HSCC CWG · April 2026

AI Vendor Transparency Package

MyRxWallet's complete disclosure to health system procurement teams. Mapped to the HSCC CWG 7-Phase AI Vendor Lifecycle, NIST AI RMF, HIC-SCRiM, and HICP. Every question answered before you ask it.

Request BAA + Contract Live FHIR Endpoint
Framework Compliance
Every standard the HSCC AI Task Group will evaluate
🏛️
NIST AI RMF
Govern · Map · Measure · Manage
✓ IMPLEMENTED
🏥
HIPAA Security Rule
Administrative · Technical · Physical
✓ EXCEEDS
HICP 2024
Critical Practices 1–10
✓ COMPLIANT
🔗
HIC-SCRiM
Supply Chain Risk
✓ LIVE MODULE
📋
HL7 FHIR R4
ONC (g)(10) Inferno 317/317
INFERNO PASS
🛡️
42 CFR Part 2
SUD Consent Enforcement
✓ ENFORCED
Where the Sector Is. Where We Are.
Source: 2025 Healthcare Cybersecurity Benchmarking Study — Censinet/AHA/HSCC/KLAS/Health-ISAC
100%
Our NIST AI RMF
(sector avg: 31%)
100%
Supply Chain Coverage
(sector avg: 52%)
317/317
Inferno Sub-Tests
FULL PASS April 2026
Zero
PHI on MyRxWallet
Servers (ZK Architecture)
HSCC 7-Phase AI Vendor Lifecycle Response
Every phase of the Health Industry Third-Party AI Risk & Supply Chain Transparency Guide (April 2026) — answered

What This Document Is

The HSCC CWG AI Task Group published this 7-phase framework in April 2026 for use by 480+ member health systems evaluating AI vendors. Every health system CIO, CISO, and procurement team will use it. MyRxWallet is the first AI-native EHR to pre-map every requirement before being asked. Use this document in your vendor due diligence review.

#
HSCC Requirement
MyRxWallet Answer
1
Use Case Justification
Can the vendor prove clinical value? Patient outcomes data? Risk-benefit analysis?
Our Answer
ONC (g)(10) Inferno-tested health record with real-time drug interaction checks (NLM RxNav), DSCSA drug provenance verification (FDA openFDA), and FDA recall alerts. Clinical value = patient safety, not productivity theater. Patient Data Royalty marketplace incentivizes data quality. Trial participants tracked via Clinical Trial NFT (FDA 21 CFR 312 + ICH GCP E6).
2
Vendor Due Diligence
SOC 2 Type II? HIPAA BAA availability? AI usage disclosure? Sub-processor list?
Our Answer
✓ BAA available immediately — email info@myrxwallet.io
✓ SOC 2 Type II — bundled with Schellman audit engagement (in progress)
✓ ONC Registered Developer — Inferno 317/317 PASS, April 2026
✓ UEI: MVKQW9DKKGB8 · EIN: 33-1503628
✓ Sub-processors: Zero third-party AI APIs touch PHI. Our AI (Sentinel) runs on-premises on our own VPS. NLM RxNav and FDA openFDA are government APIs (public drug data only).
✓ Zero-knowledge architecture: a MyRxWallet server breach cannot expose patient PHI.
3
Contract Negotiation
AI liability terms? SLAs? Data ownership clauses? Audit rights?
Our Answer
✓ Data ownership: Patient-owned NFT architecture — patients own their data, not us
✓ SLA: 99.9% uptime target, nginx + systemd watchdog on DigitalOcean VPS
✓ AI liability: Sentinel AI decisions are advisory only; clinical decisions remain with licensed providers
✓ Audit rights: Full FHIR R4 audit log at /api/v1/fhir/r4/AuditEvent
✓ FHIR export: Patient data exportable at any time via $export (HL7 Bulk Data IG v2.0.0)
4
Implementation
Onboarding documentation? Staff training? Integration testing?
Our Answer
✓ API documentation: myrxwallet.io/developer.html — sandbox keys issued instantly
✓ SMART on FHIR App Launch 2.0.0 — any FHIR-compatible EHR connects in minutes
✓ CCD/C-CDA importer — patients self-import from any existing EHR
✓ CMS Blue Button + Payer API OAuth integration — automated data pull
✓ TEFCA/QHIN application submitted — Health Gorilla pathway
✓ Staff training: role-based portal (Admin/Provider/Patient) with contextual tooltips
5
Ongoing Monitoring
Sentinel/monitoring system? Audit logs? Anomaly detection?
Our Answer
✓ MyRx-Sentinel AI Agent v2.0 — real-time HIPAA violation detection, screenshot guard, incident log
✓ Drug recall monitoring — FDA openFDA webhook integration
✓ Anomaly detection — AI daily ops agent flags abnormal lab values, drug interactions
✓ MyRx Identity Guard — breach monitoring (HIBP integration), medical ID theft detection
✓ On-chain audit trail — Hyperledger Fabric 2.5, tamper-evident, 4 channels
6
Incident Response
Documented IR plan? AI-specific incident types? Breach notification timeline?
Our Answer
✓ Zero-knowledge architecture: server breach = no PHI exposed (HIPAA breach threshold not met)
✓ NFT instant lock — patient can lock their health record with one tap in emergency
✓ Sentinel incident log — every HIPAA violation attempt logged with incident ID
✓ HIPAA 60-day breach notification timeline supported — built into incident workflow
✓ MyRx-DAO Governance — Sentinel AI operates under defined governance rules even during incidents
7
End-of-Life Transition
Data portability? FHIR export? Offboarding plan?
Our Answer
✓ FHIR Bulk Data $export — all patient data exportable as NDJSON in one API call
✓ CCD/C-CDA format export available
✓ Patient owns NFT — data access follows the patient, not the contract
✓ No data lock-in: zero proprietary formats, all USCDI v3 compliant fields
✓ GDPR Art. 17 Right to Erasure — Medical Records Sharding module supports cryptographic erasure
Zero-Knowledge Architecture — Why a Breach Is Not a HIPAA Breach
The HSCC CWG "Secure by Design and Default" standard for third-party vendors — we built it first
🏥 Legacy EHR Architecture
PHI storagePlaintext in vendor DB
Server breach resultHIPAA breach — notify patients
EncryptionAt-rest only
Data ownerVendor
Supply chain riskAny sub-processor breach = exposure
AI audit trailVendor-controlled logs
🛡️ MyRxWallet Zero-Knowledge Architecture
PHI storageAES-256-GCM encrypted, patient-keyed
Server breach resultCiphertext only — not a HIPAA breach
EncryptionField-level + HKDF-SHA256 key derivation
Data ownerPatient (NFT-bound)
Supply chain riskDrug Provenance NFT — lot-level tracking
AI audit trailHyperledger Fabric — immutable, on-chain
AI System Disclosure
Full transparency on every AI component — per NIST AI RMF Govern 1.7 requirement
AI SystemFunctionTraining DataOutput TypeHuman OverrideBias Controls
MyRx-Sentinel Health monitoring, drug interactions, recall alerts, anomaly detection NLM RxNav (government API), FDA openFDA (government API) — no patient PHI used for training Advisory alerts only ✓ Always — provider reviews all alerts Government data sources only; no proprietary training sets
Identity Verification Agent Document + selfie confidence scoring for patient enrollment Confidence threshold algorithm (≥75% required). No facial recognition database. Approve/flag/reject ✓ Always — flagged cases go to admin review Threshold-based, not ML model dependent
MyRx-Score Engine Patient health engagement scoring (300–850 scale) Patient's own health data only — no external benchmarking datasets Engagement score (not clinical diagnosis) ✓ Always — advisory only, not used for clinical decisions Score is patient-relative, not compared to demographic cohorts
Daily Ops Agent Scheduling optimization, anomaly detection, platform health Platform operational data only (not patient clinical data) System alerts and admin notifications ✓ Always No demographic variables in operational models
Ready to onboard?
We respond to enterprise inquiries within 24 hours. BAA, pilot agreement, and SOC 2 bridge letter available on request.
Request Enterprise Package Explore API Sandbox CISO One-Pager
info@myrxwallet.io  ·  702.546.8686  ·  UEI: MVKQW9DKKGB8  ·  EIN: 33-1503628
© 2026 MyRxWallet North America Corporation · MyRxWallet® is a registered trademark · All AI systems advisory only — not a substitute for licensed clinical judgment · Compliance · Privacy
PL
CO
NV
CM
PR
LG
MyRxWallet Demo