Mark HollandSenior AI Solutions Engineer

PresidioFlow

PrototypeIndependent platform

Healthcare data pipelines reject records that break the format, and someone has to fix them and show an auditor what changed. PresidioFlow repairs HL7, FHIR, and X12 records with tiered rules and an LLM that never sees PHI, and writes every step into a hash-chained ledger anyone can check.

Re-verify its ledger in your browser
PresidioFlow audit snapshot check: chain linkage, per-record re-hash, and integrity checksum all pass for 341 entries; the signature is marked not checked.

What it does

  • Validates and remediates HL7 v2, FHIR R4, X12 837, and X12 835 records with tiered rules and LLM remediation (48% tier-one auto-repair on test data).
  • PHI is tokenized so it never reaches an LLM, every change lands in a hash-chained audit ledger, and signed evidence packs map to SOC 2, HIPAA, and ISO 27001.

From my resume.

Who it is for

Teams that run regulated healthcare data pipelines and must show auditors what happened to each record.

The outcome

48%

Tier-one auto-repair, on test data.

How it works

PresidioFlow, step by step
  1. Validate

    Each record is checked against its format: HL7 v2, FHIR R4, X12 837, or X12 835.

  2. Tokenize

    PHI is tokenized, so it never reaches an LLM.

  3. Repair

    Tiered rules fix what they can, and LLM remediation handles the rest.

  4. Record

    Every change lands in a hash-chained audit ledger.

  5. Prove

    Signed evidence packs map to SOC 2, HIPAA, and ISO 27001 and verify offline.

The real screens

PresidioFlow audit snapshot check: chain linkage, per-record re-hash, and integrity checksum all pass for 341 entries; the signature is marked not checked.
  1. Chain linkage. Every row's previous hash matches the row before it, from genesis to entry 341.

  2. What was not checked. The export carries no signature, and the check says so instead of implying it.

Test dataThe June 9 2026 export checks out: 341 of 341 entries. This audit snapshot carries a checksum only, and says so; PresidioFlow's evidence packs are signed separately with a KMS key (sourced, not shown here).
PresidioFlow audit ledger timeline: validation started, validation failed with the HL7 error, and remediation attempts, each with its previous hash, hash, and sequence number.
  1. Hash chain. Each event stores the previous hash, its own hash, and its sequence number, then the next event begins.

  2. Who acted. Every event names its actor: the system, or the AI agent and the model it used.

Test dataOne record's path through the ledger. Every event carries the hash of the one before it.

The decision that matters

The model never sees PHI

PHI is tokenized before remediation, so the LLM repairs structure it cannot read. A build gate backs it: a test that fails if PHI could leave.

Built with

  • HL7 v2, FHIR R4, X12 837 and 835
  • AWS Lambda
  • Amazon Bedrock
  • AWS KMS signing
  • Python

Checked evidence

  • Verified The June 9 2026 audit export re-verifies 341 of 341 entries, in this browser and with the Python script.
  • Sourced PHI tokenization with a test_no_phi_egress build gate.
  • Sourced KMS-backed ECDSA P-256 signed evidence packs that verify offline.