Sector

Healthcare & life sciences

Agents touching patient records, clinical workflow and regulated submissions.

HIPAA Security & Privacy Rules
Clinical decision support boundaries
21 CFR Part 11 for regulated records

The problem in one sentence

Minimum necessary access was hard enough with humans. An agent that queries broadly to answer narrowly breaks it structurally.

Where it breaks

Failure pointWhat actually happens
Minimum necessaryAgents retrieve context aggressively by design. That is in direct tension with the access discipline HIPAA expects.
Audit controlsThe Security Rule expects records of access to ePHI. An agent generates orders of magnitude more access events than a clinician — most logging designs were not sized for it.
CDS boundaryWhere an agent's output stops being reference information and starts being a clinical recommendation is a regulatory line, not a product decision.
Business associatesThird-party agent platforms processing ePHI need agreements, and their audit trail has to be visible to your compliance function.
Next step

If any of this is live for you

The fastest route is a conversation. Bring the architecture you are worried about — the first useful thing usually surfaces inside twenty minutes.