A field manual for regulated AI
INDEPENDENT / SOURCE-LED / 2026Compliance lives
in the system around
the model.
A precise, source-led guide to evaluating generative AI workflows that may involve PHI. No product, plan, or prompt is compliant by name alone.
CONTROL MAP / 01—07
- 01Role & data
- 02BAA scope
- 03Risk analysis
- 04Access
- 05Configuration
- 06Workforce
- 07Monitoring
FIELD MANUAL
Start with the question your team actually has.
Direct answerIs ChatGPT HIPAA compliant? The accurate answer depends on the product and configuration
11 min ↗02ProcurementBAA checklist for generative AI vendors
9 min ↗03GovernanceA practical AI risk analysis for healthcare teams
12 min ↗