AI Governance for Direct Primary Care and Concierge Medicine Practices
Direct primary care and concierge practices adopting AI agents for scheduling, documentation, and patient messaging need runtime controls, not just vendor assurances, to enforce least-privilege access, log AI tool calls distinctly from human actions, and maintain HIPAA-aligned accountability for every AI action involving PHI.
Where AI Agent Risk Concentrates in DPC Practices
AI agents are entering small practices through several distinct workflows, each carrying its own PHI exposure and audit surface.
Scheduling and intake agents
Access patient contact and appointment data, often through third-party platforms.
Clinical documentation tools
Process visit notes and clinical detail, frequently via ambient or AI scribe integrations.
Patient messaging agents
Handle PHI-containing conversations across portals or communication platforms.
MCP-connected tool calls
Enable AI models to invoke external systems, expanding the audit surface.
Why This Applies to Small Practices, Not Just Hospital Systems
Direct primary care and concierge medicine practices operate with a different risk profile than large health systems. Panel sizes are smaller, IT staffing is minimal or outsourced, and the practice model depends on direct, high-trust relationships between physicians and patients. Over the past year, these practices have increasingly adopted AI agents for scheduling, ambient clinical documentation, and patient messaging, typically through third-party EHR add-ons, communication platforms, or Model Context Protocol (MCP) integrations rather than custom-built systems. This creates a governance gap. The HIPAA Security Rule requires access controls, audit controls, and integrity controls for electronic PHI regardless of practice size or whether the technology involved is AI-based. HHS Office for Civil Rights guidance is explicit that using AI tools does not change these existing obligations. A five-physician concierge practice has the same underlying compliance requirements as a large health system, but far fewer resources to build custom enforcement infrastructure around them.
What Changes When AI Agents Call Tools Instead of Staff Clicking Screens
Traditional EHR access control assumes a human logs in, is authenticated, and performs actions within a defined role. AI agents change this model. Under MCP architecture, an AI model's reasoning is separated from the tools it invokes, meaning a scheduling assistant or documentation agent may call external systems, databases, or APIs on a patient's behalf without a human directly initiating each action. The MCP specification includes authorization guidance for controlling tool access, but it also identifies real risks: over-permissioned tool access and a lack of standardized audit trails across implementations. In practice, this means a practice cannot assume that because a vendor mentions MCP support, tool calls are automatically logged, scoped, or reviewable. Auditability depends entirely on how the integrating platform configures logging and permissions, which varies significantly between vendors.
Applying the Minimum Necessary Standard to AI Agent Permissions
HIPAA's minimum necessary standard requires covered entities to limit PHI use and disclosure to what is required for a specific purpose. This principle applies directly to AI agent permission scoping. A scheduling agent needs access to appointment calendars and basic contact information, not full clinical notes. A documentation agent needs access to the current encounter, not the entire longitudinal patient record. A messaging agent needs access to the specific conversation thread, not the underlying EHR database. Many AI vendor integrations default to broad API credentials because narrow, per-function scoping is more difficult to build and maintain. Governance leaders evaluating AI tools should treat this as a primary evaluation criterion rather than an implementation detail, since over-broad access is difficult to detect after deployment and even harder to justify during a breach investigation or OCR inquiry.
Governance Accountability Does Not Transfer to the Vendor
A common assumption among smaller practices is that adopting a reputable AI vendor transfers compliance responsibility to that vendor. This is not accurate under HIPAA. The covered entity retains accountability for PHI handling regardless of whether an AI agent, a vendor's infrastructure, or a human staff member caused a compliance failure. NIST's AI Risk Management Framework reinforces this by framing governance, mapping, measuring, and managing risk as functions the deploying organization must own, while acknowledging that smaller organizations can scale how they implement these functions to available resources. Scaling governance does not mean omitting it. A concierge practice with no dedicated security staff still needs a documented answer to who can access what PHI through which AI agent, and how that access is verified over time. Where in-house enforcement capacity is limited, prioritizing vendors with strong built-in governance controls, such as granular permissioning and usable audit logs, is a more realistic path than attempting to build custom monitoring infrastructure internally.
Minimum Technical Controls Before Deploying an AI Agent
Before granting an AI agent access to PHI, practices should confirm the following controls are in place and enforced at runtime, not just documented in a vendor's policy.
Per-tool permission scoping
Access limited to the specific functions and data a given agent requires, not broad API credentials.
Distinct audit logging for AI actions
AI agent tool calls recorded separately from human staff actions, with enough detail to reconstruct what occurred.
Runtime enforcement of scope limits
Controls that flag or block agent actions exceeding defined permissions, rather than relying on after-the-fact review.
Ongoing monitoring
Continuous oversight of agent behavior, not a one-time security review performed only at onboarding.
Vendor Evaluation Questions Before Granting PHI Access
These questions help surface whether a vendor's AI features are governed with the same rigor as the rest of a practice's PHI systems.
- Does the vendor support per-tool or per-function permission scoping aligned with minimum necessary?
- Will the vendor sign a BAA covering every AI feature that touches PHI, including MCP-connected tools?
- Can the platform log AI agent actions separately from human staff actions, including tool calls?
- Are there runtime controls to flag or block agent actions that exceed defined permission scope?
- Does the vendor support ongoing monitoring rather than a one-time security review at onboarding?
Bring Runtime Governance to Your AI-Enabled Practice
Trussed AI provides runtime governance and security controls for AI agents, including permission scoping, MCP security, and audit logging designed for organizations that cannot rely on large in-house security teams.
Request a Demo