An independent assurance overlay above clinical decision support, triage, documentation and administrative health AI. We do not adjudicate clinical judgement. We evidence that the model was authorised for the task, that patient data stayed inside its lawful boundary, that a named clinician owned the decision, and that the episode can be reconstructed on request.
Cabier does not practise medicine, does not issue clinical guidance and does not replace the organisation's own clinical governance committee.
Resolved into testable control statements. Applicability is confirmed per engagement — jurisdiction, product and deployment scope all change what binds.
HIPAA Privacy & Security Rules
Minimum necessary, access control and audit-log expectations applied to prompts, retrieved records and model outputs — not only to the source EHR.
Clinical governance
Local approval of the tool for a defined clinical task, at a defined version, with a named clinical owner and a defined escalation path.
Medical-device software expectations
Where an output influences diagnosis or treatment, evidence of intended-use scope, change control and post-deployment monitoring.
EU AI Act high-risk duties
For in-scope deployments: human oversight, logging, accuracy and robustness evidence held by the deployer, not asserted by the vendor.
Non-discrimination and equity duties
Subgroup performance tested and recorded where the model influences access, triage priority or resource allocation.
Each module is a vertical projection of an asset already running on the platform. No parallel store, no second evidence chain.
Clinical AI Evidence Vault
Unified Evidence Vault
Prompt, retrieved patient context references, output, reviewing clinician and disposition captured independently of the vendor console, with an audit identifier per episode.
PHI Boundary Control
Sovereign AI Governance OS — residency and PII gating
Tested prevention of protected health information reaching an unapproved model, region or retention path — with the block recorded, not silently dropped.
Clinical Task Registry
AI Model Inventory
Which model is approved for which clinical or administrative task, at which version, under whose clinical authority, and when that approval lapses.
Clinician Accountability Log
Unified Audit Trail
An ordered record of who invoked the model, what it returned, which clinician accepted, modified or rejected it, and what entered the record.
A scored position across approval, PHI boundary, logging, clinician accountability, subgroup performance, patient transparency, drift monitoring and reconstruction — refreshed continuously.
A separate measure of whether protected health information can leave its lawful boundary at all, tested against live paths rather than asserted in policy.
Where unreviewed, unlogged or out-of-scope model use is accumulating by service line, surfaced before it becomes an incident or a claim.
A scoped attestation for the clinical governance committee, payer or supervisor, naming period, systems in scope and stated limitations.
Eight questions across the dimensions a clinical incident review or regulatory inspection would actually test. Answers stay in your browser — nothing is submitted, stored or transmitted.
01 · Approval
Is every AI tool touching patient care approved for a defined clinical task, at a defined version, with a named clinical owner?
02 · PHI boundary
Is there a tested control preventing protected health information reaching an unapproved model, vendor or region?
03 · Logging
Are prompts, retrieved context and outputs retained independently of the vendor's own console?
04 · Accountability
Is a named clinician recorded against every AI-influenced entry that reaches the patient record?
05 · Subgroup performance
Has performance been tested across relevant patient subgroups and the result recorded?
06 · Patient transparency
Is there a defined position on whether and how patients are told AI contributed to their care?
07 · Drift monitoring
Is post-deployment performance monitored on your own population rather than the vendor's validation set?
08 · Reconstruction
Could you reconstruct, on request, how a specific AI-influenced clinical decision was produced?
Answer the questions above to see an indicative position.
Days 1–15
Scope and obligation mapping
Service lines in scope, tools in use, obligation set fixed, evidence types and retention agreed with clinical governance.
Days 16–45
Capture and PHI boundary
Independent evidence capture stood up; PHI boundary and residency controls tested against live paths.
Days 46–75
Control testing
Clinician accountability, subgroup performance and reconstruction tested against real episodes of care.
Days 76–90
Position and attestation
Maturity position issued to the clinical governance committee, gap remediation sequenced, attestation scope agreed.
Scope, residency and retention are set per engagement. Commercial terms are quoted against scope.
Start a scoping conversation