Built and verified, switched off on purpose
Scheduled weekly and verified on real files, but set to report without moving anything until the agency has reviewed one run.
The situation
Therapy orders awaiting signature land loose in one folder under inconsistent file names. The PDF may list a physician the patient no longer has, and a misfiled order reaches a doctor who has no authority to sign it.
The cost of leaving it alone
A misfiled order is discovered only when it is chased weeks later, and until then care and billing wait on a signature.
What we built
A weekly job identifies the patient from the file name, falling back to the PDF’s header text, and matches that patient to the EMR’s patient list. It reads the current primary physician from the EMR, creates a surname folder if needed, and files the order there. Anything ambiguous goes to a review folder with a logged reason.
The key design decision: the document is evidence of the patient only. The EMR is the sole authority on the physician. A dry run is the default.
Python on a scheduled jobA view-only EMR roster exportPDF text extraction (no OCR)OneDrive folders
Why AI, or why not
No. The right answer is already written in the EMR, so inferring it would be strictly worse than looking it up.
The results
How PHI was protected
- The job runs on an agency-controlled server, and the cache holding order PDFs is pinned to the encrypted volume.
- Two agreeing name tokens are required, because a surname alone would have misfiled two different patients.
- The administrator’s own “waiting” folder is never touched.
What we would tell you to skip
A success check that compares against what it found, instead of against what it expected, reports success when it finds 5 of 63 patients. Compare against the expected size.
Reusable for
Agencies with an orders-to-sign workflow and an EMR that holds the physician of record.