NHID-Clinical
An open framework for healthcare AI agent identity, authorization, disclosure, and audit evidence.
The specification, tests, and reference implementation remain open. TrustLayer provides optional production infrastructure for organizations running AI agents at scale.
Voluntary and testable — not an accredited standard, certification, or regulatory requirement. No production pilots yet; seeking the first shadow-evaluation partners.
Why NHID exists
Impersonation latency
The measurable trust delay between an AI agent initiating a call and the receiving system verifying that the caller is authorized to represent the claimed organization.
In most healthcare voice workflows today that delay is effectively infinite, because no standard verification pathway exists. Telephony authenticates the number. Identity systems authenticate the account. Neither establishes that this caller may act for that provider — so operational data changes hands during the gap.
NHID-Clinical exists to make that delay measurable, then to close it: disclose before data moves, verify delegated authority, enforce scope, and leave a replayable record.
Easy to adopt
Start in three steps
Observe-only, on your own call logs. No vendor changes, no production risk.
Read & try
Skim the v1.3 specification and run a scenario in the simulator to see the controls fire.
Open the simulator →Run a shadow pilot
Measure impersonation latency on your own logs in 2–4 weeks with the Tier 0 Shadow Pilot Kit.
Get the pilot kit →Review & decide
Use the evidence pack and your own numbers to decide what to require of vendors.
Review the evidence →Visualizing the Five-Layer Trust Stack
The architecture in one picture: each layer is testable on its own, and together they turn "trust me" into a verifiable pathway. Click a layer to see what it does and where to try it.
The authoritative definitions live in the specification.
This is an open voluntary reference implementation, not a product or certification. Layer definitions and control text are normative only in the v1.3 specification.
The impersonation latency problem
The window where an AI agent is already talking and exchanging data — member IDs, NPIs, dates of birth, claims — before anyone can confirm it is automated and authorized. Telephony and IAM verify the number or account, not that this caller may act for that provider.
Without a baseline
- No proactive identity disclosure
- PHI potentially exchanged before verification
- No consistent escalation or audit trail
- Infinite trust delay for the receiving system
With NHID-Clinical v1.3
- Mandatory early disclosure gate (IDG-01)
- Pre-data exchange verification checkpoint (PDX-01)
- Defined human handoff + full audit requirements (EIT-01 · ATR-01)
- Measurable, testable trust pathway
This is an open voluntary reference implementation, not a product or certification. It is contributed to improve ecosystem trust and has been submitted as public comment to NIST (NIST-2025-0035-0026).
The control layer
Six checks on every AI-agent call.
Each is observable on a real call and checkable against a machine-readable trace. Mapped, not certified.
Identity Disclosure Gate
Disclose non-human identity before any PHI is exchanged.
Pre-Data Exchange Gate
No protected data moves until identity is disclosed.
Deceptive Behavior Check
No synthetic human-presence cues or false human-status claims.
Escalation Implementation Test
A clear human handoff, honored on request.
Audit Trail
Every call produces a machine-readable trace.
Call Authorization Score
One per-call score summarizing conformance across the controls.
Open core vs platform
What is open, and what is operated
The left column is free forever under CC BY 4.0 and needs nothing from us. The right column is what TrustLayer runs on your behalf when you would otherwise build and operate it yourself.
| Capability | Open framework | TrustLayer |
|---|---|---|
| Specification | ✓ CC BY 4.0, always free | ✓ Same specification |
| Conformance tests | ✓ Run them yourself | ✓ Hosted and scheduled |
| Simulator | ✓ Open, no account | ✓ Plus evaluation of your own agents |
| Documentation | ✓ Public | ✓ Public |
| Reference implementation | ✓ Fork it, vendor it, replace it | ✓ Managed and operated |
| Community | ✓ Issues, discussions, pull requests | ✓ Same community |
| Hosted monitoring | — Run it yourself | ✓ Continuous, on every agent change |
| Dashboards | — | ✓ Fleet-wide operational view |
| Agent registry | — Passport format only | ✓ Managed identity lifecycle |
| Evidence center | — Evidence pack template | ✓ Generated audit-ready packages |
| Enterprise integrations | — | ✓ SSO, RBAC, SIEM, approvals |
Adopt it yourself
Everything you need to implement, test, and evidence the controls without talking to anyone.
Explore the framework →Operational trust infrastructure
Monitoring, evidence, identity management, authorization, and reporting for AI agents in production.
See the platform →Live conformance API
One call in, a verdict out.
Send a native VAPI or Twilio call payload and get a deterministic pass/fail across the controls, plus a per-call Call Authorization Score. No key required for demo routes.
Illustrative result — not a live API response.
What it is
- — A voluntary, testable behavioral baseline for AI voice agents making administrative calls to payers
- — An open reference implementation: policy engine, conformance test suite, audit trace schema
- — Scoped to B2B provider-to-payer administrative voice workflows only
What it is not
- — A regulatory requirement or accredited standard
- — A certification body or compliance guarantor
- — An identity verifier (v1.3 standardizes observable disclosure and trace behaviors; cryptographic authorization is documented but not yet solved)
Key tools
Specification (v1.3)
The full control set: IDG-01, PDX-01, DBC-01, EIT-01, ATR-01, and the event schema.
Read the specification →Live demo call
Hear the disclosure controls trigger in a real voice call, with a step-by-step script.
Try the live demo →Shadow Evaluation Guide
The structured 90-day process for payers — no vendor changes required.
View the guide →Evidence Pack
Guarantees, a worked failure trace, and the audit-readiness model for procurement.
Review the evidence pack →Simulator
The open simulator demonstrates NHID-Clinical controls.
Sit at a payer desk and watch an AI caller reveal itself too late. The zero-latency modules, dashboard, knowledge base, and evaluation records are all open — no account, no signup, nothing to install.
The simulator is education and demonstration — not the framework itself, and not a certification.
Illustrative evaluation record — open the simulator for a live run.
Two ways in
Pick the path that matches your job
Both start free. Neither requires a commercial relationship to get value.
Developer pathway
You are building an AI agent, or integrating one, and need to show it behaves.
- Read the controls. Five deterministic checks, each observable on a real call.
- Run the conformance suite against your engine and read the per-control verdicts.
- Try the live API — demo routes need no key. Send a VAPI or Twilio payload.
- Wire it in using the reference implementation, adapters, and trace schema.
- List your implementation in the self-attested registry when you are ready.
Enterprise pathway
You are a payer, provider organization, or health system receiving or operating AI agent traffic.
- Run a shadow evaluation on your own call logs. Observe-only, no vendor changes.
- Measure your baseline — how long is your impersonation latency today?
- Review the evidence pack and decide what to require of your vendors.
- Register your agents so identity, ownership, and scope are enumerable.
- Operate continuously with monitoring, evidence generation, and enterprise integration.
NIST AI Safety Institute — Public Comment
Submitted to NIST docket NIST-2025-0035
NHID-Clinical was submitted as a public comment to NIST's AI-agent security docket in January 2026. This is a public comment — not an endorsement, not a standard. It puts the problem on the record.
View on Regulations.gov →Get involved
Read the specification. Run a shadow pilot. Tell us where it breaks.
Whether you think it is right, wrong, incomplete, or misses the real problem — that feedback shapes the next version.