Kehr Technologies

Our Services  /  AI Services  /  AI Assessment  /  Regulated Businesses

AI Assessment for Regulated Businesses

When patient records, client files, or donor data are involved, the compliance question has to be answered before anything touches production, not discovered halfway through a rollout.

Why This Is a Different Engagement

The Question Is Not Just "Does It Work"

In an ordinary business, a promising AI use case can be tested and judged on results. In a medical practice, a law firm, or a grant-funded non-profit, a use case that works beautifully can still be one you are not permitted to run because of where the data would travel, who could see it, what the vendor’s terms allow them to do with it, or what you told a funder or a client you would do.

That means the assessment carries an extra layer. Alongside the process mapping and the use-case ranking, we establish what data is in scope, what obligations attach to it, which vendors can be used under agreement, and where the human review points have to sit. Those constraints then shape the roadmap rather than getting bolted on afterward.

The reason this matters commercially: unwinding an AI workflow that was built without those constraints is far more expensive than designing within them from the start, and in a regulated setting the exposure is not only financial.

The regulated offices we assess are mostly concierge medical practices, law firms, and optical practices around Dallas, plus a handful in Plano and McKinney. Their obligations are identical to a larger organization, but the staff carrying them number eight people, and the assessment has to respect that.

The Extra Layer

Five Things We Establish Before Anything Else

1

What Data Is Actually in Scope

Regulated data is rarely confined to the system everyone thinks it is in. It appears in email threads, scanned attachments, and shared drives nobody has audited in years.

2

Which Vendors Can Be Used at All

Whether a business associate agreement is available, what the terms say about training on your data, and where processing physically happens. Consumer tiers usually fail this immediately.

3

Where Shadow AI Is Already Running

In regulated organizations this is the finding that changes the meeting. Staff pasting records into consumer tools is a live exposure, not a hypothetical one. See What Is Shadow AI?

4

Where Human Review Must Sit

Some outputs may never go out unreviewed regardless of accuracy. Establishing those checkpoints early is what makes an approved workflow possible at all.

5

What You Have Already Promised

Engagement letters, notices of privacy practices, and grant agreements often contain commitments about data handling that predate anyone thinking about AI.

By Sector

What Changes Depending on Who You Are

Medical Practices

PHI defines the boundary. The assessment establishes which vendors will sign a BAA, where de-identification is required, and which clinical-adjacent outputs must stay under human sign-off.

Law Firms

Confidentiality and privilege define the boundary, and conflicts of interest complicate anything that pools matter data. Client consent language is frequently the gating item.

Non-Profits

Donor data and grant conditions define the boundary. Funders increasingly ask what technology touches beneficiary information, and the answer needs to exist before the question arrives.

Home Health & Therapy

PHI travels on mobile devices in the field, which widens the exposure surface considerably and makes device policy part of the AI conversation rather than separate from it.

FAQS

Frequently Asked Questions

What regulated organizations ask before starting.

Are you giving us legal advice?

No. We are a technology firm. We establish what the systems do, what the vendor terms permit, and where data travels, and we present that clearly enough that your counsel or compliance officer can make the call. We work alongside them; we do not replace them.

Yes, and many already do, usually starting with work that never touches regulated data at all, such as scheduling, intake triage, or internal documentation. The constraint narrows the field of use cases; it does not close it.

Expect to. It is nearly universal and it is rarely malicious. People are trying to do their jobs faster. The response that works is a sanctioned alternative plus a written policy, not a blanket ban, because bans push the behavior somewhere you cannot see it.

Somewhat, because of the additional review layer and because compliance stakeholders need to be part of the conversation. We build that into the scope up front so the timeline you approve is the timeline you get.

We support medical practices, law firms, non-profits, and home health and therapy providers across Dallas, and we hold a HIPAA Seal of Compliance. Ask us on the first call, and we will tell you plainly how close our experience is to your situation.

BK

Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022. He holds a HIPAA Seal of Compliance and has scoped AI work for medical practices, law firms, and grant-funded organizations in the Dallas area.
Last reviewed August 2026 · Questions we have not answered here? Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.

Continue Reading

HIPAA & AI

What PHI means for AI tooling, in practical terms.

AI Governance & Compliance

The ongoing service that keeps approved workflows approved.

The 12-Point Checklist

Screen your readiness before commissioning anything.

Scroll to Top