Governing AI across clinical workflows.
Clinicians and administrators are adopting AI for documentation, coding, triage, and EHR queries. Every prompt is a potential PHI exposure vector. Arbitex puts a governance layer in front of every AI call — inspecting, enforcing, and logging before any data reaches a model.
PHI flows through every AI prompt.
Healthcare organizations are deploying AI across clinical documentation, medical coding, triage support, and patient communication tools. Clinicians type patient names, diagnoses, and medical record numbers into chat interfaces without realizing those prompts are leaving the organization.
Most AI gateways are designed for developer productivity — not regulated healthcare environments. They lack PHI-specific detection, offer no data residency controls, and produce audit logs that don't meet 45 CFR §164.312 retention requirements. A SaaS-only gateway is an architectural HIPAA disqualifier when PHI must never leave the customer VPC.
Arbitex was built to govern AI in environments where compliance is not optional. The 3-tier DLP pipeline, HIPAA compliance bundle, and Hybrid Outpost architecture are designed specifically for healthcare organizations that need to move fast without creating PHI exposure.
Built for healthcare governance.
PHI Detection at Every Layer
The 3-tier DLP pipeline runs on every AI request and response before data reaches any model. Tier 1 catches structured identifiers — MRNs, SSNs, dates of birth — using 80+ regex patterns, with checksum validation where applicable (NPI Luhn, DEA check digit, and similar regulated identifiers). Tier 2 applies ML-based entity recognition to identify Protected Health Information in free text: patient names, diagnoses, medications, and provider notes. Tier 3 applies contextual analysis to resolve ambiguity and reduce false positives. Policy runs in-path: block, redact, or route.
HIPAA Compliance Bundle
Pre-configured HIPAA policy set with minimum necessary access enforcement, PHI redaction rules, and role-based access controls. Activate the bundle and every AI call is governed under HIPAA requirements without manual rule authoring. Policy changes are version-logged with before/after deltas. Business Associate Agreement (BAA) available.
Tamper-proof Audit Logs
Every detection and enforcement action is written to an tamper-proof, append-only audit log. Records cannot be modified or deleted by any user, including account owners. Retention is configurable to meet the six-year requirement under 45 CFR §164.312. Signed exports support OCR audit requests and internal compliance review.
Data Sovereignty via Hybrid Outpost
The Arbitex data plane runs in your VPC. PHI is inspected, enforced, and logged entirely within your infrastructure — no patient data transits Arbitex-controlled systems. The Hybrid Outpost model satisfies the data residency requirements of HIPAA Business Associate Agreements and state-level health data laws.
Multi-Provider Coverage in One Policy
Healthcare organizations use AI across EHR integrations, clinical documentation, coding assistance, and patient triage. Arbitex governs 9+ LLM providers under a single policy layer — OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, and others. One compliance configuration applies across every model endpoint.
Fail-Closed by Default
If a policy evaluation fails or a detection result is inconclusive, the request is blocked — not passed through. The gateway is designed to fail safe. For healthcare environments where an undetected PHI disclosure carries regulatory and reputational consequences, fail-closed behavior is non-negotiable.
How it works
Clinician sends an AI request
A physician or clinical documentation specialist submits a prompt — a patient note summary, a coding query, a triage question. The request enters the Arbitex gateway. The 3-tier DLP pipeline runs immediately: Tier 1 regex patterns catch structured PHI, with checksum validation where applicable (NPI Luhn, DEA check digit, and similar regulated identifiers); Tier 2 applies ML-based entity recognition to identify free-text PHI in clinical context (diagnoses, patient names, provider notes); and Tier 3 contextual analysis confirms ambiguous matches.
Policy enforces HIPAA requirements in-path
Based on your configured HIPAA compliance bundle, the gateway blocks, redacts, or routes the request. Minimum necessary access rules are applied. The enforcement action is recorded immediately — policy version, detection result, action taken, user context, and model endpoint. No PHI reaches any model unless your policy explicitly permits it.
Immutable audit record supports compliance review
Every event in the chain — request received, detection result, enforcement action, model response, response inspection — is written to the tamper-proof audit log. Records are tamper-evident by construction. Retention meets 45 CFR §164.312. Signed exports are available for OCR audit requests, internal compliance review, and BAA documentation.
Frameworks covered by the HIPAA bundle.
Each framework requirement maps to a specific Arbitex capability — not a general claim.
Minimum necessary access enforcement. PHI access is governed by role and purpose — not assumed. Every access decision is logged.
Audit controls and 6-year log retention. tamper-proof records satisfy the tamper-evidence and retention requirements for ePHI access.
Detection and logging infrastructure to support breach identification, scope assessment, and notification timelines.
Data residency controls via Hybrid Outpost support state-level patient data sovereignty requirements beyond federal HIPAA scope.
Related Resources
Ready to govern clinical AI?
Talk to an Arbitex engineer about PHI detection configuration, HIPAA compliance bundle setup, and BAA availability for your environment.