Operations software around the clinic day, not a clinical decision system

Healthcare organizations run on appointment books, encounter types, provider templates, no-show rules, referral intake, prior-auth packets, and billing workqueues. We can build or integrate software for those operational jobs. This is not medical advice. We do not diagnose, treat, or claim to be a certified EHR. We do not advertise HIPAA certification we have not earned. If your project stores protected health information, your legal, security and (where applicable) HIPAA program remain yours. We will say when we are the wrong vendor.

What we will and will not touch

We will discuss scheduling templates (session lengths, overbooking rules you define, rooms, equipment), waitlists, reminder preferences, and staff workqueues for incomplete packets. We will discuss records-adjacent workflows: moving a document to a charting system via an interface you already use, tracking that a packet is complete, or giving a coordinator a queue. Completeness of a packet is not a clinical judgment.

We will not build a consumer “symptom checker” that implies care, an autonomous agent that messages patients about clinical content without your clinicians’ protocol, or a system that pretends to replace your EHR’s legal medical record. If you need an EHR, buy one in that market and hire implementers who live there.

AI in this industry is a heightened risk. Transcription or classification behind a clinician’s review is a different product than unattended advice. We default to human review on anything patient-facing. Model vendors’ data-use terms must be acceptable to your counsel, we will not hide a training-data clause behind a demo.

Operational problems (not clinical claims)

Capabilities we will consider

Use cases

How healthcare-adjacent work runs

  1. Fit and constraint call

    What data, which regulations you assert, whether a BAA is required, and whether we should decline.

  2. Discovery with compliance in the room

    Your privacy officer or counsel should see the data-flow diagram. We will not skip this to “move fast.”

  3. Scope that names PHI

    If PHI is in scope, hosting, logging, subprocessors and access are written. If it is not, we keep it out on purpose.

  4. Architecture

    Least privilege, audit, encryption in transit, and no casual use of consumer AI tools on records.

  5. Launch

    Your change control. Training for coordinators. A way to turn a feature off. Iterate on the workqueue, not on clinical content.

Questions we hear first

Are you HIPAA certified / HITRUST certified?
We do not claim HIPAA certification, HITRUST, or similar badges on this site. HIPAA is a regulatory regime for covered entities and their business associates, not a logo. If we act as a business associate, that is a contract (including a BAA) and an operational program, not a homepage claim.
Can you build us an EHR?
We do not market an EHR. Charting, e-prescribing, and certified record systems are a specialized market. We build operational software next to systems you already use, or we decline.
Can an AI agent call patients?
Not as an unattended clinical conversationalist. Scheduling reminders with approved scripts and opt-out can be discussed. Clinical advice cannot.
Do you work outside the US?
Healthcare rules differ by country. We need you to name the regime. We will not apply a US-only checklist to a different jurisdiction and call it done.
What should I send first?
The operational job (scheduling, packets, workqueue), the system of record, and whether PHI is in scope. Do not send real patient files to sales@progley.com, hello@progley.com, or support@progley.com.

Related

Describe the operational job, not a diagnosis

Scheduling, packets, or a staff queue, plus whether PHI is involved. We will tell you if we can engage, what we refuse, and what your counsel must still own.

Start a Project