A governance checklist for AI in PHI-bearing systems

7 min read

A governance checklist for AI in PHI-bearing systems

PHI boundaries, provenance, and human-in-the-loop are the three controls that decide whether an AI feature in healthcare is shippable. A practical checklist for engineering leaders.

Allen Lee
09 Sep 2026

The demo was never the hard part.

The model works. The output looks good. Someone has already shown it to a customer. And now the question is whether it can touch real patient data, and the room goes quiet.

The instinct is to write an AI policy.

But a policy that engineering cannot implement is a document, not a control. The gap is not intent. It is that nobody has decided where the boundaries sit, who reviews what, and how you would prove any of it a year from now.

Three controls decide whether an AI feature in a PHI-bearing system is shippable. Everything else is commentary.

1. PHI boundaries: where the data may go

The question is not "are we HIPAA compliant." It is "which specific fields may leave which specific process, and to whom."

  • Name every system that can receive PHI, including model providers, logging, error tracking, analytics, and evaluation tooling. The unglamorous ones are where it leaks.
  • Decide what is sent versus what is referenced. A record identifier and a de-identified summary are a different risk tier than a raw chart.
  • Confirm the contractual posture matches the technical one. A vendor without a BAA is not made acceptable by good intentions.
  • Verify retention on the receiving side. "We do not train on your data" and "we do not retain your data" are different promises.
  • Test the failure path. A stack trace containing a patient record is still a disclosure.

2. Provenance: what produced this, and from what

If a clinician or an auditor asks why the system said something, "the model generated it" is not an answer.

  • Record the model, version, prompt or template version, and retrieval inputs for every generated artifact.
  • Make the output attributable to its sources, not merely plausible.
  • Keep the chain queryable. Provenance that exists only in logs you cannot search is provenance you do not have.
  • Version the governance itself. When the prompt changes, the behavior changes, and you need to know which outputs came from which regime.

3. Human-in-the-loop: a decision, not a checkbox

Most teams claim human review. Fewer can say what the human is accountable for.

  • Define what the reviewer is approving: the facts, the phrasing, the clinical judgment, or only the formatting.
  • Give them enough to review. A reviewer who cannot see the sources is rubber-stamping.
  • Make declining easy and observable. If the fast path is approval, you have built an approval machine.
  • Instrument override rates. A review step nobody ever rejects is a control that is not working.
  • Decide what happens on disagreement, before it happens.

Why this is leadership work

None of the above is a model problem. It is architecture, contracts, data flow, and accountability — decided before the feature is built, because retrofitting boundaries into a shipped system is where the cost lives.

The reframe: do not ask whether your AI feature is accurate enough to ship. Ask whether you could reconstruct, a year from now, what it did and why — and who was accountable when it was wrong.

Governance is not the tax on AI velocity in regulated software. It is the thing that lets you keep the velocity when someone finally asks.

Next step

If your AI features are shipping faster than your governance, that ordering is fixable — and it is cheaper to fix now than after an audit. Book a fit review.

Tags:
regulated AI
AI governance
PHI
healthcare

Need this scoped for your business?

Anova can map the workflow, data model, integrations, risks, and launch path before you commit to a production build.

Book a fit review
Share:

Allen Lee

Founder, Anova Technology

Allen provides executive engineering capacity — architecture, AI governance, interoperability, and delivery systems — for founder-led healthcare and regulated teams, without the cost of a full-time CTO.

Fractional engineering leadership for healthcare and regulated software teams

Marketing contact
Working hours

Mon-Fri: 9 am — 6 pm

Located at

Marlton, NJ, 08053

Book a fit review

Book a fit review directly

30 minutes. You'll leave with a clear read on your top architecture and compliance risks — whether or not we end up working together.

Best fit for founder-led healthcare and regulated software teams entering the phase where architecture, compliance, interoperability, and AI governance start to matter more than raw build speed. Probably not a fit if you are looking for build capacity or hours.

Pick a timePrefer to write first? Use the form — it reaches the same inbox.
Or send a message

Share the engagement type, the outcome you want, and your technical context so Anova can confirm fit and the clearest next step.

30 minutes. You'll leave with a clear read on your top architecture and compliance risks — whether or not we end up working together. Share enough context to confirm fit, conflicts, and whether the right next step is a 2-week fixed-fee sprint: Architecture & Sequencing Sprint.

Examples: EMR/EHR, CRM, scheduling, intake, RCM, data warehouse, cloud platform, AI tooling, internal services. Please do not include PHI or patient details.
This helps separate urgent revenue, operations, or customer-experience problems from nice-to-have work.

Areas of focus

Sign up for newsletter

Unlock your business's full potential with our expert technical services, designed for growth and built on trust.


© 2026 Anova Technology LLC.
All rights reserved.
Privacy Policy