All insights
Responsible automation9 min read

What should — and shouldn’t — be automated in a medical practice?

Every practice manager is now being asked which parts of the day AI could take over. The useful answer is not a list of tools. It is a test you can apply to any task, and a short list of things that should never pass it.

“Automate everything you can” is the wrong rule for a medical practice. A practice is not a mailroom. Each document that arrives carries a consequence for a specific patient, and the practice, not the software, is accountable for what happens to it. The right rule is narrower: automate the preparation, keep the decision.

That rule is easier to state than to apply, because most administrative work in general practice is a blend of the two. Filing a specialist letter is mechanical until the patient name matches two records. Triaging results is routine until one of them is not. What follows is a way of separating the two inside any task, a list of what belongs on each side, and what Australian guidance says about the line between them.

A test for any task

Four questions that decide it

Run any step of the day through these four questions. A task that passes all four is a good candidate for automation. A task that fails the last two should stay with a person, no matter how repetitive it is.

  1. 01

    Is it repetitive?

    Automation pays for itself on work that looks the same a hundred times a week. Reading a sender’s name off a letterhead qualifies. Deciding what a one-off complaint means does not.

  2. 02

    Is it reversible?

    If a mistake can be undone in seconds with no one harmed, the task can run ahead of a person. If a wrong outcome reaches a patient, a record or a clinician’s decision, it cannot.

  3. 03

    Is it verifiable?

    Can a staff member check the result against the source in a glance? Automation that shows its evidence is reviewable. Automation that only shows its answer is a guess you have to trust.

  4. 04

    Who carries the consequence?

    Under RACGP Standards Criterion GP2.2, the practice is responsible for reviewing, noting and acting on every result and item of correspondence. A tool can prepare that review. It cannot own it.

Passes the test

What a medical practice should automate

These are the steps in handling clinical correspondence that are repetitive, reversible and easy to check. They are also where most of the retyping and screen-switching lives.

Sorting incoming documents by type

Pathology, imaging, specialist letter, discharge summary, referral, administrative. A wrong label is caught the moment a person opens the document.

Lifting identifiers out of the document

Name, date of birth, Medicare number, sender, report date. Extracted into editable fields with the source text highlighted, never silently written anywhere.

Proposing a patient match

Automation can find the likely record and say how confident it is. The match is a proposal until someone confirms it, especially when two patients share a name.

Drafting the summary line and category

A one-line description and a filing category save typing on every document. Both are editable before anything is saved.

Flagging language that suggests urgency

Phrases like “urgent review” or “critical value” can raise an item to the top of the queue. Raising a flag is administrative. Deciding what to do about it is clinical.

Moving reviewed documents to the right place

Once a person has confirmed the patient, the type and the recipient, the filing step and the routing to a doctor’s inbox are pure mechanics.

Keeping the trail

Who reviewed what, when, and where it went. Recording this by hand is the first thing to slip on a busy day and the first thing an accreditation surveyor asks for.

Fails the test

What should stay with people

None of these is hard to automate technically. All of them fail on consequence: a wrong answer reaches a patient, a record or a clinician before anyone can catch it.

Deciding a result is clinically significant

Significance depends on the patient’s history and context. It is the treating practitioner’s judgement and, under GP2.2, their responsibility.

Acting on a result

Recalling a patient, changing treatment, arranging follow-up. The system can remind; it must not decide.

Writing anything into the record unseen

Nothing generated by software should reach the patient record before a person has looked at it alongside the source. This is the single rule that keeps everything else safe.

Resolving a conflicting identity

When the name matches but the date of birth does not, or the document mentions two patients, a person decides. The wrong record is a privacy breach and a clinical risk in one move.

Discarding or ignoring a document

“This isn’t ours” or “this is a duplicate” are decisions with consequences. They should be one click for a human and impossible for a machine acting alone.

Anything that recommends diagnosis or treatment

The TGA’s 2026 guidance is clear: software that offers diagnostic or treatment recommendations is a medical device and needs to be regulated as one. Administrative tools should stay administrative.

The grey zone: prepare, don’t decide

Three tasks sit on the line and cause most of the argument: classifying a document, matching it to a patient, and judging whether it is urgent. Each is repetitive enough to automate and consequential enough that a wrong answer matters.

The resolution is the same for all three. Let the software do the work of proposing an answer, and require a person to confirm it, with the evidence in view. A proposed patient match with the name and date of birth highlighted on the document is checked in two seconds. A silent match, applied in the background, is checked by nobody until it goes wrong.

The test of a well-designed tool is not how often it is right. It is how obvious it is when it is wrong.

This also settles the question of uncertainty. Blurry scans, missing dates of birth, a report that names two patients: a tool that is allowed to guess will guess. A tool that is built to prepare will surface the exception and wait. The second behaviour is slower on that one document and safer on every document.

The Australian position

What the regulators and the College say

The test above is not a house opinion. It is a plain-English reading of the guidance Australian practices are already held to.

  • RACGP Standards, Criterion GP2.2

    Incoming pathology, imaging, investigation reports and correspondence must be reviewed, noted, acted on where needed and added to the patient record, and each review must itself be recorded. The responsibility sits with the practice and the treating practitioner. Automation that prepares and records that review supports the criterion; automation that performs it does not.

  • TGA guidance on AI software, 2026

    Software is regulated by its intended purpose, not its technology. Transcribing, classifying or extracting from a document is not a medical device. Analysing content to recommend a diagnosis or treatment is, and must be registered as one. The line in this article is the same line.

  • RACGP, TGA and the Safety and Quality Commission on AI

    Coordinated guidance for general practice repeats three requirements: verify AI-generated content before it informs care, guard against automation bias, and never put patient information into a general-purpose chatbot. Practices are also expected to document how AI tools are governed, which accreditation surveyors can ask to see.

This article is general information about practice workflow, not legal or clinical advice. Check the current RACGP, TGA and OAIC guidance for your circumstances.

A ten-minute audit of your own practice

Before looking at any product, map what you do now. Six questions expose where automation would help and where it would quietly take on a decision it should not.

  1. 1List every step between a document arriving and it being filed. Mark each one repetitive or judgement.
  2. 2For each repetitive step, ask: if the tool got this wrong, who would notice, and when?
  3. 3For each judgement step, ask: does the person making it have the source document and the patient context on the same screen?
  4. 4Find the steps where staff currently retype something that is already printed on the document.
  5. 5Find where the review is recorded today, and whether a surveyor could see it without asking anyone.
  6. 6Write down what happens when the tool is uncertain. If the answer is “it guesses”, it is not ready.

For a fuller map of the steps between arrival and filing, see From Practice Inbox to Patient Record.

Frequently asked questions

Is AI document processing in a medical practice a medical device?

Not when it stays administrative. The TGA’s 2026 guidance regulates software by intended purpose: tools that transcribe, classify, extract or file documents without offering diagnostic or treatment recommendations are not medical devices, while tools that analyse content to recommend a diagnosis or treatment are. Practices should ask any vendor which side of that line their product sits on and why.

Can automation satisfy RACGP Criterion GP2.2 on follow-up systems?

It can support it but not replace it. GP2.2 requires incoming results and correspondence to be reviewed, noted, acted on and added to the patient record, with the review itself recorded. Automation can prepare the document, propose the patient and category, and keep the audit trail, but a practitioner or delegated staff member must still perform and record the review.

What is the safest first task to automate in a general practice?

The preparation of incoming correspondence: classifying the document type, extracting identifiers into editable fields with the source highlighted, and proposing a patient match. Every one of those outputs is checked in seconds by the person who was already going to open the document, so errors are caught before anything is saved.

Do staff still need to read every document if a tool summarises it?

Yes. A summary is a convenience for triage, not a substitute for review. Australian AI guidance from the RACGP, the TGA and the Australian Commission on Safety and Quality in Health Care consistently requires AI-generated content to be verified by a person before it informs care, and warns specifically about automation bias, the habit of trusting a confident-looking output.

How MEDsort applies this

Automation that prepares. People who decide.

MEDsort reads incoming clinical correspondence, classifies it, extracts the details into editable fields and shows where in the document each one came from. Nothing is written to a Best Practice record until a member of your team has reviewed it. Uncertain matches are surfaced, not guessed. And the review is recorded, so the trail GP2.2 asks for exists without anyone typing it.