Sherri Douville

CEO & Architect, Medigram | Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)

Sherri Douville is CEO of Medigram, where she directs the architecture of Darwin, the platform and agentic fleet that run in production as the reference implementation of IEEE/UL 2933:2024, independently verified at the highest recorded behavioral score. She works from policy to code: the standards she helps author run in production as Darwin's verified operating controls.

She is founder and chair of the Trustworthy Technology & Innovation Consortium (TTIC), co-chairs the IEEE/UL 2933 Trust and Identity Subgroup, serves on the working group's maturity model committee, and led the TTIC contribution to the authorship of the Hospital AI Operations Governance Standard, ANSI/HSI 2800:2025. She is a six-time published author and series editor with Taylor & Francis, with a forthcoming volume on AI and cybersecurity for healthcare boards. She chaired the High-Reliability AI Track at AIMed 2025, received the 2025 AIMed AI Champion Award, chairs the High-Reliability Agentic AI Track at AIMed 2026, and builds the field's multi-domain talent network through TTIC and Medigram.

Before Medigram, she spent more than a decade at Johnson & Johnson across more than a dozen disease areas, where she won a number of sales awards. She holds a Combined Sciences degree from Santa Clara University, studied machine learning and AI through MIT coursework, and has held Series 7 and Series 66 securities licenses.

Origin Story

"Not the oracle who merely predicts the future. The architect who helps shape it and builds the infrastructure needed to protect it."

Predict → Shape → Protect

Sherri Douville's career has evolved from predicting technological and organizational change, to shaping it, trusted to build the ecosystem and leadership bench that helps protect the future being built (across domains and industries).

Read the full story

Sherri Douville

Early in her career, Sherri Douville developed an ability to see technological, organizational, and market change before its implications became obvious. But predicting the future eventually became insufficient. Being right about what was coming did not protect anyone from what happened next.

Her work shifted from asking what would happen to asking what should happen and how to make it real. Across healthcare, technology, standards, business, and governance, she repeatedly encountered important ideas that struggled at the implementation boundary. The difficult work was everything downstream: architecture, operations, security, organizational alignment, adoption, accountability, verification, and execution.

As AI became more capable, autonomous, interconnected, and consequential, the mission evolved again. Sherri's work moved from predicting the future, to helping shape it, to building the trust infrastructure needed to protect the people and institutions depending on it.

What moved Sherri Douville toward this work was not a technology. It was a pattern she could not stop seeing: how often preventable harm traces back to information that arrived too late, or reached the wrong person, or arrived after the moment had passed.

She joined Medigram to close that gap at the point of care. The work since has followed the same problem as it changed shape. When the obstacle was distance, the answer was mobile. When the obstacle became systems nobody could account for, the answer became standards.

The practice is being encoded rather than held. Two talent networks carry it, one through the Trustworthy Technology & Innovation Consortium and one through Medigram, and the instruments that formalize the method are built to be operated by people other than their author.

Trust is the price of entry

Trust is the price of entry in medicine. Without it there is no access, and it cannot be bought or carried in from another industry.

So the question was never how to convince physicians. It was how medicine already decides what to trust.

It decides through its literature and through accreditation. Both are procedures. Neither certifies that a conclusion is correct.

The literature

A practice becomes standard when it is written down, cited, and taught. Physicians are trained to ask what the evidence is before they ask who is speaking, which makes the literature one of the few doors into medicine's conversation that does not require a license to practice through it.

Six books carry her work. She edited Mobile Medicine and Advanced Health Technology, and contributed to four more across Taylor & Francis, Springer, and Artech House, including a Springer volume on TIPPSS, the framework at the center of IEEE/UL 2933:2024. Each of the two she edited required the CIO, the CISO, the physician, the engineer, the lawyer, and the executive to agree on what is true, in one volume, with their names on it. That record in medicine's own literature is what turned an interest in AIMed into an invitation to contribute to it.

She now edits the Taylor & Francis series they began, which means the work is no longer only hers to write.

Accreditation

Every physician's continuing education is accredited, and that accreditation does not check whether the teaching is correct. It checks how it was made: who was in the room, what their interests were, how disagreements were settled, who could object. Doctors trust the result because they trust the machinery.

Standards run on the same machinery. That is why she took the standards leadership. Not as a credential, but as the shortest route into a market that does not open for anything else.

What that leadership consists of is specific.

She co-chairs the Trust and Identity Subgroup for IEEE/UL 2933:2024 and serves on the working group's maturity model committee. The standard governs what clinical data and connected devices must carry about themselves as they move between systems, so that trust, identity, privacy, protection, safety, and security travel with the data rather than resting on each institution's own paperwork.

She led TTIC's contribution to the authorship of ANSI/HSI 2800:2025, Artificial Intelligence Governance in Healthcare Operations. It addresses the other half of the problem: how a health system governs AI across its own operations. Ultimate responsibility sits with the board, accountability for execution sits with the chief executive, and the scope runs the full lifecycle from procurement and development through deployment and monitoring. It also holds that clinicians retain ultimate control over patient care decisions.

A note for technical colleagues, on what it means to build and earn trust in medicine

Most engineers already build on IEEE standards daily without thinking about it. 802.11 for wireless, 754 for floating point, 1588 for time synchronization. Nobody argues about whether wireless should have a standard, because the alternative is obvious: nothing interoperates and nothing can be relied on.

Medicine adds one requirement on top of that. When software is wrong in most domains, the cost is a defect report. In clinical care the cost can be a person, and someone will later be asked to account for what happened. That moves the bar from whether it works to whether you can show how it works, who authorized it, and what it was tested on.

Accreditation is the machinery that makes that showable. It does not certify that an answer is correct. It certifies that the process producing it was balanced, disclosed, and documented, and that someone could object. That is the same reason accredited continuing medical education carries weight with physicians, and it is why standards are the currency of trust in this market rather than benchmarks or demos.

IEEE/UL 2933 applies that to clinical AI data. Its TIPPSS framework, covering trust, identity, privacy, protection, safety, and security, is the contract that lets systems built by different teams be relied on together. It is the same organization doing the same job it did for wireless, in a domain where being wrong has a different cost.

A note for colleagues in research: this is the same model you already trust

Standards development and accredited continuing medical education are both process-accreditation regimes. Neither adjudicates whether a conclusion is correct. Both impose requirements on how it was reached: balance of interests among participants, disclosure, defined consensus thresholds, documented due process, and a route of appeal. ANSI accredits standards developers on those grounds. ACCME accredits CME providers on grounds that closely parallel them.

Peer review belongs to the same family. A finding carries warrant because of the procedure that produced it, not because a reviewer reproduced the result. All three locate trustworthiness in procedure. They differ mainly in which procedure they recognize.

Which is also why standards work is nearly invisible to academic instruments. IEEE/UL 2933 and ANSI/HSI 2800 carry document numbers rather than DOIs, accumulate no citations, and give no outward sign that a single clause took three years to settle. The two fields reward opposite things: scholarship rewards novelty, standards reward durability, and a novel standard is usually a bad one. The review is not lighter for it. Consensus has to satisfy competitors who would prefer the clause did not exist, implementers who have to build it, and counsel who will read it back in a dispute.

There is now a substantial literature on AI governance that does not cite the documents that actually govern. Two communities working the same problem, with almost no contact surface. The Taylor & Francis series she edits exists in part to build one. It began with Mobile Medicine and Advanced Health Technology.

Roles and relationships

Sherri Douville holds two roles by design: Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC), the standards body, and CEO of Medigram, a company that implements the standards. TTIC writes the requirement; Medigram implements it. They are separate organizations with a deliberate firewall between them: TTIC does not endorse, attest, or certify Medigram, holds no commercial interest in it, and no sponsorship or consortium revenue flows to Medigram. Verification of Medigram's platform behavior is performed by third parties with no commercial stake in Medigram. The practice is built to transcend any one person: the standards are published, the methods are documented, and the work runs as verified operating controls in production. TTIC's own relationship disclosure and continuity page states the boundary directly.