Skip to content
Illustrative scenario

Not based on a specific customer deployment. The company, figures, decisions, and outcomes below are a constructed example that shows how Intended’s mechanism applies to this kind of problem. They are not measured results from a named customer. Where we publish a real, attributed customer outcome, we will say so explicitly.

← All case studies
Healthcare

HIPAA-Aware Governance for AI Patient-Data Operations

Consider a health system whose AI agents handle appointment scheduling, medical record access, billing automation, and clinical decision support — all touching PHI under HIPAA.

01 · the challenge

The kind of problem this addresses.

Findings
HIPAA audit gaps from inadequate AI access documentation
Fines
exposure from improper AI access to PHI
No trail
AI-driven PHI access events without tamper-proof audit trails

02 · how it works

See the difference.

AI agent requests patient records

Patient: J. Doe, MRN: 847291

System returns records

No authorization check, no logging

AI processes PHI

Full record access, no scope limits

Flat log entry (maybe)

No evidence chain, no tamper detection

03 · the solution

What they deployed.

  • Installed HR Ops domain pack plus custom Healthcare extension for PHI-specific intents
  • Configured CRITICAL risk level for all PHI access with mandatory dual authorization
  • Scoped authority tokens to individual patients with 60-second TTL and read-only permissions
  • Connected Epic EHR and internal scheduling systems via Intended connectors
  • Generated tamper-evident evidence bundles for every PHI access event, governed by the healthcare policy pack

04 · implementation

From zero to governed.

Phase 1

Assessment

Map AI agent PHI access patterns. Identify unprotected access paths across clinical systems.

Phase 2

Deploy

Install the Healthcare domain pack. Configure PHI access policies, dual-authorization workflows, and token scoping.

Phase 3

Validate

Run shadow mode in parallel with existing systems to verify complete PHI access capture before enforcing.

Phase 4

Enforce

Switch to enforcement. Every PHI access then carries a tamper-proof, independently verifiable evidence chain.

05 · illustrative outcomes

What this is designed to deliver.

Modeled figures for this scenario — what the workflow above is built to achieve, not measured results from a named customer.

0%

PHI access token-gated

Dual authorization for CRITICAL access

0%

PHI access logged

With tamper-proof evidence

0s

Token TTL for PHI access

Auto-expires, no lingering access

0-click

Auditor verification

Independent of self-reported logs

06 · decision replay

Example decisions, full trace.

Sample decision records that show the shape of the evidence Intended produces. Illustrative, not drawn from a live customer’s logs.

2026-03-15 07:22:14healthcare.phi.record-accessRISK: 72/100ALLOW28ms

AI scheduling agent requests patient demographics for appointment confirmation

Resolved by: Policy: demographics-only access auto-approved with single auth

2026-03-15 08:14:33healthcare.phi.clinical-recordsRISK: 95/100ESCALATE31ms

AI clinical support agent requests full medical history for treatment recommendation

Resolved by: Dr. Martinez (dual authorization in 1m 22s)

2026-03-15 09:45:07healthcare.phi.billing-dataRISK: 58/100ALLOW24ms

AI billing agent requests insurance information for claims processing

Resolved by: Policy: billing scope access with system auth

2026-03-15 11:02:18healthcare.phi.bulk-exportRISK: 99/100DENY19ms

AI analytics agent requests bulk patient data export for population health report

Resolved by: Policy: bulk PHI export requires IRB approval + CISO sign-off

the takeaway

The hard part of HIPAA for AI is independent verifiability: an auditor should be able to confirm every AI access to patient data without trusting self-reported logs. A tamper-proof cryptographic chain makes each access provable rather than asserted.

Why this pattern matters — not a customer quote.

Start protecting patient data

Free to start. See every AI decision from day one.

Intended — Intent Verification Infrastructure for Autonomous Agents