Legal

AI TRANSPARENCY & DISCLOSURE POLICY

Define how AI is disclosed, explained, limited, and governed in all patient-facing and clinic-facing workflows

Updated June 16, 2026

Ontario, Canada


1. PURPOSE


This policy ensures that all stakeholders (patients, clinics, and internal users) are clearly informed when Artificial Intelligence (AI) is used in processing personal health information (PHI).

It establishes:

  • transparency requirements

  • disclosure obligations

  • AI limitations

  • acceptable use boundaries

  • patient understanding requirements


2. CORE PRINCIPLE


Asellera operates under the principle:

“AI assists healthcare workflows — it does not replace clinical judgment or provide medical advice.”


3. SCOPE OF AI USAGE IN ASELLERA


AI is used for:

  • Speech-to-text transcription (voice calls)

  • Message classification and routing

  • SOAP note drafting (assistive only)

  • Appointment scheduling suggestions

  • Workflow automation decisions (non-clinical)


4. STRICT PROHIBITIONS


AI within Asellera MUST NOT:

  • Provide medical diagnoses

  • Recommend treatments or prescriptions

  • Replace clinician decision-making

  • Make autonomous clinical decisions

  • Interpret symptoms as medical conclusions


5. PATIENT DISCLOSURE REQUIREMENTS


5.1 INITIAL DISCLOSURE (ALL ENTRY POINTS)


Patients must be informed before any processing occurs.


Required statement:

“This system uses artificial intelligence to assist your healthcare provider by organizing and summarizing information. It does not provide medical advice or diagnoses.


5.2 VOICE DISCLOSURE


At start of every call:

“Before we continue, please note that artificial intelligence may be used to transcribe and organize this conversation to support your healthcare provider. Do you consent to continue?”

Consent must be explicitly recorded.


5.3 SMS DISCLOSURE


First interaction message must include:

“This communication may be processed using AI tools to assist your healthcare provider.”


5.4 WEB DISCLOSURE


On intake forms:

  • AI usage checkbox must be explicitly acknowledged

  • Cannot be pre-checked


6. CLINIC DISCLOSURE REQUIREMENTS


Clinics must be informed that:

  • AI generates draft outputs only

  • All clinical notes are “assistive drafts”

  • Final approval is always clinician responsibility

  • AI does not store independent clinical memory


7. AI OUTPUT CLASSIFICATION SYSTEM


All AI outputs are classified as:


7.1 DRAFT OUTPUT (DEFAULT)

  • SOAP notes

  • summaries

  • classifications

Must be marked:

“AI-generated draft — requires human review”


7.2 SYSTEM ASSIST OUTPUT

  • scheduling suggestions

  • message routing

Non-clinical, operational only


7.3 RESTRICTED OUTPUT (BLOCKED)

  • diagnosis-like language

  • treatment suggestions

  • clinical directives

Automatically blocked or rewritten


8. HUMAN-IN-THE-LOOP REQUIREMENT

AI outputs affecting patient records MUST:

  • be reviewable by clinic staff

  • remain editable before final storage

  • never be auto-finalized without human confirmation


9. MODEL BEHAVIOR CONSTRAINTS

All AI systems must follow:

  • no hallucinated medical facts

  • no inference of diagnosis

  • structured JSON outputs only

  • confidence scoring required where applicable


10. AI DATA HANDLING RULES

  • No persistent memory across patients

  • No cross-tenant learning

  • No model fine-tuning on PHI without explicit authorization

  • All prompts routed through backend orchestrator only


11. TRANSPARENCY IN DATA FLOW

Patients and clinics are informed that:

PHI may pass through:

  • AWS (infrastructure processing)

  • Supabase (secure storage)

  • OpenAI (AI processing)

  • Retell AI (voice transcription)

  • n8n (workflow orchestration)


All vendors:

  • process data only for service execution

  • do not independently use PHI for training (per current configuration assumption)


12. ERROR HANDLING & AI FAILURE DISCLOSURE


If AI fails or produces uncertain outputs:

  • system defaults to “needs review”

  • no silent failures allowed

  • no hidden corrections


13. AI MISUSE PREVENTION

Controls include:

  • prompt injection filtering

  • PHI redaction before AI calls

  • strict system prompt enforcement

  • backend-only API access


14. AUDITABILITY REQUIREMENTS

All AI interactions must log:

  • input type (sanitized)

  • output generated

  • timestamp

  • clinic_id

  • model version


15. RISK STATEMENT

With this policy:

  • AI transparency risk: LOW

  • regulatory misunderstanding risk: LOW

  • patient trust risk: MITIGATED

  • clinical misuse risk: CONTROLLED


16. CONCLUSION

This policy ensures Asellera is:

  • transparent about AI usage

  • compliant with PHIPA/PIPEDA expectations

  • safe for clinical deployment

  • aligned with emerging healthcare AI governance standards


SIGN-OFF

Prepared By: Asellera Compliance System
Reviewed By: Legal Counsel (Pending)
Approved By: Shane Senha, CEO (collectively, the “Service”).



Legal

Terms of Use

Privacy Policy

Cookies

Support

Contact Us

Help Center

Report Abuse

Company

About Us

Careers

Press