Design for ePHI handling
Provider eligibility and telemetry decisions are explicit, but retention enforcement and regional/dedicated cells remain required work.
The metadata-minimized architecture is being built with later BAA and dedicated-deployment requirements in mind—without claiming compliance prematurely.
Healthcare readiness is more than encryption or a badge. The service begins with minimized hosted telemetry, tenant-bound credentials, explicit workload/data context, and provider eligibility controls. A BAA, risk analysis, retention validation, workforce procedure, vendor review, and deployment boundary are still required before ePHI use.
Treat provider contracts, data class, region, retention, support, incident response, and deployment model as release gates.
Require an explicit data class and prohibit regulated traffic from unapproved routes.
Limit credentials and models to reviewed accounts, contracts, regions, and telemetry behavior.
Document BAA, risk analysis, procedures, training, incident handling, and validation before ePHI.
Use explicit workload and data-class context; never infer authorization from a model name alone.
Limit eligible providers, models, credentials, and telemetry before the request can leave the gateway.
Run the tested rule in Observe, Shadow, or Enforce according to the approved rollout stage.
Retain metadata evidence and administrative change history for authorized operational review.
Versioned profiles govern prompt attacks before spend, sensitive output before release, and the tool names, types, and MCP hosts a model may use—without retaining schemas, arguments, or results.
Versioned profiles govern prompt attacks before spend, sensitive output before release, and the tool names, types, and MCP hosts a model may use—without retaining schemas, arguments, or results.
Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.
Provider eligibility and telemetry decisions are explicit, but retention enforcement and regional/dedicated cells remain required work.
Customers bring provider credentials today. A customer-VPC data plane and customer-managed KMS options are not currently included.
BAA execution, risk analysis, policies, workforce procedures, vendor review, and validated operations are required before any HIPAA use.
The trust center separates implemented controls, deployment dependencies, unavailable capabilities, and assurance that still requires an independent review.
Review security boundaries and current statusClear answers for buyers, administrators, and security reviewers.
No. AI Gateway HQ does not currently claim HIPAA readiness or offer a BAA. Use only non-sensitive test data until contractual, administrative, and technical gates are completed.
The hosted gateway is designed not to persist prompt or response bodies by default. Provider retention and application logging remain separate customer review responsibilities.
It is an enterprise design path, not a generally available package. The deployment, update, support, and evidence boundaries require implementation and validation.
Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.