Open governance framework · v1.3 · Practitioner-led · not an accredited standard, certification, or regulatory requirement · seeking shadow-evaluation partners
Home/Regulatory Alignment

Alignment · June 2026

Regulatory Alignment

How NHID-Clinical maps to current healthcare AI governance requirements.

Note: NHID-Clinical is an open governance framework, developed independently from direct payer operations experience. It is not an accredited standard, certification, or regulatory requirement.

How NHID-Clinical Maps to Current Requirements

This is not legal advice. NHID-Clinical is voluntary. The table below shows how the controls relate to key regulations and guidance as of June 2026. Fairness and clinical-safety governance are intentionally out of scope — see the scope boundary note.

Regulatory Driver Specific Requirement NHID-Clinical Control
CMS-0057-F Prior Auth Final Rule FHIR API, 72-hour turnaround, 5-year retention HL7 FHIR R4 AuditEvent (validated) + session trace (ATR-01) — mapping spec
MACPAC May 2026 AI transparency in prior auth, human review pathway IDG-01 + EIT-01 (escalation) + ATR-01
DOJ FCA 2026 Enforcement Focus Explainability + audit trail for AI-assisted billing Structured trace + CTS conformance (ATR-01)
State AI Laws (CA, TX, MD, etc.) Inspectable, auditable AI decisions IDG-01 + DBC-01 + L1/L2/L3 tiers
NIST AI RMF / CAISI Cross-org agent identity + authorization NHID-Auth v2 + NIST-2025-0035-0026 comment

FHIR R4 AuditEvent Emission

Every NHID-Clinical conformance test suite (CTS) execution produces a HL7 FHIR R4 Bundle of AuditEvent resources — one per conformance milestone. These Bundles are validated against the FHIR R4 base specification (version 4.0.1) in CI before every merge.

What is emitted per call:
  1. nhid-session-start — call session initialised (DCM Application Activity)
  2. nhid-identity-disclosure — IDG-01 gate evaluated; outcome reflects pass/fail (DCM Security Alert)
  3. nhid-auth-verification — provider NPI authorization recorded, when present (DCM User Authentication)
  4. nhid-phi-gate — PDX-01 pre-data-exchange gate decision (DCM Security Alert)
  5. nhid-phi-exchange — PHI exchange begins, when gate cleared (DCM Patient Record)
  6. nhid-escalation — EIT-01 escalation event, when triggered (DCM Application Activity)
  7. nhid-call-end — session terminated; outcome reflects aggregate policy decision (DCM Application Activity)
Conformance scope: Validated against HL7 FHIR R4 base specification only. No conformance to any named HL7 Implementation Guide is claimed or implied. DICOM audit event type codes (DCM 110100, 110110, 110113, 110114) are used for AuditEvent.type. Three agent slices capture the AI voice agent (requestor), payer system (destination), and provider organisation (on-behalf-of, when NPI is present).
AuditEvent Mapping Spec → Example Bundle (JSON) → Payer Ingestion Guide →

STIR/SHAKEN

STIR/SHAKEN attests that a number is legitimate — not that the caller is authorized to access protected health information.

Trust Stack

LayerStandardWhat it proves
CarrierSTIR/SHAKENNumber is legitimate
DisclosureNHID-Clinical v1.3AI status declared before PHI exchange
AuthorizationNHID-Auth v2Cryptographic delegation from provider

CMS-0057-F

This page maps NHID-Clinical v1.3 controls to the CMS Prior Authorization Final Rule (CMS-0057-F) requirements for AI transparency in prior authorization workflows.

NHID-Clinical Alignment

CMS-0057-F RequirementNHID-Clinical ControlArtifact
FHIR API for PA transactionsATR-01FHIR AuditEvent R4 mapping
AI transparency in decisionsIDG-01CTS conformance test suite
Human review availabilityEIT-01Safe escalation phrases

NIST AI agent standards

This is an open proposal submitted to NIST docket NIST-2025-0035-0026.

NIST AI RMF Alignment

NIST AI RMF FunctionNHID-Clinical Control
GOVERN 1.1IDG-01 — AI system status disclosed
MANAGE 2.2EIT-01 — Human escalation path
MEASURE 2.5ATR-01 — Auditable trail

Vendor evidence pack

Minimum evidence a voice AI vendor should produce to demonstrate NHID-Clinical conformance.

Read the control text these mappings refer to

Each mapping above points at a specific v1.3 control. The specification defines them normatively.

Open the specification →   Browse the controls →

Where to go next

Four ways into NHID-Clinical, whatever you came to do.