Cases / Theme 02

Patient Agent and Precision Patient Operations

Move beyond digital entry points toward a continuously available health twin that understands patient state, initiates action, and completes clinical service loops under human confirmation and full audit.

Iterating Patient agent Precision recall Continuous care
See—remember—understand—help
Four capabilities of a patient health twin
5 stages
A continuous journey from pre-visit to recall
6 scenarios · 12 touchpoints
The outreach skeleton for lifecycle operations
Human confirmation
The safety boundary for screening and outreach

The next step in patient service is not another chat window. It is a health twin that keeps understanding the patient, proactively detects needs, and can call services to complete a task. It connects pre-visit, in-hospital, post-visit, at-home, and recall stages so every interaction updates patient state and makes the next service more precise.

Core judgment: a patient agent is not a medical record summary. It combines data, preferences, risk, memory, and the ability to act.

From digital entry point to proactive agent

Patient service broadly evolves through three stages:

StageService modelTypical capability
Digital entry pointPatients look for servicesRegistration, payment, reports
Online workflowThe system follows fixed remindersBefore, during, and after a visit
Patient agentServices respond to patient stateRecognition, decisions, execution, learning

The meaningful change is not conversation alone. The agent must be continuously available, trustworthy, and able to act.

A patient health twin needs four capabilities

  1. See me by integrating care, tests, medication, vital signs, and behavior.
  2. Remember me through long-term memory of family, insurance, time, clinician, and communication preferences.
  3. Understand me through risk stratification, intent recognition, and next-best-action decisions.
  4. Help me by invoking appointment, payment, consultation, follow-up, and recall services.

Proactivity comes from a “heartbeat” mechanism: inspect incremental data, compare it with the full health state, detect changes, trigger judgment, create an action list, and record execution feedback.

Four capabilities of a patient health twin: see, remember, understand, and help
Patient health twin.It combines data, long-term memory, risk judgment, and service execution rather than remaining a static summary.

The heartbeat should not mean constant patient interruption. It is a background state check: read only authorized incremental information, compare it with prior state, and decide whether to record silently, create a reminder, send a case for human review, or invoke a service. High-risk tasks must enter a human queue before action.

One continuous patient journey

Before the visit

Symptom questions, intelligent triage, appointment support, and reminders turn uncertain care-seeking into a prepared visit.

The pre-visit stage exists to solve four very plain problems: patients book the wrong department, make wasted trips, arrive unprepared, and special groups have no one looking after them. The product answers are equally direct. Online, a conversational LLM takes the patient from a detailed description of the problem straight to a booked appointment. Offline, an AI digital human absorbs the high-frequency repetitive questions — which department, where to print a report — and takes pressure off the staffed counter.

Redacted pre-visit guidance: conversational LLM booking online and AI digital-human wayfinding on site
The pre-visit keyword is "ahead of time."Handing a structured pre-consultation summary to the clinician is worth more than shaving ten minutes off the waiting room. Institution marks have been removed.

The line worth noticing is the structured pre-consultation output handed to the clinician. Pre-visit questioning that only reassures the patient has limited value. It matters only when it becomes a structured summary the clinician sees on opening the system — that is the point where pre-visit and in-visit actually connect.

In the hospital

Arrival, pre-visit communication, exam scheduling, and milestone reminders reduce waiting and workflow breaks.

In practice this takes the form of an outpatient full-journey guidance chain: appointment confirmed, check-in at the district, waiting and consultation, itemised billing with every charge visible, tests and imaging, then pharmacy pickup located precisely enough to be actionable — scan and collect at the ground-floor pharmacy in the outpatient hall. Every node carries an explicit status label: paid, checked in, consultation complete, payment due, medication ready for pickup.

Redacted outpatient full-journey guidance showing node status from booking and payment through tests and pharmacy pickup
Most waiting-room anxiety is an information problem.Patient identifiers and institution marks have been irreversibly removed.

None of this is technically hard. The hard part is real time. If a status updates ten minutes late, the patient walks to the counter to ask anyway — and the feature may as well not exist.

After the visit

Report explanation, prescription and payment, and follow-up planning extend a visit into an executable care plan.

At home

Health monitoring, medication reminders, and rehabilitation guidance continue service outside the hospital.

Recall

Abnormality detection, human confirmation, priority access, and result write-back convert risk discovery into a completed clinical loop.

Five-stage patient journey from pre-visit through in-hospital, post-visit, at-home, and recall
One continuous journey.Every interaction updates the same patient twin and can trigger the next more precise service.

Continuity is more than a single front door. The pre-visit symptom summary should reach clinical intake; orders and medication plans should become post-visit tasks; home-monitoring abnormalities should return to a clinical queue; and recall results should update the longitudinal health state.

“Xiao An” demonstrates the unified-entry product form

The source material presents “Xiao An” as a WeChat-based entry point that combines intelligent triage, appointment booking, visit guidance, report access, and longitudinal health records. Patients do not need a new app; they complete the journey in a familiar channel.

The important design choices are:

  • one identity across hospitals and channels;
  • every conversation enriching the health profile;
  • visits, tests, reports, and medication no longer fragmented by system;
  • summaries and plain-language explanation reducing comprehension barriers;
  • group-wide service standards with room for local differences.
Redacted unified entry point for intelligent triage, appointment booking, visit support, and report access
Real product form.Intelligent triage, appointments, visit guidance, and report access share one entry point. Company, institution, and identity information has been irreversibly removed.

The health record is the agent’s long-term memory

The source material separates capabilities into “live” and “coming soon”, which is more useful than writing every function up as a vision:

Capability layerCurrent product formNext step
Health summaryCombine visits, tests, and medication into periodic summariesA traceable, multi-year health timeline
AI explanationExplain records and reports in plain language and detect abnormal valuesConnect explanation with consultation and specialty routing
Health monitoringUse existing care dataAdd authorized vital-sign and device data
Post-visit managementRemind follow-up, medication, and testingProactive tasks, human escalation, and result write-back
Four health-record modules -- health summary, AI explanation, health monitoring, and visit lookup -- labelled live or coming soon
"Live" and "coming soon" are labelled separately.That restraint is a trust signal: it tells you which part can be verified today.

Of the four modules, the health summary occupies the core entry position on the record’s landing view, condensing full-lifecycle care data into a periodic summary and an annual condition overview. That is the right product call. What a patient needs is an answer to “what is my situation now”, not a ledger they can scroll back ten years.

The record should not become an unlimited data warehouse. Each data class needs a stated purpose, retention period, and permission scope. Withdrawal of consent or a change in contact preference must immediately affect future tasks.

A group-level patient operations platform sits underneath

An executable patient agent depends on five shared capabilities:

  1. Unified identity across hospitals and channels.
  2. Unified labels for condition, risk, behavior, value, and preference.
  3. Unified tasks for follow-up, recall, reminders, and human escalation.
  4. Unified outreach across mini-programs, SMS, phone, and enterprise messaging.
  5. Unified outcome analysis from discovery through completed service.

Without this foundation, an agent easily becomes an interface that can talk but cannot get anything done.

At the operating layer this platform is broken down into 6 scenarios and 12 touchpoints: pre-checkup, during checkup, post-checkup, pre-outpatient, post-outpatient, and long-term management, each scenario carrying two concrete outreach actions — report explanation and abnormal-result alerts after a checkup, medication guidance and follow-up management after an outpatient visit. The four strategy goals run in order: reach, accumulate, serve, operate.

Patient lifecycle operating model with 6 scenarios and 12 touchpoints, front-end outreach centre, back-end scheduling centre, and four service roles
A front-end outreach centre plus a back-end scheduling centre.The AI identifies which scenario a patient is in and matches a service role; people deliver the professional service.

The part of this diagram that deserves the most attention is the ordering of the four service roles on the right: clinical professionals (doctors, nurses, pharmacists), health management (nutritionists, exercise coaches, psychologists), customer operations (support and ops), and sales advisors (health-product sales, insurance liaison).

The order cannot be reversed and the boundaries cannot blur. A sales advisor may introduce products and packages, but must never appear in the professional consultation, report interpretation, or medication guidance path. Customer operations may run satisfaction surveys and activity notices, but must never modify clinical judgment. Once that separation is muddled inside the system, the compliance basis of the whole patient operation is gone.

The human-machine division must also be explicit. The agent detects signals, organizes evidence, and creates tasks; care coordinators verify state and communication preferences; clinicians judge indication and priority; operations teams manage channels and service quality without changing clinical judgment; and management owns permissions, audit, definitions, and incident response.

Precision recall must close the clinical loop

Recall is not mass marketing. It is an evidence-based, human-confirmed, traceable service chain:

Detect → screen with rules and models → clinical confirmation → contact and priority access → record outcome → learn

Five-step clinical recall loop from detection and screening to confirmation, service, and learning
Recall is not broadcasting.It becomes a clinical loop only when evidence is reviewed and contact, care, and outcomes are written back.

The system searches across records, laboratory tests, and imaging for signals, then gives candidate patients, screening rationale, and source evidence to clinical staff. Only after human confirmation does the task proceed to patient contact, priority scheduling, admission, follow-up, and write-back.

Redacted precision patient screening and clinical evidence review workspace
Real workbench.The left side scans data and creates candidates; the right side supports evidence review. Patient, clinician, institution, company, and brand information has been irreversibly removed.

The useful output is not a risk score alone. Clinical staff need to see why a patient was selected, where the evidence came from, whether follow-up already occurred, which specialty should act, and what happened next. Without that, a model cannot be safely placed inside a patient service workflow.

An external reference case

The source material cites an AI patient tracking system at a leading tertiary hospital in eastern China. Its stated positioning is deliberately restrained: identify in real time the patients who need urgent attention and optimise resource allocation — not “diagnostic assistance”. The difference matters. The first is an operations and scheduling problem; the second is a question of clinical liability.

Redacted overview of an AI patient tracking system and its five value propositions
Positioning defines the boundary."Find the people who should be looked at" and "decide what this person has" are two different products. Institution marks and vendor model names have been removed.

Step one: screening rationale must be traceable to source evidence

On screen, a single candidate patient carries three things at once: the screening agent’s stated rationale (for example, that the imaging findings describe a roughly 0.36 cm medium-echo mass adhering to the gallbladder wall, without acoustic shadowing and not moving with position change, a description consistent with a space-occupying lesion), the original imaging report and outpatient note text, and the patient’s full visit timeline.

Redacted screening rationale view showing the agent's reasoning, source report evidence, and the patient visit timeline
The three-column layout is a responsibility layout.Left is the queue, centre is the evidence, right is where this patient has already been -- the basis on which a coordinator decides whether to recall and to which specialty. Patient name, case number, contact details, date of birth, present illness, and attending clinician name have been irreversibly removed.

Note the parallel tabs labelled “Screening Basis I / II / III”. One patient may be flagged by several independent signals, and the system does not merge them into a single verdict. It lays each one out separately for a human to read. That is the design choice that translates model confidence into clinically checkable evidence.

Step two: confirmation must lead to a real action

The real dividing line comes next: once a case is confirmed, is there an executable action attached? Here the actions are concrete. For patients whose findings suggest they may meet surgical indication, the coordinator can send a message arranging a priority appointment slot, with slot date, location, and clinic hours written into the template. For key patients who clearly need admission, a phone call confirms intent and admission is arranged directly. Everyone else moves to scheduled follow-up, with a defined interval and a named department for re-examination.

Redacted recall action view with three notification templates: priority appointment, admission arrangement, and scheduled follow-up
"Priority access" has to be a button in the system, not a slogan.Patient name, age, case number, phone number, treating clinician, and real names inside the notification templates have been irreversibly removed.

The wording of the templates is worth reading closely. The message says only that the results of a test on a given date were abnormal and that further care can be arranged. It offers no conclusion and creates no alarm. That is what it looks like to write the clinical boundary into the copy itself.

Step three: departments need to see their own recall progress

Recall that exists only as individual tasks, with no department-level view, quickly degrades into whoever is most diligent doing the most work. The dashboard sets distribution against handling: patients distributed and patients handled today, with cross-department and own-department distribution counted separately; distributed against confirmed patients; same-day and next-day screening throughput; average screening handling days; 14-day recall counts for existing and external patients; and the recall rate.

Redacted department recall dashboard with distribution versus handling counts, screening trend, and cross-department distribution share
"Average screening handling days" is the most valuable number on this board.It measures the lag between the system detecting an abnormality and a human actually acting on it -- when it grows, the human queue has fallen behind model throughput. Patient names and phone numbers have been fully masked.

The cross-department distribution share is the other interesting curve. It shows that most abnormal findings do not belong to the department that found them. A pulmonary nodule picked up incidentally on an orthopaedic film has to reach respiratory medicine. That is exactly where cross-department recall adds value over individual follow-up, and exactly where it tends to jam organisationally.

Case outcomes and the definitions still to confirm

The source material discloses: roughly 2 million patients and tens of millions of clinical documents screened; around 18,000 positive key patients found; roughly 10,000 confirmed valid after review, a validity rate above 60%; and more than 7,000 patients managed through to a closed loop. Outpatient return recall succeeded for about 60% of cases, surgical or inpatient return recall for about 9%. The system is live across hepatobiliary-pancreatic surgery, urology, colorectal surgery, gastrointestinal surgery, thyroid surgery, thoracic surgery, gynaecology, breast surgery, cardiovascular medicine, cardiac macrovascular surgery, vascular surgery, and medical genetics, with plans to extend past 15 specialties.

Redacted recall operating figures: share of valid patients, outpatient return recall rate, and surgical recall rate
Of the three numbers, the 60% valid-patient share matters most.It measures how many of the people the model surfaced survive clinical review -- miss on that one and every recall action downstream is wasted human effort. Institution names and marks have been removed.

These figures help explain project scale and loop design; formal citation still requires confirmation of deduplication, time window, outcome definition, and reporting cutoff.

Disclosed metricSource valueDefinition still required
Patients screened2M+Deduplication, time window, and data coverage
Priority-positive patients18K+Positive definition and rule/model version
Confirmed valid patients10K+ (60%+)Who judges validity, and whether review is blinded
Closed-loop managed patients7K+Whether contact, attendance, and write-back are all required
Outpatient returnAbout 60%Denominator: contacted, confirmed, or all candidates
Inpatient or surgery returnAbout 9%Observation window and attribution

The 9% should not be read as failure. The denominator for surgical and inpatient recall is everyone contacted, and only a minority ever genuinely need surgery. Placing it next to the 60% outpatient figure is meaningless — the two carry completely different clinical thresholds and are not comparable.

Prioritize clinical outcomes and continuity

ValueWhat to measure
Earlier detectionSignals found across records, labs, and imaging
Earlier interventionHigh-risk patients entering human confirmation and priority service
Fewer interruptionsFollow-up, tests, rehabilitation, and recall connected into one path
More individualizationService adapted to disease, risk, preference, and stage

More useful metrics than conversation volume include positive predictive value, time from abnormality to intervention, loss-to-follow-up, closed-loop return, adverse events, and complaints.

Clinical value of earlier detection, earlier intervention, fewer interruptions, and more individualized service
Evaluation focus.Prioritize clinical outcomes and service continuity over conversation or message volume.

Low-friction membership, health data accumulation, contextual outreach, and optional value-added services can turn one visit into a long-term relationship. Commercial outreach still requires explicit authorization, must not influence clinical judgment, and must never exploit health risk to create anxiety.

The chain in the source material runs: a million-member pool created at registration, a health data engine over records, labs, and medications, scenario-based precise recommendation at booking, after report interpretation, at medication reminders, and at checkup follow-up, then conversion into value-added services. Enrolment is designed to be frictionless — registering for care automatically triggers basic membership and unlocks entry-level benefits with zero patient action.

Redacted membership-on-first-visit chain: frictionless enrolment, health data engine, scenario-based recommendation, and value-added conversion
This page is both the opportunity and the concentration of risk.Member names, barcodes, and group brand names have been irreversibly removed.

It is worth showing in full, because avoiding it solves nothing. Any organisation running long-term patient operations eventually faces the same question: can health data be used for commercial conversion, and how far.

My judgment comes down to three lines:

  1. Enrolment may be frictionless; consent may not. The informed-consent checkbox in the corner of that interface is the single most important element on the page. It has to be explicit and revocable, not folded into clause seven of an agreement.
  2. Timing determines character. Recommending insurance right after a patient has read an abnormal result is not the same act as recommending it at booking. The former exploits the anxiety window that opens the moment someone sees a bad number. That timing must be explicitly prohibited, even where it converts better.
  3. Clinical and sales paths must be physically isolated. Not by personal discretion but by system permission: a sales role cannot see diagnoses or laboratory detail, only membership tier and authorised service preferences.

Fail those three and “membership on first visit” stops being a service and becomes harvesting. Meet them and it is a reasonable commercial basis for extending one visit into a long-term health relationship.

The operating system should continuously enforce:

  • data minimization;
  • human sign-off and escalation for high-risk tasks;
  • informed consent and channel preferences;
  • contact-frequency controls and end-to-end audit;
  • ongoing monitoring for performance, bias, and safety.

Start with one disease-specific closed loop

Stage 1: validate in 6–8 weeks

Choose one condition, one defined population, and one set of screening rules, then connect human confirmation with outcome write-back.

Stage 2: replicate in 2–3 months

Expand to multiple specialties, establish shared labels and tasks, and connect the patient-facing channel.

Stage 3: operate the agent continuously

Build long-term memory, proactive risk monitoring, multi-specialty collaboration, and continuous learning.

Three-stage rollout from disease-specific validation to multi-specialty replication and continuous patient agent operation
Rollout path.Complete screening, human review, outreach, and outcome write-back for one condition before expanding into a continuous patient-agent platform.

The first pilot also needs explicit stop conditions: screening performance crosses a safety threshold, the human review queue cannot meet its response target, or complaints and contact refusals rise materially. Any one should pause expansion until the rules, model, or workflow is corrected.

Give every patient a continuously available health twin that understands, remembers, acts, and remains traceable.