Use Case
Confidential AI for Healthcare
Clinical decision support and patient-record AI — running inside a hardware-verified enclave that satisfies your BAA obligations and minimum-necessary standard without manual data masking.
The clinical AI compliance barrier
Healthcare organisations deploying AI for clinical use cases — patient discharge summarisation, diagnostic decision support, care pathway recommendations — face a consistent barrier: HIPAA's minimum-necessary standard requires that protected health information (PHI) be shared only to the extent necessary for the purpose. Running a model on a complete EHR record on a cloud inference host means the cloud provider's infrastructure has access to the full record. BAA agreements transfer contractual liability, but they don't change the technical fact that the record is decrypted on third-party hardware.
The alternative — manual de-identification before every model run — is expensive, time-consuming (typically 2-6 hours of preprocessing per batch), and degrades model accuracy by removing context that the clinical AI needs to produce useful output.
How Almure changes the calculus
When the inference workload runs inside an Almure enclave, the EHR record is decrypted only inside hardware-verified CPU memory. The cloud provider's host OS has no access. The inference result — a structured summary, a diagnostic code suggestion, a risk score — exits the enclave encrypted and accompanied by an attestation report.
This architectural separation transforms the compliance conversation. Instead of "we minimised the data before sharing it with the model", the evidence is "the model ran inside a verified boundary and the data never existed outside it in a form accessible to third-party infrastructure." The attestation report provides the documentation that HIPAA minimum-necessary compliance reviewers and privacy officers can assess.
Pilot narrative — healthcare technology provider, clinical summarisation
A healthcare technology provider building clinical summarisation tools for hospital groups had been requiring manual de-identification of EHR records before each model run — a 4-hour preprocessing step that stripped out contextual signals the model needed for accurate summaries. After deploying Almure, the model runs on real EHR records inside a hardware enclave. Record content never leaves the encrypted boundary. The manual de-identification step was eliminated. The attestation report from each execution satisfies the data-minimisation documentation requirement for APPI review by the hospital groups' compliance teams.
要配慮個人情報 and APPI accountability
Japan's APPI (個人情報の保護に関する法律) places medical records, diagnosis history, and prescription data in the category of sensitive personal information (要配慮個人情報) — a higher-obligation class that requires explicit consent or a recognised statutory exemption for processing. Healthcare organisations using AI to process this data must document not only what they did with the data but what technical measures prevented unauthorised access or leakage under APPI Article 24.
Almure's enclave boundary produces that documentation automatically. The attestation report for each execution records what code ran, in what verified boundary, on what category of data — a per-execution technical audit trail that is structurally more defensible than access-control logs, because the isolation is hardware-enforced rather than policy-enforced.
Read: Healthcare AI and HIPAA — How Enclaves Close the Gap →Almure does not claim HIPAA compliance certification or formal APPI certification. We design the platform with reference to HIPAA minimum-necessary requirements and APPI accountability obligations. Compliance determination remains with the deploying healthcare organisation and its legal counsel.
Ready to scope a pilot?
We review each request and respond within 2 business days with a 30-minute technical call invitation.
Discuss your AI roadmap