A clinical document with the doctor's name on it
After a consultation, doctors referring patients to specialists write a referral letter: patient details, consult summary, diagnosis, reason for referral. It's formulaic and repetitive, the same structure rewritten dozens of times a week, often between back-to-back video consults.
Generative AI is a natural fit since the consult data already exists in the system. But a referral letter is a clinical document with the doctor's name on it. A hallucinated medication, a wrong diagnosis code, or a fabricated detail isn't a UX bug: it's a clinical and legal problem.
The design question wasn't whether AI could write the letter. It was how a doctor stays meaningfully accountable for a letter they didn't type.
Doctors don't have to believe the AI is always right. They have to be certain that nothing leaves their hands without their review, that every word is editable, and that the system never pretends AI text is their text.
The shipped experience.
The letter moves through five states as authorship shifts from the AI's draft to the doctor's own words.
generate + write-manually ]
editable field ]
disclaimer + badge shifted ]
back to empty ]
The state machine. The distinguishing element in each state is the badge + disclaimer, top of every screen — "AI-drafted" while the text is the model's, shifting to "Edited by you" the moment the doctor types. Slots are sized for your exported screens.
The state machine is the design
The interesting part wasn't the generation itself. It was the state logic, how the interface behaves as the letter moves through its lifecycle. Each transition had to answer three questions: what the doctor needs to feel (in control), understand (what the AI did and from what data), and do (review, edit, send, discard).
- Empty / initial: a clear entry point to generate, and an equally clear path to write manually. AI is an offer, not a default.
- Generating: an explicit in-progress state. The doctor knows the system is working, and what it's drawing from.
- Generated: AI output lands in an editable field, visibly attributed as AI-drafted, with a disclaimer active. Regenerate and clear are both available.
- Edited: the moment the doctor touches the text, the state changes. The letter is now the doctor's, and the disclaimer and CTA respond to that shift in authorship.
- Cleared: one action wipes AI content entirely. The doctor can start from scratch, with no sticky AI residue.
Decisions that keep the doctor accountable
- Disclaimer tied to state, not stapled on. It isn't a static legal banner: it reflects whether the current text is AI-drafted or doctor-edited, so the accountability signal stays accurate.
- Editing is the primary interaction, not the fallback. The generated letter lands in a fully editable field, not a preview with an "edit" button. Reviewing by editing matches how doctors actually work.
- Regenerate and clear always visible. Recovery from a bad generation is one tap, never buried, keeping the perceived cost of a bad AI draft near zero.
- No auto-send anywhere in the flow. The AI drafts; only the doctor submits. The final action is unambiguously human.
Where this stands
Shipped Q4 2025, to Singapore providers first, and scoped to Medical Specialist referrals only, not all referral types. Early usage since launch:
Adoption at 13% is modest, and I'd rather state it plainly than bury it. Most doctors aren't reaching for one-click generation yet, and understanding why, whether it's discoverability, trust, or workflow fit, is the next question this design has to answer.
One gap worth naming: there was no formal usability testing on this feature. The 89.8% useful rating comes from an LLM-as-judge, not moderated sessions with doctors, which is a weaker kind of evidence and I'm not dressing it up as more.
The state model was designed to generalize. The same authorship-transition logic applies to any future generative drafting surface on the platform, such as discharge summaries, MCs, and consult notes.
What this taught me
- In generative AI, the state machine is the design. The screens are simple. The rigor lives in how the interface responds as authorship shifts from machine to human.
- Design for the transition of ownership. The most important moment isn't generation. It's the first edit, when AI text becomes the doctor's text, and the interface has to acknowledge it.
- Accountability is an interaction property. Disclaimers, attribution, and edit states aren't compliance decoration. They're how a clinical tool makes responsibility legible.
