Medical-Legal Intelligence Platform
- Sector
- Legal practices — plaintiff, defense & injury
- My role
- Team lead & developer
- Key decisions
- 6 covered below
In plain terms
Helps attorneys make sense of thousands of pages of medical records — without patient details ever reaching an outside AI service, and with the same answer every time the case is run.
The problem
Attorneys wanted AI help reading dense medical case records, and the output had to stand up in court. Two things made that hard. Protected health information couldn't be sent to a hosted reasoning model. And if the same case, analysed twice, gave two different answers, neither could be used as evidence.
Architecture
Scroll sideways to see the whole diagram.
Key decisions
- 01
Separate the data by design, not by policy
Detection, tokenization, date normalization and a self-hosted clinical model all live in an isolated PHI zone. The frontier reasoning model sits in a second zone and only ever sees de-identified text. Because the separation is in the system's structure, a badly written prompt can't route around it.
- 02
A six-step PHI pipeline
Detect → tokenize → shift dates → validate → store → re-identify on read. It covers 18+ PHI categories and follows HIPAA Safe Harbor. Real names come back only at the very end, and only for people authorised to see them.
- 03
The same case gives the same answer
Generation is constrained against a fixed contract, with no sampling variance in the path that produces findings, and every statement points to a location in the source record. Run a case twice and you get the same analysis — which is what makes it usable as evidence.
- 04
Built to be defended
Audit logging, role-based access for attorneys, paralegals, experts and admins, and an evidence chain designed to hold up under a Daubert challenge.
- 05
Self-hosting the clinical model
A hosted API was never an option for identified records, so the clinical model runs on hardware we control. That made compression and serving our job: 4-bit weights to fit the GPU budget, a batched runtime to keep up under load, and a domain eval set re-run after every change to check nothing important was lost.
- 06
Five connected tools
Allegation analysis, medical record structuring, clinical timelines, provider and event mapping, and a review workspace for attorneys that also suggests suitable experts.
Built with
- React
- FastAPI
- PostgreSQL
- GCP
- Claude Sonnet
- Self-hosted clinical LLM
- TLS 1.3 / AES-256