Healthcare

PHI never reaches the model.
Or the log.

PHI-redaction guardrails strip identifiers inline before a prompt is forwarded, a zero-content data policy keeps logs PHI-free, and a HIPAA BAA is available on request.

HIPAA-eligible workloads · BAA on request · redaction on every plan

  • Every requestPHI redactionIdentifiers stripped inline
  • Zero-contentData policyLogs can store no PHI at all
  • AvailableHIPAA BAAOn Enterprise, on request
  • InlineGuardrail checksIn-process, not a network round-trip
Defense in depth

Strip PHI in the request path. Keep it out of the log.

A single guardrail is a single point of failure. nRouter pairs inline PHI redaction, run by the built-in scanner, which strips common HIPAA identifiers inline (contact details, SSNs, and medical record, health-plan member and account numbers; personal names and free-text dates of birth are deliberately out of scope rather than silently missed), with a logging policy that can store no request content at all. Even an un-redacted edge case never becomes a stored record.

  • Guardrail layer: identifiers redacted before the prompt is forwarded
  • Logging layer: zero-content policy stores no request or response body
  • Metadata-only keeps cost + token counts for billing and analytics
  • Policy is org-wide and enforced on every request: no per-call opt-out

Step 01 — inbound

Prompt contains identifiers

A clinician note or patient message arrives at the gateway

Step 02 — guardrail

PHI redacted inline

The built-in scanner strips identifiers before the request is forwarded

Step 03 — storage

PHI in logs: none

Zero-content policy: only cost + token metadata is kept

Healthcare Enterprise Architecture

HIPAA-Eligible Request Pipeline: Clinical Ingress to Model Egress

Every patient interaction and clinical summary passes through in-process PHI redaction, zero-content memory safeguards, and BAA-bound multi-provider routing before egress.

Enterprise request lifecycle: client → gateway → guardrail filter → smart router → model provider

  1. Clinical / EHR Client

    POST /v1/chat/completions

    EHR systems, clinical notes, patient intake portals.

  2. Gateway Preflight & Auth

    :4000 · In-memory RLS

    Virtual key auth, department budget check, rate limiting.

  3. Guardrail Filter

    HIPAA PHI Redaction

    18 Safe Harbor identifiers stripped before provider egress.

  4. Smart Router & Optimizer

    BAA-Pinned Routing

    Routes exclusively to BAA-covered enterprise models.

  5. Model Providers

    Azure OpenAI · Bedrock · Vertex

    99.99% multi-provider failover; zero-content data policy.

45–65%

Cost Reduction

Via clinical tier routing

99.99%

Uptime SLA

Zero dead air for clinicians

< 2 ms

Inspection Overhead

In-process PHI scanner

18 Identifiers

Safe Harbor Redaction

HIPAA Privacy Rule aligned

Stage 01 — Ingress & Clinical Tenant Isolation

Virtual Key Authentication & Row Level Security

Clinical requests authenticate with an sk-nrouter-health-... virtual key over mTLS 1.3. Department-level rate limits and budgets are evaluated in memory, isolating clinic systems and research workloads via PostgreSQL Row Level Security (RLS).

Stage 02 — Inline HIPAA PHI Redaction

18 Safe Harbor Identifiers Stripped in Preflight

The gateway scanner inspects request payloads inline, redacting Medical Record Numbers (MRNs), health plan IDs, social security numbers, phone numbers, email addresses, and account identifiers before prompt payloads ever leave the security boundary.

Stage 03 — Zero-Content Policy Enforcement

Non-Storage of Protected Health Information

Under the healthcare zero-content data policy, prompt and response text bodies are held strictly in ephemeral RAM and never persisted to disk, log streams, or external observability backends. Telemetry retains only token volume, latency, and cost metadata.

Stage 04 — BAA-Pinned Provider Egress

High-Availability Cross-Cloud Routing (99.99% SLA)

Smart routing directs traffic exclusively to enterprise deployments covered by signed Business Associate Agreements (Azure OpenAI, AWS Bedrock, GCP Vertex). Multi-provider fallback automatically switches endpoints during cloud degradation without clinician disruption.

Stage 05 — Audit Logging & SOC 2 Telemetry

Append-Only Access Records for HIPAA Security Audits

Every model execution records actor credentials, timestamp, request duration, model version, and exact token micro-costs in an immutable audit ledger, giving hospital compliance officers the exact evidence required during HIPAA Technical Safeguard audits.

Clinical Integration

Configuring Zero-Content Policies & PHI Redaction Headers

Connect your clinical systems, EHR extensions, or patient intake bots via standard OpenAI SDK clients. Enforce zero-content data policies and Safe Harbor redaction using HTTP headers.

Installpip install openai
1# Cache: enabled (org default). Pass nrouter_cache: false to skip.
2from openai import OpenAI
3import os
4
5client = OpenAI(
6 api_key=os.environ["NROUTER_API_KEY"],
7 base_url="https://api.nrouter.ai/v1",
8)
9
10response = client.chat.completions.create(
11 model="gpt-5.4-mini",
12 temperature=1,
13 max_completion_tokens=1024,
14 messages=[
15 {"role": "user", "content": "Hello! What models do you support?"},
16 ],
17 extra_body={
18 # "nrouter_cache": False, # Uncomment to skip cache
19 },
20)
21
22print(response.choices[0].message.content)

Header Configuration & Policy Spec

# Healthcare Clinical Integration (OpenAI Python SDK)
from openai import OpenAI

client = OpenAI(
    base_url="https://api.nrouter.ai/v1",
    api_key="sk-nrouter-clinic-triage-live-4821",
    default_headers={
        "x-nr-guardrails": "hipaa-phi-redact,prompt-injection",
        "x-nr-data-policy": "zero-content",
        "x-nr-residency": "us",
        "x-nr-budget-scope": "cardiology-department"
    }
)

response = client.chat.completions.create(
    model="nrouter/auto",  # Routes to BAA-covered models
    messages=[
        {"role": "system", "content": "You are a clinical decision support assistant. Summarize clinical symptoms."},
        {"role": "user", "content": "Patient presents with chest tightness and dyspnea. Vital signs and notes enclosed."}
    ],
    extra_body={
        "allowed_providers": ["azure", "bedrock", "vertex"],
        "fallback_models": ["anthropic/claude-3-5-sonnet", "openai/gpt-4o"]
    }
)

Business Associate Agreement (BAA)

Signed HIPAA BAA issued through our Enterprise team, binding nRouter technical safeguards to your organization’s covered entity or business associate compliance posture.

Zero-Content Data Policy

Request and response bodies exist solely in memory during generation. Logs store strictly token counts, latency, and cost without retaining patient health narratives.

EHR & FHIR App Compatibility

Standard OpenAI-compatible REST API drop-in connects with SMART-on-FHIR clinical extensions, Epic App Orchard connectors, and Cerner workflow services.

Also on every plan

Core enterprise capabilities on every plan

Failover that keeps clinicians online

Fallback chains retry on a backup model when a provider degrades. 99.9% uptime SLA on every tier.

Append-only audit trail

Every key, guardrail, and policy change recorded with actor, timestamp, and diff for your compliance file.

Budgets per team and key

Claims, triage, and product workloads each run on budgeted keys. A tripped hard cap returns a clean 402.

Compliance — honest status

HIPAA is a shared responsibility. Here is our half.

  • nRouter provides the technical safeguards (PHI redaction, zero-content logging, AES-256 encryption, RLS tenant isolation, an append-only audit trail) and a BAA on request.
  • Your organization remains responsible for how PHI is used in your application and for your own HIPAA program. A BAA defines that boundary.
  • SOC 2 Type II is in progress (status as of August 2026); the infrastructure substrate (Microsoft Azure, Supabase) is already SOC 2 Type II certified. We will not say “certified” until our own report is signed.

Need the BAA before a privacy review? sales@nrouter.ai will issue one and have security walk your team through the safeguards.

Healthcare questions, answered

Will you sign a HIPAA Business Associate Agreement (BAA)?

Yes, a formal BAA is available for healthcare customers processing PHI, issued through the Enterprise team. Request one at /contact?topic=baa or by emailing sales@nrouter.ai.

PHI-redaction guardrails are included on every plan at no extra cost regardless of whether a BAA is in place.

How do you keep PHI out of request logs and persistent storage?

Two layers of protection. First, the inline PHI scanner detects and redacts 18 HIPAA Safe Harbor identifiers before the request is forwarded to an upstream model.

Second, the organization data policy can be set to zero-content or metadata-only, ensuring that request and response bodies are never written to disk, database tables, or telemetry streams. You maintain token and cost tracking without storing any clinical text.

Which HIPAA Safe Harbor identifiers are redacted by the inline scanner?

The scanner strips medical record numbers (MRNs), health plan beneficiary numbers, certificate/license numbers, vehicle and device identifiers, social security numbers, account numbers, email addresses, phone numbers, IP addresses, and digital biometric markers. Free-text clinician notes are scrubbed in under 2 ms of gateway overhead.

Is nRouter HIPAA compliant and what is the shared responsibility model?

nRouter supports HIPAA-eligible workloads and executes a BAA on request. HIPAA compliance operates as a shared responsibility: nRouter guarantees technical safeguards (PHI redaction, zero-content logging, AES-256 encryption in transit and at rest, RLS tenant isolation, and audit logging) and BAA commitments, while your organization manages user authentication, access control policies, and clinical application logic.

Can health data stay strictly within sovereign US healthcare regions?

Yes. The default infrastructure footprint is strictly within the United States.

For European healthcare organizations complying with GDPR and NIS2, EU residency is available on request. Data is pinned at provision time and never transits external jurisdictions.

How does multi-provider failover work during hospital EHR peak hours?

When clinical staff rely on generative triage or transcription summaries, downtime is unacceptable. nRouter monitors upstream model health continuously; if Azure OpenAI experiences an outage or 5xx surge, nRouter automatically fails over to AWS Bedrock or GCP Vertex in under 50 ms without dropping active sessions.

Explore industry solutions

Tailored AI gateway controls for every vertical

Healthcare

Start with the BAA and the safeguards walkthrough.

We will issue a Business Associate Agreement and walk your privacy and security teams through PHI redaction, the data policy, and residency before a single request is sent.

HIPAA BAA available on request · PHI redaction on every plan · SOC 2 Type II audit in progress (status as of August 2026)