A zero-trust healthcare AI assistant leveraging ReBAC-based pre-retrieval authorization to ensure patient-level data isolation and compliance.

The Challenges
Healthcare systems faced fragmented clinical data, strict compliance requirements, and high cognitive load on clinicians, limiting the safe adoption of AI copilots.
Patient Data Fragmentation
Clinical data (EHR, notes, labs, discharge summaries) was spread across multiple systems, making real-time access difficult.Strict Compliance & Privacy (HIPAA)
Ensuring that clinicians only access authorized patient records was critical to avoid regulatory violations.Unstructured Clinical Documentation
Large volumes of free-text notes, PDFs, and reports lacked structure, making retrieval inefficient.Risk of Data Leakage in AI Systems
Traditional RAG approaches risked exposing unauthorized patient data during retrieval or generation.
The Strategy
Designed a secure, multi-layered GenAI copilot using ReBAC-based authorization with SpiceDB, enforcing patient-level access before retrieval, ensuring zero data leakage.
ReBAC-Based Authorization (SpiceDB)
Modeled relationships:clinician → patient
nurse → ward → patient
specialist → referred patient
→ Generated allowed_patient_ids → allowed_document_ids
Pre-Filter Secure RAG Pipeline
SpiceDB returns authorized document IDs
Vector DB performs similarity search only on permitted records
Ensures LLM never sees unauthorized PHI
Hybrid Multi-Cloud Architecture
LLM + Guardrails (Vertex AI) → clinical reasoning
Data + Vector Layer (OpenSearch) → scalable retrieval
Streaming + Processing → real-time ingestion
Clinical Guardrails & Auditability
Input/output PHI filters
Clinical safety checks (hallucination control)
Full audit logs: clinician, patient, accessed records
The Results
The platform delivered secure, compliant, and scalable clinical AI assistance, improving care delivery while maintaining strict patient data isolation.
Zero Unauthorized Data Exposure
Pre-filter ReBAC ensured 100% patient-level isolation, meeting HIPAA and internal compliance standards.45% Faster Clinical Decision Support
Clinicians retrieved relevant patient insights instantly via conversational queries.60% Reduction in Documentation Time
AI-assisted summarization and note generation reduced administrative burden.High Adoption & Trust
50%+ clinician adoption within 90 days
Increased trust due to explainable, auditable AI responses


