Sector — Healthcare

Giving time back to care, without touching care

AI in Morocco's clinics and health groups: discharge summaries, insurance billing, patient journeys. Medical secrecy, law 09-08 and sovereign deployment.

In brief

In a Moroccan healthcare organisation, generative AI must stay in its place: it eases the administrative burden — discharge summaries, letters, coding, billing, appointment booking — and makes no diagnosis. Medical secrecy and the sensitive-data status granted to health data by law 09-08 call for a controlled, usually sovereign, deployment. Hunter BI designs these systems with the care teams, not against them.

Ask a Moroccan doctor what takes up the most of their time away from the patient, and the answer will be writing. Discharge summaries, exit letters, prior-authorisation requests, reimbursement files, coding. This work is essential, it is time-consuming, and it has nothing medical about it. That is where — and nowhere else — generative AI has an obvious place in healthcare today.

We set this boundary from the very first meeting, because it decides everything else: Hunter BI does not deploy diagnostic AI, does not offer clinical decision-support algorithms, and does not touch the medical act. We work with Moroccan clinics, health groups and laboratories on the administrative burden — the one that wears teams down, slows patients down and costs organisations money. The potential there is considerable, and the risk, properly framed, is manageable.

Updated 14 July 2026

Sector stakes in Morocco

Medical secrecy and sensitive data: the framework is strict, and rightly so

Health data is not data like any other. Medical secrecy is an obligation of the practitioner — enforceable and punishable; law 09-08 places health-related data among sensitive data, subject to a reinforced regime under the supervision of the CNDP. In practice, this means that a report, a test result or even the mere identity of a patient tied to a department cannot be fed into an AI tool without explicit framing: declared purpose, legal basis, retention period, access control, and a demonstration that the data does not travel to where you can no longer follow it.

This requirement forbids nothing — it steers. It steers towards architectures where medical text is processed within the organisation's perimeter, towards systematic pseudonymisation wherever possible, and towards administrative rather than clinical use cases. It also imposes a discipline that organisations would do well to apply independently of AI: knowing who accesses what. Many of our healthcare engagements in fact begin with this uncomfortable discovery — the data already circulates, in the clear, across messaging apps and spreadsheets. AI does not create this risk; it finally makes it visible.

Medical secrecy

An obligation of the practitioner, not a preference of the organisation. No system should expose medical content to an unauthorised third party, nor make it accessible beyond the care team.

Sensitive data, law 09-08

Health data falls under the reinforced regime of law 09-08 supervised by the CNDP: purpose, legal basis, retention and access must all be explicitly framed.

No clinical decision

Hunter BI does not deploy diagnostic AI. The scope is administrative: writing, coding, billing, scheduling, patient information.

Use cases

What AI concretely changes healthcare

Every use case links to the Hunter BI offer that delivers it. We claim no result figures until they are measured at your organisation.

Sovereignty

Health data should not leave the organisation

There are sectors where the hosting location is open to discussion. Healthcare is not one of them, or only very cautiously. A hospitalisation report, an imaging result, a medical history: these elements engage medical secrecy and fall under the most protective regime of law 09-08. Entrusting them to a service whose location and access conditions you do not control means taking a risk that neither the patient nor the CNDP has accepted — and that the practitioner personally bears.

That is why our healthcare deployments are, in the vast majority, sovereign: open models hosted within the organisation's infrastructure or with a qualified host in Morocco, upstream pseudonymisation wherever possible, department-level compartmentalisation, complete access logging. Medical text is processed where it is produced, and it does not leave. The rest — market watch, administrative writing without patient data, office productivity — can rely on enterprise cloud platforms. This clean separation is what lets an organisation move forward without ever having to apologise.

Where to start

Three steps, in this order

In healthcare, we start where there is no patient data — then move forward, once the framework is written and the team is trained.

Step 01

Free diagnostic

A session with management, a lead practitioner and the head of information systems: where administrative time is lost, which data is genuinely at stake, and what is feasible without exposure.

Step 02

Pilot without patient data

Internal protocols, organisational questions, back office: a first assistant that is useful and risk-free, building team trust and the governance framework before any contact with the care record.

Step 03

Extension to the care record

Reports and billing, within a sovereign architecture, with CNDP framing, department-level compartmentalisation and oversight. This is where the time saved becomes significant — and where you must be beyond reproach.

Frequently asked

Does Hunter BI deploy medical-diagnosis AI?

No. Our scope is administrative: writing, coding, billing, scheduling, non-clinical patient information. Diagnostic decision support falls under a medical-device regime, clinical validation and a responsibility that we do not take on. This boundary is written into our healthcare engagements, and it is not negotiable.

Can a consultation be transcribed by an AI assistant?

Technically yes, legally under conditions. This is health data within the meaning of law 09-08: the processing must be framed with the CNDP, the patient must be informed, and the processing carried out within a controlled perimeter. For this use we recommend a sovereign deployment, where the audio and text never leave the organisation.

How can you guarantee that no patient data leaves the country?

By simply not connecting the care record to an external service. That is the role of sovereign architecture: models hosted within your infrastructure, local indexing, logs under your control. The guarantee comes not from a contractual clause but from a network topology — the only one that can be demonstrated.

Will caregivers really use the tool?

Only if it saves them time from the very first week, and if they were involved in its design. Our healthcare deployments start with the irritants that teams mention spontaneously — often the exit letter or the billing rejection. A tool imposed from above, without a lead practitioner, does not survive its third month.

How is this different from a classic hospital management system?

A management system structures data that is already structured. Generative AI processes free text — the report, the note, the letter — which makes up most of the record and which no one exploited until now. The two are complementary: we plug the assistant into your existing system rather than proposing to replace it.

AI in your field: let's start with a diagnostic.

A free scoping session with a Hunter BI consultant: your data, your regulatory framework, the use cases worth launching first — and the ones better set aside.

  • Réponse sous 24 h ouvrées, par un ingénieur
  • Diagnostic gratuit, sans engagement
  • Membre des réseaux partenaires OpenAI et Anthropic