ON-DEMAND WEBINAR

A valid token grants access, but behavior reveals intent.

See how healthcare teams can evaluate agent behavior after authorization across patient portals, FHIR APIs, and clinical workflows.

WATCH ON DEMAND

See why valid access can still create risk.

Watch this 22-minute on-demand webinar to understand HTI-5, explore a three-tier trust model, and leave with privacy guidance and a practical 90-day plan.
22-minute on-demand recording
Three-tier trust model
Privacy guidance + 90-day plan
Watch On-Demand →

WHAT YOU'LL LEARN

The trust problem begins after access is granted.

01

The authorization paradox

Two agents can present valid OAuth tokens and similar scopes while serving very different purposes. Learn why permission alone cannot establish whether later behavior matches patient intent.
02

What HTI-5 changes

Software becomes a new principal that can act continuously across providers, widening the gap between consent and ongoing behavior.
03

Where traditional controls break down

Volume thresholds, origin signals, and schema validation can all pass while an agent behaves outside the expected care workflow.
04

The uncomfortable middle

Every request can be valid in isolation while the full sequence conflicts with patient intent or disrupts clinical operations.
05

From access to intent

Add session patterns, behavioral baselines, cadence, and continuous trust evaluation to point-in-time authorization checks.
06

A more practical trust model

Let low-risk activity proceed, ask for confirmation when behavior becomes ambiguous, and intervene when objective evidence supports it.
Built for healthcare security, IT, compliance, and digital transformation leaders protecting patient portals, EHR integrations, scheduling systems, and clinical APIs.

HTI-5 AND HEALTHCARE AGENTS

The HTI-5 proposal explicitly addresses automated access to patient data.

HTI-5 recognizes software as a new principal that can act continuously across providers. The question shifts from whether access was authorized to whether later activity still reflects patient intent.

SHIFT
WHAT CHANGES
SECURITY QUESTION
A new principal
Patient-authorized software
How should trust change after an agent receives authorized access?
Continuous operation
Activity across providers and time
How can teams recognize accumulated access and workflow misuse?
A consent gap
One authorization, ongoing behavior
Does the agent’s behavior still reflect what the patient intended?
Authorization is the initial gate, not the complete trust decision. The behavior that follows determines whether access remains aligned with patient intent and clinical safety.

THE UNCOMFORTABLE MIDDLE

Authorized ≠ aligned with patient intent.

Valid API calls can still add up to behavior outside the patient’s purpose. Volume, origin, and schema checks can miss low-and-slow agents that remain technically compliant.
OLD FRAME
NEW FRAME
Question
Is this request allowed?
Does this make sense in context?
Signals
Identity, scopes, request validation
Session patterns, baselines, cadence
Trust decision
Made at authorization
Updated continuously over time

A MORE PRACTICAL TRUST MODEL

Trust decisions should follow observed behavior.

Match the response to observed risk: let aligned activity proceed, confirm ambiguous or sensitive actions, and intervene when objective evidence supports it. The webinar also shows how to preserve privacy and phase adoption over 90 days.

Tier 1 · Proceed
Proceed without friction when activity aligns with patient expectations and established behavioral patterns.
Tier 2 · Confirm
Request additional confirmation when behavior falls into a gray area or a sensitive action needs supervision.
Tier 3 · Intervene
Intervene when behavior diverges significantly and objective evidence supports the response.

WHAT TO TAKE BACK TO YOUR TEAM

Four conclusions for healthcare security teams

#1

Authorization is necessary, not sufficient

Credentials and scopes establish permission at one point in time. They cannot establish whether later behavior remains appropriate.
#2

Existing anomaly detection has a blind spot

Controls tuned for noisy attacks can miss agents that follow schemas, stay below thresholds, and operate through expected channels.
#3

Intent emerges from patterns, not isolated actions

A single request may look ordinary. Sequence, timing, repetition, and workflow context help teams assess whether the full session matches the patient’s purpose.
#4

This is a system design challenge, not a checkbox

Healthcare teams need continuous evaluation, proportionate responses, and evidence that explains why access continued, required confirmation, or was restricted.

FAQ

Frequently asked questions

Who is this healthcare agent webinar for?

The webinar is for healthcare security, IT, compliance, and digital transformation leaders responsible for patient portals, EHR integrations, scheduling systems, and clinical APIs.

What is the authorization paradox?

A valid token establishes permission at a specific point in time. It does not establish whether the agent’s later sequence of actions reflects the patient’s intent.

What does the webinar cover about HTI-5?

The session discusses the HTI-5 proposal as regulatory context for automated access to electronic health information. It explains why healthcare organizations need controls based on observed risk rather than blanket restrictions on automated access.

Why can traditional API controls miss healthcare agents?

An agent can use a valid token, follow the FHIR schema, operate from an expected origin, and remain below rate thresholds. Session sequence and context can expose risks that individual requests do not show.

How can behavioral evaluation preserve patient privacy?

The transcript explains how blinded, non-reversible identifiers can connect activity across sessions without requiring the security layer to store the patient’s identity or clinical information.

What can teams do over the next 90 days?

Audit endpoints and telemetry gaps, review API access policies and contracts, establish separate governance for read and write activity, and introduce passive behavioral monitoring before enforcement.