The MVP constraint set: no integrations. Patients call and message the local health system, not Sevaro — so the inbound channels, the In Basket, the orders, and the filed note all live in the client's Epic. Our system runs beside it. This page is the operating model that keeps the two paths sane.
Epic = system of record and system of contact. Our system = system of tracking and intelligence. We don't compete with Epic for anything in its lane — we make the triage nurse faster beside it. And for MVP, copy/paste is the integration — deliberately. It's the same muscle the scribe already proved: author in our system, paste into the EHR.
The failure mode of hybrid systems is double documentation — two half-true versions of the truth. One owner per artifact, one-way flows:
| Artifact | Our system | Epic |
|---|---|---|
| Triage / visit note | Authored + archived here OURS | Pasted in — Epic copy is final EPIC FINAL |
| Orders, results, patient messages | Only what she pastes in for assist | Lives here, period EPIC |
| Worklist / status / next-action | Lives here, period OURS | Doesn't exist there |
| Schedule | Paste-parsed snapshot | Source EPIC |
Our worklist is operational tracking, never a shadow chart.
The triage nurse is virtual. Patients sit at their home clinics. There is no integration and no Sevaro patient portal, so the message lanes are asymmetric — and the asymmetry is the design constraint, not a temporary annoyance.
| Lane | Direction | How it works in MVP |
|---|---|---|
| Site MA → triage RN | → | Message in Synapse OURS |
| Physician / nurse ↔ triage RN | ↔ | Message in Synapse, both directions OURS |
| Patient → triage RN | ✕ none | Patient calls the local organization. The local org relays to her, or she reads the local portal with her site login. |
| Triage RN → patient | → | She calls the patient and/or writes a message in the local portal; our system logs that contact. LOCAL FILED |
Patients cannot reach us directly, so every inbound path runs through the local organization — which means the per-site portal logins aren't a convenience feature, they're load-bearing infrastructure. And the local-portal message is the filed copy; ours records only that we sent it. Same one-owner rule as the note.
During the call she should be able to run the triage pathway live — or pull it up fast enough to answer in the moment — and the call is recorded with the same ambient AI the scribe already uses.
The principle: keep the clinical conclusion, discard the raw material on a schedule. The note is the record; everything upstream of it is working material.
| Artifact | Retention | Why |
|---|---|---|
| Triage note — disposition + what she knew | Full medical-record retention, matched to the local org's policy | Clinical documentation, and the defense if an outcome is questioned |
| Call recording + transcript | One short fixed window (~30–90 days), then automatic purge | QA and dispute window. A recording that outlives its purpose is discoverable and can contradict the note. |
| Pasted chart context | Purge at encounter close | It's a copy of Epic's data — Epic is the record |
| Worklist status, ticklers | Short — operational only | Unless a status encodes a clinical decision, in which case it belongs in the note |
Backups silently extend real retention. If PITR or snapshots hold 35 days,
a 30-day purge policy is fiction unless it covers them.
Selective retention is worse than either extreme. Keeping some calls and not
others reads as spoliation. One automatic clock, applied uniformly, no human deletion.
The demo's queue becomes a worklist — fed by the nurse, not by patients.
The moment the worklist holds real names or MRNs, PHI enters this system — and the deferred security audit findings (systemic API-auth gap) become a blocking prerequisite, not a someday. The real-build kickoff starts with a security-remediation phase, before any live patient tracking.
Seven risks raised; five now have answers. Ordered by how early each could stop the program.
| Risk | Status |
|---|---|
| Cross-state licensure | ✓ Resolved — the RN will be licensed across the covered states |
| BAA coverage per site | ✓ Resolved — coverage will be in place |
| Physician standing orders | ✕ OPEN — do not exist yet. Must be authored, with a policy document around them. Gates live use. |
| Loop-closure escalation | ✓ Adopted — ticklers escalate, not just remind |
| Emergency at distance | ✓ Adopted — ED script is now location-first (see below) |
| Call consent | ✓ Decided — transcribe, don't record; disclose at call open |
| Return path for the patient | ✓ Decided — script always routes back to the local org |
Standing orders don't exist yet. A nurse issuing dispositions practices under physician-approved protocol — and our pathways are that protocol. They need to be authored, signed by a named physician owner, given a review cadence, and wrapped in a policy document. This is now a tracked work item in its own right, not a checkbox on the build.
Audio is captured only long enough to produce the AI transcript, then discarded. The transcript and the note are what persist. That materially shrinks the retention and discoverability surface versus keeping call recordings.
Not retaining audio does not cleanly remove the consent duty — many state
statutes turn on intercepting a conversation, not on storing it. So the disclosure is
read at the top of every outbound call regardless.
Wording matters: "quality review and care improvement" sits inside HIPAA
health-care operations. "Data analytics" is broader, and using patient transcripts to train
models is a separate authorization question — worth deciding deliberately rather than
inheriting from the disclosure sentence.
911 routes to the caller's location. A virtual nurse cannot dispatch to a patient. So the ED script now establishes location before anything else, then names who dials: the person with the patient, or the local site, or the patient themselves — and if the patient is alone and can't dial, the nurse calls that jurisdiction's 10-digit emergency dispatch, because dialing 911 herself reaches her own area, not theirs.
Recommendation adopted: the script always routes the patient back to the local organization. A dedicated Sevaro return number is only worth adding if it will actually be answered — an unanswered return line is worse than none, because an urgent patient leaves a voicemail nobody hears in time.