Control
Health AI without clinician oversight/accountability + redress
AI/LMMs used in health care must keep a human clinician accountable and able to review/override outputs, with clear responsibility assignment and redress for harmed individuals.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in Illinois (US-IL), Texas (US-TX).
The guard to add
Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.
A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.
What reviewers look for: on every path from a model response to a patient message, an EHR write, a care plan, or a diagnosis or level-of-care change, a draft or preliminary status that only a clinician action (clinician_sign_off, practitioner_review_and_sign, require_clinician_approval) can promote, with approved_by or reviewed_by recorded; auto_sign / auto_finalize off for AI-created records; a named accountability owner and a redress channel.
Example (Python + OpenAI SDK + FHIR REST), before:
note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))After:
note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
json=doc_ref(patient_id, note, doc_status='preliminary')) # AI draft
def practitioner_review_and_sign(doc_id, practitioner): # only path to 'final'
doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
doc['docStatus'] = 'final'
doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (2)
- Illinois (US-IL)
- Texas (US-TX)
- Texas practitioners using diagnostic AI must review every record the AI creates (Texas SB 1188) Tex. Health & Safety Code 183.005(a)
Standard / soft law (1)
- Everywhere (*)
- Health AI/LMMs should keep a clinician accountable with oversight and redress (WHO) WHO LMM Guidance (2024) — Human oversight & accountability recommendation
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal