Doctronic: The System Preserves a Physician’s Name, Not Physician Judgment
Evidence-Based Responsibility Reconstruction℠ Case Study
Utah authorized Doctronic’s artificial intelligence system to renew certain existing prescriptions without requiring a physician to review every decision.
The system can collect information from a patient, evaluate whether a prescription remains appropriate, and send the renewal authorization to a Utah pharmacist. After an initial rollout period, the agreement permits most renewals to proceed without individual physician review.
Doctronic’s current terms still designate a licensed physician as the prescriber of record and establish a physician-patient relationship—even when that physician does not review the individual renewal.
That is the responsibility problem at the center of this case.
The system preserves a physician’s name after physician judgment has left the decision. If a patient is harmed, the presence of that name may make the outcome attributable. It does not prove who actually made, controlled, monitored, or permitted the decision that caused the harm.
The Physician Can Own the Prescription Without Seeing the Decision
The Physician-Patient Relationship on Paper
What Doctronic’s Terms Establish
Doctronic’s current terms state that a physician-patient relationship is established with the physician serving as the prescriber of record. They also state that this remains true whether or not the physician reviews an individual renewal.
What the Utah Agreement Permits
The Utah agreement reinforces that structure. It anticipates circumstances in which a physician employed or contracted by Doctronic:
- Is named as the prescriber
- Acts in reliance on the AI system
- Does not communicate directly with the patient
- Does not communicate directly with another treating provider
Physician Attribution Is Not Physician Judgment
The physician’s professional identity therefore remains attached to the prescription even when the physician did not personally evaluate the patient or review the AI’s decision.
That is not the same thing as physician judgment.
A name on a prescription establishes whose credentials were used to issue it. It does not establish that the named physician independently considered the evidence, agreed with the AI, or had any opportunity to stop the renewal before it reached the pharmacy.
Doctronic converts AI decision-making into physician attribution.
Patient Consent Does Not Transfer Responsibility
What the Patient Is Told
Doctronic is not ElizaChat. Its consent structure is materially stronger.
The Utah agreement requires patients to receive a clear disclosure that artificial intelligence will be used before they access the renewal service. Patients must acknowledge the disclosure, may request physician review, and may submit complaints directly to Utah regulators.
Doctronic’s current terms also distinguish the Utah prescription-renewal service from its general informational chatbot. The company treats the renewal service as clinical care, recognizes the applicable professional standards, and does not apply its general chatbot liability limitation to these prescription decisions.
Those are meaningful controls. They do not transfer responsibility to the patient.
What the Patient Did Not Decide
| What the patient can do | What the patient did not decide |
|---|---|
|
|
Consent Does Not Transfer Institutional Responsibility
A patient can consent to receiving an AI-mediated service. That consent does not make the patient responsible for the institutional decisions that made the service available.
Human Review Declines as the System Expands
The Three-Stage Reduction in Physician Review
The agreement reduces physician involvement as the number of completed renewals increases.
The rollout follows three stages:
| Stage | Physician review |
|---|---|
| 1 | A physician reviews the first 250 renewals before the prescription is issued. |
| 2 | Physicians review the next 1,000 renewals retrospectively. |
| 3 | During full operation, physicians review a monthly sample of approximately 5% to 10% of renewals. |
The progression is based on accumulated volume. The agreement does not establish a specific safety, accuracy, or physician-agreement threshold that Doctronic must meet before moving from one stage to the next.
Autonomy Increases With Volume
That matters.
The system does not earn greater autonomy by satisfying a stated safety standard. It receives greater autonomy as the number of completed transactions increases.
The Physician’s Name Remains
Once the program reaches full operation, the agreement permits approximately 90% to 95% of renewals to proceed without individual physician review. The physician’s name remains attached throughout that transition.
The human does not disappear from the paperwork. The human disappears from most of the decisions.
AI Monitors the AI
The Automated Evaluator
Doctronic’s proposal describes a monitoring system that reviews patient interactions continuously. It includes an automated evaluator—described as an “LLM as a judge”—intended to detect problems, assess performance, and support real-time correction.
Internal Monitoring Is Not Independent Oversight
Automated monitoring may detect patterns that limited human sampling would miss. But another AI system observing the first AI is not independent oversight.
Doctronic selects the monitoring system, defines what it should detect, determines how its findings are interpreted, and controls the records it produces. The same organization operates the clinical system, monitors it, measures its performance, and reports the results to Utah.
The phrase “LLM as a judge” describes an internal technical function. It does not create an independent judge.
Shared Blind Spots Remain Possible
If both systems share blind spots, accept manipulated inputs, or evaluate success using incomplete criteria, continuous monitoring can continuously confirm the wrong thing. The existence of a monitoring model is not evidence that the model can detect the failures that matter.
An External Test Challenged the Human-Review Assumption
What Mindgard Tested
In March 2026, Mindgard published the results of an external security assessment involving Doctronic’s general chatbot and physician-consultation workflow.
What the Research Did Not Establish
The researchers did not test the Utah prescription-renewal service. They did not request or fill an actual prescription, access real patient records, or interfere with a real consultation. Their controlled test involved a different part of Doctronic’s system, and the OxyContin scenario they used falls outside the Utah renewal program.
The distinction is important. The research does not prove that the Utah renewal workflow was compromised.
What the Research Did Challenge
It does, however, challenge an assumption on which the Utah program depends: that human review reliably corrects an unsafe AI output.
Mindgard reported that its researchers manipulated the chatbot’s instructions and caused it to generate a clinical summary recommending an unsafe medication change. The AI-generated record was then prepared for the physician handoff.
When the AI Controls the Reviewer’s Evidence
A physician reviewing an AI-generated clinical record is not necessarily reviewing independent evidence. The AI may have already selected, summarized, organized, and framed the information the physician receives.
A physician agreeing with that record does not prove the physician independently reached the same judgment.
This matters because the Utah agreement measures physician review and agreement as evidence of system performance. Unless the reviewer receives an independent record or conducts an independent assessment, agreement may measure the AI’s influence over the reviewer rather than the accuracy of the original decision.
Human review cannot validate an AI decision when the AI controls the evidence the human receives.
The Reporting Response Becomes Part of the Record
Mindgard also reported attempting to disclose the issue to Doctronic before publication. According to the researchers, support tickets were routed internally but closed while they continued to consider the matter unresolved.
That does not establish how Doctronic ultimately assessed or remediated the reported weaknesses. It does show why complaint intake, internal review, and automated ticket closure must become part of the reconstruction record. A reporting channel is not a control if a consequential warning can enter the system without producing a provable response.
If a Patient Is Harmed, Responsibility Is Split Before the Investigation Begins
How Authority Is Distributed
The Utah arrangement distributes authority across several actors:
| Actor | Role in the responsibility chain |
|---|---|
| Utah | Utah authorized the regulatory experiment but expressly denied that the agreement constituted an endorsement. |
| Doctronic | Doctronic designed, operates, maintains, and monitors the system. |
| The AI systems | The AI evaluates the patient information and makes the renewal decision. A second AI monitors the first system’s interactions. |
| The physician and pharmacist | A licensed physician remains the prescriber of record. The pharmacist receives and dispenses the authorized renewal. |
| The patient | The patient experiences the physical consequences. |
How Responsibility Is Assigned After Harm
Utah’s Position
The agreement places responsibility for operating and monitoring the system on Doctronic. It also protects Utah’s Office of Artificial Intelligence Policy and Division of Professional Licensing from claims connected to Doctronic’s operation of the program.
Doctronic’s Terms
Doctronic’s current terms preserve professional standards for the renewal service and recognize that malpractice or professional-negligence claims may arise. They generally limit liability to the available professional or technology insurance coverage.
Insurance may determine what money is available after harm. It does not determine what happened.
An Error Label Is Not a Responsibility Finding
Neither “AI error” nor “physician error” would be an adequate responsibility finding. One would blame the technology without examining the institutions controlling it. The other could attach the entire outcome to a physician whose credentials were used even though the physician may never have reviewed the decision.
Doctronic Controls the Evidence Needed to Explain the Renewal
Evidence Designed for Traceability
Doctronic’s evidence design is stronger than many public AI pilots.
Monthly Reports to Utah
The agreement contemplates logged and reviewable decision points. Doctronic must provide Utah with monthly information that includes renewal volume, physician-review activity, physician agreement rates, complaints, known adverse outcomes, and selected record excerpts.
Medical Records and Audit Logs
Doctronic’s current privacy notice also says it retains medical records, AI-generated summaries, prescription records, and audit logs for at least seven years. It allows patients to request their records and says the company tracks data provenance where technically possible.
The Provider Controls the Record
That creates the possibility of tracing a disputed renewal.
It does not create independent possession of the evidence.
Doctronic generates the records, stores them, selects the monitoring technology, produces the reports, and initially determines whether an event qualifies as an error, complaint, adverse outcome, or control failure. Utah receives reports and can request additional information, but that is not the same as an independent investigator continuously holding the underlying evidence.
What an Outside Reviewer May Not Be Able to Recover
| Evidence Doctronic creates and reports | What an outside reviewer may not recover |
|---|---|
|
|
Traceable Is the Evidentiary Ceiling
The surviving record may make the renewal traceable. It does not make the decision reproducible.
A later investigator may be able to reconstruct what information entered the system, what the system produced, and which actors controlled the process. The investigator may not be able to rerun the system and prove that it would make the same decision again.
Traceable is the evidentiary ceiling.
What Responsibility Reconstruction Could Establish
What the Public Record Could Establish
Evidence-Based Responsibility Reconstruction℠ begins with the consequential conduct and follows the surviving record outward.
For a disputed Doctronic renewal, the public record could help establish:
| What the public record could establish | What the public record does not establish |
|---|---|
|
|
The Unanswered Questions Are the Responsibility Record
Those unanswered questions are not peripheral. They are the responsibility record.
Responsibility Reconstruction Finding
The Responsibility Chain
- Utah Authorized — Utah authorized the experiment.
- Doctronic Designed and Operates — Doctronic designed and operates the system.
- The AI Decides and Monitors — An AI system makes the renewal decision. Another AI system monitors the first.
- The Physician Is Named — A physician’s name remains attached whether or not the physician reviews the decision.
- The Patient Receives the Outcome — The patient receives the medical outcome.
Attribution Does Not Establish Judgment
Doctronic’s design does not eliminate human and institutional responsibility. It makes that responsibility harder to see by preserving the appearance of a traditional physician decision after judgment has been delegated to an AI system.
The physician’s name makes the prescription attributable. It does not prove physician involvement.
The patient’s consent makes participation authorized. It does not transfer responsibility for the design.
Utah’s agreement makes the program legally operable. It does not establish that Utah independently verified every control on which patient safety depends.
Doctronic’s logs may make the conduct traceable. They do not make Doctronic an independent investigator of its own system.
Naming the Error Is Not Owning Responsibility
If a patient is harmed, naming an AI error, a physician, or a technical failure will not answer the responsibility question. The investigation must establish who authorized the governing conditions, who determined the controls were sufficient, who monitored the system, who could have intervened, whether anyone exercised that authority, and what evidence survives to prove each connection.
The system preserves a physician’s name. Responsibility reconstruction must determine whether physician judgment was ever there.
Naming the error is not owning responsibility.