Prepare a referral packet.
Assemble the documents needed for an assigned referral. Constrain record retrieval and verify the destination before the packet leaves the workflow.
Review: patient scope + recipientHelp teams prepare documents, coordinate cases and work with research data. Check what an AI agent can read, which tools it can use and where information can go.
A case coordinator and a research assistant should not inherit the same access simply because they use the same model.
Assemble the documents needed for an assigned referral. Constrain record retrieval and verify the destination before the packet leaves the workflow.
Review: patient scope + recipientUse the project’s permitted data and analysis tools. Test whether a notebook, retrieved paper or tool response can redirect the agent toward identifiable source records.
Review: dataset + export permissionsGather the supporting documents for one case. Keep access to unrelated member records and authority to change the case outcome outside the preparation task.
Review: case access + write authorityA coordinator asks an agent to prepare a referral. An attachment contains an instruction to upload the full patient record to an external “verification” endpoint.
The requested upload includes records beyond the referral packet and a destination the organization has not approved.
At the routed tool or proxy request, evaluate permitted arguments and the destination. The record system still enforces patient-level access.
The configured destination restriction rejects the transfer. The decision is logged so the owner can investigate the attachment.
An assessment tests this outcome against the actual integration, including alternate paths that could bypass the control.
How prompt injection reaches toolsA content scan is one layer. The integration also needs a clear answer to which records the task may retrieve, which operations it may perform and who may receive the result.
Decide who can inspect the audit trail, how long it is retained and what is redacted in an export. A useful investigation record should not become an uncontrolled copy of sensitive content.
Bring the agent configuration, the connected tools and a representative dataset approved for testing. Agree the environment and data-handling conditions before the assessment begins.
Choose one administrative or research workflow. Identify its approved records, connected tools, external recipients and responsible owner. The assessment then tests whether untrusted documents or tool responses can cause access or transfers outside that scope.
Only where the integration exposes parameters that can be constrained. Tool permissions and parameter rules can restrict a request, while the underlying record system must enforce its own patient, tenant and dataset permissions. Broad credentials or direct access paths must be addressed separately.
These scenarios are assessment examples, not a catalog of packaged clinical integrations. We first review the actual MCP server, API or proxy path to determine which requests can be inspected and controlled.
No. Security controls and audit evidence support a review; they do not certify compliance, validate a diagnosis or establish the accuracy of generated clinical content. These examples cover administrative and research assistance. Clinical decisions remain with the responsible care team.
Let’s review the path from an assigned task to a requested transfer.
Discuss a healthcare assessment