trends requiring intervention, executes insulin titration within physician-approved parameters, then closes the loop by triggering follow-up lab orders and documenting the intervention in the EHR. </span></p><p><span>Map each of those steps against what the clearance documents actually describe, and the picture doesn&#8217;t look as agentic.</span></p><p><span>&#8220;</span><strong><span>Monitors patient data and identifies trends</span></strong><span>&#8221;: The system receives glucose values the patient reports or a CGM transmits, then checks them against pre-defined thresholds. That&#8217;s threshold alerting. A blood pressure cuff that beeps when you&#8217;re hypertensive does the same thing.</span></p><p><span>&#8220;</span><strong><span>Executes titration within physician-approved parameters</span></strong><span>&#8221;: This is the deterministic calculator we&#8217;ve already covered. This is very good and safe for patients. But to be clear, the AI has no agency here. It can&#8217;t deviate, can&#8217;t reason an alternative approach, can&#8217;t decide that a different protocol might fit better.</span></p><p><span>&#8220;</span><strong><span>Triggers follow-up lab orders and documents in the EHR</span></strong><span>&#8221;:  This is the most plausibly agentic-sounding item on the list and genuinely new relative to the predicate (comparison) device. But &#8220;triggers necessary follow-up labs&#8221; almost certainly means the physician pre-specified which labs fire under which clinical conditions. It&#8217;s another if/then rule in the protocol, executed automatically. Important, but still not agentic reasoning.</span></p><p><span>The &#8220;physician-governed&#8221; framing they use to address safety concerns is the clearest argument against the agentic claim. They describe the physician as prescribing the treatment plan while the AI implements it within defined boundaries, with zero tolerance for deviation, as required by the PCCP. A system that&#8217;s fully constrained by a pre-specified protocol, with no discretion and no ability to adapt its approach, isn&#8217;t an agent. It&#8217;s an automated executor with a very detailed job description.</span></p><p><span>For comparison, insulin pumps automate delivery. Ventilators automate titration. Pacemakers automate rhythm correction. Automated pharmacy refill systems initiate patient outreach. None of those are called agentic AI because automation and agency aren&#8217;t the same thing. What&#8217;s genuinely new about UpDoc is the natural language interface, the EHR integration, and the physician governance model. Those are real innovations worth evaluating on their own terms. Calling them agentic doesn&#8217;t make them more impressive; it makes the term less meaningful.</span></p><h3><strong><span>The conflict of interest worth understanding </span></strong></h3><p><span>The Medscape coverage flagged that Nayak and co-authors disclosed owning UpDoc stock at the time of publication. UpDoc was founded three months after the MIVA trial was completed. The company didn&#8217;t exist when the trial was designed or conducted, so there was nothing to disclose at conception. The trial appears to have been designed and executed cleanly.</span></p><p><span>What the disclosure reflects is that by the time the paper was published, the researchers had become the founders. The conflict isn&#8217;t in the data. It&#8217;s in how that data has since been used. The researchers who designed the study are now the executives with the most to gain from that study being accepted as definitive validation of their commercial product. They&#8217;re the most prominent voices promoting it. They&#8217;re the ones driving the conflation of the MIVA findings with UpDoc&#8217;s commercial viability.</span></p><p><span>That&#8217;s not misconduct. Physician-researchers commercializing their findings is how medical innovation is supposed to work. But it does mean the most enthusiastic advocates for the study&#8217;s conclusions have the strongest financial interest in those conclusions being stretched beyond what a 32-patient pilot can actually support.</span></p><h3><strong><span>The liability question nobody asked</span></strong></h3><p><span>One detail from the WSJ piece deserves attention. CEO Vakili drew a clear legal line: UpDoc is liable for accurately implementing the physician&#8217;s care plan. It&#8217;s not responsible if the care plan itself is faulty.</span></p><p><span>That&#8217;s a meaningful posture, and it&#8217;ll be tested. When an autonomous AI executes a physician&#8217;s protocol and something goes wrong, the line between &#8220;bad protocol&#8221; and &#8220;bad execution&#8221; is exactly what litigation will contest. A plaintiff&#8217;s attorney doesn&#8217;t need to prove the algorithm malfunctioned. They need to create reasonable doubt about where the failure originated. The Cleveland Clinic&#8217;s executive framing of UpDoc as liable for implementation is a clean division of responsibility in a press release that will look considerably more complicated in a deposition.</span></p><h3><strong><span>What&#8217;s genuinely worth crediting</span></strong></h3><p><span>The care gap UpDoc is targeting is real and large. Basal insulin titration requires frequent patient contact, glucose logs, clinician availability, and patient follow-through. The MIVA trial demonstrated that even a fully deterministic system dramatically outperforms passive standard care. If UpDoc&#8217;s commercial product can replicate that in a larger, more diverse population, patients will be better off.</span></p><p><span>The FDA pathway they chose is the right one. Robert Califf noted they sought regulatory scrutiny rather than avoiding it. That&#8217;s notable in a space where plenty of clinical AI tools deploy without any regulatory engagement at all. And the architecture (physician sets the protocol, algorithm executes it, LLM handles the conversation) is well-reasoned for this use case. Deterministic dosing logic is exactly what you want when you&#8217;re adjusting medications autonomously. You want rule-following fidelity, not creative inference.</span></p><p><span>The concern isn&#8217;t the product. It&#8217;s the story being told about it.</span></p><h3><strong><span>The three-layer disconnect</span></strong></h3><p><span>The MIVA trial tested a deterministic Alexa-based system, not UpDoc. It validated consistent protocol execution. UpDoc then added an LLM to that architecture, and that substitution has never been clinically validated. The FDA, meanwhile, cleared a dose calculator based on a 2018 predecessor and never saw the trial or evaluated the LLM. Three layers. Three separate stories. What UpDoc is selling is the version where they all fuse into one: the trial validates the product, the product earns the clearance, the clearance confirms the AI. None of those connections hold up.</span></p><h3><strong><span>Your license. Your responsibility.</span></strong></h3><p><span>UpDoc may become an important tool. The clinical problem is real. The regulatory pathway was handled responsibly. The underlying architecture is defensible.</span></p><p><span>But before your health system signs on or you prescribe this as a treating physician, ask the questions the press coverage didn&#8217;t:</span></p><p><span>What, specifically, does the LLM component do, and what does the deterministic clinical service do? Get that in writing.</span></p><p><span>Has the LLM interface layer been clinically validated in a population comparable to yours? The MIVA trial didn&#8217;t test it. The FDA didn&#8217;t evaluate it. Who did?</span></p><p><span>What happens when the LLM misparses a patient&#8217;s glucose report? What&#8217;s the actual error rate at the handoff between the conversational layer and the dosing engine? The PCCP mandates zero tolerance, but mandating and demonstrating are different things.</span></p><p><span>What does the liability split mean in practice for your institution when something goes wrong?</span></p><p><span>The algorithm that ran in the MIVA trial followed AACE and ACE guidelines faithfully. That system worked. Know what&#8217;s running in the commercial product that replaced it. That&#8217;s our job.</span></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Transparency Isn't a Safeguard ]]></title><description><![CDATA[The FDA Loosened AI Oversight. Your Liability Didn't Move.]]></description><link>https://ashooreview.com/p/transparency-isnt-a-safeguard</link><guid isPermaLink="false">https://ashooreview.com/p/transparency-isnt-a-safeguard</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Thu, 25 Jun 2026 18:36:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_Fbz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><em>On January 6, 2026, the FDA <a href="https://www.fda.gov/media/109618/download">published</a> revised guidance on clinical decision support (CDS) software, and the coverage has largely been positive. Less red tape. Faster innovation. Tools that can finally say what they actually mean instead of hedging behind padded lists of possibilities.</em></p><p><em>There&#8217;s real merit to that change. But there&#8217;s also a version of this story that hasn&#8217;t been told yet, one that is especially relevant in emergency medicine and critical care.</em></p><p><em>Let&#8217;s get into it.</em></p><p><em>As always, if you enjoy reading, I encourage you to subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Fbz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Fbz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Fbz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/beab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1786222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/203486246?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Fbz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_Fbz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbeab29b1-36a0-4e48-8761-490f7cc53303_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>What Actually Changed</strong></h3><p>For years, one of the FDA&#8217;s more awkward regulatory quirks was that clinical decision support (CDS) software offering a <em>single</em> recommendation was more likely to be classified as a medical device than software offering multiple options. The perverse result: developers were incentivized to dilute outputs, presenting three or four choices even when the evidence clearly favored one. Clinicians had to sort through the noise. Nobody loved it.</p><p>The new guidance fixes that. The FDA will now allow single-recommendation CDS without triggering device classification, provided the logic, data sources, and guideline basis behind that recommendation are visible to the clinician. They call it a &#8220;glass box&#8221; model: not opaque AI rendering a verdict, but transparent reasoning a clinician can inspect before acting.</p><p>There&#8217;s also an expanded &#8220;general wellness&#8221; carveout for consumer wearables. Devices reporting metrics like blood pressure and oxygen saturation can now stay outside device regulation as long as they don&#8217;t make diagnostic claims. That part is not controversial.</p><p>What&#8217;s important to understand is that this isn&#8217;t complete deregulation. The FDA still asserts authority over opaque models and tools that substitute for clinical judgment. The line just moved meaningfully in the direction of &#8220;trust the clinician to evaluate the output.&#8221;</p><div><hr></div><h3><strong>The Case for Optimism (And It&#8217;s a Real One)</strong></h3><p>I want to be fair here because my job isn&#8217;t to reflexively oppose change. It&#8217;s to evaluate it honestly.</p><p>The previous regulatory logic was genuinely broken. When guidelines and patient data points in one direction, medicine often has a right answer. Forcing CDS to pretend otherwise didn&#8217;t make things safer; it just made the tools harder to use.</p><p>A well-designed, transparent AI that surfaces the relevant evidence, flags the applicable guideline, and tells you its reasoning is a useful clinical assistant. If the FDA&#8217;s revised framework actually enables more of that and less of the multi-option noise, that&#8217;s a good thing for both clinicians and patients.</p><div><hr></div><h3><strong>This Should Give You Pause</strong></h3><p>The entire framework rests on one assumption: that transparency functions as a reliable safeguard. It&#8217;s worth asking whether that assumption holds in practice.</p><p>In theory, a glass box lets you inspect the AI&#8217;s reasoning before accepting its recommendation. In practice, in an overcrowded ED, at the tenth hour of a twelve-hour shift, with a septic patient in bay 3 and a chest pain in bay 7, are you clicking through the reasoning panel? Are your colleagues? Are you confident that institutional productivity pressures won&#8217;t quietly reward the physicians who just accept the output and move on?</p><p>Cognitive offloading isn&#8217;t a character flaw. It&#8217;s a predictable human response to cognitive overload. The FDA guidance even acknowledges automation bias as a concern, but it doesn&#8217;t solve it. It just names it and hands the responsibility back to the clinician.</p><p>And here&#8217;s the real kicker: <strong>the FDA explicitly carved emergency and time-critical CDS </strong><em><strong>out</strong></em><strong> of the loosened framework</strong>. The guidance states that software intended for urgent, high-stakes decisions where the clinician lacks time to independently review the logic does <em>not</em> qualify for the exemption, specifically citing automation bias in those settings. That is, our propensity to accept what the machine is telling us even when there is contradictory evidence.</p><p>Read that again: the specialty with the highest acuity, the fastest decision cycles, and the most cognitively demanding environment is the one the FDA flagged as <strong>highest-risk</strong>. If you&#8217;re practicing emergency medicine, the tools most likely to influence your practice are the ones that still require close regulatory scrutiny. Which means some of what&#8217;s entering your ED workflow may not meet that bar, and you may not know which is which.</p><div><hr></div><h3><strong>The Liability Math Nobody Is Talking About</strong></h3><p>Here&#8217;s where it gets uncomfortable.</p><p>The FDA declined to define what &#8220;clinically appropriate&#8221; means when it comes to single-recommendation CDS. That decision gets made by the developers. And when an AI-influenced recommendation leads to a bad outcome, the responsibility lands where it always has: with the physician who accepted it.</p><p>More AI authority in the workflow. Same physician accountability. That&#8217;s not necessarily wrong. It&#8217;s how medicine has always worked with every tool we use. But it&#8217;s worth being clear-eyed about the asymmetry. <strong>The guidance accelerates the path for tools to enter your workflow while leaving unchanged the standard of care you&#8217;re held to when they&#8217;re wrong.</strong></p><p>Your license. Your responsibility. That&#8217;s not just a tagline. It&#8217;s the legal and ethical reality that the FDA&#8217;s framework reinforces.</p><div><hr></div><h3><strong>The LLM Blind Spot</strong></h3><p>One more thing worth noting: the guidance is nearly silent on generative AI.</p><p>The tools that are actually proliferating at the bedside right now- AI scribes, ambient documentation platforms, chatbot-style decision support embedded in the EHR- are largely built on large language models. And LLMs present a specific transparency challenge that rule-based systems don&#8217;t: their outputs are probabilistic, not deterministic. That means the models rely on educated guesses when faced with uncertainty, rather than following a set of rules that reach the same conclusion every time. The &#8220;glass box&#8221; concept is much harder to apply when the reasoning isn&#8217;t a traceable logic chain.</p><p>The FDA&#8217;s guidance doesn&#8217;t really address this. Whether that represents regulatory humility or a gap that needs to be filled is an open question. However, it means clinicians are navigating a rapidly evolving LLM-enabled ecosystem without clear guidance on how those tools fit into the framework.</p><div><hr></div><h3><strong>A Case Study</strong></h3><p>Abstract regulatory language is easier to evaluate when it touches something real. So let&#8217;s apply the FDA&#8217;s four criteria to a tool many emergency physicians are already using: OpenEvidence.</p><p>OpenEvidence allows physicians to enter patient-specific clinical information, including protected health information, and receive synthesized answers and recommendations from peer-reviewed literature. It cites its sources. It also draws conclusions.</p><p>Walk it through the criteria.</p><p><strong>&#9989;Criterion 1: Data inputs.</strong> OpenEvidence ingests text-based clinical information: symptoms, labs, diagnoses, history. This isn&#8217;t imaging data or signals from diagnostic hardware. Criterion 1 is probably satisfied. </p><p><strong>&#9989;Criterion 2: Displaying and analyzing medical information.</strong> The software matches patient-specific data against clinical literature and guidelines, which is precisely the FDA&#8217;s own example of what this criterion covers. Criterion 2 is satisfied.</p><p><strong>&#10067;Criterion 3: Supporting versus directing judgment.</strong> This is where it gets murky. The FDA draws a sharp line between software that presents options for a clinician to weigh and software that summarizes answers and draws conclusions. OpenEvidence&#8217;s outputs function more like directives than option lists. The answer to this criterion depends on exactly how its recommendations are framed, and that&#8217;s worth looking at closely.</p><p><strong>&#10060;Criterion 4: Independent reviewability.</strong> This is where the ED context becomes decisive, and where the FDA&#8217;s own language is crystal clear.</p><p>The guidance states directly that software intended for critical, time-sensitive decisions does not meet Criterion 4, because clinicians are unlikely to have sufficient time to independently review the basis of the recommendations. The FDA states that in urgent situations, the pressure to act accelerates the tendency to accept AI output without independent scrutiny.</p><p>OpenEvidence used by a primary care physician working up a chronic condition, with time to click through citations and evaluate the reasoning, might satisfy all four criteria. The same tool, used by an emergency physician making a time-critical disposition decision, certainly doesn&#8217;t. Not because the software changed. <strong>Because the context did.</strong></p><p>That distinction matters more than most clinicians realize. The FDA&#8217;s framework isn&#8217;t tool-specific; it&#8217;s context-specific. And a lot of what&#8217;s currently running in ED workflows may be operating in a regulatory gray zone that neither clinicians nor hospital administrators have fully reckoned with.</p><p>Citing sources isn&#8217;t the same as giving clinicians time to read them. In the ED, those two things are rarely the same.</p><div><hr></div><h3><strong>What to Do With All This</strong></h3><p>The FDA&#8217;s January guidance isn&#8217;t reckless, and it isn&#8217;t trivial. It&#8217;s a deliberate bet that clinical AI can move faster without sacrificing safety if clinicians stay meaningfully engaged with what the tools are telling them and why.</p><p>Whether that bet pays off depends almost entirely on us. Before your department adopts a new AI CDS tool, here&#8217;s what I&#8217;d want to know:</p><p>Does the reasoning actually surface in the workflow, or is it buried three clicks deep? What does the vendor say about performance in high-acuity, time-critical settings specifically? Has it been validated on a patient population that resembles yours? Who reviewed the validation data, and was it anyone independent of the company selling it? And critically, what happens when it&#8217;s wrong, and how is that tracked?</p><p>The FDA has done its part by drawing a clearer map. But we&#8217;re the ones practicing in the territory, and the terrain in an ED at 2 am looks nothing like the conference room where these policies get written.</p><p>Transparency is a good start. Reflection is the part we have to supply ourselves.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[7 Things NOT To Do On OpenEvidence ]]></title><description><![CDATA[Or Any AI Clinical Decision Support Tool]]></description><link>https://ashooreview.com/p/7-things-not-to-do-on-openevidence</link><guid isPermaLink="false">https://ashooreview.com/p/7-things-not-to-do-on-openevidence</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Sun, 21 Jun 2026 19:22:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!24LL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>If you have been a regular reader of this newsletter, you know I&#8217;ve focused a lot on the failures of clinical AI tools. But I still find them clinically useful. To help my colleagues and friends avoid the traps of these tools, I developed a short checklist of things to keep in mind. Download it and read more about the reasoning behind each item below. </em></p><p><em>As always, if you enjoy reading this newsletter, subscribe and tell a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!24LL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!24LL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!24LL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!24LL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!24LL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!24LL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1915476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/202839356?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!24LL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!24LL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!24LL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!24LL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb499a9a0-ab51-47ac-a118-536ec0f076d5_1402x1122.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Clinical AI tools have become part of daily practice for many physicians. OpenEvidence, Doximity GPT, AI scribes, and clinical decision support tools can improve efficiency and provide valuable assistance. At the same time, these tools create new risks that most physicians never encountered during training.</p><p>I have written about the limitations, regulatory concerns, and real-world testing of clinical AI systems. The most common problems I see are not dramatic AI hallucinations. They are workflow mistakes made by clinicians who assume these tools are safer, more accurate, or more legally protected than they actually are.</p><p>To help physician leaders educate their clinical staff, I created the following Clinical AI Safety Checklist. You can download it here  and read more about each item below. </p><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail-default" src="https://substackcdn.com/image/fetch/$s_!0Cy0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack.com%2Fimg%2Fattachment_icon.svg"></image><div class="file-embed-details"><div class="file-embed-details-h1">Clinical Ai Safety Checklist Ashooreview</div><div class="file-embed-details-h2">520KB &#8729; PDF file</div></div><a class="file-embed-button wide" href="https://ashooreview.com/api/v1/file/28109e3f-2b19-42e0-bdfe-eb7e36cff007.pdf"><span class="file-embed-button-text">Download</span></a></div><a class="file-embed-button narrow" href="https://ashooreview.com/api/v1/file/28109e3f-2b19-42e0-bdfe-eb7e36cff007.pdf"><span class="file-embed-button-text">Download</span></a></div></div><div><hr></div><h3><span>1. Don&#8217;t Upload ECGs or X-Rays</span></h3><p>Most general-purpose clinical AI tools are not FDA-cleared devices for interpreting ECGs, radiographs, CT scans, MRIs, or other diagnostic images.</p><p>My own testing of multiple systems has demonstrated substantial errors in ECG and radiology interpretation. These errors can be subtle and dangerous because the AI often presents its conclusions with confidence. Often, there is no warning that the system can not accurately read them, and the presence of an image upload feature is misleading. </p><p>If a clinical AI platform lacks FDA authorization for diagnostic image interpretation, physicians should avoid using it for that purpose.</p><p><strong>Dive Deeper:</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;777aabc1-11d6-403f-adc6-62bb1f4673dd&quot;,&quot;caption&quot;:&quot;I&#8217;ve tested AI models on multiple tasks in previous articles. In this one, I report on X-ray interpretation. Once again, it&#8217;s important to remember that I prefer services that are upfront about the limits of their models. So, refusal to interpret is a perfectly valid answer. As always, if you enjoy reading the newsletter, subscribe and tell a friend. No&#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;11 Medical AI Tools Read These Xrays&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-09T11:33:59.811Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!BLAQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41423f1f-109e-4191-a553-2f796e589a22_1254x1254.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/11-medical-ai-tools-read-these-xrays&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201006111,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;19e4f609-db9c-4f20-95ab-5a1d3ab3b2e3&quot;,&quot;caption&quot;:&quot;Last week, I published the results of a challenging but routine case posed to 6 AI models. Today, I&#8217;m sharing the results of a similar task: reading an ECG. Before you come to the defense of your favorite model, keep one thing in mind: many of these systems are being placed into the hands of clinicians without clear instructions about what they can do, &#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Can Medical AI Read an ECG?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-02T12:38:04.317Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!OB8B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c0b05b4-7ed8-4a90-b043-708bc8501ffa_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/can-medical-ai-read-an-ecg&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:200162248,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:1,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3498762e-e93f-4562-9da4-247a5ab9a48b&quot;,&quot;caption&quot;:&quot;Another great question submitted by a reader. Send in your question about AI in Medicine for the next edition of the Ashoo Review. And as always, subscribe and tell a friend.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;OpenEvidence, Doximity, and the FDA &quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-15T16:59:36.453Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-S3f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd01a5c6-23cd-43b5-8e64-f24ecbfd3137_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/openevidence-doximity-and-the-fda&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197883326,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>2. Don&#8217;t Sign a BAA if You Work in a Hospital System</h3><p>Many physicians assume that signing a HIPAA Business Associate Agreement solves privacy concerns. After all, it&#8217;s a convenient button click in the AI tool, and it reassures the user with a &#8220;HIPAA Compliant&#8221; banner.  </p><p>In reality, employed physicians do not own the data and are not the entity responsible for it. In the law&#8217;s eyes, the protected health data is stored by the hospital, which has the responsibility of safeguarding it. For that reason, the BAA has to occur between the AI service and the hospital. So clicking that little HIPAA BAA agreement box only puts you at risk for acting as an &#8220;agent&#8221; of the hospital without authority. Unless you are in private practice, own the practice, and use the AI tool only on those patients, better to avoid this trap. </p><p><strong>Dive Deeper: </strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6bad5a9a-ac47-4086-9bf0-a2239cbb8ea9&quot;,&quot;caption&quot;:&quot;I frequently hear from physicians who are frustrated that their institution has blocked their favorite AI tool, often with no explanation. When that free tool includes ambient scribe services, there is one big trap you need to watch out for.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The &#8220;Click-to-Sign BAA&#8221; Trap in Free AI Scribes&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-28T14:28:48.668Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!1VWG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ec87a67-df94-485c-9ef9-4006808a90a1_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/the-click-to-sign-baa-trap-in-free&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195755193,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>3. Don&#8217;t Upload PHI</h3><p>Even when a platform offers a BAA, physicians should think carefully before uploading identifiable patient information. </p><p>The question is not simply whether the technology can accept PHI. The question is whether you are authorized to disclose that information under your organization&#8217;s policies and contractual arrangements.</p><p>When in doubt, de-identify the information or avoid uploading it altogether. If you don&#8217;t know what&#8217;s involved in de-identifying the information, read more at the link below. It&#8217;s a critical skill that will keep you (and your hospital) out of a lawsuit. </p><p><strong>Dive Deeper:</strong><br><a href="https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html">Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule</a></p><div><hr></div><h3>4. Don't Trust AI-Generated Insights Without Verification</h3><p>Many clinical AI systems now generate summaries, assessments, risk predictions, or observations across multiple visits. These insights can be useful. <strong>They can also be wrong.</strong></p><p>An AI may only be looking at a subset of encounters, incomplete documentation, or fragmented records. As a result, it may generate conclusions that appear reasonable while missing critical context.</p><p>Physicians should treat AI-generated insights the same way they would treat recommendations from a trainee: useful starting points that require independent verification.</p><p><strong>Dive Deeper:</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;bb692547-3dc9-4127-b2d5-d8bdc3e2fee3&quot;,&quot;caption&quot;:&quot;In this article, I&#8217;m looking at the latest feature from some of the most popular medical AI models&#8230; persistent patient memory. It&#8217;s a feature that seems super helpful, but is it creating a new legal challenge?&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Hidden Medical Record&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-12T13:06:45.093Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!CYMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/the-hidden-medical-record&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201685066,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>5. Don't Use AI-Informed Clinical Reasoning Without Documenting It</h3><p>This may be the most overlooked issue in clinical AI today.</p><p>If an AI-generated insight influences your diagnosis, treatment plan, referral decision, or other aspect of care, that reasoning should be documented in the patient&#8217;s official medical record.</p><p>Patients can review information contained in the medical record and request corrections when appropriate.</p><p>Information that exists only inside an AI platform may influence care without the transparency and accountability legally required by HIPAA and the Cures Act.</p><p>If the AI helped drive a clinical decision, document the relevant information in the chart.</p><p><strong>Deeper Dive:</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5339b648-2092-4250-8fc6-c353f2c699e3&quot;,&quot;caption&quot;:&quot;In this article, I&#8217;m looking at the latest feature from some of the most popular medical AI models&#8230; persistent patient memory. It&#8217;s a feature that seems super helpful, but is it creating a new legal challenge?&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Hidden Medical Record&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-12T13:06:45.093Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!CYMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/the-hidden-medical-record&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201685066,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>6. Don't Sign AI-Generated Notes Without Reviewing Medications and Mental Health History</h3><p>When physicians think about AI scribe errors, they often focus on hallucinations. But a report earlier this year from the Ontario Auditor General&#8217;s office found that AI scribes committed these errors most often: </p><ul><li><p>45% hallucinated treatment plans, blood tests, or referrals that were never discussed</p></li><li><p>60% documented incorrect medication names or dosages</p></li><li><p>85% omitted critical aspects of mental health history</p></li></ul><p>AI scribes frequently produce notes that appear polished and complete while leaving out clinically important details. Before signing any AI-generated note, carefully review medications, mental health history, and other high-risk sections of the chart for omissions.</p><p>Your signature confirms the accuracy of the documentation.</p><p><strong>Deeper Dive:</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;dcdd1d38-73a2-46f4-a541-a102634e992f&quot;,&quot;caption&quot;:&quot;The Canadian experience with Ambient AI scribes recently soured as the Ontario Auditor General released a special report on AI Governance. Spoiler alert&#8230; the results were not good. Let&#8217;s dive into those details. As always, keep sending in your ideas for future newsletters, and don&#8217;t forget to subscribe and tell a friend.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The &#8220;Review and Sign-Off&#8221; Fallacy&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-22T12:38:38.351Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!dqp3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feace2d4f-7927-4a8c-8947-573bb7201b24_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/the-review-and-sign-off-fallacy&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198745802,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>7. Don't Delete AI Chat History Without Understanding the Consequences</h3><p>This issue cuts both ways.</p><p>Maintaining AI chat history may provide evidence regarding what information was presented to the physician and what recommendations were generated by the system. Deleting that history may remove information that could later be relevant when evaluating clinical decisions. AI chat histories may also become discoverable during litigation or investigations. Physicians should understand their organization&#8217;s policies and think carefully before deciding whether to retain or delete AI interactions.</p><p>Most importantly, any information that materially influences patient care should be documented in the medical record rather than existing solely within an AI conversation.</p><p><strong>Deeper Dive:</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e29a1954-39ac-4c93-8543-a1640e31d229&quot;,&quot;caption&quot;:&quot;In this article, I&#8217;m looking at the latest feature from some of the most popular medical AI models&#8230; persistent patient memory. It&#8217;s a feature that seems super helpful, but is it creating a new legal challenge?&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Hidden Medical Record&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:206188244,&quot;name&quot;:&quot;Sam Ashoo, MD&quot;,&quot;bio&quot;:&quot;Emergency Physician and Medical Educator. Sam Ashoo hosts the Ashoo Review. A clinical informaticist exploring the future of medicine through a pragmatic, skeptic-first lens, bridging the gap between bedside care and AI innovation.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2002c7c-7e64-4c1e-89f9-8bee48a3d767_600x600.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-12T13:06:45.093Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!CYMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ashooreview.com/p/the-hidden-medical-record&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201685066,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8838767,&quot;publication_name&quot;:&quot;Ashoo Review: AI in Medicine&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7rBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42965e73-5c51-49cc-8af8-d07ee56092dd_814x814.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Final Thoughts</h3><p>Clinical AI tools are becoming a permanent part of healthcare delivery.</p><p>The greatest risks are rarely the ones featured in headlines. Most arise from privacy misunderstandings, documentation shortcuts, incomplete records, misplaced trust, and workflow decisions made by clinicians under pressure.</p><p>Technology will continue to improve.</p><p>Professional responsibility remains unchanged.</p><p><strong>Your license. Your responsibility.</strong></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[When Clinical AI Says “I Don’t Know”]]></title><description><![CDATA[Why Human-Curated Medical Knowledge Still Matters]]></description><link>https://ashooreview.com/p/when-clinical-ai-says-i-dont-know</link><guid isPermaLink="false">https://ashooreview.com/p/when-clinical-ai-says-i-dont-know</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Thu, 18 Jun 2026 12:15:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QOtv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Earlier this week, I discussed the <a href="https://ashooreview.com/p/when-clinical-ai-meets-independent">NYU study</a> comparing the performance of OpenEvidence, Up-To-Date AI, and Frontier LLMs. That article caused a lot of controversy and questioned the future of curated medical information. In this post, I&#8217;m diving deeper into those questions and suggesting that AI may actually be highlighting the need for such curated libraries. </em></p><p><em>As always, if you enjoy reading, please consider subscribing and telling a friend. </em></p><p><em>Sam</em></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QOtv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QOtv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QOtv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1653687,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/202283927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QOtv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QOtv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68b059db-c4cb-4ace-95a1-94767c67c480_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A recent NYU study comparing frontier AI models with specialized clinical AI tools raised an important question.</p><p>If large language models can answer clinical questions as well as, or better than, systems built on curated medical content, what is the future of organizations such as UpToDate, EB Medicine, and other services that summarize and interpret the medical literature?</p><p>For decades, physicians have relied on expert-written medical summaries to keep up with an impossible volume of research. These services review the literature, synthesize evidence, and provide practical clinical guidance. They have become part of the background infrastructure of modern medicine.</p><p>But the world is changing quickly. Today, a physician can ask an AI system a highly specific clinical question and receive a detailed answer within seconds. The answer can be adjusted for an emergency physician, hospitalist, primary care clinician, resident, or subspecialist. It can summarize trials, compare guidelines, explain mechanisms, and generate a practical approach.</p><p>So the question is unavoidable. <strong>Are human-curated medical knowledge systems still relevant? </strong>I think they are. But their future value may be different from their past value.</p><h2>The Argument Against Curated Knowledge</h2><p>The strongest argument against traditional evidence summary services is easy to understand. AI can already perform many of the tasks that physicians historically relied on these services to provide.</p><p>It can search the literature, summarize papers, compare studies, explain complex concepts, and personalize an answer. For a busy physician, this is powerful. Instead of reading a long chapter or searching through multiple articles, the clinician can ask a direct question and receive a direct response.</p><p>That is a serious challenge to the traditional medical publishing model. If summaries become instant, personalized, and inexpensive, then services built primarily around summaries will need to prove what additional value they provide.</p><p>That&#8217;s the right question, but only the first one.</p><h2>Medicine Is Not Just a Search Problem</h2><p>The mistake is assuming that physicians&#8217; needs consist mainly of finding and summarizing information.</p><p>Physicians do not just need information. We need judgment. The harder questions are not always:</p><p>What did the study show? Or what papers have been published?</p><p>The harder questions are often:</p><ul><li><p>Does this study deserve my attention?</p></li><li><p>Was the methodology strong enough?</p></li><li><p>Does this evidence apply to my patient?</p></li><li><p>How should I weigh this study against prior evidence?</p></li><li><p>Does this change practice?</p></li><li><p>What should I do when the evidence is conflicting?</p></li></ul><p>Those are not simple search tasks. They are editorial tasks. They require experience, skepticism, clinical context, and accountability.</p><p>That is what organizations like UpToDate and EB Medicine have historically provided. Their value has never been limited to summarizing articles. Their value is in deciding which evidence matters, how it should be interpreted, and how confidently it should be applied.</p><p>AI may make summaries abundant. Trustworthy interpretation remains scarce.</p><h2>The Journalism Analogy</h2><p>A useful analogy comes from journalism. The internet made information widely available. Search engines made that information easier to find. Social media made it easier for anyone to publish. Yet journalism did not disappear.</p><p>The best journalism continued to provide something beyond access to information. It provided verification, context, judgment, and accountability. Medicine is entering a similar phase.</p><p>AI makes medical information easier to retrieve and summarize than at any point in history. But that does not eliminate the need for trusted institutions that evaluate the <em>quality</em> of information. In fact, it may make them more important.</p><p>When information is scarce, access is valuable. When information is abundant, trust becomes valuable.</p><h2>My Own Experience Testing Clinical AI</h2><p>My own recent experiments with clinical AI have made this issue all the more real. I have tested multiple models across medical cases, ECGs, and  imaging tasks. The results have often been concerning.</p><p>In several cases, AI systems provided polished, confident, and incorrect interpretations. The problem was not the writing quality. The answers were usually clear, organized, and persuasive. That is exactly what makes the errors concerning. A poorly written, wrong answer is easier to distrust. A polished wrong answer is more dangerous.</p><p>This is where curated medical knowledge systems still matter. When multiple AI systems can read the same evidence and reach different conclusions, physicians need more than another summary. They need a trusted process for deciding which interpretation deserves confidence.</p><h2>The Value of Saying &#8220;I Don&#8217;t Know&#8221;</h2><p>This brings me to what may be the most underappreciated issue in clinical AI.</p><p><strong>What should an AI system do when the evidence is insufficient?</strong></p><p>In many AI evaluations, a system that does not answer is penalized. From the perspective of a benchmark, that makes sense. Researchers need a scoring system. An unanswered question is easy to count as incorrect.</p><p>But medicine is different. A benchmark rewards answers. Clinical judgment rewards calibration.</p><p>Every physician understands that some questions do not have clean answers. The literature may be sparse. Studies may conflict. The population may not match the patient. Outcomes may be surrogate rather than patient-centered. The best available evidence may be old, biased, underpowered, or indirect. In those situations, a confident answer may be satisfying. It may also be misleading.</p><p>One of the most important functions of a trustworthy medical knowledge system is recognizing when the evidence does not support a recommendation. That can be frustrating. A clinician wants help&#8230; guidance&#8230; an answer to the question.</p><p>But an honest &#8220;we don&#8217;t know&#8221; may be more valuable than an unsupported conclusion. This is where guardrails should be seen as a feature rather than a flaw.</p><p>An AI system that declines to answer may appear less capable on a leaderboard. It may also be demonstrating a form of restraint that is essential in medicine.</p><p>The ability to say &#8220;I don&#8217;t know&#8221; is not a weakness. It&#8217;s part of trust.</p><h2>Guidelines Are Full of Uncertainty</h2><p>This is not unique to AI. Medical guidelines frequently acknowledge uncertainty. Expert panels often conclude that evidence is insufficient. Recommendations are often graded as weak, conditional, or based on low-quality evidence. That is not a failure of guideline development. That is evidence-based medicine working properly.</p><p>A good guideline does not simply provide an answer to every question. It tells the reader how confident to be in the answer.</p><p>The same principle should apply to clinical AI. A system that always answers may feel more useful. A system that knows when not to answer may be safer.</p><p>The future of clinical AI should not be measured only by how often a system produces a response. It should also be measured by whether the system knows when a response is justified.</p><h2>Where Human-Curated Libraries Still Matter</h2><p>Human-curated medical libraries are systems for managing uncertainty. They don&#8217;t just collect papers. They filter, interpret, and reconcile them. They decide when evidence is strong, when it is weak, and when no recommendation can be made. That work becomes even more important when AI can generate an answer to almost anything.</p><p>A physician using AI may ask: What does the literature say?</p><p>But the deeper clinical question is often: What should I trust?</p><p>That is where expert curation still matters. The future may not be physicians reading long chapters on a website. It may be AI interfaces built on top of carefully maintained evidence bases. The interface may become conversational, personalized, and fast. But the underlying need remains the same.</p><p>Someone still has to decide what evidence is reliable.</p><p>Someone still has to decide how conflicting studies should be interpreted.</p><p>Someone still has to decide when uncertainty should be made explicit.</p><h2>The Future</h2><p>The future of these organizations, like Up-To-Date and EB Medicine, will probably depend on how they define their own value. If they define themselves as article publishers, they will face increasing pressure. If they define themselves as trusted evidence institutions, their role may become more important.</p><p>AI can help deliver their knowledge more effectively. It can make their content easier to search, easier to personalize, and easier to apply at the bedside. But the core value is not the chatbot. The core value is the editorial process behind the chatbot. That is the part physicians should care about.</p><ul><li><p>Who reviewed the evidence?</p></li><li><p>How was it selected?</p></li><li><p>How were conflicting studies handled?</p></li><li><p>What was excluded?</p></li><li><p>How often is the recommendation updated?</p></li><li><p>What level of confidence supports the answer?</p></li><li><p>When does the system refuse to answer?</p></li></ul><p>Those questions matter far more than whether the interface looks modern.</p><h2>Final Thoughts</h2><p>AI will make medical summaries abundant. That does not make expert medical curation obsolete. It may make expert curation more important.</p><p>The future of medical knowledge will be defined by which systems can earn trust. That requires more than speed. It requires evidence appraisal, clinical judgment, transparency, accountability, and humility.</p><p>In medicine, the best answer is sometimes a confident recommendation,  a cautious recommendation, or no recommendation at all. As AI becomes more capable, physicians should pay close attention to the systems that know when to pause.</p><p>In an age when every AI can generate a summary, the real value of human-curated medical knowledge may be its ability to decide which answers deserve to exist.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[When Clinical AI Meets Independent Evaluation]]></title><description><![CDATA[Real-World Testing Shows a Different Picture]]></description><link>https://ashooreview.com/p/when-clinical-ai-meets-independent</link><guid isPermaLink="false">https://ashooreview.com/p/when-clinical-ai-meets-independent</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Sun, 14 Jun 2026 19:05:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6Cs6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>An <a href="https://www.nature.com/articles/s41591-026-04431-5">NYU study</a> was published last week comparing the performance of OpenEvidence, Up-To-Date AI, and Frontier LLMs. Three things stood out to me from this paper:</em></p><ol><li><p><em>Frontier models (GPT, Gemini, and Claude) outperformed specialized clinical AI tools across every evaluation.</em></p></li><li><p><em>The performance gap narrowed as the testing became more clinically realistic. </em></p></li><li><p><em>The most important contribution of this paper is the creation of a benchmark built from actual physician questions asked during routine clinical care.</em></p></li></ol><p><em>One reason this paper caught my attention is that it mirrors observations from my own recent testing. In a series of evaluations, including OpenEvidence, Doximity Ask, Heidi Health, Glass Health, ChatGPT, Claude, and Gemini, I found that specialized medical AI products rarely demonstrated a clear advantage over frontier models.</em></p><p><a href="https://ashooreview.com/p/5-medical-ai-models-got-this-case">5 Medical AI Models Got This Case Wrong. Is Your Favorite One of Them?</a></p><p><a href="https://ashooreview.com/p/can-medical-ai-read-an-ecg">Can Medical AI Read an ECG? </a></p><p><a href="https://ashooreview.com/p/11-medical-ai-tools-read-these-xrays">11 Medical AI Tools Read These X-rays: Everyone Missed The Pneumothorax</a></p><p><em>Let&#8217;s get into the details of the study. </em></p><p><em>As always, if you enjoy reading Ashoo Review, subscribe and tell a friend. There&#8217;s no better reference. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Cs6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Cs6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Cs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1715923,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/202016214?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6Cs6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6Cs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2e4b55e-e584-4fe7-a625-13188480bddc_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A new Nature Medicine paper asks a question many clinicians have been wondering over the past year: <strong>Are specialized medical AI tools actually better than frontier models?</strong></p><p>The authors compared OpenEvidence and UpToDate Expert AI against GPT-5.2, Gemini 3.1 Pro, and Claude Opus 4.6 using 1,000 benchmark and 100 physician-generated clinical questions.</p><p>The frontier models won, but the more interesting story is how the margin changed for the three datasets tested.</p><h2>The Study Design</h2><p>The researchers used three different datasets. The first was MedQA, a collection of 500 USMLE-style multiple-choice questions designed to assess medical knowledge.</p><p>The second was HealthBench, a collection of 500 open-ended healthcare prompts scored against detailed evaluation rubrics.</p><p>The third was the study&#8217;s most interesting contribution: the Real Clinical Queries benchmark, or RCQ. For RCQ, the investigators sampled 100 de-identified physician questions from NYU Langone&#8217;s HIPAA-compliant GPT environment. The responses were then reviewed by blinded clinicians who rated correctness, completeness, safety, and clarity.</p><p>Each dataset is asking a different question.</p><ul><li><p>MedQA asks whether a model can answer a medical exam question.</p></li><li><p>HealthBench asks whether a model can satisfy a detailed rubric.</p></li><li><p>RCQ asks whether a physician would find the answer useful.</p></li></ul><h2>A Curious Pattern Emerged</h2><p>The frontier models outperformed the specialized clinical tools across all three evaluations. That part is easy to summarize. What caught my attention was something else.</p><p>The performance gap became smaller as the evaluation became more clinically realistic.</p><p><strong>On HealthBench, the separation was dramatic.</strong></p><ul><li><p>GPT-5.2 scored 88.0%</p></li><li><p>OpenEvidence scored 62.6%</p></li><li><p>UpToDate scored 61.3%</p></li></ul><p>Looking only at those numbers, one could conclude that the frontier models were operating in an entirely different league.</p><p><strong>MedQA told a different story.</strong></p><ul><li><p>Gemini scored 97.4%.</p></li><li><p>OpenEvidence scored 89.6%.</p></li><li><p>UpToDate scored 88.4%.</p></li></ul><p>The frontier models still led, but the gap was considerably smaller.</p><p><strong>Then came the RCQ benchmark.</strong></p><p>Here, the frontier models again formed the top tier, with Gemini, GPT-5.2, and Claude receiving the highest clinician ratings. But the differences were narrower. </p><p>On a four-point scale</p><ul><li><p>Gemini averaged 3.62</p></li><li><p>GPT 3.54, Claude 3.52</p></li><li><p>OpenEvidence 3.24</p></li><li><p>UpToDate 3.17.</p></li></ul><p>The superiority was statistically significant, but all of the systems generally received favorable ratings. That&#8217;s what makes the RCQ findings so interesting. If you only looked at HealthBench, you might conclude that the frontier models were vastly superior. The real-world physician evaluations tell a more nuanced story. Clinicians still preferred Gemini, GPT, and Claude, but OpenEvidence and UpToDate were generally producing acceptable answers as well.</p><p>In other words, the ranking remained the same, but the practical distance between the systems became smaller once the evaluation moved closer to actual clinical use.</p><p>That matters. This paper doesn&#8217;t tell us that specialized medical AI tools are failing. It&#8217;s telling us that specialized medical AI tools did not demonstrate a meaningful advantage over frontier models.</p><h2>Are We Measuring Medicine or Benchmark Performance?</h2><p>I suspect many readers will focus on who won. But the more interesting question may be why the margin changed between the models.</p><p>As AI systems improve, benchmark leaderboards may exaggerate differences that become less noticeable during day-to-day clinical use. A model can be significantly better at satisfying a rubric while being only modestly better when a physician evaluates the final answer.</p><p>That does not make benchmarks unimportant. It does suggest that real-world evaluation deserves more attention.</p><p>The RCQ dataset is arguably the strongest part of the paper because it moves the discussion closer to actual clinical practice.</p><h2>An Unexpected Finding in the Methods</h2><p>One detail that surprised me was buried in the Methods section. The authors built their real-world benchmark by sampling 100 de-identified physician questions from NYU Langone&#8217;s HIPAA-compliant GPT environment.</p><p>To do that, those interactions had to be recorded and retained somewhere. Researchers were then able to access those logs and use them to create the benchmark.</p><p>The paper doesn&#8217;t tell us exactly what was stored or for how long, but it does provide evidence that at least some health systems are monitoring and reviewing how clinicians use AI in practice.</p><p>That struck me as noteworthy. Much of the public conversation around healthcare AI focuses on model performance.</p><p>This paper quietly reveals that large health systems are beginning to accumulate enough real-world AI usage data to study clinician behavior, evaluate tools, and build institution-specific benchmarks.</p><p>That may become increasingly important as AI moves from experimentation into routine clinical workflows.</p><h2>What This Means for Clinical AI</h2><p>The paper raises a difficult question for the growing number of companies building clinician-focused AI products. <strong>What exactly is the advantage being offered?</strong></p><p>For years, the assumption has been that medicine requires specialized systems trained, tuned, or wrapped specifically for healthcare. That assumption seems reasonable. Yet in this study, OpenEvidence and UpToDate Expert AI did not outperform GPT, Gemini, or Claude. OpenEvidence is particularly interesting because it has become one of the most recognizable names in clinical AI. </p><p>That doesn&#8217;t mean specialized medical AI has no value. Clinical workflows involve far more than answer generation. Citation quality, medical content licensing,  governance, enterprise support, and workflow integration matter.</p><p>Those factors may ultimately prove more important than small differences in answer quality. Still, this paper suggests that specialization alone is no longer enough to assume better performance.</p><h2>Looking Ahead</h2><p>The authors showed that real physician questions can be collected, de-identified, reviewed by blinded clinicians, and used to compare AI systems. Medical AI needs more independent evaluation and fewer marketing claims.</p><p>The future of AI assessment will likely involve real workflows, real users, and real clinical questions rather than relying exclusively on public benchmarks.</p><h2>OpenEvidence Responds</h2><p>On June 14th, 2026, OpenEvidence publicly challenged the study&#8217;s conclusions and methodology on X.com. </p><p>The company&#8217;s critique focused on three areas.</p><ol><li><p>Benchmark contamination. OpenEvidence argues that public datasets such as MedQA have likely been seen by modern frontier models during training, making them a poor measure of real-world performance. - I agree. </p></li><li><p>HealthBench. The company notes that HealthBench was created by OpenAI and argues that the benchmark rewards stylistic choices that may not reflect meaningful clinical quality. - Likely true. </p></li><li><p>The RCQ dataset itself. OpenEvidence points out that the physician-query dataset is not publicly available and that limited information is provided regarding question selection, reviewer selection, and dataset construction. The company also notes that the RCQ evaluation was added after peer reviewers criticized the original submission for lacking stronger real-world grounding. - This is valid, but not unusual. As soon as a valid medical dataset is publicly released, it becomes fodder for frontier LLMs to use for training. So it makes sense to keep the content private. </p></li></ol><p>These criticisms are worth considering. At the same time, OpenEvidence&#8217;s response highlights an interesting point of agreement.</p><p>Both sides appear to believe that benchmark performance is insufficient. The company argues that clinical AI should be evaluated using real-world clinical workflows and meaningful clinical outcomes rather than benchmark leaderboards. </p><p>The disagreement is not whether real-world evaluation matters. The disagreement is whether this particular real-world evaluation is convincing. That question will likely require additional independent studies from other health systems to answer.</p><h2>Final Thoughts</h2><p>The publication of this paper and the rapid response from OpenEvidence highlight how quickly the conversation around clinical AI is evolving.</p><p>Both perspectives contain important truths. Five years from now, few people will remember which model topped the leaderboard in this paper. The more durable contribution may be the demonstration that clinical AI can be evaluated using real physician questions and blinded clinician review. At the same time, the questions raised about benchmark contamination, transparency, and reproducibility deserve serious consideration.</p><p>Clinicians do not need another leaderboard. We need evidence. The debate this paper has already generated may prove just as valuable.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Hidden Medical Record]]></title><description><![CDATA[When Does AI Memory Become A Medical Record?]]></description><link>https://ashooreview.com/p/the-hidden-medical-record</link><guid isPermaLink="false">https://ashooreview.com/p/the-hidden-medical-record</guid><dc:creator><![CDATA[Sam Ashoo, MD]]></dc:creator><pubDate>Fri, 12 Jun 2026 13:06:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CYMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>In this article, I&#8217;m looking at the latest feature from some of the most popular medical AI models&#8230; persistent patient memory. It&#8217;s a feature that seems super helpful, but is it creating a new legal challenge? </em></p><p><em>As always, if you enjoy reading this newsletter, consider subscribing and telling a friend. </em></p><p><em>Sam</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ashooreview.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CYMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CYMO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CYMO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1620657,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ashooreview.com/i/201685066?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CYMO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!CYMO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aa49440-f075-4bf0-b421-ccad4974672a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the last several years, healthcare has undergone a remarkable shift in transparency. Not long ago, patients waited days or weeks to receive laboratory results, imaging reports, pathology findings, and physician notes. Some health systems intentionally delayed access to information until a physician could review it first. Others required patients to submit formal records requests to obtain information that already existed electronically.</p><p>The 21st Century Cures Act and subsequent Information Blocking regulations accelerated a different vision of healthcare. The guiding principle became increasingly clear: if patient information exists electronically, patients should  have access to it.</p><p>Healthcare spent years debating how quickly information should be released. We may soon be debating something very similar. What happens when information influencing clinical decisions is created not by a physician, laboratory, or radiologist, but by an AI system?</p><h2>From Documentation to Memory</h2><p>Ambient scribes listen to patient encounters, generate notes, and reduce clerical burden. Whether one uses Heidi, Glass, Abridge, Suki, or another platform, the core value proposition is largely the same: document what happens during the encounter.</p><p>The next generation of tools is beginning to do something different. Many AI platforms now maintain context across encounters, synthesize information from multiple visits, and generate longitudinal patient summaries. OpenEvidence can associate patient-specific searches and information with an individual patient. Heidi and Glass can pull together information spanning multiple encounters. Several platforms can generate summaries that span months or years of clinical history.</p><p>These capabilities are often described as contextual awareness, patient memory, longitudinal synthesis, or pre-visit intelligence. Whatever terminology is used, the underlying shift is significant. The industry is moving from AI that documents encounters to AI that remembers patients.</p><h2>When Does Memory Become a Record?</h2><p>At first glance, this seems like a distinction without a difference. After all, physicians have always reviewed prior notes, laboratory results, imaging studies, and discharge summaries. AI simply makes that process faster. But there is an important progression worth examining.</p><p>At the most basic level, an AI system retrieves information. &#8220;Show me the last three notes.&#8221; Few would view that as creating a new medical record.</p><p>The next level is summarization. &#8220;Summarize the last three notes.&#8221; Again, the system is organizing information that already exists.</p><p>Then comes another level entirely as the AI prompts the physician with &#8220;<em><strong>This patient demonstrates progressive cognitive decline and increasing medication nonadherence</strong></em>.&#8221;  Now the AI has created a patient-specific conclusion that may influence future clinical decisions.</p><p>At that point, the system is doing more than retrieving information. It is generating and retaining patient-specific knowledge. If clinicians rely on that information, what exactly is it?</p><h2>A Possible Future</h2><p>Imagine opening a patient&#8217;s chart five years from now. Before you review a single note, an AI-generated summary appears:</p><p><strong>Longitudinal Patient Summary</strong></p><ul><li><p>Progressive decline in renal function over two years</p></li><li><p>Multiple episodes of medication nonadherence</p></li><li><p>Increasing emergency department utilization</p></li><li><p>Missed specialist referrals</p></li><li><p>High likelihood of care fragmentation</p></li></ul><p>The summary immediately shapes your thinking. You order additional testing. You spend more time discussing medication adherence. You prioritize care coordination. The AI-generated summary influenced your clinical decision-making within seconds.</p><ul><li><p>Yet no physician wrote that summary.</p></li><li><p>No laboratory generated it.</p></li><li><p>No radiologist signed it.</p></li><li><p>No individual encounter contains it.</p></li></ul><p>The information was synthesized by software and retained over time. Is that simply a software feature? Or is it more like a clinical record?</p><h2>The Legal Framework Was Built for a Different World</h2><p>Current law does not provide a clear answer. HIPAA provides patients with the right to access protected health information. The regulation states that individuals have a right to &#8220;inspect and obtain a copy of protected health information about the individual in a designated record set.&#8221;</p><p>The key phrase is <em>designated record set</em>. The phrase encompasses all records used to make medical decisions about individuals. Most clinicians intuitively understand what belongs in the medical record when information originates from a physician, laboratory, radiologist, or pharmacist. The answer becomes less obvious when information is generated by an AI system and retained across encounters.</p><p>The Cures Act and Information Blocking regulations add another dimension. The Information Blocking Rule defines information blocking as a practice that is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information. Yet current AI systems do not provide patient portal access or a mechanism for patients to view their own information. </p><p>Federal policy has been moving steadily toward greater transparency and fewer barriers to information access. Yet neither HIPAA nor the Cures Act was written for a world in which software could develop and retain its own understanding of a patient over time.</p><p>If a physician routinely relies on an AI-generated patient summary, should patients be able to access it? Is that summary part of the designated record set?  These are the questions the law will have to answer soon.</p><h2>The Governance Challenge</h2><p>The regulatory questions may ultimately prove easier than the governance questions.</p><p>Consider a few practical issues.</p><ul><li><p>Who owns AI-generated patient memory?</p></li><li><p>Who is responsible for correcting errors?</p></li><li><p>How long should it be retained?</p></li><li><p>What happens when an AI-generated summary conflicts with the underlying chart?</p></li><li><p>Should these systems maintain audit trails?</p></li><li><p>Should patients be informed that longitudinal AI memory exists?</p></li><li><p>Should patients have access to it?</p></li><li><p>Could it become discoverable during litigation?</p></li></ul><p>Unlike a lab result, which is binary and objective, AI-synthesized 'memory' is interpretative. If an AI incorrectly tags a patient as 'medication nonadherent' based on a misinterpreted data point, that 'memory' can color every future clinical interaction. We don&#8217;t have a clear mechanism for patients to challenge or 'edit' these persistent algorithmic conclusions, raising a critical question: how do we protect patients from automated bias that the legal system has not yet classified as part of the medical record?</p><p>Health systems are increasingly developing governance frameworks for AI-generated documentation. Far fewer appear to be discussing governance frameworks for AI-generated memory, but the distinction is important. </p><p>Documentation captures what happened. Memory influences what happens next.</p><h2>The Hidden Medical Record</h2><p>AI may be creating a new category of information. Patient-specific knowledge generated by software, retained across encounters, and used to inform future care.</p><p>That information lives somewhere. It may influence clinical decisions. It may persist for years. In many cases, patients may not know it exists.</p><p>Healthcare is approaching a new and largely unexamined boundary. For the past decade, we debated who should have access to the medical record. The next decade may be spent defining what the medical record actually is.</p><p>Before deploying AI memory systems at scale, health systems should begin asking a few questions:</p><ul><li><p>Is AI-generated patient memory part of the medical record?</p></li><li><p>Would we be comfortable if a patient requested access to it?</p></li><li><p>Would we be comfortable if it became discoverable in litigation?</p></li><li><p>Do we even know what our AI systems are storing, synthesizing, and retaining?</p></li></ul><p>The answers may shape the next chapter of healthcare transparency.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ashooreview.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ashoo Review: AI in Medicine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item></channel></rss>