Skip to content
MedOrbit

How we keep AI safe in a hospital

Patient identifiers are redacted before any model call. Every AI output is a draft until a clinician approves it, every action is audit-logged, agents run against an offline evaluation harness, spending is capped per facility, and each agent has a kill switch.

PHI redacted before every model call · Clinician sign-off on every output · Full AI audit trail · Offline evaluation harness · Per-tenant cost caps · One-switch kill.

The safety layer, piece by piece

Seven controls, all shipped in the platform — not roadmap items.

PHI redaction before every call

Patient identifiers are redacted before any model call. The AI works on the clinical question, not on who the patient is — names, contact details and IDs never leave the platform with a prompt.

Agent answers are also held to the record: outputs that reference patient data must cite the chart they came from, so a clinician can check every statement at its source.

Human-in-the-loop by default

Every AI output is a draft until a human approves it. Nothing enters the chart without a clinician's signature, a pharmacist signs off every medication reconciliation, and a biller approves every claim appeal before it leaves.

The gate is enforced in the platform, not in policy documents — an unsigned draft cannot become part of the record.

A full AI audit trail

Every AI action is audit-logged: which agent acted, what it read, what it produced, who approved it and when. Administrators can reconstruct any agent decision after the fact — the same discipline hospitals already apply to controlled drugs and blood units, applied to AI.

Offline evaluations before real workflows

Agents run against an offline evaluation harness on scheduled test suites — separate from live patient traffic. Dry-run modes let your staff watch an agent work before it is allowed to act, and evaluation results gate what ships.

Cost caps and a kill switch

AI spending is capped per facility with daily budgets and per-call metering, and the platform falls back to smaller models automatically when a task doesn't need the largest one. MedOrbit runs on enterprise LLMs (AWS Bedrock / OpenRouter).

Each agent has a kill switch: one flag turns it off instantly, per facility — no deployment, no support ticket.

Data residency: AWS ap-south-1 (Mumbai)

Cloud-first, hosted in India (AWS Mumbai region) for data residency. Your patient data stays in-country, encrypted in transit and at rest, with access limited by role and audit-logged.

DPDP data requests

Statutory information and data requests are handled in-system, and patients or their representatives can raise a DPDP request directly: hello@medorbit.ai (subject: DPDP data request).

You stay in charge

Agents switch on one flag at a time, run dry before they act, and switch off with one flag. Adopting AI here is reversible at every step.

These are capability badges, not certification logos — we publish certificates only when they exist.

Safety questions hospitals ask us

How is AI kept safe for clinical use?

Patient identifiers are redacted before any model call. Every AI output is a draft until a clinician approves it, every action is audit-logged, agents run against an offline evaluation harness, spending is capped per facility, and each agent has a kill switch.

Is my patient data used to train AI models?

No. Identifiers are redacted before any AI call, and your data is not used to train models.