Key facts
| Healthcare fit | Boundary matched to privacy analysis; one API across deployments |
| Private access | Private endpoints; traffic stays in the deployment you select |
| Residency | Region-locked planes plus VPC, on-prem and air-gapped |
| Identity | Scoped keys per clinical service; SSO with SCIM and RBAC |
| Retention | Configurable prompt retention; confirm your terms in the DPA |
| Audit | Inference, key and admin events exportable to SIEM |
| Models | 30+ models behind one OpenAI-compatible API |
| Pricing | Flat monthly self-serve plans; no per-token billing |
TL;DR
- Choose the boundary from your privacy analysis, not from vendor defaults.
- Minimise or de-identify PHI before it reaches any model, private or not.
- Give each clinical service a minimum-necessary scoped key; keep staff on SSO.
- Set retention per workload and confirm the terms in the DPA.
- Export auth, key and inference events so a reviewer can reconstruct activity.
How it works, step by step
- Complete the privacy and risk analysis for the intended workflow before selecting a deployment boundary.
- Choose the lightest boundary that satisfies the analysis: region-locked plane, VPC, on-prem or air-gapped.
- Design de-identification and redaction into the pipeline, and verify that identifier mappings stay inside hospital systems.
- Issue minimum-necessary scoped keys per service and environment, and require SSO with SCIM for staff access.
- Set retention to the shortest period the records policy allows and confirm it in the DPA and contract review.
- Export authentication, key, admin and inference events to the security platform, and rehearse incident response.
- Pilot with mandatory human review, measure accuracy and edit rates, then expand only on evidence.
Try it yourself
Open the AI data residency checklist →
Privacy by design, not by vendor promise
Healthcare's hard question is not which model to use but what data may leave which boundary. Plugsky supports four placements — region-locked plane, VPC, on-prem and air-gapped — with the same OpenAI-compatible API, so the boundary can follow the privacy analysis: shared region for de-identified back-office work, hospital tenancy or network for anything touching patient data, air-gapped for the most sensitive programmes.
Whatever the placement, minimise first. Send only the fields the task requires, redact identifiers where the workflow allows, and keep the mapping between identifiers and pseudonyms inside hospital systems. That single discipline reduces risk more than any deployment choice.
Controls healthcare reviews ask for
Reviews focus on access, retention and evidence. Build them into the pilot from day one.
- Access: minimum-necessary scoped keys per clinical service; no shared credentials.
- Identity: SSO with SCIM for staff, RBAC for administrative actions.
- Retention: configurable per workload, aligned with records policy and confirmed in the DPA.
- Evidence: authentication, key lifecycle, admin and inference events exported to security operations.
Keep statements precise: Plugsky provides scoped authentication, retention settings, audit export and deployment variants. It does not practice medicine, manage consent or confer a compliance certification on your organisation.
Clinical governance and operational reality
Start with workflows where a clinician or coder reviews every output: documentation support, coding assistance, inbox triage. That keeps accountability clear and makes measurement straightforward — accuracy on a held-out set, escalation rates, proportion of outputs edited before use. Route routine steps to smaller models and reserve larger tiers for reasoning, all behind one API with 30+ models.
Plan operations too: private placements put capacity, patching and monitoring on your team, so compare total cost with the flat monthly plans on the live pricing page. Endpoint coverage is the same everywhere — chat, streaming, JSON mode, function calling and embeddings are live, while audio, images and files are labelled coming soon.
Honest comparison
| Concern | Plugsky private AI | Consumer AI apps | DIY open-source stack |
|---|---|---|---|
| PHI path | Region, VPC, on-prem or air-gapped at your choice | Vendor cloud on vendor terms | Inside hospital infrastructure |
| Minimisation | Supported in your pipeline; you control inputs | Mostly user-managed | Entirely your responsibility |
| Identity | Scoped keys, RBAC, SSO/SCIM | Personal accounts | Custom-built |
| Retention | Configurable; confirmed in the DPA | Vendor-defined | Hospital-defined |
| Effort | Days to pilot, more for on-prem | Minutes | Months |
Frequently asked questions
Is Plugsky HIPAA compliant?
Plugsky provides the controls you assess — scoped authentication, retention settings, audit export, deployment options and a DPA. Whether a specific use is compliant depends on configuration, contracts and policies; determine that with your compliance team.
Should PHI ever go into a prompt?
Only when the workflow requires it and your analysis permits. Minimise fields, redact identifiers where possible, and keep mappings inside hospital systems.
Which boundary should we pick?
The lightest one your privacy analysis allows. Region-locked planes and VPC cover most clinical workloads; on-prem and air-gapped are for stricter requirements.
How do clinicians sign in?
Through your IdP with SSO, provisioned with SCIM and authorised with RBAC roles. Clinical services use scoped keys rather than staff accounts.
What retention can we configure?
Retention is set per workload to the shortest period the records policy allows, with the terms confirmed in the DPA.
What evidence can we show auditors?
Authentication, key lifecycle, administrative and inference events exported to your security platform, giving a joined view of access and model activity.
How do we start safely?
A documentation workflow with human review on a free workspace and synthetic data, then move to a paid plan or the 14-day full-access trial as evidence accumulates.