Nurse-led · Nurse-driven · Nurse-owned

Healthcare runs on trust.
We build the receipts.

Nightingale OS is the nurse-owned software company. Our flagship product, Charlie Owl, is the evidence layer for governed hospital AI — every algorithm inventoried, every decision earning a tamper-evident receipt, every refusal naming its policy. The same spine holds the 148 designation and accreditation programs a hospital answers to. No EHR integration required to start.

Two minutes inside the Owl cockpit — screen-recorded from the running product on synthetic, zero-PHI data.Silent, with captions burned into the recording; best viewed full screen. Walk the same path yourself in the live Playground.
The Flagship — Charlie Owl

Continuous readiness is the standard.
Charlie Owl is how you hold it.

Hospitals are deploying clinical AI faster than they can prove they govern it, and the question arrives the same way from a surveyor, a board, and a plaintiff's counsel: produce the record. Charlie Owl produces it — continuously, before anyone asks. The same evidence spine carries the designations. A designation is the externally-verified promise that a hospital's stroke, trauma, cancer, or maternity care actually works — so losing one is a patient-safety event, a loss of community access, and a revenue event, in that order. The category judges itself by survey-day survival. We think always-ready is the only honest bar.

AI Governance — the Evidence Layer

Every algorithm touching patients gets an inventory entry, human-in-the-loop evidence, calibration monitoring, and a tamper-evident receipt for what it said and what the clinician decided. When the model is wrong, it isn't a nurse's license on the line with nothing to show — the receipts exist.

The Designation Ledger

Trauma verification, stroke certification, cancer accreditation — each one an outside body's promise that the service line works, and the license to bill for it. Charlie Owl tracks every criterion, its evidence, and what a lapse would cost in safety, access, and revenue, so survey day is a walk-through instead of a scramble.

Registrar Amplification

Registry abstraction still means a human hunting through charts — about 39 minutes per case before acuity. Charlie Owl proposes; a named registrar attests; the hash chain keeps the receipt. Abstract once, submit everywhere. Amplification, never replacement.

Survey Mode, in Your Pocket

Walk the halls with the surveyor: tracer prompts, two-tap evidence pull, document requests captured live, findings logged in real time. Drill mode runs the same walk before the real one — offline-capable, because surveys don't wait for hospital wifi.

No Integration Required

Compliance evidence is documents, attestations, public data, and exports your hospital already owns. Charlie Owl never writes to your EHR and never needs a vendor's permission. Start with a spreadsheet; see your first receipts the same week.

Refusal-Grade Honesty

When Charlie Owl won't do something, it says so with a machine-readable code naming the policy and the citation. It never fabricates a readiness score, a regulatory update, or a survey finding. Honesty isn't a feature — it's the foundation.

How It Actually Works

Continuous readiness is a number
with four inputs — not a slogan.

Each accreditation domain carries a running 0–100 readiness score. It is not a mood. It moves on four measurable inputs, and the weakest domains flag themselves. Score bands: ready ≥ 90 · watch 75–89 · at-risk < 75. The score is a prioritization aid, honestly labeled in the product as such — not a guarantee of survey outcome.

Open findings

Unresolved findings from tracers, drills, and prior surveys weigh the score down until each one is closed with evidence attached.

Criterion gaps

Every criterion a designation requires that has no evidence behind it yet — the standard's own checklist, scored against what you can actually show.

Stale & expiring evidence

Evidence has a freshness clock. Competencies, policies, and attestations decay toward their review date, and the score decays with them before they lapse.

Mock-survey pass rate

Your team's scored performance on the sandboxed drill walk feeds back in — practice that never touches the real evidence chain, but that the score can see.

Screenshot of the Owl Designation Ledger — a readiness board of criteria marked green, amber, or red, each with its evidence or its gap attached
The Designation Ledger — every criterion green, amber, or red, with the evidence or the gap attached

Underneath: a hash-chained Decision log a surveyor can verify end-to-end, a tracer engine that walks one patient through every standard touchpoint, a sandboxed mock-survey mode that never inflates real evidence, and evidence-loop refusals that block a surface from publishing without a verified citation chain. See the mechanism in full →

The Portfolio

Not just Joint Commission.
The spine 148 programs share.

Most readiness tools are Joint Commission tools. A hospital answers to far more than one accreditor — and no one holds the portfolio in one place. Owl does: deemed-status accreditors, CMS conditions, federal programs, nursing designation, pharmacy and controlled-substance rules, lab and safety, privacy and civil rights, and a 50-state scope-of-practice matrix. Charlie Owl covers all of these today — in honest tiers: 50 programs modeled end-to-end (583 individually-cited survey criteria behind a live readiness score), 58 pre-cited certifier packs (13 curated + 45 derived from the modeled programs’ cited criteria — 611 criteria, every one cited), and a 148-program designation roster — 43 regulatory, 39 certification, 35 accreditation, 31 voluntary-excellence — that you can register, attest, and revenue-model against — breadth never dressed up as depth.

Deemed-status accreditors

The Joint Commission (deep tracer engine + mock-survey), DNV / NIAHO, HFAP, CIHQ, ACHC as alternative accreditor tracks, and CARF for behavioral and rehab programs.

CMS & federal

Conditions of Participation (42 CFR 482), the CMS-2567 Statement of Deficiencies and Plan of Correction, EMTALA, NHSN / CDC infection surveillance, MQSA mammography, and Section 1557 language access.

Pharmacy, lab & safety

DEA controlled-substance and diversion, SAMHSA OTP/MAT, 340B, USP 797/800 compounding, CLIA / CAP lab, and OSHA workplace safety.

Nursing, privacy & state scope

ANCC Magnet and shared governance, HIPAA / OCR privacy and Safe-Harbor de-identification, and an all-50-state scope-of-practice matrix.

Screenshot of the Owl 50-state scope-of-practice matrix — practice-act rules resolved per state
The 50-state scope-of-practice matrix
The Family

Charlie is the family.
Owl flies first — with Nuthatch on its wing.

Charlie is the company’s shell; Charlie Owl is the product a hospital buys first. Owl helps hospitals pass inspections by attaining continuous survey readiness — not a binder, not a pre-survey scramble, a facility that is inspectable on any given Tuesday. That is not paperwork: for a community hospital, staying inspectable is how care stays in the community, and keeping care in communities is what keeps communities healthy and resilient. Nuthatch is the second name we are ready to say out loud, because governance that only looks backwards is not governance — and we found that out by auditing ourselves. The rest of the Charlie family is waiting in the wings, built on the same spine, and named here only when each one is ready to be named. Built and gated is not shipped, and shipped is not sold. Breadth never dressed up as depth.

No Interface Engine

Owl and the care-facing family run on documents, attestations, public data, and exports a hospital already owns. Nothing there waits on an integration project to start being true, and nothing asks for a feed the hospital does not already control. Nuthatch asks for less still: a hook in the repository it watches, and no network access of any kind.

Continuous Readiness Is the Standard

Every member holds the same bar: inspectable on any given Tuesday, not readied for a date on a calendar. A score that only moves in the eight weeks before a survey is a mood, not a measurement — and ours is a prioritization aid labelled as one, never a prediction of a survey outcome.

The Firewall Is the Product

One hash-chained spine underneath, one refusal taxonomy on top of it. A surface that cannot cite its evidence does not publish, and the refusal names the policy it refused under. Every member of the family holds that shape — Nuthatch with a hash-chained ledger and refusal codes of its own, on the development floor.

Waiting in the Wings

More of the family is built and gated behind the same spine. We name each one on the day it is ready to be named, with its phase stated in the same sentence — because a roadmap read as a product is how software companies lose clinicians.

Nuthatch — Governance in the Moment

Owl proves what happened. Nuthatch is there while it happens: every write an AI coding agent attempts through its tool channel inside a clinical codebase is evaluated at the tool call and receipted to a hash-chained ledger. Twenty controls come in the starter pack and every one of them starts at “ask” — not one can deny today; each earns “deny” only by demonstrating a low false-positive rate on real evidence. We say built and gated, never coming soon. Nuthatch governs the software-development process. It makes no clinical recommendation and is not a medical device.

Why the Standard Matters

A designation is not a billing code.

It is a promise — verified by someone outside the building — that the care works when a patient arrives. That is why continuous readiness is the standard, and why a lapse costs three things at once.

Patient safety

In a large-vessel ischemic stroke, an estimated 1.9 million neurons are lost each minute the stroke goes untreated — a modeled figure for a typical such stroke, not a measured outcome (Saver, Stroke, 2006). A stroke or trauma designation is the verified promise that the clock is being beaten. Losing it is a patient-safety event first.

Community access

When a trauma center closes and a community's drive time to the nearest one rises, injured patients there had 21% higher adjusted odds of in-hospital death — associated with, not caused by, the closure (Hsia et al., J Trauma Acute Care Surg, 2014). A designation lost is specialty care the community can no longer reach.

Revenue

A Level II trauma center already spends about $2.33M a year staying ready (peer-reviewed Georgia study, PubMed 28958278) — and the designation gates the service line and the revenue that line carries. The finance story is real; it is simply the third stake, not the whole reason.

Why Now — The Record Is the Defense

Every theory in court right now
ends in the same demand: produce the record.

Clinical AI stopped being a governance exercise and became a discovery exercise. Two waves are running at once, and neither is answered by a vendor's assurance — only by what the hospital can show. We cite these as filed, not as decided.

Wave one — the payer algorithms

Suits over automated coverage denial are past the pleadings. Lokken v. UnitedHealth drew a March 2026 discovery order on the nH Predict model; in Kisting-Leung v. Cigna, the ERISA claims survived against a review averaging 1.2 seconds per file. (The $556M Kaiser settlement is a chart-review False Claims Act matter, not an AI case — we don't count it as one.)

Wave two — the scribes and the agents

Saucedo v. Sharp (Nov 2025) is the first AI-scribe class action against a health system, over 100,000+ encounters. Washington v. Sutter Health / MemorialCare (Apr 2026) plead CIPA at $5,000 per interception. Winters v. OpenAI (Jul 2026) is the first missed-diagnosis claim against an AI agent. The exposure moved from the payer to the delivery side.

Regulators ask the same question

The Texas Attorney General's Sept 2024 settlement with Pieces Technologies turned on hallucination-rate claims the vendor could not substantiate. Enforcement and litigation converge on one question: what did the model say, who decided, and can you prove it.

What has actually worked as a defense

In Lisota v. Heartland (dismissed Jan 2026), the documented operating posture was the defense — governance in practice, not a disclaimer in a contract. That is exactly what Charlie Owl produces continuously: inventory, human-in-the-loop evidence, calibration, and a hash-chained receipt for each one.

The Second Name — Charlie Nuthatch

The record is the defense.
Now the record has a second author.

Increasingly, the code that produces a hospital’s evidence is written by an AI coding agent. Nuthatch exists because we audited our own AI governance and found the prevent rung nearly empty. Detection was excellent. Prevention was one deny rule. We built the missing layer, on ourselves, first.

Nuthatch does not make bad code impossible. Nuthatch makes non-compliance immediate, attributed, and provable, and it makes bypass impossible to do silently.

For your engineers

A governance harness that hangs off the coding agent’s own tool-call boundary and writes one hash-chained receipt per attempt: what was asked for, which control matched, who the actor was, what the verdict was. Deterministic rules decide the verdict; a model only drafts the human-readable explanation. Three modes, set by one readable file — shadow measures and emits nothing, teach turns each finding into an approvable prompt, enforce acts with a citable reason — and the same controls do the evaluating in all three, so a shadow row and an enforce row are the same measurement with only the verdict gated. The default is shadow, and every control starts at “ask” — not one can deny today; each earns “deny” only on demonstrated evidence. Claude Code today; other agent transports are roadmap.

For your survey binder

What the harness produces is an artifact a non-engineer reads: an attestation packet naming the controls that were in force and the signature state of the pack they came from, the receipt totals, whether the chain and its signed tree heads verify, and every break-glass event rendered individually with its named actor and its stated reason — closing with a methodology section that states its own limits, including that observations are not blocks and that this is evidence for conformance, never a compliance certification. It is designed so that an independent auditor holding only a public verification key can re-check a packet offline, with a separate, dependency-free verifier — and the starter pack is unsigned today, which every packet discloses. Both are built; publication is roadmap, not shipped.

Bypass is possible and we say so. Every bypass emits a coded event, and every break in the chain is enumerated. And Nuthatch does not judge clinical content: dose-gate’s epistemic claim is “this constant came from the registry,” not “this constant is correct.” Nuthatch receipts are designed to register as an Owl evidence source, so the governance file a hospital hands a surveyor covers both the algorithms that touch patients and the agents that touch the code. See how Nuthatch works → · The developer page →

The Trust Gap

Clinicians are using AI they don’t trust.
Owl is how trust gets built.

Nurse AI use nearly tripled in a year — 15% to 44% — while trust stayed flat. The surveys agree on why, and on what fixes it: consultation, citations, validation over time, and an override that is honored. Those are not features we bolted on; they are the architecture.

60%
Of RNs do not trust their employer to deploy AI with patient safety as the first priority
2,300+ U.S. RNs, National Nurses United AI survey, fielded Jan–Mar 2024
83%
Of nurses say AI output is rarely or only sometimes accurate enough to act on without checking
2,240 U.S. nurses, Incredible Health State of Nursing Report, July 2026
74% vs 38%
Trust in AI tools among nurses consulted on their selection — versus nurses never consulted
Same 2026 survey; only 8% say frontline staff is always included in AI selection
>60%
Of clinicians say transparent citations to peer-reviewed evidence would increase their trust in AI
2,757 clinicians across 118 countries, Elsevier Clinician of the Future, 2026

Consultation doubles trust, and almost no one does it — we are structurally the exception, because the frontline runs the company. Every Owl answer carries its citation; validation is continuous, not launch-day; and the clinician can always overrule the model — with the override recorded, never punished. Trust is not a campaign here. It is what the receipts are for.

For CISOs & Quality Officers

The security review is short,
because the answers are architectural.

Security reviews ask the same three questions: where does the model run, what happens to our data, and what does the system do when it is not sure. Here is the posture, stated the way we would state it to your review board rather than the way it would read on a datasheet.

No cloud AI by default

Inference runs on-premise. The cloud seams ship dark by default and open only as a BAA-attested opt-in you turn on deliberately — so no cloud model sits in a clinical or compliance decision path unless you put it there.

A tamper-evident audit spine

Decisions are written to a hash-chained log designed to be tamper-evident: an edit or a deletion breaks the chain, and the break is detectable. The completeness verifier itself is exercised in our CI on every push.

Worker data has a floor

Rollups of worker data hold a k ≥ 5 anonymity floor — small cohorts are suppressed, never fudged — and use of that data for discipline is refused by code, not discouraged by policy language. Watch the floor hold →

Gates fail closed

Where a gate cannot establish that an action is permitted, it refuses. Unknown is never treated as authorized, and the refusal returns a machine-readable code naming the policy it refused under.

Weak config will not boot

Boot-time validators refuse to start the application on missing, weak, or development-default security configuration. A misconfigured deployment fails loudly at startup instead of running quietly without its guarantees.

The commercial shape is as unremarkable as the security posture: a five-figure annual per-facility license, priced to land under the typical $100K board-approval line, running on the exports and documents your hospital already owns. An operating expense your team can approve — not a capital project with an integration queue behind it.

Who Built It

Built by clinicians
who hold the license.

Nightingale OS was founded by a 20-year ER, Flight, and Trauma Nursing veteran who spent two decades running hospital trauma and accreditation programs — and who sat inside the surveys that decide designations, including two CDPH survey visits where her own performance was material to the plan of correction. Continuous survey readiness is not a category she read about. It is the work she did, on the days it counted. That is the moat, stated plainly: you cannot hire your way to this domain judgment — not the incumbents, not a well-funded copy, no one.

She is a primary contributing author across the Emergency Nurses Association’s trauma curricula — the Trauma Nursing Core Course provider manual (8th ed.), the ENA Advanced Course on Trauma, and the Emergency Nursing Core Curriculum (8th ed.) — the national courses emergency and trauma nurses train and certify through. A former Stanford educator, she taught herself to build by directing AI coding agents inside a governance harness she authored — the same discipline the product sells, applied to our own codebase first. The equity model follows the same logic: the profession that carries the accountability holds the ownership. Nurse-owned is a structural fact here, not a tagline.

Her writing on the systems that fail clinicians runs from the ENA’s national curricula to peer-reviewed journals to the Bulletin of the Atomic Scientists and KevinMD, and she has been the subject of a ProPublica investigation and PBS NewsHour reporting for going on the record when it counted — the full record is on the company page, or connect with her on LinkedIn.

The Mission

Nurse-led. Nurse-driven. Nurse-owned.

"I was waiting for someone to save us, and I realized that person would have to be me."

Kristen Cline, RN, Founder & CEO, Nightingale OS

Nurse-led

Founded and run by a bedside trauma-informed RN. Clinical judgment sets the product direction — engineering serves it, not the other way around. The asymmetry is structural: the clinician answers to a licensing board, and the vendor whose model she followed holds no license at all.

Nurse-driven

Nurses are the product's engine, not its users. Named clinicians attest every piece of evidence; registrars and quality nurses are amplified, never replaced — the standards require humans, and so do we.

Nurse-owned

The profession that carries the accountability keeps the equity. We hire from the bedside diaspora and build the careers nursing comes next — starting with the AI safety officer.

Nurse as the integration layer

Nurses are the human API of a hospital — crossing six to twelve systems in a single shift to make one plan of care hold. KLAS finds 12% of nurses rate their EHR “Elite,” against 22% of physicians. The people doing the integrating are the least served by the tools, and they are the buyer: we sell nurse to nurse.

Who It's For

Built for the office that
answers the surveyor.

Trauma & Stroke Program Managers

You carry the designation on your back — the criteria grid, the education hours, the registry deadlines, the verification visit. Charlie Owl is the program in one place, always current, always attested.

Quality, Accreditation & Compliance Officers

Continuous readiness instead of survey-season panic: tracers, mock surveys, plan-of-correction gating, policy evidence, and the AI governance file your committee — and increasingly your counsel — keeps asking about, with receipts a surveyor or a court can verify.

Community Hospitals, 100–400 Beds

The hospitals doing this work without a department to do it — where one person holds three of these jobs and the binder is the system. No EHR integration project, no vendor permission. Your exports in, your evidence out, the first week.

The Owl Digital Pilot

We replay your designation
portfolio digitally.

Revenue-at-risk per designation from public data, a scored mock-survey drill of your own tracer walk, the registrar workload your case volume actually costs, and your AI-algorithm inventory — built from documents and exports you already own. No EHR integration required.

$2.33M
Annual readiness spend, Level II trauma (peer-reviewed)
$25K–$151K
Mock-survey consulting, site to network (federal POs)
~39 min
Registrar abstraction per trauma case (peer-reviewed)
Explore the Digital Pilot
Revenue at Risk per designation
Survey Replay scored drill
Registrar Model 39 min/case
AI Inventory bootstrap
Four receipts, from data you already have — public figures cited, modeled estimates labeled. Methodology
Team & Advisors

Built by nurses.
Backed by engineers.

Founder & CEO

Kristen Cline, RN

Bedside trauma-informed RN and former trauma program manager. Built the platform to production conventions by directing AI coding agents against a written constitution she authored. The governance architecture, clinical judgment, and domain insight are hers.

Nurse Scientist / Clinical Research Lead

Dr. Lisa Wolf, PhD, RN

Tenured nursing faculty and emergency nursing researcher; led the Emergency Nurses Association’s nursing research institute. Owns the validation agenda — abstraction-accuracy studies, calibration methodology, peer-reviewed evidence. Committed; joins on funding.

Security Advisor

Luke Burton

Seventeen years on Apple’s Security and Engineering team; currently a senior security engineer at a leading AI-computing company. Advises the hardening path from prototype to production against a written briefing and an openly maintained risk register.

Legal Nurse Consultant

Cheryl Randolph, FNP

Reads hospital evidence the way opposing counsel will. Charlie Owl’s receipts exist to survive exactly that reading — an Immediate Jeopardy defense, a designation contest, a deposition — and Cheryl is that lens on every evidence pack the product produces.

Equity & Innovation Consultant

Sarah Wells, CNL

Founder of New Thing Nurse and architect of the federated equity model — the structure by which nurse collaborators earn real ownership in the products they design, and the pipeline into the nursing innovation community.

See Charlie Owl on your own compliance calendar.

We are seeking design partners — any hospital standing up AI governance, and community hospitals defending trauma, stroke, or specialty designations. No integration project required: the first receipts come from data you already have.

Or email directly: info@nightingaleos.com · kristen@nightingaleos.com