Miju Labs

The security dossier

What the doctor on the other end is risking

The largest practical risk in this business is not patient privacy but the hospital employment contract — and two questions that determine whether clinicians say yes have no answer anywhere in the record: whether this is the practice of medicine, and what organised medicine thinks of doctors selling judgement for AI training.

medium confidence8 minupdated 2026-08-30clinicians · licensure · malpractice · employment · ip · moonlighting

Supply in this market is not a recruiting problem. It is a risk-transfer problem. A consultant radiologist weighing an hourly rate against an unquantified exposure to their employer, their insurer and their regulator will decline by default, and the ones who say yes without asking are the ones you least want. So the operator's real job is to know that exposure better than the clinician does and to have already absorbed it.

There are three known risks and two genuine voids. Both categories matter, and the voids are more interesting than the risks.

Licensure and scope

The strong argument that this is not the practice of medicine: in essentially every jurisdiction, practice requires a physician-patient relationship and a specific patient. Rendering an opinion about a fictional case, or rating a model's output about a fictional case, creates neither. There is no patient, no diagnosis of any person, no treatment, and no reliance by an individual. The activity sits with medical writing, examination-question authoring, expert-witness work, textbook authorship and guideline drafting — all things licensed clinicians have done for decades without anyone calling it practice.

Two situations move toward the line, and both are avoidable by design. If the clinician reviews data about a real, identifiable patient and renders an opinion that influences that patient's care, that is practice, and it engages licensure in the patient's jurisdiction — a live cross-border problem for anything telemedicine-shaped. And if the output is marketed such that a downstream user relies on it as clinical advice about a specific person, the characterisation shifts regardless of what the contract says.

The defensive design writes itself: every case fictional; never route a real identifiable patient's data to a clinician for opinion; characterise the work contractually as expert content authoring and dataset adjudication rather than clinical consultation; and put an explicit "no patient relationship, no clinical advice" clause in both the clinician agreement and the customer agreement. All of that is free, and it is a direct consequence of Build it without ever touching a patient record.

Malpractice cover almost certainly does not extend to this

Assume it does not. A typical medical professional liability policy insures against claims arising from the rendering of, or failure to render, professional services to a patient. No patient, no covered claim — which sounds protective and is the wrong way round. It means that if a claim does somehow arise from this work, the clinician is uninsured for it [WEAK]; this is a reading of standard policy structure, not of any specific policy, and the founder must have an actual policy reviewed by a broker before repeating it.

The claim theories that would land outside malpractice cover are not exotic. A device cleared partly on your reference standard performs badly and a patient is harmed. A buyer sues over negligently produced data — professional negligence or breach of contract. A hospital sues a clinician over misappropriated confidential information.

What the company must therefore carry, and budget from day one: technology and professional errors-and-omissions cover, media liability, and product liability, with the clinician panel named as additional insureds or expressly indemnified.

Indemnifying the panel is a recruitment instrument, not a legal nicety

The best clinicians will ask what happens if something goes wrong. An operator who can answer with a policy number closes them; one who answers with reassurance does not. Treat the indemnity line in the budget as customer acquisition cost for supply, because that is what it is.

Employer IP and moonlighting: the single largest practical risk

Hospital and academic employment contracts commonly combine assignment of inventions and works created during employment or using employer resources; a duty to disclose outside activity; conflict-of-interest policies with hour caps; non-compete or non-solicit provisions; and confidentiality obligations covering patient information and institutional know-how.

In descending order of severity:

ExposureMechanismWhy it bites the operator
IP assignmentCases written on hospital time, hospital hardware, or from employer-derived materials may belong to the employerYour corpus is your only asset and could be encumbered without your knowing — this is what Series A diligence finds
ConfidentialityEven a wholly fictional case can be attacked as embodying institutional protocols, pathways or internal criteriaWeaker claim, but a claim, and it is expensive to defend per contributor
Conflict of interestAcademic centres cap outside professional hours and require prior disclosure, especially to commercial parties in a related fieldSilent breach by your highest-volume contributors is the default failure mode
Employer's own AI ambitionsA growing number of academic medical centres run institutional health-AI programmes and data-licensing arrangements with AI companiesA clinician selling judgement to their employer's partner's competitor is a governance problem for them and a relationship problem for you [WEAK]

The mitigations must be built into onboarding rather than bolted on afterwards. A contractual warranty from each clinician that the work does not breach their employment terms, plus a representation that they have disclosed it where required. A hard rule — personal time, company-issued devices and accounts, no employer resources, no employer materials — enforced technically, not just contractually, because company-issued equipment is what breaks the "employer resources" argument. A written IP assignment stating exactly what is assigned. Screening of the specific employment contract for the highest-value contributors, and a policy of declining contributors whose contracts cannot be cleared.

And a structural advantage worth testing properly: in several Member States, employee-invention and moonlighting restrictions are more constrained than under typical US at-will contracts, and post-termination non-competes often require compensation to be enforceable [UNVERIFIED] — jurisdiction-specific, and it needs local advice. If it holds, it is a real reason for a European operator to recruit European clinicians, and it compounds with the labour-cost argument in Where the supply can legally live.

The two voids

State these as voids. Do not fill them with inference.

Nobody has ruled on whether this is the practice of medicine

No medical board opinion, statute or case squarely addressing whether writing cases or annotating data for AI training constitutes the practice of medicine could be found anywhere [UNVERIFIED]. The argument in the first section above is strong, and it is still an argument rather than an authority. This is the right subject for a short targeted legal memo in the two or three jurisdictions that will supply most of the panel — cheap, and it converts the single most common clinician objection into a document you can send.

No medical society has taken a position

No published position by any medical society on clinicians being paid to supply their judgement as AI training data could be found [UNVERIFIED]. What is on the record is the surrounding posture: the AMA adopted AI policy at its June 2026 annual meeting framed around AI supporting rather than replacing physician judgement [WEAK] — located via news index, and the policy text itself was not read.

The second void is probably white space rather than risk, and the reasoning is worth stating plainly to any specialty society you approach. Organised medicine's stated fear is that AI displaces physician judgement. This business does the opposite: it pays physicians for judgement and puts that judgement at the centre of how AI systems are trained and validated. The interests are aligned, not opposed.

An early specialty-society endorsement looks gettable, and would be worth more than it costs

Nobody has defined the norms here yet. Being first to define them — fair compensation, attribution, transparency to clinicians about end use — is cheaper than complying with someone else's later definition, and an explicit society partnership is simultaneously a recruitment asset and a procurement asset. The two ethical trip-wires to pre-empt: do not build a reputation for extracting expert judgement cheaply, and let clinicians know whether their work trains a triage device or a consumer chatbot. Some will decline the latter, and that is fine. Medical coding and Clinical reasoning are the two niches where a society relationship would move the most supply.

What a founder must read in full before spending money

Carried across from the underlying research, in priority order. These are documents to read, not summaries to trust.

Tier 1 — before capital.

  1. FDA, "Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations," draft guidance, 7 January 2025, docket FDA-2024-D-4488 — Section VIII and its Reference Standard and Data Annotation subsections are the product specification (PDF).
  2. PhysioNet Credentialed Health Data License 1.5.0 and Data Use Agreement 1.5.0, plus the AI-services notice — short, and they close a route most founders assume is open (licence, DUA, notice).
  3. 45 CFR §164.514 in full, especially (a), (b)(1), (b)(2)(R) and (b)(2)(ii) (govinfo).
  4. Peabody et al., JAMA 2000;283(13):1715-22 — the evidentiary foundation of the de-novo thesis (PubMed).
  5. EU AI Act (Reg. (EU) 2024/1689), Articles 6 and 10, Article 10 in full (Art. 10).
  6. Regulation (EU) 2026/1744 — recital 181, the Article 113 amendment, and new Article 4a (EUR-Lex).

Tier 2 — before signing a customer or a clinician. EHDS Regulation (EU) 2025/327 Chapter IV, Articles 51, 53, 54, 55, 68 and 73 (EUR-Lex); GDPR Articles 9 and 89 with recitals 52–54 and 156–159 (Art. 9, Art. 89); the HHS OCR de-identification guidance in full (HHS); the FDA PCCP final guidance, docket FDA-2022-D-2628, especially the Modification Protocol section; 21 U.S.C. §360j(o), the CDS exclusion, in full (US Code); 45 CFR §46.102 and §46.104 (govinfo); and the Stanford AIMI commercial-use terms, the $70,000 anchor (AIMI).

Tier 3 — only if the PHI route is ever seriously contemplated. 45 CFR §164.504(e) on business associate agreement contents and §§164.400–414 on breach notification (govinfo); the January 2025 HIPAA Security Rule NPRM, whose mandatory encryption, MFA, asset-inventory and annual penetration-test requirements carried an HHS-projected $9 billion first-year industry cost and whose final rule is now projected for July 2027 [WEAK] (HIPAA Journal); and MDR (Regulation (EU) 2017/745) classification rules with MDCG 2019-11 if any buyer is an EU device manufacturer.

Where this dossier lands is The health read; what to build first is Characterised disagreement.