AI deployed inside healthcare carries PHI exposure, FDA SaMD oversight, clinical-workflow risk, and biased-model liability — risks that are easier to govern up front than to remediate after an incident. AltiriOS scopes that frame, writes it down, and routes regulatory submissions when a model falls inside FDA scope.
Clinical-AI deployment is constrained by HIPAA Privacy and Security Rules plus §164.312 technical safeguards, by FDA Software-as-a-Medical-Device oversight for any model whose output drives diagnosis or treatment, and by an escalating patchwork of state telehealth and AI laws that treat clinical-model outputs differently than software features in other industries.
Most organizations have AI pilots running — diagnostic models, ambient documentation, CDS tools, patient-facing chatbots, RCM automation — without a model inventory tiered by patient impact, without a verified BAA posture on every model vendor, and without a documented bias-evaluation methodology against the populations they actually serve. The risk surface grows with every new model before the governance framework catches up.
Four concrete deliverables — model inventory, PHI exposure mapping, bias evaluation methodology, and SaMD scope determinations — written down, owned by you, on infrastructure you designate.
A registry tiered by patient-impact severity — not by technical sophistication. Diagnostic models sit at the top, ambient documentation and RCM automation elsewhere. Each model is documented with vendor, deployment environment, training-data lineage, applicable oversight regime, and the re-evaluation cadence tied to its tier.
Callouts where PHI is created, transformed, or inferred — across the full clinical-AI surface, including ambient documentation, CDS, patient-facing chatbots, and downstream billing. The map shows where §164.312 technical safeguards apply and verifies Business Associate Agreement coverage per model vendor.
A written methodology: which population cohorts the model is evaluated against, sample-size discipline, and the performance thresholds we recommend for re-evaluation. Threshold breaches trigger a written variance and re-deployment decision rather than a silent update.
A documented determination of whether a given model falls inside FDA Software-as-a-Medical-Device oversight, using the IMDRF SaMD WG/N12 framework and current FDA guidance. When the answer is yes, we hand off cleanly to a SaMD regulatory consultant for the submission pathway rather than re-doing the scope work.
Two tiers. Foundation is fixed-fee and produces the initial risk frame; Advisor is a monthly retainer that keeps the model inventory, BAA posture, and bias reporting current as your AI surface evolves.
| Tier | Scope | Deliverable | Fee |
|---|---|---|---|
| Foundation | One-time clinical-AI risk assessment: model inventory tiered by patient impact, PHI exposure map covering §164.312 technical safeguards and BAA posture per model vendor, written bias evaluation methodology with thresholds and re-evaluation cadence, HIPAA Privacy/Security + §164.312 gap analysis, documented SaMD scope determinations per model. | Written assessment report; model risk register; 90-day remediation roadmap covering gaps requiring action before the next bias re-evaluation cycle. | $28,000 fixed fee |
| Advisor | Monthly retainer for ongoing clinical-AI governance: quarterly model inventory refresh as new models deploy, vendor BAA review on each new AI procurement, bias monitoring cadence with written variance reporting, board-and-audit-committee reporting template, named AltiriOS clinical-AI specialist. | Continuously-maintained clinical-AI risk posture, including bias findings before they become a liability exposure. | $5,500 / month retainer |
Every artifact, risk register, model classification, PHI exposure map, bias evaluation methodology, and SaMD scope determination delivered as part of your engagement is owned by you, the client — not by Altiri. Altiri retains no derivative copy of your risk register, model inventory, or document conclusions once the engagement closes; we retain redacted, anonymized engagement notes scoped to the practitioner's own internal QA, not your record.
We do not ingest PHI into any AltiriOS tooling. Model evaluation, vendor assessment, and bias testing happen on infrastructure you designate — your environment, your de-identification controls, your data. If population-level outcomes data is needed for bias evaluation, we scope the methodology and the re-identification controls, then hand the data-side work to your team or your data partner. Source-conversion to standard formats is available on request, so your record remains consumable by tools other than ours without an active retainer relationship.
Seven questions healthcare organizations ask most before starting a clinical-AI governance engagement.
This is a clinical-AI governance and risk advisory engagement focused on the specific considerations of deploying AI systems in healthcare — HIPAA exposure, FDA SaMD oversight, biased-model liability, and clinical-workflow risk. It is not a HIPAA consulting engagement, not a SaMD regulatory submission practice, not an EHR implementation project, and not a clinical-research service. We do not diagnose, treat, or triage clinical questions. We scope, document, and govern the AI systems your organization is deploying — and route regulatory submissions to a SaMD regulatory consultant when a model inside your inventory falls inside FDA oversight.
General HIPAA consulting addresses administrative, physical, and technical safeguards across an organization's full data environment. Clinical-AI governance intersects HIPAA at specific, narrow points — where PHI is created, transformed, inferred, or surfaced to a model — and those points drift as soon as a model is retrained, fine-tuned, or swapped for a vendor release. We treat HIPAA §164.312 technical safeguards as one input in a wider risk frame that also covers model lifecycle, vendor BAA posture per model, FDA SaMD scope, and bias-evaluation discipline against the populations your organization serves. The deliverable is a model risk register and a bias evaluation methodology — not a generic HIPAA binder.
Biased outputs are an operating risk for clinical-AI systems, not an edge case. We scope bias-evaluation methodology into the engagement by asking: against which population cohorts is the model evaluated? what sample sizes are required before each re-evaluation? which performance disparities constitute a re-deployment block versus an acceptable variance? Each model is tiered by patient-impact severity, not by technical sophistication — a patient-facing chatbot and a CDS model are evaluated on different thresholds. The deliverable is a written methodology, re-evaluation cadence tied to model release cycles, and a board-and-audit-committee reporting template that surfaces bias findings before they become a liability exposure.
AltiriOS determines, in writing, whether a given model falls inside FDA Software-as-a-Medical-Device (SaMD) oversight, using the IMDRF SaMD WG/N12 framework and current FDA guidance. If the model is in scope — for example, a model whose output drives diagnosis, treatment, or clinical decision-making — we produce a documented scope determination and route you to a qualified SaMD regulatory consultant for the submission, quality-system regulation (QSR / 21 CFR 820), and pre-market pathway work (510(k), De Novo, or PMA). We do not file SaMD submissions. Our engagement is designed to leave no ambiguity at the regulatory hand-off so your SaMD consultant steps into a documented model classification rather than re-doing the scoping work.
We do not ingest PHI into any AltiriOS tooling. Model evaluation, vendor BAA cover analysis, and bias testing happen on infrastructure you designate — your environment, your data, your de-identification posture. We work from data flow diagrams, vendor architecture documents, BAA copies, and model behavior data you provide; if population-level outcomes data is needed for bias evaluation, we scope the evaluation methodology and the re-identification controls, then hand the data-side work to your team or your data partner. The risk register and all artifacts produced are owned by you — Altiri retains no derivative copy containing PHI or any patient-level data after the engagement closes.
Foundation is a one-time, fixed-fee clinical-AI risk assessment — your scope on engagement signing (model count, deployment modalities, population cohorts for bias evaluation) determines the deliverable; no hourly overruns creep in mid-engagement. Advisor is a flat monthly retainer priced against named deliverables (quarterly model inventory refresh, vendor BAA review on each new AI procurement, bias monitoring cadence, board-and-audit-committee reporting), not against seat count or model count. Engagement scope and any change in scope (a new model added mid-retainer, a SaMD scope determination that requires additional work) are agreed in writing before work begins at any tier.
At the end of Foundation you receive: a written assessment report covering model inventory, PHI exposure map, bias evaluation methodology, HIPAA + §164.312 gap analysis, and SaMD scope determinations; a model risk register tiered by patient-impact severity; a 90-day remediation roadmap for gaps requiring action before the next bias re-evaluation cycle. At Advisor, you retain a continuously-maintained risk posture — quarterly model inventory refresh, vendor BAA posture per model, bias monitoring cadence, board reporting — and a named AltiriOS clinical-AI specialist. Every artifact is owned by you, in your format, on your infrastructure. Source-conversion to standard formats is available on request so your record remains consumable by tools other than ours without an active retainer.