Runtime control plane · Healthcare AI agents
Decide what agents may do with PHI. Sign what they did.
nxthreat sits between your AI agents and your EHR. It evaluates every tool call against policy, blocks what exceeds scope, and writes a signed receipt your auditor can verify — without production access.
FHIR R4 · MCP · minimum-necessary policy · append-only receipts
Decision receipt
no. 182,401 of chain
- Receipt
- rcpt_0000182401
- Recorded
- 2026-07-16T14:32:05.406Z
- Agent
- intake-agent-07 · midwest-health
- Tool call
- fhir.bulk_export → Patient/*
- Stated purpose
- intake_summarization
- Policy applied
- minimum-necessary / v41
- Decision
- Blockedbulk export exceeds task scope
Signature · AWS KMS tenant key
9f41c2…e708 ← links receipt 182,400
Illustrative receipt — one blocked call, recorded and signed
One gateway
in front of all agent tool traffic
Per operation
policy on the call, not coarse roles
Every decision
captured, chained, and signed
The control gap
Your agent can act. Can you say why it was allowed to?
API gateways authenticate requests. SIEMs record what already happened. Neither can decide, at the moment of the call, whether this agent should touch this record for this task — and neither leaves proof that anyone decided at all.
Know the caller
Identity for every agent
Shared bearer tokens make every agent look the same. nxthreat issues workload identity scoped to one agent, one tenant, one job — so a decision can name who asked.
Control the action
Policy on every tool call
The exact operation, FHIR resource, patient context, tool schema, and stated purpose are evaluated before access is granted. Not roles. The call itself.
Prove the outcome
Signed evidence by default
Every allow and every deny lands in an append-only receipt chain, signed with your KMS key. The audit trail exists before anyone asks for it.
In the request path
Security that runs at agent speed.
nxthreat sits where intent becomes action — the only place policy can still change the outcome instead of describing it afterward.
Intercept
Agent tool calls route through nxthreat before they reach MCP servers, FHIR endpoints, or internal APIs.
Decide
Identity, tool schema, operation policy, and returned content are evaluated in the request path — milliseconds, not batch review.
Attest
Each decision, allowed or blocked, produces a KMS-signed receipt chained to the one before it.
prior-auth-014
Patient.read
clinical-docs-03
Observation.search
intake-agent-07
fhir.bulk_export
prior-auth-014
Claim.search
Deployment model
Fits between your agents and your systems.
Keep the models, tools, and observability stack you already chose. nxthreat adds the enforcement layer in the middle — nothing else moves.
- Works with MCP, FHIR R4, and internal HTTP APIs
- Feeds existing SIEM and evidence workflows
- Tenant- and agent-scoped by design
runtime
nxthreat control plane
audit plane
Audit readiness
Evidence your auditor can verify without production access.
Export signed receipts by tenant, agent, resource, action, and date range. Hand compliance the evidence produced at runtime — not a spreadsheet reconstructed three weeks before the audit.
Review the HIPAA control mappingEvidence Pack
verifier includedAI Agent Activity Attestation
- Audit Period
- 2026-04-01 - 2026-04-30
- Tenant
- midwest-health
- Agents Covered
- 14
- FHIR Resources Touched
- Patient, Observation, Claim
- Receipt Count
- 182,401
- Signing Authority
- AWS KMS tenant key
Threat research
MCP made agent tooling portable. It also made tool definitions and transports part of your attack surface.
30-minute technical walkthrough
Bring your agent architecture. Leave with a runtime threat model.
No generic deck. We screen-share the control and evidence flow against your actual deployment — agents, tools, and the systems they touch.
Book a technical walkthrough