Who is this healthcare agent webinar for?
The webinar is for healthcare security, IT, compliance, and digital
transformation leaders responsible for patient portals, EHR
integrations, scheduling systems, and clinical APIs.
What is the authorization paradox?
A valid token establishes permission at a specific point in time. It
does not establish whether the agent’s later sequence of actions
reflects the patient’s intent.
What does the webinar cover about HTI-5?
The session discusses the HTI-5 proposal as regulatory context for
automated access to electronic health information. It explains why
healthcare organizations need controls based on observed risk rather
than blanket restrictions on automated access.
Why can traditional API controls miss healthcare agents?
An agent can use a valid token, follow the FHIR schema, operate from
an expected origin, and remain below rate thresholds. Session sequence
and context can expose risks that individual requests do not
show.
How can behavioral evaluation preserve patient privacy?
The transcript explains how blinded, non-reversible identifiers can
connect activity across sessions without requiring the security layer
to store the patient’s identity or clinical information.
What can teams do over the next 90 days?
Audit endpoints and telemetry gaps, review API access policies and
contracts, establish separate governance for read and write activity,
and introduce passive behavioral monitoring before
enforcement.