HIPAA does not stop you from doing useful work; it stops you from doing it casually.
The Curee inference stack runs entirely within a HITRUST-certified envelope. PHI is encrypted at rest with AES-256 and in transit with TLS 1.3. Models inference inside a tenant-isolated boundary; nothing crosses out to a shared multi-tenant endpoint. Inference logs are deidentified before they leave the boundary, and we keep them only as long as our retention policy requires.
This costs us latency we'd rather not pay and engineering hours we'd rather spend on features. It is, however, the only way to deploy AI in a setting where the data being processed is, by definition, protected. Pretending otherwise is what gives "AI in healthcare" the reputation it has earned in some quarters.
