Find and read
Search a patient, open an encounter, pull an invoice, read today’s queue, list appointments. Read-only questions are answered straight away.
Platform · AI Copilot
Every clinic system now claims AI. The question a clinic should actually ask is narrower: what is it allowed to read, what can it change without me, and what happens if it is wrong. This page answers those three first.
Dr AMove Patient B’s follow-up to next Thursday afternoon
Questions are answered straight away. Anything that changes a record stops here, showing exactly what it would change, until a person decides. Either decision is logged.
The copilot
The copilot is not a text box bolted onto the side. It reaches the same records your staff do — through the same permission checks — and it can act, once someone says yes.
Search a patient, open an encounter, pull an invoice, read today’s queue, list appointments. Read-only questions are answered straight away.
A SOAP note from the consultation, a remark for a medical certificate, a summary of a patient’s history. Always as a draft, always editable, never saved on its own.
Book, reschedule or cancel an appointment; add someone to the queue; correct patient details; send a reminder. Anything that writes is held for a human yes.
Each tool re-checks the signed-in user’s own permissions. A front-desk account asking the copilot for clinical notes gets the same refusal it would get from the interface.
Every question it answers is limited to your clinic’s records. No wording of a request can reach another clinic’s data, because the system never hands it any.
When it tells you the last HbA1c, it tells you which encounter that came from — so you can check it in one click instead of trusting it.
The part that matters
These are not settings we hope you turn on. They are how the thing is built.
Anything that would change a record does not happen on its own. It comes back as a proposal showing exactly what would change, and waits for a person to approve or reject it. That decision is recorded too.
NRIC, phone numbers and account numbers are redacted before the request leaves for the model — S••••567G, not the real thing. The clinic still sees the full value; the model does not.
Who asked, what the AI looked up or proposed, what came back, and whether it was approved. The AI is in the same audit log as everything else.
Each AI model is recorded with where it runs and whether it is cleared for health information. Anything that touches patient data only uses models that are.
If you want to turn the copilot off for a role, or entirely, that is a permission — not a support request.
In the room
The typing after each consultation is the time doctors most want back.
Dictate the consultation and it comes back structured into history, examination and plan — as a draft on screen, before anything is saved.
The write-up is tuned to each doctor, so the note reads like the doctor who dictated it rather than like a template.
ICD-10 and SNOMED candidates are suggested from what was written. Nothing is submitted on a suggestion alone — the doctor confirms.
If dictation is unavailable, the encounter is an ordinary typed note. No part of the clinical workflow depends on the model answering.
Before they arrive
Most patient WhatsApp messages are four questions: are you open, can I get an appointment, how much is it, do I need a referral. Those do not need a human at 11pm — but the fifth one does.
Patient · 23:41
Any slots tomorrow morning?
AI front desk · 23:41
Tomorrow 9:20am and 10:40am are open. Shall I take one?
Patient · 23:43
Can the doctor tell me what last week’s blood test means?
clinical question — agent has no clinical tools
It can book a slot. It cannot interpret a result: it has no access to the record, so it hands over.
Are you open, can I get an appointment, how much is it, do I need a referral: answered from your clinic’s own information, not from the open internet.
It can only offer the slots and services your clinic has set up. What it may book is your configuration, not its improvisation.
Anything clinical, anything angry, anything it is unsure about goes to a human with the thread attached. Handing over is a tool it is expected to use, not a failure.
Messages that try to trick it into ignoring its rules are caught on the way in, and its replies are checked on the way out.
The agent has no clinical tools. It cannot read a diagnosis to a patient because it cannot reach one.
Staff see the AI’s replies in the same shared inbox as their own, attributed to the agent — not as a black box running somewhere else.
Paper in, data out
Paper that arrives at the counter is read into the right fields, and a person confirms it.
An NRIC or passport photographed at the counter is parsed into the registration form for the front desk to confirm.
Upload a discharge summary or an external report and the relevant history is surfaced into the encounter instead of retyped.
Claim paperwork is extracted into the fields the payer expects, with the extraction shown next to the source for checking.
Extraction proposes; a person accepts. The pattern is the same everywhere the model touches a record.
How we know
Every change to the AI is checked against a fixed set of clinic situations before it reaches you, and the result decides whether it ships.
Each thing the AI does is checked against a set of real-world cases with known right answers, every time, rather than tried once by hand.
Each answer is marked against written criteria and gets a pass, a score and notes, so if it gets worse, the score shows it.
Each version of the AI’s instructions is recorded with every answer it gives, so any change in behaviour can be traced back to the change that caused it.
Usage is tracked per clinic, so AI spend is a line you can see rather than a surprise attached to a subscription.
Questions
No. Patient data is sent only to serve the request in front of you, identifiers are masked before it leaves, and it is not contributed to model training.
No. Anything that writes is held as a proposed action with its exact arguments until a person approves it, and both the proposal and the decision are logged.
Yes — per role or entirely. Copilot access is an ordinary permission, so the same screen that controls who can void an invoice controls who can use the AI.
It drafts and proposes; a clinician decides. That is the design, not a disclaimer — which is also why every answer points at the record it came from.
Each AI model is recorded with where it runs and whether it is cleared for health information, and anything touching patient data only uses models that are. We will walk through the current setup on the call rather than print something here that changes.
Next step
Thirty minutes, screen shared, using your workflow — your busiest hour, your payer mix, your claim types. We will tell you plainly if we are the wrong fit.
No slide deck. No obligation.