HIPAA As Go Seams

Compliance expressed as interfaces: policy, audit, PHI redaction, and a HITL gate

HIPAA As Go Seams Compliance expressed as interfaces: policy, audit, PHI redaction, and a HITL gate PHI trust boundary Request · clinical caller · Architecture component Request clinical caller Agent App · Go service · Architecture component · seams Agent App Go service seams Policy Iface · governance seam · PHI trust boundary · authorize Policy Iface governance seam authorize PHI Redactor · logger boundary · PHI trust boundary · redact PHI Redactor logger boundary redact HITL Gate · Cures Act CDS · PHI trust boundary · carve-out HITL Gate Cures Act CDS carve-out Audit DB · append-only · PHI trust boundary · DB GRANTs Audit DB append-only DB GRANTs request authorize emit log CDS action redacted rows Legend External Backend Security Database

Governance Seam

  • • A policy interface authorizes every action
  • • Compliance is a Go type, not a checklist
  • • Implementations are swappable and testable

PHI Handling

  • • Redaction happens at the logger boundary
  • • Only redacted rows reach the audit DB
  • • Append-only is enforced at DB GRANTs, not app code

Cures Act

  • • Clinical decision support hits a HITL gate
  • • The carve-out is an explicit seam
  • • A human confirms before the action lands