Dome Systems

AI agents in healthcare

Give your clinicians agents that only see their own patients

Three agents for prior authorizations, visit notes and eligibility checks. The ones clinicians call act as that clinician and read only the charts they can read. Every call lands in one audit record.

cliniciansAgentsDomeHospital systemsCallerscliniciansAgentsprior-auth-assemblerAgentsnote-drafterAgentseligibility-checkerGatewaysclinical-toolsEpicEHR, over FHIRAvailityPayer eligibilityMicrosoft TeamsCare team chatAnthropicBAA-covered modelsRulesGuardsAuditsaudit-trail
eligibility-checker→availity/check_eligibility· scheduledAllowed

Governing Healthcare Agents

Any tool, any model, any use case

Our example demonstrates three agents for your clinical and revenue-cycle work, pulled from our template library. Our team can work with yours to build, govern, and operate your agents as you deliver on your IT strategy.

Examples for Healthcare

More from the library · Health

Also in the library

FinanceSecurityITHRSalesSupportEngineeringResearch

Assemble prior authorizations

Pulls the notes, orders and imaging a payer asks for into one authorization packet. A clinician reviews it and submits.

Tools

EpicAvaility

Model

Claude Sonnet 5or any approved provider

Runs

When an order needs authorization

Limits

Acts as the clinicianCannot submitBAA-covered models only

Tuned for your team

  • Payer requirements for your highest-volume commercial plans
  • Packets in the format each payer's portal accepts

Applying Controls to Agents

Enforce care-team access, PHI handling and sign-off in one place

Dome sits between the agents and your systems. Every call is checked against rules your team writes before it reaches Epic, Availity or a model.

Acting as

agent note-drafter · acting as dr.hollis
epic/read_chart(patient: "MRN 4471-203")
  1. Agentnote-drafter is registered and active
  2. Callerdr.hollis verified through Entra ID
  3. Toolread_chart is granted on clinical-tools
  4. Ruledr.hollis is on this patient's care team
DecisionAllowed

Comprehensive Audit

Show compliance exactly which charts an agent opened

One record for every call: the agent, the clinician it acted for, the system, and the decision. Enable investigations, increase confidence and reduce risk in agentic operations.

Audit · clinical-tools
Events 0Denied 0
  • eligibility-checker02:10:04
1 audit events

Regulation

Answer HIPAA for agents the way you do for staff

Agents that touch PHI answer to the same rules as your workforce. These are the ones they reach, and what the controls above give you for each.

HIPAA minimum necessary

What it asks

Uses of PHI are limited to the minimum necessary for the purpose, for an AI agent as for a person.

What Dome gives you

Agents act as the clinician and open only charts where that clinician is on the care team. A guard strips identifiers a note doesn't need.

Business associate agreements

What it asks

Any vendor that handles PHI needs a BAA, AI model providers included.

What Dome gives you

Agents reach only models covered by your BAA. A call to any other model is refused before PHI leaves.

HIPAA Security Rule audit controls

What it asks

Record and examine activity in systems that contain electronic PHI.

What Dome gives you

Every agent call is recorded with the agent, the clinician it acted for, the system and the decision, refused calls included.

CMS prior authorization rule (CMS-0057-F)

What it asks

Payers must decide prior authorizations within 72 hours for urgent requests and 7 days for standard ones, from 2026.

What Dome gives you

The prior auth agent assembles the request from the chart and can't submit it. A clinician reviews and sends.

FAQ

Common questions

Do AI agents need a BAA?

The vendor that processes PHI does, which for agents usually means the model provider. Dome routes agent calls only to models on your BAA and refuses the rest.

How do you enforce minimum necessary for AI agents?

Scope access to the person the agent acts for, then strip what the task doesn't need. Dome checks care-team membership on each call and redacts identifiers before the model call.

Can AI submit prior authorizations?

It can assemble one. On this setup the agent drafts from the chart, a clinician submits, and the agent's submit call is refused.

How do I audit AI agent access to PHI?

Put the agents behind one gateway. Every call is recorded with the agent, the clinician it acted for, the system and the decision.

How are AI agents being used in healthcare?

Prior authorizations, visit notes and eligibility checks are common first agents. Each works inside the chart access its clinician already has.

Forward deployed engineering

Spend 30 minutes with our FDE team to understand the platform, and how it fits to your needs.

Our FDE team can get your first agent under management and work with your platform team to deliver results for your AI program.

Key topics to discuss:

  • Review your AI plans, progress to date, and timeline for agentic projects in production.
  • Planning a specific agent, or agentic app, to bring under governance.
  • Learning more about our platform capabilities, from gateways to routing.
  • Defining agentic operations as repeatable golden pathways for Platform and AppDev teams.

Explore

Other industries

Industries

AI agents for financial services

KYC reviews, client servicing and SAR narratives. Approvals, money movement and filings stay with your people.

Agentic use cases

  • Review onboarding documentsChecks identity and entity documents against your CDD requirements, runs sanctions screening and writes the KYC summary. An analyst approves.
  • Answer client requestsReads the client's accounts and open cases and drafts the reply to a servicing request. It never moves money or changes an account.
  • Draft SAR narrativesPulls the alert history and transactions for a case and drafts the SAR narrative. An investigator edits it and files.

Answers to

  • GLBA Safeguards Rule
  • BSA/AML and the FinCEN CDD Rule
  • NYDFS Part 500
  • Regulation E (EFTA)
  • CFPB UDAAP
  • Interagency third-party risk guidance
  • ECOA and Regulation B
  • FCRA
  • SR 11-7 model risk management
  • PCI DSS v4.0.1
  • Regulation E (EFTA) error resolution
  • BSA/AML and OFAC sanctions screening
  • SEC Regulation S-P (2024 amendments)
  • SEC Marketing Rule and FINRA Rule 2210
  • Books and records (Rule 204-2 and Rule 17a-4)
  • FINRA Rule 3110 and Regulatory Notice 24-09
  • SEC Rule 17a-4 recordkeeping
  • Exchange Act Section 15(g) information barriers
See the finance agents