Healthcare programs from a demonstration
How to automate a repeating EMR / payer-portal task without sending PHI to a model
The last write still lives in the EMR or a payer portal. Citrix-delivered charts are the same job, from outside the session. That write has to stay on your computer: PHI, the credentials for that system, and a delivery you must prove. OpenAdapt compiles a demonstration into a program. Later healthy runs make no generative-model API calls, so the repeating task doesn't send PHI to a model. VERIFIED means an independent check of the stored record agreed. A Seal is the signed receipt of that check. Unsigned local replay is not a Seal, and neither is a screenshot.
RCM vendors, healthcare BPOs, automation teams, and vertical-software companies already have structured input and business logic. Keep document processing, eligibility, routing, and business rules in the systems that already do them well. Then give OpenAdapt the final UI-only write and verify its effect against an independent source of truth. If the EMR already exposes that write, use the API. A computer-use agent still fits a chart you have not demonstrated. Don't put PHI on Cloud; keep it inside a customer-controlled boundary.
Two patients share a name and a date of birth. Their record numbers differ by a look-alike character. OCR reads them the same, and the program stops before it writes. See the wrong-patient defense
Citrix-delivered applications
OpenAdapt runs beside Citrix Workspace on a customer-controlled machine. It observes the remote application, checks the patient or record and workflow state, then clicks and types through the same interface as an operator. Nothing needs to be installed inside the remote Citrix session.
Local is $0. MIT. Hosted is $29/month. Enterprise goes through qualification.
Customer result
Recovering missed billables with automated RVU audits
OpenAdapt now handles the repetitive EMR evidence collection and spreadsheet reconciliation behind Dr. Victor Abrich’s monthly RVU audits. The workflow helps recover about $75,000 a year in missed billables and saves several hours of physician time each month.
Dr. Victor Abrich, MD
Board-certified cardiac electrophysiologist
A US cardiology electrophysiology practice
Disclosure: Dr. Abrich is the founder’s brother. This is OpenAdapt’s founding deployment, not independent validation.
Read the case study≈$75,000
in missed billables recovered per year
Several hours
of physician audit work saved each month
More complete
audits than manual review alone
Real application footage
OpenEMR 8.0.0.3: one synthetic patient, REST and SQL had to agree
Pinned local fixture, not a customer EMR. All 3 Standard-profile runs returned VERIFIED only after a separately authenticated REST readback matched direct SQL and a non-target delta audit. Median end-to-end runtime was 59.8 seconds. Model calls: 0. Silent incorrect success: 0/3.
Guided view synchronized to the exact retained runtime timeline; raw footage remains unchanged.
- 1DemonstrateCapture the task and its evidence.
- 2ExecuteReplay the compiled workflow locally.
- 3Verify or haltProve the effect, or stop for review.
PHI stays on the machine that already holds it
Original recordings stay local. Managed execution only accepts an approved sanitized copy that passes the destination policy. Live observations can contain PHI again, so workflows involving PHI, private systems, desktop applications, RDP, or Citrix run on a customer-controlled machine. For RDP and Citrix, that runner operates the existing remote client from outside the session rather than requiring access to the remote server.
The wrong-patient defense
Identity evidence comes before a consequential write
For a step configured with patient identity evidence, OpenAdapt halts when it cannot verify that the live record matches the demonstrated target. The public safety gallery shows the exact look-alike record cases behind this defense. A halt does not mint a Seal.
See the wrong-patient defense →Review the runtime safety model →

Attended healthcare operations
When identity is ambiguous, the runner asks one question and waits.
This synthetic OpenEMR example shows the runner-local full-evidence portal. The hosted queue uses the same signed actions and transition states without screenshots or protected fields. Both lanes use the qualified entity class for each workflow and fall back to the neutral word “record.”
Try all six decision typesThe remaining EMR or portal write
Write approved output from an existing intake, RCM, or operations pipeline into the remaining browser-only form. Prefer supported APIs for reads and writes, then use governed GUI replay only where the target exposes no suitable integration path.
OpenAdapt will not write the look-alike chart. It will not treat a painted success banner as a Seal. If the independent check cannot prove the effect, the run returns HALTED or RECONCILIATION_REQUIRED.
Qualify one repeating EMR or payer-portal workflow
Bring the application and version, monthly volume, common exceptions, and the independent success oracle for that write.