Large language models are fluent. That is their strength and the source of their most dangerous failure: they can produce a confident, well-formed answer that nothing supports. In most software that is an annoyance. In a chart it is a hazard. "Metformin was started in March" is a useful answer if it is true and a harmful one if the model made it up.
Terra answers two kinds of questions: questions about the patient's record, and questions about the medical literature. For both, we hold to one rule. Every statement cites a source you can open, and when there is no source, Terra says so.
Record chat: answers from the chart, with the excerpt
The chat column beside every visit answers questions about the patient you are looking at. "When was metformin started, and at what dose?" "What did the last two signed notes say about the knee?" "Which documents mention a penicillin reaction?"
What it can read
Record chat reads a deliberately limited set of sources:
- this visit's context and transcript,
- documents whose extracted text a clinician has reviewed and approved,
- approved facts: allergies, medications and problems,
- verified signed notes, with their amendments.
Unreviewed document text is excluded. So are unsigned drafts from other visits and every other patient. These limits are not about speed. They are about what counts as evidence. An extraction nobody has checked, or a draft nobody has signed, is not something a clinician should have quoted back to them as fact.
How an answer is checked
Every answer must cite exact, versioned excerpts from those sources. The citation is not a link to "the chart". It is a pointer to a specific passage in a specific version of a specific note, document or fact, and it opens that passage when you select it.
The model is told it may answer only from the sources provided, and that when the sources do not support an answer it must say the record does not contain it. Terra validates the citations in every response against the sources that were actually sent. A citation to something that was not provided is rejected.
"Not in the record"
The most important answer record chat gives is sometimes "not in the record". If you ask about a colonoscopy and nothing in the reviewed sources mentions one, Terra says that rather than guessing.
That answer has a limit worth stating clearly: absence from the record is not absence in the patient. "No colonoscopy found in the reviewed record" does not mean the patient never had one. It means you should ask, or look for the report.
Literal mode
Sometimes you do not want interpretation at all. In literal mode, or when no AI provider is connected, record chat returns the exact matching excerpts from the record with no model involved and no credits used. It is a search, not an answer, and it is labelled that way.
Evidence research: the literature, with privacy built in
Questions about the literature are different. The answer is not in the chart; it is in PubMed, in drug labels, in patient-education resources. And the question often contains patient details that should never leave the practice.
Evidence research handles this in five steps.
1. Plan, without fetching anything
You type a question while you write the note. The model sees the question and the list of available sources, and returns a plan: up to five searches, each with the source it will use and the reason. Nothing has been fetched yet.
2. A privacy check, twice
Every planned search passes a privacy check before you see it. It rejects exact dates, exact ages such as "67 year old" or "45M", record and ID numbers, contact details, addresses, names with honorifics and links. Age ranges like "65 and older" are fine. Then Terra checks each search again against the patient's actual name, date of birth in its written forms, birth year, MRN and record IDs.
A search that fails is withheld from the plan and not stored. Only the fact that one was blocked, and why, is kept.
3. You confirm
The plan appears as a checklist. You can untick searches, edit them, remove them or add your own. Edited searches go through the same check, and if one fails, nothing is sent. Only the searches you leave ticked run.
4. Retrieve from public sources
The searches go only to public services built into Terra: NCBI's PubMed and PubMed Central, DailyMed and openFDA drug labels, and MedlinePlus. Terra sends no account, no cookies and no identity with them, follows no redirects, and keeps strict limits: five queries, twenty passages, a few short snippets each. Retraction, erratum and expression-of-concern flags from PubMed come along with the passage.
5. Answer, citing only what was retrieved
The answer has a fixed shape: what the evidence says, where every statement cites a retrieved passage; what may apply to your patient, as considerations to check; conflicts and gaps, which always lists at least one; and an explicit flag when the evidence is insufficient. Terra rejects any citation that does not point to a retrieved passage, including one pointing at the question itself. If nothing was retrieved, Terra records an insufficient-evidence answer without calling the model at all.
Citation chips open the source on NIH, FDA or MedlinePlus in a new tab, so checking a claim is one click.
Why "always at least one gap"
We require the answer to name at least one conflict or gap because a literature summary that sounds complete is usually overconfident. Studies have populations, dates and limits. Labels change. Telling the clinician what the evidence does not cover is part of an honest answer.
Advisory, always
Neither feature writes anything on its own. Record chat answers stay in the chat column. Evidence answers stay in the research panel until you choose to cite them. Nothing reaches a note, a coding worksheet or the practice's citation library without a separate, deliberate action by a clinician.
The principle underneath
Hallucination is not solved by a better prompt. It is reduced by a system that gives the model only trustworthy sources, requires it to cite them, checks every citation, and makes "I don't know" an acceptable answer. That is what we have tried to build.
You can read the step-by-step guides for record chat and evidence research in the Help Center.

