Inquire +

Industries / Healthcare

ICA for healthcare

Your organization has an AI policy.
Can it prove AI control?

AI agents already read charts, route cases, draft notes, code claims and answer patients. ICA sits between those agents and the systems they act on. It decides each action before it runs, holds what needs a clinician, and seals a signed receipt of what happened that anyone can check without asking ALEETH.

What did an AI agent do on 2 October 2026 at 03:09:35 UTC?

Signed ICA receipt · production Checking with ICA
Agent
NVIDIA Nemotron Nano 12B v2 · IN_TRAINING
Asked
DELETE httpbin.org/delete
Class
irreversible
Decision
DENY
Reason
no signed scope contract on record; fail closed
Signed
2026-10-02 03:09:35 UTC · ed25519

This page asks ICA's public verifier about this exact receipt as it loads. Open the raw check

Where AI acts in a health system

AI adoption is no longer the question. Control is.

AI is already inside care and operations. The question now is whether your organization can govern its use, and prove it to the people who will ask.

01

Clinical decision support

The agent
Reviews the record and recommends the next step.
The receipt shows
The recommendation, the scope that allowed it, and who approved acting on it.
02

Documentation and ambient scribes

The agent
Drafts the note and writes it toward the chart.
The receipt shows
Each write, the scope it ran under, and the human who approved it.
03

Prior authorization and utilization review

The agent
Assembles the case and drafts a determination.
The receipt shows
Each step checked before it completes, and the clinician who authorized any denial.
04

Imaging and triage

The agent
Prioritizes studies and routes urgent findings.
The receipt shows
What it routed, when, under which rule, and every escalation it raised.
05

Coding and revenue cycle

The agent
Suggests codes and submits claims.
The receipt shows
Every submission allowed, held or refused under the agent's scope, with the authorizer named.
06

Patient messaging

The agent
Answers portal messages and escalates.
The receipt shows
What it sent, what it escalated, and what waited for a person.

The AI control gap

The distance between AI use and provable institutional control.

Every AI-influenced clinical, coding or access-to-records decision inside that gap is either governed work product or unmanaged institutional exposure. There is no third category.

01

Which AI systems and data sources are approved, restricted or prohibited?

02

Where are clinician review and model validation documented?

03

What proof exists if a patient, an OCR review, a court or a payer asks?

What ICA governs

Seven controls for a health institution.

ICA works beside the systems you already run and governs how AI agents use them, across clinical support, documentation, coding, prior authorization and access decisions.

01

Agent registry and signed scope

Every agent is registered with a signed scope contract that says what it may do. No contract on record means no action: ICA fails closed, as the receipt on this page shows.

02

PHI and data boundary

Every outbound request an agent sends through ICA is checked against a released list of approved destinations. Anything else is refused before data leaves.

03

Clinical, coding and access permissions

Reads, consequential actions and irreversible actions are classed apart, and each class carries its own rule. A read inside scope runs. A delete waits or is refused.

04

Clinician review gates

Irreversible actions wait for a named human. Approvals come only from a signed-in identity, and the rule can require a second, distinct approver.

05

Halt and quarantine

When something is wrong, ICA halts and quarantines a live agent, and seals the halt to the ledger before the action is stopped.

06

Audit and disclosure

Every decision is a signed receipt naming the agent, the action, the decision and who authorized it, ready for internal audit, a payer or an OCR review.

07

Evidence ledger

Receipts are hash-chained, sealed into Merkle roots, timestamped under RFC 3161 and anchored to Bitcoin. Any edit breaks the chain where anyone can see it.

→

See the controls on a real receipt

Signed scope, action class, decision and anchor on a production decision, checked by your browser against ICA's published key.

Proof, not promises

A real receipt. Check it yourself.

Every governed action receives a signed receipt, hash-chained in sequence and anchored to Bitcoin through OpenTimestamps. A sealed record cannot be quietly rewritten by anyone, including us: an edit breaks its signature and its chain.

This receipt is real. On 2 October 2026 an AI agent running on NVIDIA Nemotron Nano 12B asked production ICA to delete. It had no signed scope for that, so ICA refused before the call ran. Your browser asked ICA's public verifier about this exact receipt when the page loaded.

Signed ICA receipt · production Checking with ICA
Agent
NVIDIA Nemotron Nano 12B v2 · IN_TRAINING
Asked
DELETE httpbin.org/delete
Class
irreversible
Decision
DENY
Reason
no signed scope contract on record; fail closed
Signed
2026-10-02 03:09:35 UTC · ed25519
Anchored
root b63347a3211d · leaf 1,820 of 4,251 · 04:29:20 UTC

Receipt fingerprint · SHA-256

9f3f 7c52 9a56 df77
9370 b727 f16e 309b
0ae7 0677 77b5 3c06
847c 6a24 9378 7cc4
  • Fingerprint matches the receipt bodywaiting
  • Ed25519 signature valid against ICA's published keywaiting
  • Included in a signed, anchored Merkle rootwaiting

This page asks ICA's public verifier about this exact receipt as it loads. Open the raw check

What the receipt holds

Proof of the action, beside the record of care.

ICA leaves the EHR in place and records the agent action beside it, which is the record the EHR never held. The receipt carries digests of the request, so it proves what was sent without storing the arguments.

Your institution

  • EHR and clinical records
  • Clinical AI and scribes
  • Imaging and triage tools
  • Coding, prior-authorization and billing tools
  • Patient portal and messaging

Your systems stay as they are.

ICA decides, per action

  • Allow inside the signed scope
  • Hold for a named human
  • Refuse and fail closed
  • Halt and quarantine the agent

The signed receipt

  • The decision and its reason
  • The action class: read, consequential or irreversible
  • The agent's identity and its state
  • Who authorized it, for anything held for a person
  • The time, to the millisecond
  • A SHA-256 digest of the request arguments and the resource
  • An Ed25519 signature against ICA's published key
  • Its place in an anchored Merkle root

Anyone can verify it, offline, with ICA's published key.

Health systems and payers

Two institutions. One kind of record.

Health systems

HIPAA, PHI, business associate agreements, OCR review

What the reviewer asks for
Who authorized the agent action, what PHI it touched, whether a human stopped it, and a record a third party can check.
What ICA hands them
A signed receipt per agent action naming the agent, the action, the decision and who authorized it. Irreversible actions held for a human. The record verifies without ALEETH.
Where to start
One workflow, one data class, one facility.Internal audit accepts the evidence package: yes or no.
Beside what you run
ICA leaves the EHR in place and records the agent action beside it, which is the record the EHR never held.

The HIPAA Security Rule requires audit controls that record and examine activity in information systems that contain or use electronic protected health information. An agent's action is that activity.

45 CFR 164.312(b) · checked 3 October 2026

Payers

Claims integrity, prior authorization, state examination

What the reviewer asks for
A claims or prior-authorization agent record an examiner can read.
What ICA hands them
Each prior-authorization or claims action checked before it completes, the clinician or reviewer who authorized a denial named in the receipt, and a record the examiner verifies alone.
Where to start
One decision path.The exam team accepts the evidence package: yes or no.
Beside what you run
ICA proves the agent's part in the decision and the human who signed the denial, which the claims core logs as an outcome only.

Colorado HB26-1139, signed 2 June 2026 and effective 1 January 2027: a medical-necessity denial cannot issue on AI output alone without review by a licensed clinician or physician, and the payer keeps an audit-information process for its AI.

Colorado HB26-1139 · checked 3 October 2026

Start small

One service line. One decision type. One model family.

A bounded first engagement puts ICA on one workflow, one data class and one facility: the agent registry, the data boundary, decision permissions, the evidence record, the clinician review gate, and a leadership review of what it produced. Success is one question: does internal audit accept the evidence package? Prove control on a defined use case, then expand.

AI Governance Readiness Check

Where does your AI governance actually stand?

Answer six questions. Get an indicative Control Readiness Score and the gap between policy and proof, on the spot, with no login. The paid Control Readiness Assessment confirms the score by testing.

Which of these are true?

Indicative in seconds. No login. We never sell your data.

The health institution of the future will not be judged by whether it used AI. It will be judged by whether it can prove AI was controlled.