AAnaheraAI OPERATIONS SYSTEMS
AI Patient Assistant 24/7NewAI Receptionist 24/7
Back to all articles
Healthcare Operations

How should an AI patient assistant handle someone calling for a patient?

Design calls made on behalf of a patient: separate message taking from access, verify authority, limit disclosure and route difficult cases to staff.

Kevin Marchwiak7 min read
Adult caller checks an appointment by phone with an older patient beside her in a European clinic waiting area

The short answer

Treat the caller's relationship to the patient as a claim, not as permission. An AI patient assistant may take a minimal message without revealing anything from the patient record. It should view, disclose or change protected information only after identifying the caller and patient and checking authority that is current, recorded and sufficient for that specific action.

If authority is missing, expired, disputed or narrower than the request, the assistant should stop the transaction and create a restricted case for staff. It should also say at the start that the caller is speaking with AI. The clinic and its advisers must set the legal basis, local age rules and accepted forms of authority. The workflow must not invent them during a call.

Decide by the action, not the family label

A caller may ask for opening hours, leave a message, cancel an appointment, choose a new time or request details from the record. Those actions do not require the same access. Saying 'I am her daughter' or 'I am his partner' explains the relationship, but it does not settle what the clinic may disclose or change.

Write an action matrix before implementation. One route can accept a message without confirming that the patient is registered. Another can permit a limited administrative change when the source system shows the required authority. Results, sensitive correspondence, disputed requests and anything outside the recorded scope go to staff. This avoids a single yes or no rule for every person who helps a patient.

Keep caller and patient identities separate

The case should show who called, which patient they referred to and how the clinic may contact each person. Do not overwrite the patient's telephone number with the caller's number or describe the caller as the patient. When the action requires it, verify both identities through the clinic's approved process and record which check supported which action.

Knowing a date of birth, address or appointment time may help find a record, but it does not by itself establish authority. NHS England's proxy access guidance is a useful operating example: it gives the proxy a separate account, verifies patient and proxy, and records the permitted level of access. It is not a universal rule for every European clinic, but the separation is worth carrying into a phone workflow.

Match verification and authority to the requested action

Public information should not require the same checks as changing an appointment or hearing details about one. Define the minimum assurance for each action and the exact source that confirms authority. That source may be a proxy record, a mandate or another clinic-approved status supported by local policy and law.

If the authority service is unavailable or the record conflicts with what the caller says, do not disclose data or promise that a change succeeded. Save only the information needed for review, mark the action as pending and send it to the named team. A completed conversation is not evidence that the clinic accepted the request.

Disclose less on callbacks and shared phones

A return call, voicemail or text can reach a shared device. Use neutral wording until the authorised person has been verified. Do not include a specialty, test, diagnosis, referral reason or appointment detail merely to prove that the clinic found the record. Send confirmations to the channel approved for that patient and action.

The European Commission's GDPR guidance requires purpose limitation, data minimisation, accuracy and protection against unauthorised processing. In practice, the assistant should repeat only what the caller needs to confirm the permitted task. The call log should also distinguish information supplied by the caller from information read from the clinic system.

Keep authority current, scoped and revocable

Record which actions the caller may perform, the source of that authority, any end date and who reviews it. A permission to book an appointment does not automatically allow access to results or correspondence. Do not keep using a note from an earlier call after the patient withdraws permission or the recorded arrangement ends.

EDPB guidance on data protection by design and by default supports building these limits into the system rather than relying on staff memory. Test revocation across open sessions, notifications and integrations. The clinic may need to retain an audit record of the earlier action, but a revoked caller should not retain access to future information.

Stop when the request needs human judgement

The assistant should not decide whether a patient has capacity, whether consent was freely given, who has parental responsibility, what serves the patient's best interests or how to resolve a family disagreement. Signs of coercion, safeguarding concerns and contested authority require the clinic's authorised process. NHS England's guidance places those questions with people and formal records, not with the access channel itself.

Clinical judgement stays outside the administrative flow as well. If the caller introduces symptoms, deterioration, medication risk or a request for medical advice, follow the clinic's approved clinical or emergency route. AI can capture limited facts and hand over context. It must not rank urgency, interpret the patient's condition or accept consent for treatment.

Test awkward calls before launch

Run calls with the patient present, an unrecorded relative who knows personal details, a proxy authorised only for booking, a revoked proxy and a person using a shared telephone. Include a caller who changes the request after verification and one who introduces a clinical concern midway through an administrative task.

For each test, inspect what the assistant said, which fields it read, what it changed, the status left for staff and the audit event. Fail the test if the system reveals protected data before authority is confirmed, treats relationship as permission, hides a pending request or lets AI settle a capacity, safeguarding or clinical question.

FAQ

Can a relative reschedule a patient's appointment?

Only when the clinic's approved process and current record show that this caller may perform that action. Otherwise the assistant can take a limited request for staff review without confirming appointment details.

Is knowing the patient's date of birth and address enough?

No. Those details may help identify a record, but they do not prove that the caller is authorised to view or change it. Identity and authority are separate checks.

Can AI decide whether a parent, carer or proxy has legal authority?

No. The assistant can read a current approved status and follow the actions attached to it. Capacity, parental responsibility, coercion, contested authority and exceptions require authorised people and the applicable local process.

Sources and further reading

Ready to test one patient-service workflow?

Explore AI Patient Assistant 24/7

Related articles

Enterprise Workforce Operations
6 min read

Who should see worker hotline cases across staffing branches?

Define branch case access, headquarters reporting and temporary cover before deploying a shared AI worker hotline. Includes practical permission tests.

Read article
Healthcare Operations
5 min read

How can a clinic use AI for overflow calls without changing its phone number?

Plan AI overflow for a busy clinic reception: check the existing phone system, set transfer rules, protect callbacks and test a return to staff.

Read article