Perspectives · Healthcare · Regulated AI

Healthcare AI doesn't have a model problem. It has a compliance-architecture problem.

I spent years building cloud platforms in healthcare, and here's the pattern that repeats: a clinical or operational AI use case with obvious value — documentation burden, prior-auth triage, analytics on claims — gets prototyped in weeks, demos beautifully, and then enters a compliance review from which it never returns. The postmortem blames regulation. Regulation is rarely the problem. The problem is that the platform underneath was never architected to make the compliant path buildable.

HIPAA doesn't prohibit any of these systems. It prohibits sloppiness: PHI flowing through services without BAAs, data paths nobody can enumerate, access nobody can attribute, retention nobody configured. A prototype violates all of that by default — not because the team is careless, but because the sanctioned alternative doesn't exist. There's no governed enclave to build in, no blessed de-identification service, no paved path from the EHR data to a model with the audit trail intact. So every use case pays the full architecture cost alone, and most die paying it.

Compliance reviews don't kill healthcare AI projects. The absence of a platform that makes the compliant path cheap kills them — the review just signs the certificate.

What the platform owes the use case

The organizations that ship healthcare AI treat compliance as infrastructure, built once and inherited by everything: segregated environments where PHI-touching workloads land by default, with encryption, logging, and retention preconfigured rather than re-litigated per project. A de-identification and tokenization layer offered as a service, so most analytics and model work never touches raw PHI at all. Data paths that are enumerable — you can print where PHI flows, because the network and IAM were designed to make that printable. And audit as a first-class output: who accessed what, on whose behalf, with what justification, answerable in minutes because the identity chain was built in, not bolted on.

None of that is exotic. It's the same landing-zone, segmentation, and workload-identity discipline every regulated platform needs — healthcare just raises the price of skipping it. Build it once and the fourth AI use case costs a fraction of the first. Skip it and every use case is the first.

Interrogate the use case before you build it

One practice worth stealing regardless of platform maturity: before any healthcare AI build, run the use case through an adversarial review as if the toughest compliance officer and the most skeptical clinician were both in the room — and yes, a well-prompted model plays both roles surprisingly well. Where does PHI enter and leave? What happens when the model is wrong about a patient? Who's accountable for the recommendation? What does the clinician's workflow actually permit? An afternoon of hostile questions is the cheapest de-risking available, and it routinely reshapes the build — or kills it before it consumes a quarter. In a domain where the cost of a wrong system is measured in more than money, kill-it-early is a feature.

This is the work I do.

Bounded proofs on real data, agent platforms your organization owns, and the operating-model design that makes them stick — delivered end to end, corp-to-corp through Mazo Cloud Group LLC.

Start an engagement