Every design decision Ardia makes is anchored to compliance first — creating a structural competitive moat that generic AI wrappers cannot replicate.
| Capability | Waystar/XIFIN | ChatGPT Wrapper | Ardia Precision Health |
|---|---|---|---|
| Post-care appeal drafting for licensed review | ✗ | Partial | ✓ Full |
| Deterministic "Warranty of Truth" (no hallucination) | ✗ | ✗ FCA Risk | ✓ Layer 4 Auditor |
| PAMA rate intelligence & LCD cross-reference | Basic | ✗ | ✓ By design |
| Texas SB 1188 & TRAIGA native compliance | ✗ | ✗ | ✓ Built-in |
| PLG self-serve (no sales call, credit card checkout) | ✗ | Partial | ✓ |
Sentinel is the compliance kernel every Ardia model inherits — it de-identifies before any reasoning, encrypts at rest and in transit, logs every access, and enforces least-privilege. Ardia is pre-revenue and processes no production PHI today; the controls below are labelled honestly by what is enforced now versus designed/planned before the first pilot under a signed BAA.
All 18 HIPAA Safe-Harbor identifiers (§164.514(b)(2)) — names, geography smaller than a state, all date elements, phone/fax, email, SSN, MRN, health-plan & account numbers, certificate/license, vehicle & device IDs, URLs, IPs, biometric IDs, full-face photos, and any other unique identifier — are stripped or generalized before text reaches a model.
A hard rule in the codebase: patient identifiers are never sent to a third-party model API and never written to console or error logs. De-identified, minimum-necessary data only — the LLM never sees raw PHI.
PHI encrypted at rest with AES-256 and in transit with TLS 1.3, on HIPAA-eligible Google Cloud (Cloud Healthcare API, BigQuery). Keys managed in Cloud KMS with rotation; 100% US-based data residency.
Every PHI access and every reasoning step is written to an append-only, timestamped, Merkle-chained audit trail — reviewable end-to-end, built to a CLIA/CAP-grade documentation standard for defensibility.
Minimum-necessary access by role — a reviewer sees only what their task requires. No standing broad access to PHI; every grant is scoped, time-boxed, and logged.
No vendor touches PHI without a Business Associate Agreement. BAAs with the cloud and model providers are to be executed before any pilot processes real patient data.
Every model — MolecuIQ, ToxIQ, PulmoIQ, Meridian, Cadence, Aria, Lumen — runs behind the same guardrails on the TARA core. Data is protected not by policy alone but by the order of operations: de-identify first, reason on the minimum necessary, cite every claim, and require a human before anything is used.
Sentinel strips PHI at ingestion. A model only ever reasons over de-identified, minimum-necessary text — raw identifiers never enter the reasoning path.
Every clinical or policy claim must trace to a named source — a policy section or a line in the record. If there’s no support, the model abstains rather than invent one.
The symbolic policy layer executes encoded LCD/NCD/MolDX rules; the guarded LLM cannot override it. Policy citations are looked up, never generated.
Non-diagnostic by design. Nothing auto-files; a licensed professional reviews, attests to, and submits every output (TX SB 1188).
Each access and reasoning step lands in the tamper-evident audit trail, so any recommendation can be reconstructed and defended after the fact.
No diagnoses, no drug-and-dose orders. Care-facing agents (Aria) escalate crisis signals to a human / 911 immediately rather than handling them alone.
We are explicit about our data. No real patient data is processed until Limited-Data-Set / Data-Use Agreements and BAAs are in place.