Verigrey
Healthcare

PHI in an AI agent is a HIPAA breach waiting to happen. Prove it isn't.

Verigrey tests healthcare agents against HIPAA-derived controls — no PHI leakage, minimum-necessary enforced, no unauthorized clinical advice — with audit evidence for your BAA and regulators.

Live patient-record inspection
Record field · disclosure request
diagnosis history requested beyond scheduling scope
FLAGGED · minimum-necessary
PROVEevidence · 0x9a4d…2e11
Why agents are different here

This isn't a generic agent-risk problem.

Agents now touch records, scheduling, claims, and triage — and HIPAA's minimum-necessary rule is one agents routinely over-reach. A wrong clinical statement is patient harm, not just a compliance miss.

PHI everywhere
Agents touch records, scheduling, claims, and triage.
Minimum-necessary
HIPAA demands agents access only the PHI needed — a rule agents routinely over-reach.
Patient safety
A wrong clinical statement is harm, not just a compliance miss.
Common agent use cases

The agents this buyer is actually deploying.

Patient-support / scheduling agent

Handles appointment booking and patient inquiries.

FailureDiscloses PHI to the wrong patient or after a tool call.
FixDeepScan + RuntimeGuard.

Clinical documentation / summarization agent

Summarizes notes and records for clinicians.

FailurePulls PHI beyond minimum-necessary scope.
FixPolicyForge + DeepScan.

Claims / prior-auth agent

Processes claims and prior-authorization requests.

FailureLeaks or mishandles PHI across payers.
FixPolicyForge + ProofLedger.

Symptom / triage chatbot

Assesses patient symptoms and routes care.

FailureGives unauthorized clinical advice or misses a required escalation.
FixDeepScan + PolicyForge.
Specific risks

What keeps you up at night.

PHI leakage / wrong recipient

HIPAA

Agent discloses protected health information to the wrong patient or party.

Minimum-necessary violation

HIPAA

Agent pulls more PHI than the task actually requires.

Unauthorized clinical advice

FDA guidance

Triage agent gives guidance outside its authorized scope, missing an escalation.

Missing audit trail

HIPAA / HITRUST

No evidence exists to satisfy a BAA review or HITRUST audit.

How Verigrey solves it

Across the full lifecycle — Define to Prove.

DeepScan drives the agent to its actual disclosure boundaries, PolicyForge encodes minimum-necessary as a checkable rule, and ProofLedger produces the audit trail your BAA and regulators expect.

PolicyForge

Encodes minimum-necessary access and escalation rules as checkable, versioned tests.

DeepScan (adaptive testing)

Drives the agent through multi-turn, tool-mediated paths to find over-reach a static reviewer would miss.

ProofLedger

Produces regulator- and BAA-ready evidence for every disclosure decision the agent makes.

Regulation mapping

Tested against controls derived from your regime.

Regulation names are proof, not decoration — Verigrey doesn't claim to make you compliant. It tests against controls derived from these regimes and hands you the evidence.

HIPAA Privacy
Tested against: Authorized disclosure and minimum-necessary access to PHI.
HIPAA Security
Tested against: Technical safeguards around PHI handling and access.
HITRUST CSF
Tested against: Control-framework alignment for healthcare data protection.
FDA AI/ML guidance
Tested against: Boundaries on agent-issued clinical statements.
CCPA / CPRA
Tested against: Consumer health-data protection for California residents.
Filter by regulation
RegulationControl areaVerigrey policyLifecycle stageEvidence output
HIPAA PrivacyAuthorized disclosureMinimum-necessary access policyDefine / TestDisclosure trace record
HIPAA SecurityTechnical safeguardsPHI access-scope policyTest / ProtectAccess-scope enforcement log
HITRUST CSFControl framework alignmentFramework-mapped policy suiteProveHITRUST-mapped evidence pack
FDA AI/ML guidanceClinical statement boundariesEscalation-gate policyTestEscalation-compliance trace
CCPA / CPRAConsumer health dataData-boundary isolation policyTestPII-leak trace record
9× more violations found vs. standard red-team benchmarks
OWASP Agentic Top 10MITRE ATLASNIST AI RMF
triage_bot →pulled full diagnosis history for scheduling taskFLAGGEDminimum-necessary policy violatedevidence logged

See it catch a real violation.

Book a demo and watch Verigrey run against a scenario like the ones on this page.

Concerns

What we hear before the demo.

Can you sign a BAA?

A BAA is available on enterprise plans where applicable — we’ll confirm current terms before you deploy.

Where does our data live?

Verigrey deploys in your VPC or on-prem environment — PHI never leaves your network boundary.

Our EHR vendor already handles security.

Vendor and embedded-agent testing gives you independent evidence — not a claim in someone else’s compliance deck.

Where this fits

Part of the full assurance loop.

PHI risk starts before deployment — Define encodes minimum-necessary rules, Test drives the agent to its real disclosure boundaries, and Protect monitors the same rules on live traffic.

1
Define

PolicyForge

Plain-English rules → formal, checkable tests

2
Test

DeepScan

Adaptive testing — 9× more violations found

3
Re-test

FixLoop

Root-cause + fix, re-test on every agent change

4
Protect

RuntimeGuard

Same policies monitored on live traffic, streamed to your SOC

5
Prove

ProofLedger

Regulator-ready, OWASP/MITRE-mapped audit evidence

Put agents near PHI without putting PHI at risk.

Book a demo and see Verigrey catch a minimum-necessary violation before it reaches a patient.

Book a demo