Trust & Governance
The governance model.
HarnessHealth is built on the premise that AI outputs in healthcare require physician accountability. The following documentation describes how the physician hard intercept is designed to work (sandbox today, not yet enforced in production), what the attestation record contains, and how the governance model maps to current regulatory frameworks.
The Governance Model
How physician oversight is structured, enforced, and audited. Four principles. The attestation chain. Regulatory alignment.
Read documentationHard Intercept
Technical specification of the physician attestation requirement. The mechanism designed to prevent rubber-stamping. Design stage: sandbox only.
Read documentationPublished Validation
Three publications in one quarter that describe the gap this architecture closes: MIRA and AMIE in Nature (June 17, 2026); Lotus Health AI (May 2026).
Read documentationHIPAA Compliance
Complete compliance matrix. Data handling, encryption, BAA, audit logging, breach notification, and what is still in process.
Read documentationFour principles, stated plainly.
No AI output with clinical content reaches a patient without a licensed physician review.
Physician authority is designed to be tracked and limited: volume above a threshold that would preclude genuine review is flagged. The ceiling is not yet enforced in the sandbox.
The reviewing physician's identity (NPI, timestamp) is permanently attached to every attested document.
The governance framework is designed to satisfy Joint Commission, OIG, and CMS oversight requirements. It is not designed for regulatory arbitrage.
Regulatory alignment.
The governance framework references the following regulatory frameworks. Each has detailed documentation in the sub-pages.
Compensation to reviewing physicians is a flat fee per review, the same whether they sign or decline, never tied to referral volume or downstream revenue. A design principle that keeps pay independent of the decision, not a legal opinion about any arrangement.
Compensation to reviewing physicians is flat per-attestation, not percentage-based. No referral arrangement created by the attestation relationship.
Remote Therapeutic Monitoring requires physician oversight; the attested record documents it, and the treating practice bills. CMS requires the tool meet the FDA device definition — no registration is in process.
The Joint Commission’s Responsible Use of AI in Healthcare certification (launched June 2026; it certifies organizations, not products) is organized around five areas: governance, data management, risk/bias reduction, monitoring & validation, and transparency. Org-governance platforms cover the program; the hard intercept is designed as the per-output physician-attestation mechanism that the governance and monitoring areas imply but a governance platform does not perform. NPI-bound, timestamped, audit-trailed.
The hard intercept, as designed
Sandbox today. Not yet enforced in production.
The design: no AI-generated document with clinical content leaves the HarnessHealth system without a cryptographic physician signature, designed to be enforced at the API gateway, with per-physician authority consumption tracking that prevents rubber-stamping at scale.
Read the design specification