Protect PHI at the proxy layer across
Hospitals, telehealth platforms, and life sciences companies handle the most sensitive data in any industry and are adopting AI faster than they have built governance for it. Igris redacts protected health information before it leaves the network, creates the HIPAA and GDPR Article 9 audit evidence examiners require, and keeps every AI workload inside approved boundaries.
Clinical Documentation AI
Voice-to-note AI tools are one of the fastest-growing productivity investments in clinical settings. The risk is embedded in exactly what makes the transcripts useful — they are verbatim records of what happened in the room. Patient names, diagnoses, medication names, dates of birth, and insurance identifiers appear naturally in every recording. If those transcripts are sent directly to an external LLM provider without redaction, the clinical team has transmitted protected health information to a third party without a documented control in place. That is a HIPAA Security Rule violation, a potential HITECH Act breach notification event, and for European patients, a GDPR Article 9 special-category data exposure. A clinical note that contains the wrong patient's identifiers because records were commingled in an LLM context is not just a regulatory problem — it is a patient safety event waiting to happen downstream.
Igris Guard sits between the clinical documentation tool and the LLM provider, scanning every transcript before it leaves the network. PII redaction policies strip patient names, date-of-birth references, insurance identifiers, and medication combinations tied to specific individuals automatically. Encrypted body logging creates the audit trail that HIPAA Security Rule audit controls require, with a configurable retention window and permanent deletion enforced when the window closes. Igris Lens gives the clinical informatics team a live view of redaction events by volume and category, so the HIPAA Privacy Officer can see how often PHI is appearing in documentation prompts and what types are being caught.
Clinicians get the documentation speed of AI-assisted note generation. The organization gets an enforceable control at the transmission layer and a HIPAA-compliant audit record ready for OCR review without manual reconstruction. For EU patients, GDPR Article 9 special-category data obligations are met at the same layer, automatically, on every note.
Drug Interaction Checker
Pharma companies and clinical research organizations using LLMs to check drug interactions in clinical trial datasets are working with two categories of data that must never reach an external provider without documented controls: patient-level identifiers carrying HIPAA and GDPR obligations, and proprietary trial identifiers, compound codes, and dosing protocols carrying intellectual property sensitivity. A bulk query that accidentally sends a large slice of trial data to an external LLM is not recoverable. The FDA's 21 CFR Part 11 audit trail requirement does not distinguish between intentional and accidental transmission: the question the examiner asks is whether every interaction with trial data was logged, controlled, and auditable.
Igris Guard applies content guard policies that redact patient IDs and trial-specific identifiers before any prompt reaches the LLM, with custom pattern support so proprietary compound codes and internal project references are caught alongside standard PII. Allowed model lists restrict the workload to LLMs reviewed and approved for clinical data. Rate limiting prevents a runaway batch query from exposing large volumes of trial data in a single uncontrolled burst. Igris Lens logs every call with its timestamp, model, connection, and policy outcome, creating the immutable audit record that satisfies FDA 21 CFR Part 11 electronic records requirements and GDPR Article 5 data minimization principles. For Indian participants, DPDP Act 2023 obligations are addressed by the same redaction layer.
Clinical trial LLM pipelines run with the speed of automated interaction checking and the governance posture of a controlled audit environment. The organization can walk into an FDA inspection with a complete log of every LLM call made against trial data — assembled automatically, not reconstructed from fragments under examination deadline pressure.
Patient-Facing Health Chatbot
When a telehealth platform deploys an AI chatbot for symptom checking, patients share their current medications, prior diagnoses, mental health history, and full medical background. The risk is bidirectional: patient inputs contain PHI that must be redacted before reaching the LLM, but LLM responses can also re-surface PHI in ways the original prompt did not intend — a model incorporating earlier context and returning a response naming a medication or condition mentioned three turns ago has just created an outbound PHI event. Under HIPAA, both directions are in scope. Under GDPR Article 9, health data is special-category data regardless of which direction it travels. Under India's DPDP Act 2023, health data is sensitive personal data with explicit consent and protection obligations. A chatbot that returns health guidance contaminated by another patient's context is not just a compliance failure — it is a clinical risk.
Igris Guard deploys PHI detectors on the chatbot connection that inspect both inbound patient messages and outbound LLM responses before either crosses the governance boundary. Patient names, medication identifiers, diagnosis references, and health condition patterns are redacted in both directions automatically. Igris Sentinel governs every tool call the chatbot agent makes, enforcing an allowlist that prevents the agent from accessing medical records or external systems beyond what the current session explicitly permits. Token limits prevent patients from pasting large document blocks into the chat. Igris Lens surfaces cost anomaly alerts when unusually complex medical conversations spike token usage beyond expected parameters.
Patients interact with a symptom-checking chatbot that is genuinely safe in both directions. HIPAA, GDPR Article 9, and DPDP Act 2023 obligations are addressed by the same governance layer simultaneously, for every session, without per-session configuration.
Medical Research Literature Analysis
Research teams in pharma and life sciences using LLMs to synthesize medical literature at scale face a data protection problem distinct from the clinical side: the sensitivity is not patient PHI, it is proprietary intellectual property. Unpublished findings, internal project codenames, compound identifiers under development, and trial outcome data not yet disclosed are all present in the prompts that flow to external LLM providers. If any of those terms reach an external provider, the exposure is an IP leak with competitive consequences that no compliance framework addresses after the fact. When multiple research projects run LLM workloads through the same integration, there is no isolation between projects, no per-project cost visibility, and no way to audit which research initiative sent what to which model.
Igris Guard supports custom detection patterns, so internal project codes, proprietary compound names, and unpublished trial identifiers are defined once and caught automatically before any prompt leaves the network. Each research project gets its own isolated connection in Igris, so query context from one project cannot bleed into another's interaction history. Igris Lens tracks cost per connection, giving research operations the per-project spend data that feeds AI cost attribution across initiatives and flags any project whose model usage is running outside expected parameters.
Research teams run large-scale literature analysis pipelines with the speed that LLMs enable and the IP protection that a proxy-layer enforcement control provides. Each project's work stays isolated from every other. Proprietary terms never reach an external provider. When the research director asks what each initiative spent on AI last quarter, the answer comes from Lens.
Prior Authorization AI Agent
Prior authorization is one of the highest-volume, most PHI-intensive workflows in US healthcare, and AI agents are being deployed to handle it at scale — reviewing diagnosis codes, treatment plans, formulary rules, and member histories. The governance problem is structural: a prior authorization agent that makes tool calls across a health system's records environment has legitimate access to a broad slice of PHI, and HIPAA's minimum necessary standard applies to every individual action it takes. If the agent accesses records beyond what the specific authorization request requires, that is a HIPAA minimum necessary violation regardless of whether the excess access was intentional. Most healthcare organizations deploying these agents today have no technical control that enforces access scope at the tool call level.
Igris Sentinel governs every tool call the prior authorization agent makes, enforcing an allowlist of permitted record types and systems so the agent cannot access data beyond the scope of the current authorization request. Guard applies PHI redaction to any prompt element that contains member identifiers not required for the specific decision task. The full audit trail logs every agent action — which records were accessed, which tool calls were made, which decisions were produced, and which policy was applied at each step — creating the HIPAA audit control artifact that an OCR investigation would require.
Prior authorization AI scales to thousands of decisions a day with an enforceable HIPAA minimum necessary control at every tool call. The audit trail satisfies OCR audit control requirements automatically, without manual log assembly, from the first authorization request the agent processes.
Mental Health and Behavioral Health Documentation AI
Mental health and behavioral health documentation carries protections that go beyond standard HIPAA — substance use disorder records fall under 42 CFR Part 2, certain state mental health laws impose additional restrictions, and the sensitivity of what appears in a therapy session transcript is categorically different from a general clinical note. When a psychiatrist or therapist uses an AI tool to generate session documentation, the transcript contains diagnostic impressions, medication names, trauma disclosures, crisis risk assessments, and personal history that, if exposed, creates risks not limited to regulatory penalties. The patient safety and patient trust stakes are uniquely high.
Guard applies an elevated PHI redaction policy to behavioral health connections specifically, configured to catch the additional categories of sensitive terms in mental health documentation: diagnostic labels, medication classes associated with psychiatric treatment, crisis-related language patterns, and substance-related identifiers falling under 42 CFR Part 2 scope. The policy can be configured to deny rather than redact when the sensitivity level of a detected term requires complete exclusion. Encrypted body logs with a shortened retention window reflect the heightened data minimization obligation for this record category. Lens gives the compliance team a separate visibility layer for behavioral health AI activity, isolated from general clinical documentation.
Mental health documentation teams get AI-assisted note generation with a protection posture that matches the sensitivity of the records it is generating. Behavioral health PHI never reaches an external LLM without the governance layer enforcing controls that go beyond standard HIPAA — technically enforced, not policy-dependent, on every session note.
Bring HIPAA-grade governance to your AI
See how healthcare teams protect PHI on every call and produce HIPAA, HITECH, and FDA 21 CFR Part 11 audit evidence without manual reconstruction.