Solutions · Healthcare

Clinical AI.
PHI-safe. HIPAA-clean.

Every clinical AI action attributed to a human clinician, every PHI touch redacted at the perimeter, every decision signed for the auditor.

HIPAA
BAA available
Perimeter redaction
PHI never leaves
Human-in-loop
Every clinical decision
Every action
Attributed to a clinician
What “HIPAA-safe clinical AI” actually means

AI that touches PHI without consent, redaction, and attribution
isn’t compliant. It’s a lawsuit.

Untethered clinical AI
PHI flows. Nobody signs off.
Patient
PHI
Agent A
PHI
Agent B
PHI
Model
PHI

PHI moves unredacted from patient to intake bot to specialist agent to model. No consent, no attribution. HITECH breach notification is just a matter of time.

Governed clinical AI
PHI redacted. Human attests. Chain signed.
Patient
Redact
Model
Human-in-loop
Signed chain · 25y

PHI gets redacted at the perimeter. A clinician signs off on every action that touches a patient record. The chain is signed for 25 years.

“When an AI touches PHI, a clinician takes responsibility. Or the action doesn’t ship.”

HIPAA · HITECH · GDPR-Health · 21st Century Cures
How Veldt maps to Healthcare

Three pillars. One compliant clinical AI.

HIPAA doesn’t care that your model is state-of-the-art. It cares who authorized the PHI touch, what got redacted, and whether the chain of custody survives a subpoena. Three of Veldt’s pillars carry that weight.

01 · Runtime Governance

Perimeter redaction of PHI before dispatch

Before any tool call, prompt, or model context ships out, PHI fields are redacted at the perimeter. Names, MRNs, DOB, addresses: redacted or tokenized. The model sees a de-identified surface. The chain remembers the mapping.

Runtime Governance →
02 · Authority

Human-in-loop required for every clinical decision

A clinical AI can suggest. It cannot decide. Every clinical action that hits a patient chart carries a required attestation from a licensed clinician. The chain shows the clinician, the timestamp, and the exact suggestion they signed off on.

Authority →
03 · Evidence

Signed chain for every PHI touch, 25 years

Every PHI access is a signed block: which patient, which principal, which purpose, which clinician attested. Retention runs 25 years, past the HIPAA six-year floor. When the OCR knocks, the chain answers.

Evidence →
Real scenarios

Five clinical workflows. One safety surface.

ED triage, radiology, ambient scribing, cross-hospital referral, prior auth. Every one of them puts an AI on the clinical side of the line. Every one of them needs a clinician to own the outcome.

Emergency Department
Human-in-loop

AI triage in the ED

The problem

An AI triage model assigns severity scores at intake. If it under-triages, a patient walks out with an untreated MI. If the model acts without a clinician sign-off, the hospital owns the outcome and there’s no chain to show due care.

With Veldt

The AI proposes. An ED clinician attests. The chain shows: model version, input features, clinician sign-off, final severity assignment. Malpractice defense starts with the signed block, not with a chart note.

Clinician owns the call.
Radiology
Attending attributed

Radiology AI

The problem

A radiology AI flags a suspicious lesion. If the finding shows up in the final read without an attending attribution, the AI’s output becomes the diagnosis, and no human is on the hook when it’s wrong.

With Veldt

The AI’s output is a suggestion attached to the study. The attending radiologist attests to accept or reject. The chain records model version, image hash, attending signature, and the final read.

Attending owns the read.
Ambient scribe
Patient consent

Ambient scribe in the exam room

The problem

An ambient scribe listens to a visit and generates a note. Without explicit consent tracking, the recording is a HIPAA breach in waiting. Without a clinician attestation, the note becomes fabricated history.

With Veldt

Patient consent is captured as a signed principal event. The scribe’s output is a draft. The clinician reviews and attests. The chain shows consent, transcript hash, note version, and clinician signature.

Consent · captured · signed.
Cross-hospital referral
Identity portability

Cross-hospital referral

The problem

A clinical AI needs to pull labs from a referral hospital’s EHR. Each hospital’s SSO is different. Federation projects run quarters. And when the transit happens, no one signs off on the PHI hop.

With Veldt

The AI carries a portable, signed credential. Any hospital in the network verifies it in one round trip. The referring clinician attests to the referral. The PHI hop is signed and retained.

One credential · every EHR.
Prior authorization
Appeal-ready

Insurance prior authorization

The problem

An AI generates a prior-auth request. If the payer denies, the appeal needs the clinical rationale, the clinician who authored it, and the model’s inputs. Without a chain, appeals fail on procedural grounds.

With Veldt

The prior-auth is a signed chain: clinical rationale, model version, clinician attestation, submitted request. The appeal packet is generated from the chain. The payer verifies the signatures offline.

Appeal · defensible.

Bring the clinician into the loop.

Bring a real clinical workflow: an ED triage model, a radiology AI, an ambient scribe. Thirty minutes: see perimeter PHI redaction, human-in-loop enforcement, and the signed chain built for the OCR.

Book a demo → Read the Runtime Governance docs