Menu
Azure-native FHIR-first HIPAA-aligned

AI Vault
Privacy-First Clinical AI

A De-ID Before AI architecture that guarantees no identifiable patient data ever reaches the AI processing layer. Built for healthcare organizations that need clinical intelligence without compromising patient privacy.

Zero PHI in AI Zone
AES-256 Encryption Standard
100% Audit-ready Logging

Platform Overview

Three core pillars that work together to deliver clinical intelligence while keeping patient identity fully protected.

CI

Clinical Intelligence

Transforms raw clinical inputs into actionable insights using multimodal AI models trained on anonymized data.

  • Video assessments (mobility, behavior, motor function)
  • Physician assessment forms and evaluations
  • Clinical notes and metadata
PF

Privacy-First Design

Our De-ID Before AI architecture ensures no identifiable patient data ever reaches the AI processing layer.

  • One-way cryptographic tokenization
  • Consistent patient surrogation
  • Zero PHI boundary enforced at every step
FH

Unified FHIR Core

Azure Health Data Services (AHDS) FHIR API acts as the single source of truth for all clinical data.

  • Structured Observation resources
  • Interoperable data standards
  • Longitudinal patient tracking via token
Zero PHI in AI Zone
Tokenized Longitudinal Tracking
Audit-ready Logging

Inputs & Outputs

Raw clinical data enters, gets de-identified and processed, and emerges as structured FHIR resources - with no PHI ever crossing the AI boundary.

Clinical Capture (Inputs)

Video Assessment

Raw clinical video capturing patient movement, behavior, and physical assessments across any specialty.

MP4 Format

Physician Assessment

Standardized physician assessment forms, structured clinical evaluations, and diagnostic drawings.

High-Res Image

Clinical Notes

Physician observations and patient metadata providing clinical context for AI analysis.

Unstructured Text
Standardized Outputs (FHIR)

Observation

Stores discrete clinical scores - assessment results, functional metrics, and physician evaluation outcomes - all linked to an opaque token, never a patient name.

DiagnosticReport

Groups related observations into a single assessment session for streamlined clinical review.

DocumentReference

Secure links to de-identified media stored in Azure Blob Storage with immutable versioning.

React Frontend

Clinician SPA and Patient PWA consume FHIR data via RBAC with Recharts trendlines and masked video playback.

End-to-End Architecture

Four distinct layers that enforce the zero-PHI principle at every boundary, from clinical capture through to authorized clinical consumption.

1

AHDS Privacy Gate

Critical checkpoint: De-identification and tokenization occur before any data touches AI components. PHI stripped, identity vaulted.

2

Azure AI Foundry

Multimodal model processes anonymized physician assessment inputs for precise clinical scoring across any specialty, with no patient identifiers present.

3

AHDS FHIR Core

Stores Observation scores, DiagnosticReport groupings, and DocumentReference media links - all keyed to opaque tokens.

4

Dual React Interfaces

Clinician SPA (Desktop) and Patient PWA (Tablet) consume FHIR API via Role-Based Access Control for secure re-identification only where authorized.

Privacy Gate Deep Dive

"We strip identity first, then score movement - privacy by default."

Secure Identity Stream

PHI / PII Extraction

Names, MRNs, and DOBs are stripped from raw input before any processing begins.

Identity Vault Storage

Encrypted mapping table linking Token to Identity, stored separately with AES-256 and restricted RBAC access.

John Doe + MRN Raw Identity
TOKEN_A8F3 One-Way Hash
De-Identified AI Stream

Media De-Identification

Face blurring applied to video assessments; PHI and identifying information removed from physician assessment documents.

AI Processing Zone

Azure AI Video Indexer and Azure AI Foundry Multimodal process only anonymized inputs.

Azure Key Vault
RBAC Policies
Audit Logging
AES-256 Encrypt

Zero PHI AI Zone

Only De-Identified Data Processed Here
Video Analysis Engine

Azure AI Video Indexer

Input: Redacted Video (Face Blurred)
  • Clinical movement and behavior scoring
  • Functional assessment indexing
Multimodal Model

Azure AI Foundry

Input: Anonymized Physician Assessment
  • Structured evaluation scoring
  • Multi-specialty clinical analysis
Text Analytics for Health

Clinical NLP Engine

Input: Scrubbed Notes (No PII)
  • Automated clinical scoring
  • Symptom and risk factor extraction

HIPAA Safeguards Mapped to Architecture

Every HIPAA technical safeguard is backed by a concrete Azure control - not just a policy statement.

Access Control

§164.312(a)(1)

Unique User Identification

Assign a unique name and number for identifying and tracking user identity across all sessions.

Microsoft Entra ID (Azure AD) - MSAL.js integration for all users

Automatic Logoff

Electronic procedures that terminate an electronic session after a predetermined time of inactivity.

Session Timeout Policies - Token expiration logic in SPA

Audit Controls

§164.312(b)

Activity Logging

Hardware and software mechanisms to record and examine activity in information systems containing PHI.

Azure Monitor - Full audit trail of all API calls

Integrity Controls

Policies and procedures to protect EPHI from improper alteration or destruction in an unauthorized manner.

Azure Blob Versioning - Immutable storage policies

Encryption & Security

§164.312(c/e)

Transmission Security

Guard against unauthorized access to EPHI being transmitted over electronic communications networks.

TLS 1.2+ Enforcement - Private Link VNet Isolation

Encryption at Rest

Mechanism to encrypt and decrypt PHI stored in any electronic medium whenever deemed appropriate.

AES-256 Encryption - Azure Storage Service Encryption
Privacy-First by Design Principle
De-ID
Tokenize
AI on Anonymized Data
FHIR Longitudinal View

Built on Trust, Secured by Design

Our architecture guarantees that sensitive patient identity is separated from clinical data before it ever reaches the AI processing layer.

HIPAA Compliant
Zero Trust Model
AES-256 Encryption
Full Audit Trail
Schedule a Consultation