Industry · Healthcare
Evidence for the AI that reads charts, drafts messages, and summarizes records.
OCR audits the Security Rule, HHS Section 1557 has asked since May 2025 which decision support tools use protected-class inputs, ONC HTI-1 expects source attributes for predictive tools, and Texas, California, and Colorado now require disclosure and clinician review. Meilynx produces the runtime evidence for the LLM and agent slice: what protected health information reached which model and what was redacted in flight, whether the approved configuration changed, and whether a clinician reviewed the output.
Four questions every healthcare examiner asks about AI.
OCR audit and state disclosure is the reflex. These are the requests the evidence has to answer.
01
What PHI reaches which model
The minimum-necessary standard applies to every prompt. An auditor expects to see which identifiers went to which provider, under which business associate agreement, and what was stripped before the call.
02
Which decision support tools use protected-class inputs
Section 1557 turned identification into an ongoing duty. HTI-1 makes the source attributes available; the covered entity still has to know which tools it runs and record the determination.
03
Who reviewed the AI's output
Texas SB 1188 expects a practitioner to review AI-generated records, California AB 3030 exempts provider-reviewed communications from the disclaimer, and Colorado will require clinician review of AI-involved denials from 2027.
04
A record that survives a breach assessment
When PHI reaches an unapproved model, the four-factor risk assessment starts with the audit trail. A hash-chained record of every AI request answers the first question an investigator asks.
Named regulations, with a control mapping for each.
Presets ship in the product for each framework below. Each page walks the requirement, the Meilynx control, and the artifact.
Evidence in your regulator's vocabulary.
Meilynx evidences the LLM and agent traffic that runs through it. PHI detection and redaction are detection support, not de-identification. Risk analyses, business associate agreements, bias testing, source attributes, clinician review, and patient disclosure remain the covered entity's acts and are attested in the package, never performed by Meilynx.
In the package
- PHI detection findings with in-flight redaction, per workflow and provider, placeholders only
- The LLM provider inventory the business associate agreements must cover, generated from traffic
- Drift findings against the approved configuration, including the disclosure baseline
- Clinician-review records in the same tamper-evident chain
- Evidence packages for HIPAA, HHS §1557, ONC HTI-1, Healthcare AI Governance, and FDA readiness
Who we work with
Who reads the evidence
Healthcare and the proxy.
Is this de-identification?
No. The PHI guard model detects the Safe Harbor identifier classes it was benchmarked on and redacts each span before the request leaves your perimeter. It makes no Safe Harbor or expert-determination claim, and the package says so. Two identifier classes, license and vehicle numbers, carry no benchmark support and are disclosed as unscored rather than claimed.
Does the HIPAA preset make us HIPAA compliant?
No runtime product could. The preset evidences the AI-traffic slice of the Security Rule: six proxy-verified controls plus attestations for the risk analysis, business associate agreements, workforce training, and breach procedures. Compliance is a conclusion your privacy officer and OCR reach; the package is the evidence they read.
Which healthcare frameworks ship as presets?
HIPAA Security Rule, HHS Section 1557 patient care decision support, ONC HTI-1 decision support transparency, Healthcare AI Governance for the Texas, California, and Colorado laws with the Joint Commission / CHAI guidance, and an optional FDA AI lifecycle readiness preset. SOC 2 Type II applies as it does everywhere.
We are a payer, not a provider. Which applies?
Section 1557 and the Colorado utilization-review law reach payers directly; HIPAA applies to the health plan as a covered entity; HTI-1 applies where the plan deploys certified health IT. The Healthcare AI Governance preset covers the utilization-review safeguards as readiness ahead of Colorado's 2027 effective date.
See the evidence on your own traffic
A 15-minute walkthrough of inline enforcement, the audit chain, and the examination package.