RankShieldMD // Resources

Proof,
explained.

Guides on making clinical AI, medical devices, and record access verifiable, without exposing patient data. Practical, honestly-sourced writing for the people accountable when AI acts inside care: how to prove a clinical-AI decision, what FDA §524B and HIPAA actually require, and how to make a device quantum-safe. Every claim checkable, every stat attributed.

CitedPHI-freePost-quantumNon-device
RankShieldMD ledger · PHI-free
Clinical-AI decision
onco-v4 · 0x5377a9a1…
Sealing…
Record access · export
verified actor · 0xa6ee5342…
Sealing…
Telehealth order
signed · 0xfa65fce3…
Sealing…
Scroll to read
Coverage

Provenance, compliance, and post-quantum.

Three questions the people accountable for clinical AI keep facing, and the guides that answer each one honestly.

01

Prove the decision

The unprovable AI decision is a new class of risk. These guides explain the receipt every clinical-AI decision needs, and how it stays non-device.

provenance
02

FDA and HIPAA, made verifiable

What §524B, the CDS non-device line, and HIPAA §164.312(b)/§164.528 actually require, and the evidence that supports them, honestly framed.

compliance
03

Secure into the quantum age

Why implants and records outlive their cryptography, and how post-quantum identity with in-field rotation keeps a decade of evidence defensible.

post-quantum
The guides

Guides for proving the medicine.

Every guide is honestly sourced, cites its statistics to the original, and holds the same line the product does: attests but never decides, PHI-free, supports compliance rather than claiming to make you compliant.

Long-form, cited, and written for a security committee. Start here.

Provenance · 10 min

One record, two regulators: what FDA and the EU AI Act each ask of a model that changes

A PCCP is permission for your model to change after clearance. The EU AI Act requires you to say what ran. Build the record per decision and one trail answers both.

Read →
Provenance · 10 min

Which model read this slide? Pathology provenance and the image you cannot re-create

A whole-slide image is the end of a physical production line, and a re-cut slide is a new specimen. Why the record you sealed at the time is the only route back to a challenged read.

Read →
EU AI Act · 10 min

Article 50 is already in force: the AI Act transparency duties your clinical AI has today

The Omnibus deferred the high-risk dates and left Article 50 alone. Two of its four duties land on you rather than your vendor, and a marking deadline arrives 2 December 2026.

Read →
EU AI Act · 10 min

Annex I or Annex III? Which EU AI Act deadline binds your medical AI

The Digital Omnibus moved two deadlines, not one, to dates eight months apart. Article 6 decides which clock is yours, and the deciding condition is not whether your software is medical.

Read →
EU AI Act · 11 min

The EU AI Act high-risk deadline moved to 2028. Article 12 logging did not move with it.

The Digital Omnibus gave medical AI two more years. It did not give anyone a way to record a year that has already passed. What changed, and the one duty you cannot backfill.

Read →
Provenance · 9 min

Tamper-evident audit logs for clinical AI: what immutable really requires

Keeping logs for years is not the same as keeping them trusted. Learn what makes a clinical-AI audit log genuinely tamper-evident and independently verifiable.

Read →
Provenance · 9 min

Model cards are not proof: transparency documents versus verifiable provenance

Model cards and frameworks describe an AI system. They do not prove what it did. Learn the difference between transparency documents and verifiable provenance.

Read →
HIPAA · 9 min

Put your AI scribe in your HIPAA risk analysis: the step small practices miss

OCR ties most penalties to risk-analysis gaps, and your AI scribe is often missing from it. Learn how a small practice documents the scribe in its SRA.

Read →
Telehealth · 9 min

Signed clinical orders: proving a telehealth prescription came from your clinician

Voice clones and spoofed orders threaten telehealth. Learn how cryptographically signed clinical orders prove a prescription truly came from your clinician.

Read →
Governance · 9 min

Governance, security, and provenance: the third pillar of clinical-AI trust

Most clinical-AI trust advice covers governance and security, then stops. Learn why verifiable provenance is the missing third pillar, and how to add it.

Read →
Provenance · 9 min

Which AI model read this scan? Tamper-evident imaging provenance for small centers

When an AI-assisted read is challenged, can you prove which model version read the scan on intact images? Build a tamper-evident imaging provenance record.

Read →
HIPAA · 9 min

PHI-free HIPAA access auditing: prove who touched a record without exposing it

Access logs often widen your PHI footprint. Learn how PHI-free, tamper-evident access auditing proves who touched which record without exposing patient data.

Read →
Telehealth · 9 min

Verify a telehealth patient is real, not a deepfake, before you prescribe

Synthetic patients now book telehealth visits to obtain prescriptions. Learn how to verify a real, live patient with signed proof before you prescribe.

Read →
Provenance · 9 min

Prove an AI scribe note is genuine: the audit trail small practices need

AI scribe notes get questioned months later. Learn to build a tamper-evident, PHI-free audit trail that proves what your model captured and who signed it.

Read →
Compliance · 10 min

How to answer a hospital's AI security questionnaire with proof

Turn a hospital's AI security review into a fast win. Build a reusable evidence pack that proves your model, access, and controls, not just your promises.

Read →
Provenance · 11 min

What clinical-AI decision provenance is, and why every AI decision needs a receipt

When an AI decision reaches a patient and is later questioned, no one can prove what happened. Here is the receipt layer that changes that.

Read →
Compliance · 12 min

FDA Section 524B, explained: what "reasonable assurance of cybersecurity" actually requires

A plain guide to the three §524B obligations, the June 2025 final guidance, and the evidence an FDA submission actually needs.

Read →
HIPAA · 11 min

Is a clinical-AI audit trail HIPAA-compliant? Audit controls and accounting of disclosures

How a tamper-evident, PHI-free audit trail supports HIPAA §164.312(b) and §164.528, and why ordinary logs fail the test.

Read →
Post-quantum · 12 min

Why post-quantum cryptography matters for implants: harvest now, forge later

Implants run for a decade inside a realistic quantum window and are rarely re-secured. How post-quantum identity migrates a device without a recall.

Read →
Compliance · 12 min

The unpatchable medical device problem and the FDA compensating-control answer

You cannot patch a 12-year-old infusion pump. How FDA compensating controls and a sealed residual-risk dossier bring the risk to acceptable.

Read →
Provenance · 12 min

Non-device by design: staying on the right side of the FDA clinical decision support line

The FDA CDS fourth criterion separates a regulated device from software that supports it. Why attesting a decision, not rendering it, stays non-device.

Read →
Compliance · 12 min

AIBOM for healthcare: CISA and CycloneDX ML-BOM for clinical AI

An AI bill of materials inventories the model, datasets, and lineage behind clinical AI. The standards stack, and the missing signed-provenance piece.

Read →
Provenance · 12 min

How to choose between verifiable AI and AI governance (and tell which a vendor actually does)

Governance documents and manages risk. Verifiable AI proves, per decision, that a model was genuine. A buyer guide to which layer you need.

Read →
Liability · 14 min

Who is liable when a clinical AI decision is wrong?

When an AI-assisted decision harms a patient, who is accountable: the clinician, the hospital, or the AI vendor? How the evidence record decides. Includes an accountability mapper.

Read →
Governance · 12 min

Shadow AI in hospitals: finding and governing the clinical AI you did not authorize

Clinicians are using AI tools no one approved, and PHI is leaving the building. How to discover, govern, and verify it. Includes an exposure calculator.

Read →
HIPAA · 13 min

The proposed 2025 HIPAA Security Rule update: mandatory MFA, encryption, and clinical AI

The 2025 NPRM would make MFA, encryption, and audit controls mandatory. What changes, and what it means for clinical AI. Includes a readiness checklist.

Read →
Scope

What we write about.

Clinical-AI decision provenance, FDA §524B and the CDS non-device line, HIPAA audit controls and accounting of disclosures, AIBOM for clinical AI, EU AI Act obligations, the NIST AI RMF, and post-quantum security for implants and long-retention records. If a claim cannot be checked or a statistic cannot be attributed, it does not appear.

Get started

Proof for every clinical decision.

Bring a decision, an access flow, or a device, and verify the evidence yourself, without PHI, and without trusting us.