FOR HEALTHCARE

THE CHART THAT SHOULD NOT LEAVE NEVER LEAVES.

AI is scheduling patients, drafting notes, routing referrals, and touching protected health information to do all of it. It saves hours. It also means software can take a wrong action around a patient at machine speed. Mountain Theory checks each action first, against rules your compliance team can read without a translator. The action that needs a person gets one, on the record, before anything happens.

The question your privacy officer is about to ask

A support agent pastes a patient record into a chatbot to draft a follow-up. A billing workflow pulls insurance data into an automated email. A scheduling assistant sends a referral outside the network. Each one is real productivity. Each one is also a regulated record moving through a system that was never approved to see it.

Access controls decided who could open the chart. Nothing decided where the AI takes it next. By the time anyone reviews the action, the record has left, and the question is no longer "are we compliant" but "how many patients do we notify."

How personal data is stopped at the action

What we do

We control what autonomous AI does. The model still decides. The action does not run until it has been checked.

For healthcare the line that matters most comes next: personal data is checked in and out. Health records, patient contact details, insurance and payment data, clinical notes. Stopped before it leaves your environment, whether it was typed, pasted, or pulled from a system the agent was allowed to read. Every action gets one of three outcomes, ALLOW, HOLD, or BLOCK, and every decision is logged with the rule that matched it.

The scenario

A vendor updated the hosted model behind one of our own agents overnight, and the agent began reaching for the network to answer questions it used to answer from local records, improvising raw shell commands instead of the sanctioned scripts. Every attempt was stopped the day it appeared, with no new rule on our side. In the ungoverned lane of the same run, every one of them completed.

The July run, recorded, with the two actions we had no policy for

One rule, as your privacy officer would write it

Policy

Protected health information does not leave the environment in any AI action. No approval path. Log every attempt.

Plain English, written by whoever owns the risk, no code to change it. The check is on the action, so it holds however the data got into the agent's hands.

A second rule is the one most health systems want next: a referral, a note to a patient portal, or a record leaving for a vendor goes to HOLD for a named person, with a timeout, and fails safe if nobody answers. You choose where a person belongs. Everything else runs at full speed.

Why HOLD is the third outcome, and where it belongs

What you hand the auditor

An append-only record of every decision: the action proposed, the rule that matched, the outcome, the time, and who wrote the rule. It exists because enforcement produced it, not because someone assembled a report after the incident. That is what a HIPAA or SOC 2 auditor asks for when an AI system touches protected health information, and it is what a breach counsel asks for first.

What the record has to contain, and why the usual logs do not count

The ask

A 30-day paid proof of concept on your agents and your action set, in your environment, not ours. Then one flat annual price for the organization, with no per-agent count. Tests published, misses included, before anyone signs.

Book 30 minutes and bring the workflow your privacy officer is worried about

Every published test, on one page →

Proof

Four things with a published run behind them.

Tests published, misses included. The Recorded Run Protocol →

Scroll to Top