Solutions · Healthcare

Keep your agents’ patient updates with the care team.

Let your agents use patient records to coordinate care. Set policies that allow updates to the care team’s channel and block posts to department-wide channels.

Custom MCP
Reads a patient’s recordEHR MCP · patient record
✓ Allow
Slack
Posts a visit summary to a department channelSlack MCP · department-wide channel
✗ Deny
Slack
Posts it to the care team’s channelSlack MCP · private channel
✓ Allow

Why: patient record read by the same identity.

Both servers connect through Wicket.

Choose which sharing attempts to block.

Use these policies to let your agents read the records they need while blocking their writes to the destinations below.

  • Care coordination

    A care-coordination agent reads a patient’s record, then tries to post a visit summary to a department-wide Slack channel.

    Custom MCP
    Reads a patient’s recordEHR MCP · patient record
    ✓ Allow
    Slack
    Posts to a department channelSlack MCP · department-wide channel
    ✗ Deny

    PolicyBlock posts to department-wide channels after the same identity reads a patient record.

  • Research exports

    A research agent reads lab results for a patient cohort, then tries to copy them into an external Airtable base.

    Custom MCP
    Reads cohort lab resultsEHR MCP · patient data
    ✓ Allow
    Airtable
    Copies into an external baseAirtable MCP · external base
    ✗ Deny

    PolicyBlock writes to external bases after the same identity reads patient data.

  • IT support

    A support agent reads a patient’s record to reproduce a portal bug, then tries to file a Jira ticket that contains it.

    Custom MCP
    Reads a patient’s recordEHR MCP · patient record
    ✓ Allow
    Jira
    Files a ticket with the recordJira MCP · IT project
    ✗ Deny

    PolicyBlock ticket creation after the same identity reads a patient record.

Set sharing rules for patient data.

Let your agents read charts and update the care team. Choose which other destinations to block after that access. Test your draft policy against the last 24 hours of calls before enforcing it.

  1. 01

    Connect the EHR

    Work with our team during onboarding to connect your EHR’s MCP server through Wicket. Connect Slack, Airtable, and Jira through Wicket too.

  2. 02

    Choose the patient data to protect

    Scope your read policy to patient records and lab results. Leave scheduling and directory lookups outside that policy.

  3. 03

    Allow updates to the care team’s channel

    Allow updates to private care-team channels and internal notes after a patient record is read.

  4. 04

    Block wider sharing

    Block posts to department-wide channels, writes to external bases, and ticket creation after the same identity reads patient data.

Show your privacy team why sharing was blocked.

Each denial records the agent, the clinician it acted for, the earlier patient-record read, and the blocked destination. Wicket blocks the message before it reaches Slack.

AUDIT-4E9A612 ✗ Denied
Who
care-agent · OBO j.lee@hospital.example
What
slack.send_message → department-wide channel
When
09:41:15 UTC · Slack MCP
After
ehr.get_patient_record · patient chart · 09:39:02 UTC
Why
block-broadcast-after-patient-read — patient-record read matched earlier for this identity

Other solutions

Tell us what your agents need to access.

Wicket applies policies using earlier policy matches for the same identity. It does not classify message contents, and both MCP servers must connect through Wicket. We’ll help you plan custom MCP connections during onboarding.