Healthcare programs from a demonstration

How to automate a repeating EMR / payer-portal task without sending PHI to a model

The last write still lives in the EMR or a payer portal. Citrix-delivered charts are the same job, from outside the session. That write has to stay on your computer: PHI, the credentials for that system, and a delivery you must prove. OpenAdapt compiles a demonstration into a program. Later healthy runs make no generative-model API calls, so the repeating task doesn't send PHI to a model. VERIFIED means an independent check of the stored record agreed. A Seal is the signed receipt of that check. Unsigned local replay is not a Seal, and neither is a screenshot.

RCM vendors, healthcare BPOs, automation teams, and vertical-software companies already have structured input and business logic. Keep document processing, eligibility, routing, and business rules in the systems that already do them well. Then give OpenAdapt the final UI-only write and verify its effect against an independent source of truth. If the EMR already exposes that write, use the API. A computer-use agent still fits a chart you have not demonstrated. Don't put PHI on Cloud; keep it inside a customer-controlled boundary.

Two patients share a name and a date of birth. Their record numbers differ by a look-alike character. OCR reads them the same, and the program stops before it writes. See the wrong-patient defense

Citrix-delivered applications

OpenAdapt runs beside Citrix Workspace on a customer-controlled machine. It observes the remote application, checks the patient or record and workflow state, then clicks and types through the same interface as an operator. Nothing needs to be installed inside the remote Citrix session.

Local is $0. MIT. Hosted is $29/month. Enterprise goes through qualification.

Customer result

Recovering missed billables with automated RVU audits

OpenAdapt now handles the repetitive EMR evidence collection and spreadsheet reconciliation behind Dr. Victor Abrich’s monthly RVU audits. The workflow helps recover about $75,000 a year in missed billables and saves several hours of physician time each month.

Dr. Victor Abrich, MD
Board-certified cardiac electrophysiologist
A US cardiology electrophysiology practice

Disclosure: Dr. Abrich is the founder’s brother. This is OpenAdapt’s founding deployment, not independent validation.

Read the case study

≈$75,000

in missed billables recovered per year

Several hours

of physician audit work saved each month

More complete

audits than manual review alone

Real application footage

OpenEMR 8.0.0.3: one synthetic patient, REST and SQL had to agree

Pinned local fixture, not a customer EMR. All 3 Standard-profile runs returned VERIFIED only after a separately authenticated REST readback matched direct SQL and a non-target delta audit. Median end-to-end runtime was 59.8 seconds. Model calls: 0. Silent incorrect success: 0/3.

OpenAdaptObservingStep 1 of 33Observing the application
0:00 / 0:00Evidence

Guided view synchronized to the exact retained runtime timeline; raw footage remains unchanged.

  1. 1
    DemonstrateCapture the task and its evidence.
  2. 2
    ExecuteReplay the compiled workflow locally.
  3. 3
    Verify or haltProve the effect, or stop for review.

PHI stays on the machine that already holds it

Original recordings stay local. Managed execution only accepts an approved sanitized copy that passes the destination policy. Live observations can contain PHI again, so workflows involving PHI, private systems, desktop applications, RDP, or Citrix run on a customer-controlled machine. For RDP and Citrix, that runner operates the existing remote client from outside the session rather than requiring access to the remote server.

The wrong-patient defense

Identity evidence comes before a consequential write

For a step configured with patient identity evidence, OpenAdapt halts when it cannot verify that the live record matches the demonstrated target. The public safety gallery shows the exact look-alike record cases behind this defense. A halt does not mint a Seal.

See the wrong-patient defense →Review the runtime safety model →

OpenAdapt mobile portal requesting an identity check before Save
Runner-local portal example · synthetic OpenEMR data · the hosted lane omits screenshots

Attended healthcare operations

When identity is ambiguous, the runner asks one question and waits.

This synthetic OpenEMR example shows the runner-local full-evidence portal. The hosted queue uses the same signed actions and transition states without screenshots or protected fields. Both lanes use the qualified entity class for each workflow and fall back to the neutral word “record.”

Try all six decision types

The remaining EMR or portal write

Write approved output from an existing intake, RCM, or operations pipeline into the remaining browser-only form. Prefer supported APIs for reads and writes, then use governed GUI replay only where the target exposes no suitable integration path.

OpenAdapt will not write the look-alike chart. It will not treat a painted success banner as a Seal. If the independent check cannot prove the effect, the run returns HALTED or RECONCILIATION_REQUIRED.

Qualify one repeating EMR or payer-portal workflow

Bring the application and version, monthly volume, common exceptions, and the independent success oracle for that write.

Or book a 30-minute call