Health systems
HIPAA, PHI, business associate agreements, OCR review
- What the reviewer asks for
- Who authorized the agent action, what PHI it touched, whether a human stopped it, and a record a third party can check.
- What ICA hands them
- A signed receipt per agent action naming the agent, the action, the decision and who authorized it. Irreversible actions held for a human. The record verifies without ALEETH.
- Where to start
- One workflow, one data class, one facility.Internal audit accepts the evidence package: yes or no.
- Beside what you run
- ICA leaves the EHR in place and records the agent action beside it, which is the record the EHR never held.
The HIPAA Security Rule requires audit controls that record and examine activity in information systems that contain or use electronic protected health information. An agent's action is that activity.
45 CFR 164.312(b) · checked 3 October 2026