Announcing CIMD support for MCP Client registration
Learn more

7 Agent Use Cases in Healthcare

Nityashree Yadunath
Product Marketing Manager

TL;DR

  • The spend follows action, not chat. Menlo Ventures counted $1.4B of healthcare AI spend in 2025: ambient documentation at $600M, coding and billing at $450M, and prior authorization growing about 10x.
  • Every use case touches three to six systems, each with its own auth model: the EHR (SMART on FHIR), payer APIs (client credentials), clearinghouses (API keys), payer portals (logins with MFA), plus CRM, telephony and fax.
  • Approval gates cluster in the same four places: clinical sign-off on notes and orders, outbound submissions to payers, medication and problem-list changes, and any adverse coverage decision.
  • 2026–2027 is a dual-stack period. FHIR prior-auth APIs are due from CMS-regulated (impacted) payers by January 1, 2027, so agents need both FHIR and legacy channels (X12, portals, fax) for now.
  • Scalekit's view: the model is rarely what limits these agents. What limits them is authenticating to every system as the right person, per tenant, with a record a health system will accept.

How to read each use case

For each use case we cover what the agent does, the systems it touches and how it authenticates to each, where humans approve, the rules that apply, and who's building it. The auth patterns repeat:

  • SMART user-context: the agent acts with a clinician's or patient's EHR scopes. Actions are attributed to that person.
  • SMART Backend Services: a system credential for jobs with no user present, like overnight batches.
  • Payer or clearinghouse credentials: organization-level client credentials, mTLS or API keys, one set per payer or clearinghouse.
  • Vaulted portal login: a user's own portal username, password and MFA, stored encrypted and injected at call time.
  • SaaS OAuth: per-user OAuth for CRM, email, calendar and ticketing.

Why these differ, and when to use which: see our deep-dive on OAuth for AI Agents: Production Architecture and Practical Implementation Guide.

1. Prior authorization

The problem: physicians handle about 40 prior authorizations a week, costing about 13 hours of staff time, and 26% report a serious adverse event tied to prior-auth delays, according to the AMA's 2025 survey. The same survey found 60% of physicians worry AI will increase denials, which is why auditability matters here.

What the agent does

  1. Detects the trigger: a new order, scheduled procedure or medication in the EHR.
  2. Checks whether prior auth is required through the payer's Da Vinci CRD service (FHIR, delivered via CDS Hooks), falling back to payer rules or a portal lookup.
  3. Gathers documentation: diagnoses, labs, notes, procedures and coverage from the chart, filling payer questionnaires (Da Vinci DTR) with cited evidence.
  4. Drafts the submission, including the medical-necessity narrative.
  5. Waits for staff review of the packet.
  6. Submits through Da Vinci PAS (FHIR), X12 278 via a clearinghouse, the payer portal, or fax.
  7. Tracks status through API responses, portal checks or payer phone calls.
  8. Writes back the authorization number and status to the order, or opens a task and drafts an appeal if denied.

Systems and auth

System
Interface
Auth
EHR
FHIR R4, CDS Hooks
SMART user-context for in-workflow steps; Backend Services for queue workers
Payer CRD, DTR, PAS
FHIR, hosted by each payer
Client credentials or mTLS, registered per payer
Clearinghouse
X12 278
API key or SFTP
Payer portals
Web UI
Vaulted per-user login with MFA
Fax
Cloud fax API
API key

Where humans approve

Before submission, and before any appeal leaves the building. Writing the result back is a separate, narrower permission: Epic exposes prior-auth update operations on ServiceRequest and MedicationRequest, so the write-back tool needs only those.

Rules that apply

  • CMS-0057-F: faster decision timeframes for impacted payers since January 1, 2026 (72 hours expedited, 7 days standard), and FHIR Prior Authorization APIs required from impacted payers (Medicare Advantage, Medicaid, CHIP and marketplace plans) by January 1, 2027.
  • Da Vinci PAS lets FHIR submissions go direct instead of converting to X12 278, under CMS enforcement discretion.
  • Health plans' pledge: AHIP members committed to answering 80% of electronic prior-auth approvals in real time by 2027.

Who's building it

Latent Health, Develop Health, Silna Health and Infinitus on the provider side; Availity with Abridge at the point of care; Epic's Penny and real-time CRD checks inside the EHR.

2. Revenue cycle: eligibility, coding, claims and denials

The problem: administrative transactions are still heavily manual. The CAQH Index 2025 estimates $21B in savings still available from automation, and reports that more than half of health plans and about a quarter of providers already use AI in administrative workflows.

What the agent does

  1. Front end: checks eligibility and benefits (X12 270/271), discovers coverage and produces a patient estimate.
  2. Mid cycle: reads the signed note and encounter, proposes CPT, ICD-10 and HCC codes, and flags documentation gaps before billing.
  3. Claim: builds and scrubs the 837, then submits through the clearinghouse.
  4. Follow-up: tracks claim status (276/277) and posts remittances (835).
  5. Denials: classifies the denial reason, pulls the supporting chart and drafts the appeal.
  6. Writes back codes, charges and work-queue notes to the EHR or practice management system.

Systems and auth

System
Interface
Auth
EHR / practice management
FHIR reads, plus proprietary charge and coding APIs
Backend Services or vendor API client, per customer
Clearinghouse
X12 270/271, 837, 276/277, 835
API key or SFTP, plus enrollment per payer
Payer portals
Claim status, appeals
Vaulted per-user login with MFA
Patient billing CRM
SaaS API
SaaS OAuth

Clearinghouses are starting to expose agent interfaces directly. Stedi's MCP server, for example, exposes real-time eligibility checks as a tool.

Where humans approve

Low-confidence codes go to a coder. Appeals get human sign-off before submission.

Who's building it

Commure, Smarter Technologies (SmarterDx, Thoughtful.ai and Access Healthcare combined), AKASA, CodaMetrix, Fathom, Adonis and Charta Health. Inside Epic, Penny handles coding and appeal drafting.

3. Ambient scribe write-back to the EHR

The problem: documentation takes clinicians' evenings. Ambient scribes are healthcare AI's largest category, and the fight has moved from transcription quality to how deeply the scribe writes back into the chart.

What the agent does

  1. Opens in context: the clinician starts it from the EHR, and it receives the patient and encounter.
  2. Preps the visit: pulls the problem list, medications, recent labs and prior notes.
  3. Captures and transcribes the conversation, with patient consent where required.
  4. Drafts the note, patient instructions, suggested orders, codes and prior-auth triggers.
  5. Waits for the clinician to edit and sign.
  6. Writes back the signed note (DocumentReference), structured data such as vitals (Observation) and problems (Condition), and orders as unsigned drafts for the clinician to sign.

Systems and auth

  • EHR: SMART user-context with write scopes such as user/DocumentReference.cu, so the note is attributed to the signing clinician. The app is registered and activated per health system.
  • Payer (for prior-auth triggers): see use case 1.
  • Recording and consent: depends on the scribe's own stack.

Where humans approve

Always: the clinician signs the note. Epic creates new medication orders from third parties as unsigned orders via CDS Hooks, so a clinician signs every order.

Rules that apply

  • Consent: state recording laws apply. Illinois HB 1806 requires written consent for AI recording or transcription in therapy settings.
  • Patient-facing text: California AB 3030 requires a disclaimer on AI-generated clinical communications sent to patients without provider review.
  • Disclosure: Texas TRAIGA requires disclosure of AI use in treatment from January 1, 2026.

Who's building it

Abridge, Ambience Healthcare, Microsoft Dragon Copilot, Suki, Nabla, Heidi Health, DeepScribe and Commure Ambient, alongside EHR-native scribes from Epic, Oracle Health and NextGen.

4. Patient access: scheduling, intake and the call center

The problem: phone lines are the front door, and they're overloaded. Menlo reported patient-engagement spend grew about 20x in 2025. Epic says its Emmie agent helped Ochsner patients reschedule more than 14,900 appointments.

What the agent does

  1. Answers an inbound call, text or chat.
  2. Verifies identity against the EHR (name, date of birth, callback number). A wrong-patient match is a safety and HIPAA issue.
  3. Works out the intent: new appointment, reschedule, refill, billing question, or a clinical question that goes to a nurse.
  4. Schedules: reads availability, applies provider templates and referral or prior-auth rules, and books the appointment.
  5. Runs intake: captures insurance, checks eligibility in real time, and sends pre-visit forms that come back as structured responses.
  6. Handles outbound work: reminders, waitlist backfill, recalls and care-gap outreach.
  7. Hands off to staff for clinical content, complaints or failed identity checks.
  8. Writes back the appointment, a call summary and a CRM case.

Systems and auth

  • EHR: usually Backend Services, since the patient isn't an EHR user in the loop. Scheduling write support varies: Oracle Health documents Appointment create and update, MEDITECH has FHIR scheduling APIs, and Epic scheduling often runs through customer-specific interfaces.
  • Telephony and SMS: API keys.
  • CRM: SaaS OAuth.
  • Clearinghouse (eligibility): API key.

Rules that apply

  • TCPA: the FCC ruled in February 2024 that AI-generated voices count as "artificial," so outbound AI calls need prior express consent, identity disclosure and an opt-out. The healthcare exemption for calls to mobile phones has strict limits on frequency, length and content. Have counsel review outbound programs.
  • California AB 3030 applies to clinical content, not scheduling or billing.

Who's building it

Assort Health, Hello Patient, Hippocratic AI, Notable, Hyro and Luma Health, plus EHR-native agents from Epic (Emmie), athenahealth and eClinicalWorks.

5. Chart prep and medication reconciliation

The problem: clinicians walk into visits without a clear picture of what changed. Epic says its Art chart summary is used more than 16 million times a month.

What the agent does

  1. Runs the night before: pulls tomorrow's schedule, then each patient's medications, allergies, labs, problems and outside records from health information exchanges.
  2. Reconciles: flags duplicates, discrepancies (a dispensed drug missing from the med list), interactions and care gaps.
  3. Produces a pre-visit summary with citations back to source documents.
  4. Waits for the clinician or pharmacist to confirm each change.
  5. Writes back the summary as a note and approved allergy or problem updates. Medication changes stay as unsigned orders or clinician actions.

Systems and auth

  • Batch prep: Backend Services plus Bulk FHIR export for the panel.
  • At the visit: SMART user-context reads for freshness, under the clinician's authority.
  • Networks: network or QHIN credentials with a declared treatment purpose.

Rules that apply

If the agent recommends treatment, FDA clinical decision support guidance and Section 1557's rule on patient-care decision support tools apply.

Who's building it

Navina, Regard, Epic Art, and ambient vendors moving into pre-visit summaries.

6. Referral intake and management

The problem: referrals still arrive by fax. Tennr, which raised $101M in 2025 to automate referral intake, cites the problem that more than half of specialist referrals never complete.

What the agent does

  1. Ingests faxes, Direct messages, EHR referral queues or electronic referrals.
  2. Extracts demographics, reason for referral and attachments.
  3. Matches or creates the patient record.
  4. Checks eligibility, network status and whether prior auth is needed.
  5. Requests missing documents from the referring office by fax or call.
  6. Schedules the visit and closes the loop with the referrer.
  7. Writes back referral status, attachments and the appointment.

Systems and auth

Fax API key; Backend Services to the EHR; clearinghouse API key; CRM OAuth; outbound calling under TCPA rules.

Where humans approve

Low-confidence extractions and clinical triage go to intake staff.

The risk to design for

Faxed documents are untrusted input. A referral is a prompt-injection surface: an agent that reads faxes shouldn't hold tools that send data outside the organization.

Who's building it

Tennr, Notable, Innovaccer and Salesforce Agentforce for Health.

7. Payer-side review: utilization management, claims and appeals

The problem: payers are behind providers on AI adoption, and trust is low. The AMA found only 24% of physicians say denials are consistently reviewed by qualified clinicians.

What the agent does

  1. Takes in a prior-auth request (FHIR, X12 278, portal or fax) or a claim (837).
  2. Pulls the clinical record from attachments or, from 2027, the provider data APIs CMS requires.
  3. Maps the case to clinical criteria or plan policy.
  4. Auto-approves clear cases and routes every potential denial to a licensed clinician.
  5. Returns a decision with a specific reason, within CMS timeframes.
  6. Drafts appeal determinations for reviewer sign-off.

Rules that apply

  • California SB 1120: only a licensed physician or qualified professional can decide medical necessity.
  • CMS WISeR: AI-assisted prior auth in traditional Medicare in six states (2026–2031), with licensed clinicians deciding every non-payment.
  • AHIP pledge: clinically based denials continue to get medical professional review.

Who's building it

Cohere Health, Anterior and Alaffia Health.

What these use cases have in common

Use case
Systems touched
Auth models needed
Human approval point
Prior authorization
EHR, payer APIs, clearinghouse, portals, fax
SMART user-context, payer credentials, API keys, vaulted logins
Before submission and appeals
Revenue cycle
EHR/PM, clearinghouse, portals, billing CRM
Backend Services, API keys, vaulted logins, SaaS OAuth
Low-confidence codes, appeals
Scribe write-back
EHR, payer (for PA triggers)
SMART user-context with write scopes
Every note and order
Patient access
EHR, telephony, CRM, clearinghouse
Backend Services, API keys, SaaS OAuth
Clinical content, failed identity checks
Chart prep and med rec
EHR, networks
Backend Services + bulk, SMART user-context
Every med or problem-list change
Referral intake
Fax, EHR, clearinghouse, CRM, telephony
API keys, Backend Services, SaaS OAuth
Low-confidence extraction, triage
Payer review
Core admin, UM platform, provider APIs
Service accounts, client credentials
Every potential denial

Three patterns follow:

  1. Credential sprawl is the real integration cost. One agent run can need five credential types across as many systems, per user and per health system.
  2. Approvals are authorization, not UX. An approval gate has to re-check that the credential is still valid when the approved action finally runs. This is closely related to how token refresh for AI agents must be handled at the infrastructure level.
  3. Attribution decides deployment. Every one of these touches PHI, so every action needs a record of who authorized it, which agent acted, and with what scope, without copying PHI into logs. Understanding audit trails for agent auth in B2B SaaS is essential to getting this right.

More on the architecture that handles these in the API access patterns for AI agents guide, and on managing credentials across complex multi-system workflows in Who Holds the Token? Credential Ownership Across Agent Tool-Calling Patterns.

How Scalekit supports these use cases

Scalekit AgentKit is the authorization and tool-calling layer these agents share:

  • One interface across auth models. SMART on FHIR, OAuth 2.0 and 2.1, API keys, bearer tokens and more, across 500+ connectors and 20K+ actions. The agent calls a tool by user and connection; Scalekit resolves the right credential.
  • EHR access as the user, through the SMART on FHIR connector for any FHIR server and a pre-built AdvancedMD connector.
  • Bring your own connectors for payer and clearinghouse HTTP APIs or internal systems (OAuth, API key, bearer or basic auth), with the same vault, scoping and audit as built-in ones.
  • Scoped tool bundles per agent, so the fax-reading agent doesn't hold outbound tools.
  • Credential state held across approvals, so an approved action runs with a valid token.
  • PHI stays out: payloads processed in memory, metadata-only audit to your SIEM, deployable in your or your customer's cloud with a HIPAA BAA on Enterprise.

When AI agents operate across multiple systems and tenants, access control for multi-tenant AI agents becomes a foundational design concern — not an afterthought. Scalekit's architecture is built around this requirement. When an employee leaves and their grants must be revoked, revoking AI agent access should be instantaneous and tenant-isolated — exactly what static API keys cannot provide.

See AgentKit.

Frequently asked questions

What are the top agent use cases in healthcare?

The most funded and deployed are ambient documentation, revenue cycle (coding, claims, denials), prior authorization, and patient access (scheduling and call centers). Chart prep, referral intake and payer-side utilization review are growing fast. Menlo Ventures put 2025 healthcare AI spend at $1.4B, led by ambient documentation and coding.

How do AI agents handle prior authorization?

They detect when an order needs prior auth, check payer requirements, gather documentation from the chart, draft the submission and, after staff review, submit it through payer FHIR APIs, X12 278, portals or fax. They then track status and write the result back to the EHR. CMS requires FHIR prior-auth APIs from impacted payers by January 1, 2027.

Can AI scribes write directly into the EHR?

Yes, within limits. Scribes typically write signed notes as DocumentReference and some structured data, using the clinician's SMART on FHIR authorization so the entry is attributed to them. New orders are usually created as unsigned drafts for the clinician to sign. Write access varies by EHR and health system.

Do healthcare AI agents need human approval?

For high-impact actions, yes. Clinicians sign notes and orders, staff review prior-auth submissions and appeals, and payer denials require licensed clinician review under rules like California SB 1120 and CMS's WISeR model. Reads and routine lookups usually don't need approval.

What systems do healthcare AI agents connect to?

Usually the EHR (via FHIR and SMART on FHIR), payer APIs and portals, clearinghouses (X12 transactions), CRM, telephony, SMS and fax. A single workflow like prior authorization can touch five of these, each with a different authentication method.

Can AI agents make outbound calls to patients?

Yes, with consent. The FCC treats AI-generated voices as artificial under the TCPA, so outbound AI calls need prior express consent, identity disclosure and an opt-out. Healthcare exemptions for calls to mobile phones have strict limits on frequency, length and content.

No items found.
Agent
Auth Quickstart
On this page
Share this article
Agent
Auth Quickstart

Acquire enterprise customers with
‍zero upfront cost.

Every feature unlocked. No hidden fees.