AI drafts it. A qualified person decides it.
Ryland is the AI inside Prusik Health. It reads your evidence against the regulation, drafts what it would write, and shows its reasoning so you can check the work. Deciding is not part of its job. Every output arrives as a proposal that a person accepts or edits or throws away, so your compliance record contains only what a human put there.
Compliance is a judgement call. Software should not pretend otherwise.
A HIPAA assessment is a statement your organization makes about itself, to a regulator, under its own signature. Handing that judgement to a model would be a bad trade even if the model were never wrong. When an investigator asks why you answered the way you did, "the software decided" is not an answer.
Ryland is built to take on the part of the work that is slow, and to leave alone the part that is yours to judge.
It works through the regulation so you are not holding hundreds of requirements in your head. It reads the evidence you attached and tells you where it falls short of what the requirement asks for. It drafts the remediation plan you were going to write anyway. At that point it stops and waits for you, because the next step is a decision and decisions belong to your team.
Four controls, enforced in the product
These are not policy statements. They are how the software behaves.
It is off until you turn it on
AI is disabled for every new organization. Enabling it is an explicit decision an admin makes, after reading exactly what would be sent and to whom. Nothing reaches a model before that.
It does not overwrite your answer
When Ryland reviews an assessment item, its verdict and its reasoning are stored beside your answer rather than on top of it. Your answer stays the one you gave. The review is an annotation you are free to disagree with.
You can overrule it, on the record
Disagree with a verdict and you overrule it with a note saying why. The override is stored with your name and the time, so the disagreement becomes part of the evidence rather than a silent edit.
A new review needs new attention
If the answer or its evidence changes, Ryland reviews it again and deliberately clears your previous override. A judgement you made about the old evidence is not allowed to stand as approval of the new.
Drafts work the same way. Ryland can write a remediation plan, a policy, a risk entry or a suggested answer, and every one of them lands in front of you as a proposal with an Apply button. If nobody presses it, nothing was written.
Most of this product is not AI, on purpose
Roughly a third of the services in Prusik Health involve a model. The rest are ordinary code, because ordinary code is better at their job.
Answered by code
Deterministic, repeatable, identical every time you ask.
- Your compliance score. Arithmetic over your own answers. A model would only make it less predictable.
- Which evidence has gone stale. A date comparison. Whether a file is older than a year needs no judgement.
- Duplicate evidence. A checksum. Two files either match exactly or they do not.
- Which controls your policies cover. Structural mapping between the requirements a policy cites and the controls they belong to.
- Every statutory deadline. Counted from the dates you enter, never estimated.
Helped by Ryland
Where the question genuinely needs reading comprehension, or a first draft.
- Does this evidence support this answer? Comparing a document against a requirement is reading work, and it is the slowest part of an assessment.
- What does this requirement mean for us? Plain-language explanation of a regulation, grounded in your own answers.
- Write me a starting point. Policies, remediation plans and risk entries you then edit into something true for your organization.
- What should we do next? Your open work ranked by impact, from your data alone.
The dividing line is simple. If a question has a correct answer that can be computed, we compute it. If it needs someone to read a document and form a view, Ryland drafts the view and you confirm it. Putting a model in front of a date comparison would be worse software wearing a better badge.
What Ryland is not allowed to do
Restrictions built into the product, not intentions we hold.
- Answering your assessment. It can draft a suggested answer for you to review. Applying that draft is a person's action, and the record shows which person took it.
- Signing anything. Signing an assessment requires a real person re-entering their password and clearing a second factor. There is no AI path to a signature.
- Deciding whether a breach is notifiable. That determination carries legal consequence and belongs to your privacy officer. Ryland helps you organize the incident; the deadlines are counted by code from the dates you enter.
- Going looking for patient data. Most of what Ryland sees is counts, labels and regulatory text. Two kinds of content can carry it: the evidence files you upload, which the review features read in full, and free text a person types — assessment notes, the interview description, an incident narrative, a finding title or description, or a question you ask Ryland. Either may contain PHI, and both go to the same BAA-covered zero-retention service. The model is instructed to judge that material without quoting a patient identifier or a record back to you.
- Taking instructions from your documents. Everything you upload is treated as material to analyze rather than as commands. Text inside a file that tries to steer a verdict is itself treated as a warning sign and resolved conservatively.
- Filling gaps with plausible guesses. Where your data does not support a conclusion, Ryland reports that the data is missing and names what you would need to capture. Silence is reported as silence.
The regulatory content Ryland reasons from is ours, and people review it
Ryland does not know HIPAA because it read the internet. It works from a question bank and a policy library written, cited and reviewed by healthcare security and privacy practitioners who hold CISSP, CISA and AI-governance credentials. When the model reasons about a requirement, it is reasoning over text a qualified person wrote and put their name to.
Reviewed before every release
When a question, a citation or a policy statement changes, the release stops until a specialist review pass has covered it, across the Security Rule, the Privacy and Breach rules, and the generated policies.
Every requirement carries its source
Questions cite the provision they implement, so you can check the regulation yourself rather than taking our word for it, or Ryland's.
Guided engagements add a named reviewer
On a guided assessment a practitioner works through your answers item by item and countersigns the finished report. You see who reviewed it, by name.
A regulatory claim does not reach you because a model was confident about it. It reaches you because a person put it there and stood behind the wording.
What is sent, and what happens to it
When you enable AI, the compliance material Ryland needs is sent to a third-party AI service for analysis. That material includes assessment answers, notes, evidence file contents and related records. The service operates under a business associate agreement that provides for zero retention and no training on your data.
We tell you this before you switch it on, in those words, because your organization needs to confirm the arrangement fits its own privacy posture and BAA obligations. If it does not, leave AI off. Everything else in Prusik Health works without it.
See where it helps, and where we left it out
Start an assessment and judge Ryland on its drafts. If you would rather interrogate the controls first, ask us and a person will walk you through them.
Ryland is included on the Premium and Advanced plans. The free tier covers the HIPAA Security Rule without AI — compare the plans.