Compliance
How to bake HIPAA, DPDP, audit logging, and consent into the first commit — not a last-mile checklist.
ICP job: Ship regulated AI without killing product velocity
Planned and live topics for this pillar. Priority 1 ships first.
Audit logging for every inference call
Query: How to audit log LLM API calls for HIPAA
What to log, what never to log, retention, and who can access the trail.
BAA before PHI: the sequencing most teams get wrong
Query: When do I need a BAA for an LLM vendor?
Decision tree for vendors, subprocessors, and when synthetic data is enough.
Query: How do you build HIPAA compliant AI products from day one?
Bake HIPAA/DPDP into the first commit; contrast checklist theater vs system design.
DPDP consent UX that founders can actually ship
Query: DPDP consent requirements for AI products India
Practical consent, purpose limitation, and notice patterns for Indian buyers.
HIPAA vs DPDP: one product, two postures
Query: HIPAA vs DPDP for AI startups
Shared primitives (access control, logs, minimization) vs jurisdiction-specific deltas.
Choosing an LLM vendor under regulated constraints
Query: Best LLM providers for HIPAA healthcare
BAA availability, data retention defaults, region, and eval portability — not model leaderboard cosplay.
Data residency without freezing the roadmap
Query: Data residency requirements for AI products India US
Region pinning, vendor contracts, and when residency is theater.
Human-in-the-loop that clinicians will use
Query: Human in the loop design for clinical AI
Review UX, override paths, and liability-aware product design.
On-prem vs private cloud for regulated AI
Query: Should healthcare AI run on-prem?
Decision matrix: latency, cost, talent, and actual compliance need vs fear.
PHI minimization in RAG pipelines
Query: How to keep PHI out of LLM context windows
Chunking, redaction, retrieval filters, and eval hooks for leakage.
RBAC and break-glass for AI features
Query: Access control for clinical AI tools
Role scopes for copilots, admin overrides, and audit of privileged prompts.
Incident response when the model is in the blast radius
Query: LLM security incident response healthcare
Prompt injection, data exfil, wrong clinical advice — playbooks that map to existing IR.
Canonical hub: https://brandlabs.app/blog/topics/regulated-ai-architecture