# Healthcare AI Security Guides: FDA & HIPAA | RankShieldMD

> Guides on proving clinical-AI decisions, FDA §524B and HIPAA compliance evidence, AIBOM, and post-quantum security for healthcare. Verifiable and PHI-free.
>
> Source: https://rankshieldmd.com/resources/ · RankShieldMD (verifiable AI & post-quantum security for healthcare)

RankShieldMD // Resources
# Proof, explained .

**Guides on making clinical AI, medical devices, and record access verifiable, without exposing patient data.** Practical, honestly-sourced writing for the people accountable when AI acts inside care: how to prove a clinical-AI decision, what FDA §524B and HIPAA actually require, and how to make a device quantum-safe. Every claim checkable, every stat attributed.
Read the guides →   The platform       Cited  PHI-free  Post-quantum  Non-device          RankShieldMD ledger · PHI-free                  Clinical-AI decision  onco-v4 · 0x5377a9a1…   Sealing…      Record access · export  verified actor · 0xa6ee5342…   Sealing…      Telehealth order  signed · 0xfa65fce3…   Sealing…           Scroll to read
Coverage
## Provenance, compliance, and post-quantum.

Three questions the people accountable for clinical AI keep facing, and the guides that answer each one honestly.
01
### Prove the decision

The unprovable AI decision is a new class of risk. These guides explain the receipt every clinical-AI decision needs, and how it stays non-device.
provenance     02
### FDA and HIPAA, made verifiable

What §524B, the CDS non-device line, and HIPAA §164.312(b)/§164.528 actually require, and the evidence that supports them, honestly framed.
compliance     03
### Secure into the quantum age

Why implants and records outlive their cryptography, and how post-quantum identity with in-field rotation keeps a decade of evidence defensible.
post-quantum               The guides
## Guides for proving the medicine.

Every guide is honestly sourced, cites its statistics to the original, and holds the same line the product does: attests but never decides, PHI-free, supports compliance rather than claiming to make you compliant.

Long-form, cited, and written for a security committee. Start here.
Provenance · 10 min
### One record, two regulators: what FDA and the EU AI Act each ask of a model that changes

A PCCP is permission for your model to change after clearance. The EU AI Act requires you to say what ran. Build the record per decision and one trail answers both.
Read →      Provenance · 10 min
### Which model read this slide? Pathology provenance and the image you cannot re-create

A whole-slide image is the end of a physical production line, and a re-cut slide is a new specimen. Why the record you sealed at the time is the only route back to a challenged read.
Read →      EU AI Act · 10 min
### Article 50 is already in force: the AI Act transparency duties your clinical AI has today

The Omnibus deferred the high-risk dates and left Article 50 alone. Two of its four duties land on you rather than your vendor, and a marking deadline arrives 2 December 2026.
Read →      EU AI Act · 10 min
### Annex I or Annex III? Which EU AI Act deadline binds your medical AI

The Digital Omnibus moved two deadlines, not one, to dates eight months apart. Article 6 decides which clock is yours, and the deciding condition is not whether your software is medical.
Read →      EU AI Act · 11 min
### The EU AI Act high-risk deadline moved to 2028. Article 12 logging did not move with it.

The Digital Omnibus gave medical AI two more years. It did not give anyone a way to record a year that has already passed. What changed, and the one duty you cannot backfill.
Read →      Provenance · 9 min
### Tamper-evident audit logs for clinical AI: what immutable really requires

Keeping logs for years is not the same as keeping them trusted. Learn what makes a clinical-AI audit log genuinely tamper-evident and independently verifiable.
Read →      Provenance · 9 min
### Model cards are not proof: transparency documents versus verifiable provenance

Model cards and frameworks describe an AI system. They do not prove what it did. Learn the difference between transparency documents and verifiable provenance.
Read →      HIPAA · 9 min
### Put your AI scribe in your HIPAA risk analysis: the step small practices miss

OCR ties most penalties to risk-analysis gaps, and your AI scribe is often missing from it. Learn how a small practice documents the scribe in its SRA.
Read →      Telehealth · 9 min
### Signed clinical orders: proving a telehealth prescription came from your clinician

Voice clones and spoofed orders threaten telehealth. Learn how cryptographically signed clinical orders prove a prescription truly came from your clinician.
Read →      Governance · 9 min
### Governance, security, and provenance: the third pillar of clinical-AI trust

Most clinical-AI trust advice covers governance and security, then stops. Learn why verifiable provenance is the missing third pillar, and how to add it.
Read →      Provenance · 9 min
### Which AI model read this scan? Tamper-evident imaging provenance for small centers

When an AI-assisted read is challenged, can you prove which model version read the scan on intact images? Build a tamper-evident imaging provenance record.
Read →      HIPAA · 9 min
### PHI-free HIPAA access auditing: prove who touched a record without exposing it

Access logs often widen your PHI footprint. Learn how PHI-free, tamper-evident access auditing proves who touched which record without exposing patient data.
Read →      Telehealth · 9 min
### Verify a telehealth patient is real, not a deepfake, before you prescribe

Synthetic patients now book telehealth visits to obtain prescriptions. Learn how to verify a real, live patient with signed proof before you prescribe.
Read →      Provenance · 9 min
### Prove an AI scribe note is genuine: the audit trail small practices need

AI scribe notes get questioned months later. Learn to build a tamper-evident, PHI-free audit trail that proves what your model captured and who signed it.
Read →      Compliance · 10 min
### How to answer a hospital's AI security questionnaire with proof

Turn a hospital's AI security review into a fast win. Build a reusable evidence pack that proves your model, access, and controls, not just your promises.
Read →      Provenance · 11 min
### What clinical-AI decision provenance is, and why every AI decision needs a receipt

When an AI decision reaches a patient and is later questioned, no one can prove what happened. Here is the receipt layer that changes that.
Read →      Compliance · 12 min
### FDA Section 524B, explained: what "reasonable assurance of cybersecurity" actually requires

A plain guide to the three §524B obligations, the June 2025 final guidance, and the evidence an FDA submission actually needs.
Read →      HIPAA · 11 min
### Is a clinical-AI audit trail HIPAA-compliant? Audit controls and accounting of disclosures

How a tamper-evident, PHI-free audit trail supports HIPAA §164.312(b) and §164.528, and why ordinary logs fail the test.
Read →      Post-quantum · 12 min
### Why post-quantum cryptography matters for implants: harvest now, forge later

Implants run for a decade inside a realistic quantum window and are rarely re-secured. How post-quantum identity migrates a device without a recall.
Read →      Compliance · 12 min
### The unpatchable medical device problem and the FDA compensating-control answer

You cannot patch a 12-year-old infusion pump. How FDA compensating controls and a sealed residual-risk dossier bring the risk to acceptable.
Read →      Provenance · 12 min
### Non-device by design: staying on the right side of the FDA clinical decision support line

The FDA CDS fourth criterion separates a regulated device from software that supports it. Why attesting a decision, not rendering it, stays non-device.
Read →      Compliance · 12 min
### AIBOM for healthcare: CISA and CycloneDX ML-BOM for clinical AI

An AI bill of materials inventories the model, datasets, and lineage behind clinical AI. The standards stack, and the missing signed-provenance piece.
Read →      Provenance · 12 min
### How to choose between verifiable AI and AI governance (and tell which a vendor actually does)

Governance documents and manages risk. Verifiable AI proves, per decision, that a model was genuine. A buyer guide to which layer you need.
Read →      Liability · 14 min
### Who is liable when a clinical AI decision is wrong?

When an AI-assisted decision harms a patient, who is accountable: the clinician, the hospital, or the AI vendor? How the evidence record decides. Includes an accountability mapper.
Read →      Governance · 12 min
### Shadow AI in hospitals: finding and governing the clinical AI you did not authorize

Clinicians are using AI tools no one approved, and PHI is leaving the building. How to discover, govern, and verify it. Includes an exposure calculator.
Read →      HIPAA · 13 min
### The proposed 2025 HIPAA Security Rule update: mandatory MFA, encryption, and clinical AI

The 2025 NPRM would make MFA, encryption, and audit controls mandatory. What changes, and what it means for clinical AI. Includes a readiness checklist.
Read →                Scope
## What we write about.

Clinical-AI decision provenance, FDA §524B and the CDS non-device line, HIPAA audit controls and accounting of disclosures, AIBOM for clinical AI, EU AI Act obligations, the NIST AI RMF, and post-quantum security for implants and long-retention records. If a claim cannot be checked or a statistic cannot be attributed, it does not appear.
Get started
## Proof for every clinical decision.

Bring a decision, an access flow, or a device, and verify the evidence yourself, without PHI, and without trusting us.
Request early access →   How it works
