TwinEthosRequest access

Control

More health information than the task needs is sent to an AI model

Prompts, retrieval context, and fine-tuning sets built from health records carry only the fields the AI task needs, never the entire record by default.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.health-data-to-ai-exceeds-minimum-necessary

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in United States (federal) (US).

The guard to add

Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.

In the prompt builder or retrieval step for each AI task that reads health records, define the fields that task needs (a TASK_FIELDS allowlist, pydantic model_dump(include=...), FHIR _elements or _summary on the query) and pass only those; do not json.dumps a patient, chart or encounter object, call a get-full-chart helper, or fetch Patient/$everything to feed a model. Keep the per-task field list as the standard protocol for that routine AI use and review it when the task changes. Where a task genuinely needs the whole record, record that justification next to the code path; de-identifying the input is an alternative.

Where it goes: 7 prompt construction, 2 data models, 6 API calls and integrations.

What reviewers look for: prompts, retrieval context and fine-tuning rows assembled from an explicit per-task field list or a narrowed FHIR query, with no json.dumps(patient), JSON.stringify(chart), encounter.to_dict(), get_full_chart( or $everything in files that call a model API; any whole-record use carries a written justification.

Example (Python + OpenAI SDK), before:

patient = ehr.get_patient(pid)
prompt = 'Write a discharge summary for: ' + json.dumps(patient)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

DISCHARGE_FIELDS = ('age', 'admit_reason', 'procedures', 'discharge_meds', 'follow_up')
patient = ehr.get_patient(pid)
selected = {k: patient[k] for k in DISCHARGE_FIELDS}
prompt = 'Write a discharge summary for: ' + json.dumps(selected)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)