Healthcare

Deployment Blueprint: A Multi-Clinic Network Runs Ambient Scribing with Zero PHI Egress

This blueprint is a representative reference architecture — anonymized and generalized from the healthcare deployment patterns we design. No client names appear, and no outcome figures are invented.

The situation

A multi-clinic regional network — an Ontario primary-care group or a US regional system, the pattern is identical — watches clinicians spend evenings on documentation: encounter notes, referral letters, coding. Commercial ambient-scribing products exist, but every one the network evaluated streams consultation audio to a vendor cloud, adding either a business associate agreement to police (US) or a vendor PHI agreement and cross-border analysis (Canada). Meanwhile clinicians, like employees everywhere, were quietly testing consumer AI on their drafting — security-industry surveys consistently find roughly a quarter of employees admit pasting confidential material into public tools, and clinical staff are not exempt.

The constraint

  • United States: HIPAA. A cloud scribe vendor is a business associate under 45 CFR 164.502(e); every subcontractor extends the chain, and breach-notification duties land on the covered entity when any link fails. The Security Rule (45 CFR 164.306–312) governs whatever systems hold PHI.
  • Ontario: PHIPA makes the network, as health information custodian, accountable for every disclosure of personal health information; vendor chains multiply the disclosures to account for.
  • Everywhere: consultation audio is the most identified data imaginable — de-identification pipelines (45 CFR 164.514) cannot help when the raw input is a named patient describing symptoms.

The network's requirement, stated by its privacy officer: ambient documentation where PHI never leaves the network — not "leaves under contract," never leaves.

The architecture

Component Choice
Scribe model Open-weight speech-to-text plus a tuned language model with clinic-vocabulary LoRA adapters (specialty terms, local formularies, referral formats)
Vision pipeline Qwen3-VL for faxes, scanned records, requisitions, and forms — intake digitization on the same rack
Hardware Inference rack inside the clinical network; air-gap-capable segment for behavioural-health and research enclaves
Access control Role-based access mapped to care teams; clinician review-and-sign required before any note enters the EHR
Logging Full audit lineage: audio → transcript → draft note → signed note, with model and adapter versions recorded
Egress Zero. No cloud API in the PHI path; no BAA exists because no business associate exists

The engagement followed the standard arc: assessment mapping data classes and clinic workflows, hardware sized to peak concurrent consultations, hardening and security review before live PHI, then adapter tuning evaluated by clinicians against real (consented, internal) encounter samples until draft notes cleared their bar.

What it unlocks

Ambient documentation with zero PHI egress. The consultation is transcribed and drafted into a structured note on-LAN, in the clinic's own formats, with the clinician signing off. The privacy analysis that consumed the vendor evaluation — cross-border transfers, subcontractor chains, retention policies — evaporates, because the answer to "where does the audio go?" is one rack down the hall.

A radically simpler compliance posture. No business associate agreement to negotiate, monitor, and re-paper at every vendor change; no PHIPA disclosure chain; Security Rule controls applied to infrastructure the network's IT team already governs alongside the EHR. Compliance by architecture rather than by contract — the kind privacy officers accept without argument.

The overnight queue. Coding suggestions, referral-letter drafts, chart summarization for tomorrow's patients, and backlog digitization of scanned records all run as batch jobs on hardware that would otherwise idle — zero marginal cost, no per-token meter quietly taxing every encounter.

Clinician hours back, adoption without shadow AI. The sanctioned tool is on-LAN fast, tuned to local vocabulary, and unmetered — better than anything staff could sneak. The paperwork hours it recovers are the point; the network hired clinicians, not typists.

The full architectural comparison — including when cloud-with-BAA patterns are defensible and when they are not — is in our guide to HIPAA-compliant LLMs without a BAA; isolation techniques for research and behavioural-health enclaves are covered in the air-gapped LLM deployment guide. See also our healthcare practice and on-premise LLM deployment service.

Deployment blueprints are representative reference architectures — anonymized and generalized from the deployment patterns we design. They are not client testimonials.

Questions we get

Frequently asked questions

Can ambient AI scribing be done without sending audio to the cloud?

Yes. Open-weight speech and language models run on hardware inside the clinical network: transcription, note drafting, referral letters, and coding suggestions all execute on-LAN. The consultation audio and the resulting note never cross the network boundary.

Does an on-premise clinical AI system need a BAA?

No. HIPAA requires a business associate agreement under 45 CFR 164.502(e) only when a third party creates, receives, maintains, or transmits PHI on the covered entity's behalf. A fully on-premise deployment has no third party in the PHI path, so the BAA requirement never triggers — the Security Rule obligations apply to systems the organization already governs.

How does this pattern satisfy PHIPA in Ontario?

PHIPA makes health information custodians responsible for safeguarding personal health information and controlling its disclosure. When the model runs inside the custodian's own network, there is no cross-border transfer analysis and no chain of vendor agreements to police — PHI simply never leaves the custodian's control.

Is this a real hospital case study?

It is a representative deployment blueprint — a reference architecture anonymized and generalized from the healthcare deployment patterns we design. It names no clients and invents no outcome statistics; quantitative claims are structural properties of owned infrastructure, such as overnight batch processing at zero marginal cost.

Want this architecture, sized to your workloads?

The sovereignty assessment maps your obligations and concurrency, then hands you a written architecture and cost model.

Book a sovereignty assessment Explore industries

New blueprints and briefings, monthly

Deployment patterns, model releases, and regulatory shifts — no hype.

Sovereign-AI briefings, roughly monthly. No spam, one-click unsubscribe.