Accepted for/Published in: JMIR Medical Informatics
Date Submitted: Sep 2, 2025
Open Peer Review Period: Sep 15, 2025 - Nov 10, 2025
Date Accepted: Jun 30, 2026
(closed for review but you can still tweet)
Warning: This is an author submission that is not peer-reviewed or edited. Preprints - unless they show as "accepted" - should not be relied on to guide clinical practice or health-related behavior and should not be reported in news media as established information.
A Secure User Interface for Pre-Clinical Evaluation of Artificial Intelligence in Patient Portal Message Management
ABSTRACT
Background:
The growing use of artificial intelligence (AI) to support patient portal message management requires rigorous pre-clinical evaluation. Directly testing AI within electronic health record (EHR) systems poses significant safety, workflow, and data-governance risks. We developed and describe a secure user interface (UI) that enables clinical and technical teams to experiment with AI for portal messaging on de-identified data before clinical integration.
Objective:
We developed a secure user interface (UI) that enables clinical and technical teams to experiment with AI for portal messaging on de-identified data before clinical integration, which we describe here for others to adapt.
Methods:
We developed a web UI in Python 3 with a modular backend for data handling, de-identification, and AI task execution. The system runs in a secure research environment equipped with an NVIDIA GRID T4-1Q GPU and institutional access controls. An IRB-approved corpus of patient-portal messages was cleaned to a dementia-relevant subset of 6,941 Medical Advice Request messages. We designed a de-identification pipeline to remove or replace personal health identifiers. The platform supports single-message and batch workflows and exposes exemplar LLM-enabled tasks such as authorship identification, message categorization, criticality flagging, and response drafting using zero-, one-, and few-shot prompting. Only de-identified text is sent to the model endpoint.
Results:
The system successfully executed end-to-end workflows: ingest de-identified messages, run individual or batch AI analyses, and present outputs for review. PHI masking was consistently applied across the corpus. Exemplar runs demonstrated prompting strategies to yield interpretable outputs for authorship identification, categorization, and criticality flagging, while response drafting produced editable clinician starting points. A token-based cost readout provided transparent operating estimates for LLM-backed tasks.
Conclusions:
This framework offers a practical path to study AI behavior on real, de-identified messages without affecting live EHR workflows and thus supports exploratory testing, prompt iteration, and comparative analyses, including LLM prompts versus baseline models, while preserving governance boundaries. We discuss design choices, safety controls, and the limits of a sandbox approach. A secure, UI-based sandbox enables health-system teams to evaluate AI for patient-portal messaging before clinical integration.
Citation
Request queued. Please wait while the file is being generated. It may take some time.
Copyright
© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.