{"schema_version":"1","site":"https://decosa.ai","id":"ehr-drafts","num":"145","name":"Put the visit into your EHR as drafts","tool_name":"Put the visit into your EHR as drafts","short":"EHR drafts","blurb":"For clinicians in small practices who finish every visit by re-typing it into the EHR. Take what the visit produced (diagnosis codes, lab and imaging orders, medicine changes, the note) and an agent in your own browser enters it into the chart you have open as drafts: problems marked unconfirmed, prescriptions and orders saved but not sent, the note unsigned. It checks the chart is the visit's patient (name and date of birth read off the screen) before anything and again before every save, reads each medicine against the transcript and holds any that differ, never types a controlled substance, and stops before sign. Signing, transmitting, sending and e-prescribing are held in the browser's network layer whatever the button says. You get a checklist of what went where with the transcript line behind each value, and a copy list for what it could not enter. Where an EHR's terms forbid tools in your session, you get the copy list only.","status":"preview","labels":{"industry":["healthcare"],"job":["draft","act"],"input":["text"],"deploy":["selfhost"],"status":"preview","output":["text","record"],"data":["phi"],"hardware":"gpu-96","licence":"permissive"},"industries":["healthcare"],"runs_in":["selfhost"],"part_of":[],"built_from":["flight-recorder","signed-record"],"models":"Qwen3.8-27B (drives the forms) · decosa-note-detail-checker (M17, reads each medicine against the transcript, CPU) · decosa-commit-detector (flags buttons that commit, CPU)","where":"Works today with self-hosted OpenEMR, in the clinician's own browser; commercial EHRs through each vendor's official API (not yet available). Hosted demo: made-up patients only","hardware":"1x RTX PRO 6000 (96 GB) for Qwen3.8-27B; the medicine check and the commit detector run on CPU","final_artifact":"Drafts in your EHR (unsigned), a checklist of what went where with its transcript line, a copy list for the rest, the requests the gate held, and a signed record.","self_host_first":true,"verification":{"receipt_coverage":"full","summary":"Chart identifiers read off the screen before any entry and before every save; every typed value from the visit output; the form compared with the visit in code before its one save; sign/send/transmit held at the network layer; signed flight record of every step","manual_qa":{"hosted":{"date":"2026-09-29","result":"pass","p50_ms":90300,"p95_ms":162900,"runs":32,"receipts_per_run":null,"cost_per_run_usd":0.0341},"selfhost":null,"known_limits":["Measured on one EHR only: self-hosted OpenEMR 7.0.3 with made-up patients. A second open-source EHR (OpenMRS O3) was tried and did not start cleanly; not measured.","Not yet packaged as the browser extension; the engine ran in a test browser against the test EHR.","A prescription whose quantity was not said goes to your list (OpenEMR requires a quantity, and the agent never guesses one).","The medicine check wrongly held 2 of 28 correct medicines (an inhaler whose route was said).","The entries are saved under your login, so the EHR's audit log shows you; each draft's comment or note says it came from ehr-drafts, and the signed record shows every step.","About 1.5 to 3 minutes per visit on a shared model; no batch mode yet."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Typed or picked values wrong (read back from the EHR's database)","value":"0 / 419","unit":null,"n":419,"split":"synthetic","note":"95% CI 0-0.91%. 32 synthetic visits, clean run 2 (quantity and refills only when said). Run 1: 0 / 534."},{"name":"Items entered, of those the rules allow the agent to enter","value":"101 / 104","unit":null,"n":104,"split":"synthetic","note":"Misses: 2 inhalers wrongly held by the medicine check, 1 lab order the agent could not finish. Left for you by rule: 14 prescriptions with no quantity said, 2 controlled substances, stops and follow-ups."},{"name":"Wrong-patient attempts that wrote to another chart","value":"0 / 20","unit":null,"n":20,"split":"synthetic","note":"16 wrong charts open at the start (near-duplicate name, date of birth or MRN; another patient): stopped with 0 entries. 4 chart switches mid-run: caught before the next save."},{"name":"Forced sign, transmit, send, fax, e-mail, bill and delete requests held","value":"80 / 80","unit":null,"n":80,"split":"synthetic","note":"8 kinds x 10 visits, sent from inside the page after the drafts; plus 16 of 16 clicks on the app's own eSign, Transmit Order and Fax buttons held."},{"name":"Planted medicine errors flagged by the medicine check","value":"90 / 90","unit":null,"n":90,"split":"synthetic","note":"Dose, frequency, drug (sound-alikes) and duration; sound-alike pairs written after the fix: 28 / 28. End to end: 8 of 8 never entered."},{"name":"Planted instructions in the chart that caused harm","value":"0 / 10","unit":null,"n":10,"split":"synthetic","note":"Encounter reason or an intake note, English and Spanish; 9 of 10 runs paused on the text."},{"name":"Correct medicines wrongly held by the medicine check","value":"2 / 28","unit":null,"n":28,"split":"synthetic","note":"Both an inhaler with a spoken route."}],"dataset":"32 synthetic primary-care visits (18 templates, made-up patients): items fixed in code as the ground truth, transcripts written by Qwen3.8-27B around them, on a self-hosted OpenEMR 7.0.3 test instance.","held_out":false,"caveats":["Synthetic visits and transcripts; the model that wrote the transcripts is the model that drives the agent.","One EHR (OpenEMR). The agent's instructions per form (the EHR profile) were written while testing on the same forms.","The medicine checker was trained on Qwen-written visits; its numbers on these transcripts are likely optimistic.","Values were checked against the visit output, not against what a clinician would have wanted: a wrong visit output would be copied faithfully.","Transcripts were patched twice before the measured runs, both recorded: amounts per dose, and quantities and refills said in half the visits.","Two blind cold users (a solo physician: maybe / maybe; a practice manager: no / no) read a one-page description; neither used it on real work."],"date":"2026-09-29","doc_url":null},"stack":{"summary":"For clinicians in small practices who re-type every visit into the EHR. An agent in your own browser enters what the visit produced (ICD-10-CM problems, lab and imaging orders, new prescriptions and dose changes, the SOAP note) into the chart you have open as drafts: problems unconfirmed, prescriptions saved but not sent, orders saved but not transmitted, the note unsigned. It reads the patient's name and date of birth off the screen before anything and before every save, reads each medicine against the transcript and holds any that differ, types a quantity or refill count only if it was said, never drafts a controlled substance, and stops before sign: signing, transmitting, sending and e-prescribing are held in the browser's network layer whatever a button says. It types only where the EHR's terms allow a tool in your session (today: self-hosted OpenEMR); every other EHR gets the same checklist as a copy list.","tagline":"Works today with self-hosted OpenEMR: the visit's codes, orders, prescriptions and note typed in as unsigned drafts. You sign.","deployment":"self-host-first","regulatory_note":"Checked 28 Sep 2026; not legal advice. FDA: suggested codes and orders a clinician can review, each with the transcript line behind it and nothing time-critical, fit the non-device clinical decision support criteria (FD&C Act 520(o)(1)(E); FDA guidance of 29 Jan 2026). DEA: controlled-substance e-prescriptions are signed only by the prescriber through their own two-factor authentication (21 CFR 1311.135, 1311.140); this tool never drafts one and never touches a sign screen. HIPAA: hosting or relaying chart data makes Decosa a business associate (45 CFR 160.103); no BAA is signed yet, so the hosted demo is synthetic only and real use runs the model in the practice's network. EHR terms: eClinicalWorks, DrChrono and TherapyNotes forbid tools in the customer's session in their own terms (read 28 Sep 2026); Practice Fusion, Tebra and SimplePractice restrict it or could not be read; those EHRs get the copy list. CPT codes are not shown or typed (AMA licence pending); diagnoses are ICD-10-CM and tests carry LOINC codes. Texas SB 1188 requires telling patients when AI is used for diagnosis or treatment recommendations.","components":[{"id":"agent","role":"The agent that fills the EHR's forms: one receipted decision per step, values only from the visit, the one draft save released after the chart and form are checked in code","name":"Qwen3.8-27B on the Decosa computer-use engine","hf_repo":"Qwen/Qwen3.8-27B-FP8","license":"Apache-2.0","params":"27B","quant":"NVFP4","vram_gb":20,"memory_gb_estimate":null,"engine":"vLLM","receipt_coverage":"none","in_hosted_demo":null,"tiers":[],"alternative_to":null},{"id":"medcheck","role":"Reads each medicine (drug, dose, frequency, route when said, duration) against the transcript lines it came from","name":"decosa-note-detail-checker (M17)","hf_repo":"decosaai/decosa-note-detail-checker-modernbert-large","license":"Apache-2.0","params":"0.4B","quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"PyTorch (CPU)","receipt_coverage":"partial","in_hosted_demo":null,"tiers":[],"alternative_to":null},{"id":"gate","role":"Holds sign, finalise, transmit, send, fax, e-prescribe, bill and delete requests in the browser; releases each draft save once","name":"decosa-api ehr-drafts and the computer-use network gate","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12, Playwright / Chrome DevTools Protocol","receipt_coverage":"partial","in_hosted_demo":null,"tiers":[],"alternative_to":null}],"tiers":[{"id":"standard","label":"Standard · one GPU for the model","summary":"Qwen3.8-27B drives the forms; the medicine checker runs on CPU. What the eval measured.","components":["agent","medcheck","gate"],"hardware":"1x RTX PRO 6000 96 GB (measured)","quality_evidence":[{"metric":"Typed and picked values wrong, read back from the EHR's database (32 synthetic visits)","value":"0 / 419","source":"decosa-api docs/evals/ehr-drafts.md, clean run 2, 2026-09-29 (run 1: 0 / 534)"},{"metric":"Wrong-patient attempts that wrote to another chart","value":"0 / 20","source":"decosa-api docs/evals/ehr-drafts.md, 2026-09-29"},{"metric":"Planted wrong doses, drugs, frequencies and durations flagged by the medicine check","value":"90 / 90","source":"decosa-api docs/evals/ehr-drafts.md, 2026-09-29"}],"latency_note":null,"in_hosted_demo":null,"receipt_coverage":null,"receipt_note":null,"hosting":null}],"alternates":[],"services":[{"name":"decosa-api","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:<tag>","purpose":"GET /ehr-drafts/info, /ehr-drafts/gate, /ehr-drafts/samples; POST /ehr-drafts/check (the medicine check and the review for your EHR; touches no EHR), POST /ehr-drafts/ack (your signed acknowledgement)."},{"name":"vLLM (model)","port":8114,"image":"vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1","purpose":"Qwen3.8-27B for the agent, in your network (self-host) or through our gateway once a BAA is signed."},{"name":"note-detail checker","port":8495,"image":null,"purpose":"The medicine check, on CPU: a small FastAPI service in decosa-api (services/detail_checker, systemd unit decosa-detail-checker); no published image yet."}],"tools":[{"name":"ICD-10-CM 2026 code set (CMS/NCHS order file)","url":"https://www.cms.gov/files/zip/2026-code-descriptions-tabular-order.zip","license":"US government publication","purpose":"Diagnosis codes on the problem list; the test EHR's code picker."},{"name":"LOINC","url":"https://loinc.org/","license":"LOINC licence (free, with notice)","purpose":"Codes for the lab and imaging tests; names shown in our own words."},{"name":"DEA controlled substance schedules (21 CFR 1308)","url":"https://www.deadiversion.usdoj.gov/schedules/orangebook/c_cs_alpha.pdf","license":"US government publication","purpose":"Controlled substances are never drafted."},{"name":"RxNorm Current Prescribable Content (NLM)","url":"https://www.nlm.nih.gov/research/umls/rxnorm/docs/prescribe.html","license":"Public; no licence required","purpose":"Every medicine name is resolved to its ingredients (brand, salt and combination names), from a snapshot bundled with the code. A name that resolves to no known drug is held, not drafted."},{"name":"openFDA NDC directory (FDA)","url":"https://open.fda.gov/apis/drug/ndc/","license":"Public domain (CC0)","purpose":"The DEA schedule of each ingredient: a medicine is held when any ingredient is scheduled."}],"hardware":[{"tier":"1x RTX PRO 6000 Blackwell 96 GB","fits":true,"notes":"Measured: the eval ran the agent against the model on our server, shared with other workloads."},{"tier":"Any laptop or desktop for the browser side","fits":true,"notes":"The agent drives a browser tab; the medicine checker runs on CPU."}],"latency":[{"lane":"one visit (4-5 items) entered by the agent on the synthetic OpenEMR, 3 visits in parallel on a shared model","typical_ms":90300,"source":"measured on our server 2026-09-29: p50 over 32 visits (p95 162.9 s), direct route; 188.6 s p50 in an earlier run under heavier load"},{"lane":"the hosted check (medicine check and the review for your EHR)","typical_ms":2013,"source":"measured on our server 2026-09-29: smoke module on the pre-release server"}],"benchmark":null,"notes":[]},"buyer_facts":[{"label":"What it gives you","value":"Drafts in your EHR (unsigned), a checklist of what went where with the transcript line behind each value, a copy list for what it could not enter, every request the gate held, and a signed record of the run."},{"label":"What it never does","value":"Sign, finalise, transmit an order, send, fax, e-mail or e-prescribe; draft a controlled substance; type a value the visit did not give (a quantity or refill count nobody said stays blank); edit or delete an existing entry."},{"label":"Where it may type","value":"Works today with self-hosted OpenEMR (open source). Commercial EHRs (eClinicalWorks, DrChrono, athenaOne and others) come through each vendor's official API, not yet available; until then they get the copy list. The hosted demo uses made-up patients only."},{"label":"Data retention","value":"The hosted check keeps nothing: the visit lives in memory for the request, logs carry counts only. The agent's signed record holds hashes of the patient identifiers, never their text, and stays with the practice."},{"label":"What leaves the box","value":"Self-hosted, nothing: the agent, the model and the checker run in your network. Our hosted model would see chart screens, so it waits for a BAA."}],"data_handling":{"page":"/data#ehr-drafts","self_host":{"level":"confidential","leaves":"nothing","summary":"Runs on your machine; nothing is sent to Decosa or a third party by default."},"hosted":{"level":"operator-processed","demo_only":true,"summary":"Hosted demo on sample or public data only; self-host for real data.","gpus":"operator-contracted","third_parties":[],"retention":"The hosted check keeps nothing: the visit lives in memory for the request, logs carry counts only. The agent's signed record holds hashes of the patient identifiers, never their text, and stays with the practice.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[{"to":"Decosa's model gateway (Qwen3.8-27B)","route":"hosted","sends":"content","what":"Screens of the EHR form and the visit's values for each step, when the agent uses our hosted model. Needs a BAA first; the hosted demo is synthetic only.","default":"off","off":null},{"to":"Your EHR (the tab you have open)","route":"both","sends":"your-system","what":"The drafts, typed into your own session; nothing is signed or sent.","default":"always","off":null}]},"console":{"href":"/clinics/ehr-drafts","input":"runner","lanes":[{"id":"patient","title":"Right patient","kind":"list"},{"id":"medicines","title":"Medicines checked","kind":"list"},{"id":"drafts","title":"Drafts entered","kind":"list"},{"id":"yours","title":"For you to enter","kind":"list"},{"id":"record","title":"Held and signed","kind":"json"}],"samples":[{"n":1,"id":"diabetes-followup","title":"Diabetes followup","deep_link":"/clinics/ehr-drafts?sample=1&autorun=0"},{"n":2,"id":"uti","title":"Uti","deep_link":"/clinics/ehr-drafts?sample=2&autorun=0"},{"n":3,"id":"insomnia-controlled","title":"Insomnia controlled","deep_link":"/clinics/ehr-drafts?sample=3&autorun=0"},{"n":4,"id":"wrong-dose-planted","title":"Wrong dose planted","deep_link":"/clinics/ehr-drafts?sample=4&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/ehr-drafts-hosted.md","selfhost":"/prompts/ehr-drafts-selfhost.md","assemble":null,"mac":null},"rehearsal":null,"hardware_fit":{"check":"/self-host/hardware?use=ehr-drafts","data":"/api/hardware.json","tiers":[{"id":"standard","gpu_gb":33.6,"basis":"stack","unknown":[]}],"mac":null},"links":{"page":"/clinics/ehr-drafts","json":"/use-cases/ehr-drafts.json","metrics":"/metrics/ehr-drafts","console":"/clinics/ehr-drafts","console_sample":"/clinics/ehr-drafts?sample=1&autorun=0","stack":"/clinics/ehr-drafts#stack","try_live":"/clinics/ehr-drafts","watch":"/clinics/ehr-drafts","build":"/clinics/ehr-drafts#build","self_host":"/clinics/ehr-drafts#self-host","prompts":{"hosted":"/prompts/ehr-drafts-hosted.md","selfhost":"/prompts/ehr-drafts-selfhost.md","assemble":"/prompts/ehr-drafts-assemble.md","mac":null}}}