Skip to main content
Healthcare

AI in the clinic. Governed at the gateway.

Healthcare organizations adopting AI face one immovable constraint: PHI cannot leave the environment uncontrolled. Arbitex puts a governance layer in front of every AI call — inspecting, enforcing, and logging before any data reaches a model.

Healthcare AI data flows through the Arbitex protection pipeline — PHI detected and redacted before reaching the language model
Capabilities

AI governance built for healthcare data environments.

DLP for PHI — DEA, NPI, MRN, MBI

Arbitex's 3-tier DLP pipeline covers the full spectrum of healthcare identifiers. Structured patterns catch DEA registrant numbers (9-character format with checksum validation), NPI numbers (10-digit National Provider Identifiers with Luhn verification), MRNs (Medical Record Numbers with institution-specific format support), and MBI codes (Medicare Beneficiary Identifiers in the 11-character 1C2C2N2C2N2C format). All 18 HIPAA identifier categories are covered. Detection runs on every request and response before any data reaches a model.

HIPAA Policy Packs

Pre-built policy bundles map enforcement controls directly to the HIPAA Security Rule. Each DLP detection rule aligns to a specific 45 CFR §164 safeguard category: technical safeguards (§164.312), access controls (§164.312(a)), and integrity controls (§164.312(c)). The bundle activates by default in HIPAA mode. Enforcement actions are logged with full chain-of-custody metadata. Business Associate Agreement (BAA) available.

Audit Trails for Compliance

Audit log retention is configurable to meet the six-year record-keeping requirement under 45 CFR §164.312. Every detection and enforcement action is logged with timestamp, user context, model endpoint, and policy version. Logs are tamper-proof for tamper evidence and cannot be modified or deleted. Exportable in structured format for OCR examination submissions and HITECH breach notification documentation.

GeoIP for Data Residency

Arbitex deploys via Hybrid Outpost — the data plane runs in your VPC. PHI is inspected, enforced, and logged entirely within your infrastructure. No patient data transits Arbitex-controlled systems. GeoIP enforcement ensures AI requests originate from approved jurisdictions, supporting state-level data residency requirements and cross-border transfer restrictions under HIPAA and state privacy laws.

Content Categories for Clinical vs Admin

Content classification distinguishes clinical AI use cases from administrative ones. Prompts containing clinical terminology, diagnosis codes (ICD-10), procedure codes (CPT), and drug references route through clinical-grade DLP with maximum enforcement. Administrative queries — scheduling, billing inquiries, HR — apply lighter policies. Classification runs automatically using the content category engine, reducing false positives for non-clinical workflows.

Credential Intelligence for EHR Systems

Healthcare organizations integrate AI tools with EHR platforms — Epic, Cerner, MEDITECH. Credential intelligence detects leaked EHR API keys, FHIR access tokens, OAuth client secrets, and service account credentials in AI prompts before they reach model endpoints. Detected credentials are blocked or redacted in-path. Every detection is logged with credential type and source context for incident response.

How it works

01

Protect PHI in AI prompts

A clinician or application sends an AI request. The request enters the Arbitex gateway before reaching any model endpoint. Tier 1 regex patterns immediately catch structured identifiers: DEA registrant numbers, NPI provider codes, MRN formats, and MBI codes — each with checksum or format validation. Tier 2 applies ML-based entity recognition to flag PHI in free text: patient names, dates of birth, diagnosis codes, and other unstructured identifiers. Tier 3 contextual validation confirms ambiguous matches and reduces false positives.

02

Enforce HIPAA policies

Based on your configured HIPAA compliance bundle, the gateway blocks, redacts, or routes the request according to your rules. Content categories separate clinical from administrative AI usage — clinical queries enforce maximum DLP; administrative queries apply lighter policies. The enforcement action is recorded with full metadata. No PHI reaches the model unless your policy explicitly permits it.

03

Audit everything

The audit log captures the complete chain of events: request received, detection result, enforcement action, model response, response inspection. Retention is configurable to meet 45 CFR §164.312 requirements. tamper-proof logs are tamper-evident and cannot be modified. Exportable for OCR examination submissions, HITECH breach notification documentation, and HITRUST assessment evidence.

Compliance mapping

Six frameworks. One policy layer.

Each compliance obligation maps to a specific Arbitex capability. All bundles are active simultaneously — no separate configuration per framework.

HIPAA
PHI · BAA · Minimum Necessary

All 18 PHI identifier categories detected and enforced per 45 CFR §164. Technical safeguards (§164.312), access controls (§164.312(a)), and integrity controls (§164.312(c)) mapped to DLP enforcement actions. BAA available. Minimum necessary principle enforced via role-based access controls and content category routing.

HITECH Act
Breach Notification · EHR · Penalties

HITECH strengthened HIPAA enforcement with mandatory breach notification for unsecured PHI. Arbitex audit logs provide the evidence trail for breach determination — was PHI exposed, to whom, and what enforcement action was taken. Tamper-evident logs support the four-factor risk assessment required under 45 CFR §164.402.

HL7 / FHIR
API Security · Data in Transit

HL7 FHIR APIs power modern EHR interoperability. AI tools consuming FHIR endpoints can expose patient resources in prompts. Arbitex detects FHIR resource identifiers, patient references, and clinical data structures in AI requests. FHIR access tokens and OAuth credentials are caught by credential intelligence before reaching model endpoints.

FDA 21 CFR Part 11
Electronic Signatures · Audit Trails

FDA regulations for electronic records require audit trails, access controls, and electronic signature validation. Arbitex provides the governance layer for AI tools used in clinical research and FDA-regulated workflows — every AI interaction is logged with user identity, timestamp, and enforcement action. Immutable audit logs satisfy Part 11 record-keeping requirements.

HITRUST CSF
Common Security Framework

HITRUST CSF consolidates healthcare security requirements into a certifiable framework. Arbitex enforcement controls map to HITRUST control categories — access control, audit logging, data protection, and incident management. Audit log exports provide assessment evidence for HITRUST r2 and e1 certification engagements.

42 CFR Part 2
Substance Use Disorder Records

Federal regulations protecting substance use disorder (SUD) treatment records impose stricter consent and disclosure requirements than HIPAA. Arbitex content categories can flag AI interactions involving SUD-related terminology, routing them through enhanced enforcement policies that restrict disclosure beyond the minimum necessary for treatment coordination.

Related Resources

Healthcare Use Case

PHI detection and HIPAA controls

DLP Protection

Inspect every AI prompt for sensitive data

Audit Log

Tamper-proof activity trail

Compliance Frameworks

Pre-built policy packs for regulatory requirements

HIPAA Compliance for AI Assistants

How to meet HIPAA requirements when deploying AI in clinical environments

Ready to put governance in front of your clinical AI?

Talk to an Arbitex engineer about PHI detection, HIPAA compliance configuration, and BAA availability for your environment.