HEALTHCARE
CONCEPT STUDY
CASE 03
An AI agent that books appointments and shares medical records with new clinics. It saved patients hours, but it shared everything, with no end date. We audited it and redesigned consent.
AGENT
Books appointments and shares medical records
USERS
Patients and family caregivers
ENGAGEMENT
Trust Audit + UX Sprint
FOCUS
User control · Supervision · Traceability
Concept study: a composite of patterns common in consumer healthcare agents, not a client project. Scores come from our TRUST audit of the “before” state.
01 — THE PROBLEM
The agent booked appointments and sent records ahead of visits. But it shared full medical histories, kept access open forever, and left no trace of who looked.
✕
All or nothing
Patients could only share their entire history, or nothing at all.
TYPICAL USER REACTION
“The dentist didn’t need my therapy notes.”
✕
Access never ended
Once records were shared, clinics kept access with no end date.
TYPICAL USER REACTION
“Can they still see my file?”
✕
No record of who looked
Patients couldn’t see which clinic or doctor opened their records.
TYPICAL USER REACTION
“Who has seen this?”
02 — THE AUDIT
Each action was mapped to the Risk Ladder, then scored against 40 checks across the five TRUST pillars.
TRUST SCORE · BEFORE
33
Untrustworthy
Transparency
35
Reversibility
20
User control
32
Supervision
40
Traceability
38
Read the appointment calendar
L1
Reads silently and logs it
OK
Book a routine appointment
L3
Books, with no easy way to cancel
Gap
Request a prescription renewal
L4
Sends without confirming the medication
Critical gap
Share records with a new clinic
L5
Shares the full history in one tap
Critical gap
Keep a clinic’s access open
L5
Access never expires
Critical gap
CRITICAL FINDINGS
F1
U3 · User control
All-or-nothing sharing
Patients had to overshare or not share at all.
F2
R1 · Reversibility
Access with no end
Consent given once lasted forever, with no way to revoke it.
F3
TR1 · Traceability
No access history
Patients couldn’t see who had opened their records.
03 — THE REDESIGN
We redesigned consent so patients decide what is shared, for how long, and can always see who looked.
F1
Consent that shows exactly what’s shared
→ Choose which record types to include
→ Sensitive categories excluded by default
→ Plain language, not legal text
BEFORE
Health Agent
Share your records with Riverside Clinic?
Allow
Deny
AFTER
L5 · CONSENT REQUIRED
Share with Riverside Clinic
✓
Lab results (2024–2026)
✓
Current prescriptions
✕
Therapy notes: not shared
Allow access
Customize
F2
Access that ends, and can be revoked
→ Every share has an end date
→ Revoke any clinic’s access in one tap
→ A reminder before access is renewed
BEFORE
✓ Access granted
Riverside Clinic can now view your records.
AFTER
Riverside Clinic
Can see
Labs, prescriptions
Access ends
Oct 29, 2026
Access active · 30 days left
Revoke
F3
A clear history of who looked
→ Every view logged: who, what and when
→ An alert when someone new opens a record
→ Export for complaints or audits
BEFORE
Sharing history
No history available.
AFTER
Who saw my records
Riverside Clinic viewed Lab results
Today, 11:02 AM
Dr. Khan viewed Prescriptions
Yesterday, 4:18 PM
City Dental’s access ended
Sep 12 · Expired automatically
04 — THE RESULT
We re-audited the redesigned concept with the same 40-point checklist.
BEFORE
33
Untrustworthy
AFTER
89
Trusted
Transparency
35 → 88
Reversibility
20 → 86
User control
32 → 92
Supervision
40 → 90
Traceability
38 → 91
Before
After
WHAT WE’D MEASURE AFTER LAUNCH
01
Consent completion
Share of patients who finish the consent step
02
Custom sharing
How often patients adjust what’s included
03
Revocations
How often access is revoked early, and why
04
Patient confidence
Survey: “I know who can see my records”
05
Support calls
Calls and messages about who has access