ChironAI OMHow we prevent fabrication

The honest answer to “what if it makes something up?”

Most answers to that question are reassurance. Ours is a list of places where the software refuses to produce an answer at all — because the constraint is in the construction rather than in the instructions given to a model.

Each guarantee below names the function that implements it. A gate in the product repository checks that every one of those functions still exists; if a guarantee is removed, that build fails and this page has to change.

A causation determination in ChironAI OM, showing the conclusion, mechanism analysis, diagnostic correlation and timeline validation as separate reviewable blocks. The timeline validation reads: relied only on provided case data; revised determination: no, initial analysis consistent.
Two of the guarantees below are visible in this screen. “Relied only on provided case data” is the provenance rule. “Revised determination: no — initial analysis consistent” is the verification pass reporting that it tried to overturn the first answer and could not. Synthetic data — no real patient or practice appears on this site.
Eight guarantees

Constrained by construction, not by instruction.

A claim that cannot reach a source is dropped

Every entry in a record chronology has to trace to a document that was actually fed to the model. Entries citing anything else do not make it into the output.

Fail-closed: the default is to discard, not to include and flag. An unsourced line never reaches a physician to be missed.

record-digest-chronology.ts · buildProvenancedEntries

A second pass tries to refute the first

After the chronology is built, an adversarial pass goes back over it and attempts to disprove each entry against the source material.

Generating and checking are separate steps with opposite objectives. A model asked to review its own work agrees with itself; a model asked to break it does not.

record-digest-verification.ts · planVerification

Page citations are verified against the page

A report that cites [Ex. 4 p.17] is checked back against exhibit 4, page 17. A citation that does not resolve does not ship.

The citation is treated as a falsifiable assertion rather than a formatting convention.

digest-citations.ts · verifyPageCitations

Legal authorities come from a closed registry

Escobedo, Brodie, Hikida, Almaraz/Guzman and the rest are drawn from a fixed list. An authority outside it is rejected rather than rendered.

Invented case citations are the single most damaging failure mode for a medical-legal document. The model cannot produce one, because it is not choosing from an open set.

justine.service.ts · VALID_AUTHORITY_KEYS

A date that cannot be read is left blank

Extracted dates are validated. Where a date is illegible or absent, the field stays empty instead of receiving a plausible guess.

A wrong date on a chronology moves causation, apportionment and every statutory clock that runs from it.

record-digest-chronology.ts · isValidIsoDate

Sources that disagree are surfaced as a dispute

Where two documents conflict, the conflict is presented as a conflict — not silently resolved in favour of the more recent or the more confident.

The disagreement between records is frequently the fact that matters. Smoothing it away is how a defensible file becomes an indefensible one.

record-digest-chronology.ts · reconcileConflicts

A truncated document says so

If a document was too long to be read in full, the output carries a per-document warning naming what was cut.

Silent truncation produces an answer that looks complete. The warning is attached to the document, not buried in a log.

record-digest.service.ts · truncationWarnings

A malformed model response fails closed

Structured output that does not parse is an error, not a best-effort salvage.

The alternative — recovering what can be recovered from a broken response — is how a partial answer gets presented as a whole one.

llm-response-parser.ts · parseStructuredLLMResponse

The one we would demo first

The software argues with itself before you see the file.

A record chronology is built, and then a separate pass is run with the opposite instruction: take every entry and try to break it against the source. What survives is what reaches the physician.

There is a companion to it on the case as a whole — a defence pre-mortem that war-games the file the way opposing counsel will, before anyone else gets the chance.

Timeline validation — as it appears on the determination

“Answered Q1–Q4. Relied only on provided case data. Mechanism-to-diagnosis correlation is medically sound. Alternative explanations (degenerative changes) are minor and not substantial contributors given the acute onset and lack of prior symptoms. Revised determination: no — initial analysis consistent.

The last sentence is the part that matters. The system is reporting that it went back and tried to overturn its own conclusion, and says so whether or not it succeeded.

Where it stops

The physician signs. Nothing else does.

Nothing is written without a person

Report sections lock behind physician approval. EOR postings are proposals a human confirms or discards. The system drafts; it does not decide.

Section locking · extract-then-confirm posting

It never claims to be a clinician

Output is rewritten to remove any phrasing that would imply licensure, in line with California AB 489. Decision support, stated as decision support.

scrub-licensure-claims.ts · scrubLicensureClaims

AI-derived content says that it is

A disclosure is attached to responses derived from the reasoning layer, rather than left to the reader to infer.

ai-disclosure.ts · withAiDisclosure

Try to make it cite something that is not there.

That is the demo we would rather give. Bring a file with a gap in it, or a document that contradicts another one, and watch what the system does with it. Nothing about that conversation requires you to take our word for anything.

Book a demo
Next stepOne conversation

See it run an encounter that looks like yours.

Tell us the workflow you want to see and who needs to be in the room. A member of our clinical and engineering team replies within two business days to arrange it — a real person, not a sequence.

Talk to our team →

What happens after you send it

  1. 01. The form reaches a monitored inbox. No auto-sequence.
  2. 02. We reply within two business days to book a time that suits you.
  3. 03. Forty-five minutes: your workflow, the reasoning trace, procurement questions.

Prefer to talk now? +1 (949) 200-8668, or email hello@mindhyve.ai.