Provider and Patient Portals
Most of Your AI Exposure Is in Models You Did Not Build
The Challenge
You are accountable for models you cannot inspect
Vendor AI arrived without a decision
Delegated entities run their own AI
No answer for the regulator or the board
Population effects nobody is measuring
Everything treated as one risk category
Pilots accumulate without a portfolio view
Inventory before roadmap, and the inventory is mostly other people models.
Our Approach
Governance that says yes faster than the workaround
Step 1
Step 2
Step 3
Step 4
Define the boundaries that never move. The decisions that stay human regardless of accuracy, agreed with clinical, legal and compliance leadership.
Step 5
Step 6
Step 7
Step 8
Step 9
Step 10
A stop list is as valuable as a roadmap and considerably rarer.
Capabilities
Built to be operated, not published
See the Surface
Full AI Inventory
Vendor AI Assessment
Delegated Entity Oversight
Risk Tiering
Decide and Prioritize
Portfolio Prioritization
Readiness Gates
The data, monitoring, ownership, escalation and evidence conditions a use case must satisfy before deployment.
Boundary Definition
Review Path Design
Operate and Evidence
Operating Model
Monitoring Standards
Evidence and Artifacts
AI Incident Management
What happens when a capability produces harmful output, crosses a boundary, acts on incorrect information, exposes data or behaves differently after a change.
Contract and Procurement Standards
What CaliberFocus does, and does not do.
We are not your counsel and we do not provide legal opinions on regulatory obligations. We build the inventory, the tiering, the operating model and the evidence trail, working alongside the legal and compliance leadership who own the interpretation. We will also tell you when a governance programme is being built to document a decision that has already been made, because a framework produced to justify a deployment is not governance and it will not read as governance to anyone examining it.
The Portfolio
Five verdicts, and two of them are refusals
Proceed
Prepare
Pilot
Proceed, assist only
Hold
Do not pursue
The plan will not do this. Recorded with the reasoning, so it is a decision rather than a recurring debate.
Prioritize the work AI can remove, not the decisions it can replace.
Governance
The contract is the strongest control you have over a model you cannot see
Disclosure
Validation evidence
Monitoring commitment
Population performance
Audit and inspection
Change notification
Off switch
Exit
Data provenance and permitted use
No client data training third-party models
Model and configuration versioning
Retirement as a normal outcome
Trust
Assume the question arrives with a deadline
The artifacts to hold current
- An AI register covering built, bought, embedded and delegated capabilities, with owner, tier, purpose and the decision each influences
- Tier definitions and the requirements attached to each, approved by the accountable body
- Approval records, validation evidence and monitoring results per capability, current rather than point-in-time
- The stop list, with reasoning
Security
PHI
- Encryption, access control and least privilege across model development, inference and monitoring environments
- PHI minimization in training data, prompts, inference logs and monitoring stores
- Vendor hosting, residency and subprocessor position documented per capability rather than at platform level
- A usable non-digital path that is not a deliberately degraded channel, so a portal-first strategy does not become an access barrier for the people who need access most
Oversight and accountability
- A named accountable executive for AI, and a named owner per capability distinct from the platform owner
- Clinical ownership for any capability influencing care access, with a defined route to pause it
- Compliance visibility by design, including delegated entity AI
- A defined cadence and content for what reaches the board
Operational
readiness
- The ability to pause, restrict or disable any capability, including vendor-embedded ones, without disabling the platform
- Monitoring thresholds and escalation owners set before deployment
- Incident definition and response for AI specifically, since an AI failure often presents as a pattern rather than an outage
Outcomes
Coverage, speed and what you declined
And a first roadmap that works usually has three lists rather than one: scale, where value is proven and controls are sufficient; fix before scaling, where the data, content, review or vendor controls are not ready; and do not delegate, where AI may assist the work but the authority stays with a qualified person. That distinction is what leadership can actually fund.
| Category | What we measure | Why it matters |
|---|---|---|
| Inventory coverage | Share of AI capabilities in the register, including vendor-embedded and delegated | You cannot govern what you have not found, and most of it is not yours |
| Decision speed | Time from submission to a decision, and the share receiving a conditional yes | Governance faster than the workaround is governance that gets used |
| Refusals | Capabilities placed on hold or declined, with reasoning recorded | A portfolio with no refusals has not been assessed |
| Vendor position | Agreements carrying AI disclosure, validation, monitoring and audit provisions | The only real control over a model you cannot inspect |
| Monitoring in force | Higher-tier capabilities with active monitoring, thresholds and named owners | The gap between approved and monitored is where exposure sits |
| Evidence readiness | Time to produce the register and the supporting evidence for a named capability | The measure that matters on the day it is requested |
The inventory will find AI nobody approved.
Build a governed AI roadmap for your health plan
Start with the clinical workflow, not the ambient AI platform.
Bring us a specialty or clinical setting where clinicians are spending too much time creating notes. We will assess where ambient documentation fits, what must remain clinician controlled, how it should integrate with your EHR, and how to measure whether it is actually reducing burden.
- AI Agents and Workflow Automation
- Voice and Conversational AI
- Document AI and Intelligent Processing
- Generative AI and Enterprise Copilots
- AI Strategy and Governance
- HCC and Risk Adjustment Analytics
Security & Compliance
