Your Health System Doesn't Have an AI Problem. It Has an Architecture Problem.
I once watched a Stripe dashboard cross $1M in a single day. I was running a DTC company, the number kept climbing, and I remember thinking we'd made it. We hadn't. The product underneath was bad, the operations were held together with tape, and scale was hiding all of it. Revenue that big buys you a very expensive delay on learning the truth.
Health systems are doing the same thing with AI right now. Buying tools, running pilots, announcing wins. The number goes up.
The foundation doesn't.
There's a sharp piece in MedCity News arguing that your healthcare AI strategy is probably an architecture problem, and I think it's one of the most honest things written about health system AI this year. Let me build on it from the trenches.
Why do AI tools pile up without compounding?
Because each tool builds its own private tunnel back to the EHR, and nothing shares a foundation. Every vendor brings its own integration, its own governance, its own audit trail (or lack of one). You end up with twelve point solutions and zero platform.
The MedCity piece nails the fix: stand up a curated, FHIR-native data layer between the EHR and every AI tool, and force new vendors to read from it instead of bypassing it. Boring work. Zero board-slide appeal. It's also the only version of this that compounds, where investment number seven builds on investment number six instead of starting from scratch.
I mean, we all know why it doesn't happen. Foundations don't demo well. Although the tide might be turning: Sentara just partnered with Infosys to build exactly this kind of governed foundation across twelve hospitals before rolling out a single flashy clinical tool. Scaffolding before spectacle.
Where should AI governance actually live?
One layer down from the applications, in the shared data and integration plane. Model versioning, lineage tracking, audit logging, human-review checkpoints, all of it at the platform level, not retrofitted inside each vendor's product.
When governance lives inside each app, every vendor model update breaks something and nobody can explain what the system did last Tuesday. When it lives in the platform, you can answer the only question that matters in a regulated industry: what happened, when, and who approved it?
This is exactly why we built HANA the way we did. Every patient interaction is logged, auditable, and reviewable at the infrastructure level. Not because a compliance checklist asked for it. Because I'm a clinical psychologist before I'm a founder, and "we can't explain what the AI said to your patient" is not a sentence I'm ever willing to say.
What makes agentic AI different from generative AI?
Generative AI reads from the chart. Agentic AI acts against it, and that difference is architectural, not incremental. An agent that books appointments, updates records, or escalates a symptom needs real-time integration, transactional reliability, and authorization boundaries that hold under load.
Voice agents calling patients are agentic by definition. They act. They schedule, they escalate, they write back. Our use cases all live on that side of the line, which forced us to solve the hard infrastructure problems years before the industry started using the word agentic in earnest.
Here's the uncomfortable part: your EHR vendor will switch on agentic features on their timeline, not yours. If your architecture is already strained by read-only AI, that gap becomes visible fast.
Why does self-hosted, open-source AI matter for health systems?
Because you can't govern what you can't see, and you can't build a foundation on infrastructure you rent by the token. When your patient engagement layer runs on a closed API, your governance ends at someone else's terms of service. Model changes without notice. Pricing changes without warning. Data flowing through systems you'll never audit.
HANA is fully open-source and self-hosted, with no OpenAI dependency. Your patient data stays inside your walls, your compliance team can inspect every layer, and the integration docs are public because infrastructure you can't verify isn't infrastructure. It's a promise. Health systems have been burned by enough promises.
Look, I'm not saying closed models have no place. I'm saying the layer that talks to your patients shouldn't be a black box.
What did a million patient interactions teach us about infrastructure?
That reliability is the product, and everything else is decoration. We've now run 1M+ patient interactions across 5 countries in 3 languages with zero critical adverse events, and the honest reason isn't a smarter model. It's the unglamorous scaffolding: escalation paths, monitoring, structured capture, humans in the loop where the stakes demand it. The evidence base behind that design is on our research page.
My daughter is 10, and I tell her the same thing I tell my team: I work for you, not the other way around. Infrastructure has the same job description. It works for the clinicians and the patients. The moment they're working around it, adapting their day to its failures, you've built the wrong thing. Scale won't save you.
It'll just hide the problem until it's expensive. Ask my Stripe dashboard.
Key Takeaways
Health system AI stalls because governance and integration get bolted onto each application instead of living in a shared platform layer beneath them. The fix is sequencing: data foundation first, FHIR-native integration layer second, AI procurement third, which is the opposite of how most systems are buying today. Agentic AI that acts on the chart is architecturally different from generative AI that reads it, and voice agents live firmly on the agentic side. Self-hosted, open-source infrastructure means your governance actually reaches the layer that touches patients. A million safe interactions taught us that boring reliability beats impressive demos, every time.
FAQ
What should health systems build before buying more AI tools?
A curated, FHIR-native data and integration layer that sits between the EHR and every AI application, with governance, audit logging, and model versioning handled at that platform level. Vendors then read from that layer instead of building private bypasses to the EHR.
Is open-source AI safe enough for clinical environments?
Transparency generally makes safety easier, not harder, because your team can audit every layer instead of trusting a vendor's claims. HANA runs open-source and self-hosted in production across 5 countries with zero critical adverse events over 1M+ interactions.
How is agentic AI regulated differently from generative AI?
Regulators care about actions, and agentic systems take them, so they need authorization boundaries, transactional audit trails, and human-review checkpoints that read-only tools don't. CMS is already piloting AI-supported prior authorization in traditional Medicare, which signals where oversight is heading.
If you're a health system or platform leader thinking about the engagement layer of your AI stack, book a discovery call and let's compare notes on architecture.
