Role-based access control directly supports HIPAA’s access-control and minimum-necessary principles. The retrieval and orchestration layers must verify the authenticated user’s role before protected health information enters the model context. Authorization should be applied to individual records, data sources, tools, and actions, with audit events recording the requesting identity, accessed resource, purpose, and result. Model instructions alone are not a security boundary.
Patient information must also remain within services and processing activities covered by the organization’s Business Associate Agreement. Anthropic states that PHI processing requires a HIPAA-ready organization and an accepted BAA, and that only specified eligible services and configurations are covered. Patient data must not be submitted through training, feedback, beta, third-party, or integration pathways that fall outside the applicable agreement. A BAA is not blanket authorization; architects must verify feature eligibility and disable inappropriate data-sharing mechanisms.
Reducing max_tokens, selecting a more capable model, and enabling streaming affect output length, quality, or latency. They do not establish authorization, contractual coverage, minimum-necessary access, or compliant PHI handling.
Study Guide references/topics: Anthropic Business Associate Agreement requirements ; HIPAA-ready services; PHI access control; minimum necessary; eligible-service boundaries; auditability.
===============