For the complete documentation index, see llms.txt. This page is also available as Markdown.

Healthcare compliance

Healthcare compliance — HIPAA, BAA, audit retention, PHI handling, FDA SaMD considerations.

Regulatory frame

Clinical AI sits at the intersection of three regulatory regimes. Each has its own evaluation evidence requirement.

Regime
Applies when
Evaluation-evidence shape

HIPAA / BAA

Anything touching Protected Health Information (PHI)

Tenant-isolation, audit log, PHI handling controls

FDA SaMD

The AI makes or substantially supports a clinical decision (Class II+ Software as a Medical Device)

Clinical-validation evidence, change-control records

State Medical Practice Acts

The AI's output could be construed as practicing medicine

Disclaimers, scope-of-use constraints, escalation paths

Stratix supports the evidence side of all three. It does not certify your product — that's between you and your regulator. It produces the artifacts that make certification tractable.

HIPAA / BAA

Stratix Enterprise supports a Business Associate Agreement.

Required for production:

  1. Executed BAA with LayerLens

  2. PHI redaction at trace ingestion (in your application code, not Stratix's)

  3. SSO with role-based access (no shared logins)

  4. Extended audit retention for the period your record-retention policy requires

  5. Data residency in a region your security team has approved

Discuss with [email protected] and [email protected] to start the BAA workflow. See DPA process (Enterprise tier — contact sales) for the legal mechanics.

PHI handling

PHI must never enter Stratix trace bodies in plaintext unless your BAA covers it AND your security team has approved the data flow.

Recommended pre-trace redaction:

  • Names → <PATIENT_NAME> token

  • DOB → age-band only

  • MRN / SSN / addresses → category tokens

  • Free-text clinical notes — entity-level redaction (Presidio, AWS Comprehend Medical, or equivalent) before the trace leaves your boundary

The redaction happens client-side, before Stratix sees the data. Stratix's PHI-redaction rule pattern then verifies redaction was effective by scoring traces for any leftover PII.

FDA Software as a Medical Device (SaMD)

If your product makes or substantially supports a clinical decision, FDA may classify it as SaMD. The classification (Class I, II, or III) drives the evidence burden.

Stratix's role in the SaMD evidence pack:

  • Pre-market validation — agentic evaluations against curated clinical trace sets become the validation evidence

  • Change control — every release pin cites the evaluation ID that gated it; before-and-after evaluations document the impact of any change

  • Post-market surveillance — continuous trace evaluations on production traffic become the post-market quality monitoring artifact

Talk to your FDA regulatory consultant about how the evaluation evidence Stratix produces maps to your specific submission shape (510(k), De Novo, PMA).

Audit retention

Enterprise tier supports configurable audit retention. Common configurations:

Use
Retention

HIPAA-compliant operational logs

6 years (HIPAA minimum)

FDA-regulated clinical-AI change logs

Lifecycle of the product + post-market period

Quality audit trail (eval IDs cited in release notes)

Indefinite

Configure during onboarding; retention period is a contractual term.

State medical practice acts

State boards regulate "practice of medicine." AI that crosses certain thresholds (diagnosis, prescription, treatment recommendation) may be regulated as such.

Mitigations Stratix's evaluation framework supports:

  • Disclaimer-presence rule on patient-facing outputs (state-specific)

  • No-diagnosis rule that a triage assistant must not assert a specific diagnosis

  • Escalation rule to a licensed clinician for any output above configured risk

These are documentation patterns, not legal opinions. Consult counsel for your specific deployment.

Data residency

Enterprise: choose US, EU, or other available region for tenant data. Healthcare customers typically pin to a region matching their patient population to avoid cross-border data transfers.

  1. Enterprise tier with executed BAA

  2. PHI redaction at trace ingestion (your code)

  3. SSO with role-based access

  4. Trace evaluations with evaluation IDs cited in release notes

  5. Continuous trace evaluation on production traffic for post-market quality monitoring

  6. Data residency configured to your region of record

  7. Audit retention configured to your record-retention policy

See also

Last updated

Was this helpful?