HIPAA compliant AI agents
HIPAA compliant AI agents, by mechanism, not by promise
Ambient scribes, chart summarizers, and billing agents are new PHI boundaries — and the HIPAA Security Rule NPRM pulls every one of them into mandatory risk analysis. DataShield gives agents tokenized data instead of identifiers: datasets tokenized at ingest, agents query over MCP, detokenization is a privileged, audited operation.
Healthcare breaches average $7.42M and 279 days to resolve (IBM 2025). The control isn't a promise in a BAA — it's a mechanism you can verify.
PHI de-identification for LLM agents: the three failure points, closed
Agents see PHI they don't need
The minimum-necessary standard applies per agent, per handoff. DataShield classifies fields at ingest (NAME, DOB, MRN, and the rest) and replaces identifiers with deterministic, join-preserving tokens — agents get answers, not identifiers. Quasi-identifiers are generalized to k-anonymity so tokenized rows can't be re-identified by combination. See Ontology.
No proof of who accessed what
HIPAA §164.312(b) requires audit controls over ePHI activity. Every governed tool call is scoped, metered, attributed to agent identity, and sealed into a SHA-256 hash chain with Ed25519-signed checkpoints — verification distinguishes tampering, insertion, deletion, and truncation. Try it on a sample log.
Re-identification is all-or-nothing
One-way redaction destroys clinical utility. DataShield tokenization is vault-reversible under policy: a billing workflow that legitimately needs the identifier gets it through a privileged, logged detokenization — and erasure is crypto-shred, which survives in the audit chain. Details in Security.
The HIPAA Security Rule NPRM puts AI tools in your risk analysis
The proposed Security Rule update explicitly requires AI tools touching ePHI to appear in risk analysis: what type and amount of ePHI, disclosed to whom, output going where. OCR's risk-analysis enforcement initiative runs into 2026, with penalties up to $73,011 per violation and $2.19M annual caps. And the first healthcare GenAI enforcement has already happened — Texas AG v. Pieces Technologies, over hospitals feeding live patient data to a GenAI summarizer.
No law bans PHI near an LLM outright. The requirements are risk analysis, minimum-necessary access, BAAs, and auditability — which is exactly what an at-ingest de-identifying data plane plus hash-chained audit evidence provides.
"Our LLM vendor has a BAA" is not a control. A BAA allocates liability for one vendor node. It doesn't cover pipeline entry, application logging, or agent tool-chaining — the places the 2025 MCP incidents actually happened. DataShield deploys self-hosted or in your VPC, with your keys; a BAA conversation is welcome. Read the architecture.
HIPAA and AI agents: buyer questions
Does DataShield make our ambient scribe or chatbot HIPAA compliant?
No product makes you compliant by itself — compliance is your program. DataShield supplies the technical safeguards that program needs: at-ingest PHI tokenization and k-anonymity generalization (Ontology), per-tool-call authorization with mid-session revocation (Auth), and tamper-evident audit logs designed to map to §164.312(b).
Does DataShield intercept prompts to strip PHI in real time?
No. Tokenization happens at ingest, per dataset — not by inline traffic interception. Agents query already-tokenized data over MCP, so identifiers never enter the query path. Detokenization is a separate privileged, audited vault operation.
Can we still join patient records after de-identification?
Yes. Tokens are deterministic and join-preserving — the same MRN always maps to the same token, so joins across datasets work while the identifier stays out of the query path. Quasi-identifiers are generalized to a configured k to block combination re-identification.
How do we handle a patient erasure request if data is tokenized?
Erasure is crypto-shred: destroy the key material and the tokens become irrecoverable, while the audit chain stays intact and verifiable. You keep your evidence trail without keeping the identifiers.
PHI tokenized at ingest, queried over MCP, detokenized only under audit — on your infrastructure, with your keys.
Get an instant quoteYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →