← The Protokol
The Operating System

Private by design: why your charting AI should never touch a frontier model

By Tom Higgins — I run Zvia, my Lakewood medspa, on the tool behind this.

Charting is where the most sensitive data in a practice is created: a recorded visit, a transcript, a clinical impression. The convenient thing to do is ship all of it to a frontier model in the cloud. We think that’s exactly the wrong default.

Private for the sensitive work

In ProtokolIQ, the model that drafts a SOAP note from a recording is private and self-hosted — never a frontier AI provider. The audio and the transcript are never sent to an outside AI service. The provider reviews the draft and signs it. Only data that has been de-identified is ever eligible to reach a frontier model — and a de-identification gate sits between the two by construction.

”PHI-free by construction” is an architecture, not a promise

A privacy policy is a promise. Architecture is a constraint. When the wiring makes it impossible for raw PHI to reach a frontier model, you don’t have to trust a vendor’s intentions — you can evaluate the design. That’s the bar a practice owner’s counsel should hold every clinical AI vendor to.

What this means for you

  • Audio and transcripts are never sent to a frontier AI provider.
  • PHI is encrypted at rest and tokenized in a vault.
  • Every model call is captured — prompt and response — for audit.

We’re HIPAA-aligned and a BAA is available. SOC-2 is on the roadmap. No product is “HIPAA certified” — and we’ll never claim to be.

When you want to see where your own practice stands, the Clinic Freedom Score walks you through it in a few minutes — or see the platform. Not a minute before.