Open governance framework · v1.3 · Practitioner-led · not an accredited standard, certification, or regulatory requirement · seeking shadow-evaluation partners
Open framework · v1.3 · CC BY 4.0

NHID-Clinical

An open framework for healthcare AI agent identity, authorization, disclosure, and audit evidence.

The specification, tests, and reference implementation remain open. TrustLayer provides optional production infrastructure for organizations running AI agents at scale.

Soft isometric illustration: floating governance platforms connected by verified identity nodes, with disclosure, verification, and audit tokens.

Voluntary and testable — not an accredited standard, certification, or regulatory requirement. No production pilots yet; seeking the first shadow-evaluation partners.

Why NHID exists

Impersonation latency

The measurable trust delay between an AI agent initiating a call and the receiving system verifying that the caller is authorized to represent the claimed organization.

In most healthcare voice workflows today that delay is effectively infinite, because no standard verification pathway exists. Telephony authenticates the number. Identity systems authenticate the account. Neither establishes that this caller may act for that provider — so operational data changes hands during the gap.

NHID-Clinical exists to make that delay measurable, then to close it: disclose before data moves, verify delegated authority, enforce scope, and leave a replayable record.

See how the controls close it

Mapped to & aligned with

NIST AI RMF 1.0Map & Measure functions EU AI Act Art. 50Transparency obligations ISO/IEC 42001Annex A transparency FHIR R4AuditEvent evidence STIR/SHAKENCarrier authentication
Who it's for Payers Providers AI vendors Regulators Researchers
446passing tests in the open repo (Phase 6A infrastructure)
4 + 1controls (IDG · PDX · DBC · EIT) plus ATR-01 audit
Liveconformance API — no key for demo routes
CC BY 4.0open · NIST comment on record

Easy to adopt

Start in three steps

Observe-only, on your own call logs. No vendor changes, no production risk.

1

Read & try

Skim the v1.3 specification and run a scenario in the simulator to see the controls fire.

Open the simulator →
2

Run a shadow pilot

Measure impersonation latency on your own logs in 2–4 weeks with the Tier 0 Shadow Pilot Kit.

Get the pilot kit →
3

Review & decide

Use the evidence pack and your own numbers to decide what to require of vendors.

Review the evidence →
Start a pilot

Visualizing the Five-Layer Trust Stack

The architecture in one picture: each layer is testable on its own, and together they turn "trust me" into a verifiable pathway. Click a layer to see what it does and where to try it.

Diagram of the NHID-Clinical five-layer trust stack: STIR/SHAKEN carrier authentication, NHID-Clinical v1.3 behavioral disclosure, NHID-Auth v2 cryptographic authorization, FHIR AuditEvent R4 audit logging, OpenTelemetry observability.

The authoritative definitions live in the specification.

This is an open voluntary reference implementation, not a product or certification. Layer definitions and control text are normative only in the v1.3 specification.

The impersonation latency problem

The window where an AI agent is already talking and exchanging data — member IDs, NPIs, dates of birth, claims — before anyone can confirm it is automated and authorized. Telephony and IAM verify the number or account, not that this caller may act for that provider.

Diagram contrasting the impersonation latency problem (left: an unverified caller reaching PHI with no checks) with the verified trust pathway enabled by NHID-Clinical (right: disclosure gate, verification checkpoint, sealed PHI, human escalation).

Without a baseline

  • No proactive identity disclosure
  • PHI potentially exchanged before verification
  • No consistent escalation or audit trail
  • Infinite trust delay for the receiving system

With NHID-Clinical v1.3

  • Mandatory early disclosure gate (IDG-01)
  • Pre-data exchange verification checkpoint (PDX-01)
  • Defined human handoff + full audit requirements (EIT-01 · ATR-01)
  • Measurable, testable trust pathway

This is an open voluntary reference implementation, not a product or certification. It is contributed to improve ecosystem trust and has been submitted as public comment to NIST (NIST-2025-0035-0026).

The control layer

Six checks on every AI-agent call.

Each is observable on a real call and checkable against a machine-readable trace. Mapped, not certified.

Identity Disclosure Gate IDG-01

Identity Disclosure Gate

Disclose non-human identity before any PHI is exchanged.

Pre-Data Exchange Gate PDX-01

Pre-Data Exchange Gate

No protected data moves until identity is disclosed.

Deceptive Behavior Check DBC-01

Deceptive Behavior Check

No synthetic human-presence cues or false human-status claims.

Escalation Implementation Test EIT-01

Escalation Implementation Test

A clear human handoff, honored on request.

Audit Trail ATR-01

Audit Trail

Every call produces a machine-readable trace.

Call Authorization Score CAS

Call Authorization Score

One per-call score summarizing conformance across the controls.

Open core vs platform

What is open, and what is operated

The left column is free forever under CC BY 4.0 and needs nothing from us. The right column is what TrustLayer runs on your behalf when you would otherwise build and operate it yourself.

CapabilityOpen frameworkTrustLayer
Specification CC BY 4.0, always free Same specification
Conformance tests Run them yourself Hosted and scheduled
Simulator Open, no account Plus evaluation of your own agents
Documentation Public Public
Reference implementation Fork it, vendor it, replace it Managed and operated
Community Issues, discussions, pull requests Same community
Hosted monitoring Run it yourself Continuous, on every agent change
Dashboards Fleet-wide operational view
Agent registry Passport format only Managed identity lifecycle
Evidence center Evidence pack template Generated audit-ready packages
Enterprise integrations SSO, RBAC, SIEM, approvals
The specification is never paid. No tier, plan, or contract gates the specification, the control catalog, or the conformance test suite. If TrustLayer disappeared tomorrow, every open component would keep working.
Open framework

Adopt it yourself

Everything you need to implement, test, and evidence the controls without talking to anyone.

Explore the framework →
TrustLayer

Operational trust infrastructure

Monitoring, evidence, identity management, authorization, and reporting for AI agents in production.

See the platform →

Live conformance API

One call in, a verdict out.

Send a native VAPI or Twilio call payload and get a deterministic pass/fail across the controls, plus a per-call Call Authorization Score. No key required for demo routes.

Try the live API

What it is

  • A voluntary, testable behavioral baseline for AI voice agents making administrative calls to payers
  • An open reference implementation: policy engine, conformance test suite, audit trace schema
  • Scoped to B2B provider-to-payer administrative voice workflows only

What it is not

  • A regulatory requirement or accredited standard
  • A certification body or compliance guarantor
  • An identity verifier (v1.3 standardizes observable disclosure and trace behaviors; cryptographic authorization is documented but not yet solved)

Key tools

Simulator

Run the v1.3 controls against call scenarios in real time.

Open the simulator →

Specification (v1.3)

The full control set: IDG-01, PDX-01, DBC-01, EIT-01, ATR-01, and the event schema.

Read the specification →

Live demo call

Hear the disclosure controls trigger in a real voice call, with a step-by-step script.

Try the live demo →

Shadow Evaluation Guide

The structured 90-day process for payers — no vendor changes required.

View the guide →

Evidence Pack

Guarantees, a worked failure trace, and the audit-readiness model for procurement.

Review the evidence pack →

Simulator

The open simulator demonstrates NHID-Clinical controls.

Sit at a payer desk and watch an AI caller reveal itself too late. The zero-latency modules, dashboard, knowledge base, and evaluation records are all open — no account, no signup, nothing to install.

The simulator is education and demonstration — not the framework itself, and not a certification.

Two ways in

Pick the path that matches your job

Both start free. Neither requires a commercial relationship to get value.

Developer pathway

You are building an AI agent, or integrating one, and need to show it behaves.

  1. Read the controls. Five deterministic checks, each observable on a real call.
  2. Run the conformance suite against your engine and read the per-control verdicts.
  3. Try the live API — demo routes need no key. Send a VAPI or Twilio payload.
  4. Wire it in using the reference implementation, adapters, and trace schema.
  5. List your implementation in the self-attested registry when you are ready.
Start building

Enterprise pathway

You are a payer, provider organization, or health system receiving or operating AI agent traffic.

  1. Run a shadow evaluation on your own call logs. Observe-only, no vendor changes.
  2. Measure your baseline — how long is your impersonation latency today?
  3. Review the evidence pack and decide what to require of your vendors.
  4. Register your agents so identity, ownership, and scope are enumerable.
  5. Operate continuously with monitoring, evidence generation, and enterprise integration.
Start a shadow evaluation

NIST AI Safety Institute — Public Comment

Submitted to NIST docket NIST-2025-0035

NHID-Clinical was submitted as a public comment to NIST's AI-agent security docket in January 2026. This is a public comment — not an endorsement, not a standard. It puts the problem on the record.

Comment ID: NIST-2025-0035-0026  ·  January 12, 2026

CAISI's RFI drew 932 public comments before closing March 9, 2026 — this is one of them, not a uniquely selected or vetted submission.

View on Regulations.gov →

Get involved

Read the specification. Run a shadow pilot. Tell us where it breaks.

Whether you think it is right, wrong, incomplete, or misses the real problem — that feedback shapes the next version.

Start a pilot →