Enterprise — Active Development

Behavioral health AI that never leaves your building.

Cloud-based ambient scribes are sending patient audio to vendor servers. One California health system is facing a class-action lawsuit for it. This is the architecture that makes that lawsuit impossible.

See How It Works Request a Briefing
Audio never leaves the facility
Consent enforced in code not policy
Immutable per-encounter audit log
WellSky FHIR integration
42 CFR Part 2 compliant by architecture
The Problem

A class-action lawsuit is what happens when audio leaves the building.

100K+
Patients recorded by a cloud ambient scribe without meaningful consent — November 2025 class-action lawsuit
$5,000
Statutory damages per violation per recording under California CIPA wiretapping statute
$500M+
Mathematical exposure at CIPA rates for a 100,000-patient class before attorney fees

Cloud scribes send sessions to vendor servers

No consent form fixes this. The data left the building. That is the violation.

Behavioral health has 42 CFR Part 2

Federal protections above HIPAA. Substance use and mental health records have a higher bar.

Vendor customer lists become class definitions

Plaintiffs use vendor customer lists as pre-built class definitions. Every customer is a defendant.

The only fix is architecture

Audio never leaves the building. That is the only statement that survives a courtroom.

“Sovereignty is not a feature you add to an AI product. It is a decision you make on day one. If data flow is not logged, gated, and visible from the first module build, you cannot make it sovereign later — you can only apologize for it.”

RigidTrust Sovereignty Architecture — Kavanagh Industries 2026 — USPTO Patent Pending #63/991,057

Architecture Comparison

Cloud ambient scribe vs. RigidHealth Clinical Node.

Cloud Ambient Scribes

  • Audio transmitted to vendor servers
  • Vendor employees can access sessions
  • HIPAA BAA does not eliminate consent gap
  • No sovereignty audit trail
  • Opt-out is policy not code
  • 42 CFR Part 2 depends on vendor controls
  • No immutable consent chain — verbal or EHR flag only
  • Cloud-dependent — no internet no documentation
  • Vendor customer list becomes plaintiff class definition
  • Wiretapping lawsuit exposure compounds with any existing regulatory inquiry

RigidHealth Clinical Node

  • Audio transcribed on-premise — never transmitted
  • No third party has any access to patient sessions
  • No third party means no BAA needed for AI processing
  • Complete sovereignty audit log per encounter — immutable
  • Opt-out enforced by Three Laws pre-flight — hard block in code
  • 42 CFR Part 2 compliant by architecture — data never leaves
  • Cryptographically timestamped consent record at intake
  • Fully air-gap capable — works without internet
  • Your name never appears on a vendor customer list
  • Sovereignty audit log is your legal defense — already built

WellSky FHIR R4 Compatibility

Notes deposit into WellSky clinician workflow via HL7 FHIR R4. Clinician experience unchanged. Only data routing changes — to your hardware.

How It Works

Seven steps. Audio in. Signed note out. Nothing leaves.

1

Three Laws Pre-Flight

Before any encounter begins, the system verifies consent status, audit log integrity, and data routing. If any check fails, recording does not start.

2

RigidConsent Gate

Patient consent is captured and cryptographically signed. No consent, no recording. Consent is enforced in code, not policy. Revocation is immediate.

3

RigidTranscribe

Audio is transcribed on-premises using a local speech-to-text model running on the Clinical Node. No audio leaves the facility. No cloud API calls.

4

RigidScribe

The local LLM generates a structured clinical note from the transcript. SOAP, DAP, or custom format. The clinician reviews and approves before signing.

5

Clinician Review

The clinician reviews the AI-generated note on screen, edits as needed, and digitally signs. Nothing is finalized without human approval.

6

WellSky FHIR Deposit

The signed note is deposited into the WellSky EHR via HL7 FHIR R4. The clinician workflow is unchanged. Only the data routing changes.

7

Immutable Audit Log

Every encounter is logged with timestamp, consent hash, clinician ID, note hash, and FHIR deposit confirmation. The log is append-only and tamper-evident.

Module Stack

Six modules. One node. Everything on your hardware.

🔒

RigidConsent

Cryptographic patient consent capture and enforcement. No consent, no recording. Revocation is immediate and retroactive. Every consent event is hashed and logged.

🎤

RigidTranscribe

On-premises speech-to-text. Audio is processed locally on the Clinical Node. No cloud dependency. No vendor API. Supports multi-speaker diarization for group sessions.

📝

RigidScribe

Local LLM generates structured clinical notes from transcripts. SOAP, DAP, or custom templates. Clinician reviews and signs before deposit. AI assists, never decides.

📑

RigidAudit

Immutable, append-only encounter log. Every session recorded with consent hash, clinician ID, timestamp, note hash, and FHIR deposit confirmation. Tamper-evident by design.

🔁

RigidRoute

FHIR R4 integration layer for WellSky and other EHR systems. Notes deposit directly into the clinician workflow. No manual data entry. No copy-paste.

🛡

RigidComply

Automated compliance reporting for HIPAA, 42 CFR Part 2, and state wiretapping laws. Generates audit-ready documentation on demand. Architecture is the compliance proof.

Three Laws

Three Laws Pre-Flight — Enforced Before Every Encounter

Law 1: Consent must be cryptographically verified before recording begins. Law 2: Audio must be confirmed routed to local-only processing. Law 3: Audit log integrity must pass hash verification. If any law fails, the encounter does not start. There is no override. There is no bypass. The Three Laws are enforced in code, not policy.

Deployment

Three phases. Twelve weeks to sovereign documentation.

Phase 1 — Weeks 1–4

Infrastructure & Integration

Clinical Node hardware deployed on-site. WellSky FHIR R4 integration configured and tested. Network isolation verified. Three Laws pre-flight validated. Staff credentials provisioned.

Phase 2 — Weeks 5–8

Pilot & Validation

Pilot group of clinicians runs parallel documentation. AI-generated notes compared against manual notes for accuracy. Consent workflows tested with real patients. Audit log reviewed by compliance team.

Phase 3 — Weeks 9–12

Full Rollout & Compliance Certification

All clinicians onboarded. Compliance documentation finalized. 42 CFR Part 2 architectural compliance certified. Ongoing monitoring and model updates delivered via secure local update channel.

“Your honor, the audio never left the building. The consent was cryptographically signed before recording began. The audit log is immutable and tamper-evident. Here is the proof.”

The legal defense you want to have. The architecture that makes it true.

RigidTrust Alignment

Constitutional protections for patients, clinicians, and the organization.

Bill I

Creator's Rights

Patients

Every patient's audio and resulting documentation is treated as their sovereign data. Digital Birth Certificate at creation. No scraping. No secondary use without explicit consent. Portable sovereignty means the patient can take their data and leave.

Bill II

Manufacturer's Rights

Health Networks

The behavioral health network owns its operational data. Zero-knowledge architecture means no vendor can see, access, or monetize patient encounters. Right to exit with full data return in 30 days. No lock-in.

Bill IX

The AI's Bill of Rights

Clinical AI Governance

No clinical note is finalized without human approval. AI reasoning is explainable with citations. Consent-based learning only. Annual third-party ethical audit published. The AI assists. It never decides.

Enterprise Inquiry

Ready to move patient audio off vendor servers?

Request a technical briefing for your behavioral health network. We will walk through the architecture, the Three Laws pre-flight, WellSky integration, and a 12-week deployment timeline.

shaun@kavanaghind.com

Kavanagh Industries LLC · Clinton Township, Michigan · 5 miles from the Detroit Arsenal

R

RigidAI

Kavanagh Industries · Always on