How Does InferTrust™ Address HIPAA Requirements for AI Decision Records?

HIPAA requires integrity and confidentiality of protected health information. InferTrust™ creates tamper-evident AI decision records while keeping PHI within or

HIPAA-Aligned Decision Integrity

InferTrust™ (Patent Pending) was designed from the ground up with HIPAA requirements in mind, providing cryptographic decision integrity for AI-assisted healthcare decisions. The architecture ensures that protected health information is never unnecessarily duplicated or exposed in the decision record chain.

PHI Handling in Decision Records

InferTrust™ uses the Input Feature Hash (IFH) to prove what data the AI model evaluated without storing the raw clinical data in the decision record. The IFH is a one-way cryptographic hash: it proves the exact input the model received, but the original data cannot be reconstructed from the hash. This means auditors can verify decision integrity without accessing PHI, and the decision chain itself does not create a new PHI data store.

Access Controls and Audit Logging

InferTrust™ implements role-based access controls designed to align with HIPAA minimum necessary requirements. Access to decision records is logged and auditable. Administrative functions (policy configuration, threshold management, user provisioning) are separated from clinical decision record access with appropriate authorization controls.

Business Associate Agreements

illuminis is prepared to execute Business Associate Agreements with covered entities and business associates as appropriate. The BAA scope is designed to cover InferTrust™'s handling of any metadata that may constitute PHI, including encounter references, provider identifiers, and temporal data that could be linked to individual patients.