Overview
Ship AI in regulated healthcare environments without rebuilding your compliance program.**
Kriv AI is a US-based AI consultancy focused exclusively on regulated industries. As an AWS Select Tier Services Partner and member of the Anthropic Claude Partner Network (approved April 2026), we help healthcare CISOs, Chief Privacy Officers, CMIOs, and Chief Compliance Officers deploy generative AI on AWS while maintaining defensible alignment with HIPAA and emerging AI-specific regulations.
This engagement operationalizes controls — it is not a policy PDF. Methodology is derived from our 7-agent governed AI reference architecture (spanning intake, policy, PHI detection, model routing, audit, red-team, and reporting functions) and adapted to AWS-native services where the customer's workload runs on AWS.
Three fixed-scope tiers
-
Tier 1 — Governance Assessment (4 weeks, $20,000). Workload inventory, PHI data-flow mapping, gap analysis against HIPAA Security Rule (§164.308 administrative, §164.310 physical, §164.312 technical, §164.316 documentation), HITRUST CSF v11.2 AI Security Assessment, NIST AI RMF Govern/Map/Measure/Manage, ISO/IEC 42001 AIMS clauses. Deliverable: prioritized remediation roadmap and executive readout.
-
Tier 2 — Assessment + Framework Design (6 weeks, $40,000). Everything in Tier 1, plus a tailored AI governance framework: model-risk tiering, acceptable-use policy for clinical and administrative AI, human-in-the-loop thresholds, vendor/BAA review checklist, AI Incident Response Runbook, and state-law overlay for Colorado SB 24-205 (effective 30 Jun 2026) and Texas TRAIGA HB 149 (effective 1 Jan 2026) where applicable.
-
Tier 3 — Full Implementation + Starter Controls (8 weeks, $75,000). Tiers 1 and 2, plus deployment of starter technical controls: Amazon Bedrock Guardrails (PHI filter, denied topics, content safety, contextual grounding); PHI de-identification pipeline (Amazon Comprehend Medical DetectPHI with redaction Lambda fronting Bedrock, or Microsoft Presidio for MS-stack customers); hash-chained audit trail (KMS-signed, S3 Object Lock, 6-year retention per §164.316); AWS CloudTrail data events + AWS Config HIPAA conformance pack + AWS Security Hub HIPAA standard; Amazon Macie PHI discovery baseline; IAM Identity Center least-privilege with time-bound access; PHI-regex tool-use hooks on Claude Code / agent actions. Includes two tabletop exercises and a 30-day hypercare window.
Frameworks and citations. HIPAA Security Rule (45 CFR §164.308/310/312/316); HITRUST CSF v11.2 AI Security Assessment (released October 2024); NIST AI RMF 1.0 + NIST AI 600-1 GenAI Profile (July 2024); ISO/IEC 42001:2024; Colorado SB 24-205; Texas TRAIGA HB 149; SEC Regulation S-K Item 1.05 for public companies. The HHS OCR HIPAA Security Rule NPRM (89 Fed. Reg. 104504, Dec 27, 2024) is expected to finalize in 2026 — this framework pre-positions customers for the updated risk-analysis + asset-inventory requirements.
Who this is for
Healthcare providers (200–800 beds), regional payers + Medicaid MCOs (500K–5M members), PBMs, digital-health scale-ups (Series C–D), and medical-device firms with Class II/III SaMD + AI/ML PCCP filings.
Get started. Contact info@kriv.ai or +1 732 433 5564 to scope a private offer. Most engagements kick off within 2–3 weeks of contract signature.
Highlights
- Three fixed-scope tiers (4 / 6 / 8 weeks). Tier 1 governance assessment with HIPAA Security Rule §164.308/310/312/316 + HITRUST CSF v11.2 AI Security + NIST AI RMF + ISO/IEC 42001 gap analysis. Tier 2 adds AI governance framework, model-risk tiering, AUP, AI Incident Response Runbook, Colorado SB 24-205 + Texas TRAIGA state-law overlay. Tier 3 deploys starter technical controls into your AWS account with two tabletop exercises and 30-day hypercare.
- AWS-native starter controls (Tier 3): Amazon Bedrock Guardrails (PHI filter, denied topics, contextual grounding), Amazon Comprehend Medical PHI redaction pipeline, KMS-signed hash-chained audit trail with S3 Object Lock and 6-year retention per §164.316, AWS CloudTrail data events, AWS Config HIPAA conformance pack, AWS Security Hub HIPAA standard, Amazon Macie PHI discovery baseline, IAM Identity Center least-privilege, and PHI-regex tool-use hooks on Claude Code
- Methodology derived from Kriv AI's production 7-agent governed AI reference architecture, delivered by an AWS Select Tier Services Partner and member of the Anthropic Claude Partner Network (approved April 2026). Pre-positions your team for the HHS OCR HIPAA Security Rule NPRM finalization expected in 2026 (updated risk-analysis + asset-inventory requirements). Methodology only not legal or HIPAA compliance-attestation advice;
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Support
Vendor support
Primary support contact: info@kriv.ai · +1 732 433 5564 · https://kriv.ai/support
Response SLA: Kriv AI responds to AWS Marketplace inquiries and post-private-offer kickoff requests within 2 business days during US business hours (Eastern Time, Monday–Friday). Engagement-specific escalations are routed to the assigned Kriv engagement lead within 1 business day on request.
Customers receive a dedicated Microsoft Teams or Slack channel with named engagement lead at kickoff for the duration of the engagement. Tier 3 customers receive a 30-day hypercare window post-implementation with weekly office hours and incident-support routing.
Hours of operation: Monday–Friday 9:00 AM – 6:00 PM Eastern Time (US). Off-hours messages acknowledged the next business day.