Stop Blaming The Front Desk: Why Healthcare Platforms Have To Protect Against The Mistake

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Alan Rencher, serves as CTO of Henry Schein One, overseeing technology operations for the world’s largest global dental technology provider.

Alan Rencher, serves as CTO of Henry Schein One, overseeing technology operations for the world’s largest global dental technology provider.

gettyA scheduling coordinator pastes a patient’s history into a consumer chatbot to draft a chart note in seconds. An office manager connects an AI assistant that claims to cut no-shows by a third. A practice owner’s nephew builds a weekend dashboard that pulls the patient roster into a cloud spreadsheet. Nobody in that chain is careless. They are all trying to do better work, faster.

And every one of them may have just moved protected health information somewhere it can never be recalled.

For years, our industry filed this under training. We wrote policies, ran modules, collected signatures and, when data walked out anyway, noted that the employee had been told not to. That is an evasion. If a system lets a well-intentioned person expose a thousand patient records in four seconds, the person is not the point of failure; the design is.

AI agents do not touch data the way software used to. A traditional integration asked for a defined slice of information on a defined schedule. An agent connected to the dental technology reads broadly, acts continuously and moves information through paths no one mapped in advance—inside systems architected when a query was something a person typed.

At the same time, building software no longer requires software developers. Natural-language coding tools now let a motivated office manager stand up a working solution in an afternoon. That democratization is good. But the person building that integration has no threat model—no sense of where the data comes to rest, which sub-processor is in the path or whether the API key they pasted into a public repository is scoped to anything. The tooling got much better at building things. It did not get better at refusing to build dangerous ones.

The cloud era gave us a tidy model: The vendor secures the platform; the customer secures its use of it. That is reasonable when the customer is an enterprise with a security team.

We support more than 70,000 dental practices. A typical one has 10 employees, no security officer and no IT department beyond a contractor who appears when the printer dies. Handing that practice a business associate agreement and calling the risk transferred is not a security program. The party with the security engineers, the threat intelligence and the view across tens of thousands of environments should carry the weight.

Permissions narrow by construction. An agent should never inherit broader access than the person who authorized it, and it should be bound to a purpose. A scheduling agent has no reason to read clinical notes and should be incapable of it.

Egress control at the interface layer. A platform should recognize patient data moving toward an unapproved destination and stop it in the moment, not describe it in a log somebody reads next quarter.

Human authorization is necessary for anything irreversible. Sending records outside the practice, deleting them, submitting them to a payor: An AI agent can prepare the action, but a person should authorize it.

Safe defaults must be present on build surfaces. If we invite people to build on our platform, and we should, de-identified data is the default and live patient data is the exception that requires review. Pointing a weekend project at production records should be hard, not one checkbox away.

Audit trails written for the practice, not the auditor: plain language, searchable and monitored by us for anomalies rather than archived and forgotten.

And the safe path has to be the fast path. When the compliant workflow is slower than the workaround, we have effectively designed the workaround. That is on the platform, not the user.

Traffic deaths fell because of seat belts, crumple zones, airbags and lane-keeping systems, not because drivers got better. Designing for human error works; exhorting humans not to err does not. Healthcare technology is at that point with AI. Training cannot be the load-bearing control when a single paste can move a chart into a model we do not govern.

Seat belts did not become standard because manufacturers volunteered. Instead, regulators required them and liability made the alternative expensive. HIPAA, by contrast, was written for defined data exchanges between known parties, and it lets a vendor discharge much of its exposure with a signed business associate agreement. That mechanism has stopped working. I am not arguing for a rulebook that specifies architectures—technology outruns any rule, and prescriptive mandates hit the 10-person practice hardest. But a floor is reasonable. Purpose-bound agentic access, egress control and human authorization for irreversible actions should not be optional or self-graded. I would rather this industry set that bar itself than have it set for us after a breach big enough to make the news.

Practices should keep asking hard questions. Do you hold SOC 2 Type 2 or HITRUST certification from an independent auditor? Who performed your last penetration test, and did you hire them to find problems or to confirm you have none? Self-attested compliance is homework that a company grades itself.

The sharper question is this: What does your platform prevent? Not what it permits. Show me the mistake your customers cannot make.

None of this is a brake on AI. The gains in healthcare are real, and I want practices adopting them faster than they are. But a platform’s measure is no longer what it makes possible. It is what it makes impossible to do by accident.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/02/stop-blaming-the-front-desk-why-healthcare-platforms-have-to-protect-against-the-mistake/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business