Industry starterIndustry-Specific

Healthcare (U.S. — HIPAA) policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Help U.S. health care teams govern AI workflows that handle protected health information. The template maps selected HIPAA Privacy and Security Rule requirements to configurable gateway controls. It covers Safe Harbor identifiers, minimum-necessary access, bulk extraction, retention and human review. Validate the configuration and all safeguards outside the gateway before use.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

US

Source references

8 source references

Control areas

5 mapped control areas

Deployment options

Regulated SaaS, Clinical zero-retention

Source frameworks, standards and obligations

HIPAA Privacy Rule (45 CFR §164.500-534)HIPAA Security Rule (45 CFR §164.302-318)HITECH Act (42 U.S.C. § 17901 et seq.)42 CFR Part 2 (Substance Use Disorder)HHS Guidance on AI in HealthcareONC Cures Act Final RuleCMS Interoperability RulesFDA Software as Medical Device (SaMD)

Control areas mapped by this template

PHI protection
Access control
Audit logging
Clinical safety
Data loss prevention

Deployment options

Regulated SaaS
Clinical zero-retention

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.