Every clinical AI action attributed to a human clinician, every PHI touch redacted at the perimeter, every decision signed for the auditor.
PHI moves unredacted from patient to intake bot to specialist agent to model. No consent, no attribution. HITECH breach notification is just a matter of time.
PHI gets redacted at the perimeter. A clinician signs off on every action that touches a patient record. The chain is signed for 25 years.
“When an AI touches PHI, a clinician takes responsibility. Or the action doesn’t ship.”
HIPAA doesn’t care that your model is state-of-the-art. It cares who authorized the PHI touch, what got redacted, and whether the chain of custody survives a subpoena. Three of Veldt’s pillars carry that weight.
Before any tool call, prompt, or model context ships out, PHI fields are redacted at the perimeter. Names, MRNs, DOB, addresses: redacted or tokenized. The model sees a de-identified surface. The chain remembers the mapping.
Runtime Governance →A clinical AI can suggest. It cannot decide. Every clinical action that hits a patient chart carries a required attestation from a licensed clinician. The chain shows the clinician, the timestamp, and the exact suggestion they signed off on.
Authority →Every PHI access is a signed block: which patient, which principal, which purpose, which clinician attested. Retention runs 25 years, past the HIPAA six-year floor. When the OCR knocks, the chain answers.
Evidence →ED triage, radiology, ambient scribing, cross-hospital referral, prior auth. Every one of them puts an AI on the clinical side of the line. Every one of them needs a clinician to own the outcome.
An AI triage model assigns severity scores at intake. If it under-triages, a patient walks out with an untreated MI. If the model acts without a clinician sign-off, the hospital owns the outcome and there’s no chain to show due care.
The AI proposes. An ED clinician attests. The chain shows: model version, input features, clinician sign-off, final severity assignment. Malpractice defense starts with the signed block, not with a chart note.
Clinician owns the call.A radiology AI flags a suspicious lesion. If the finding shows up in the final read without an attending attribution, the AI’s output becomes the diagnosis, and no human is on the hook when it’s wrong.
The AI’s output is a suggestion attached to the study. The attending radiologist attests to accept or reject. The chain records model version, image hash, attending signature, and the final read.
Attending owns the read.An ambient scribe listens to a visit and generates a note. Without explicit consent tracking, the recording is a HIPAA breach in waiting. Without a clinician attestation, the note becomes fabricated history.
Patient consent is captured as a signed principal event. The scribe’s output is a draft. The clinician reviews and attests. The chain shows consent, transcript hash, note version, and clinician signature.
Consent · captured · signed.A clinical AI needs to pull labs from a referral hospital’s EHR. Each hospital’s SSO is different. Federation projects run quarters. And when the transit happens, no one signs off on the PHI hop.
The AI carries a portable, signed credential. Any hospital in the network verifies it in one round trip. The referring clinician attests to the referral. The PHI hop is signed and retained.
One credential · every EHR.An AI generates a prior-auth request. If the payer denies, the appeal needs the clinical rationale, the clinician who authored it, and the model’s inputs. Without a chain, appeals fail on procedural grounds.
The prior-auth is a signed chain: clinical rationale, model version, clinician attestation, submitted request. The appeal packet is generated from the chain. The payer verifies the signatures offline.
Appeal · defensible.Bring a real clinical workflow: an ED triage model, a radiology AI, an ambient scribe. Thirty minutes: see perimeter PHI redaction, human-in-loop enforcement, and the signed chain built for the OCR.
Book a demo → Read the Runtime Governance docs