HEALTHCARE

Review healthcare AI in an administrative workflow.

EYZEC provides a local protection and evidence layer for supported AI API requests. A responsible first healthcare evaluation should begin with one administrative or nonclinical workflow using non-sensitive or otherwise appropriately governed test data.

Review policy results

Apply rules to model identifiers, API routes, request-declared tool names, selected request content, request-declared maximum-output-token fields, request-declared streaming, and UTC operating windows.

Evidence

Preserve the gateway-generated request ID, route, matched rule, active-policy hash, request and response hashes, upstream status, and observer-produced timestamps.

Verify

Re-verify the local evidence chain from stored bytes and detect rollback or rotation relative to the saved local checkpoint.

Begin outside clinical decision-making.

The built-in Healthcare profile is an alternative complete policy—not a composable pack. It classifies declared clinical-decision and write-like tool names, request-declared streaming, request-declared maximum-output-token fields above the configured cap, and requests outside configured routes or exact identifier lists as DENY. Its shipped exact model lists are empty; the tool-using ALLOW path also requires an exact tool-name list. Until every required exact list for at least one complete ALLOW path is configured, requests continue to receive policy DENY results. The current Gateway distribution records those policy results and forwards the requests. Technical or evidence failures can still stop forwarding; there is no active-enforcement switch in this distribution.

Gateway evidence contains request and response body hashes rather than raw bodies or headers. Forwarded request content still reaches the configured upstream provider; this design does not itself determine whether a workflow may process protected health information.

Discuss a healthcare evaluation