HIPAA (US Health Privacy)
US health-data regime (Privacy, Security & Breach Notification Rules): PHI minimum-necessary standard, BAA chains for AI vendors, audit controls and access logging. For clinical AI (scribing, diagnostics, prior-auth) it is the US-side twin of GDPR Art. 9 — evidence overlap: access logs, vendor due diligence, encryption attestation.
3 components0 articles / obligations4 triggering use casesopen in graph WORM / Immutable Audit Vault
75% of use casesAppend-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
- evidence artefactHIPAA (US Health Privacy) → Event Logs & Decision Traces → produced by WORM / Immutable Audit VaultEvent Logs & Decision Traces
OpenTelemetry / FCoT Tracing
0% of use casesHierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
- evidence artefactHIPAA (US Health Privacy) → Event Logs & Decision Traces → produced by OpenTelemetry / FCoT TracingEvent Logs & Decision Traces
Vendor & Model Due-Diligence Kit
0% of use casesScoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.