Platform
Clinical-AI provenanceDiagnostic Provenance LedgerPHI-free access auditTelehealth verificationVerifiable AI for healthcareHealthcare identityFor clinical-AI vendorsVerifiable AI vs governanceDevices & systems
Medical device securityPost-quantum implantsFDA 524B cybersecurityDevice manufacturersAIBOM for healthcareHealth systemsHealth data exchange (TEFCA)Threat federationCompliance
Is your AI a device? (CDS)FDA 524B cybersecurityHIPAA complianceHIPAA access auditEU AI Act for medical AINIST AI RMFPost-quantum cryptographyTools
Is your AI a medical device?HIPAA audit readinessPost-quantum readinessVerify a proof (live demo)All tools →Resources
FDA 524B explainedNon-device CDS lineHIPAA clinical-AI audit trailShadow AI in hospitalsClinical-AI decision provenanceAIBOM (CycloneDX)Clinical-AI liabilityHIPAA Security Rule 2025Post-quantum implantsUnpatchable devicesVerifiable AI or governanceAll resources →Proof,
explained.
Guides on making clinical AI, medical devices, and record access verifiable, without exposing patient data. Practical, honestly-sourced writing for the people accountable when AI acts inside care: how to prove a clinical-AI decision, what FDA §524B and HIPAA actually require, and how to make a device quantum-safe. Every claim checkable, every stat attributed.
Provenance, compliance, and post-quantum.
Three questions the people accountable for clinical AI keep facing, and the guides that answer each one honestly.
Prove the decision
The unprovable AI decision is a new class of risk. These guides explain the receipt every clinical-AI decision needs, and how it stays non-device.
provenanceFDA and HIPAA, made verifiable
What §524B, the CDS non-device line, and HIPAA §164.312(b)/§164.528 actually require, and the evidence that supports them, honestly framed.
complianceSecure into the quantum age
Why implants and records outlive their cryptography, and how post-quantum identity with in-field rotation keeps a decade of evidence defensible.
post-quantumGuides for proving the medicine.
Every guide is honestly sourced, cites its statistics to the original, and holds the same line the product does: attests but never decides, PHI-free, supports compliance rather than claiming to make you compliant.
Long-form, cited, and written for a security committee. Start here.
One record, two regulators: what FDA and the EU AI Act each ask of a model that changes
A PCCP is permission for your model to change after clearance. The EU AI Act requires you to say what ran. Build the record per decision and one trail answers both.
Read → Provenance · 10 minWhich model read this slide? Pathology provenance and the image you cannot re-create
A whole-slide image is the end of a physical production line, and a re-cut slide is a new specimen. Why the record you sealed at the time is the only route back to a challenged read.
Read → EU AI Act · 10 minArticle 50 is already in force: the AI Act transparency duties your clinical AI has today
The Omnibus deferred the high-risk dates and left Article 50 alone. Two of its four duties land on you rather than your vendor, and a marking deadline arrives 2 December 2026.
Read → EU AI Act · 10 minAnnex I or Annex III? Which EU AI Act deadline binds your medical AI
The Digital Omnibus moved two deadlines, not one, to dates eight months apart. Article 6 decides which clock is yours, and the deciding condition is not whether your software is medical.
Read → EU AI Act · 11 minThe EU AI Act high-risk deadline moved to 2028. Article 12 logging did not move with it.
The Digital Omnibus gave medical AI two more years. It did not give anyone a way to record a year that has already passed. What changed, and the one duty you cannot backfill.
Read → Provenance · 9 minTamper-evident audit logs for clinical AI: what immutable really requires
Keeping logs for years is not the same as keeping them trusted. Learn what makes a clinical-AI audit log genuinely tamper-evident and independently verifiable.
Read → Provenance · 9 minModel cards are not proof: transparency documents versus verifiable provenance
Model cards and frameworks describe an AI system. They do not prove what it did. Learn the difference between transparency documents and verifiable provenance.
Read → HIPAA · 9 minPut your AI scribe in your HIPAA risk analysis: the step small practices miss
OCR ties most penalties to risk-analysis gaps, and your AI scribe is often missing from it. Learn how a small practice documents the scribe in its SRA.
Read → Telehealth · 9 minSigned clinical orders: proving a telehealth prescription came from your clinician
Voice clones and spoofed orders threaten telehealth. Learn how cryptographically signed clinical orders prove a prescription truly came from your clinician.
Read → Governance · 9 minGovernance, security, and provenance: the third pillar of clinical-AI trust
Most clinical-AI trust advice covers governance and security, then stops. Learn why verifiable provenance is the missing third pillar, and how to add it.
Read → Provenance · 9 minWhich AI model read this scan? Tamper-evident imaging provenance for small centers
When an AI-assisted read is challenged, can you prove which model version read the scan on intact images? Build a tamper-evident imaging provenance record.
Read → HIPAA · 9 minPHI-free HIPAA access auditing: prove who touched a record without exposing it
Access logs often widen your PHI footprint. Learn how PHI-free, tamper-evident access auditing proves who touched which record without exposing patient data.
Read → Telehealth · 9 minVerify a telehealth patient is real, not a deepfake, before you prescribe
Synthetic patients now book telehealth visits to obtain prescriptions. Learn how to verify a real, live patient with signed proof before you prescribe.
Read → Provenance · 9 minProve an AI scribe note is genuine: the audit trail small practices need
AI scribe notes get questioned months later. Learn to build a tamper-evident, PHI-free audit trail that proves what your model captured and who signed it.
Read → Compliance · 10 minHow to answer a hospital's AI security questionnaire with proof
Turn a hospital's AI security review into a fast win. Build a reusable evidence pack that proves your model, access, and controls, not just your promises.
Read → Provenance · 11 minWhat clinical-AI decision provenance is, and why every AI decision needs a receipt
When an AI decision reaches a patient and is later questioned, no one can prove what happened. Here is the receipt layer that changes that.
Read → Compliance · 12 minFDA Section 524B, explained: what "reasonable assurance of cybersecurity" actually requires
A plain guide to the three §524B obligations, the June 2025 final guidance, and the evidence an FDA submission actually needs.
Read → HIPAA · 11 minIs a clinical-AI audit trail HIPAA-compliant? Audit controls and accounting of disclosures
How a tamper-evident, PHI-free audit trail supports HIPAA §164.312(b) and §164.528, and why ordinary logs fail the test.
Read → Post-quantum · 12 minWhy post-quantum cryptography matters for implants: harvest now, forge later
Implants run for a decade inside a realistic quantum window and are rarely re-secured. How post-quantum identity migrates a device without a recall.
Read → Compliance · 12 minThe unpatchable medical device problem and the FDA compensating-control answer
You cannot patch a 12-year-old infusion pump. How FDA compensating controls and a sealed residual-risk dossier bring the risk to acceptable.
Read → Provenance · 12 minNon-device by design: staying on the right side of the FDA clinical decision support line
The FDA CDS fourth criterion separates a regulated device from software that supports it. Why attesting a decision, not rendering it, stays non-device.
Read → Compliance · 12 minAIBOM for healthcare: CISA and CycloneDX ML-BOM for clinical AI
An AI bill of materials inventories the model, datasets, and lineage behind clinical AI. The standards stack, and the missing signed-provenance piece.
Read → Provenance · 12 minHow to choose between verifiable AI and AI governance (and tell which a vendor actually does)
Governance documents and manages risk. Verifiable AI proves, per decision, that a model was genuine. A buyer guide to which layer you need.
Read → Liability · 14 minWho is liable when a clinical AI decision is wrong?
When an AI-assisted decision harms a patient, who is accountable: the clinician, the hospital, or the AI vendor? How the evidence record decides. Includes an accountability mapper.
Read → Governance · 12 minShadow AI in hospitals: finding and governing the clinical AI you did not authorize
Clinicians are using AI tools no one approved, and PHI is leaving the building. How to discover, govern, and verify it. Includes an exposure calculator.
Read → HIPAA · 13 minThe proposed 2025 HIPAA Security Rule update: mandatory MFA, encryption, and clinical AI
The 2025 NPRM would make MFA, encryption, and audit controls mandatory. What changes, and what it means for clinical AI. Includes a readiness checklist.
Read →What we write about.
Clinical-AI decision provenance, FDA §524B and the CDS non-device line, HIPAA audit controls and accounting of disclosures, AIBOM for clinical AI, EU AI Act obligations, the NIST AI RMF, and post-quantum security for implants and long-retention records. If a claim cannot be checked or a statistic cannot be attributed, it does not appear.
Proof for every clinical decision.
Bring a decision, an access flow, or a device, and verify the evidence yourself, without PHI, and without trusting us.