HIPAA compliant AI agents

HIPAA compliant AI agents, by mechanism, not by promise

Ambient scribes, chart summarizers, and billing agents are new PHI boundaries — and the HIPAA Security Rule NPRM pulls every one of them into mandatory risk analysis. DataShield gives agents tokenized data instead of identifiers: datasets tokenized at ingest, agents query over MCP, detokenization is a privileged, audited operation.

Healthcare breaches average $7.42M and 279 days to resolve (IBM 2025). The control isn't a promise in a BAA — it's a mechanism you can verify.

PHI-safe agent data flow EHR data is tokenized at ingest; agents query tokens over MCP; every access is sealed into a hash-chained audit log. EHR / clinical systems MRN 4471 → TOK_9f2a… Tokenize at ingest Tokenized dataset scope ≤ ceiling tool call Scribe / triage agent HIPAA §164.312(b) Security Rule NPRM Minimum necessary EVIDENCE LANE Ed25519 checkpoint verify_chain → VALID signed checkpoints — deletion detectable

PHI de-identification for LLM agents: the three failure points, closed

Agents see PHI they don't need

The minimum-necessary standard applies per agent, per handoff. DataShield classifies fields at ingest (NAME, DOB, MRN, and the rest) and replaces identifiers with deterministic, join-preserving tokens — agents get answers, not identifiers. Quasi-identifiers are generalized to k-anonymity so tokenized rows can't be re-identified by combination. See Ontology.

No proof of who accessed what

HIPAA §164.312(b) requires audit controls over ePHI activity. Every governed tool call is scoped, metered, attributed to agent identity, and sealed into a SHA-256 hash chain with Ed25519-signed checkpoints — verification distinguishes tampering, insertion, deletion, and truncation. Try it on a sample log.

Re-identification is all-or-nothing

One-way redaction destroys clinical utility. DataShield tokenization is vault-reversible under policy: a billing workflow that legitimately needs the identifier gets it through a privileged, logged detokenization — and erasure is crypto-shred, which survives in the audit chain. Details in Security.

The HIPAA Security Rule NPRM puts AI tools in your risk analysis

The proposed Security Rule update explicitly requires AI tools touching ePHI to appear in risk analysis: what type and amount of ePHI, disclosed to whom, output going where. OCR's risk-analysis enforcement initiative runs into 2026, with penalties up to $73,011 per violation and $2.19M annual caps. And the first healthcare GenAI enforcement has already happened — Texas AG v. Pieces Technologies, over hospitals feeding live patient data to a GenAI summarizer.

No law bans PHI near an LLM outright. The requirements are risk analysis, minimum-necessary access, BAAs, and auditability — which is exactly what an at-ingest de-identifying data plane plus hash-chained audit evidence provides.

"Our LLM vendor has a BAA" is not a control. A BAA allocates liability for one vendor node. It doesn't cover pipeline entry, application logging, or agent tool-chaining — the places the 2025 MCP incidents actually happened. DataShield deploys self-hosted or in your VPC, with your keys; a BAA conversation is welcome. Read the architecture.

The regulatory cost of AI over ePHI HIPAA penalties reach $73,011 per violation and a $2.19M annual cap. The average healthcare breach is $7.42M and takes 279 days to resolve (IBM 2025). Enforcement is already happening (Texas AG v. Pieces Technologies), and the HIPAA Security Rule NPRM puts AI tools that touch ePHI into mandatory risk analysis. THE COST OF GETTING THIS WRONG $2.19M annual HIPAA penalty cap up to $73,011 per violation · OCR $7.42M average healthcare breach 279 days to identify and contain · IBM 2025 Enforcement is already here Texas AG v. Pieces Technologies — GenAI over patient data Your AI tools are in the risk analysis HIPAA Security Rule NPRM — type, amount, and flow of ePHI Priced in now as a control — or paid later as a finding.

HIPAA and AI agents: buyer questions

Does DataShield make our ambient scribe or chatbot HIPAA compliant?

No product makes you compliant by itself — compliance is your program. DataShield supplies the technical safeguards that program needs: at-ingest PHI tokenization and k-anonymity generalization (Ontology), per-tool-call authorization with mid-session revocation (Auth), and tamper-evident audit logs designed to map to §164.312(b).

Does DataShield intercept prompts to strip PHI in real time?

No. Tokenization happens at ingest, per dataset — not by inline traffic interception. Agents query already-tokenized data over MCP, so identifiers never enter the query path. Detokenization is a separate privileged, audited vault operation.

Can we still join patient records after de-identification?

Yes. Tokens are deterministic and join-preserving — the same MRN always maps to the same token, so joins across datasets work while the identifier stays out of the query path. Quasi-identifiers are generalized to a configured k to block combination re-identification.

How do we handle a patient erasure request if data is tokenized?

Erasure is crypto-shred: destroy the key material and the tokens become irrecoverable, while the audit chain stays intact and verifiable. You keep your evidence trail without keeping the identifiers.

What the spend retires Three mechanisms retire three costs: Tokenize shrinks breach blast radius (an exfiltrated token set is not a notifiable trove); Authorize stops policy violations per call rather than discovering them per quarter; Prove makes the log itself the evidence, removing audit-reconstruction work. Deployed self-hosted or in your VPC, with your keys, BAA-ready and verifiable. WHAT THE SPEND RETIRES Tokenize breach blast radius — an exfiltrated token set is not a notifiable trove Authorize the 80% problem — policy violations stopped per call, not per quarter Prove audit prep — the log IS the evidence, no reconstruction project Self-hosted · your keys · BAA-ready · verifiable
Get an instant quote

PHI tokenized at ingest, queried over MCP, detokenized only under audit — on your infrastructure, with your keys.

Get an instant quote

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →