Sector
Healthcare & life sciences
Agents touching patient records, clinical workflow and regulated submissions.
HIPAA Security & Privacy Rules
Clinical decision support boundaries
21 CFR Part 11 for regulated records
Clinical decision support boundaries
21 CFR Part 11 for regulated records
The problem in one sentence
Minimum necessary access was hard enough with humans. An agent that queries broadly to answer narrowly breaks it structurally.
Where it breaks
| Failure point | What actually happens |
|---|---|
| Minimum necessary | Agents retrieve context aggressively by design. That is in direct tension with the access discipline HIPAA expects. |
| Audit controls | The Security Rule expects records of access to ePHI. An agent generates orders of magnitude more access events than a clinician — most logging designs were not sized for it. |
| CDS boundary | Where an agent's output stops being reference information and starts being a clinical recommendation is a regulatory line, not a product decision. |
| Business associates | Third-party agent platforms processing ePHI need agreements, and their audit trail has to be visible to your compliance function. |
Next step
If any of this is live for you
The fastest route is a conversation. Bring the architecture you are worried about — the first useful thing usually surfaces inside twenty minutes.