Foundry research · Great Library of SISO

US ambulatory medical practices

Start with supervised administrative queues that preserve the practice's EHR, privacy controls and staff authority. Measure review, rework and exception effort against matched baseline records; no adoption, savings or clinical-outcome claim is made.

Research dated 2026-09-05. Business value remains unmeasured. Software descriptions are documented capabilities; each project must verify fit, rights and outcomes before adoption.

United States research pilot; state licensure, payer, privacy and practice-specific requirements require authorized review.

What the evidence supports

HealthIT.gov describes HIPAA privacy and security basics, including safeguards around protected health information. That supports a privacy-preserving administrative inventory, not permission to automate clinical decisions or a forecast of automation prevalence.

[healthit-hipaa-basics]

Processes to test

Appointment request intake, scheduling and reminder queue

Collect stated appointment preferences, check configured availability and draft or queue reminders; do not triage symptoms, select clinical urgency, recommend care or override staff scheduling policy.

Measure
Net staff minutes per correctly scheduled, approved appointment; reschedule, duplicate, reminder and privacy-exception rate
Reject the idea if
Reject if wrong-provider/time bookings, unauthorized disclosures, symptom-based triage or review/rework increase, or total effort is not reduced.
Human authority
Practice-designated scheduling staff approve bookings, exceptions and patient communications; licensed clinicians retain all clinical authority.

[openemr-features] [jane-online-booking] [healthit-hipaa-basics]

Administrative intake and demographic/document completeness review

Check required fields, identify duplicates or missing administrative documents and return a request for completion; do not infer diagnoses, clinical history, eligibility or consent.

Measure
Net staff minutes per accepted complete intake; missing-field, duplicate, correction and privacy-exception rate
Reject the idea if
Reject if incomplete or incorrect records pass acceptance, sensitive information is exposed, or review/chase/rework effort is not lower.
Human authority
Authorized practice staff review identity, consent and administrative completeness; clinicians determine whether information is clinically sufficient.

[openemr-features] [repo-activepieces] [healthit-hipaa-basics]

Referral and payer authorization-status queue coordination

Track supplied referral and authorization statuses, dates and missing administrative artifacts; draft staff follow-up and escalate exceptions. Do not determine medical necessity, coverage, coding, eligibility or approval.

Measure
Net staff minutes per accurately updated authorization-status item; stale, duplicate, wrong-patient and unresolved-exception rate
Reject the idea if
Reject if stale or wrong-patient statuses drive action, medical-necessity/coverage judgments are automated, or exception and review effort does not fall.
Human authority
Practice authorization staff and payer-designated contacts control submissions and decisions; clinicians retain medical-necessity authority.

[repo-n8n] [repo-activepieces] [healthit-hipaa-basics]

Approved administrative follow-up and records-request routing

Draft status, scheduling or records-request messages from current queue state, route for approval and log delivery; do not provide clinical advice, results interpretation or treatment guidance.

Measure
Net staff minutes per accurate approved request; response, duplicate, wrong-recipient and privacy-exception rate
Reject the idea if
Reject if a message contains clinical advice, stale or wrong-patient information is sent, duplicate retries occur, or review/rework removes effort reduction.
Human authority
Authorized practice staff approve recipient, content and send; clinicians own any clinical response or interpretation.

[jane-online-booking] [repo-n8n] [healthit-hipaa-basics]

Existing software

OpenEMR

Project describes an open-source electronic health record and medical practice management system with scheduling, billing and patient-facing administrative capabilities.

No current practice quote, hosting cost or avoidable spend verified.

[openemr-features]

Jane App

Vendor advertises online booking, appointment scheduling, reminders and practice-management workflows for healthcare and wellness practices.

No current practice quote, billing basis or achieved savings verified.

[jane-online-booking]

Reusable code candidates

openemr/openemr

Repository for the OpenEMR electronic health record and medical practice management project; useful as a source-owned system boundary reference for scheduling and administrative records.

Possible reuse
Read-oriented administrative sidecar or explicitly scoped connector; preserve the practice's EHR, permissions, audit trail and clinician authority.
Limits
Repository and README capability are not evidence of HIPAA configuration, interoperability correctness, support, security, migration or production fitness.
Rights
Coverage inventory records GPL-3.0 and a source-owned-fork route; edition, deployment and rights obligations require review.

[repo-openemr]

Revision: unverified

activepieces/activepieces

Repository describes visual workflow automation, triggers, actions and connectors that could route bounded administrative events.

Possible reuse
Allow-listed, approval-gated workflow for non-clinical queue routing and reminders; no unrestricted PHI write or external send.
Limits
Repository capability is not evidence of healthcare compliance, secure deployment, connector correctness, idempotency or measured effort reduction.
Rights
Value matrix records a community-core service plus SISO pieces route; license, hosting, tenant isolation and connector rights require review.

[repo-activepieces]

Revision: unverified

n8n-io/n8n

Repository describes node-based workflow automation and integrations that could support bounded administrative notifications and queue transformations.

Possible reuse
Prototype against synthetic or redacted records, with explicit approval before any practice-system write or patient communication.
Limits
README capability is not evidence of HIPAA eligibility, secure operations, clinical safety, support or production qualification.
Rights
Repository license and deployment terms require current edition and commercial-use review before reuse.

[repo-n8n]

Revision: unverified

Business value and a falsifiable pilot

No practice baseline, achieved automation rate, review/rework data, operating cost, displacement proof or eligible-population measurement. Null is not zero.

Within one authorized practice, compare matched synthetic or redacted administrative queues under the incumbent and supervised candidate workflows; pre-register permitted fields, approval points and rollback conditions.

  • Human time including review/rework is not lower than matched baseline.
  • Any patient or practice record crosses an unauthorized boundary or an unapproved message/write occurs.
  • A workflow makes or appears to make a clinical, coverage, medical-necessity or treatment decision.
  • Measured first-year net cash is not positive for a cash-savings offer; capacity gains alone are not cash.
Read the shared value model

Limits

  • This is not medical, legal, privacy, billing or clinical advice, product admission or an industry-wide forecast.
  • Current practice adoption prevalence, subscription prices and achieved savings were not verified; named offerings are not assumed installed.
  • No generic repository is claimed to replace a practice's EHR, payer authority, privacy controls or professional judgment.
  • Rights, HIPAA/security configuration, BAA and vendor terms, restoration, integrations, accessibility and state-specific requirements remain product-owner gates.

Sources

  1. Health Insurance Portability and Accountability Act (HIPAA) Basics · HealthIT.gov, Office of the National Coordinator for Health Information Technology

    Supports privacy/security boundary and safeguards framing; does not establish automation permission, compliance for a product, adoption, savings or clinical authority.

  2. OpenEMR Features · OpenEMR

    Project feature claims for EHR and practice-management workflows; not installation, security, interoperability or outcome proof.

  3. Online booking · Jane App

    Vendor capability claims for booking and reminders; no practice adoption, price, accuracy or achieved savings verified.

  4. openemr/openemr repository · OpenEMR

    Repository was accessible; revision, configuration, deployment, rights obligations and production behavior remain unverified.

  5. activepieces/activepieces repository · Activepieces

    Repository was accessible; automation capability is not healthcare compliance or production qualification evidence.

  6. n8n-io/n8n repository · n8n

    Repository was accessible; license edition, PHI controls, deployment and production behavior require separate review.

Canonical source and machine access

Pinned Foundry source · Record JSON

SHA-256: e29a0baf52013b58b4c04faf2b82c034cebd607d6d216dfc9ed89359724b062a