Full review
MAIA CAIHL draft report
Evidence-linked HugoScore draft report for a health AI tool that affects patients.
MAIA: CAIHL reassessment
September 8, 2026. Published AI-assisted draft.
MAIA describes patient-directed record interpretation with important hosting qualifications. Patient authority over questions does not establish privacy from a demo operator. Actual data handling, correction, and deployment controls remain untested.
Scope and agency posture
Patient-provisioned MAIA private record agent. A shared demo or someone else's hosting account is a different trust arrangement.
Posture: Strongly agency-expanding, with demo-host-trust, security-maturity, and technical-burden caveats.
Axis: 90/100, retained provisionally. No numerical recalibration was performed.
Sources and documented findings
- The live welcome and raw README fetches failed, but the targeted GitHub repository page rendered current documentation. It describes editable chats, patient-verified medications and summaries, source-page links, private instructions and optional public-model routing. https://github.com/agropper/self
- The same README says the hosting account owner can likely control data access and recommends personally provisioned hosting. It separates code verification from operator access. These are architecture claims, not an operational audit. https://github.com/agropper/self
Patient authority
Inference from the documented workflow: User-selected documents, editable instructions and verified summaries support direction over the assistant's context. Caregiver or third-party hosting must not be mislabeled as control by the patient.
Critical capacity
Editorial assessment: Source links and required reconciliation offer concrete mechanisms for checking interpretations and preparing care discussions.
Informed control
Editorial assessment: The trust model is unusually candid. Pseudonymization does not guarantee anonymity, and choosing a public model introduces its own processing conditions.
Assessment and limits
The strongly positive design assessment remains supported for personally controlled provisioning. Openness helps inspection but supplies no automatic score credit or proof of secure operation.
Confidence: Moderate for documented design, limited for current live deployment.
Remaining uncertainty: Actual deletion, host isolation, public-model data handling and usability remain untested
Published documentation is evidence of stated conditions, not proof of actual implementation. Unknowns did not receive automatic negative points. Funding, sponsorship, and public code do not determine agency by themselves.
Review provenance
- Reviewer/model: OpenAI Codex / GPT-6.
- Method: Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
- Human review: Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
- Earlier review: 2026-06-26. Historical assessment. Earlier claims are not automatically reverified by this publication.