Compliance

Regulated AI architecture

How to bake HIPAA, DPDP, audit logging, and consent into the first commit — not a last-mile checklist.

ICP job: Ship regulated AI without killing product velocity

Published in this pillar

Topic inventory

Planned and live topics for this pillar. Priority 1 ships first.

  • BacklogP1framework

    Audit logging for every inference call

    Query: How to audit log LLM API calls for HIPAA

    What to log, what never to log, retention, and who can access the trail.

  • BacklogP1field-note

    BAA before PHI: the sequencing most teams get wrong

    Query: When do I need a BAA for an LLM vendor?

    Decision tree for vendors, subprocessors, and when synthetic data is enough.

  • PublishedP1pillar-guide
    Compliance as architecture, not paperwork

    Query: How do you build HIPAA compliant AI products from day one?

    Bake HIPAA/DPDP into the first commit; contrast checklist theater vs system design.

  • BacklogP1checklist

    DPDP consent UX that founders can actually ship

    Query: DPDP consent requirements for AI products India

    Practical consent, purpose limitation, and notice patterns for Indian buyers.

  • BacklogP1comparison

    HIPAA vs DPDP: one product, two postures

    Query: HIPAA vs DPDP for AI startups

    Shared primitives (access control, logs, minimization) vs jurisdiction-specific deltas.

  • BacklogP2comparison

    Choosing an LLM vendor under regulated constraints

    Query: Best LLM providers for HIPAA healthcare

    BAA availability, data retention defaults, region, and eval portability — not model leaderboard cosplay.

  • BacklogP2field-note

    Data residency without freezing the roadmap

    Query: Data residency requirements for AI products India US

    Region pinning, vendor contracts, and when residency is theater.

  • BacklogP2framework

    Human-in-the-loop that clinicians will use

    Query: Human in the loop design for clinical AI

    Review UX, override paths, and liability-aware product design.

  • BacklogP2framework

    On-prem vs private cloud for regulated AI

    Query: Should healthcare AI run on-prem?

    Decision matrix: latency, cost, talent, and actual compliance need vs fear.

  • BacklogP2framework

    PHI minimization in RAG pipelines

    Query: How to keep PHI out of LLM context windows

    Chunking, redaction, retrieval filters, and eval hooks for leakage.

  • BacklogP2field-note

    RBAC and break-glass for AI features

    Query: Access control for clinical AI tools

    Role scopes for copilots, admin overrides, and audit of privileged prompts.

  • BacklogP3checklist

    Incident response when the model is in the blast radius

    Query: LLM security incident response healthcare

    Prompt injection, data exfil, wrong clinical advice — playbooks that map to existing IR.

Canonical hub: https://brandlabs.app/blog/topics/regulated-ai-architecture