Healthcare · Clinical AI

Clinical-AI governance, before a patient is touched

AI deployed inside healthcare carries PHI exposure, FDA SaMD oversight, clinical-workflow risk, and biased-model liability — risks that are easier to govern up front than to remediate after an incident. AltiriOS scopes that frame, writes it down, and routes regulatory submissions when a model falls inside FDA scope.

At a Glance
Who this is for
Covered entities, business associates, health-tech vendors, and clinical-AI developers evaluating or operating AI systems in clinical environments.
Primary frameworks
HIPAA Privacy & Security Rules, NIST AI RMF, FDA SaMD guidance (IMDRF SaMD WG/N12), ONC §170.315.
Modalities covered
Diagnostic models, clinical decision support (CDS), ambient documentation, patient-facing chatbots, revenue-cycle automation.
Delivery model
Foundation assessment + Advisor retainer.
Residency
Client PHI environments — no Altiri data ingestion.
Ownership
Client owns all artifacts.
The Problem

Clinical AI Sits in a Different Risk Frame

Clinical-AI deployment is constrained by HIPAA Privacy and Security Rules plus §164.312 technical safeguards, by FDA Software-as-a-Medical-Device oversight for any model whose output drives diagnosis or treatment, and by an escalating patchwork of state telehealth and AI laws that treat clinical-model outputs differently than software features in other industries.

Most organizations have AI pilots running — diagnostic models, ambient documentation, CDS tools, patient-facing chatbots, RCM automation — without a model inventory tiered by patient impact, without a verified BAA posture on every model vendor, and without a documented bias-evaluation methodology against the populations they actually serve. The risk surface grows with every new model before the governance framework catches up.

How This Works

Clinical-AI Governance, From Inventory to Reporting

Four concrete deliverables — model inventory, PHI exposure mapping, bias evaluation methodology, and SaMD scope determinations — written down, owned by you, on infrastructure you designate.

Model inventory scoped to clinical risk

A registry tiered by patient-impact severity — not by technical sophistication. Diagnostic models sit at the top, ambient documentation and RCM automation elsewhere. Each model is documented with vendor, deployment environment, training-data lineage, applicable oversight regime, and the re-evaluation cadence tied to its tier.

PHI exposure map for every AI touchpoint

Callouts where PHI is created, transformed, or inferred — across the full clinical-AI surface, including ambient documentation, CDS, patient-facing chatbots, and downstream billing. The map shows where §164.312 technical safeguards apply and verifies Business Associate Agreement coverage per model vendor.

Bias evaluation against the populations you serve

A written methodology: which population cohorts the model is evaluated against, sample-size discipline, and the performance thresholds we recommend for re-evaluation. Threshold breaches trigger a written variance and re-deployment decision rather than a silent update.

SaMD scope decision, in writing

A documented determination of whether a given model falls inside FDA Software-as-a-Medical-Device oversight, using the IMDRF SaMD WG/N12 framework and current FDA guidance. When the answer is yes, we hand off cleanly to a SaMD regulatory consultant for the submission pathway rather than re-doing the scope work.

Engagement Model

Pricing & Engagement

Two tiers. Foundation is fixed-fee and produces the initial risk frame; Advisor is a monthly retainer that keeps the model inventory, BAA posture, and bias reporting current as your AI surface evolves.

Tier Scope Deliverable Fee
Foundation One-time clinical-AI risk assessment: model inventory tiered by patient impact, PHI exposure map covering §164.312 technical safeguards and BAA posture per model vendor, written bias evaluation methodology with thresholds and re-evaluation cadence, HIPAA Privacy/Security + §164.312 gap analysis, documented SaMD scope determinations per model. Written assessment report; model risk register; 90-day remediation roadmap covering gaps requiring action before the next bias re-evaluation cycle. $28,000 fixed fee
Advisor Monthly retainer for ongoing clinical-AI governance: quarterly model inventory refresh as new models deploy, vendor BAA review on each new AI procurement, bias monitoring cadence with written variance reporting, board-and-audit-committee reporting template, named AltiriOS clinical-AI specialist. Continuously-maintained clinical-AI risk posture, including bias findings before they become a liability exposure. $5,500 / month retainer
Ownership

Ownership & Data Handling

Every artifact, risk register, model classification, PHI exposure map, bias evaluation methodology, and SaMD scope determination delivered as part of your engagement is owned by you, the client — not by Altiri. Altiri retains no derivative copy of your risk register, model inventory, or document conclusions once the engagement closes; we retain redacted, anonymized engagement notes scoped to the practitioner's own internal QA, not your record.

We do not ingest PHI into any AltiriOS tooling. Model evaluation, vendor assessment, and bias testing happen on infrastructure you designate — your environment, your de-identification controls, your data. If population-level outcomes data is needed for bias evaluation, we scope the methodology and the re-identification controls, then hand the data-side work to your team or your data partner. Source-conversion to standard formats is available on request, so your record remains consumable by tools other than ours without an active retainer relationship.

Anchored in HIPAA Privacy & Security Rules and NIST SP 800-66r2, cross-walked to the NIST AI RMF, FDA SaMD guidance (IMDRF SaMD WG/N12), and ONC §170.315.

Engagements led by a credentialed healthcare-AI governance specialist [credential placeholder — pending].
FAQ

Common Questions

Seven questions healthcare organizations ask most before starting a clinical-AI governance engagement.

What this engagement is and is not

This is a clinical-AI governance and risk advisory engagement focused on the specific considerations of deploying AI systems in healthcare — HIPAA exposure, FDA SaMD oversight, biased-model liability, and clinical-workflow risk. It is not a HIPAA consulting engagement, not a SaMD regulatory submission practice, not an EHR implementation project, and not a clinical-research service. We do not diagnose, treat, or triage clinical questions. We scope, document, and govern the AI systems your organization is deploying — and route regulatory submissions to a SaMD regulatory consultant when a model inside your inventory falls inside FDA oversight.

How this differs from a generic consulting practice for HIPAA

General HIPAA consulting addresses administrative, physical, and technical safeguards across an organization's full data environment. Clinical-AI governance intersects HIPAA at specific, narrow points — where PHI is created, transformed, inferred, or surfaced to a model — and those points drift as soon as a model is retrained, fine-tuned, or swapped for a vendor release. We treat HIPAA §164.312 technical safeguards as one input in a wider risk frame that also covers model lifecycle, vendor BAA posture per model, FDA SaMD scope, and bias-evaluation discipline against the populations your organization serves. The deliverable is a model risk register and a bias evaluation methodology — not a generic HIPAA binder.

What happens when a clinical-AI model produces a biased output

Biased outputs are an operating risk for clinical-AI systems, not an edge case. We scope bias-evaluation methodology into the engagement by asking: against which population cohorts is the model evaluated? what sample sizes are required before each re-evaluation? which performance disparities constitute a re-deployment block versus an acceptable variance? Each model is tiered by patient-impact severity, not by technical sophistication — a patient-facing chatbot and a CDS model are evaluated on different thresholds. The deliverable is a written methodology, re-evaluation cadence tied to model release cycles, and a board-and-audit-committee reporting template that surfaces bias findings before they become a liability exposure.

When AltiriOS engages versus when you need a SaMD regulatory consultant

AltiriOS determines, in writing, whether a given model falls inside FDA Software-as-a-Medical-Device (SaMD) oversight, using the IMDRF SaMD WG/N12 framework and current FDA guidance. If the model is in scope — for example, a model whose output drives diagnosis, treatment, or clinical decision-making — we produce a documented scope determination and route you to a qualified SaMD regulatory consultant for the submission, quality-system regulation (QSR / 21 CFR 820), and pre-market pathway work (510(k), De Novo, or PMA). We do not file SaMD submissions. Our engagement is designed to leave no ambiguity at the regulatory hand-off so your SaMD consultant steps into a documented model classification rather than re-doing the scoping work.

How PHI is handled in vendor evaluations and model assessments

We do not ingest PHI into any AltiriOS tooling. Model evaluation, vendor BAA cover analysis, and bias testing happen on infrastructure you designate — your environment, your data, your de-identification posture. We work from data flow diagrams, vendor architecture documents, BAA copies, and model behavior data you provide; if population-level outcomes data is needed for bias evaluation, we scope the evaluation methodology and the re-identification controls, then hand the data-side work to your team or your data partner. The risk register and all artifacts produced are owned by you — Altiri retains no derivative copy containing PHI or any patient-level data after the engagement closes.

How the engagement is priced and scoped

Foundation is a one-time, fixed-fee clinical-AI risk assessment — your scope on engagement signing (model count, deployment modalities, population cohorts for bias evaluation) determines the deliverable; no hourly overruns creep in mid-engagement. Advisor is a flat monthly retainer priced against named deliverables (quarterly model inventory refresh, vendor BAA review on each new AI procurement, bias monitoring cadence, board-and-audit-committee reporting), not against seat count or model count. Engagement scope and any change in scope (a new model added mid-retainer, a SaMD scope determination that requires additional work) are agreed in writing before work begins at any tier.

What deliverables an organization receives at the end

At the end of Foundation you receive: a written assessment report covering model inventory, PHI exposure map, bias evaluation methodology, HIPAA + §164.312 gap analysis, and SaMD scope determinations; a model risk register tiered by patient-impact severity; a 90-day remediation roadmap for gaps requiring action before the next bias re-evaluation cycle. At Advisor, you retain a continuously-maintained risk posture — quarterly model inventory refresh, vendor BAA posture per model, bias monitoring cadence, board reporting — and a named AltiriOS clinical-AI specialist. Every artifact is owned by you, in your format, on your infrastructure. Source-conversion to standard formats is available on request so your record remains consumable by tools other than ours without an active retainer.

Need broader AI program governance — not just healthcare-specific?
Our cross-vertical AI governance engagements cover the full NIST AI RMF frame, board-and-audit-committee reporting templates, and AI vendor rationalization across regulated industries.
See All Services →
Want a focused conversation about healthcare AI governance?
Tell us what model is in scope and we'll route the right AltiriOS specialist to follow up.
Start a Consultation →