Maintenance Notice

Due to necessary scheduled maintenance, the JMIR Publications website will be unavailable from Wednesday, July 01, 2020 at 8:00 PM to 10:00 PM EST. We apologize in advance for any inconvenience this may cause you.

Who will be affected?

Accepted for/Published in: JMIR Medical Informatics

Date Submitted: Sep 2, 2025
Open Peer Review Period: Sep 15, 2025 - Nov 10, 2025
Date Accepted: Jun 30, 2026
(closed for review but you can still tweet)

The final, peer-reviewed published version of this preprint can be found here:

A Secure User Interface for Preclinical Evaluation of AI in Patient Portal Message Management: Tutorial

Gleason K, Kidu T, Babu V, Hasselfeld B, Wolff J

A Secure User Interface for Preclinical Evaluation of AI in Patient Portal Message Management: Tutorial

JMIR Med Inform 2026;14:e83216

DOI: 10.2196/83216

PMID: 42475255

A Secure User Interface for Pre-Clinical Evaluation of Artificial Intelligence in Patient-Portal Message Management: A Tutorial

  • Kelly Gleason; 
  • Thomas Kidu; 
  • Vignesh Babu; 
  • Brian Hasselfeld; 
  • Jennifer Wolff

ABSTRACT

The growing use of artificial intelligence (AI) to support patient-portal message management requires rigorous pre-clinical evaluation. Directly testing AI within electronic health record (EHR) systems poses significant safety, workflow, and data-governance risks. Here, we present a technical feasibility report on a secure user interface (UI) sandbox designed to enable clinical and technical teams to experiment with AI for portal messaging on de-identified data before clinical integration. Here, a sandbox refers to a controlled, non-production environment that allows safe testing, prompt iteration, and evaluation of AI outputs without impacting live EHR systems or patient care. We developed a web UI in Python 3 with a modular backend for data handling, de-identification, and AI task execution. The system runs in a secure research environment equipped with an NVIDIA GRID T4-1Q GPU and institutional access controls. We designed a de-identification pipeline to remove or replace personal health identifiers. The platform supports single-message and batch workflows and exposes exemplar LLM-enabled tasks such as authorship identification, message categorization, criticality flagging, and response drafting using zero-, one-, and few-shot prompting. Only de-identified text is sent to the model endpoint. The system successfully executed end-to-end workflows: ingest de-identified messages, run individual or batch AI analyses, and present outputs for review. PHI masking was consistently applied across the corpus. We ran use cases with an IRB-approved corpus of a dementia-relevant subset of 6,941 patient portal messages categorized as “Medical Advice Requests.” With the support of the user interface, we tested which prompting strategies to yield interpretable outputs for authorship identification, categorization, and criticality flagging, and whether response drafting produced editable clinician starting points. A token-based cost readout provided transparent operating estimates for LLM-backed tasks. This framework offers a practical path to test AI behavior on real, de-identified messages without affecting live EHR workflows and thus supports exploratory testing, prompt iteration, and comparative analyses, including LLM prompts versus baseline models, while preserving governance boundaries. We discuss design choices, safety controls, and the limits of a sandbox approach. A secure, UI-based sandbox enables health-system teams to evaluate AI for patient-portal messaging before clinical integration. The goal is not to assume benefit but to generate evidence about feasibility, risks, and fit to clinical needs in a controlled setting.


 Citation

Please cite as:

Gleason K, Kidu T, Babu V, Hasselfeld B, Wolff J

A Secure User Interface for Preclinical Evaluation of AI in Patient Portal Message Management: Tutorial

JMIR Med Inform 2026;14:e83216

DOI: 10.2196/83216

PMID: 42475255

Download PDF


Request queued. Please wait while the file is being generated. It may take some time.

© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.