Listing Thumbnail

    HIPAA-Compliant AI Governance Framework — Assessment to Implementation

     Info
    Sold by: Kriv AI 
    Kriv AI operationalizes HIPAA-aligned AI governance for healthcare providers, payers, PBMs, digital-health, and medical-device firms. Three fixed-scope tiers (4 / 6 / 8 weeks) map your generative AI workloads to HIPAA Security Rule §164.308/310/312/316, HITRUST CSF v11.2 AI Security Assessment, NIST AI RMF 1.0 + NIST AI 600-1 GenAI Profile, ISO/IEC 42001:2024, Colorado SB 24-205, Texas TRAIGA HB 149, and SEC Regulation S-K Item 1.05. Tier 3 deploys starter technical controls in your AWS account: Amazon Bedrock Guardrails (PHI filter, denied topics, contextual grounding), Amazon Comprehend Medical PHI redaction pipeline, AWS CloudTrail data events, AWS Config HIPAA conformance pack, AWS Security Hub HIPAA standard, Amazon Macie PHI discovery baseline, IAM Identity Center least-privilege, and PHI-regex tool-use hooks on Claude Code. Two tabletop exercises plus 30-day hypercare. AWS Select Tier Partner + Anthropic CPN member.

    Overview

    Ship AI in regulated healthcare environments without rebuilding your compliance program.**

    Kriv AI is a US-based AI consultancy focused exclusively on regulated industries. As an AWS Select Tier Services Partner and member of the Anthropic Claude Partner Network (approved April 2026), we help healthcare CISOs, Chief Privacy Officers, CMIOs, and Chief Compliance Officers deploy generative AI on AWS while maintaining defensible alignment with HIPAA and emerging AI-specific regulations.

    This engagement operationalizes controls — it is not a policy PDF. Methodology is derived from our 7-agent governed AI reference architecture (spanning intake, policy, PHI detection, model routing, audit, red-team, and reporting functions) and adapted to AWS-native services where the customer's workload runs on AWS.

    Three fixed-scope tiers

    • Tier 1 — Governance Assessment (4 weeks, $20,000). Workload inventory, PHI data-flow mapping, gap analysis against HIPAA Security Rule (§164.308 administrative, §164.310 physical, §164.312 technical, §164.316 documentation), HITRUST CSF v11.2 AI Security Assessment, NIST AI RMF Govern/Map/Measure/Manage, ISO/IEC 42001 AIMS clauses. Deliverable: prioritized remediation roadmap and executive readout.

    • Tier 2 — Assessment + Framework Design (6 weeks, $40,000). Everything in Tier 1, plus a tailored AI governance framework: model-risk tiering, acceptable-use policy for clinical and administrative AI, human-in-the-loop thresholds, vendor/BAA review checklist, AI Incident Response Runbook, and state-law overlay for Colorado SB 24-205 (effective 30 Jun 2026) and Texas TRAIGA HB 149 (effective 1 Jan 2026) where applicable.

    • Tier 3 — Full Implementation + Starter Controls (8 weeks, $75,000). Tiers 1 and 2, plus deployment of starter technical controls: Amazon Bedrock Guardrails (PHI filter, denied topics, content safety, contextual grounding); PHI de-identification pipeline (Amazon Comprehend Medical DetectPHI with redaction Lambda fronting Bedrock, or Microsoft Presidio for MS-stack customers); hash-chained audit trail (KMS-signed, S3 Object Lock, 6-year retention per §164.316); AWS CloudTrail data events + AWS Config HIPAA conformance pack + AWS Security Hub HIPAA standard; Amazon Macie PHI discovery baseline; IAM Identity Center least-privilege with time-bound access; PHI-regex tool-use hooks on Claude Code / agent actions. Includes two tabletop exercises and a 30-day hypercare window.

    Frameworks and citations. HIPAA Security Rule (45 CFR §164.308/310/312/316); HITRUST CSF v11.2 AI Security Assessment (released October 2024); NIST AI RMF 1.0 + NIST AI 600-1 GenAI Profile (July 2024); ISO/IEC 42001:2024; Colorado SB 24-205; Texas TRAIGA HB 149; SEC Regulation S-K Item 1.05 for public companies. The HHS OCR HIPAA Security Rule NPRM (89 Fed. Reg. 104504, Dec 27, 2024) is expected to finalize in 2026 — this framework pre-positions customers for the updated risk-analysis + asset-inventory requirements.

    Who this is for

    Healthcare providers (200–800 beds), regional payers + Medicaid MCOs (500K–5M members), PBMs, digital-health scale-ups (Series C–D), and medical-device firms with Class II/III SaMD + AI/ML PCCP filings.

    Get started. Contact info@kriv.ai  or +1 732 433 5564 to scope a private offer. Most engagements kick off within 2–3 weeks of contract signature.

    Highlights

    • Three fixed-scope tiers (4 / 6 / 8 weeks). Tier 1 governance assessment with HIPAA Security Rule §164.308/310/312/316 + HITRUST CSF v11.2 AI Security + NIST AI RMF + ISO/IEC 42001 gap analysis. Tier 2 adds AI governance framework, model-risk tiering, AUP, AI Incident Response Runbook, Colorado SB 24-205 + Texas TRAIGA state-law overlay. Tier 3 deploys starter technical controls into your AWS account with two tabletop exercises and 30-day hypercare.
    • AWS-native starter controls (Tier 3): Amazon Bedrock Guardrails (PHI filter, denied topics, contextual grounding), Amazon Comprehend Medical PHI redaction pipeline, KMS-signed hash-chained audit trail with S3 Object Lock and 6-year retention per §164.316, AWS CloudTrail data events, AWS Config HIPAA conformance pack, AWS Security Hub HIPAA standard, Amazon Macie PHI discovery baseline, IAM Identity Center least-privilege, and PHI-regex tool-use hooks on Claude Code
    • Methodology derived from Kriv AI's production 7-agent governed AI reference architecture, delivered by an AWS Select Tier Services Partner and member of the Anthropic Claude Partner Network (approved April 2026). Pre-positions your team for the HHS OCR HIPAA Security Rule NPRM finalization expected in 2026 (updated risk-analysis + asset-inventory requirements). Methodology only not legal or HIPAA compliance-attestation advice;

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Primary support contact: info@kriv.ai  · +1 732 433 5564 · https://kriv.ai/support 

    Response SLA: Kriv AI responds to AWS Marketplace inquiries and post-private-offer kickoff requests within 2 business days during US business hours (Eastern Time, Monday–Friday). Engagement-specific escalations are routed to the assigned Kriv engagement lead within 1 business day on request.

    Customers receive a dedicated Microsoft Teams or Slack channel with named engagement lead at kickoff for the duration of the engagement. Tier 3 customers receive a 30-day hypercare window post-implementation with weekly office hours and incident-support routing.

    Hours of operation: Monday–Friday 9:00 AM – 6:00 PM Eastern Time (US). Off-hours messages acknowledged the next business day.