This is the foundation level of the Master AI Medical Practice Certification, rebuilt as a master class. It is written for the people who do the work: front-desk, scheduling and prior authorization staff; medical assistants; billing and revenue-cycle teams; managers; privacy, security and compliance officials; owners; and clinicians who want the operational grounding. It assumes you know how a practice runs day to day, and nothing about artificial intelligence. A learner who finishes should be able to decide, for one real task, whether and how AI may be used, who owns the output, and how they would know if it stopped working.

The first two modules explain what the systems sold to practices as "AI" actually are: rules-based automation, machine learning and generative AI, how language models and speech-to-text produce output, and what retrieval, tools and agents change. They then show where fluent output fails in healthcare work: confabulated rules and citations, omissions in a summary, elaboration of a planted false detail, stale payer rules, and the automation bias that lets a plausible draft through on a busy day. Study figures are read only as far as their samples and measures allow.

Modules three to five cover the duties that do not move when a tool helps. Module three recognises protected health information in every form it takes, applies the business associate analysis to a hosted AI service, works through permitted uses, minimum necessary and what real de-identification requires, and ends with a seven-step method for deciding what may enter which system. Module four draws the clinical line, with FSMB's position that boards regulate physicians rather than tools, AMA policy on consent and final review, state examples on unlicensed practice and diagnostic AI, and a procedure that routes every clinical output unedited to a named clinician. Module five is research: a workflow from a framed question to a verified answer, a four-part citation check, and worked status checks on rules that are proposed, superseded or partly vacated.

Modules six to eight turn to daily production work. Module six builds the structured administrative prompt in eight parts ending in a named reviewer, runs the pre-prompt data check, shows what a better prompt cannot fix, and gives draft patterns for schedules, letters, forms, policy summaries and machine translation under the Section 1557 review requirement. Module seven covers patient communication: what studies of AI-drafted portal replies measured and missed, sorting administrative from clinical messages, and California's disclosure statute alongside AMA policy. Module eight covers documentation: what ambient scribes do and do not do, what the randomised trials found, what a signature on an AI-transcribed entry affirms, and how to review a draft note before signing it.

Modules nine to eleven follow the work through the practice. Module nine separates the revenue-cycle tasks AI can support from the judgements it must never make, keeps code selection with the clinician's documentation and the coding professional, and covers the overpayment obligation and OIG's billing risk areas. Module ten covers the front office: scheduling, intake and phone automation as administrative support, reminders and AI voices under the conditions that apply to calls and texts, portals and records requests, and a method for ranking front-office uses by risk. Module eleven builds the workflow canvas: six stages from trigger to record, designing so a wrong output is not a wrong action, and designing the review step against automation bias.

Modules twelve to fourteen build control. Module twelve places every agent use on a five-rung ladder from reading to submitting, sets the autonomy vocabulary, control points and a tested stop switch, and covers instructions hidden in incoming documents. Module thirteen covers the Security Rule as it stands against the rule that is only proposed, updating the risk analysis when a tool arrives, where the data lives, and vendor claims, authentication and the breach clock. Module fourteen writes the practice AI use policy in eight sections, fits AI into the compliance programme the practice already has, places every framework by who it binds, and covers the one governance duty here that genuinely binds a covered entity.

Module fifteen is a practical lab of four exercises on fictional practices and patients: find the planted errors in an AI-drafted letter, reminder script and payer summary; expose a fabricated citation and rebuild the weak prompt behind it; review a referral extraction, instruction-like text and a failed de-identification; and grade a fictional vendor against business associate requirements. Module sixteen is the capstone: a Medical Practice AI Implementation Plan for one checkable first use, with a baseline from the practice's own records, the data class and vendor status settled before anything starts, controls that match the risks, named reviewers, and a bounded pilot with honest metrics and stop authority. The level ships with a printable workbook and eleven templates, and the final examination draws fifty scenario questions at random from a reviewed bank. Every statement of authority is labelled with whom it binds and the date it was checked.

Everything here is professional education. It is not clinical training, it does not replace physician or nursing judgment, clinical protocols, legal counsel, privacy or compliance review, payer requirements or applicable law, and it never teaches diagnosis, triage, prescribing, treatment decisions or how to select a code. Learners must check the rules that apply to them in their own state, with their own counsel. Completing the level earns an independent educational certificate from AI Coalition Network with a public verification page. It is not a licence or a credential, it carries no professional education hours, and it satisfies no licensing or credentialing requirement.