Patient-controlled health records AI
Fetch My Epic Token
Fetch My Epic Token enables patient-directed record retrieval. Its 88 describes infrastructure, not clinical AI output. Local scripts and hosted helpers have different data-processing boundaries, and broad no-collection wording does not explain all necessary transient processing.
Published September 8, 2026 as an AI-assisted draft. The public report separates documented facts, agency judgments and unresolved questions.
Summary judgment · 88 out of 100 toward patient-directed
88 is an infrastructure-specific editorial placement. Core AI output is not applicable.
Strongly agency-expanding, with credential-handling and technical-burden caveats
Fetch My Epic Token enables patient-directed record retrieval. Its 88 describes infrastructure, not clinical AI output. Local scripts and hosted helpers have different data-processing boundaries, and broad no-collection wording does not explain all necessary transient processing.
Patient agency
How this tool changes agency
Access to underlying records can support checking and advocacy. Correcting source records remains a provider process, and downstream AI quality is outside this utility.
Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified
Patient agency assessment
Who sets and changes the goal?
Patients gain portable records and can choose downstream analysis. Hosted helper use delegates sensitive processing, while local script use has a different trust boundary.
What can the patient understand, question, or do?
Access to underlying records can support checking and advocacy. Correcting source records remains a provider process, and downstream AI quality is outside this utility.
Can the patient evaluate the conditions of use?
The policy's broad no-collection wording does not explain necessary transient server processing. Source availability enables inspection but is not an audit or evidence of deployment parity.
Text findings
Conditions of use
Published controls and their limits
The policy's broad no-collection wording does not explain necessary transient server processing. Source availability enables inspection but is not an audit or evidence of deployment parity.
What remains unknown?
Not tested or not established
Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified
Who evaluated this?
AI-assisted public-source draft
Vendor statements describe published conditions, not independently verified behavior. No clinical, security, accessibility, or legal validation is claimed. Earlier evidence remains dated in the report and history.
Sources checked
- https://fetch-my-epic-token.org/
- https://fetch-my-epic-token.org/policies.shtml
- https://raw.githubusercontent.com/glmck13/Fetch-My-Epic-Token/main/getEHR_async.py
Source-specific findings and retrieval limitations are recorded in the full report.
Review provenance
Criteria
CAIHL-derived HugoScore framework and September 7 qualitative review priorities. Draft v1.2 numerical anchors remain unadopted.
Reviewer
AI-assisted public-source reassessment prepared in OpenAI Codex.
AI / model
OpenAI Codex / GPT-6
Human review
Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
Review date
2026-09-08
Limitations
Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified No live product use, patient-data upload, account creation, code audit, clinical evaluation, or independent implementation validation.
Review method
Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
AI-assisted draft · Moderate for public interface and source design (AI-assisted draft)