New noteWhat changes on January 1, 2027
Solidare AI — Technology built on solidarity

Industries · Practice managers, physician-owners and compliance officers.

No BAA, no PHI, no exceptions.

Your physicians want a scribe. Your budget is about $500 a provider. Prior auth is 39 requests a week per physician. And a scribe that charts the wrong patient is a clinical event, not a bug. Set it, but check it.

WHAT YOU NEED TO HAVE READY

  • The AI vendor checklist your compliance officer will sign — BAA first
  • The note-review step for ambient scribes
  • The paragraph that adds AI to your Security Rule risk analysis
  • Which prior-auth steps an agent may submit, and which a human signs
  • A two-doctor pilot with a measurement

WHO WILL ASK FOR IT

  • OCR
  • The compliance officer
  • The malpractice carrier
  • The medical board
  • Payers

HERE IT IS IN 3–4 WEEKS

Privacy & Security Review

3–4 weeks

A BAA-first vendor checklist, the scribe review step, the risk-analysis paragraph, and a two-doctor pilot plan.

Start with the Privacy & Security Review

What you hold

  • Patient records and PHI
  • Claims, prior authorizations and denials
  • Billing and revenue-cycle data
  • Protocols, templates and order sets
  • Employee and credentialing records

What keeps you up at night

  • PHI in a tool that never signed a BAA
  • An ambient scribe inserting the wrong symptom or the wrong patient
  • Payer AI increasing denials with nobody tracking it
  • Physician burnout driving unapproved tools
  • An EHR AI feature switched on by an update

Where AI helps first

  • An ambient scribe with a note-review step and a BAA
  • Prior-auth and eligibility agents that prepare; a human signs
  • Denial-pattern sorting for the billing team
  • Patient-communication drafts reviewed before sending
  • A policy the compliance officer and the carrier can both read

How we usually start

Three ways in for clinics.

033–4 weeks

Privacy & Security Review

Find where data is already flowing into AI tools, review who handles it, and fix the biggest exposures first.

  • Data map and shadow-AI inventory
  • Vendor data-handling review with scorecards
  • Private-versus-public decision by class of data
What you get →
023 weeks

AI Use Policy Sprint

A policy written for the people who will follow it, with the structure behind it to satisfy a regulator, an auditor or a trustee.

  • AI use policy and one-page do's-and-don'ts card
  • Approval path and intake form for new tools
  • Human-review rule for consequential decisions
What you get →
056–8 weeks

Agent Pilot

One agent, one workflow, in production, with the autonomy level you chose, approval gates, logs and an off switch.

  • Scoped workflow and autonomy level agreed in writing
  • Working agent in production with approval gates and logging
  • Activity report your team can read
What you get →

Reading for clinics

Procurement · June 30, 2026

Ten questions to ask any AI vendor before you sign

The demo will be good. The contract is where the risk lives. Send these ten questions in writing and read the answers before the second call.

Read the note · 3 min

Privacy · August 18, 2026

Five ways member data leaks into public chatbots

It is rarely a hack. It is a helpful person with a deadline and a free tool. Here are the five routes we find in almost every organization, and the fix for each.

Read the note · 3 min

The standard we work to

  • Data that names a person stays inside your environment
  • A person approves anything that touches a person, a record or a dollar
  • Every AI use disclosed in plain language to the people it affects
  • Aligned to NIST AI RMF and designed to ISO/IEC 42001 structure; threat-modeled to OWASP and MITRE ATLAS
  • You own what we build and can leave with it
The seven commitments in full →

Next step

Tell us what you hold and who you serve.

We'll tell you what AI should and shouldn't touch, and what to do first — in one conversation.

NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI