Surgeon focused during a surgical procedure

Turn this thinking into a working system.

Semantic engineers the data, models and applications required to move complex operational use cases into production.

Surgeon focused during a surgical procedure

Turn this thinking into a working system.

Semantic engineers the data, models and applications required to move complex operational use cases into production.

Surgeon focused during a surgical procedure

Turn this thinking into a working system.

Semantic engineers the data, models and applications required to move complex operational use cases into production.

Surgeon focused during a surgical procedure

Turn this thinking into a working system.

Semantic turns complex operational use cases into production systems.

The Two Gates Every Healthcare AI System Has to Pass Before It Reaches a Patient

Published:

Category:

Deployment

Most healthcare AI coverage is still framed as a forecast.

What AI will do to clinical documentation. What it will mean for prior authorization. What regulators will eventually require.

That framing is already becoming outdated.

Healthcare organizations are no longer preparing for a future in which interoperability, algorithm transparency and traceable clinical decisions matter. They are operating inside it.

On January 1, 2026, older versions of the US Core and SMART App Launch implementation guides expired as certification options under the ONC Standardized API criterion. Certified health technology is now expected to operate against updated interoperability standards, while new federal requirements for electronic prior authorization and clinical data exchange continue to reshape the infrastructure connecting providers, patients and payers.

None of this is only about whether a clinical model is accurate enough.

It is about whether the system surrounding that model can prove what it did, why it did it and which information moved between every participant involved.

Healthcare AI now has to clear two gates.

Gate One: Can You Prove It Was Necessary?

The first gate belongs to the payer.

It has quietly become an algorithmic one.

Medical necessity can no longer be communicated through a diagnosis and procedure code alone. It must be supported by documentation that connects the requested intervention to a specific clinical rationale.

That record may need to include the diagnosis, treatment history, previous interventions, evidence of failure and the risk associated with delaying or denying the proposed care.

The documentation also has to survive increasingly automated review workflows.

A clinically appropriate decision may still be denied when the supporting record is incomplete, inconsistent or written in a form that cannot be interpreted reliably by the payer’s systems.

The old documentation formula was designed for human review.

The emerging one must work for both human reviewers and machine-assisted authorization systems.

That distinction matters.

An AI system may produce a fluent and clinically accurate note while still omitting the specific evidence required to demonstrate medical necessity.

When that happens, the system does not appear to fail at the point of care.

It fails later, through an authorization request, a denial or an appeal that the clinician should never have needed to file.

Gate Two: Can Your System Communicate With Everyone Else’s?

The second gate is interoperability.

A healthcare AI system cannot operate as an isolated application that produces useful output inside its own interface.

It must exchange information with electronic health records, patient applications, payer platforms and other clinical systems through standardized and secure interfaces.

Under the ONC Health IT Certification Program, standardized patient and population APIs rely on FHIR, US Core and SMART App Launch implementation requirements.

Older US Core and SMART App Launch versions expired as certification options on January 1, 2026, moving certified systems toward more current interoperability standards.

The direction is clear.

Clinical information must be available through structured APIs rather than trapped inside proprietary databases or transferred through manual exports.

For AI-enabled systems, interoperability alone is not enough.

The organization must also understand which data informed an output, how that information moved through the system and what role the model played in the final decision.

The clinician remains responsible for exercising professional judgment.

Software may structure the record, retrieve relevant information or surface a recommendation, but it does not absorb the clinical and legal accountability attached to the decision.

A system that cannot show its work leaves the human operator carrying the risk it was intended to reduce.

Why Both Gates Are the Same Problem Wearing Different Uniforms

The two gates appear to belong to different parts of the healthcare system.

One concerns whether a payer accepts the clinical rationale behind a decision.

The other concerns whether information can move between systems in a standardized, secure and auditable form.

Underneath, they are the same engineering problem.

Gate One fails when documentation cannot be traced to a specific and defensible clinical rationale.

Gate Two fails when that documentation and its underlying data cannot move between systems with their meaning, source and context intact.

Both are problems of data architecture, provenance and workflow design.

They are not simply problems of model accuracy.

The same pattern appears across every regulated industry.

In defense, it appears through classification boundaries and disconnected programs of record.

In insurance, it appears through claims platforms, rating engines and fragmented policy systems.

In healthcare, it appears through denial codes, clinical documentation, certification criteria and interoperability standards.

The terminology changes.

The underlying constraint does not.

A hospital may operate a highly accurate ambient documentation system and still fail both gates.

Accurate notes that do not contain the evidence required by a payer fail the first.

Accurate notes trapped inside a system that cannot produce a standardized and traceable data trail fail the second.

The healthcare AI market has spent years optimizing the model.

The surrounding infrastructure is now being tested.

The Compliance Calendar Is Already Running

Healthcare organizations should not treat interoperability and AI governance requirements as distant planning assumptions.

Several important changes are already active, while others have defined implementation timelines.

January 1, 2026: Updated API Certification Standards

Older US Core and SMART App Launch implementation-guide versions expired as options for certification under the ONC Standardized API criterion.

Certified systems must now use currently accepted versions of the applicable interoperability standards.

March 1, 2026: End of Temporary Enforcement Discretion

ONC provided temporary enforcement discretion for certain HTI-1 certification updates through February 28, 2026.

That temporary period has ended.

Electronic Prior Authorization Requirements

The HTI-4 Final Rule introduced new certification criteria supporting coverage-requirement discovery, documentation templates and electronic prior authorization workflows.

These requirements are moving authorization processes toward standardized exchanges between providers and payers rather than disconnected portals and manual submissions.

January 1, 2027: Colorado Automated-Decision Requirements

Colorado’s revised automated-decision law is scheduled to take effect on January 1, 2027.

The law establishes requirements for developers and deployers of systems that materially influence consequential decisions, including protections related to algorithmic discrimination and inaccurate personal data.

Ongoing: Expanding Model Governance and Oversight

Healthcare AI remains subject to overlapping clinical, privacy, reimbursement, safety and technology-governance requirements.

The specific obligations depend on how a system is classified, what decision it influences, which data it processes and where it is deployed.

A system designed against last year’s assumptions may not simply be behind schedule.

It may already be incompatible with the technical and governance environment in which it is expected to operate.

What Clears Both Gates

A healthcare AI system built for production must be designed to satisfy both the clinical-justification gate and the interoperability gate.

Documentation That Captures Clinical Rationale

The system must capture more than a fluent summary of the encounter.

It should structure the diagnosis, clinical rationale, relevant treatment history, previous interventions, observed outcomes and risk of progression in a form that supports both clinical continuity and payer review.

The objective is not to write for an authorization algorithm.

It is to ensure that the evidence supporting the clinician’s decision is explicit, complete and recoverable.

A Native Interoperability Layer

FHIR and SMART-based interoperability should be part of the system architecture, not an export function added after the core product has already been built.

Clinical data must retain its structure, source and meaning as it moves between the EHR, third-party applications and external organizations.

The system should meet the existing environment where it operates without creating another isolated repository.

Traceable Data Provenance

Every meaningful output should be connected to the data that produced it.

The organization should be able to identify which records were retrieved, where they originated, how they were transformed and which version of the model or workflow processed them.

Without provenance, an accurate output cannot be reliably explained, challenged or audited.

Disclosed Model Risk

The organization should understand and document the system’s intended use, limitations, training or evaluation data, known performance gaps and potential sources of bias.

That documentation should exist before a regulator, auditor or affected patient requests it.

Model governance cannot depend on reconstructing the system only after an incident occurs.

Human Accountability Built Into the Workflow

The clinician must remain the accountable decision-maker for clinical judgments.

Recommendations, generated notes and retrieved evidence should be presented in a way that allows the clinician to review, correct and override them before they become part of a consequential decision.

Human oversight cannot be a policy statement disconnected from the product.

It must be visible in the workflow, permissions and audit trail.

None of these requirements represents an unsolved research problem.

They are engineering and governance problems.

They are also the same problems underneath every regulated industry we work in: the operational details change, but the shape of the infrastructure does not.

Explore how we approach regulated, high-stakes industries, read how the same underlying pattern appears in defense procurement and insurance underwriting, or talk to our team about the infrastructure underneath your next clinical AI deployment.

From pilots to production

From pilots to production

From pilots to production

We help enterprises move past isolated AI experiments and build reliable systems that operate inside real workflows.

We help enterprises move past isolated AI experiments and build reliable systems that operate inside real workflows.

We help enterprises move past isolated AI experiments and build reliable systems that operate inside real workflows.

Engineered around your operations

Engineered around your operations

Engineered around your operations

Every deployment is designed around your data teams processes and constraints so intelligence works where decisions happen.

Every deployment is designed around your data teams processes and constraints so intelligence works where decisions happen.

Every deployment is designed around your data teams processes and constraints so intelligence works where decisions happen.

Built to scale with control

Built to scale with control

Built to scale with control

Semantic combines strategy engineering governance and human review to make AI transformation measurable secure and repeatable.

Semantic combines strategy engineering governance and human review to make AI transformation measurable secure and repeatable.

Semantic combines strategy engineering governance and human review to make AI transformation measurable secure and repeatable.