Use Cases/Compliance-heavy systems/Healthcare (HIPAA)
Healthcare (HIPAA)

PHI handling that survives a BAA review.

Patient data needs encryption, scoped access, and an audit trail granular enough to answer "who saw what, when?"

01 — Problem

Generic vector stores treat PHI like any other blob. Compliance teams say no — and they're right to.

02 — What CortexDB does

Capabilities that map directly to the pain.

01

Field-level encryption

Per-field keys, rotatable without re-indexing.

02

Per-clinician audit trail

Every read is an event. Reconstruct exactly which records each user touched.

03

Tenant isolation

Per-practice, per-org, or per-patient namespaces.

04

BAA-ready deployment

Self-hosted or VPC-isolated managed deploys.

03 — Why CortexDB

The architectural decisions that matter here.

Right-to-erasure

Tombstone events with cryptographic proof of removal.

Next step

Want to see this running on your data?