Patient-controlled health records AI
Savva
Savva offers local models and separately selected cloud-provider queries, with model and context choices. Shared API keys do not make record contents anonymous. Optional cloud processing and metadata retention qualify broader local-only and anonymity claims.
Published September 8, 2026 as an AI-assisted draft. The public report separates documented facts, agency judgments and unresolved questions.
Summary judgment · 78 out of 100 toward patient-directed
Local record app with on-device AI and separately selected cloud-provider queries. Shared API credentials do not make record contents anonymous.
Potentially agency-expanding
Savva offers local models and separately selected cloud-provider queries, with model and context choices. Shared API keys do not make record contents anonymous. Optional cloud processing and metadata retention qualify broader local-only and anonymity claims.
Patient agency
How this tool changes agency
Comparing interpretations can prompt useful questions when users can inspect original records. Agreement between models is not validation.
Actual local/cloud boundaries, export, derived-data correction and provider retention remain unverified
Patient agency assessment
Who sets and changes the goal?
Choice of models, local execution and context size give users meaningful control over analysis. Switching models does not itself establish a way to correct extracted records or resolve conflicting advice.
What can the patient understand, question, or do?
Comparing interpretations can prompt useful questions when users can inspect original records. Agreement between models is not validation.
Can the patient evaluate the conditions of use?
An API key identifies the application, not necessarily the patient, but health-record content may identify them. Provider choice must include that distinction and policy retention exceptions.
Text findings
Conditions of use
Published controls and their limits
An API key identifies the application, not necessarily the patient, but health-record content may identify them. Provider choice must include that distinction and policy retention exceptions.
What remains unknown?
Not tested or not established
Actual local/cloud boundaries, export, derived-data correction and provider retention remain unverified
Who evaluated this?
AI-assisted public-source draft
Vendor statements describe published conditions, not independently verified behavior. No clinical, security, accessibility, or legal validation is claimed. Earlier evidence remains dated in the report and history.
Sources checked
Source-specific findings and retrieval limitations are recorded in the full report.
Review provenance
Criteria
CAIHL-derived HugoScore framework and September 7 qualitative review priorities. Draft v1.2 numerical anchors remain unadopted.
Reviewer
AI-assisted public-source reassessment prepared in OpenAI Codex.
AI / model
OpenAI Codex / GPT-6
Human review
Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
Review date
2026-09-08
Limitations
Actual local/cloud boundaries, export, derived-data correction and provider retention remain unverified No live product use, patient-data upload, account creation, code audit, clinical evaluation, or independent implementation validation.
Review method
Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
AI-assisted draft · Moderate for current documented choices, limited for runtime behavior (AI-assisted draft)