You visit a new doctor. Old magazines, maybe. Then you see it. Hello old friend. The clipboard. The clipboard with the dangling elastic band to make sure you don't walk out with that classic blue Papermate pen, which is, of course, missing its top. You have to sign a form authorizing the release of your medical records. You look for the X and line at the bottom and sign it. You don't really read it. Who does? The form grants access to everything, to an organization, for a duration that's not really specified. Today we call this consent. But it isn't, really.
This is a ritual. This is theater. Something that we all participate in that lets us proceed. The receptionist knows they need the signature; you know you want the appointment, and the form goes into a drawer where it collects dust and no one really checks what it permits. Healthcare has held this ritual dear for over fifty years. From the launch of personal computers to the internet, cloud computing, smartphones, and now even AI. It's consent theater: paperwork permission without substance.
The wrong question
Oftentimes when people hear "patient to agent is the future of healthcare," they ask, "you think it's a good idea to give AI access to your medical records?" The question sounds right. The question is actually backward. The interesting question isn't whether the record is safe from your agent, it's why your consent has never mattered until now.
Start with what agents change. Delegation in healthcare services is not new. Wives and husbands call pharmacies for one another, and for their kids too. Adult children completely manage their parents' medical appointments and medications, mostly without any paperwork involved at all, just a receptionist or pharmacy attendant deciding the voice on the phone or the person in front of them checks out. Medicine has always run on a system of informal delegation, because sick people are exactly the type of people least able to do all the work themselves. Sick people want to manage their health, not the labyrinth of bureaucracy that stands between them and receiving care. The legal world already even has the machinery for the formal version of all this: power of attorney, guardianship, healthcare proxies.
So the new thing here isn't that patients want and require someone else to act for them. The new thing is that the someone people want now is software. It's an agent. And software turns out to be an unusual kind of delegate because it's the first one whose permission can actually be made to be precise.
Real consent
Think about it. A paper clipboard release can't do much. It can't limit itself to one purpose. It doesn't expire on its own. It can't tell you, later, what was actually even done with it. Once signed, the paper is a key that works on every door, forever, and leaves zero trace or record of which doors, where, it opened. Consent theater doesn't exist because people actually love it. Heck, it seems universally unliked. But consent theater exists and persists because paper can't do better.
But we live in 2026 now. Software definitely can do better. A permission granted to software can say: this agent or team of agents, for this purpose or these purposes. Only. It can be revoked in one place and expire everywhere all at once. Software can log every access, so that the question "what did I agree to?" has a real answer for the first time in the history of medical paperwork. When a patient connects using a service like Flexpa, they prove exactly who they are; they grant deliberate access that they can revoke at any time, with every retrieval on the record. Whatever your gut reaction to the word agent is, think about what we're talking about when we discuss agents in healthcare. This is not a weaker form of consent than the clipboard and Papermate pen. It's the first real form of healthcare consent.
It took us time to see and appreciate this inversion. And we're in it every day. So it makes sense that most people arguing about AI in health don't fully get it yet. They haven't seen it. They haven't experienced it. Agents don't threaten consent. Agents make consent real. Agents are why consent finally has to work, and the mechanism by which it can.
The authority wall
Now for the part that's still unsolved. Identity has two halves, one easy and one hard. The easy half is proving the patient is who they say they are. Federal standards already exist for this; they are already in use, in production, today. The harder half is proving the agent is what it says it is: that this specific piece of software was authorized by this specific patient to do this specific thing. That the permission hasn't expired or been revoked. And that someone identifiable is accountable if it malfunctions or misbehaves.
There's no standard for this...yet. There isn't really a power of attorney for software. A provider that receives a request from an agent today has no standard way to check any of it, so the safe answer tends towards always saying no. In part 2, we called this barrier the authority wall, and of the four walls we described, it's the one where the least has been built.
Because humans generally get scared of change, the most tempting answer is: let's just keep saying no until someone figures it out. This is mostly the response we are seeing in healthcare today. It feels responsible. It isn't, for exactly the reason anyone who has actually watched patients behave in the real world already knows: prohibition doesn't stop healthcare delegation. Instead, prohibition just pushes delegation into the dark. Delegation becomes invisible. Patients already paste portal passwords into chatbots and agents. Patients have already handed their logins to software to manage and enter on their behalf for a decade. When the front door is locked, patients don't stop entering it; they just use the window. The window has no logs, no scopes, no tracing, and no revocation. The real choice healthcare faces today is not agents or no agents. It's a choice between transparent delegation or invisible delegation.
Where this leads
Fifty-plus years of signed clipboard consents living in dusty drawers and boxes in massive physical data warehouses have carved out a strange equilibrium. If we're all consenting to everything, nobody is consenting to anything. This equilibrium has existed because checking was impossible. We slapped glass on top of paper forms in healthcare and accepted informal delegation as business as usual. Agents in healthcare end both conditions simultaneously, which is why they feel threatening to some, and it's also why they're the opposite.
The future of healthcare is patient to agent. The patient's half of that sentence is the proof, permission, and the right to change your mind and make the most informed decision possible. That half is ready.
This is the third post in a four-part series from Arlo and Flexpa. Next, and last: agents that act instead of just read, and what happens when the loop closes. If you think we're wrong about any of it, we want to hear why.
Missed part 2? Read it on Arlo's blog or via The Healthcare AI Guy.



