AI Insights Healthcare & Medical

Fred: A Patient Assistant That Guards PHI and Skips the Diagnosis

June 14, 2026 6 min read

Talk to Fred

Ask Fred about Healthcare & Medical

This is the same Fred you would put on your own site. Ask about Healthcare & Medical, compliance, or how the guardrails work. Fred listens.

A patient opens your practice’s website at 11 p.m. and types out their symptoms: chest tightness, some shortness of breath, should they be worried? A generic chatbot, eager to help, offers an assessment and a reassurance. It just practiced medicine without a license, on a patient it cannot examine, and depending on how the conversation was logged and where that data flowed, it may also have created a HIPAA problem. The practice wanted easier appointment booking. It got an unlicensed triage line wired to an ad tracker.

The threat and standard articles in this series walk through how that exposure builds. This one is the answer: what a compliant AI assistant for healthcare looks like, and why the safe version is defined by what it is built to refuse.

The Real Choice Is Governed or Ungoverned

Practices often ask whether they should use AI on the site at all. Patients have moved past that question, they expect to book, ask about hours, and get directions without waiting for the front desk to open. The decision that matters is whether the assistant is governed.

An ungoverned chatbot will assess symptoms, suggest whether a condition is serious, and capture protected health information into systems that were never set up to handle it. A governed one books the appointment, answers the logistics, and routes every clinical question to a licensed provider while handling patient data the way the rules require. Identical convenience for the patient. Entirely different legal posture for the practice.

How Fred Holds the Line

Fred inverts the default of a general chatbot. A generic tool answers anything unless told not to; Fred answers only what it is cleared to, and the boundary lives in the system rather than in a prompt that drifts.

In practice, Fred works from your practice’s own content, books and reschedules, answers logistics, and routes anything clinical, symptoms, whether something is serious, what a result means, medication questions, to a licensed provider. It handles patient information with the HIPAA Privacy and Security Rules in mind, treating identifiers as the protected data 45 CFR 160.103 defines rather than as analytics fodder, the precise failure the FTC penalized when it acted against GoodRx and BetterHelp for sharing health data with advertisers. Fred runs more than 50 industry guardrail packs, and the healthcare pack is built around the line between scheduling logistics and the practice of medicine, plus the nondiscrimination duties that Section 1557 of the ACA places on covered providers.

The strength of that design shows under pressure. A worried patient will rephrase "is this serious" five different ways, and a prompt-instructed bot eventually answers the version it was not warned about. Fred does not depend on catching the phrasing. It decides what may be said before the reply is formed, so the clinical answer never reaches the patient.

Fred vs. a Generic AI Chatbot

Situation Generic AI Chatbot Fred
"I have these symptoms, should I worry?" Offers an assessment, practicing medicine Urges appropriate care; routes to a licensed provider
"What does my test result mean?" Interprets clinical data it cannot verify Hands it to the provider; books the visit
Patient identifiers and condition May leak into analytics or ad pixels Treated as PHI; not fed to advertising tools
Where the rules live In a prompt the model can drift from Built into the system; enforced before output
A clinical question, reworded Eventually answers when phrasing changes Held the same way regardless of wording
Who owns the regulated answer Effectively the chatbot, and your practice A licensed provider, every time

That single screen is the argument. A general chatbot is helpful until helpful becomes diagnosis or a privacy breach. Fred is helpful across everything administrative and structurally incapable of the clinical and the careless.

What Your Practice Actually Gets

Step back from the regulatory framing and look at operations. Fred handles the volume that buries a front desk, booking, rescheduling, hours, directions, insurance accepted, what to bring, and it does it instantly, overnight, in plain language. It captures new-patient inquiries with context, so staff follow up prepared. Everything clinical, and everything that touches protected data, stays inside the boundaries the law draws.

There is a staffing dividend in this. The questions Fred absorbs, where do I park, do you take my plan, can I move my Tuesday appointment, are the ones that ring the front desk all day and pull staff away from the patients standing in front of them. Handing that volume to an assistant that handles it correctly, at any hour, gives the team its attention back. The phone stops being a constant interruption, and the after-hours inquiries that used to vanish by morning get captured instead.

You get the always-on scheduling and intake a practice wants from a chatbot, without the version that triages a heart-attack symptom or pipes a diagnosis into a marketing tag. That is an assistant a healthcare practice can actually run.

So the question is not whether AI belongs on your practice’s website. Patients expect it. The question is whether yours is governed before a frightened patient asks it the one thing it must never answer.

Frequently asked questions

Can a compliant healthcare assistant give any medical information?

It can share general, non-individualized information a practice already publishes, services offered, what a visit type involves, what to bring, and it always points clinical questions to a licensed provider. What it will not do is assess a specific patient’s symptoms, judge whether a condition is serious, or interpret results, because that is the practice of medicine. A compliant assistant like Fred books the visit and routes the clinical question to the provider who can actually examine the patient.

How does Fred handle HIPAA and patient data?

Fred treats patient identifiers and health details as protected information, not as analytics to be shared with advertising or tracking tools, which is exactly the conduct the FTC penalized in the GoodRx and BetterHelp cases. The design keeps PHI out of the places it does not belong and routes clinical matters to licensed staff. Specific HIPAA compliance still depends on a practice’s full configuration and agreements, so treat Fred as built to support those obligations, not as a substitute for the practice’s own program.

How is Fred different from a generic chatbot with medical guardrails in its prompt?

A prompt instruction holds until a patient phrases a question in a way the instruction did not anticipate, and a frightened patient will try many phrasings. Fred enforces its limits at the system level, deciding what is permitted before it answers, so a symptom assessment or result interpretation is never generated regardless of wording. That is the difference between a bot that usually deflects clinical questions and one that cannot answer them.

Put your own Fred to work.

You just talked to Fred above. The same agent answers your visitors from your content, captures the lead, and books the job, 24/7.