Legal
Asellera AI Governance Policy
Define how AI is disclosed, explained, limited, and governed in all patient-facing and clinic-facing workflows
Updated June 16, 2026
Ontario, Canada
1. PURPOSE
The purpose of this AI Governance Policy is to define the safe, ethical, and compliant use of artificial intelligence systems within Asellera.
This policy ensures that AI systems used by Asellera operate within clearly defined boundaries, do not perform regulated clinical decision-making, and remain under appropriate human oversight.
2. Scope
This policy applies to:
All AI systems developed or used by Asellera
Voice AI agents
SMS and messaging automation
Intake and form processing systems
SOAP note drafting tools
Workflow automation engines
Third-party AI services (e.g., LLM providers)
Employees, contractors, and system users
3. Core AI Principle
Asellera AI systems are designed to:
Support administrative healthcare operations, not replace clinical judgment.
AI is used to reduce workload, automate communication, and assist documentation—not to diagnose, prescribe, or determine medical treatment.
4. Approved AI Use Cases
Asellera AI systems are permitted to perform the following functions:
4.1 Administrative Automation
Appointment scheduling
Appointment confirmations and reminders
Rescheduling and cancellations
Patient routing and triage to staff
4.2 Communication Automation
SMS messaging
Voice call handling
Email responses (where applicable)
FAQ responses related to clinic operations
4.3 Intake & Data Collection
Collecting patient information
Completing intake forms
Gathering medical history (for clinician review only)
Structuring patient-provided information
4.4 Documentation Assistance
Drafting SOAP notes
Summarizing patient conversations
Structuring clinical notes for provider review
IMPORTANT:
All documentation is draft-only and requires human approval.
4.5 Workflow Automation
Triggering reminders
Updating CRM or PMS systems
Routing tasks between staff
Administrative follow-ups
5. Prohibited AI Use Cases
Asellera AI systems must NOT:
5.1 Clinical Decision Making
Diagnose diseases or conditions
Recommend treatments or medications
Interpret lab results clinically
Replace clinician judgment
5.2 Autonomous Medical Advice
Give medical instructions to patients
Provide emergency medical guidance beyond basic escalation
Suggest treatment plans
5.3 Autonomous Chart Finalization
Sign SOAP notes
Finalize clinical records
Submit medical documentation without provider review
5.4 Risk Scoring Without Oversight
Assign clinical risk scores without clinician validation
Make triage decisions that affect medical care priority without rules defined by clinics.
6. Human-in-the-Loop Requirement
All AI outputs that relate to patient care must follow a human-in-the-loop process.
Required Workflow:
AI generates output (e.g., SOAP draft)
Human clinician or authorized staff reviews
Human edits or approves
Human finalizes decision or record
AI outputs are assistive only and never final authority.
7. Transparency Requirements
Patients and users must be informed when interacting with AI systems where required.
Examples:
AI voice agents must identify as automated systems where appropriate
SMS communications generated by AI must not misrepresent human identity
Clinics are responsible for ensuring proper patient disclosure
8. Data Handling in AI Systems
8.1 Data Minimization
AI systems shall only process data necessary to perform their function.
8.2 Sensitive Data Handling
AI may process:
Personal health information (PHI)
Personal identifiable information (PII)
Only for:
Administrative purposes
Documentation assistance
Workflow automation
8.3 Data Storage
AI prompts and outputs may be logged for system improvement and auditing
Sensitive data must be protected under encryption and access controls
Data retention must follow Asellera Data Retention Policy
9. Model and Vendor Governance
Asellera may use third-party AI providers such as:
OpenAI or equivalent LLM providers
Requirements:
Vendors must be reviewed for security and privacy compliance
Data processing agreements must be in place where required
Vendor risk must be periodically reassessed
10.AI Safety Controls
No persistent memory across patients
No cross-tenant learning
No model fine-tuning on PHI without explicit authorization
All prompts routed through backend orchestrator only
11. Auditability and Logging
AI interactions must be logged for:
Compliance audits
Debugging
Incident investigation
Quality assurance
Logs may include:
Input prompts
AI outputs
System actions triggered by AI
12. Incident Escalation for AI Failures
AI-related incidents include:
Incorrect or harmful outputs
Misrouting of patients
Hallucinated clinical information
Unauthorized data exposure via AI systems
These must be handled under the Asellera Incident Response Plan.
13.Risk Classification of AI Systems
High Risk Components
SOAP note generation
Voice AI interacting with patients
Intake processing involving health data
Medium Risk Components
SMS automation
Scheduling agents
Workflow routing systems
Low Risk Components
Internal admin automation
Non-patient-facing workflows
14. Continuous Monitoring & Improvement
Asellera will:
Monitor AI outputs for safety and accuracy
Improve prompts and guardrails over time
Update policies as regulations evolve
Conduct periodic AI risk assessments
15. Compliance Alignment
This policy is designed to support alignment with:
Office of the Privacy Commissioner of Canada (PIPEDA)
Information and Privacy Commissioner of Ontario (PHIPA)
U.S. Department of Health and Human Services (HIPAA guidance)
Health Canada (medical device guidance where applicable)
SOC 2 Trust Services Criteria (security, availability, confidentiality)
16. Policy Exceptions
Any exceptions must:
Be documented
Be approved by leadership
Include risk justification
Be time-bound
17. Policy Review
This policy shall be reviewed:
Annually
After major product changes
After regulatory updates
After any AI-related incident
Approval
Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026
