Governance and assurance

Turn AI Policy Into Evidence

Follow one healthcare requirement from explicit content and disclosure controls through monitored decisions, bounded measurement, request-level evidence, and accountable change history.

What this answers

Transcript

A policy document can say that patient identifiers must be protected and analysts may receive trends, not individual records. That document cannot show which requests matched, what the runtime did, how the rule was tested, or who changed it. Assurance begins when policy intent becomes observable evidence. A review meeting should not depend on somebody reconstructing that story from screenshots, provider logs, and a spreadsheet of approvals. The live content policy makes the ingress boundary explicit. PHI Guard applies to all routed traffic at the strictest sensitivity tier and fails closed. It blocks a detected United States Social Security number, while health information and secrets remain in monitor mode. Those actions are deliberately different. Block rejects the affected request. Monitor records what matched without changing traffic. Scope, detection type, action, failure posture, enabled state, and policy version are all reviewable as one control. Monitor-first operation lets the team observe a rule before making it disruptive. Reviewers can examine affected workload, matched decisions, and false-positive risk, then tighten a deterministic rule deliberately. PrivacyFirst keeps that operating choice explicit instead of treating every detector as an inline block. For this evidence chain, PHI Guard shows one enforced Social Security number rule beside two monitor-only rules, so the policy can protect a clear boundary without pretending every classification is equally certain. The audience boundary is a separate live control. Aggregate-Only — Patient Records applies to analysts and viewers. It permits aggregates, trends, and averages, requires a minimum cohort of five, and rewrites a violating response to the permitted grain. Individual identifiers and per-record values remain banned for that audience. The protected scope names the patient record and medical-record-number fields at sensitivity level three. The product also states the limitation clearly: this response-layer control complements data-layer access control; it does not replace it. Before enforce mode is treated as acceptable, PrivacyFirst attacks the exact policy version. In the latest shipped-corpus run, four of two hundred and fifty probes violated the rule, two were ambiguous, and two hundred and forty-four resisted. Measured slippage was one point six percent, with the confidence interval and ninety percent human-judge agreement visible beside the score. The product calls this result what it is: a measured lower bound on observed adversarial risk, not proof of safety. The family breakdown shows whether pressure came from record extraction, prompt injection, or aggregate-boundary differencing. Testing is connected to runtime evidence, but the film does not pretend that every privacy action came from the same policy. On this exact request, PrivacyFirst recorded two personal-data detections and linked the redaction decision to the affected trace. The retained body remains redacted server-side, with obvious synthetic replacement markers instead of patient data. The active retention period is stated in the interface, and every retained-body read is audited. Protection appears where it occurred in the session, not as an alert detached from the request. The final question is accountability. The unified audit log records the policy subject, actor, time, category, and change summary. Here, PHI Guard was updated with the Social Security number block, and the aggregate-only policy moved from monitor to enforce with risk acceptance recorded. The policy filter keeps this review narrow, while the same log also covers provider, key, role, logging, and denied-access events. The evidence chain is now concrete: requirement, configured control, measured residual risk, runtime decision, and accountable change. That is a defensible assurance story without turning a passed test into a promise the evidence cannot support. Bring us one A.I. policy your organization needs to defend. We will show you the live control, the measured residual risk, the runtime decision, and the audit trail behind it. Book a live demo at PrivacyFirst dot A.I.