Scenarios
HIPAA-compliant AI workflows for healthcare teams.
Step-by-step examples of payer workflows, message triage, intake programs, and compliance
exports—each one shows Assistant, Studio, Public API, and Agent SDK sharing the same PHI
handling, metering, and audit chain. Plan limits stay aligned with what's published at
checkout; your contracts and policies still decide what ships in production.
Active HIPAA BAA included
AOC under NDA SOC 2 Type II · inherited
AOC under NDA HITRUST r2 · inherited
EU + UK GDPR Art. 17 · 20 · 30
Active + CPPA-ready PIPEDA / CPPA Canada
Q3 2026 ISO 27001 In progress
Scenario 01 · Clinical ops
Prior authorization packet assembly
A specialty practice merges Studio checklists, Assistant Q&A against policy text, and the Data API so each payer packet inherits the same PHI handling and hash-chained evidence as everything else inside HASP.
Read narrative →
Scenario 02 · Access center
Secure message triage without another inbox
Care coordination teams orchestrate outbound Agent SDK drafts for portal messages while supervisors approve them in Studio queues—every Agent Action traces to both the automation and the human who released it.
Read narrative →
Scenario 03 · Population health
Ambulatory intake scoring on real signals
Occupational-health programs iterate intake questionnaires in Studio, keep Assistant-aligned PHI controls for kiosk and lobby Q&A, and meter kiosk bursts separately from inference through App Operations when volume spikes.
Read narrative →
Scenario 04 · Compliance
Compliance export the auditor can rerun
Governance leads schedule nightly pulls through the authenticated Public API, land signed exports in their own archival storage, and give examiners JSON plus the published /trust/verify recipe—not dashboard screenshots.
Read narrative →