Every practice weighing up an agent is asking the same question, in clinical governance meetings and between patients. Who checked this before it reached the chart? Clinicians won’t accept reassurance as the answer. They want to see how the agent behaves, where it stops, and who can stop it.
Until now, AI in the clinic helped draft notes, and the engineering questions were about transcript accuracy and output format. With Heidi II, our agents can now act. Heidi can handle the visit prep, the follow-up list, and the chart update, and each of those actions reaches further than a note does.
In healthcare, an agent’s mistakes reach real people. A wrong medication written back to the chart or a follow-up sent to the wrong patient can land with patients, payers or another clinician, and the record stays in the chart. The test for any agent is whether you’d put your name to its work.
Medicine already builds friction in where the stakes are high, from the surgical safety checklist to the independent double-check on high-risk medications. We built our agents on the same principle, a bar we think every healthcare agent should meet. By default, drafts wait for a clinician's review and a write-back pauses at the chart.
Many people on our team have a clinical background, and some still work in clinics. We know what safety means in practice, the same way you do, and that shaped three decisions in how our agents work.
Clinical judgment stays with clinicians and their practice
The clinician responsible for a patient’s care should control any agent acting on it. An agent can send a message, update a chart, or reach information in an EHR, inbox or external system, and each of those actions carries clinical responsibility.
Our agents start in Manual mode, where you watch them work and approve each step. Supervising a new registrar works the same way. You review their work closely at first, then loosen oversight as they earn your trust with each task. Where appropriate, you can switch to Auto mode so agentic flows and Routines run on their own, and you should still check from time to time that they run as intended.
Reviewing every step has a cost too. A clinician who approves dozens of low-risk steps a day will start approving them without reading, and a review that has become a reflex no longer protects the patient. Auto mode exists for the tasks you’ve come to trust, so your attention goes to the steps that carry clinical consequence. When a task is unclear, or the next step falls outside what was asked, the agent comes back to you for clarification. It carries out the tasks you direct, in the mode you set.
Agents are built for clinicians, by clinicians
An agent built for clinical work should be shaped and tested by clinicians. Engineers can measure whether an agent completes a task. Judging whether it completed the task the way care requires takes clinical expertise. Our clinical safety team designed, evaluated and stress-tested our agents for clinical usefulness, functional reliability and safety, and continues to monitor them in use.
Before launch, we tested our agents alongside over a thousand clinicians. Our engineers and product teams worked with them directly, looking for the moments where an agent behaved in ways a clinician would not expect. We also tested against difficult edge cases and deliberate misuse, to make our agents as resistant as possible to being pointed in the wrong direction.
No AI system is 100% accurate, and agents are no exception. Clinician review is built in for that reason. Staying in the loop matters as much with an agent as it does with any colleague whose work you sign.
Patient privacy is critical across our entire platform
Patient data should stay under the control of the clinicians and organizations it belongs to. You answer to your patients, your practice and your regulator for how that data is handled, and an agent reaches into more systems than a scribe does. Clinicians will only grant that access if they can trust where the data goes.
We never use identifiable patient health information to train our models. What our agents produce belongs to you and your organization, not to Heidi. Our security controls are independently audited to SOC 2 Type II, ISO 27001 and ISO 42001, which together cover the protection of sensitive health data, the management of AI systems and their risks, and secure operational practice.
Agents are moving into work across industries worldwide, and healthcare is already part of that shift. For healthcare, the open question is how agents should act when the work reaches a patient. We think the answer is friction by design, with the clinician in control, and that’s the standard every agent in healthcare should meet. Over the coming months, we’ll share more on how we evaluate our agents, our learnings, and what’s next.
Heidi II begins rolling out globally today, in English, with more languages in the coming weeks. On a managed account, your Heidi team will work through the right setup for your organization, and where you need something that doesn't exist yet, we'll embed engineers to build it. Heidi II is coming to Asia and the Middle East, and is not available in the EU and UK.


