Field notes. John Arndt, Soxoa. Published .
Practice administrators have watched the AI conversation run for two years now, and most of the ones I talk to are still waiting for something that fits their actual situation. Not an enterprise EHR integration. Not diagnostic AI that needs clinical validation before anyone can touch it. Something that stops a six-provider family practice from spending its week on administrative work that does not require a medical degree.
That is where the opportunity sits, and it is narrower and more boring than the conference-stage version. What follows is how I would decide which of these is worth doing, which is worth doing later, and which is not worth doing at all.
Start with the HIPAA reality
Before anything else: AI in a medical practice is subject to HIPAA. Any system handling patient data has to run on compliant infrastructure, which means Business Associate Agreements with every vendor in the chain, data handling controls, and audit logging. That determination is not a vendor’s to make and it is not mine. Your privacy officer, your counsel, and your compliance advisor own it, and they should approve the architecture before it sees a record.
The useful part is that the workflows eating the most staff time frequently do not require protected health information to automate. Scheduling data, template documents, payer reference criteria, and internal communications carry a lot of the drag and much less of the exposure.
So the sequence is PHI-adjacent work first, then PHI-involved work once the infrastructure is confirmed and the agreements are signed. Running it the other way round means retrofitting compliance into a live system, which is the expensive version of the same project.
Where the math usually works: prior authorization
Prior authorization is the largest administrative burden in most of the practices that ask me about this. Staff time goes into initiating the request, and then into the follow-up calls, status checks, peer-to-peer reviews, and appeals sitting behind it, which is the part nobody counts.
Do that arithmetic with your own numbers rather than anyone’s benchmark. Count last month’s submissions, have two staff members time themselves initiating five requests each, multiply it out, then add the follow-up. That figure is the ceiling on what automating this can return, and it is worth knowing before anybody quotes you anything.
The mechanism is straightforward. An assisted workflow reads the diagnosis codes, the requested procedure, and the payer’s published criteria, pre-fills the submission, drafts the justification narrative from templated inputs, and routes it to the right payer portal. A medical assistant initiates, reviews, and submits. Clinical justification stays a clinical statement, reviewed by the person whose name goes on it.
The reason this workflow usually comes first is that it repeats constantly, its inputs are structured, and there is no clinical judgment inside the assembly work. If your own arithmetic says the volume is not there, the answer is to leave it manual and look at something else.
Patient intake and new patient onboarding
Every practice has a version of this one. New patients call to schedule, get emailed a PDF packet, print it, fill it in by hand, bring it to the appointment, and then a front desk person retypes all of it into the EHR while the patient waits.
The fix is not complicated. A digital intake form with field logic, connected to scheduling, pre-populates what the practice already learned on the scheduling call. The patient completes it on a phone before the visit. The data maps into the EHR. Front desk staff review for completeness instead of typing, which is also where the data entry errors were coming from.
Measure the current version before you replace it. Time the retyping for one week and count your new patients over the same week. Whether this is worth building depends on your new-patient volume, not on anything I can tell you in an article.
Care gap outreach and appointment follow-up
Care gap closure is a quality metric under value-based arrangements and one of the most manual workflows in primary care. Identifying who is overdue for a preventive screening, drafting the outreach, and tracking responses either needs a dedicated coordinator or happens inconsistently.
An assisted version pulls the list from the EHR or care management platform, segments by condition and gap type, drafts the outreach, and tracks responses. The care coordinator reviews and approves a batch in one sitting rather than composing messages one at a time across a day. Nothing goes out unreviewed, and the review is the point, because the coordinator is the person who knows which patient should not receive a templated message this month.
What this earns is upkeep rather than judgment. It decides nothing clinical. It makes sure the relationships that are supposed to be maintained on a schedule actually are.
What is probably not worth it yet
Ambient clinical documentation, the tools that listen to a visit and generate the note, gets most of the attention. For a clinician carrying a full daily panel the time saving is real. It also sits downstream of the administrative friction, so a practice that has not sorted out intake, prior auth, and follow-up tends to hand the gain back on either side of the visit.
My read is that ambient documentation pays off best once the administrative workflows around the visit are already handled, and that buying it first is optimizing the wrong end of the day. That is an opinion, and your own before-and-after timing is better evidence than my opinion.
Diagnostic AI is a different category again. The liability, the validation requirements, the payer policies around AI-assisted diagnosis, and the clinical workflow integration all make it a later decision for a practice of this size. Not never. Not before the administrative work is handled, and not without your own clinical leadership driving it.
Multi-location groups have a different first problem
A multi-location group faces the same workflows repeated across sites, run slightly differently at each one. Automation that ignores the variation fails at the outlier locations, which are usually also the ones that complain loudest.
So the order is standardization first, automation second. Before deploying assisted insurance verification across a dozen sites, the practice management team defines the standard verification process, confirms it works at every location, and then automates the standard. Automating the variation produces automated chaos.
Eligibility and insurance verification is usually the strongest candidate in a high-volume group, because it is frequent, structured, and checkable. Real-time eligibility APIs handle the straightforward cases and the front desk keeps the exceptions. Time your own current verification process and let that number decide it.
How to scope your first project
Pick one process. It should meet three tests: it happens at least weekly, its inputs and outputs are predictable, and it does not require clinical judgment in the middle of it. Prior auth, intake, eligibility verification, and care gap outreach qualify. Diagnostic support and treatment planning do not.
If you would rather not run that alone, an AI Build Sprint is the fixed-scope version: one to three workflows taken from mapped to operating in your own environment, evaluated on real examples, with a human review path and written operating notes. A stop decision is a valid outcome of it.
Scope tightly
Write down exactly what the system handles and what it does not. Scope creep in healthcare projects usually arrives as edge cases that are a small share of the volume. Build for the ordinary cases, then decide whether the exceptions are worth adding.
Confirm the compliance posture first
BAAs with vendors, data classification, audit logging, named sign-off from the people responsible for it. An hour with your compliance advisor before the build is far cheaper than a retrofit after go-live.
Name the reviewer
Anything reaching a patient, a payer, or the permanent record gets a named human reviewer, chosen before the build starts, with a deadline and a way to reject.
Set the stop condition
Decide in advance what result would make you abandon the project, and then hold to it. An evaluation that cannot come back negative was not an evaluation.
Measure against the before
You timed the manual version. Time the new one on the same work, with the same staff, and compare the two rather than comparing either to a brochure.
Getting an honest read
I would rather tell a practice that a workflow should stay manual than build something its staff route around within a month. Scope and price are agreed before work begins, and the useful outcome of a first conversation is often a shorter list than you walked in with.
Start with the readiness assessment: five dimensions, self-scored, it runs in your browser and your answers are not stored. Schedule a strategy call and bring the workflow your staff complain about most. Thirty minutes, and a straight answer about whether there is anything worth building.
Common questions
- Does using AI in a medical practice create HIPAA problems?
- Any system handling patient data has to run on HIPAA-compliant infrastructure, with Business Associate Agreements, data handling controls, and audit logging, and that determination belongs to your privacy officer, counsel, and compliance advisor rather than to a vendor. The workflows carrying the most administrative drag (scheduling data, template documents, payer reference criteria, internal communications) often do not touch PHI at all, which is why PHI-adjacent work comes first.
- What is the highest-value AI workflow for a medical practice?
- Prior authorization, usually. An assisted workflow pre-fills the submission from diagnosis codes and payer criteria and drafts the justification narrative from templated inputs, so staff initiate, review, and submit instead of assembling each request by hand. Whether it is worth building at your practice depends on your own auth volume and how long a submission takes today, so time it before anyone quotes you anything.
- Should we invest in ambient documentation or diagnostic AI?
- Usually not first. Ambient documentation pays off best after the administrative workflows around the visit are already handled, and diagnostic AI carries liability, validation, and integration complexity that make it a later-stage decision for most practices of this size.
- What does a first build cost?
- Scope and price are agreed before work begins.