What an AI phone agent is actually allowed to do in your practice software
The first question any practice asks is not "what can it do" but "what can it see". That is the right question. Here is what gets connected, which way it flows and where it deliberately stops.
Felix Reuter
Co-founder
When a practice first talks about an AI phone agent, one question comes before all the others: does this touch our patient records. "Yes, but only as much as necessary" is not an answer, because nobody can check it. So here is the long version.
Three layers worth keeping apart
An integration is not one door. It is three questions, answered separately:
- What does the agent read, so it can say anything useful during the call
- What does it write back, so the practice has nothing to enter afterwards
- What does it never get to see, whichever way the conversation goes
Most misunderstandings come from putting all three in one bucket. "Access to the practice software" sounds like everything. What is meant is a very narrow slice.
What gets read
Availability, live and mid-call. The agent queries the calendar at the moment it offers a slot. That is the difference between an assistant and an answering machine with a better voice: a slot that is offered is a slot that exists. Cached availability produces exactly the double bookings the system was bought to prevent.
The record of the person on the phone, where there is one. If someone already in the files calls, the agent recognises the number and does not have to ask for things the practice has known for years. That is the part callers notice most.
What gets written
The appointment itself, immediately, straight into the practice software calendar. No intermediate list for someone to type up in the morning.
Reschedules and cancellations, also immediately. This is the underrated part: cancellations arrive more often than new bookings, and a cancelled appointment left standing for three hours blocks a slot somebody else needed.
A call summary after every call, with the reason in one sentence. So the team sees in the morning not just that somebody called, but why.
Where it stops
The part discussed least and needed most. Access ends at what a phone call requires. Concretely: no findings, no diagnoses, no documents, no billing data. Not "the agent does not ask for them", but the access does not include them.
That is also why every integration page on this site has a field that says "nothing else", followed by the list of what that covers. A scope you cannot read aloud in one sentence is not a scope.
Why this looks different per field
Because the call is different. A dental practice and a veterinary practice need the same logic, because the conversation at the front desk is the same one. A pharmacy needs something else, because the decisive question there is whether the box is on the shelf, and that needs a look at stock, not at a calendar.
So each category on this site carries its own account of what synchronises and what the access covers, instead of one general phrasing that half fits everywhere.
What you can check before you sign anything
- The specific breakdown per system is on each integration page
- The technical and organisational measures are set out under security
- The data processing agreement is available as a DPA
- How personal data is processed is described in the privacy policy
And if a question stays open, that is a question this site has not answered yet. Ask it, and the answer will be there next time.