Legal

Asellera AI Governance Policy

Define how AI is disclosed, explained, limited, and governed in all patient-facing and clinic-facing workflows

Updated June 16, 2026

Ontario, Canada


1. PURPOSE

The purpose of this AI Governance Policy is to define the safe, ethical, and compliant use of artificial intelligence systems within Asellera.

This policy ensures that AI systems used by Asellera operate within clearly defined boundaries, do not perform regulated clinical decision-making, and remain under appropriate human oversight.


2. Scope

This policy applies to:

  • All AI systems developed or used by Asellera

  • Voice AI agents

  • SMS and messaging automation

  • Intake and form processing systems

  • SOAP note drafting tools

  • Workflow automation engines

  • Third-party AI services (e.g., LLM providers)

  • Employees, contractors, and system users


3. Core AI Principle


Asellera AI systems are designed to:

Support administrative healthcare operations, not replace clinical judgment.

AI is used to reduce workload, automate communication, and assist documentation—not to diagnose, prescribe, or determine medical treatment.


4. Approved AI Use Cases

Asellera AI systems are permitted to perform the following functions:

4.1 Administrative Automation

  • Appointment scheduling

  • Appointment confirmations and reminders

  • Rescheduling and cancellations

  • Patient routing and triage to staff

4.2 Communication Automation

  • SMS messaging

  • Voice call handling

  • Email responses (where applicable)

  • FAQ responses related to clinic operations

4.3 Intake & Data Collection

  • Collecting patient information

  • Completing intake forms

  • Gathering medical history (for clinician review only)

  • Structuring patient-provided information

4.4 Documentation Assistance

  • Drafting SOAP notes

  • Summarizing patient conversations

  • Structuring clinical notes for provider review

IMPORTANT:
All documentation is draft-only and requires human approval.

4.5 Workflow Automation

  • Triggering reminders

  • Updating CRM or PMS systems

  • Routing tasks between staff

  • Administrative follow-ups


5. Prohibited AI Use Cases

Asellera AI systems must NOT:

5.1 Clinical Decision Making

  • Diagnose diseases or conditions

  • Recommend treatments or medications

  • Interpret lab results clinically

  • Replace clinician judgment

5.2 Autonomous Medical Advice

  • Give medical instructions to patients

  • Provide emergency medical guidance beyond basic escalation

  • Suggest treatment plans

5.3 Autonomous Chart Finalization

  • Sign SOAP notes

  • Finalize clinical records

  • Submit medical documentation without provider review

5.4 Risk Scoring Without Oversight

  • Assign clinical risk scores without clinician validation

  • Make triage decisions that affect medical care priority without rules defined by clinics.


6. Human-in-the-Loop Requirement


All AI outputs that relate to patient care must follow a human-in-the-loop process.

Required Workflow:

  1. AI generates output (e.g., SOAP draft)

  2. Human clinician or authorized staff reviews

  3. Human edits or approves

  4. Human finalizes decision or record

AI outputs are assistive only and never final authority.


7. Transparency Requirements


Patients and users must be informed when interacting with AI systems where required.

Examples:

  • AI voice agents must identify as automated systems where appropriate

  • SMS communications generated by AI must not misrepresent human identity

  • Clinics are responsible for ensuring proper patient disclosure


8. Data Handling in AI Systems

8.1 Data Minimization

AI systems shall only process data necessary to perform their function.

8.2 Sensitive Data Handling

AI may process:

  • Personal health information (PHI)

  • Personal identifiable information (PII)

Only for:

  • Administrative purposes

  • Documentation assistance

  • Workflow automation

8.3 Data Storage

  • AI prompts and outputs may be logged for system improvement and auditing

  • Sensitive data must be protected under encryption and access controls

  • Data retention must follow Asellera Data Retention Policy



9. Model and Vendor Governance

Asellera may use third-party AI providers such as:

  • OpenAI or equivalent LLM providers

Requirements:

  • Vendors must be reviewed for security and privacy compliance

  • Data processing agreements must be in place where required

  • Vendor risk must be periodically reassessed


10.AI Safety Controls


No persistent memory across patients

  • No cross-tenant learning

  • No model fine-tuning on PHI without explicit authorization

  • All prompts routed through backend orchestrator only


11. Auditability and Logging


  • AI interactions must be logged for:

    • Compliance audits

    • Debugging

    • Incident investigation

    • Quality assurance

    Logs may include:

    • Input prompts

    • AI outputs

    • System actions triggered by AI


12.  Incident Escalation for AI Failures

AI-related incidents include:

  • Incorrect or harmful outputs

  • Misrouting of patients

  • Hallucinated clinical information

  • Unauthorized data exposure via AI systems

These must be handled under the Asellera Incident Response Plan.


13.Risk Classification of AI Systems

High Risk Components

  • SOAP note generation

  • Voice AI interacting with patients

  • Intake processing involving health data

Medium Risk Components

  • SMS automation

  • Scheduling agents

  • Workflow routing systems

Low Risk Components

  • Internal admin automation

  • Non-patient-facing workflows


14. Continuous Monitoring & Improvement

Asellera will:

  • Monitor AI outputs for safety and accuracy

  • Improve prompts and guardrails over time

  • Update policies as regulations evolve

  • Conduct periodic AI risk assessments


15. Compliance Alignment

This policy is designed to support alignment with:

  • Office of the Privacy Commissioner of Canada (PIPEDA)

  • Information and Privacy Commissioner of Ontario (PHIPA)

  • U.S. Department of Health and Human Services (HIPAA guidance)

  • Health Canada (medical device guidance where applicable)

  • SOC 2 Trust Services Criteria (security, availability, confidentiality)


16. Policy Exceptions

Any exceptions must:

  • Be documented

  • Be approved by leadership

  • Include risk justification

  • Be time-bound


17. Policy Review

This policy shall be reviewed:

  • Annually

  • After major product changes

  • After regulatory updates

  • After any AI-related incident


Approval

Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026