$1.5M
HIPAA fine exposure
A single PHI-handling failure can become a reportable event with severe financial consequences.
Healthcare AI governance for regulated clinical workflows
ClinicalGuard gives healthcare teams deterministic guardrails around LLM-powered clinical decision support with MACI separation of powers, tamper-evident audit logging, and built-in checks for PHI, drug safety, and adverse events.
Quick start
pip install acgs-lite
Embed constitutional rules in YAML, route decisions through MACI roles, and retain a chain-valid audit trail for every governance event.
Purpose-built for teams that need trustworthy AI oversight before recommendations reach clinicians, patients, or regulators.
The problem
$1.5M
A single PHI-handling failure can become a reportable event with severe financial consequences.
2
Healthcare AI faces two oversight fronts at once: privacy obligations and FDA-style expectations for evidence, controls, and escalation.
0
If a recommendation cannot be reconstructed after the fact, the liability sits with the deploying organization.
How it works
Define
Encode healthcare policy as a 20-rule constitution covering evidence tiers, PHI handling, dosing, escalation, audit, and clinical safety.
Enforce
The system separates proposer, validator, and approver roles so no agent can self-approve or bypass governance.
Prove
Every decision is written to a tamper-evident chain with constitutional hash, timestamp, reasoning, and integrity verification.
Compliance
| Framework | Coverage | Operational evidence |
|---|---|---|
| HIPAA | 9/15 auto-covered controls for healthcare AI governance workflows | PHI detection, audit logging, access control hooks, de-identified workflows |
| FDA AI/ML | Aligned with evidence-tiering, monitoring, escalation, and adverse-event review expectations | Off-label routing, dosing checks, MedWatch-style adverse event signaling, human review gates |
| SOC 2 | Ready for control mapping across security, change management, and traceability | Tamper-evident logs, API-key auth, persistent audit storage, deployment hardening |
Two-layer validation
ClinicalGuard combines an LLM layer for semantic clinical reasoning with a deterministic governance layer for what cannot be left to model judgment alone.
Assesses evidence tier, drug interactions, dosing concerns, step therapy, and risk tier in free-text clinical proposals.
Enforces MACI validation, PHI restrictions, escalation logic, audit requirements, and reproducible rule checks with chain integrity.
Features
Flags 10 HIPAA Safe Harbor identifier types including SSNs, MRNs, DOBs, phones, email, and device identifiers.
Routes major interaction, contraindication, dosing, narrow therapeutic index, and step-therapy concerns before approval.
Detects severe allergic reactions, overdose, hospitalization, death, and other MedWatch-relevant safety signals.
Persists audit entries with constitutional hash and chain validation so investigators can verify nothing was altered.