Book a demo
Solutions / Healthcare

An agent opened a patient's chart.
Can you prove it was allowed to?

Healthcare AI agents touch ePHI through FHIR. When one acts on its own, your EHR's audit log can't say which agent touched which patient, or under whose authorityAIR can, and signs the proof.

FHIR R4 / R5HIPAA 164.312(b)BAAAir-gapped
Free eval · nothing deployed · ePHI never leaves your boundary
Signed Intent Capsule · live
Agentdischarge-summarizer-03
Delegated bydr.okafor · Auth0
FHIR readPatient/8841
FHIR readObservation/22907
Bulk exportblocked · SV-EXFIL
BLAKE3 · Ed25519 · anchored Rekor #1466351923
✓ chain intact · verify on search.sigstore.dev
01The stakes
02:14:07 · agent: discharge-summarizer-03
An autonomous agent just read 1,400 patient charts to draft discharge summaries.
Under 45 CFR 164.312(b) you must be able to say which patients, under whose authority, and prove the record was never changed. Your EHR answers that for a human at a workstation; for an autonomous agent, it can't.
02The mandate

What the rules require, and where they're heading.

FHIR / HL7
the data substrate

Agents read and write ePHI as FHIR resources over SMART-on-FHIR / OAuth. Since the 2020 ONC Cures Act, FHIR (R4 / R5) is the US standard for exchanging health data.

The question your EHR can't answer: which agent touched which resource, for which patient.
HIPAA 164.312(b)
audit controls

Audit logging is "addressable" today, and for autonomous agents it's routinely skipped. The 2025 Security Rule NPRM would make it mandatory.

Proposed, not final — OCR hasn't issued a final rule. Either way, agents are the uncovered gap.
BAA
the contract

Any vendor touching ePHI signs a Business Associate Agreement, with annual certification under the proposed rule.

With air-gapped AIR the ePHI never leaves your boundary, so there's nothing to phone home.
03How AIR answers

Every demand, mapped to a capability that already ships.

Which agent touched which patient's record?
MonitorPer-agent identity with DataSubjectRef / DataAssetRef stamped on every action.
Under whose authority did it act?
AccountEvery agent bound to a named human through Auth0, Microsoft Entra, Okta, or SPIFFE.
Prove the log was not edited afterward.
ProveEach action signed in-process (BLAKE3 + Ed25519) and anchored to a public transparency log.
Stop an agent before it over-reaches.
ProtectStructural Verification halts out-of-scope access deterministically: SV-EXFIL, SV-SCOPE.
Keep ePHI inside the boundary.
Air-gappedOn-prem deployment with private anchoring; the transparency log runs inside your enclave.
04The evidence

This is what you hand the auditor.

Not a screenshot of a dashboard, and not a log your team could have edited. A signed, anchored record of exactly what the agent did, who authorized it, and proof the chain is intact, self-authenticating under FRE 902(13)–(14).

See the full evidence model →
AgDR record · agdr/v2
Delegation · dr.okafor authorized discharge-summarizer-03
Subject · DataSubjectRef = Patient/8841
Action · FHIR read Observation/22907 — in scope
Halt · bulk export blocked — SV-EXFIL
sig: ed25519 · hash: blake3 · anchor: Rekor #1466351923
✓ chain intact · verify on search.sigstore.dev
05What you get

The tiers regulated healthcare teams choose.

Enterprise
most teams here
  • Containment — halt agents before harm
  • Causal graph, query & replay
  • SIEM: Splunk · Datadog · Sentinel · Sumo
  • SSO / OIDC, SLA
  • SOC 2 · HIPAA · ISO 42001 · EU AI Act · NIST
Book an agent audit
Air-gapped
regulated · sovereign
Everything in Enterprise, plus
  • Air-gapped license — no phone-home
  • Signed BAA
  • HL7v2 / FHIR R4 interop
  • On-prem / offline anchoring
  • Admissibility Pack — FRE 902 + expert support
Talk to us

Retention is the lever: you don't pay us to store records, you pay us to keep them provable, signed, tamper-evident, and re-anchored, for as long as the law and a courtroom require.

See what your agents did to ePHI.

A free agent audit. Nothing deployed, nothing leaves your boundary. You walk away with the record, whether or not you ever buy.

Book an agent audit →
HIPAA 164.312(b)45 CFRFHIR R4 / R5BAAFRE 902(13)–(14)SOC 2ISO 42001
Vindicara · project AIR v1.0.1 support@vindicara.io · This page is itself on the record.