Healthcare
PII-safe agents, adversarial defense, and mastery-tracked medical education
Healthcare AI demands the highest standards of privacy, safety, and verifiable competence. PrimeSwarm's PII sanitization strips SSNs and NPI numbers before agent processing, TPNN prevents prompt injection from corrupting medical recommendations, and Learning Trails tracks structural mastery of medical knowledge — not just course completion.
Regulated industry pathway
Healthcare is a regulated industry. PrimeSwarm deploys in four phases: Discovery, Build, Deploy, Maintain. We configure the governance stack, write the ONLY Lang scripts, and run the DGV test card suite. You approve every script before it goes live.
Discovery
Week 0. We map your regulatory constraints, infrastructure, and decision workflows.
Build
Weeks 1-4. We configure the gate, write ONLY Lang scripts, and run DGV test cards. You sign off on every script.
Deploy
Week 4-5. We deploy to your VPC or on-prem. You receive a signed verification report.
Maintain
Ongoing. Quarterly reviews, DGV re-verification, script updates. You retain full control.
Why this matters
Clinical and life-sciences teams will use language models. If those models ingest identifiers, invent a dose, or cannot show what they remembered, the institution holds the liability.
Safety and legal compliance
Ready layer is governance: PII redaction, HITL on thin confidence, receipts, governed memory. PIR lattice work on CGM streams is a research demonstration on sample data — not a medical device.
- HIPAA program (design-for). PII strip + audit trail. Not a HIPAA certification or BAA by default.
- 21 CFR Part 11 (mapping). DGV cards for electronic records / signatures language
- GDPR. Retention knobs and fail-closed wipe on the ledger
Start this month
- Governed clinical-documentation or literature agents behind PrimeSwarm
- EMR Continuity Ledger (episodic memory — not an EHR)
- DGV evidence packet for an internal AI-use policy
- Learning Trails demo for competency structure
Not yet — we will not sell this
- · FDA/TGA device software
- · Production EHR integration
- · Clinical validation of PIR-on-glucose as a diagnostic
First diagnostic · not a product
Prior authorization — freeze the trajectory before we freeze the stack
A denial is rarely one event. It is the last hop of a path: condition → evidence → documentation → interpretation → authority → submission → payer rule → exception → consequence. The question we instrument is NOVA’s: where did this path first stop corresponding to Reality?
Every layer may claim only what its observable frame can show. G = 1 does not prove contemporaneous standing. TPNN does not prove the entire privacy boundary. Bare metal does not eliminate every leak. Those sentences are hypotheses. They go on the card. We keep a layer only when it moves origin hop, cycle time, or cash delay by a number the institution already believes.
1. Baseline — before any layer
Closed cohort, approved and denied, reconstructed as typed records — not tickets and not chat. Score origin hop blind to the denial code.
| Metric | Unit | Why we take it |
|---|---|---|
| Denial rate | % of closed trajectories | The last visible event. Not the object. |
| Touches per exception | staff actions | Rework after the break, not before. |
| Staff time | hours / case | What the denial consumes once it is already late. |
| Cycle time | hours, condition → close | Clock between Reality and the last hop. |
| Cash-flow delay | days / $ | What finance already believes. |
| Rework | resubmits / case | Same break, paid again. |
| Avoidable escalation | count / rate | Human review that a hop-2 or hop-4 catch would have spared. |
| Clinical capacity consumed | clinician minutes / case | Beds and clinics, not tickets. |
| Origin hop | 1–10, scored blind to denial | First point the series left Reality. |
2. Origin-hop rubric
The origin hop is the first point the series left Reality. Hop 10 is where the organization finally sees it. If we cannot name a hop earlier than the denial, the extract cannot see Reality either — that is still a finding.
| Hop | Name | Left Reality when… |
|---|---|---|
| 1 | Clinical condition | Is the condition record still the one the decision is about? |
| 2 | Evidence | Is every cited artifact present, hashed, and untransformed? |
| 3 | Documentation | Does the note still correspond to the evidence, or did the write invent? |
| 4 | Interpretation | Did a hop treat dependent facts as independent? |
| 5 | Authority | Is the signer still authorized after the condition moved? |
| 6 | Submission | Did the packet leave after the decision window closed? |
| 7 | Payer rule | Is the rule version the one in force at submit — or an older local copy? |
| 8 | Exception | Was the exception a new event, or the first time an earlier break became visible? |
| 9 | Consequence | Did a locally successful workflow produce a bad field-level result? |
| 10 | Denial | Where the organization finally sees the problem — not where it began. |
3. Layer off / layer on
Run the same cohort through each layer alone, then through the combined field. Record what became detectable, and at which hop. Residual is not a defect in the write-up — it is the claim we refuse to inflate.
| Layer | Observes | May prevent | Outside its frame | Off | On |
|---|---|---|---|---|---|
| None (baseline extract) | Tickets, notes, denial codes as the institution already stores them | Nothing. This is the starting state. | Origin hop is usually invisible. Denial is the first reported event. | Cohort as-is. | — |
| PIR correspondence | Structural balance of a signed basket: condition, evidence hashes, rule version, authority window, clocks | A locally green hop whose composite has already left Reality — if those fields are in the basket | Clinical truth. Payer systems not in the extract. Anything unsigned. | Hop success flags only. | Gap at the first hop the basket fails. G = 1 is a measured claim on that basket, not contemporaneous standing. |
| Continuity Ledger | Typed claims, provenance, status, supersession, decay. Draft ≠ verified. Recalled-often ≠ true | Silent merge; chat-dump memory; authority that stayed active after the condition record moved | EHR and payer of record, unless those writes enter as receipted objects | No lineage. Status does not expire. | Un-superseded authority and missing EvidenceLink become first-class breaks. |
| PrimeSwarm gates | Request-time PII, sandbox, HITL, refuse-before-submit | Identifier in context; unboxed tool; thin-confidence submit | A rule that changed after submit. Cash delay. Staff minutes. | Submit proceeds if the workflow is locally successful. | Refuse or escalate before hop 6 when the gate is thin. |
| TPNN | Whether a packet can form a valid vector on the manifold | Representability of injection or malformed transformation — if the test shows it | Authorized-but-stale context. A well-formed leak. Policy drift. Not the whole privacy boundary. | Any well-shaped packet proceeds. | Malformed transform at hop 2–3 cannot form. |
| DGV receipts | Whether a claimed check was run and hashed | “We tested that” without a packet | HIPAA, FDA, SOC 2. Those certificates are not this protocol. | Narrative compliance. | Each hop-level claim is a card or it is not a claim. |
| Combined field | PIR on the ledger series, plus refuse-before-act, plus receipts at each hop | What we are here to measure: denial at 10 that was a gap, a stale receipt, or live authority at 2, 4, or 6 | Whatever still does not move origin hop, cycle time, or cash delay — that layer is not kept | Each layer in isolation. | Incremental catch vs isolation. If the combination does not move the baseline, we do not freeze it. |
Line we owe on every denial
- Starting state
- Hidden break
- When it became detectable
- What each layer contributed — or failed to see
- Intervention (refuse, escalate, refresh evidence, expire authority)
- What changed
- Capacity recovered
- What the client paid
If we cannot attach dollars, hours, or clinician minutes to “detectable at hop 4 versus seen at hop 10,” we do not have a commercial object yet. We have a walkthrough. Architecture is frozen only after this table moves.
How Our Products Apply
3 products with specific use cases in Healthcare
PrimeSwarm
View product →Use Case
Deploy clinical decision-support agents that process patient data with PII sanitization, fairness gates for treatment recommendations, and human-in-the-loop approval when agent confidence drops below 98%.
Key Benefits
- PII sanitization strips SSNs, account numbers, and NPI before agent interaction
- Fairness gates detect Adverse Impact Ratio violations using the Four-Fifths Rule
- Human-in-the-loop approval for low-confidence clinical recommendations
- Cryptographic audit receipts for every agent interaction — designed for a HIPAA program, not a certificate we print
- GDPR retention policies with configurable session data lifetimes
TPNN
View product →Use Case
Prevent prompt injection attacks from corrupting medical AI outputs. TPNN's topological constraints ensure that injected text cannot form valid output vectors — adversarial resistance is a mathematical guarantee, not a heuristic.
Key Benefits
- Mathematical proof that prompt injection cannot produce valid medical outputs
- Topological manifold constraints on the output space
- Ricci curvature identifies information flow bottlenecks in the network
- No false negatives — attacks outside the manifold are physically incapable of forming
Learning Trails
View product →Use Case
Track medical residents' mastery of clinical concepts using PIR balance gap to measure structural understanding. Identify bottleneck concepts that block downstream learning and generate personalized remediation trails.
Key Benefits
- PIR balance gap measures knowledge equilibrium — not just completion percentages
- Ricci curvature identifies bottleneck concepts blocking downstream learning
- Topological sort computes personalized learning trails from any starting point
- Cryptographic audit receipts for verifiable mastery demonstrations
Other Industries
All industriesBanking & Markets
Regime detection, fair-lending gates, and audit-ready agent governance
Legal & Compliance
Immutable audit receipts, fairness gates, and zero-knowledge proof of compliance
Education & Research
Mastery-tracked learning, autonomous research generation, and knowledge graphs
Sales & CRM
Agentic inbox reading, company enrichment, and workflow automation