Safety guardrails in patient-facing large language model systems for chronic disease self-management: a realist review.

Zhao, Yuhan; Miao, Yiqun; Luo, Yuan; Guo, Rongrong; Wang, Huiying; Wu, Ying · Int J Med Inform · 2026

systematic_review · Level I

Where this comes from

Abstract

Patient-facing large language model (LLM) systems are increasingly proposed as scalable tools for chronic disease self-management support. In this setting, safety depends not only on factual accuracy but also on whether outputs are interpretable, trusted, and used safely over time. To explain how safety guardrails shape outcomes in patient-facing LLM-supported self-management across different task-risk, user, and interaction contexts. We conducted a realist review of LLM-based or LLM-enabled generative conversational systems used for self-management of long-term physical health conditions. Searches of PubMed, Web of Science Core Collection, IEEE Xplore, ACM Digital Library, and arXiv covered all indexed years to 1 April 2026 and used terms for chronic disease or self-management, patient-facing conversational systems, and LLMs or generative AI, identifying 1,154 records before deduplication. The core evidence base comprised 21 studies and 38 context-mechanism-outcome configurations (CMOCs). The patient-facing self-management task, rather than disease label, was the unit of synthesis. At the study level, the dominant patient-facing task was coded as low risk in 6 studies, moderate risk in 11, and high risk in 4; 17 studies evaluated mainly single-turn interactions and 4 included multi-turn, sequential, or simulated-consultation elements. Most evidence concerned simulated or expert-judged patient-facing tasks rather than sustained real-world deployment. Three patterns recurred. Provenance-related safeguards improved transparency and checkability more consistently than they ensured safe downstream action. Communication-oriented safeguards improved readability or perceived comprehensibility while leaving recurring gaps in completeness or actionability. Boundary-control strategies, including source-bounded retrieval, clinician deferral, and escalation support, became more important as task actionability and interaction complexity increased. In patient-facing chronic disease self-management, safety cannot be judged adequately by answer plausibility alone. This review develops a refined programme theory and a risk-linked, theory-generating heuristic framework, but many proposed mechanisms remain indirect and require real-world, longitudinal, multi-turn testing before deployment.