EVE ProofEvidence
Prove that an AI decision over protected health information respected the policy — minimum necessary, access controls, the right reason — with a signed record that contains a digest of the request, never the raw PHI.
These map to concrete EVE Proof capabilities — enforcement, reproducibility, and signed evidence — not a policy PDF.
Confidentiality guards block disclosure before it happens; the certificate proves the decision without storing the PHI.
Each decision records the policy version and reason code — who could act, on what basis, and why.
The request is bound by SHA-256 digest, so the evidence is verifiable without ever embedding patient data.
When a policy blocks an over-broad PHI disclosure, the certificate records the reason code and policy version — a tamper-evident record of the safeguard working.
Hand over an evidence pack scoped to a window or a case; the auditor verifies each decision offline, with no patient data in the bundle.
Demonstrate to a covered entity that AI decisions were governed and provable — with evidence they can verify independently.
Informational mapping, not legal advice — EVE Proof supports your compliance program; it does not replace counsel.
| Framework | Obligation | EVE Proof capability |
|---|---|---|
| HIPAA | Minimum necessary; access controls for PHI | Confidentiality guards + digest-bound, signed decision records. |
| EU AI Act | Art. 12 record-keeping (high-risk health) | Automatic, tamper-evident decision records. |
| NIST AI RMF | Map / Measure / Manage | Signed evidence across enforcement and measurement. |
Verify a live decision certificate in your browser — then hand the evidence to your own auditor and watch them verify it without us.