For the Accuity platform & engineering team · Concept brief

Clinical AI runs on the most sensitive data there is.

Accuity applies AI to clinical documentation — which means the data flowing to your models is PHI, the most regulated, highest-stakes information a company can handle. Every prompt that reaches Claude or any provider has to be controlled, logged, and provable. You already run on Cloudflare — and the same platform has the governance layer built for exactly this: redact, audit, and control the data before it leaves your edge.

PHI-safe
Control data before it reaches a model
Audit-ready
Every prompt + response logged
Already on CF
Self-serve today — no new vendor

Most companies adding AI worry about cost. In clinical documentation, the first question is compliance. When AI reads patient records to improve documentation, the inputs are PHI — so every model call is a potential disclosure event. You need to know exactly what was sent to which provider, strip or tokenize sensitive fields before they leave your control, retain an audit trail for every interaction, and cap cost as volume scales across hospitals. Doing that with bespoke code per integration is slow and risky. Doing it at the edge — on the platform you already run — is a configuration.

Govern the clinical-AI pipeline, on the edge you already use.

Lead with the PHI-and-AI problem; the rest of the platform secures the workforce and apps around it.

Govern the clinical AI

AI Gateway Start here

One control plane for "PHI-safe model routing" across every provider Accuity runs — Claude, Azure AI Foundry, and whatever's next. Redact PHI before it reaches a model, log every prompt and response for the decision traceability and auditability clinical AI demands, and produce the reproducible evaluation records behind metrics that govern commercial terms. Multi-provider governance Azure-native tooling can't give you on its own.

🔒
Protect the workforce

Zero Trust (Cloudflare One)

Physician-led, distributed teams access systems holding patient data. Replace VPN with identity-aware, least-privilege access — every reviewer reaches only what they're entitled to, fully logged — alongside the Microsoft Entra stack you already run.

Close the gaps

Email Security + DLP

Healthcare is the #1 target for phishing and data breaches. Add a dedicated email security layer over Microsoft 365, and DLP to keep PHI inside sanctioned apps — on the same platform.

Run the platform

Workers + R2

Build the documentation-improvement product on a serverless edge, with zero-egress storage for the clinical data and model artifacts behind it — scaling per hospital without standing up new infrastructure each time.

You're already a Cloudflare customer.

Accuity already runs on Cloudflare on the self-serve plan — so this isn't a new-vendor evaluation, it's a graduation. Moving to a focus relationship brings dedicated support, the governance controls a HIPAA-regulated AI workload needs, and the ability to put the most sensitive part of the product on the platform you already trust.

Already on Cloudflare AI Gateway for PHI-safe AI Zero Trust for clinical teams Dedicated support + SLA

The most sensitive AI workload deserves the most governed edge.

Accuity is doing something genuinely hard: applying AI to clinical documentation without compromising the data that makes it sensitive. Cloudflare is where that pipeline gets governed — PHI controlled before it reaches a model, every call audited, the workforce secured — on the platform you already run. Worth 30 minutes to map it to how Accuity is built today?

Matt Holscher · Cloudflare Digital Native team