Medical AI That Drafts. Clinicians Decide.

AI drafting for clinical documents and imaging reports, with a clinician approving every output

A hospital wanted AI to take the typing out of clinical documentation without letting a model sign anything. We built the drafting assistant, review flow and audit trail.

Healthcare · Medical AI

Medical AI That Drafts. Clinicians Decide.
Client
Hospital (anonymised)
Type
Clinical documentation assistant
Review model
Clinician approval on every output
Deployment
On-prem or private cloud
Stack
Python · LLM APIs · PostgreSQL · Docker

HealthcareMedical AILLMHuman-in-the-loopGDPRPython

What the hospital needed

Clinicians spent much of each shift typing discharge summaries, referral letters and imaging-report fields from information that already existed. Consumer AI tools were off the table: patient data can't leave approved systems, and every output needs a named human who signs it. We built a dedicated assistant. It gathers only the context a case needs, drafts in the hospital's own template and sends it to a review queue. Nothing leaves draft without a clinician's signature, every step is audited, and it runs on-prem or in a private cloud.

Constraints we had to design around

  • 01

    Health data under GDPR

    Special-category data means data minimisation, purpose limitation, role-based access and a clear record of processing. Nothing could be sent to a service the hospital had not approved.

  • 02

    A model must never be the author of record

    Drafts can be wrong. The workflow had to make clinician review mandatory and make it obvious which text came from the model and which from a human.

  • 03

    Hospital IT, not a greenfield

    The assistant had to read from and write back to existing hospital systems, follow their identity management and fit into how departments already work.

  • 04

    Deployment the security team can sign off

    Some hospitals will not let patient data leave the building. The architecture had to support on-prem and private-cloud installs from the same codebase.

Architecture and what we shipped

  1. 01

    Context assembly, then drafting

    For each case the system gathers only the notes, measurements and prior reports it needs, then drafts in the hospital's own template. Less data in, fewer surprises.

  2. 02

    Human-in-the-loop review queue

    Every draft lands in a queue for the responsible clinician. They edit, approve or reject. Model-generated text is highlighted until a human accepts it.

  3. 03

    Audit log on every step

    Who requested a draft, which inputs were used, which model version answered, what the clinician changed and who signed. Queryable for compliance and quality review.

  4. 04

    Access control and data handling

    Role-based access tied to the hospital's identity provider, encryption in transit and at rest, configurable retention and no training on patient data.

  5. 05

    Pluggable model layer

    The model sits behind an internal interface, so the hospital can run a self-hosted or an approved private-cloud model without changing the application.

  6. 06

    Integration with hospital systems

    Read and write-back through the interfaces hospital IT already exposes, so approved documents end up where clinicians and records staff expect them.

How it was delivered

Scoped with clinicians and hospital IT first, piloted in one department, then hardened for wider rollout.

  1. Phase 1

    Discovery and data map

    Document types, templates, data flows, access rules and deployment constraints agreed with clinicians, IT and data protection

  2. Phase 2

    Pilot

    Drafting, review queue and audit log running for one document type in one department

  3. Phase 3

    Hardening and rollout

    Integrations, role-based access, private deployment packaging and additional document types

What shipped

Production

Assistant running inside the hospital's approved environment

Human-in-the-loop

No AI output leaves draft status without clinician approval

Full audit trail

Inputs, model version, edits and sign-off logged for every document

Questions hospitals ask about medical AI

Can AI write clinical documents safely?

AI can draft them. It should not sign them. In this system the model produces a draft in the hospital's template, a clinician reviews, edits and approves it, and nothing reaches the record without that approval.

Where does patient data go in a medical AI system?

Only where the hospital approves. The application runs on-prem or in a private cloud, the model layer can be self-hosted, and only the minimum context needed for a draft is sent to the model.

How do you handle GDPR for health data in AI software?

Data minimisation, role-based access, encryption, configurable retention, no training on patient data and a complete audit log. We work with the hospital's data protection officer from discovery onwards.

Does medical AI have to replace our hospital systems?

No. This assistant reads from and writes back to existing systems through the interfaces hospital IT already provides. Clinicians keep their tools; the typing gets shorter.

How do you start a medical AI project?

With one document type in one department. We map the data and the approval flow, run a pilot, and only then scale. Book a free call and we'll scope the first pilot with a fixed price.

Clinicians should treat patients, not type.

Tell us which documents eat the most time. We'll scope a pilot with human review and an audit trail built in, at a fixed price.

Tell us what you're building

Prefer to talk? Pick a 30-minute slot.

sales [at] yarify.tech WhatsApp Telegram