Level 4 taught you to govern AI across a medical practice or group. Level 5 is about building the part that acts. An assistant suggests; an automation does. It routes a fax, matches a referral packet or stages a chart update, and when it is wrong the error has reached a patient, a payer or the legal medical record before anyone looks. It is written for the practice IT, systems, integration, revenue-cycle, patient-access, security and privacy staff who own automation projects. No programming background is required: the work is registers, maps, contracts, gate designs, log specifications, threat models and runbooks.

Modules one to three set authority and orchestrate the front of the practice. Module one places every proposed automation on a three-level scale — suggest, act inside the practice, or act outward only with a named person's approval — finds where it holds more permission or reach than its job needs, writes the authority register a covering manager can enforce, and holds the acts that never leave a licensed or authorised person. Module two maps intake, registration, referrals and document requests step by step with the narrowest data each step may see, escalates the instant an exchange stops being administrative, recognises consent-protected records, and keeps a queue from becoming a delay in access. Module three designs recalls, reminders and outreach around consent every channel reads and a revocation that stops every channel, treats a generated voice as an artificial voice, locates where a reminder becomes marketing or a review request becomes a prohibited practice, and plans the return path for the patient who replies with a symptom.

Modules four to six cover the systems and the money. Module four draws the integration map: every system touched, every boundary patient information crosses, who is a business associate at each one, and a data contract naming required fields, forbidden fields and missing-field behaviour. Module five keeps integration read-first, separating the staged proposal a named person commits from the committed write nobody saw, naming the objects no automation writes, and following the trail each write leaves. Module six separates duties around the claim: whoever configures an automation cannot approve what it produces, payee and banking changes take dual control verified away from the request, nothing submits, appeals or refunds on its own authority, and a surfaced overpayment starts clocks the practice must work.

Modules seven to nine are human control. Module seven builds gates that put the source beside the proposal, name the exact act and demand a positive step, designs against deference and anchoring, sizes gate volume against a real clinic day, and retires a gate that has stopped deciding anything. Module eight gives every automation its own identity rather than a borrowed login, cuts its rights to the smallest set its job needs, protects the staff who configure automations, and extends joiner, mover and leaver routines to accounts that are not people. Module nine designs a stop a staff member can invoke within minutes without a vendor ticket, decides what becomes of work in flight, keeps the manual route rehearsed rather than assumed, and plans for the outage and the supplier's model change.

Modules ten to thirteen are defence, observation and response, from the defender's side. Module ten treats every fax, portal message, referral packet and upload as data rather than instruction, threat-models channel by channel, and designs detection, containment and review for the day an automation is fooled anyway. Module eleven specifies the eight questions an action log must still answer fourteen months later, places the work inside the audit control and activity review duties a practice already has, and decides integrity, retention and disposal deliberately. Module twelve catches the failure that raises no error, expects drift when a product, a payer form or a plan year moves, and builds a risk-based monitoring plan with named alert recipients. Module thirteen works the first half hour of an incident in order, applies the breach presumption and its four factors, and runs a review that ships a structural change.

Module fourteen measures return honestly. No recorded study puts a return figure on practice automation, so the level teaches a baseline taken before the automation exists, measures and stop conditions capable of showing failure, an honest count of the review hours it creates, and the published ambient documentation findings read for what they measured in their own settings. It then assembles everything into the capstone: the Automation Implementation Package for a fictional practice of your own design, which an owner, a privacy official and a security official could approve. The level ships with a printable workbook and ten templates, and the examination draws forty scenario questions.

Statements of authority say whom they bind: device law binds manufacturers, certification criteria bind certified health IT developers, and the prior authorization timeframes bind impacted payers, not practices. No rule recorded here requires an AI use record, so the log is taught as this programme's recommendation. Prompt injection is a residual risk that controls reduce, never solved, and every status statement is dated as verified on September 15, 2026.

Everything here is professional education. It is not clinical training, it does not teach diagnosis, triage, prescribing, treatment decisions or code selection, and it is not legal, privacy, security or coverage advice. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It is not a medical, nursing or other healthcare licence, a coding credential, a security qualification or a compliance certification, it carries no professional education hours, and it satisfies no licensing, credentialing or payer training requirement.