The Healthcare AI Control Plane: Designing the Whole System

A 500-foot operating architecture for the future of healthcare across people, payers, providers, pharmacy, claims, data, agents, human authority, and the learning loop that turns activity into accountable value.
Return to insightsHealthcare founders, CEOs, CFOs, payer and provider executives, pharmacy leaders, product teams, and operating partners / Reviewed 2026-09-01
Decision use
Define the health system before choosing the technology.
This is an independent operator synthesis of current public regulation, interoperability policy, and peer-reviewed research. It describes a category-level architecture and does not imply that any cited institution endorses Azis Dabas or that every future state is already deployed.
Executive thesis
The Healthcare AI Control Plane: Designing the Whole System
A 500-foot operating architecture for the future of healthcare across people, payers, providers, pharmacy, claims, data, agents, human authority, and the learning loop that turns activity into accountable value.
Public facts
CMS-0057-F makes payer-provider interoperability operational: impacted payers face process requirements generally beginning in 2026 and API requirements generally beginning in 2027 for patient, provider, payer-to-payer, and prior-authorization exchange.
ASTP/ONC reported in February 2026 that nearly 500 million health records had been exchanged through TEFCA, evidence that nationwide exchange is becoming a practical substrate rather than a policy abstraction.
A 2026 Nature Health framework argues that longitudinal health agents require coherence, continuity, adaptation, and agency across repeated interactions, not isolated prompt-response encounters.
A 2026 npj Digital Medicine framework says meaningful oversight depends on epistemic capacity, cognitive space, decisional authority, and intervention effectiveness. A human's presence alone is not an operating control.
A 2026 scoping review of agentic AI in healthcare found only seven eligible studies; most were exploratory, few had real-world deployment, and only one involved patients. The capability narrative remains ahead of clinical validation.
FDA guidance increasingly treats AI as a total-product-lifecycle concern, including planned modifications, monitoring, real-world performance, and controls that continue after deployment.
Operator read
The future health system will not be run by one model. It will be coordinated by a control plane that carries context, policy, identity, action rights, human authority, and evidence across many specialized systems.
The unit of design is moving from an encounter or task to a longitudinal trajectory. That changes the product requirement from producing a good answer to maintaining continuity, ownership, follow-through, and safe adaptation over time.
Healthcare's core architecture is economic as well as clinical. Coverage, benefit design, provider capacity, pharmacy access, claims, and patient burden determine whether an apparently intelligent workflow can actually operate.
Agentic capability should be classified by consequence, reversibility, and action scope. Retrieving context, drafting a message, changing a queue, initiating an authorization, and influencing care are not the same autonomy tier.
The durable moat is not access to a foundation model. It is trusted context, workflow position, integration depth, operating rights, distribution, and an evidence loop that becomes more useful with responsible use.
Value must be reconciled across the system. Labor removed from one organization can become rework, access friction, patient burden, or financial risk somewhere else.
Architecture artifact / whole-system crosswalk
Where the system lives. How control operates. How a decision travels.
The control plane is the connective architecture across the health system, not another destination or autonomous model.
Ten health-system domains
The boundary of the system being designed.
- 01Person and caregiver
The durable subject of the system.
- 02Care delivery
Encounters, plans, escalation, and follow-through.
- 03Provider network
Capacity, referral corridors, and operating fit.
- 04Payer and coverage
Benefits, authorization, eligibility, and risk.
- 05Pharmacy and therapeutics
Access, adherence, fulfillment, and outcomes.
- 06Diagnostics and labs
Signals that change the clinical or operating path.
- 07Claims and revenue cycle
Transactions, denials, payment, and burden.
- 08Data and interoperability
Portable context with provenance and freshness.
- 09Agents and workflow
Specialized intelligence placed in the work.
- 10Authority and learning
Human ownership, economics, and adaptation.
Five control planes
The governing capabilities that make the system coherent.
- 01Context
Assemble the person, episode, evidence, history, and current state.
- 02Policy
Translate rules, benefits, clinical boundaries, and incentives into constraints.
- 03Action
Choose the smallest useful next step, with explicit permissions and rollback.
- 04Authority
Give the right person the time, information, and power to decide or interrupt.
- 05Evaluation
Measure outcomes, exceptions, burden, equity, value, and drift.
Six decision chapters
The sequence that turns a need into accountable evidence.
- 01Need
A signal, friction, risk, or unmet goal makes the next decision necessary.
- 02Context
The control plane carries a coherent person-and-episode state into the work.
- 03Policy
Rules and incentives narrow what is permitted, advisable, or out of bounds.
- 04Action
An agent drafts, recommends, routes, or initiates a bounded move.
- 05Authority
A named human or accountable service accepts, changes, stops, or reverses it.
- 06Evaluation
The result becomes evidence for value, safety, burden, and the next need.
Every evaluated outcome re-enters the system as the context for the next decision.
Operating response
Translate the signal into a governed decision.
The architecture is a forward-looking operator framework grounded in cited public sources. It separates published facts from interpretation and makes no claim that Azis personally built the public systems discussed.
Buyer implications
Health-system leaders need an enterprise architecture that distinguishes the data plane, decision plane, action plane, authority plane, and evidence plane before scaling AI use cases.
Payers and providers should design electronic authorization and data exchange as shared workflows with exception ownership, not simply compliant endpoints.
Pharmacy, medical benefit, diagnostics, and care delivery should be modeled as one therapy-access-and-outcomes loop when the patient experience crosses those boundaries.
Founders should define the longitudinal outcome and operating owner before choosing an agent framework or model stack.
CFOs and investors should evaluate transferred burden, implementation cost, exception growth, and evidence durability alongside gross automation or productivity claims.
Founder actions
- 01
Map the whole system around one patient, member, provider, or transaction journey, including every handoff, incentive, data boundary, and exception owner.
- 02
Define one longitudinal unit of value and state how it affects access, quality, operating burden, total cost, and trust.
- 03
Separate context, decision, action, authority, and evidence into explicit architecture layers with named owners and interfaces.
- 04
Create an autonomy matrix that sets permissions, required evidence, human review, escalation, rollback, and stop rules by risk tier.
- 05
Instrument provenance, freshness, overrides, exceptions, subgroup performance, drift, workflow impact, and finance-validated value from the first pilot.
- 06
Design for interoperability and portable evidence so the operating model can survive a new payer, provider, pharmacy partner, EHR, or model vendor.
Metrics that matter
Time from qualified signal to closed-loop action
Continuity and completion across care, coverage, and therapy handoffs
Percentage of consequential outputs with traceable source, freshness, and reviewer action
Exception, override, escalation, reversal, and unresolved-queue behavior
Access, quality, equity, patient burden, and operating impact by population
Finance-validated net value after implementation, human review, rework, and transferred cost
Real-world performance, calibration, drift, and incident response over time
Red flags
The AI strategy starts with a model or vendor rather than a system problem and accountable owner.
Medical, pharmacy, claims, and care workflows are optimized independently even though the patient journey crosses all four.
Human-in-the-loop means a person is present, but that person lacks time, context, authority, or a reversible control.
An agent can invoke tools or change workflow state without explicit action rights, provenance, and escalation rules.
The pilot reports accuracy or automation while ignoring continuity, exceptions, downstream burden, and real-world outcomes.
Scaling volume increases hidden manual work faster than the operating system can resolve it.
Executive questions
- 01
What is the full system boundary, and which important actor or incentive is currently outside it?
- 02
Whose goal is the system optimizing, and what happens when patient, payer, provider, pharmacy, and financial goals conflict?
- 03
What longitudinal context must travel with the person, decision, and workflow for the system to remain coherent?
- 04
What can the AI observe, recommend, initiate, change, and complete without approval?
- 05
Who has the time, information, authority, and practical control to interrupt or reverse a consequential action?
- 06
Which outcome proves the system created value rather than moving cost or work to another part of healthcare?
- 07
What does the architecture learn after deployment, and who is accountable for changing it?
Primary and attributed sources
The cited agencies, publishers, and authors inform the analysis and do not endorse this framework or its recommendations.
Related operating work
Use this mandate to define the system boundary, longitudinal value unit, operating owner, action rights, evidence loop, and first implementation wedge.
Architect the operating mandateStart a serious conversation