A tamper-evident audit layer for CDS alerts, prior-auth decisions, PHI access, e-signatures, and SaMD inference — court-survivable proof that a specific decision was made, by whom, with exactly these inputs, at this time. It does not assert clinical truth; it proves the decision happened.
Which alert fired. What the clinician did. Who accessed the chart, and why. Whether a prior-auth denial followed its own guideline. Each becomes a row in an institution-controlled EHR audit log — never a signed artifact. When a decision is challenged in court or by a regulator, the reason is irrecoverable as verified evidence.
Average cost of a healthcare data breach — the most expensive sector for 14 straight years (IBM, 2025). 289M records were exposed in 2024 alone.
PHI access logs are mutable, internal, and not cryptographically bound to the data state.
Annual prior-auth administrative waste (AMA). 29% of physicians report a PA delay caused a serious adverse event — 8% a death or permanent harm.
No signed proof binds the guideline version to the denial at the moment it was rendered.
Rise in AI-related malpractice claims 2022–24. Over 35 US states have enacted AI-accountability laws; the EU AI Act adds high-risk logging duties from Aug 2026.
No CDS vendor emits a signed record of which alert fired, on what input, and what the clinician did.
A CDS override is a free-text note. A PHI access is a database row. A Part-11 e-signature is a boolean stored beside the record it signs. All mutable, all institution-controlled. Anima signs the decision event at the moment it happens — independently verifiable without trusting the hospital's own systems.
→ A Part-11 e-signature capsule can carry this decision's id as a foreign key. The signature can never outrun the exact record it signs.
§ 164.312(b) audit controls. The Jan 2025 NPRM makes technical safeguards mandatory; OCR's 2024–25 audits target audit-control sufficiency. Up to $1.9M/category/yr.
Signed e-records in FDA-regulated work need meaning-of-signature, record linkage, and two-component auth. Today the signature is a flag beside the record.
AI-device makers must prove each inference ran inside the authorized model-version envelope. 53 PCCPs authorized — zero signed per-inference standard exists.
Prior-auth denials must carry specific clinical rationale, with a PA Decision FHIR API by Jan 2027. Covers MA, Medicaid, CHIP, QHPs — the whole payer market.
Medical AI as an MDR/IVDR safety component is high-risk: automatic event logging with timestamps + input references, plus recorded human-oversight overrides (Art. 12).
500M records now exchanged via TEFCA; nonconformity letters issued Feb 2026, up to $1M/violation. Cross-network data needs portable, signed access provenance.
Native audit logs stored in the EHR's own database. Mutable, institution-controlled, exportable only with platform trust. KLAS-surveyed Epic customers say the trails "aren't robust enough" for privacy monitoring.
Behavioral analytics flag anomalous access — celebrity snooping, mass export. But they read the same mutable EHR log; detection is probabilistic and retrospective. They can flag what looks wrong, never prove what happened.
AI prior-auth and embedded alerting. Cohere itself states "no claim is denied exclusively by AI" — because the accountability chain isn't signed. No guideline-version-bound proof, no appeal-replay.
Each is an EIP-712 typed struct, secp256k1-signed, schema-published. Four carry Go↔Rust/WASM cross-language parity vectors enforced in CI; three are Go-signed with sign/verify tests, WASM parity pending. Source: internal/medical/signing/.
Each liability pool already has incumbents. None of them emit a signed, replayable proof of the decision and its exact inputs — that empty slot is the moat.
Average cost of a single healthcare breach — the costliest sector worldwide for 14 straight years (IBM, global). On top sits $1.3B US prior-auth waste and a rising AI-malpractice surface. Every market mirrors the demand: EU GMP Annex 11, GDPR Art. 9 and the EU AI Act impose the same signed-record duty.
AI-enabled medical-device (SaMD) market by 2034, from $11B in 2025 (21.5% CAGR). Every FDA PCCP and EU AI Act high-risk device needs per-inference provenance that does not exist today.
Anima is not a clinical system and not a truth oracle. It does not assert that a CDS recommendation or a PA denial was medically correct — it attests that the decision was made, with these inputs, under this model or guideline, at this time, and lets anyone replay it. That distinction is the legal moat.
Irreversible on creation. Replayable without trusting the hospital's, payer's, or vendor's own systems.
For the first time, a clinical decision can prove itself.