Put an LLM in your product without putting PHI in someone else's logs.
Healthcare teams don't have an AI problem. They have a PHI-boundary problem. We design and build the boundary — then ship the feature through it.
The five questions your security review will ask
- 01
Where does PHI physically go?
Every call to a model endpoint is a data transfer. We map every path PHI can take before writing code — and design so most paths don't exist.
- 02
Will the vendor sign a BAA?
Not every model provider will, and not on every endpoint. We architect against BAA-eligible infrastructure and document which components are covered by which agreement.
- 03
What's in your prompt logs?
Prompt and completion logging is the most commonly missed PHI leak in healthcare AI. Observability that captures raw prompts is a breach surface. We log for debuggability without retaining protected data.
- 04
What does the model do when it's wrong?
In clinical and claims contexts, a confident wrong answer is the risk. We build escalation paths, confidence gating, and human review into the workflow — not bolted on after.
- 05
Can you prove any of this six months from now?
Audit trails, access controls, and documented data flows — produced during the build, not reconstructed during the audit.
The boundary, component by component
Redaction & de-identification
At the boundary, before inference — not as a post-processing hope.
Scoped retrieval
RAG that can only reach records the requesting user is authorized to see.
Model routing
Sensitive paths to BAA-covered endpoints; non-sensitive paths optimized for cost.
PHI-stripped logging
Debuggable observability that is not a breach surface.
Human-in-the-loop
Escalation and confidence gating for clinical and claims decisions.
Reviewer-ready documentation
Data-flow diagrams you hand to the security reviewer, produced as we build.
Providers
Clinical documentation, intake, care coordination, patient-facing assistants grounded in real records.
Dental & specialty practices
Practice workflow, treatment-planning support, insurance verification and billing automation.
Payers & insurtech
Claims intake and analytics, prior-authorization support, care-plan matching, member-facing tools.
Device & remote monitoring
Signal interpretation, alerting, and escalation for wearables and connected devices.
Architecture Review
Two to three weeks, fixed fee. We audit your planned or existing AI implementation against the five questions and hand you a remediation plan.
Build
We design and ship the AI feature — PHI-safe from the first commit, documented for the review.
HIPAA + AI, answered plainly
Can you use Claude or GPT with PHI?
Yes — with the right architecture. Major providers offer BAA-eligible enterprise endpoints, but eligibility varies by tier and endpoint. The architecture must also control what enters prompts, what's logged, and what's retained. We design so PHI is redacted or scoped before inference and never lands in provider or observability logs.
Do LLM providers sign a BAA?
Some do, on specific enterprise offerings — not on every endpoint or consumer tier. We architect against BAA-covered infrastructure only, and document exactly which components of your stack are covered by which agreement.
What usually fails a healthcare AI security review?
Raw prompts containing PHI in observability logs. RAG pipelines that retrieve records the requesting user isn't authorized to see. Calls to non-BAA endpoints. No documented data-flow diagram. All four are architectural, and all four are preventable.
How long does a PHI-safe AI build take?
The architecture review takes two to three weeks. Build timelines depend on scope — but the compliance layer costs far less time designed in from the first commit than retrofitted after a failed review.
Bring us the architecture. We'll tell you what fails.
Thirty minutes, no pitch, no deck.
Book a 30-minute call