A standard
The AI Standard
Five rules for putting AI into a practice without automating waste, losing the human moments, or creating a compliance problem.
I sell AI systems to functional medicine practices, and the most common thing I do on a first call is talk someone out of buying one. Not because the tools are bad. Because the task they want to automate should not exist, or is not their real constraint, or is the one thing in the practice that should stay human.
A lever amplifies whatever you attach it to. Attach it to the wrong point and it amplifies waste with tremendous efficiency. So before any tool goes into any practice I work with, it clears these five rules, in order. A task that fails a rule does not get automated until the failure is fixed.
This is the whole standard. No gate, no call required, nothing held back. Run it yourself on the next thing you are tempted to buy.
Prove the work should exist before you automate it.
Automation multiplies whatever it touches. Point it at waste and you get faster waste.
Before any tool, run the task through these five questions, in order. Write the answers down. If you cannot answer one, that is your answer.
- Does this exist on purpose? Can you say in one sentence what it produces? "We have always done it this way" is not an answer, it is a habit you are about to make permanent.
- If it vanished tomorrow, would a patient notice? Follow the process to the person at the end of it. If no patient is better off, delete it instead. Deletion is free and instant. Automation is neither.
- Is this the constraint, or is it just annoying? Your bottleneck is the step where a two-times improvement makes everything downstream better. The task that irritates you daily is rarely that step.
- Would a simple fix beat the smart one? A checklist beats a chatbot more often than the people selling chatbots admit. Try the dumb fix first. If it works, you just saved a subscription.
- Can you name the number that moves in 30 days? New patient calls. Show rate. Time from inquiry to booked. If you cannot name it, you cannot tell success from motion, and you will pay for motion indefinitely.
Anything that survives all five is a real candidate. Most tasks do not survive the first pass. That is the rule working, not the rule being difficult.
Automate the script. Keep the judgment.
The fear that AI makes a practice cold is legitimate. The fix is a line, not an abstention.
The test: would a smart, caring front desk person handle this the same way every time, working from a script? If yes, automate it. If the right answer changes depending on who is asking and why, it stays with you.
- Automate: appointment reminders and confirmations, intake data collection, the same protocol questions you answer every week, scheduling and rescheduling, routine result delivery with standard reference ranges, chasing missed forms.
- Keep human: interpreting an ambiguous result against a specific history, delivering a hard finding, any conversation where the patient is frightened, adjusting a plan that is not working, and the visit itself.
The line is not human versus machine. It is whether the task requires judgment. Everything that does not require judgment is currently stealing time from everything that does.
Classify by PHI before any tool touches the task.
One legitimate risk should not become a blanket ban on everything with AI in the name.
Most of what a practice wants AI for (content, visibility, message templates) never touches protected health information at all. The work that does touch it requires care, not avoidance. Sort every task before you adopt any tool:
- Does this task require a specific patient's identifying or health information? Writing about a condition in general does not. Summarizing a chart does.
- If no: you are in low-risk territory. Normal judgment applies. Do not paste anything you would not want public, but this is not a PHI event.
- If yes: two follow-ups before you proceed. Has this vendor signed a Business Associate Agreement with your practice? Is the tool configured the way that agreement requires, and not just signed once and then used carelessly?
- If either follow-up is no: do not put the information into that tool. Either remove the identifying details first, or use a tool where both boxes are genuinely checked.
- If both are yes: you are on a defensible path, and you should still confirm the specific use with your own compliance advisor before scaling it across the practice.
This is a framework for thinking clearly, not legal advice. I am not a lawyer and I am not your compliance officer. Confirm anything in this category with a qualified HIPAA advisor for your practice, your vendors, and your state.
Automated is not anonymous.
A system can send a message and still sound like you. Most practices give this away for free.
A reminder written in your voice, using the language you actually use about a protocol, reads as personal even though software sent it. A generic "Reminder: you have an appointment" reads as institutional even if a human typed it by hand. Voice matters more than who pressed send.
- Write every automated message once, in your own words, the way you would say it in the room.
- Never ship a vendor's default template. The default is written to work for a dental office, a chiropractor, and you, which means it works for none of you.
- Re-read the automated messages every quarter. If patients are replying to them with confusion, the copy is wrong, not the channel.
The impersonal thing in most practices is not the software. It is voicemail, a two-day reply, and a doctor too tired by Thursday to be present. Automation done properly removes those.
Instrument it, review at 90 days, and kill what did not move.
The number you named in Rule 1 is not a formality. It is the exit criterion.
Most practices install a tool, never measure it, and keep paying for it out of guilt and inertia. An engineer would not run a system with no monitoring. Neither should a practice.
- Record the baseline before the tool goes in. You cannot measure an improvement against a number you never wrote down.
- Put a 90-day review on the calendar the same day you deploy. Not a vague intention. A dated appointment.
- At the review, ask one question: did the number from Rule 1 move? If yes, keep it and go find the next constraint. If no, turn it off.
- Cancel the subscription the same day you decide. A tool you have decided is not working but keep paying for is a tax on your own indecision.
This is the rule almost nobody runs, which is why practices accumulate software instead of leverage.
What this standard is not
It is not legal or compliance advice. Rule 3 in particular is a way to think clearly about where risk actually lives, not a substitute for a conversation with a qualified HIPAA advisor about your specific practice and vendors. Have that conversation before you scale anything that touches patient information.
It is also not a tool list. Tools change every quarter. These rules are the part that does not, which is why they are worth writing down and the tool comparison is not.
The longer arguments behind each rule
Each rule here is the compressed version. If you want the full reasoning:
- Rule 1: AI Will Not Save Your Practice
- Rule 2: Will AI Make My Practice Feel Impersonal?
- Rule 3: "AI Is Illegal Under HIPAA" Is Not True
- The whole worldview underneath: The Leverage Doctrine
Get the thinking as it publishes
AI leverage, business systems, and the doctrine, one essay at a time. No pitches. Unsubscribe anytime.
Run the standard yourself. If you would rather have the systems built to it, work with me →