AI agents in healthcare
Give your clinicians agents that only see their own patients
Three agents for prior authorizations, visit notes and eligibility checks. The ones clinicians call act as that clinician and read only the charts they can read. Every call lands in one audit record.
Governing Healthcare Agents
Any tool, any model, any use case
Our example demonstrates three agents for your clinical and revenue-cycle work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.
Examples for Healthcare
More from the library · Health
Also in the library
Assemble prior authorizations
Pulls the notes, orders and imaging a payer asks for into one authorization packet. A clinician reviews it and submits.
Tools
Model
Runs
Limits
Tuned for your team
- Payer requirements for your highest-volume commercial plans
- Packets in the format each payer's portal accepts
Applying Controls to Agents
Enforce care-team access, PHI handling and sign-off in one place
Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches Epic, Availity or a model.
Acting as
- Agentnote-drafter is registered and active
- Callerdr.hollis verified through Entra ID
- Toolread_chart is granted on clinical-tools
- Ruledr.hollis is on this patient's care team
Comprehensive Audit
Show compliance exactly which charts an agent opened
One record for every call: the agent, the clinician it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.
- eligibility-checker02:10:04
| Timestamp | Type | Agent | Acting as | Resource | Outcome | Latency |
|---|---|---|---|---|---|---|
| 02:10:04.118 | ||||||
Regulation
Answer HIPAA for agents the way you do for staff
Agents that touch PHI answer to the same rules as your workforce. These are the ones they reach, and what the controls above give you for each.
HIPAA minimum necessary
What it asks
Uses of PHI are limited to the minimum necessary for the purpose, for an AI agent as for a person.
What Dome gives you
Agents act as the clinician and open only charts where that clinician is on the care team. A guard strips identifiers a note doesn't need.
Business associate agreements
What it asks
Any vendor that handles PHI needs a BAA, AI model providers included.
What Dome gives you
Agents reach only models covered by your BAA. A call to any other model is refused before PHI leaves.
HIPAA Security Rule audit controls
What it asks
Record and examine activity in systems that contain electronic PHI.
What Dome gives you
Every agent call is recorded with the agent, the clinician it acted for, the system and the decision, refused calls included.
CMS prior authorization rule (CMS-0057-F)
What it asks
Payers must decide prior authorizations within 72 hours for urgent requests and 7 days for standard ones, from 2026.
What Dome gives you
The prior auth agent assembles the request from the chart and can't submit it. A clinician reviews and sends.
FAQ
Common questions
Do AI agents need a BAA?
The vendor that processes PHI does, which for agents usually means the model provider. Dome routes agent calls only to models on your BAA and refuses the rest.
How do you enforce minimum necessary for AI agents?
Scope access to the person the agent acts for, then strip what the task doesn't need. Dome checks care-team membership on each call and redacts identifiers before the model call.
Can AI submit prior authorizations?
It can assemble one. On this setup the agent drafts from the chart, a clinician submits, and the agent's submit call is refused.
How do I audit AI agent access to PHI?
Put the agents behind one gateway. Every call is recorded with the agent, the clinician it acted for, the system and the decision.
How are AI agents being used in healthcare?
Prior authorizations, visit notes and eligibility checks are common first agents. Each works inside the chart access its clinician already has.
Forward deployed engineering
Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.
Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.
Key topics to discuss:
- Review your AI plans, progress to date, and timeline for agentic projects in production.
- Planning a specific agent, or agentic app, to bring under governance.
- Learning more about our platform capabilities, from gateways to routing.
- Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.
Explore
Other industries
AI agents for financial services
KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.
Agentic use cases
- Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
- Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
- Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.
Answers to
- GLBA Safeguards Rule
- BSA/AML and the FinCEN CDD Rule
- NYDFS Part 500
- Regulation E (EFTA)
- CFPB UDAAP
- Interagency third-party risk guidance
- ECOA and Regulation B
- FCRA
- SR 11-7 model risk management
- PCI DSS v4.0.1
- Regulation E (EFTA) error resolution
- BSA/AML and OFAC sanctions screening
- SEC Regulation S-P (2024 amendments)
- SEC Marketing Rule and FINRA Rule 2210
- Books and records (Rule 204-2 and Rule 17a-4)
- FINRA Rule 3110 and Regulatory Notice 24-09
- SEC Rule 17a-4 recordkeeping
- Exchange Act Section 15(g) information barriers
AI agents for gaming and sports betting
Player support, responsible gaming review and bonus setup. Self-exclusions and limits stay out of an agent's reach.
Agentic use cases
- Answer player questionsLooks up a player's account, bets and withdrawal status so a specialist can answer fast. It reads. Balances and limits stay with people.
- Review responsible gaming signalsReviews players flagged for risky play and drafts case notes for the responsible gaming team. It never changes a limit.
- Configure bonusesSets up deposit matches and free bets from a campaign brief, up to the cap you set. Self-excluded players are never targeted.
Answers to
- State gaming regulations
- Bank Secrecy Act (FinCEN casino rules)
- Age, identity and location checks
AI agents for insurance claims
Claim intake, file summaries and fraud screening. Agents read only the claims assigned to their adjuster.
Agentic use cases
- Triage new claimsReads each first notice of loss, sets severity and line of business, and routes it to the right adjuster queue. It flags. It never settles.
- Summarize claim filesSummarizes medical records, police reports and correspondence in a claim file for the assigned adjuster. Only claims that adjuster handles.
- Screen claims for fraud signalsChecks each open claim against prior claims history and flags patterns for the special investigations unit. It never denies a claim.
Answers to
- NAIC Model Bulletin on AI Systems
- Unfair claims settlement practices laws
- Insurance data security laws
AI agents for law firms
Conflicts checks, clause extraction and redlines. Every agent acts as the lawyer who asked.
Agentic use cases
- Check new matters for conflictsSearches Intapp and past matters in iManage for parties that conflict with a proposed engagement. It reports. It never clears a conflict.
- Extract clauses from contractsPulls parties, dates, renewal and change-of-control terms from the contracts in a matter workspace. Only in matters the requester is staffed on.
- Draft redlines against the playbookMarks up a counterparty draft against your playbook and saves it as a new version. Counsel reviews it and sends it.
Answers to
- ABA Formal Opinion 512
- Privilege after United States v. Heppner
- Ethical walls (Model Rules 1.7, 1.9, 1.10)
AI agents for professional services firms
Proposals, staffing and engagement status. Each agent sees only the engagements its consultant works on.
Agentic use cases
- Draft proposalsReads an RFP and drafts a response from the firm's reuse library. Client names in past work are stripped before the model sees them.
- Match staff to engagementsMatches skills and availability to a new engagement's roles and proposes a team. Resource managers make the assignments.
- Report engagement statusReads the project plan and engagement files and drafts the weekly status report. It sees only engagements its consultant is on.
Answers to
- Client confidentiality terms
- AICPA Confidential Client Information Rule
- SOC 2
- GDPR and state privacy laws
AI agents for retail
Order lookups, replenishment and product copy. Refunds, orders and publishing stay with your people.
Agentic use cases
- Answer order questionsLooks up orders, shipments and returns so an associate can answer a customer fast. It reads. Refunds stay with the associate.
- Plan replenishmentForecasts demand by store and drafts purchase orders against par levels. Buyers review them and send them.
- Write product copyWrites product titles and descriptions from supplier data, in your voice, and saves them as drafts. Merchandisers publish.
Answers to
- PCI DSS v4.0.1
- State privacy laws (CCPA/CPRA)
- SOX internal controls
- FTC Act, Section 5
- Antitrust and algorithmic pricing
- Predictive scheduling laws
- Routing guides and carrier contracts
AI agents for software companies
Escalation triage, incident summaries and release notes. Agents read code and incidents. Shipping stays with engineers.
Agentic use cases
- Triage engineering escalationsReads an escalated ticket and the code it points to, drafts a diagnosis and sets priority. Fixes stay with the engineer.
- Summarize incidentsFollows an incident's timeline and recent deploys, drafts status updates and a first postmortem. It never acknowledges, pages or resolves.
- Draft release notesReads the pull requests merged since the last release and drafts customer-facing notes. The release stays a draft until an engineer publishes it.
Answers to
- SOC 2
- ISO/IEC 42001
- EU AI Act
- State privacy laws (CCPA/CPRA)
Enabling agent operations
Governance at the agent‑action boundary.
However an agent was built and wherever it runs, the same three boundaries are available to control it: the code it ships as, the tools it calls, and the model it reasons through.
Code
Agent Registry
Make every agent known and manageable. Credentials issued, capabilities declared, lifecycle owned.
See moreTool
MCP Gateway
Evaluate every call against policy with full context. Allow, deny, or escalate. Filter what comes back.
See moreModel
Model Broker
Constrain how the agent reasons. Selection by policy, routing across providers, evals against real traffic.
See more