Level 3 taught you to run AI-assisted practice work as an operation several people repeat across thousands of patients. Level 4 asks you to govern it across the whole practice or group, and to defend what you decided to a privacy regulator, a state medical board, a payer, a malpractice carrier and your patients. It is written for physician owners and partners, practice executives and administrators, medical directors, compliance officers, privacy and security officials, and revenue-cycle leaders who own AI policy.

The honest starting point of this tier is a silence. No state medical board has published an AI rule, no AI disciplinary case against a physician is recorded, the profession's ethics code carries no AI opinion, and the federal compliance guidance a practice already follows does not mention AI at all. A practice that waits for a rule will wait past the point where the decisions are made. The level therefore builds the programme from the duties that do exist, plus this programme's own recommendations, labelled as such wherever they appear.

Modules one to four place accountability and map what binds the practice. Module one traces where AI decisions hide between the switchboard, the portal inbox, the documentation queue and the billing office, names owners inside roles a practice already has, and writes the list nothing may take from a person. Module two builds the programme a practice can actually operate: a permitted-use inventory, an approved tool list, a way to find the tools nobody registered, decision rights and stop authority, all fitted inside the compliance programme already running, with the voluntary frameworks used as vocabulary for asking questions rather than as rules. Module three keeps the decision record — the evidence, the owner and what was rejected — decides how long to hold it, and re-opens it when the tool or the rule moves. Module four builds the four-column map and the only two routes across it, placing device law with manufacturers, certification criteria with health IT developers and payment rules with health plans, and dating every entry so the map ages visibly.

Modules five to seven cover what the practice buys. Module five asks where patient information goes, who else touches it, how a supplier builds, secures and changes the product, how to read a cleared indication, and how to tell a real answer from a practised evasion. Module six reads published accuracy claims for what was measured and in whom, separates an examination benchmark from a workplace result, weighs developer-run evaluations and single-centre studies honestly, and designs the practice's own acceptance test with pass conditions agreed in advance. Module seven decides who in an AI supply chain is a business associate before anything moves, reads the required contract elements as they stand, adds the AI clauses no rule supplies, sets reporting clocks across several vendors, and decides what a vendor may keep at exit.

Modules eight to eleven cover security, public speech and patients. Module eight re-opens a risk analysis written before the practice had any AI, walks the safeguards again with one live flow in hand, and reads the Security Rule proposal as a proposal. Module nine puts a named owner and a sign-off in front of everything the practice publishes: substantiation held before a claim goes out, the binding rule on fabricated reviews, the line between a reminder and marketing, and consent before an artificial voice calls anyone. Module ten maps patient notice and the state disclosure duties that exist — each narrow, each triggered by something different — and decides what the practice says, in whose words and on which channel. Module eleven works out how nondiscrimination coverage is determined rather than assuming it, builds the decision support tool inventory the ongoing duty asks for, and finds the patient the practice's channels quietly exclude.

Modules twelve to fourteen make the practice answerable and sequence the work. Module twelve designs verification by someone who did not do the work, reads recorded corrective action plans for what an investigation asks, learns the clocks that start without you, and assembles the evidence before anyone requests it. Module thirteen hears the objection under the objection from clinicians, the front desk and the billing office, leads against both refusal and over-reliance, and measures adoption in a way that cannot be satisfied by appearing to comply. Module fourteen sequences the programme against dated milestones and what the practice can absorb, states benefit, cost and risk with a baseline and a measure that can show failure, puts a real choice including not proceeding in front of the owners, and prepares the capstone: a Practice AI Governance and Implementation Package for a fictional practice.

Statements of authority say whom they bind: what binds the practice is kept apart from what binds manufacturers, certified health IT developers and health plans, one state's rule is never presented as a national one, and a voluntary framework binds no one. Every status statement carries its date as verified on September 15, 2026, and where the authority is unsettled the level teaches a method of reasoning rather than a confident answer. It ships with a printable workbook and ten templates, and the examination draws forty scenario questions from a reviewed bank.

Everything here is professional education. It is not clinical training, it does not teach diagnosis, triage, prescribing, treatment decisions or code selection, and it is not legal, privacy or coverage advice. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It is not a medical, nursing or other healthcare licence, a coding credential or a compliance certification, it carries no professional education hours, and it satisfies no licensing, credentialing or payer training requirement.