Kill the Clipboard: What CMS's Paperless Intake Push Actually Changes

Kill the Clipboard: What CMS's Paperless Intake Push Actually Changes
The principles behind "Kill The Clipboard"

An informational briefing for clinical leadership

Every clinical leader has watched the same scene play out a few thousand times. A patient arrives, is handed a clipboard, and reconstructs their own medical history from memory in a waiting room chair — medications they half-remember, doses they guess at, an allergy they mention only if the form has a line for it. A staff member then re-keys that reconstruction into the EHR.

CMS has given the effort to end this a deliberately blunt name: Kill the Clipboard. It is one workstream inside the agency's broader Health Technology Ecosystem initiative, launched at the White House in July 2025 and now carrying more than 700 pledged companies.

The name is memorable. What it actually specifies is more interesting — and more consequential for how you govern data coming into your organization.

The mechanism, stated plainly

Kill the Clipboard is not a portal, an app, or a CMS product. It is a set of existing standards wired together in a specific sequence.

The patient holds the key. A patient establishes an app after verifying their identity to an IAL2/AAL2 assurance level — the same tier used by CLEAR, ID.me, or a mobile driver's license. This is a meaningfully high bar, and it is the load-bearing element of the whole design.

The QR code is a pointer, not a payload. What the patient presents at check-in is a SMART Health Link — in CMS's own framing, "an encrypted pointer, not the data." The record stays encrypted until decryption at the point of scan. The same standard carried verifiable COVID-19 vaccination records at national scale, so this is proven infrastructure rather than a demonstration project.

What arrives is structured, not scanned. Data lands as FHIR R4 (US Core IG) covering USCDI v3: demographics, medications, allergies, conditions, immunizations, vital signs, lab results, care team, and insurance card. Not a PDF. Not a fax. Discrete, mappable elements.

The patient can take it back. The link is generated by the patient, time-limited, and revocable at any time. CMS grounds the legal basis in the patient's HIPAA right of access under 45 CFR 164.524 — the patient is sharing their own record with you, which means receiving it fits obligations you already carry.

Data moves both directions. At the close of the encounter, the EHR returns a visit summary to the patient's app automatically. No portal login. No printed after-visit summary the patient loses in the parking lot.

The clipboard was never really a paper problem

It is tempting to file this under administrative convenience — fewer forms, shorter check-in, happier front desk. That framing badly undersells what is at stake, and it will cost you the clinical case for funding the work.

The clipboard is a patient-safety failure with a long, well-documented evidence base. According to PubMed, the research on what happens when medication histories are reconstructed from memory is consistent and uncomfortable:

  • In a Swedish study of 670 admitted patients, 47% had at least one medication history error, and standard non-pharmacist ward care left a considerable share of those errors undetected four days later (Hellström et al., 2012).
  • In a two-year prospective study of 814 internal medicine patients, 64.5% had at least one reconciliation error at admission, averaging 2.2 errors per patient. Roughly 39% of admission errors carried potential to cause moderate or severe harm (Belda-Rustarazo et al., 2015).
  • A Swiss study found 5.24 discrepancies per patient at admission, with at least one in every patient. Notably, 67% of discrepancies surfaced only during a pharmacist's direct interview with the patient or caregiver (Giannini et al., 2019).
  • Among hospitalized hypertensive patients, 46.7% had at least one unintentional discrepancy, and about 64% of those discrepancies were of moderate to high clinical significance (Abu Farha et al., 2021).

Across every one of these studies, the single most common error type is the same: omission. The drug the patient is actually taking simply is not on the list.

That is the real argument for Kill the Clipboard. Not that intake is annoying. That your clinicians are making decisions on records the patient was structurally unable to complete accurately, and the resulting gaps have measurable potential for harm.

What changes for patients

They stop being the transport layer. For decades the patient has been the mechanism by which information moves between disconnected institutions — carrying it in their head, in a folder, in a plastic bag of pill bottles. This design retires that role. The record moves as data; the patient authorizes the movement.

Authorization becomes granular and reversible. A patient who could previously only sign a broad release form now generates a specific, time-limited, revocable link. That is a materially different relationship to one's own record — closer to holding a key than signing a waiver.

The identity gate is real, and it cuts both ways. IAL2/AAL2 verification is what makes the data trustworthy enough for a clinician to act on. It is also a smartphone, a credential, and a documented identity — three things a meaningful share of your patient population does not reliably have. The people whose records are most fragmented (the elderly, the unhoused, patients with limited English proficiency, rural patients on thin connectivity) are the same people least likely to clear the gate.

What changes for providers

CMS lays out three adoption paths, and the sequencing advice is explicit: "Don't wait if you don't have to."

Native EHR capability. Epic, athenahealth, eClinicalWorks, MEDITECH, Medplum, NextGen, and Parker support SMART Health Link reading today. CMS calls this "the cleanest long-term path because scanned data lands directly in your existing workflow." Several vendors remain in development — Healthcare Registries targeting 8/31/2026, Modernizing Medicine 12/1/2026, Prompt Health 1/31/2027.

Community-hosted readers. Andor Health, b.well Connected Health, and Patient Centric Solutions host browser-based readers usable today with no IT deployment. This is the bridge if your vendor has not shipped.

Self-hosted open source. CMS publishes MIT-licensed reader code on GitHub for organizations that require the data to stay inside their environment and want to run their own security review.

The obstacles reported by early movers are not technical. They are operational: staff must be trained to ask for the code consistently, reception needs scanning hardware, and — the one most often underestimated — someone has to decide where patient-supplied data lands in the chart and what status it carries. As Deven McGraw of Citizen Health has noted, providers do not agree on what information they need, which makes standardizing intake harder than standardizing the transport.

The honest status, as of today

This is a voluntary program. There is no mandate, no fine, no certification requirement, and no deadline attached to provider adoption. CMS showcased its first wave of working tools in April 2026, and the infrastructure is genuinely live.

But the adoption asymmetry is the number worth carrying into your next governance meeting: more than 700 technology companies have pledged, and fewer than 50 provider organizations have. The tooling exists. The demand signal from delivery organizations does not yet match it.

Industry observers have been direct about why. Leigh Burchell of Altera Digital Health argued CMS "will need to invest in… fee schedule incentives that motivate that behavior," calling provider utilization "a critical last mile." The Bipartisan Policy Center has called for "clear, predictable reimbursement pathways." Others note the voluntary model lacks binding contracts, enforcement, or dedicated funding.

Read plainly: the standards are ready, the business case for the provider side is not yet written, and no one is coming to write it for you.

What you can authorize this quarter

Four decisions, each with a named owner and a measure:

  1. Get your vendor's date in writing. Assign your CMIO or IT director to obtain a written SMART Health Link capability timeline from your EHR vendor. Measure: a dated commitment on file within 30 days.
  2. Pilot in one clinic, not enterprise-wide. Stand up a community-hosted reader in a single high-reconciliation-burden service line — anticoagulation, transplant, complex care management. Measure: scans attempted and successfully ingested per week.
  3. Write the data-provenance policy before the data arrives. Decide now how patient-supplied FHIR data is labeled in the chart, who may act on it unverified, and what still requires clinician confirmation. Measure: a written policy ratified by your clinical informatics committee.
  4. Define the paper path deliberately. Whatever you build, a share of your patients will still present without a code. Name who owns that workflow so it does not silently become the second-class lane. Measure: documented parity in intake time and data completeness between digital and non-digital patients.

Three questions this technology has not yet answered

1. When patient-supplied structured data is wrong, who is accountable?

The clipboard had one underrated virtue: the patient attested to it, in the moment, in their own handwriting. Now verified-looking FHIR resources flow machine-to-machine into the chart, carrying the visual authority of structured data. If a medication list arrives complete, discrete, and stale — sourced from a payer claims feed that lags six weeks — and a clinician acts on it, where does liability sit? Does ingesting patient-supplied data create an affirmative duty to reconcile it? No standard of care has been established, no case law tested, and no professional society has issued guidance. Organizations are being asked to accept the data before anyone has defined what accepting it means.

2. What happens to the patients who cannot clear the identity gate?

IAL2/AAL2 verification is the feature that makes this trustworthy and the barrier that makes it exclusionary. If digital intake becomes the fast, complete, well-documented path, paper intake does not stay neutral — it becomes the slow lane, and the patients in it are disproportionately those whose records were already the most fragmented. Nobody has committed to measuring whether the completeness gap between digital and non-digital patients widens. Until someone does, the equity claim rests on assertion rather than data.

3. Once the record reaches the patient's app, what governs what happens next?

This is the question with the longest tail. HIPAA's right of access is the legal engine that moves the data — but the moment it lands in a consumer application, it has generally left HIPAA's jurisdiction and entered the FTC's. The patient gained control; they also gained a terms-of-service agreement most will never read. Can that record be used to train commercial models? Sold to a data broker? Priced into an insurance product? The architecture is a genuine advance for patient sovereignty at the point of care. Whether it becomes an extraction pipeline one screen later depends on rules that have not been written.


The Center of Patient Innovation publishes strategic insights for clinical leaders navigating AI-enabled care.


Sources