When an AI agent takes over a GP's screen, navigates through their practice management system and extracts patient records, it is doing something the terms and conditions of every major Australian PMS vendor expressly prohibit.
What happens when a software company decides to do something it knows is legally contestable, in a regulated industry, with patient data, and then releases it publicly to tens of thousands of clinicians without asking anyone’s permission first?
That is pretty much what Heidi has done with their Heidi II launch.
The Australian health software industry has built itself a pretty neat trap — a customer service versus business model trap.
The Ts and Cs
The major Australian practice management software vendors – Best Practice, MedicalDirector, Magentus (Genie/Gentu) and MediRecords – all have terms and conditions that seem to create significant problems for what Heidi II’s robotic process automation (RPA) agents are doing.
MedicalDirector is the most explicit. Its terms expressly prohibit unauthorised data mining and extraction, restrict copying or interacting with the interface, and ban third-party integration without a written agreement.
Its terms specifically define “third-party automation tools” to include bots, scraping tools and robotic process automation, then prohibit their unauthorised use outright.
Doesn’t feel like there is much room for interpretation there.
Best Practice’s licence agreement requires customers to obtain prior written consent before allowing any third party to “access, use or modify” the software.
Magentus restricts access to authorised staff with credentials on a need-to-know basis, and prohibits making the software available to others.
The contractual obligations in each case run between the vendor and the customer – the GP practice – not between the vendor and Heidi directly.
This means the practice and perhaps the GP are the ones technically in breach, not Heidi.
It also means every GP who has installed Heidi II and set up an RPA routine on their PMS has almost certainly violated their software licence, whether they know it or not.
Most won’t know it.
GP technology and policy commentator Dr Max Mollenkopf is pretty clear about what he thinks he sees in a LinkedIn post he put out on Friday last week which everyone should have a read of:
“I … have absolutely no doubt I’m actively breaking all the T+Cs of the PMS software I’m using,” he says.
Kelly’s position: the terms didn’t contemplate us…
Dr Thomas Kelly, Heidi’s co-founder and CEO, does not dispute the substance of what the RPA agents are doing.
When asked directly about the T&C problem in an interview with The Medical Republic today, his response was measured but clear: “I think the original way that they were drafted their [terms and conditions] probably didn’t quite contemplate tools like this”.
His argument is essentially that the terms were written before agentic AI existed as a category, that Heidi’s RPA is not classic screen scraping in the way those terms envisioned, and that the agent operates under the GP’s own authenticated login – using the practice’s own access to the practice’s own patient data.
“We’re literally this week sharing an open [multi context protocol (MCP)] standard,” Dr Kelly added.
“Anyone can connect with the system. Our preference is not to do computers [RPA automation of the GP computer to get access]. Of course it’s faster to do a direct connection.”
The argument has some legal texture.
Related
Best Practice’s terms, for instance, use language around “you” that could arguably extend to an agent or contractor acting on the GP’s behalf.
But legal sources with knowledge of the agreements say this reading is a stretch, particularly given MediRecords’ and MedicalDirector’s explicit prohibitions on automated tools.
The fact that Heidi operates under the doctor’s login does not resolve the question according to those sources. In fact, it may actually compound it, given the fiduciary and clinical governance obligations attached to that login.
Painted into a corner
Everybody in this story has a problem now – the PMS vendors whose terms Heidi is breaching, the practice managers and their GPs, who might be breaching terms and exposing the practice to anything that goes wrong from here on in, and, unsurprisingly, Heidi itself.
I’m not entirely sure, though, that Heidi isn’t aware of what they’ve done.
It’s literally driving a fully loaded fuel tanker into a smouldering fire…
The PMS vendors know, with absolute certainty, that their doctors wanted what Heidi is offering. A pre-charted day. Agents drafting referrals while the next patient walks in. Evidence retrieval grounded in full journal text.
The productivity upside is not marginal, it is transformational for a GP running 30-plus consults a day.
If the PMS vendors had built this, their customers would be ecstatic.
Note: we will talk about price tomorrow in Robot Doctor, because the amount of compute to do all this stuff is huge and may even be preventative in the end.
The incumbent PMS vendors don’t seem even close to this functionality, even Best Practice with its tight Lyrebird integration (more on that tomorrow too).
Building a modern agentic AI layer on top of a clinical record system is not a feature addition. It is a fundamental reorientation of what the product is.
The compliance overhead alone – conformance with Services Australia, TGA obligations for anything that touches clinical decision-making, state and federal data governance – is crushing.
Kelly himself noted that adding a single prostate cancer registry module to Heidi’s earlier telehealth product would have taken six months of conformance work. Multiply that by the scope of a full PMS.
Here’s the trap the PMS vendors have unwittingly built for themselves.
If the vendors enforce their terms and move to block Heidi’s RPA access – technically, through rate limiting, login detection or legal action – they will be doing something that looks, from the outside, exactly like the information blocking that has made Epic and Oracle so loathed by clinicians globally.
They will be denying their own customers access to tools and functionality those customers demonstrably want, for reasons that are commercial more than anything else.
They will no doubt they will say there are important issues of safety, legality, compliance and so on. But it’s about the money, not about the GP user experience at this point.
The alternative for them not withstanding is pretty bad.
If they integrate – give Heidi the direct MCP access it is publicly requesting, with full read and write – they accelerate the process by which Heidi becomes the primary interface for the doctor and they become the expensive to maintain, heavily regulated database sitting underneath it.
The compliance costs don’t go away. The customer relationship does.
Dr Kelly is frank about the endgame: “We can be the Heidi inside of a MediRecords or Best Practice or whoever.”
But he does say that Heidi can’t just roll over the top of PMS vendors who own the customer now. There will need to be an appropriate commercial deal, he suggests.
Just what that deal would be however is anyone’s guess because no one has any understanding at all of the compute costs of agentic AI at this scale in the hands of a GP.
It’s messy.
It’s disruption writ large, something that the healthcare sector has largely been immune to through all the phases of digital disruption.
Dr Kelly, you sense, is all about disruption… for all sorts of reasons, commercial and in the interests the profession.
What happens next
Best Practice was asked for comment today and politely declined (well, not all that politely, but we get it).
None of PMS vendors are in a comfortable position. Best Practice is probably the least comfortable, followed by Magentus and Genie.
What feels clear is that Heidi has done something strategically deliberate here.
Releasing RPA agents publicly – to all clinician-tier subscribers, without waiting for regulatory or vendor sign-off – isn’t an accident. It is a test of market appetite designed to create facts on the ground before anyone can respond.
Dr Kelly acknowledged as much: “Part of this release is pushing the bleeding edge. I know that. I think it’s partly to show that there’s appetite.”
Show who?
The Australian government has not yet contacted Heidi about Heidi II, despite the agents now operating live inside practice management systems across the country, navigating patient records under clinician logins, in an environment still raw from the OpenAI Medicare hack.
OK, it’s only a week. But an ‘AI week’ is equivalent to months in the old tech development world, or, if you have waited a week to respond, you are sitting on your backside either perplexed or stuffing around.
The legal exposure sits primarily with the GP practices running Heidi II against their PMS.
The regulatory questions – what the TGA makes of autonomous agents operating within clinical software, what the OAIC makes of the data flows – aren’t clarified by anyone other than Heidi itself. Dr Kelly unsurprisingly says, it’s all OK – they do nothing that makes them technically a medical device.
They don’t, but that’s not the issue here. The issue now is just how well tested and safe these little agent critters running around inside our GP software actually are.
I guess we’ll all find out soon enough.
The vendors whose terms are being breached (we think) are left choosing between two versions of the same bad outcome.
In that sense, Heidi has done to Australian health software what Uber did to the taxi industry: not asked for permission, created demand at scale, and waited to see if the market and the regulators would follow.
In transport, that worked (not for the Taxi industry of course).
In medicine, with patient records, we’re in a different universe.
Tomorrow, TMR’s Robot Doctor will be running a special issue just on Heidi II. If you liked this story you might want to tune in to that issue (Robot Doctor is a different type of newsletter than TMR and Health Services Daily). To give you a taste of what we will be writing about here are the headings for the stories tomorrow:
Heidi II agents escape, crash GP’s new Chinese EV

What is Thomas Kelly and his merry band really thinking here?
Heidi II puts Best Practice in a difficult place
Heidi II and the local non EMR hospital market
Heidi II and the local EMR hospital market
To be added to the Robot Doctor mailing list, email Sarah@medicalrepublic.com.au.



