Trust & Methodology · canonical

How we make sure a clinic is safe to send you to.

The credentialing pipeline, the audit playbook, the data we collect, the rules we enforce, and the signals we monitor every day. Read the version that matches your role.

The pipeline

Every clinic clears the same five-stage pipeline.

No fast track. No founder favors. A clinic doesn’t see a JetPatient patient until every stage closes — and then they’re monitored daily for the life of the partnership.

01APPLY~5 days
Application
The clinic submits an attested profile. AI pre-fills 80% from their public credentials, but every field is signed off by a human.
Legal entity + beneficial owner
Specialties + procedure volumes
Surgeon roster + license numbers
02REVIEW~10 days
Document review
Verified directly with each issuing body. Sanctions screened against four authoritative lists. Malpractice history pulled for every surgeon.
JCI / ISO / ISQua verification
Board cert. + 10-yr malpractice
OFAC / EU / UN / WHO checks
03AUDIT~12 days
On-site audit
Our team flies to the clinic. We walk the OR, watch sterilization in real time, and stress-test the code-blue protocol.
OR walkthrough + equipment
Code-blue drill + ICU access
Nurse-ratio + staff interviews
04BASELINE~26 days
Outcome baseline
90 days of historical outcomes loaded into our Registry, benchmarked against U.S. medians. Drift triggers a 7-day re-review.
Complication + readmission
PROMs at 30/60/90/180 days
Benchmarked vs. U.S. medians
05MONITOR24/7 + annual
Continuous monitor
Daily polls of every accreditation, license, and sanctions registry. Auto-suspend on any lapse. Full annual on-site re-audit.
Daily automated polls
Quarterly outcome drift review
Annual on-site re-audit
Surgeon-level checks

The clinic gets the seal. Every surgeon earns it again.

Accreditation tells you about the building. We check the people. Every surgeon performing JetPatient procedures clears the same six checks — re-verified annually against the issuing board’s registry, not against clinic attestation.

Board certification
Active US ABMS, EU UEMS, or recognized national equivalent. Re-verified annually with the issuing board, never accepted as clinic attestation alone.
Malpractice history
10-year claims history across all jurisdictions of practice. No closed claims above $2M. No pattern claims (3+ matters of similar root cause). Pattern hits are disqualifying.
Procedure volume
Minimum annual volume floors by procedure class — e.g. ≥50 primary hip replacements per year for an arthroplasty roster, ≥25 LASIK per quarter, ≥3 CABG/month for the cardiac roster.
Sanctions & license
Daily polls of OFAC, EU consolidated, UN, WHO/MoH watchlists, and the issuing license board. Any hit triggers an immediate auto-suspension — no appeals queue.
Outcome track record
Procedure-level complication, readmission, and revision rates from the surgeon’s last 24 months. Must be within +0.5 SD of the WHO benchmark for the procedure class.
Patient feedback
Every JetPatient patient submits PROMs at 30/60/90/180 days. Surgeon-level NPS <45 triggers a quarterly review. NPS <30 triggers a re-audit.
Facility safety

What we observe inside the building.

Accreditations cover paper. Our on-site audit covers reality. Here’s what we watch for during the 3-day audit, and the floors we enforce for every JetPatient partner facility.

Sterilization & infection control
SSI rate within 1 SD of the WHO benchmark for the procedure class. CRE / MRSA / VRE surveillance program active. Sterilization observed live in two OR turnovers during the audit.
SSI rate: floor varies by class (e.g. <1% for total hip, <0.5% for LASIK)
CRE outbreak: any in trailing 24 months = disqualifying
Sterilization process: observed at two OR turnovers minimum
Anesthesia & emergency readiness
Dedicated anesthesia team for inpatient procedures. ACLS-current. Code-blue drill timed end-to-end during the audit. ICU access within 5 minutes, on-site or transfer agreement.
Code-blue drill: response <3 min, full intubation <90 sec
ICU access: on-site or transfer SLA <5 min
Blood bank: on-site, ≥6 units of each major type at all times
Nursing model
Nurse-to-patient ratios reviewed by department. Post-op recovery: 1:2. Ward: 1:5 nights, 1:6 days. ICU: 1:1 or 1:2 (level-dependent). All nurses interviewed during the audit.
Post-op recovery: 1:2 minimum
Ward: 1:6 days, 1:5 nights
Direct staff interviews during the audit
Equipment & implants
Implants are FDA / CE / TGA-approved — no off-brand substitutions. Imaging equipment must be <7 years old for CT/MRI. Anesthesia machines must be on a documented PM schedule.
Implants: FDA, CE, or TGA only
CT / MRI: <7 years old, 1.5T minimum
Anesthesia + monitors: documented PM
Outcomes data

How we measure whether a clinic is actually good.

Accreditation is a floor. Outcomes are the ceiling. Every JetPatient procedure feeds the same Outcomes Registry — 480k procedures and counting — so we can compare a partner clinic against the U.S. median for the same procedure on the same patient profile.

Metric
JetPatient median
U.S. in-network
Floor
90-day complication rate (ortho)
2.1%
3.4%
≤4.0%
30-day readmission rate
1.6%
2.8%
≤3.5%
Surgical site infection rate
0.7%
1.1%
≤1.5%
Revision/reoperation at 1yr
1.2%
1.9%
≤3.0%
Patient NPS (180-day)
+72
+38
≥+45
What we won’t do

The lines we will not cross.

The other side of the model

This section describes what the clinic pays. On the patient side, JetPatient adds a disclosed 15% platform fee to the clinic’s price, shown before commitment. The clinic receives its price in full.

Nothing a clinic pays JetPatient varies with the number or value of patients it receives. That is why placement on JetPatient cannot be bought.

We don’t take referral commissions
JetPatient is paid by clinics on a flat $175/month SaaS subscription — not per patient, not per booking, not on procedure margin. Your savings number is never inflated to cover a kickback.
We don’t accept palliative or emergency cross-border cases
JetPatient is for curative-intent, elective, scheduled procedures only. We won’t quote anything that should stay local. Acute care, oncology under active treatment, and palliative referrals are routed back.
We don’t list clinics with disqualifying signals
An OFAC hit, a lapsed JCI, a malpractice cluster, or an outcome-drift breach are immediate auto-suspension events — the clinic falls out of the search index within an hour and existing bookings are reviewed within 24.
We don’t sell your data
Your Passport is HIPAA-aligned. PHI is encrypted at rest (AES-256) and in transit (TLS 1.3). We minimize PHI on every cross-border hand-off and never sell or share patient identifiers with third parties.
The playbook

What you submit at each stage.

If you’re considering applying, this is exactly what we’ll need from you, what we’ll verify ourselves with the issuing bodies, and how long each stage typically takes if there are no holds.

01APPLY~5 days
Application
Submit: Site URL + JCI cert. AI auto-drafts 80%; you sign off.
Ownership + beneficial owner KYC
Surgeon roster CVs + license #s
Procedure volumes by code (24 mo)
02REVIEW~10 days
Document review
Submit: COI (E&O + GL), malpractice attestations, 3 yr financials.
Certificates of insurance current
Audited financials or equivalent
10-yr malpractice attestation
03AUDIT~12 days
On-site audit
Host: 3-day on-site (we cover travel). Two OR observations, code drill.
2 observed OR cases with consent
Live sterilization + code-blue drill
Staff interviews + culture review
04BASELINE~26 days
Outcome baseline
Connect: EHR via HL7/FHIR. 90 days of historical outcomes loaded + benchmarked.
EHR: Epic / Cerner / OpenMRS / custom
90-day procedure outcomes load
PROMs collection workflow validated
05LIVE24/7 + annual
Live in the network
Maintain: Outcome feed live. Accreditations current. Annual re-audit.
Clinic Portal dashboard active
Quarterly outcome review with us
Annual on-site re-audit (3 days)
The bar, in numbers

Acceptance criteria.

These are the hard floors. Any one of them auto-rejects at the stage where it’s observed. They’re the same floors a U.S. hospital network would use for a credentialing committee — we just publish them.

Accreditation
Active JCI, or ISO 9001 plus a recognized national equivalent. Re-verified directly with the issuing body via API or scheduled fetch, never via clinic attestation.
Surgeon roster
100% of your procedure-performing roster must hold an active board certification (US ABMS / EU UEMS / national equivalent). Locum and visiting surgeons must clear before any case.
Malpractice
No closed claims > $2M in the last 10 years across the surgical roster. No pattern claims (3+ claims of similar root cause for any individual surgeon).
Infection control
SSI rate within 1 SD of WHO benchmark for procedure class. No CRE outbreak in trailing 24 months. Active surveillance program with monthly internal reporting.
Sanctions & license
Zero hits across OFAC, EU consolidated, UN, WHO health-authority watchlists, and the issuing license board. Daily polling. Auto-suspend on hit.
Outcomes drift
Complication, readmission, and revision rates must stay within +0.5 SD of your established baseline. Drift triggers a 7-day investigation, possible re-audit, and a corrective-action plan.
Ongoing obligations

What we ask you to do every day.

Once you’re live, the SaaS portal handles most of it automatically. These are the things you’re still on the hook for.

Outcome reporting
Within 7 days of discharge for every JetPatient case. EHR-pulled where possible, manual entry only as a fallback. Late reporting freezes new referrals.
PROMs collection
Patient-reported outcomes at 30/60/90/180 days post-op. Patients submit via the JetPatient app; you only act on flagged scores.
Credentialing freshness
License renewals filed within 14 days. Board re-certs updated within 30. Insurance renewals flagged 60 days in advance via the punch-list.
Incident reporting
Any complication, code-blue, or unanticipated return-to-OR — within 24 hours via the portal. Root-cause analysis filed within 14 days for serious events.
Quarterly review
90-minute video review with our credentialing team. Outcome drift, patient feedback, upcoming volume, anything you flag. Quarterly cadence, never skipped.
Annual re-audit
3-day on-site every 12 months, scheduled 60 days in advance. Same playbook as the original audit. No clinic is grandfathered out of it.
Apply

Start the 60-second AI auto-draft.

Drop your URL and your JCI certificate number. Copilot will scrape your site, registries, and license boards, and pre-fill 80% of the application before you sign in.

Compliance posture

The legal framework we operate under.

JetPatient is structured as a flat-fee SaaS platform, not a referral broker. We don’t take per-patient compensation from clinics, which keeps us outside the Anti-Kickback Statute exposure pattern and clean of the Corporate Practice of Medicine prohibitions in all U.S. states.

Anti-Kickback Statute (AKS)
JetPatient charges clinics a flat $175/month SaaS subscription — no per-patient, per-booking, or success-fee component. This structure falls outside the AKS quid-pro-quo pattern.
No referral fees
No per-patient comp
No procedure-margin share
Corporate Practice of Medicine (CPOM)
JetPatient does not employ physicians, doesn’t make medical decisions, and doesn’t direct clinical practice. Every clinical decision remains with the credentialed surgeon. CPOM-safe in all participating U.S. states.
No employed clinicians
No clinical decision algorithms gate care
State-by-state safe-harbor memo available
ERISA & SBC integration
JetPatient integrates as a carve-out benefit inside your existing self-insured plan. We provide plan-document language, SBC inserts, and TPA configuration packs.
Plan amendment template
SBC carve-out language
TPA configuration brief
HIPAA & state privacy
A BAA is executed before any PHI flows. PHI is encrypted at rest (AES-256) and in transit (TLS 1.3). Minimum-necessary principle on every cross-border hand-off.
BAA executed pre-PHI
AES-256 at rest, TLS 1.3 in transit
State privacy mapping (CA, TX, WA, IL)
Audit trail

Everything is logged. Everything is exportable.

For your ERISA fiduciary review, every decision JetPatient makes — every clinic admit, every suspension, every patient routing, every credential refresh — is written to an immutable audit log. Quarterly attestation reports ship to your compliance team automatically.

Per-decision audit trail
Every clinic admission, suspension, re-audit, and patient routing decision is written to an immutable, timestamped log. Exportable as JSON or CSV. Retained for 10 years.
Quarterly attestation report
Auto-generated PDF + machine-readable XBRL. Network composition, suspension/re-admit log, outcome aggregates, sanctions screening summary, BAA status.
Real-time network state API
REST API your TPA or compliance team can poll for current network state, by clinic. Includes accreditation status, last audit date, current outcomes, suspension status.
Independent assurance
SOC 2 Type II annual. ISO 27001 certified. ISO 9001 for the credentialing process itself. Reports available under NDA pre-contract, automatic post-contract.
Data sources

Every number is sourced. Auditable.

For your fiduciary review, here is the canonical list of data sources behind every figure JetPatient surfaces in your dashboards, reports, and patient-facing surfaces.

U.S. pricing
FAIR Health Consumer
Self-pay benchmark prices by procedure + ZIP. Used as the “list price” reference in the savings calculator.
U.S. pricing
CMS Medicare Fee Schedule
Medicare allowed amounts by procedure code and locality. Used as the “Medicare reference” toggle.
Wait cost
KFF Healthcare Cost Survey
Median out-of-pocket for chronic-care management by procedure class. Annually refreshed.
Wait cost
BLS Wage & Productivity
Median lost-wage data by occupation. Used for the cost-of-waiting wage component.
Clinical risk
JetPatient Risk Engine
Internal cohort-based complication forecasts. Validated against external registries (NSQIP, ICHOM).
Outcomes
JetPatient Outcomes Registry
Live partner-clinic complication, readmission, PROM, and NPS data. 480k procedures tracked to date.
Sanctions
OFAC / EU / UN / WHO
Daily-polled sanctions, embargo, and health-authority watchlists. Auto-suspend on hit.
Accreditation
JCI / ISO / ISQua registries
Direct API or scheduled-fetch verification of clinic accreditations. No clinic-attested status accepted.
Quality-of-life
ICHOM & QALY tables
International Consortium for Health Outcomes Measurement standards used for QALY-weighted cost-of-waiting.
Evidence pack

Download the full compliance evidence pack.

For your benefits committee, your TPA, and your ERISA fiduciary review. Includes plan-document language, SBC carve-out template, AKS structuring memo, state CPOM safe-harbor mapping, HIPAA + state-privacy posture, sample BAA, SOC 2 Type II report, and the Outcomes Registry methodology white paper.

AKS-safe SaaS structuring memo (current)
SBC carve-out language + TPA brief
State CPOM safe-harbor mapping (50 states)
HIPAA + state-privacy posture + sample BAA
SOC 2 Type II report · ISO 27001 certificate
Outcomes Registry methodology white paper
Download the pack
Methods & principles Security System status Changelog
Methods & principles

How our AI works, and what it doesn't do yet.

JetPatient builds AI into a regulated category — cross-border surgical care. Every model ships with a public model card naming its intended use, training data, performance targets, fairness audit, limitations, and operating status. Three principles hold for every surface.

01 · Status, always
Prototype is not production

Every AI surface carries a visible status badge: scripted demo, conceptual prototype, pre-production, or production. The badge is on the model card and on every page that surfaces the model.

02 · One human in the loop
Models never act alone

Every JetPatient AI output feeds a human reviewer — a benefits coordinator, a surgeon, a nurse navigator. No model makes a clinical, financial, or coverage decision on its own.

03 · Citations and refusals
Where the answer came from

Patient- and clinician-facing assistants ship with citations on clinical statements and an explicit refusal contract for out-of-scope queries. We'd rather refuse and route to a human than guess.

The contract behind every model

  • Human review on every output. Models surface evidence, ranked candidates, or summaries — a named human approves the action.
  • BAA before PHI. No PHI touches a model until a Business Associate Agreement is in place with the data source.
  • Validated before shipped. Each model card defines its v1.0 acceptance criteria; no surface ships until the validation report clears the clinical advisory board.
  • Audit and rollback. Every release is logged, every release is reversible, every fairness audit is public.
Security

What we do today, and what's on the way.

JetPatient handles cross-border surgical care — clinical records, AI inference, payments, identity. This is the security posture as it stands today, what's on the active roadmap, and how to request the formal procurement pack. We'd rather show the gaps than pretend they aren't there.

Today, in production Live

01
HTTPS everywhere

TLS 1.2+, HSTS preload (max-age=31536000; includeSubDomains; preload). Provider-managed certificates, automatic renewal. Plaintext HTTP requests redirected unconditionally.

02
Content Security Policy

CSP locked to self; script-src + style-src allow only allowed CDN origins and analytics; frame-ancestors 'none'. Telehealth surfaces get a scoped Permissions-Policy opening camera+mic only on that page.

03
Hardened headers

X-Frame-Options: DENY, nosniff, strict-origin-when-cross-origin, COOP, CORP. Permissions-Policy locks camera, mic, geolocation, and payment by default.

04
Pre-release gate

HMAC-signed session cookie, fail-closed. Constant-time compare, 30-day TTL, HttpOnly + Secure. If JP_GATE_SECRET is unset, every gated request returns HTTP 503 with an operator-facing message.

05
Secret hygiene

All production secrets are held in the hosting provider’s secret store, never in source. Build-step preflight (check-env.js) fails the deploy if a required secret is missing or under length. Documented rotation runbook.

06
Audit log

Every mutation against the Network Spine (cases, outcomes, payments, messages, artifacts, flags) writes an audit row keyed by actor, timestamp, namespace, and action. Daily backups, 14-day retention.

07
Honest AI labelling

When live AI is unavailable, every endpoint returns 200 with a labelled SAMPLE response — never a silent failure. Clinic cohorts below the publish threshold show PENDING, never demo numbers behind a small pill.

08
Tested before shipped

CI build runs npm run check:env:strict && npm test — any failure kills the deploy. A separate CI runner executes end-to-end smoke tests + First-Patient Journey chain against every preview deployment.

How to ask for the formal procurement pack

For procurement, security reviews, and enterprise diligence: email trust@jetpatient.com with the company name, the use case, and the artifacts you need. We typically respond within two business days with:

  • Architecture overview (one-pager)
  • Data-flow diagram (per-feature, including AI inference paths)
  • Sub-processor list with their SOC reports
  • Current security questionnaire responses (CAIQ / VSAQ format)
  • BAA template (DOCX) and signed-copy turnaround
  • Model cards for any AI surface in scope
  • Incident-response runbook
System status

What's up, what's warning, what's down.

Real-time health for every public JetPatient endpoint and AI surface. Reads come straight from the production Functions — what you see is what visitors are seeing right now. AI endpoints that return a labelled SAMPLE response count as healthy: that's the documented graceful-fallback path, not a failure.

Core surfaces
Marketplace · Passport · Clinics
Public spine
Cases · Outcomes · Payments
AI endpoints
Live or graceful SAMPLE
Auth & gate
HMAC session, fail-closed

A row is marked down only on 5xx, timeout, or unreachable. SLA targets per surface live in the (private) ops dashboard at /admin/ops.html; the public version ships with the Drift, Fairness & Audit Console (above).

Public changelog

What we shipped, block by block.

JetPatient ships in numbered “blocks” — each one a focused, testable, verifiably-green increment. Updated in the same PR that ships the block. For the full internal release notes on any specific block, email trust@jetpatient.com.

Block 41 · 2026-05-31
Trust hub + honest credibility chrome

Built the public Trust hub: status, security, changelog, honesty/badge explainer. Shipped a canonical jp-trust-badge component that renders consistent LIVE/CACHED/SAMPLE/PENDING/VERIFIED badges with rich tooltips. The team's discipline around labelling sample-vs-live data is now productized as a reusable component and public source-of-truth page.

Block 40 · 2026-05-31
Gate secret hygiene + First-Patient Journey CI smoke

Removed the in-source fallback for the gate signing secret; auth.js + gate.js now return HTTP 503 with an operator-facing message when JP_GATE_SECRET is unset or under 32 chars. Promoted the First-Patient Journey simulator into a unit-test spec + a vanilla-Node HTTP companion that runs against every deploy-preview via the CI runner.

Block 39 · 2026-05-30
Fix, tighten, resolve — three audit-recommended actions

First-Patient Journey Audit closed: a P0 Scribe defect (transcripts sent as String instead of Array, silently 400'd every clinician click since Block 18) and a P1 credibility risk (clinic profiles substituting demo cohort data when real cohort was empty). Added a 24-check consumer-contracts test suite across 13 endpoints.

Block 38 · 2026-05-30
Spine routing for AI workbench outputs

One-click routing for every AI workbench output: Scribe SOAP notes auto-route to the patient inbox as encounter_summary threads; high-risk Risk Engine results auto-route as risk-alert threads; Navigator turns become case-timeline entries. Every routed artifact carries a sourceArtifactId so the audit trail traces thread → artifact → AI usage → audit log.

Block 37 · 2026-05-30
AI workbench v2 — auto-save + history

Every AI workbench result auto-saves to NS.PATIENT_ARTIFACTS with an AR-prefixed ID. The 3-most-recent results sit in a history strip beside the workbench. Risk Engine gains side-by-side comparison of consecutive runs. Patient Passport gains a 6th “Recent AI activity” card.

Block 34 · 2026-05-30
Feature flag infrastructure

New NS.FLAGS namespace + flags.js Function + jp-flags.js client (60s sessionStorage cache, fails-open false) + /admin/flags.html admin surface. SHA-256 sticky bucketing for percentage rollouts.

Block 33 · 2026-05-30
Clinic outcome cohorts + recovery-curve chart

Every clinic profile gains a real outcome cohort engine reading NS.OUTCOMES with an inline SVG recovery-curve chart (30/90/180/365 day trajectories with 25th/75th percentile bands).

Block 20 · 2026-05-29
Payments scaffold — 6 new Functions, 8 new namespaces

State machines for quote, payments, BNPL, settlements, disputes, insurance. Stubbed adapters for Stripe, CareCredit, Affirm, Klarna, Splitit, GreenSky — every transition wired but no real money moves yet. The integration surface for the partnership track to fill in.

Block 17 · 2026-05-28
AI failover + cache + telemetry

New callAnthropicWithFailover (2-retry exponential backoff [500,1500]ms → NS.LLM_CACHE SHA-256 prompt cache → sample). Every AI response carries source ∈ {live, cache, sample, no_key, failed}. recordAiUsage writes per-call telemetry.

Block 16 · 2026-05-28
Production foundations

Daily backups (NS.BACKUPS, 14-day retention), audit log (NS.AUDIT), client error reporting (NS.CLIENT_ERRORS wired to 94 pages). Fixed a critical latent rate-limit bug where 5 of 7 LLM endpoints had been silently bypassing Claude since Block 9.

Still have questions?

Our network team will walk through any of this with you in detail — whether you’re a patient considering care, a clinic considering joining, or a benefits team scoping a carve-out.

The verification ledger

Don't trust us.
Recompute it yourself.

Every verification we record, every correction we make, and every claim we refuse to make is appended to a hash chain that cannot be edited without breaking. Your browser is checking the whole thing right now — with our server having no say in the result.

Verifying the chain in your browser…
Recomputing every entry with SHA-256 via WebCrypto. Nothing is being asked of our server.
Entries
Head
Declared
Algorithm
sha256(canonical JSON · sorted keys · no whitespace · UTF-8)

Don't take our word for it — break it yourself

Pick any record we have published, change it, and watch this page catch you. The check that runs is the same one that ran a moment ago on the real chain; the only difference is that you are the one doing the tampering. Nothing you do here leaves your browser.

Why this matters: a hash chain only proves anything if the reader can recompute it without our help. Every clinic verification, every correction and every claim we withhold is an entry in this chain — so if we ever quietly revised one, this page would say so on our own website.

Look anything up

What does the ledger say about…

A clinic, a claim we make, a file we changed. If it isn't here, we didn't record it — and that is itself an answer.

What's on the record

Including the parts that don't flatter us

A ledger that only holds good news is marketing. This one records our corrections, the claims we withhold because we can't stand behind them, and the size of our own verification backlog.

For the sceptical

How to check this without us

Each entry's hash covers its own contents and the hash before it. Change one character anywhere and every subsequent hash changes, so the chain stops matching its published head. Remove an entry and the sequence gaps. There is nowhere to hide an edit.

Download /fixtures/ledger.json and run this — no JetPatient code involved:

node -e '
const c=require("crypto"),d=require("./ledger.json");
const K=v=>v===null||typeof v!=="object"?JSON.stringify(v)
  :Array.isArray(v)?"["+v.map(K).join(",")+"]"
  :"{"+Object.keys(v).sort().map(k=>JSON.stringify(k)+":"+K(v[k])).join(",")+"}";
let p="0".repeat(64),bad=0;
for(const[i,e]of d.entries.entries()){
  const h=c.createHash("sha256").update(K({seq:e.seq,ts:e.ts,kind:e.kind,
    subject:e.subject,payload:e.payload,prev:e.prev})).digest("hex");
  if(e.seq!==i||e.prev!==p||e.hash!==h)bad++;p=e.hash;}
console.log(bad?"BROKEN":"intact",d.entries.length,"entries; head",p);'

If that prints anything other than intact and a head matching the one above, we have altered the record and you should tell us — and everyone else.