- Every follow-up has a current authoritative request
- Bind patient, recipient, requester, intent, purpose, order or plan, priority, occurrence, content, response and stop conditions; recheck current status; and stop draft, held, revoked, replaced, completed, entered-in-error or do-not-perform work.
- Recipient and destination are verified for the action
- Resolve patient identity without merging ambiguity, establish representative authority separately, use the current permitted destination, expose it for review where required and block cross-patient, cross-tenant and stale-contact disclosure.
- Messages carry minimum approved content
- Render exact source instructions through versioned templates, language and accessible format; apply confidential-contact and sensitivity rules; preview destination and payload; protect links and tokens; and keep model-generated clinical language out.
- Delivery evidence is never overstated
- Record generated, queued, provider-accepted, sent, delivered, bounced, opened, replied and acknowledged states from their owners; use bounded retries; and never convert transport evidence, silence or model classification into comprehension or clinical disposition.
- Clinical and urgent replies reach qualified people
- Preserve patient words, apply fixed escalation rules, make no diagnosis or advice, route symptoms and sensitive ambiguity promptly, show handoff ownership and acceptance and keep emergency information available through the approved path.
- Non-response creates owned work, not conclusions
- Use approved timing and attempt thresholds, assign a named task owner and due time, expose aging and failure, fence late signals and require qualified staff evidence to close, correct or replace the underlying follow-up requirement.