HugoScore hugoscore.org

Patient-controlled health records AI

Fetch My Epic Token

Fetch My Epic Token enables patient-directed record retrieval. Its 88 describes infrastructure, not clinical AI output. Local scripts and hosted helpers have different data-processing boundaries, and broad no-collection wording does not explain all necessary transient processing.

AI-assisted draft Read full report Open directory

Published September 8, 2026 as an AI-assisted draft. The public report separates documented facts, agency judgments and unresolved questions.

88 /100 toward patient-directed
Agency posture Strongly agency-expanding, with credential-handling and technical-burden caveats
The question we ask Who does Fetch My Epic Token serve in this deployment?
Control Patient-directed record retrieval and AI-enabling infrastructure. The core token utility does not itself provide AI clinical judgments.
Agency read Strongly agency-expanding, with credential-handling and technical-burden caveats
Vendor
glmck13 / independent open-source project
Who it serves
Patient-directed, AI-enabling interoperability utility
Primary User
Patients, caregivers, and patient-developers with Epic/MyChart accounts
Control Model
Local scripts or hosted download helper. Processing and custody differ by mode.
Patient Impact
Access to underlying records can support checking and advocacy. Correcting source records remains a provider process, and downstream AI quality is outside this utility.
Profile Status
AI-assisted draft
Last assessed
Sep 8, 2026
Review Confidence
Moderate for public interface and source design (AI-assisted draft)
AI / Model
OpenAI Codex / GPT-6
Human Review
Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Summary judgment · 88 out of 100 toward patient-directed

88 is an infrastructure-specific editorial placement. Core AI output is not applicable.

Strongly agency-expanding, with credential-handling and technical-burden caveats

Fetch My Epic Token enables patient-directed record retrieval. Its 88 describes infrastructure, not clinical AI output. Local scripts and hosted helpers have different data-processing boundaries, and broad no-collection wording does not explain all necessary transient processing.

Patient agency

How this tool changes agency

Expands agency when

Access to underlying records can support checking and advocacy. Correcting source records remains a provider process, and downstream AI quality is outside this utility.

Limits agency when

Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified

Patient agency assessment

Who sets and changes the goal?

Patient authority

Patients gain portable records and can choose downstream analysis. Hosted helper use delegates sensitive processing, while local script use has a different trust boundary.

What can the patient understand, question, or do?

Critical capacity

Access to underlying records can support checking and advocacy. Correcting source records remains a provider process, and downstream AI quality is outside this utility.

Can the patient evaluate the conditions of use?

Informed control

The policy's broad no-collection wording does not explain necessary transient server processing. Source availability enables inspection but is not an audit or evidence of deployment parity.

Text findings

Conditions of use

Published controls and their limits

The policy's broad no-collection wording does not explain necessary transient server processing. Source availability enables inspection but is not an audit or evidence of deployment parity.

What remains unknown?

Not tested or not established

Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified

Who evaluated this?

AI-assisted public-source draft

Vendor statements describe published conditions, not independently verified behavior. No clinical, security, accessibility, or legal validation is claimed. Earlier evidence remains dated in the report and history.

Sources checked

Source-specific findings and retrieval limitations are recorded in the full report.

Review provenance

Criteria

CAIHL-derived HugoScore framework and September 7 qualitative review priorities. Draft v1.2 numerical anchors remain unadopted.

Reviewer

AI-assisted public-source reassessment prepared in OpenAI Codex.

AI / model

OpenAI Codex / GPT-6

Human review

Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.

Review date

2026-09-08

Limitations

Hosted code parity, logging, temporary-data deletion behavior and practical credential warnings remain unverified No live product use, patient-data upload, account creation, code audit, clinical evaluation, or independent implementation validation.

Review method

Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.

AI-assisted draft · Moderate for public interface and source design (AI-assisted draft)