Inspiration

The sister site, lab.hipaa.technology, teaches doctors how to adopt AI safely — and its only way to raise a hand is a mailto: link in the footer. Meanwhile the practices most at risk aren't deciding whether to use AI. They already are: an ambient scribe on live patient audio, ChatGPT on a consumer tier, no BAA, no consent workflow, no risk analysis that mentions AI. They don't need another article. They need to know what they're exposed to, in the time between patients. WebMCP made it possible to let their agent do the asking.

What it does

Ten questions about how a practice already uses AI. A readiness score and the three sharpest exposures, free, each with the statute underneath. A personalised remediation roadmap, built from a thirty-control library, gated behind an email the human types themselves.

Nine WebMCP tools:

Tool Role
check_ai_vendor_baa, check_state_ai_rules Hook tools — work with no assessment started
start_readiness_check, answer_check_question, get_readiness_score, explain_risk The check
email_remediation_roadmap, open_21_day_mission, book_compliance_review Conversion — each hands a decision back to the human

How we built it

  • React + TypeScript, imperative registration in the top-level document: document.modelContext with navigator.modelContext fallback, feature-detected, Strict-Mode safe, silent when the API is absent.
  • Every input schema is additionalProperties: false with bounded enums. No free-text input anywhere in the assessment, so patient information cannot enter it.
  • Every tool returns { display, spoken, next_step, disclaimer }. spoken is written to be read aloud, because in an agent flow the human may never see the page. The legal disclaimer travels inside the return value, not just the footer.
  • The gate: email_remediation_roadmap takes no email argument and rejects one if supplied. It pauses execution and opens a real dialog on the page. The human types. The agent can't.
  • Answers stay in the browser. The server keeps email, score, state, clinician count, specialty and three risk-category IDs — never the itemised gaps.
  • Built entirely inside the challenge window. /webmcp on the site documents tools, schemas and the AI MAY / HUMAN MUST boundary.

Challenges we ran into

  • The spec moved under us. navigator.modelContext and document.modelContext both exist in the wild; we register against whichever is present.
  • ChatGPT's browser supports a subset — no declarative forms, no iframes. Everything is imperative, top-level.
  • Language is a legal surface. No "audit", "certified" or "compliant" anywhere — copy, tool names, descriptions or return values. The site says what is missing; it never says a practice is or isn't compliant.
  • Cutting thirty controls to ten questions. Completion collapses past seven. Ten is the ceiling; the thirty stay in the codebase to power the roadmap.

Accomplishments that we're proud of

  • An agent can run the whole check in one prompt, and ChatGPT's browser lists all nine tools first try.
  • A gate the agent cannot pass on its own — designed as a feature, not a limitation.
  • A data model chosen for the client's legal position: a written record of a named practice's admitted gaps is a discoverable document, so we never hold one.
  • Shipped, on a real domain, with a live activity rail showing every tool call and every human decision.

What we learned

The best tool surface is the smallest one. Copy belongs in tool return values. And the most important tool is the one that refuses to act — the gate is the product.

What's next for Exposed

Roadmap email delivery, state-law overlays beyond recording consent, booking straight into a calendar, and the hand-off into the 21-day adoption mission at lab.hipaa.technology.

Built With

Share this project:

Updates

Submission history