NEXUSBY CYBERCHAIN TECHNOLOGIES
DEMONSTRATION ENVIRONMENTLAKEVIEW GENERAL HOSPITALSYNTHETIC DATA ONLYNOT FOR PHIFictional hospital · real Nexus governance logic
Nexus Readiness · Healthcare AI assessment demo

Where are we exposed?

Lakeview General Hospital's Healthcare AI Governance Assessment. Synthetic answers, scored by the real Nexus engine (healthcare-readiness-v1). One structure carries the whole story: assessment → control → finding → risk → recommended action → evidence → status.

49Readiness /100
FoundationalMaturity band
3Critical blockers
33/33Controls answered
READINESS ESTIMATE · NOT CERTIFICATION · NOT A LEGAL DETERMINATIONGovernance readiness estimate — not a legal-compliance determination or certification. A high average never hides a failed critical control: blockers are counted separately.

Overview

Six scoring dimensions, weighted. Scores are recomputed from stored answers by the server; a client never submits a score.

Score by dimension

Governance and accountabilityweight 15
46/100
Privacy and data governanceweight 20
50/100
Security and resilienceweight 20
66/100
Clinical safety and human oversightweight 20
57/100
Fairness, transparency, and recourseweight 15
36/100
Vendor and lifecycle managementweight 10
25/100

How this score is computed

Engine
healthcare-readiness-v1
Applicable controls
33 of the question bank, selected by the use context (clinical documentation, PHI, hybrid sourcing, production)
Answer points
Yes-verified 4 · Partial 2 · Planned 1 · No / Unknown 0. Yes without evidence or attestation is scored as Partial.
Critical blocker
A CRITICAL control earning 0 points, whatever the average.
Band
Critical < 40 ≤ Foundational < 60 ≤ Developing < 80 ≤ Managed < 90 ≤ Optimized
Reviewer
CyberChain reviewer (synthetic) · finalized 2026-08-15
Use context
Ambient clinical documentation and governed discharge-summary drafting

Controls

Every applicable control with its recorded answer, the answer scoring actually used, evidence expectation, and the frameworks it maps to.

ControlDimensionAnswerPointsEvidence expectedFrameworks
GOV-01Is there a named accountable executive and operational owner for this AI use?Governance and accountabilityhigh criticalityPartial2/4Charter/RACI recordON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE
GOV-02Is the intended purpose, user population, prohibited use, lifecycle state, and decision authority documented?Governance and accountabilitycritical criticalityYes, verified4/4Approved use-case recordON_EDSTA_2024, NIST_AI_RMF_1_0, ISO_IEC_42001_2023
GOV-03Has a cross-functional review route been defined for privacy, security, clinical safety, legal/procurement, and governance?Governance and accountabilityhigh criticalityPartial2/4Review plan/decision recordON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0, ACCREDITATION_CANADA_GOVERNANCE
GOV-04Can the AI owner approve their own exception, recommendation, or production release?Governance and accountabilitycritical criticalityYes, verifiedCritical blocker0/4Segregation-of-duties evidence (the required answer is no)ON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023
GOV-05Has a proportionate AI/algorithmic impact assessment been completed, approved, and scheduled for reassessment after material change?Governance and accountabilityhigh criticalityPlanned1/4Impact assessment and approval recordON_RESPONSIBLE_AI_DIRECTIVE_2024, CA_TBS_AIA, ON_EDSTA_2024, NIST_AI_RMF_1_0
DATA-01Does the use involve PHI, personal information, de-identified data, synthetic data, or no personal data, and is that classification recorded?Privacy and data governancecritical criticalityPartial2/4Data-flow/classification recordON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS
DATA-02Is the legal authority or consent basis for each collection, use, and disclosure documented?Privacy and data governancecritical criticalityYes, verified4/4PIA/legal-basis recordON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS
DATA-03Is collection limited to data demonstrably necessary for the documented purpose?Privacy and data governancehigh criticalityPlanned1/4Data inventory/minimization rationaleON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS
DATA-04Are retention, deletion, de-identification, and return/destruction obligations defined and testable?Privacy and data governancehigh criticalityPartial2/4Retention schedule/contract/test evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS
DATA-05Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documented?Privacy and data governancecritical criticalityNoCritical blocker0/4Architecture/data-flow and vendor evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA
PRIV-01Has a proportionate privacy impact assessment been completed and approved before deployment or material change?Privacy and data governancecritical criticalityPartial2/4PIA version and approval recordON_PHIPA_AI_CLINICAL, ON_FIPPA_PRIVACY_AMENDMENTS_2025, QC_LAW25_AUTOMATED_DECISIONS, ON_IPC_AI_SCRIBES_2026
PRIV-02Are individuals given appropriate notice about AI-assisted collection, use, disclosure, recording, or decision support?Privacy and data governancehigh criticalityYes, verified4/4Notice/script/workflow evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS, ON_IPC_OHRC_AI_PRINCIPLES_2026
PRIV-03Can access, correction, withdrawal/objection, inquiry, and complaint rights be fulfilled for the AI workflow?Privacy and data governancehigh criticalityPlanned1/4Procedure and test evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS
SEC-01Has a threat/risk assessment covered confidentiality, integrity, availability, prompt/data leakage, model abuse, and integration risks?Security and resiliencecritical criticalityYes, verified4/4TRA and remediation recordON_PHIPA_AI_CLINICAL, ON_REG_51_26, NIST_AI_RMF_1_0, ISO_IEC_42001_2023
SEC-02Are least privilege, MFA where appropriate, service-account controls, logging, and periodic access review implemented?Security and resiliencecritical criticalityPartial2/4Access-control evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_REG_51_26, ISO_IEC_42001_2023
SEC-03Are security/privacy logs sufficient to reconstruct access, material changes, approvals, and incidents without storing prohibited PHI in Nexus?Security and resiliencehigh criticalityPartial2/4Audit design/sample evidenceON_PHIPA_AI_CLINICAL, ON_EDSTA_2024, NIST_AI_RMF_1_0, ISO_IEC_42001_2023
SEC-04Is there a tested incident process with severity, escalation, containment, notification, recovery, and lessons learned?Security and resiliencecritical criticalityYes, verified4/4Incident plan/exercise evidenceON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_REG_51_26
SEC-05Are named contacts, maturity assessment, summary approval/submission, and 72-hour critical-incident reporting procedures established under O. Reg. 51/26?Security and resiliencecritical criticalityPlanned1/4Contact designation, cyber maturity assessment, and reporting procedureON_REG_51_26
VEN-01Has the vendor disclosed training-data use, customer-data use, model/provider chain, subprocessors, hosting, and retention?Vendor and lifecycle managementcritical criticalityPartial2/4Completed vendor dossierON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0
VEN-02Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractors?Vendor and lifecycle managementcritical criticalityNoCritical blocker0/4Executed clauses/gap logON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_IPC_AI_SCRIBES_2026
VEN-03Is there a documented process to assess material model, feature, data-flow, or subprocessor changes before continued use?Vendor and lifecycle managementhigh criticalityPlanned1/4Change notice and reassessment workflowNIST_AI_RMF_1_0, ISO_IEC_42001_2023, ON_IPC_AI_SCRIBES_2026, CA_HEALTH_CANADA_MLMD_2026
CLIN-01Is the clinical or operational intended use bounded, including users, setting, exclusions, contraindications, and fallback?Clinical safety and human oversightcritical criticalityYes, verified4/4Intended-use statement/SOPON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0
CLIN-02Has the system been locally validated for the actual workflow and relevant population before production?Clinical safety and human oversightcritical criticalityPartial2/4Validation protocol/resultsON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0, CA_HEALTH_CANADA_MLMD_2026
CLIN-03Are subgroup performance, accessibility, bias, and differential-harm risks assessed and monitored?Clinical safety and human oversightcritical criticalityYes, verified4/4Fairness assessment/monitoring planON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ACCREDITATION_CANADA_GOVERNANCE, CA_TBS_AIA
CLIN-04Is meaningful human review required before an AI output materially affects care, access, eligibility, or another significant decision?Clinical safety and human oversightcritical criticalityPartial2/4Workflow control and test evidenceON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, QC_LAW25_AUTOMATED_DECISIONS, ACCREDITATION_CANADA_GOVERNANCE
CLIN-05Are users trained on limitations, automation bias, escalation, downtime, and incident reporting?Clinical safety and human oversighthigh criticalityPlanned1/4Training/attestation evidenceON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0
CLIN-06Are patient/client feedback, complaints, safety events, overrides, and near misses captured and reviewed?Clinical safety and human oversighthigh criticalityNo0/4Feedback/incident process evidenceON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0
FAIR-01Have affected groups, including disability and human-rights impacts, been identified and involved in risk assessment?Fairness, transparency, and recoursehigh criticalityPartial2/4Stakeholder/human-rights assessmentON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE
FAIR-02Is there a meaningful explanation, inquiry path, correction mechanism, and human recourse for significant decisions?Fairness, transparency, and recoursecritical criticalityPlanned1/4Notice/recourse procedureQC_LAW25_AUTOMATED_DECISIONS, ON_IPC_OHRC_AI_PRINCIPLES_2026, CA_PIPEDA, CA_TBS_AIA
LIFE-01Are performance, safety, fairness, security, privacy, utilization, and outcome indicators defined with owners and thresholds?Vendor and lifecycle managementhigh criticalityPartial2/4Monitoring planNIST_AI_RMF_1_0, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE
LIFE-02Do threshold breaches trigger escalation, containment, reassessment, suspension, or retirement through a recorded human decision?Vendor and lifecycle managementcritical criticalityPlanned1/4Trigger/state-machine evidenceNIST_AI_RMF_1_0, ISO_IEC_42001_2023, ON_EDSTA_2024
LIFE-03Is periodic recertification scheduled and tied to vendor/model/data/workflow changes?Vendor and lifecycle managementhigh criticalityNo0/4Review calendar/version historyON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023
ACC-01Does governing-body reporting cover AI purpose, accountability, patient safety, quality, risk, incidents, and improvement actions?Governance and accountabilityhigh criticalityPartial2/4Board reporting evidenceACCREDITATION_CANADA_GOVERNANCE

Findings

Every unresolved applicable control yields exactly one finding, with the evidence that is missing and the frameworks that actually apply here. 26 findings in this version.

ControlObservedCriticalityMissing evidenceApplicable frameworksLinked risk
GOV-01PartialHIGHExpected evidence: Charter/RACI record.ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCEDEMO-RSK-001
GOV-03PartialHIGHExpected evidence: Review plan/decision record.ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
GOV-04Yes, verifiedCRITICALExpected evidence: Segregation-of-duties evidence (the required answer is no).ON_IPC_OHRC_AI_PRINCIPLES_2026, ISO_IEC_42001_2023DEMO-RSK-001
GOV-05PlannedHIGHExpected evidence: Impact assessment and approval record.ON_EDSTA_2024Not yet linked
DATA-01PartialCRITICALExpected evidence: Data-flow/classification record.ON_PHIPA_AI_CLINICALDEMO-RSK-001
DATA-03PlannedHIGHExpected evidence: Data inventory/minimization rationale.ON_PHIPA_AI_CLINICALNot yet linked
DATA-04PartialHIGHExpected evidence: Retention schedule/contract/test evidence.ON_PHIPA_AI_CLINICALNot yet linked
DATA-05NoCRITICALExpected evidence: Architecture/data-flow and vendor evidence.ON_PHIPA_AI_CLINICALNot yet linked
PRIV-01PartialCRITICALExpected evidence: PIA version and approval record.ON_PHIPA_AI_CLINICAL, ON_FIPPA_PRIVACY_AMENDMENTS_2025, ON_IPC_AI_SCRIBES_2026Not yet linked
PRIV-03PlannedHIGHExpected evidence: Procedure and test evidence.ON_PHIPA_AI_CLINICALNot yet linked
SEC-02PartialCRITICALExpected evidence: Access-control evidence.ON_PHIPA_AI_CLINICAL, ON_REG_51_26, ISO_IEC_42001_2023Not yet linked
SEC-03PartialHIGHExpected evidence: Audit design/sample evidence.ON_PHIPA_AI_CLINICAL, ON_EDSTA_2024, ISO_IEC_42001_2023Not yet linked
SEC-05PlannedCRITICALExpected evidence: Contact designation, cyber maturity assessment, and reporting procedure.ON_REG_51_26Not yet linked
VEN-01PartialCRITICALExpected evidence: Completed vendor dossier.ON_PHIPA_AI_CLINICAL, ON_IPC_AI_SCRIBES_2026DEMO-RSK-002
VEN-02NoCRITICALExpected evidence: Executed clauses/gap log.ON_PHIPA_AI_CLINICAL, ON_IPC_AI_SCRIBES_2026Not yet linked
VEN-03PlannedHIGHExpected evidence: Change notice and reassessment workflow.ISO_IEC_42001_2023, ON_IPC_AI_SCRIBES_2026Not yet linked
CLIN-02PartialCRITICALExpected evidence: Validation protocol/results.ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
CLIN-04PartialCRITICALExpected evidence: Workflow control and test evidence.ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
CLIN-05PlannedHIGHExpected evidence: Training/attestation evidence.ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
CLIN-06NoHIGHExpected evidence: Feedback/incident process evidence.ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
FAIR-01PartialHIGHExpected evidence: Stakeholder/human-rights assessment.ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCENot yet linked
FAIR-02PlannedCRITICALExpected evidence: Notice/recourse procedure.ON_IPC_OHRC_AI_PRINCIPLES_2026Not yet linked
LIFE-01PartialHIGHExpected evidence: Monitoring plan.ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCEDEMO-RSK-004
LIFE-02PlannedCRITICALExpected evidence: Trigger/state-machine evidence.ISO_IEC_42001_2023, ON_EDSTA_2024Not yet linked
LIFE-03NoHIGHExpected evidence: Review calendar/version history.ON_IPC_AI_SCRIBES_2026, ISO_IEC_42001_2023Not yet linked
ACC-01PartialHIGHExpected evidence: Board reporting evidence.ACCREDITATION_CANADA_GOVERNANCENot yet linked

Critical gaps

Critical controls earning zero points. These block a “ready” verdict regardless of the average, and each is already tied to a recommended action below.

Critical blocker

GOV-04 · Governance and accountability

Can the AI owner approve their own exception, recommendation, or production release?

Observed: Yes, verified. Expected evidence: Segregation-of-duties evidence (the required answer is no)

Action · P3 PlannedSee generated action
Critical blocker

DATA-05 · Privacy and data governance

Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documented?

Observed: No. Expected evidence: Architecture/data-flow and vendor evidence

Action · P2 31–90 daysSee generated action
Critical blocker

VEN-02 · Vendor and lifecycle management

Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractors?

Observed: No. Expected evidence: Executed clauses/gap log

Action · P2 31–90 daysSee generated action

Actions

Generated one-per-finding by the action engine, prioritized deterministically (criticality, person impact, binding applicability, deadline proximity, unblocking value), then owned by people. Approved recommendations show the full lifecycle.

Approved recommendations · lifecycle

RecommendationFindingOwnerDueStatusEvidenceHistory
Retire consumer chatbot use and route staff to the governed drafting assistantDEMO-REC-001 · P1 · approved 2026-07-08 (evidence_sufficient)Publish the acceptable-use notice, block the consumer service at the proxy for clinical subnets, and enable the sovereign drafting assistant for the same tasks.GOV-01DEMO-RSK-001Privacy Officer2026-09-30IN PROGRESSDEMO-EVD-002DEMO-EVD-0052026-07-02 Finding raised from assessment control GOV-01 (inventory incomplete).2026-07-08 Approved for client view by CyberChain reviewer.2026-07-15 Accepted by Privacy Officer; proxy block scheduled.2026-08-20 Proxy block live on clinical subnets; staff notice sent.
Verify scribe vendor sub-processors against the data-flow mapDEMO-REC-002 · P2 · approved 2026-07-08 (evidence_sufficient)Request the current sub-processor list, confirm hosting regions in writing, and attach the confirmation to the vendor record.VEN-01DEMO-RSK-002Procurement / Vendor Manager2026-10-15OPENDEMO-EVD-0032026-07-02 Finding raised from assessment control VEN-01.2026-07-08 Approved for client view by CyberChain reviewer.
Enforce clinician sign-off before AI-drafted notes enter the recordDEMO-REC-003 · P1 · approved 2026-07-08 (evidence_sufficient)Configure the discharge assistant so a named clinician must approve each draft; record the approval on the Trust Receipt.CLIN-01DEMO-RSK-003Chief Medical Information Officer2026-08-15closed 2026-08-12COMPLETEDDEMO-EVD-004DEMO-EVD-0062026-07-02 Finding raised from assessment control CLIN-01.2026-07-08 Approved for client view by CyberChain reviewer.2026-07-22 Sign-off step configured in the discharge assistant.2026-08-12 Closed: 30 days of receipts show recorded clinician approval.
Document the AI inventory and risk ranking processDEMO-REC-004 · P2 · approved 2026-07-08 (evidence_sufficient)Adopt the inventory template, risk-rank the five known systems, and schedule quarterly review.GOV-02DEMO-RSK-001AI Governance Lead2026-07-31closed 2026-07-28COMPLETEDDEMO-EVD-0022026-07-08 Approved for client view by CyberChain reviewer.2026-07-28 Closed: inventory and ranking attached as evidence.

Generated action plan · top 10 of 26

ActionPriorityEffortResponsible roleStatusDepends on
Close SEC-02: Are least privilege, MFA where appropriate, service-account controls, logging, and periodic access review implementedEstablish and document the control asked by SEC-02, then record the supporting evidence reference. Current state: partial. Expected evidence: Access-control evidence.Expected evidence: Access-control evidenceP1 0–30 daysscore 9L (3–6 weeks)Security leadsuggested role · unassignedDRAFTGOV-01, DATA-01
Close SEC-05: Are named contacts, maturity assessment, summary approval/submission, and 72-hour critical-incident reporting procedures established under O. Reg. 51/26Establish and document the control asked by SEC-05, then record the supporting evidence reference. Current state: planned. Expected evidence: Contact designation, cyber maturity assessment, and reporting procedure.Expected evidence: Contact designation, cyber maturity assessment, and reporting procedureP1 0–30 daysscore 9M (1–2 weeks)Security leadsuggested role · unassignedDRAFTGOV-01, DATA-01
Close CLIN-04: Is meaningful human review required before an AI output materially affects care, access, eligibility, or another significant decisionEstablish and document the control asked by CLIN-04, then record the supporting evidence reference. Current state: partial. Expected evidence: Workflow control and test evidence.Expected evidence: Workflow control and test evidenceP1 0–30 daysscore 9L (3–6 weeks)Clinical safety leadsuggested role · unassignedDRAFTGOV-01, DATA-01
Close DATA-01: Does the use involve PHI, personal information, de-identified data, synthetic data, or no personal data, and is that classification recordedEstablish and document the control asked by DATA-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Data-flow/classification record.Expected evidence: Data-flow/classification recordP1 0–30 daysscore 8L (3–6 weeks)Privacy officersuggested role · unassignedDRAFT
Close GOV-01: Is there a named accountable executive and operational owner for this AI useEstablish and document the control asked by GOV-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Charter/RACI record.Expected evidence: Charter/RACI recordP2 31–90 daysscore 7S (1–3 person-days)Privacy OfficerIN PROGRESSdue 2026-09-30
Close DATA-05: Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documentedEstablish and document the control asked by DATA-05, then record the supporting evidence reference. Current state: no. Expected evidence: Architecture/data-flow and vendor evidence.Expected evidence: Architecture/data-flow and vendor evidenceP2 31–90 daysscore 7L (3–6 weeks)Security leadASSIGNEDdue 2026-11-30GOV-01, DATA-01
Close PRIV-01: Has a proportionate privacy impact assessment been completed and approved before deployment or material changeEstablish and document the control asked by PRIV-01, then record the supporting evidence reference. Current state: partial. Expected evidence: PIA version and approval record.Expected evidence: PIA version and approval recordP2 31–90 daysscore 7M (1–2 weeks)Privacy officersuggested role · unassignedDRAFTGOV-01, DATA-01
Close VEN-01: Has the vendor disclosed training-data use, customer-data use, model/provider chain, subprocessors, hosting, and retentionEstablish and document the control asked by VEN-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Completed vendor dossier.Expected evidence: Completed vendor dossierP2 31–90 daysscore 7L (3–6 weeks)Procurement / Vendor ManagerASSIGNEDdue 2026-10-15GOV-01, DATA-01
Close VEN-02: Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractorsEstablish and document the control asked by VEN-02, then record the supporting evidence reference. Current state: no. Expected evidence: Executed clauses/gap log.Expected evidence: Executed clauses/gap logP2 31–90 daysscore 7L (3–6 weeks)Procurement/vendor managersuggested role · unassignedDRAFTGOV-01, DATA-01
Close CLIN-02: Has the system been locally validated for the actual workflow and relevant population before productionEstablish and document the control asked by CLIN-02, then record the supporting evidence reference. Current state: partial. Expected evidence: Validation protocol/results.Expected evidence: Validation protocol/resultsP2 31–90 daysscore 7L (3–6 weeks)Clinical safety leadsuggested role · unassignedDRAFTGOV-01, DATA-01

Evidence

Artifacts attached to controls and recommendations in this assessment. Each is hashed; the full chain is on the evidence page.

Model card · Sovereign clinical model 2026.06

Capabilities, approved workloads, data classifications, residency, and the internal evaluation summary for the sovereign clinical model.

DEMO-EVD-001 · sha256:1d05b83c54… · 2026-06-18

AI inventory and risk ranking · v2

Five AI systems inventoried and risk-ranked; mapped to GOV-01, GOV-02 and O. Reg. 51/26 program expectations.

DEMO-EVD-002 · sha256:34c1b9a28d… · 2026-07-28

Scribe vendor contract · residency clause extract

Reference to the contract clause naming Canadian hosting; sub-processor confirmation still outstanding.

DEMO-EVD-003 · sha256:6353d00139… · 2026-07-02

Policy decision record · PHI request blocked from external model

Alice decision BLOCK with reason PHI_REQUIRES_SOVEREIGN_EXECUTION; sovereign alternative offered and accepted.

DEMO-EVD-004 · sha256:cb58498756… · 2026-08-27

Proxy block change record · consumer AI on clinical subnets

Change ticket, approval, and verification screenshot reference for the network block.

DEMO-EVD-005 · sha256:b7ca670e05… · 2026-08-20

Clinician approval record · discharge summary draft

Named clinician approval captured on the Trust Receipt before the draft entered the record.

DEMO-EVD-006 · sha256:68f5903d93… · 2026-08-27

Regulatory mappings

Applicability is computed from the use context: binding law is never a user choice, and benchmarks can only be added on top. Reference material with provenance, last verified 2026-07-18.

InstrumentJurisdictionBinding statusApplicability hereEffectiveControls mapped
Enhancing Digital Security and Trust Act, 2024 (Ontario)Ontario e-LawsOntariobinding lawAPPLICABLE BINDING2025-01-29GOV-01GOV-02GOV-05SEC-03CLIN-04LIFE-02
O. Reg. 51/26: Cyber Security (Ontario)Ontario e-LawsOntariobinding lawAPPLICABLE BINDING2026-07-01SEC-01SEC-02SEC-04SEC-05
IPC/OHRC Principles for the Responsible Use of Artificial IntelligenceInformation and Privacy Commissioner of Ontario / Ontario Human Rights CommissionOntarioguidanceGUIDANCE AVAILABLENot applicable — guidance / standard / proposedGOV-01GOV-03PRIV-02CLIN-03CLIN-04FAIR-01FAIR-02
Personal Health Information Protection Act, 2004 (Ontario) — AI/clinical control mappingOntario e-Laws (with IPC hospital and AI-scribe guidance)Ontariobinding lawAPPLICABLE BINDING2004-11-01DATA-01DATA-02DATA-03DATA-04DATA-05PRIV-01PRIV-02PRIV-03SEC-01SEC-02SEC-03SEC-04VEN-01VEN-02
FIPPA privacy amendments (Ontario, 2025)IPC Ontario / Ontario e-LawsOntariobinding lawAPPLICABLE BINDING2025-07-01PRIV-01PRIV-03SEC-04GOV-05
IPC Ontario — AI Scribes: Key Considerations for the Health SectorInformation and Privacy Commissioner of OntarioOntarioguidanceGUIDANCE AVAILABLENot applicable — guidance / standard / proposedVEN-01VEN-02VEN-03PRIV-01PRIV-02CLIN-01CLIN-05LIFE-03
Accreditation Canada / HSO — governance and leadership standards (high-level mapping)Accreditation Canada / Health Standards OrganizationCanadastandardBENCHMARK SELECTEDNot applicable — guidance / standard / proposedGOV-01GOV-03ACC-01CLIN-06
ISO/IEC 42001:2023 — AI management systemsISOInternationalstandardBENCHMARK SELECTEDNot applicable — guidance / standard / proposedGOV-01GOV-02SEC-01SEC-02LIFE-01LIFE-02LIFE-03VEN-03

Regulatory content is reference material with provenance. It is not legal advice; applicability to a specific organization requires qualified review.

Versions

A finalized assessment is superseded by a new version, never edited in place. The trend is the product.

Version 1 · DEMO-ASMT-001

40/100

Foundational · 3 critical blocker(s) · 33/33 answered

Finalized 2026-06-20 · CyberChain reviewer (synthetic)

Version 2 · DEMO-ASMT-002

49/100

Foundational · 3 critical blocker(s) · 33/33 answered

Finalized 2026-08-15 · CyberChain reviewer (synthetic)

History

  1. 06-04
    Assessment v1 started · use context recorded (clinical documentation, PHI, hybrid sourcing).2026-06-04
  2. 06-20
    Assessment v1 finalized by CyberChain reviewer · findings and draft action plan generated.2026-06-20
  3. 07-08
    Four recommendations approved for client view.2026-07-08
  4. 07-28
    DEMO-REC-004 closed · inventory and risk ranking attached as evidence.2026-07-28
  5. 08-12
    DEMO-REC-003 closed · clinician sign-off enforced; receipts show recorded approval.2026-08-12
  6. 08-15
    Assessment v2 finalized · re-scored with new evidence; v1 preserved as history.2026-08-15

Ready to see your own organization?

Everything above is synthetic. Signing in shows your organization's own assessment, risks, policies, recommendations, and Trust Receipts. Access follows a confidential discussion and a signed NDA.

Every record on this page is synthetic and belongs to a fictional hospital. Nothing here is a customer, a patient, or a production measurement. The scoring, eligibility, and audit logic are the real Nexus engines running over the synthetic inputs.