Resources | Insights

Trust by design: Included Health's commitment to responsible AI

By Owen Tripp, CEO and Co-Founder
A header image showing Owen Tripp speaking at an event.

AI is reshaping healthcare at extraordinary speed. The companies that lead the way will deliver innovation and accountability, not choose between them. To move healthcare forward faster, safely, and responsibly, we must build trust into AI from the outset.

AI has created a generational opportunity to improve healthcare access, experience, and outcomes while lowering costs. From surfacing population-level insights to making healthcare more personalized, responsive, and easier to navigate, AI has the potential to raise the standard of healthcare in profound ways. But in healthcare, technology is only transformative if people trust it. To earn that trust, AI must be clinically grounded, thoughtfully governed, and designed around people's best interests.

That is both the challenge and the responsibility facing our industry. As AI adoption accelerates, the stakes are too high for shortcuts: The data is deeply personal, biased or inaccurate models can lead to mental and bodily harm, and confidence in the technology is difficult to regain once lost. AI will fulfill its potential only if trust guides every decision, process, and safeguard that goes into it.

Our commitment to trustworthy AI

Many organizations have published AI principles; what matters is how those principles are operationalized. At Included Health, trust takes shape through clinician-led validation, risk-based human oversight, and governance that keeps our practices aligned with our commitments.

While AI helps Included Health's care teams work at the top of their license and get members to the right next step faster, those advantages never come at the expense of individuals' health and well-being. Our commitment is to advance AI with both ambition and accountability, across safety, human oversight, privacy and security, and transparency.

Safety

The safety of our members takes precedence over any other goal. Building safety into every stage of AI development, testing, and deployment is the first condition for earning trust. At Included Health, clinician-led multidisciplinary teams rigorously validate and monitor AI products — including our AI healthcare assistant, Dot — to identify potential risks, as described in our 2026 NEJM Catalyst publication.

Critically, we do not rely solely on the safety features built into the foundational large language models (LLMs) we use. General-purpose LLMs include basic content filtering and guardrails against certain high-risk queries (regarding self-harm, for example), but those native safeguards are insufficient for safety-sensitive clinical guidance. We take accountability for the safety of our AI by applying additional safeguards, including:

  • Pre-launch evaluation. Dot's AI capabilities undergo structured evaluations in staging environments before any production launch. These evaluations test coverage, accuracy, routing logic, voice and tone, and edge-case handling. For new generative AI capabilities, evaluations must meet defined performance thresholds before release.

  • Cross-functional design and review. Before any AI or machine learning (ML) model is implemented, engineers, data scientists, product managers, and clinicians conduct a mandatory cross-functional review to ensure the design and its expected outcomes are ethically sound. Our Security and Privacy teams also review every application that uses ML or AI before it goes live.
  • Emergency routing. In ambiguous or high-risk situations, our AI healthcare assistant, Dot, does not attempt to provide guidance. When a member's question falls outside clearly defined boundaries, Dot directs members to our care team or, where appropriate, to emergency services. These guardrails are non-negotiable and are not configurable by the member.

No built-in guardrail can catch everything on its own. Human oversight continues well after launch, throughout the product's entire lifecycle. Included Health's human care teams are the ultimate safety backstop. Members always have a clear path to a person.

Human oversight

Included Health applies clinician-in-the-loop oversight wherever AI is involved in member experience or clinical guidance. After launch, our teams conduct ongoing audits and targeted evaluations to identify and address hallucinations, bias, and model drift. We've implemented near real-time clinician review of Dot's conversations, so that if there's concern for an emergency — or if Dot misses something rare — our care team intervenes. Here's what that oversight looks like in practice:

  • Seamless escalation to human support. When Dot encounters a question outside its scope or detects clinical complexity, or when a member requests a human, Dot provides a clear, context-aware handoff to a live Member Care Advocate. The care team receives the full conversation context so the member never has to repeat themselves.

  • Ongoing monitoring. Human review is central to our monitoring approach, and the level of review scales with the risk profile of each application. For new tools in early pilot phases, we review 100 percent of AI-generated outputs. As confidence grows, we shift to reviewing representative samples. For certain high-stakes applications, human review occurs every time, without exception.

  • Prompt and model refinement. With the aid of automated tools, the Included Health team continuously compares AI-generated outputs against verified, real-world data — including conversations between members and human care team members, and internal care team notes — to refine our AI products and prompts.
  • Bias and fairness. We carefully curate representative training and test sets, and we conduct additional validation on model performance across demographic subgroups to identify and address potential bias. We also actively collect patient-reported data on social determinants of health to give our models a richer picture of the populations we serve. Identified inaccurate or biased data is quarantined and removed from training datasets.

At Included Health, consequential decisions for a member's health remain in human hands, informed and assisted by AI. Coupling high-speed automation with human clinical accountability protects member trust better than either one alone. As AI models, user behavior, and clinical best practices evolve, our oversight evolves with them.

Privacy and security

AI tools suitable for general use are not necessarily suitable for healthcare. When it comes to members' health, privacy and data security must be built in, not bolted on. We embed HIPAA and other applicable regulations in the architecture and governance of our AI applications, which undergo thorough review by our cybersecurity, compliance, and clinical teams before any AI product goes live.

When sensitive health information is involved, we apply heightened controls over access, data handling, deployment, and third-party use that are designed to detect and restrict sensitive information before it is exposed to an AI model. Key controls in place include:

  • Business Associate Agreements (BAAs). We require all external LLM providers to execute BAAs with Included Health, classifying them as HIPAA Business Associates and subjecting them to all applicable HIPAA administrative, technical, and physical safeguard requirements.

  • Member data. We ensure that only the minimum necessary data is passed to an LLM; no bulk member data is transmitted. We engineer prompts to minimize the exposure of protected health information (PHI) to LLMs, and where possible, we replace member-identifying information with anonymized tokens before passing data to external models.

  • Client data. For applications that touch sensitive data, we do not use public-facing AI tools. We deploy enterprise-grade models hosted in a private cloud or on our clients' own servers, ensuring that client data is never commingled or used for unauthorized purposes.

  • Data retention and use. We contractually require external providers to implement a zero data retention policy for Included Health's prompts, member inputs, and query data. Additionally, for LLM-based applications, we contractually require that outside providers do not use any Included Health data to train or improve their foundation models.

As in all aspects of our business, we put the interests of our members first when it comes to privacy and security. Our members entrust their data and personal information to us to support their care, and we ensure that data and information are used for nothing else.

Transparency

Transparency is not a standalone commitment. It is the thread that holds the other dimensions together, and the way we demonstrate safety, oversight, and privacy to our members and clients.

Included Health provides multiple layers of guidance to help members understand how to interact with AI products effectively and recognize its scope and limitations. In member-facing AI experiences, we disclose AI's role, using plain language that communicates what the system can and cannot do. Members know when they are interacting with AI, and the path to a person is clearly marked. Here's how we achieve that:

  • In-product onboarding and prompts. When members first access Dot, they are presented with a brief introduction to the assistance Dot can provide, including sample questions and suggested conversation starters. This helps members understand Dot's capabilities and intended use cases, and how to phrase their questions for best results.
  • Scope transparency. Dot's interface makes clear that it is an AI-powered assistant best suited for benefits navigation, coverage questions, provider search, and claims status. For complex clinical questions or any emergency, Dot clearly communicates the limits of its capabilities and provides immediate pathways to human support.

  • Clear communication. Dot is governed by a series of voice and tone protocols that ensure Dot's explanations are clear and accessible to every member. Where relevant, Dot also explains the rationale behind its responses. When members search for a provider, for example, Dot generates summaries of recommended providers that help members understand why Included Health believes that provider is a good fit.

Just as important, we make our AI policies and processes transparent to clients, too. Our cross-functional AI governance committee conducts regular reviews to ensure that what we say publicly reflects what we actually do, and we believe our clients deserve to understand, at any time, how we are using AI on behalf of their members. We maintain active feedback loops, co-develop solutions to real-world challenges, and continually assess the impact that our AI applications have on both clients and members.

We are all in the loop

This work belongs to everyone at Included Health. Building trustworthy AI is not the mandate of a single team or committee; it's a shared responsibility that runs from the C-suite to frontline clinicians, from engineers and product designers to legal, compliance, and member services.

This company-wide accountability is not incidental. The decisions that determine whether AI earns or erodes trust in the market require contributions from across our organization, because no single leader or discipline has the full picture. Checks, balances, and diverse viewpoints keep our members' interests at the core of our AI.

The healthcare companies that will have the greatest positive impact in the AI era will be the ones that can innovate credibly, govern rigorously, and earn confidence from members, clients, clinicians, and regulators. That's the standard Included Health is committed to upholding.

Owen Tripp Included Health