Healthcare: Healthcare AI Compliance & Risk

Healthcare AI that passes legal, security, and clinical review.

HIPAA compliant, SOC 2 Type II, on prem/VPC deployment, PHI de identification, and full provenance: so your AI clears compliance instead of dying in it.

HIPAASOC 2 Type IIFHIR R4/R5Surescripts AuthorizedSNOMED CT

The short answer

Is AI in healthcare HIPAA compliant, and what is PHI vs PII?

AI in healthcare can be HIPAA compliant: compliance is a property of how the system is built and operated, not of the model itself. PII (personally identifiable information) is any data that identifies a person; PHI (protected health information) is the subset of PII tied to health, treatment, or payment, and it's what HIPAA regulates. A compliant clinical AI keeps PHI inside covered infrastructure (VPC or on prem), runs under a Business Associate Agreement (BAA) with access controls, encryption, and audit logging, and de identifies data before any component that sits outside that boundary.

What we build

Healthcare AI Compliance & Risk, engineered on your data.

HIPAA & BAA

BAA covered components, property level access controls, encryption in transit and at rest, and full query audit logging.

HIPAABAA

SOC 2 Type II

Independently audited controls across security, availability, and confidentiality for the platform.

SOC 2 Type II

On prem & VPC LLMs

Open weight models (Llama, Mistral) deployed in your VPC or on prem GPUs so PHI never leaves your infrastructure.

On-premPrivate AI

PHI de identification

Safe Harbor and Expert Determination de identification so only de identified context is ever sent to any external component.

De-identification

HITRUST & data residency

Architecture and evidence packs against the HITRUST CSF, with region locked or on prem deployment for data residency requirements.

HITRUSTResidency

Cures Act & FDA awareness

Designs aligned to 21st Century Cures Act information blocking rules and informed by FDA AI/ML (SaMD) guidance for clinical software.

Cures ActFDA AI/ML

FAQ

Healthcare AI Compliance & Risk: frequently asked questions.

What is a Business Associate Agreement (BAA)?

A BAA is the contract HIPAA requires between a covered entity (like a provider or payer) and any vendor that handles PHI on its behalf. It binds the vendor to safeguard PHI, limits how it can be used, and defines breach responsibilities. We sign BAAs for the components that touch PHI.

How do you keep an LLM HIPAA compliant?

The reliable path is to keep PHI inside your boundary: run open weight models in your VPC or on prem so prompts and data never leave, with access controls, encryption, and audit logging. When a public API is genuinely needed, we use zero retention agreements and send only de identified context through a PHI de identification layer.

What is PHI de identification (Safe Harbor vs Expert Determination)?

De identification removes the link between data and a person so HIPAA no longer applies. Safe Harbor removes 18 specified identifiers; Expert Determination uses a qualified statistician to certify re identification risk is very small, which can retain more analytic value. We apply whichever fits the use case before data crosses a trust boundary.

Does the FDA regulate healthcare AI?

It can. Software that diagnoses, treats, or drives clinical decisions may be regulated as Software as a Medical Device (SaMD), and the FDA has specific guidance for AI/ML based devices. Most grounded decision support and documentation tools are designed to keep a clinician in the loop; where a use case approaches SaMD, we design to the applicable guidance and scope the regulatory path explicitly.

Explore the healthcare stack

Related healthcare capabilities.

Ready to build healthcare ai compliance & risk on grounded, compliant AI?

A 6 week pilot with one use case, fixed scope, and outcomes guaranteed in writing: hit the target or the pilot is free.