Framework · HIPAA
Security Rule evidence for the AI that touches PHI.
The Security Rule has bound covered entities since 2005 and business associates directly since 2013; the proposed modernization published in January 2025 is not final. Meilynx evidences the AI-traffic slice: which protected health information reached which model and what was redacted before the call, whether the approved AI configuration changed, and a tamper-evident, write-once record of every request. Detection and redaction support, never de-identification, never a certification.
Safeguards, minimum necessary, associates, breach.
The technical safeguards of §164.312 apply to every information system that uses ePHI, the Privacy Rule's minimum-necessary standard applies to every prompt, and an LLM provider that receives PHI is a business associate.
- Minimum necessary for every use and disclosure of PHI, with a standard protocol for routine disclosures (§164.502(b), §164.514(d)). An AI prompt is a disclosure to the provider behind it.
- Technical safeguards: audit controls, access control, transmission security, integrity, and encryption for the systems that use ePHI (§164.312), retained six years (§164.316).
- Administrative safeguards: an accurate and thorough risk analysis covering the AI systems that receive PHI, workforce training, and business associate contracts with every LLM provider (§164.308, §164.314).
- Breach notification without unreasonable delay and within 60 days of discovery, with procedures that cover AI-workflow incidents (§§164.400–414).
Runtime expectations, to runtime evidence.
A specific Meilynx control for each expectation the proxy can substantiate, and the artifact it produces. Everything else is attested in the package, and the package says which is which.
HIPAA Security Rule → Meilynx controls (AI-traffic slice)
| Requirement | How Meilynx maps | Examination artifact |
|---|---|---|
Limit PHI in AI requests and responses to the minimum necessary HIPAA · §164.502(b) · §164.514(d) | The PHI detection rule scans every request and response for the Safe Harbor identifier classes it was benchmarked on and redacts each span in flight, before the request leaves your perimeter. Findings carry placeholders only; the control plane never holds PHI. | PHI detection and redaction findings by workflow and provider |
Record and examine activity in the systems that use ePHI HIPAA · §164.312(b) · §164.316(b)(2)(i) | Each AI request, response, and governance decision is sealed into a hash-chained record with write-once retention under your own key. Completeness across all systems that use ePHI is attested; tamper-evidence of the recorded events is verified. | Hash-chained audit trail with six-year retention lock |
Encrypt ePHI in transit and at rest HIPAA · §164.312(e)(1) · §164.312(a)(2)(iv) | TLS on every hop of the AI request path and customer-managed keys on the audit record. Encryption of your own data stores outside the proxy path is attested. | Encryption posture with the cited mechanisms |
Protect the AI configuration from unapproved alteration HIPAA · §164.312(c)(1) | Prompt-drift and tool-grant-drift detection flag changes to PHI-handling workflows against approved baselines; the governance bundle the data plane acknowledges is compared with the approved one. | Drift findings and configuration-integrity verdict |
Know which business associates received PHI, and attest the rest HIPAA · §164.308(b)(1) · §164.314(a) · §164.308(a)(1)(ii)(A) | The providers observed at the proxy are the LLM business associates the BAA control must cover. The BAAs themselves, the risk analysis, workforce training, and breach procedures are your program, attested in the package with structured evidence. | Observed-provider inventory and administrative-safeguard attestations |
Limit PHI in AI requests and responses to the minimum necessary
HIPAA · §164.502(b) · §164.514(d)
Maps to · The PHI detection rule scans every request and response for the Safe Harbor identifier classes it was benchmarked on and redacts each span in flight, before the request leaves your perimeter. Findings carry placeholders only; the control plane never holds PHI.
Examination artifact · PHI detection and redaction findings by workflow and provider
Record and examine activity in the systems that use ePHI
HIPAA · §164.312(b) · §164.316(b)(2)(i)
Maps to · Each AI request, response, and governance decision is sealed into a hash-chained record with write-once retention under your own key. Completeness across all systems that use ePHI is attested; tamper-evidence of the recorded events is verified.
Examination artifact · Hash-chained audit trail with six-year retention lock
Encrypt ePHI in transit and at rest
HIPAA · §164.312(e)(1) · §164.312(a)(2)(iv)
Maps to · TLS on every hop of the AI request path and customer-managed keys on the audit record. Encryption of your own data stores outside the proxy path is attested.
Examination artifact · Encryption posture with the cited mechanisms
Protect the AI configuration from unapproved alteration
HIPAA · §164.312(c)(1)
Maps to · Prompt-drift and tool-grant-drift detection flag changes to PHI-handling workflows against approved baselines; the governance bundle the data plane acknowledges is compared with the approved one.
Examination artifact · Drift findings and configuration-integrity verdict
Know which business associates received PHI, and attest the rest
HIPAA · §164.308(b)(1) · §164.314(a) · §164.308(a)(1)(ii)(A)
Maps to · The providers observed at the proxy are the LLM business associates the BAA control must cover. The BAAs themselves, the risk analysis, workforce training, and breach procedures are your program, attested in the package with structured evidence.
Examination artifact · Observed-provider inventory and administrative-safeguard attestations
What you hand an OCR investigator.
The audit trail renders into a Security Rule evidence package for the AI-traffic slice. Each control is classified as proxy-verified runtime evidence or attested in your program, and the package says which.
In the package
- PHI detection evidence: rule run-state, guard-model tier, redaction and fail-closed counts, placeholders only.
- Audit controls, retention, encryption, access, and integrity evidence blocks with the cited mechanisms.
- The observed LLM provider inventory the business associate agreements must cover.
- Administrative safeguards: risk analysis, BAAs, workforce training, breach procedures, attested with structured fields.
- Obligation timeline: Security, Privacy minimum necessary, and Breach Notification Rules in effect; the January 2025 modernization proposal as a watch item.
HIPAA Security Rule and the proxy.
Is PHI detection de-identification?
No. The guard model detects the Safe Harbor identifier classes it was benchmarked on and redacts each span before the request leaves your perimeter. The package makes no Safe Harbor or expert-determination claim under §164.514(b). On the ratified benchmark it met the signed-off bar on every scored identifier class; license and vehicle numbers carry no benchmark support and are disclosed as unscored rather than claimed.
Does the preset make us HIPAA compliant?
No runtime product could. The preset evidences the AI-traffic slice of the Security Rule: six proxy-verified controls plus attestations for the risk analysis, business associate agreements, workforce training, and breach procedures. Compliance is a conclusion your privacy officer and OCR reach; the package is the evidence they read.
What happens when the PHI guard model is unavailable?
The authored disposition applies, block by default, and every occurrence is recorded as a critical finding. The package counts them. Nothing degrades silently.
What about the proposed Security Rule update?
The notice of proposed rulemaking was published on 6 January 2025 and the federal agenda targets July 2027 for final action. Nothing in the package relies on it; the obligation timeline lists it as a watch item.
Build the evidence.
See exactly what an examiner receives
Download a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.