Healthcare AI agents touch ePHI through FHIR. When one acts on its own, your EHR's audit log can't say which agent touched which patient, or under whose authority — AIR can, and signs the proof.
Agents read and write ePHI as FHIR resources over SMART-on-FHIR / OAuth. Since the 2020 ONC Cures Act, FHIR (R4 / R5) is the US standard for exchanging health data.
Audit logging is "addressable" today, and for autonomous agents it's routinely skipped. The 2025 Security Rule NPRM would make it mandatory.
Any vendor touching ePHI signs a Business Associate Agreement, with annual certification under the proposed rule.
DataSubjectRef / DataAssetRef stamped on every action.Not a screenshot of a dashboard, and not a log your team could have edited. A signed, anchored record of exactly what the agent did, who authorized it, and proof the chain is intact, self-authenticating under FRE 902(13)–(14).
See the full evidence model →Retention is the lever: you don't pay us to store records, you pay us to keep them provable, signed, tamper-evident, and re-anchored, for as long as the law and a courtroom require.
A free agent audit. Nothing deployed, nothing leaves your boundary. You walk away with the record, whether or not you ever buy.
Book an agent audit →