Inspiration
The sister site, lab.hipaa.technology, teaches doctors how to adopt AI safely — and its only way to raise a hand is a mailto: link in the footer. Meanwhile the practices most at risk aren't deciding whether to use AI. They already are: an ambient scribe on live patient audio, ChatGPT on a consumer tier, no BAA, no consent workflow, no risk analysis that mentions AI. They don't need another article. They need to know what they're exposed to, in the time between patients. WebMCP made it possible to let their agent do the asking.
What it does
Ten questions about how a practice already uses AI. A readiness score and the three sharpest exposures, free, each with the statute underneath. A personalised remediation roadmap, built from a thirty-control library, gated behind an email the human types themselves.
Nine WebMCP tools:
| Tool | Role |
|---|---|
check_ai_vendor_baa, check_state_ai_rules |
Hook tools — work with no assessment started |
start_readiness_check, answer_check_question, get_readiness_score, explain_risk |
The check |
email_remediation_roadmap, open_21_day_mission, book_compliance_review |
Conversion — each hands a decision back to the human |
How we built it
- React + TypeScript, imperative registration in the top-level document:
document.modelContextwithnavigator.modelContextfallback, feature-detected, Strict-Mode safe, silent when the API is absent. - Every input schema is
additionalProperties: falsewith bounded enums. No free-text input anywhere in the assessment, so patient information cannot enter it. - Every tool returns
{ display, spoken, next_step, disclaimer }.spokenis written to be read aloud, because in an agent flow the human may never see the page. The legal disclaimer travels inside the return value, not just the footer. - The gate:
email_remediation_roadmaptakes no email argument and rejects one if supplied. It pauses execution and opens a real dialog on the page. The human types. The agent can't. - Answers stay in the browser. The server keeps email, score, state, clinician count, specialty and three risk-category IDs — never the itemised gaps.
- Built entirely inside the challenge window.
/webmcpon the site documents tools, schemas and the AI MAY / HUMAN MUST boundary.
Challenges we ran into
- The spec moved under us.
navigator.modelContextanddocument.modelContextboth exist in the wild; we register against whichever is present. - ChatGPT's browser supports a subset — no declarative forms, no iframes. Everything is imperative, top-level.
- Language is a legal surface. No "audit", "certified" or "compliant" anywhere — copy, tool names, descriptions or return values. The site says what is missing; it never says a practice is or isn't compliant.
- Cutting thirty controls to ten questions. Completion collapses past seven. Ten is the ceiling; the thirty stay in the codebase to power the roadmap.
Accomplishments that we're proud of
- An agent can run the whole check in one prompt, and ChatGPT's browser lists all nine tools first try.
- A gate the agent cannot pass on its own — designed as a feature, not a limitation.
- A data model chosen for the client's legal position: a written record of a named practice's admitted gaps is a discoverable document, so we never hold one.
- Shipped, on a real domain, with a live activity rail showing every tool call and every human decision.
What we learned
The best tool surface is the smallest one. Copy belongs in tool return values. And the most important tool is the one that refuses to act — the gate is the product.
What's next for Exposed
Roadmap email delivery, state-law overlays beyond recording consent, booking straight into a calendar, and the hand-off into the 21-day adoption mission at lab.hipaa.technology.
Built With
- chatgpt
- chrome
- css3
- html5
- javascript
- lovable
- lucide
- react
- shadcn
- supabase
- tailwindcss
- typescript
- vite
- webmcp
Log in or sign up for Devpost to join the conversation.