HugoScore hugoscore.org

Full review

Microsoft Dragon Copilot CAIHL draft report

Evidence-linked HugoScore draft report for a health AI tool that affects patients.

Microsoft Dragon Copilot: CAIHL reassessment

September 8, 2026. Published AI-assisted draft.

Microsoft Dragon Copilot supports clinician-controlled documentation and nursing workflows. Clinicians approve the output. Declining encounter recording may still allow later AI processing of clinician dictation, and revocation does not remove data already anonymized.

Scope and agency posture

Microsoft Dragon Copilot clinician documentation and nursing workflows, deployed by healthcare organizations. Institutional AI affecting the patient record, not a patient-operated assistant.

Posture: Mixed, institution-led.

Axis: 36/100, retained provisionally. No numerical recalibration was performed.

Sources and documented findings

  • The privacy whitepaper, updated August 20, assigns review, editing, transfer, and sign-off to clinicians. It describes post-encounter dictation when a patient prefers not to record.
  • That whitepaper describes anonymization within 90 days and customer-mediated revocation. Already anonymized data is not purged on revocation.
  • The FAQ describes retained audio, text, and generated flowsheet data. Public article content was retrievable despite an authorization notice. No login was used.

Patient authority

Inference from the documented workflow: The clinician sets the documentation task and approves its consequences. Refusing encounter recording can change capture method, but is not the same as preventing later AI processing of clinician dictation.

Critical capacity

Editorial assessment: Better documentation may support subsequent patient review, but the product assigns the patient no direct evidence-inspection or editing workflow in these materials. Clinician benefit is not evidence of increased patient authorship.

Informed control

Editorial assessment: The lifecycle and revocation limits are specifically disclosed. Effective consent still depends on what the healthcare organization tells the patient and how requests are handled.

Assessment and limits

Mixed, institution-led remains supported by explicit allocation of control, rather than institutional ownership alone. The update adds a concrete distinction between recording refusal and AI-use refusal.

Confidence: Medium for product governance.

Remaining uncertainty: Local consent wording, access to transcripts, AI-specific correction routes, patient-facing release of outputs, and actual enforcement.

Published documentation is evidence of stated conditions, not proof of actual implementation. Unknowns did not receive automatic negative points. Funding, sponsorship, and public code do not determine agency by themselves.

Review provenance

  • Reviewer/model: OpenAI Codex / GPT-6.
  • Method: Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
  • Human review: Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
  • Earlier review: 2026-06-08. Historical assessment. Earlier claims are not automatically reverified by this publication.