AIR
Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
H33-VaultH33-ShareH33-ShieldH33-HealthH33-KeyH33-128H33-CKKSH33-256H33-FHE-IQH33-TFHEFHE OverviewH33-CompileZK LookupsBiometricsH33-3-KeyH33-MPCZK-TrustlessZK-PhishZK-VerifyPQC ArchitecturePQ VideoStorage EncryptionAI DetectionEncrypted Search

HIPAA safeguards you can back with cryptographic proof, not just promise.

Related · tier-1 reading. For what a portable artifact actually is, see Portable Artifact.

Every healthcare org signs a BAA and hopes for the best. H33-Health backs the technical safeguards with cryptographic evidence — Kyber-encrypted PHI storage, zero-knowledge eligibility verification, and Dilithium-signed audit trails that resist tampering even against quantum computers. This supports HIPAA compliance; a compliance determination itself remains a separate assessment your organization and auditors make.

Start Protecting PHI

EHR integrations check compliance boxes. Access controls log who opened a record. Encryption at rest protects a disk, not a query. None of it gives you strong cryptographic evidence that PHI stayed encrypted end to end — not to your staff, not to your vendors, not to an attacker who already has your database.

Not another EHR integration. Cryptographic evidence for your HIPAA safeguards.

H33 Products · Healthcare

What H33-Health is

Definition. H33-Health is an industry-vertical product that protects Protected Health Information across healthcare workflows — eligibility verification, prescription checks, clinical-trial matching, analytics — so PHI stays encrypted end to end and every operation leaves verifiable audit evidence. It owns the PHI-handling workflow, the privacy outcome, and the operational experience. It does not own, redefine, or reimplement the encryption, proof, verification, or governance it relies on; it composes them.

Why this exists. A signed BAA and access logs do not stop PHI from being exposed to staff, vendors, or an attacker who already holds the database. H33-Health backs the HIPAA technical safeguards with cryptographic evidence instead of policy attestation alone. Bounded claim: post-quantum encryption and FHE support HIPAA safeguards — they do not by themselves make an organization HIPAA-compliant. Compliance is a separate determination made by your organization and its auditors across the full environment.

The product boundary. H33-Health owns the PHI-handling workflow and privacy outcome. It uses H33 mechanisms for privacy, proof, evidence, and governance; it does not redefine or own those mechanisms.

USES FHE
Fully homomorphic encryption lets eligibility, risk scoring, and analytics run on encrypted PHI without decryption. H33-Health consumes FHE; it does not define or implement it.
USES ZK
Zero-knowledge proofs confirm eligibility or Rx validity without transmitting the underlying PHI. H33-Health requests these proofs; the proving is owned elsewhere.
USES H33-74 / Verification
H33-74 supplies the portable post-quantum attestation and Verification lets patients and auditors confirm a receipt offline. H33-Health attaches and surfaces these; it does not produce the primitive or perform the verifying.
USES H33-Key
H33-Key governs the keys and secrets used to encrypt PHI, referenced and never disclosed. H33-Health consumes this custody; it does not own key management.
GOVERNED_BY Agent-008
Agent-008 governs any automated decisioning on PHI — preserving authority and preventing drift. H33-Health is governed by it; it does not perform governance.
Replaceability
If H33-Health swapped Kyber/BFV for another confidential-computing technology, it would still be H33-Health: the PHI-handling workflow and privacy outcome are the product. Mechanisms are chosen, not owned.

Here’s what happens when you store, verify, and compute on PHI with H33-Health.

Step 01 — Kyber-1024 Encrypted PHI Storage
Field-Level Post-Quantum Encryption
Patient records encrypted at the field level. SSN, allergies, labs — each field individually encrypted with Kyber-1024 key encapsulation. Even a full database breach reveals nothing. No plaintext PHI ever touches your servers, logs, or any intermediate cache. HIPAA §164.312(a)(2)(iv) encryption requirements satisfied by NIST post-quantum standards, not legacy AES that quantum computers will break.
Patient records encrypted at the field level. SSN, allergies, labs — each field individually encrypted with Kyber-1024 key encapsulation. Even a full database breach reveals nothing. No plaintext PHI ever touches your servers, logs, or any intermediate cache. HIPAA §164.312(a)(2)(iv) encryption requirements satisfied by NIST post-quantum standards, not legacy AES that quantum computers will break.
Step 02 — Zero-Knowledge Eligibility Verification
Prove Without Transmitting PHI
Prove a patient is insured, has a valid Rx, or meets clinical trial criteria without transmitting the underlying PHI. The verifier learns only true or false — nothing else. Insurance eligibility, prescription legitimacy, age thresholds, diagnostic criteria — all verified with zero-knowledge proofs. The data stays encrypted, and the answer is cryptographically verifiable.
Prove a patient is insured, has a valid Rx, or meets clinical trial criteria without transmitting the underlying PHI. The verifier learns only true or false — nothing else. Insurance eligibility, prescription legitimacy, age thresholds, diagnostic criteria — all verified with zero-knowledge proofs. The data stays encrypted, and the answer is cryptographically verifiable.
Step 03 — FHE Computation on Encrypted Records
Analytics Without Decryption
Run aggregate queries across encrypted patient data. Clinical trial matching, population health analytics, outcome tracking — all without decrypting a single record. Fully homomorphic encryption lets you compute on ciphertext and get the correct plaintext result. Researchers never see individual PHI — a strong privacy posture that supports IRB review, though IRB approval remains a separate determination.
Run aggregate queries across encrypted patient data. Clinical trial matching, population health analytics, outcome tracking — all without decrypting a single record. Fully homomorphic encryption lets you compute on ciphertext and get the correct plaintext result. Researchers never see individual PHI — a strong privacy posture that supports IRB review, though IRB approval remains a separate determination.
Step 04 — Dilithium-Signed Audit Trails
Tamper-Proof Compliance Proof
Every PHI access, verification, and computation produces a post-quantum tamper-resistant audit entry signed with Dilithium-3 (FIPS 204). This gives your HIPAA §164.312(b) audit-control evidence cryptographic backing rather than a checkbox — auditors verify signatures, not trust. Generate audit reports on demand with cryptographic proof of every access, every query, every result. (Meeting §164.312(b) in full remains an assessment your organization makes.)
Every PHI access, verification, and computation produces a post-quantum tamper-resistant audit entry signed with Dilithium-3 (FIPS 204). This gives your HIPAA §164.312(b) audit-control evidence cryptographic backing rather than a checkbox — auditors verify signatures, not trust. Generate audit reports on demand with cryptographic proof of every access, every query, every result. (Meeting §164.312(b) in full remains an assessment your organization makes.)
< 3 ms
full encrypt + verify + audit per PHI operation

Kyber-1024 field encryption + ZK eligibility proof + Dilithium audit signature — in a single API call under 3 milliseconds.

PHI protection pipeline — every operation, every proof, every audit entry.

ENCRYPT  Kyber-1024 field-level PHI encryption
VERIFY  ZK eligibility proof (true/false only)
COMPUTE  FHE query on encrypted records
AUDIT  Dilithium-signed tamper-proof log entry
Total: —
PHI Protection Pipeline

Every healthcare workflow touches PHI. None of them need to expose it.

Insurance Eligibility
Hospital proves patient has active coverage without sending SSN or policy details to the insurer. Zero-knowledge proof of eligibility — the insurer learns only true or false.
has_active_coverage(patient_id, procedure_code) → true/false
Prescription Verification
Pharmacy verifies Rx validity and prescriber credentials without accessing full medical history. Zero-knowledge proof of prescription legitimacy — no PHI transmitted.
verify_rx(rx_id, prescriber_npi) → valid/invalid
Clinical Trial Matching
Run FHE queries across thousands of encrypted patient records to find eligible candidates. Researchers never see individual PHI — a strong privacy posture that supports IRB review, though IRB approval remains a separate determination.
fhe_match(criteria, encrypted_cohort) → [eligible_ids]
Lab Result Sharing
Encrypted results in Vault, ZK proof of “value within normal range” for insurance or employer wellness programs — without revealing the actual numbers.
in_normal_range(lab_result, reference) → true/false

The more you protect, the less each operation costs.

Volume-tiered pricing — standardized across the H33 platform.

See pricing →

How H33-Health compares

H33-Health Epic MyChart Cerner AWS HealthLake Azure Health Data
Post-quantum PHI encryption Kyber-1024 (NIST)
Field-level encryption Per-field Kyber KEM At rest only At rest only
Zero-knowledge verification ZK proofs (true/false)
FHE computation BFV on encrypted records
PQ-signed audit trail Dilithium-3 (FIPS 204) Access logs Access logs CloudTrail Activity logs
Compliance evidence Cryptographic proof Policy-based Policy-based Policy-based Policy-based

All units fungible — same balance as H33-Auth, H33-Vault, H33-Share, and H33-Shield.

HIPAA Technical Safeguards — Mapped to H33-Health

Every HIPAA §164.312 technical safeguard requirement mapped to a specific H33-Health cryptographic feature that supports it with verifiable evidence — not policy attestation alone. Full HIPAA compliance remains a determination your organization and auditors make across your whole environment.

HIPAA Section Requirement H33-Health Feature Tier
§164.312(a)(2)(iv) Encryption & decryption Kyber-1024 field-level encryption Health-0+
§164.312(b) Audit controls Dilithium-signed tamper-proof logs Health-0+
§164.312(c)(1) Integrity controls Post-quantum signatures on all records Health-1+
§164.312(d) Person / entity authentication ZK eligibility verification Health-1+
§164.312(e)(1) Transmission security Kyber-1024 key encapsulation in transit Health-0+
§164.314(a) Business associate contracts Automated BAA management Health-3
§164.530(j) Record retention (6 years) Encrypted immutable audit archive Health-2+

Each requirement above is backed by post-quantum cryptographic primitives rather than access-control policy alone — strengthening the evidence you bring to a HIPAA assessment, which your organization and auditors still perform.


Frequently Asked Questions

How does H33-Health satisfy HIPAA encryption requirements?
H33-Health uses BFV fully homomorphic encryption (FHE) to process Protected Health Information (PHI) without ever decrypting it. Data remains encrypted during computation. This goes beyond typical encryption-at-rest and encryption-in-transit controls by adding encryption-in-use, which supports HIPAA's encryption requirements. Whether an organization is HIPAA-compliant overall is a separate determination.
What is zero-knowledge eligibility verification?
A health plan can verify a patient's eligibility without seeing the patient's actual medical records. The computation runs on encrypted data using FHE, and the result (eligible/not eligible) is returned without exposing any PHI fields.
Can H33-Health work with existing EHR systems?
Yes. H33-Health provides a REST API that accepts standard HL7 FHIR resources. Your EHR system encrypts PHI client-side before sending. The API processes encrypted payloads and returns encrypted results that only the authorized recipient can decrypt.
How does FHE computation work on PHI?
Protected Health Information is encrypted with BFV (lattice-based FHE). The H33 server performs computations — eligibility checks, risk scoring, claims adjudication — directly on the ciphertext. The server never sees plaintext PHI at any point.
What is the latency for an encrypted eligibility check?
A single FHE eligibility verification completes in approximately 1-2 milliseconds using BFV batching. The Dilithium attestation adds ~191 microseconds. Total end-to-end: typically under 5 milliseconds.
How does the Dilithium audit trail work?
Every computation on encrypted PHI produces a Dilithium (ML-DSA) signed attestation recording the operation type, timestamp, data fields accessed (by encrypted reference, not plaintext), and result hash. This creates a tamper-resistant audit trail that survives quantum attacks and supports HIPAA audit-control requirements; the compliance determination itself remains a separate assessment.
Can patients verify their own data was handled correctly?
Yes. Each computation produces a Dilithium-signed receipt that patients can independently verify. The receipt proves what computation was performed, when, and that the result matches the input, without revealing the actual data.
How does H33-Health handle cross-state insurance queries?
FHE enables cross-jurisdiction queries without violating state-specific privacy laws. Since data never leaves encrypted form, no plaintext PHI crosses state boundaries. The computation runs on ciphertext, and only the authorized insurer can decrypt the result.
Is H33-Health compatible with HL7 FHIR?
Yes. H33-Health accepts FHIR R4 resources (Patient, Coverage, Claim, ExplanationOfBenefit) wrapped in an encrypted envelope. The API maps FHIR resource fields to FHE computation slots. Response payloads follow FHIR OperationOutcome format.
What PHI fields are encrypted at rest?
All 18 HIPAA identifiers are encrypted with BFV FHE: name, address, dates, SSN, medical record numbers, health plan IDs, account numbers, certificate numbers, device IDs, URLs, IPs, biometric identifiers, photos, and any other unique identifying characteristic.

When to use H33-Health — and when not to

Use H33-Health when your workflow touches PHI and you need it to stay encrypted end to end — eligibility verification, prescription checks, clinical-trial matching, encrypted analytics — with verifiable audit evidence. Status is honest: the Kyber/BFV encryption, ZK verification, and Dilithium audit pipelines run today; a HIPAA BAA is available; SOC 2 / ISO postures are tracked on /compliance/. Latency figures shown on this page are illustrative benchmarks, not per-deployment guarantees. And to be explicit: the product supports HIPAA safeguards — it does not itself certify your organization as compliant.

When NOT to use it — use a neighbor
If your need is a bank-wide post-quantum migration rather than PHI handling, use Quantum-Safe Banking instead. For continuous cyber-control monitoring and cyber-insurance claim evidence, use HATS instead. For the broader healthcare solution set, see the Healthcare hub.
If you want the mechanism, not the product
To evaluate a primitive directly rather than the healthcare workflow, read the FHE, ZK, H33-74, or Verification hubs. H33-Health composes these; it does not redefine them.
TECHNICAL DEEP DIVES

Go Deeper

🏥 HIPAA 2026
Post-Quantum HIPAA: The 2026 Mandate
HIPAA now mandates AES-256 encryption. But AES alone won't survive quantum. Here's the full-stack solution.
Read Full Article →
🧬 FHE
Homomorphic Encryption for Healthcare
Compute on encrypted patient records, run analytics on ciphertext, match PHI without decryption.
Read Full Article →
💊 AI + PRIVACY
Is ChatGPT HIPAA Compliant?
Spoiler: No. But you can use AI on healthcare data safely with FHE. Here's how H33-Health makes it possible.
Read Full Article →

Start Protecting PHI

Free tier includes 1,000 units. No credit card required.