Services Case Studies Webinar Blog News & Press Events About Request a Briefing
Home  /  Case Studies  /  Doctronic
Evidence-Based Responsibility Reconstruction℠ for AI-Mediated Conduct

Doctronic: The System Preserves a Physician’s Name, Not Physician Judgment

AI use Prescription renewals
Human checkpoint Phased clinical review
Evidence source Provider reports and review samples
Reconstruction finding Named responsibility not demonstrated

Evidence-Based Responsibility Reconstruction℠ Case Study

Utah authorized Doctronic’s artificial intelligence system to renew certain existing prescriptions without requiring a physician to review every decision.

The system can collect information from a patient, evaluate whether a prescription remains appropriate, and send the renewal authorization to a Utah pharmacist. After an initial rollout period, the agreement permits most renewals to proceed without individual physician review.

Doctronic’s current terms still designate a licensed physician as the prescriber of record and establish a physician-patient relationship—even when that physician does not review the individual renewal.

That is the responsibility problem at the center of this case.

The system preserves a physician’s name after physician judgment has left the decision. If a patient is harmed, the presence of that name may make the outcome attributable. It does not prove who actually made, controlled, monitored, or permitted the decision that caused the harm.

What Utah Authorized

The Regulatory Experiment

In October 2025, the Utah Office of Artificial Intelligence Policy and the Utah Division of Professional Licensing entered into a regulatory mitigation agreement with Doctronic. Utah publicly launched the program in January 2026 as an experiment in AI-authorized prescription renewals.

What the AI Is Permitted to Do

Under the agreement, Doctronic’s system can:

  • Verify the patient and the existing prescription
  • Collect medical history and current symptoms
  • Review medication information and potential interactions
  • Determine whether the prescription is appropriate for renewal
  • Send an approved renewal to a Utah pharmacist
  • Escalate selected cases to a physician

The patient may request human review, and a pharmacist can escalate a renewal for physician review. Doctronic also established criteria intended to identify cases the AI should not complete independently.

The Consequential Decision Remains With the AI

Those safeguards do not change the central fact: Utah authorized the AI system to make a consequential clinical decision.

This was not merely an AI system organizing information for a doctor. The system was authorized to decide whether a qualifying prescription should be renewed.

The Physician Can Own the Prescription Without Seeing the Decision

The Physician-Patient Relationship on Paper

What Doctronic’s Terms Establish

Doctronic’s current terms state that a physician-patient relationship is established with the physician serving as the prescriber of record. They also state that this remains true whether or not the physician reviews an individual renewal.

What the Utah Agreement Permits

The Utah agreement reinforces that structure. It anticipates circumstances in which a physician employed or contracted by Doctronic:

  • Is named as the prescriber
  • Acts in reliance on the AI system
  • Does not communicate directly with the patient
  • Does not communicate directly with another treating provider

Physician Attribution Is Not Physician Judgment

The physician’s professional identity therefore remains attached to the prescription even when the physician did not personally evaluate the patient or review the AI’s decision.

That is not the same thing as physician judgment.

A name on a prescription establishes whose credentials were used to issue it. It does not establish that the named physician independently considered the evidence, agreed with the AI, or had any opportunity to stop the renewal before it reached the pharmacy.

Doctronic converts AI decision-making into physician attribution.

Human Review Declines as the System Expands

The Three-Stage Reduction in Physician Review

The agreement reduces physician involvement as the number of completed renewals increases.

The rollout follows three stages:

StagePhysician review
1 A physician reviews the first 250 renewals before the prescription is issued.
2 Physicians review the next 1,000 renewals retrospectively.
3 During full operation, physicians review a monthly sample of approximately 5% to 10% of renewals.

The progression is based on accumulated volume. The agreement does not establish a specific safety, accuracy, or physician-agreement threshold that Doctronic must meet before moving from one stage to the next.

Autonomy Increases With Volume

That matters.

The system does not earn greater autonomy by satisfying a stated safety standard. It receives greater autonomy as the number of completed transactions increases.

The Physician’s Name Remains

Once the program reaches full operation, the agreement permits approximately 90% to 95% of renewals to proceed without individual physician review. The physician’s name remains attached throughout that transition.

The human does not disappear from the paperwork. The human disappears from most of the decisions.

AI Monitors the AI

The Automated Evaluator

Doctronic’s proposal describes a monitoring system that reviews patient interactions continuously. It includes an automated evaluator—described as an “LLM as a judge”—intended to detect problems, assess performance, and support real-time correction.

Internal Monitoring Is Not Independent Oversight

Automated monitoring may detect patterns that limited human sampling would miss. But another AI system observing the first AI is not independent oversight.

Doctronic selects the monitoring system, defines what it should detect, determines how its findings are interpreted, and controls the records it produces. The same organization operates the clinical system, monitors it, measures its performance, and reports the results to Utah.

The phrase “LLM as a judge” describes an internal technical function. It does not create an independent judge.

Shared Blind Spots Remain Possible

If both systems share blind spots, accept manipulated inputs, or evaluate success using incomplete criteria, continuous monitoring can continuously confirm the wrong thing. The existence of a monitoring model is not evidence that the model can detect the failures that matter.

An External Test Challenged the Human-Review Assumption

What Mindgard Tested

In March 2026, Mindgard published the results of an external security assessment involving Doctronic’s general chatbot and physician-consultation workflow.

What the Research Did Not Establish

The researchers did not test the Utah prescription-renewal service. They did not request or fill an actual prescription, access real patient records, or interfere with a real consultation. Their controlled test involved a different part of Doctronic’s system, and the OxyContin scenario they used falls outside the Utah renewal program.

The distinction is important. The research does not prove that the Utah renewal workflow was compromised.

What the Research Did Challenge

It does, however, challenge an assumption on which the Utah program depends: that human review reliably corrects an unsafe AI output.

Mindgard reported that its researchers manipulated the chatbot’s instructions and caused it to generate a clinical summary recommending an unsafe medication change. The AI-generated record was then prepared for the physician handoff.

When the AI Controls the Reviewer’s Evidence

A physician reviewing an AI-generated clinical record is not necessarily reviewing independent evidence. The AI may have already selected, summarized, organized, and framed the information the physician receives.

A physician agreeing with that record does not prove the physician independently reached the same judgment.

This matters because the Utah agreement measures physician review and agreement as evidence of system performance. Unless the reviewer receives an independent record or conducts an independent assessment, agreement may measure the AI’s influence over the reviewer rather than the accuracy of the original decision.

Human review cannot validate an AI decision when the AI controls the evidence the human receives.

The Reporting Response Becomes Part of the Record

Mindgard also reported attempting to disclose the issue to Doctronic before publication. According to the researchers, support tickets were routed internally but closed while they continued to consider the matter unresolved.

That does not establish how Doctronic ultimately assessed or remediated the reported weaknesses. It does show why complaint intake, internal review, and automated ticket closure must become part of the reconstruction record. A reporting channel is not a control if a consequential warning can enter the system without producing a provable response.

If a Patient Is Harmed, Responsibility Is Split Before the Investigation Begins

How Authority Is Distributed

The Utah arrangement distributes authority across several actors:

ActorRole in the responsibility chain
Utah Utah authorized the regulatory experiment but expressly denied that the agreement constituted an endorsement.
Doctronic Doctronic designed, operates, maintains, and monitors the system.
The AI systems The AI evaluates the patient information and makes the renewal decision. A second AI monitors the first system’s interactions.
The physician and pharmacist A licensed physician remains the prescriber of record. The pharmacist receives and dispenses the authorized renewal.
The patient The patient experiences the physical consequences.

How Responsibility Is Assigned After Harm

Utah’s Position

The agreement places responsibility for operating and monitoring the system on Doctronic. It also protects Utah’s Office of Artificial Intelligence Policy and Division of Professional Licensing from claims connected to Doctronic’s operation of the program.

Doctronic’s Terms

Doctronic’s current terms preserve professional standards for the renewal service and recognize that malpractice or professional-negligence claims may arise. They generally limit liability to the available professional or technology insurance coverage.

Insurance may determine what money is available after harm. It does not determine what happened.

An Error Label Is Not a Responsibility Finding

Neither “AI error” nor “physician error” would be an adequate responsibility finding. One would blame the technology without examining the institutions controlling it. The other could attach the entire outcome to a physician whose credentials were used even though the physician may never have reviewed the decision.

Doctronic Controls the Evidence Needed to Explain the Renewal

Evidence Designed for Traceability

Doctronic’s evidence design is stronger than many public AI pilots.

Monthly Reports to Utah

The agreement contemplates logged and reviewable decision points. Doctronic must provide Utah with monthly information that includes renewal volume, physician-review activity, physician agreement rates, complaints, known adverse outcomes, and selected record excerpts.

Medical Records and Audit Logs

Doctronic’s current privacy notice also says it retains medical records, AI-generated summaries, prescription records, and audit logs for at least seven years. It allows patients to request their records and says the company tracks data provenance where technically possible.

The Provider Controls the Record

That creates the possibility of tracing a disputed renewal.

It does not create independent possession of the evidence.

Doctronic generates the records, stores them, selects the monitoring technology, produces the reports, and initially determines whether an event qualifies as an error, complaint, adverse outcome, or control failure. Utah receives reports and can request additional information, but that is not the same as an independent investigator continuously holding the underlying evidence.

What an Outside Reviewer May Not Be Able to Recover

Evidence Doctronic creates and reports What an outside reviewer may not recover
  • Logged and reviewable decision points
  • Renewal volume
  • Physician-review activity
  • Physician agreement rates
  • Complaints and known adverse outcomes
  • Selected record excerpts
  • Medical records and AI-generated summaries
  • Prescription records and audit logs
  • The exact model and version used for a particular renewal
  • The governing system instructions
  • The complete patient interaction
  • Every tool call and external record consulted
  • The output of the monitoring model
  • Any corrections or changes made after the decision
  • The reason the system did or did not escalate
  • The information presented to a reviewing physician
  • The physician’s independent reasoning, if any

Traceable Is the Evidentiary Ceiling

The surviving record may make the renewal traceable. It does not make the decision reproducible.

A later investigator may be able to reconstruct what information entered the system, what the system produced, and which actors controlled the process. The investigator may not be able to rerun the system and prove that it would make the same decision again.

Traceable is the evidentiary ceiling.

What Responsibility Reconstruction Could Establish

What the Public Record Could Establish

Evidence-Based Responsibility Reconstruction℠ begins with the consequential conduct and follows the surviving record outward.

For a disputed Doctronic renewal, the public record could help establish:

What the public record could establish What the public record does not establish
  • That Utah authorized the AI renewal program
  • That Doctronic controlled the system and its operating conditions
  • That the AI was permitted to authorize qualifying renewals
  • That a physician was named as the prescriber of record
  • Whether the patient requested human review
  • Whether the system or pharmacist escalated the case
  • Whether a physician reviewed the renewal
  • What reports Doctronic provided to Utah
  • What complaints or adverse outcomes Doctronic recorded
  • Who approved the clinical thresholds used by the AI
  • Who determined that the automated monitoring system was sufficient
  • Who independently validated the “LLM as a judge”
  • Who approved reducing physician review to a 5%–10% sample
  • Whether physician reviewers formed judgments independently of AI-generated summaries
  • What evidence Utah possessed outside Doctronic’s reports
  • Who decided the remaining risk to patients was acceptable
  • Whether the weaknesses reported by Mindgard affected any component used in the Utah service
  • Whether those weaknesses were independently verified as resolved

The Unanswered Questions Are the Responsibility Record

Those unanswered questions are not peripheral. They are the responsibility record.

Responsibility Reconstruction Finding

The Responsibility Chain

  1. Utah Authorized — Utah authorized the experiment.
  2. Doctronic Designed and Operates — Doctronic designed and operates the system.
  3. The AI Decides and Monitors — An AI system makes the renewal decision. Another AI system monitors the first.
  4. The Physician Is Named — A physician’s name remains attached whether or not the physician reviews the decision.
  5. The Patient Receives the Outcome — The patient receives the medical outcome.

Attribution Does Not Establish Judgment

Doctronic’s design does not eliminate human and institutional responsibility. It makes that responsibility harder to see by preserving the appearance of a traditional physician decision after judgment has been delegated to an AI system.

The physician’s name makes the prescription attributable. It does not prove physician involvement.

The patient’s consent makes participation authorized. It does not transfer responsibility for the design.

Utah’s agreement makes the program legally operable. It does not establish that Utah independently verified every control on which patient safety depends.

Doctronic’s logs may make the conduct traceable. They do not make Doctronic an independent investigator of its own system.

Naming the Error Is Not Owning Responsibility

If a patient is harmed, naming an AI error, a physician, or a technical failure will not answer the responsibility question. The investigation must establish who authorized the governing conditions, who determined the controls were sufficient, who monitored the system, who could have intervened, whether anyone exercised that authority, and what evidence survives to prove each connection.

The system preserves a physician’s name. Responsibility reconstruction must determine whether physician judgment was ever there.

Naming the error is not owning responsibility.