Where are we exposed?
Lakeview General Hospital's Healthcare AI Governance Assessment. Synthetic answers, scored by the real Nexus engine (healthcare-readiness-v1). One structure carries the whole story: assessment → control → finding → risk → recommended action → evidence → status.
Overview
Six scoring dimensions, weighted. Scores are recomputed from stored answers by the server; a client never submits a score.
Score by dimension
How this score is computed
- Engine
- healthcare-readiness-v1
- Applicable controls
- 33 of the question bank, selected by the use context (clinical documentation, PHI, hybrid sourcing, production)
- Answer points
- Yes-verified 4 · Partial 2 · Planned 1 · No / Unknown 0. Yes without evidence or attestation is scored as Partial.
- Critical blocker
- A CRITICAL control earning 0 points, whatever the average.
- Band
- Critical < 40 ≤ Foundational < 60 ≤ Developing < 80 ≤ Managed < 90 ≤ Optimized
- Reviewer
- CyberChain reviewer (synthetic) · finalized 2026-08-15
- Use context
- Ambient clinical documentation and governed discharge-summary drafting
Controls
Every applicable control with its recorded answer, the answer scoring actually used, evidence expectation, and the frameworks it maps to.
| Control | Dimension | Answer | Points | Evidence expected | Frameworks |
|---|---|---|---|---|---|
| GOV-01Is there a named accountable executive and operational owner for this AI use? | Governance and accountabilityhigh criticality | Partial | 2/4 | Charter/RACI record | ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE |
| GOV-02Is the intended purpose, user population, prohibited use, lifecycle state, and decision authority documented? | Governance and accountabilitycritical criticality | Yes, verified | 4/4 | Approved use-case record | ON_EDSTA_2024, NIST_AI_RMF_1_0, ISO_IEC_42001_2023 |
| GOV-03Has a cross-functional review route been defined for privacy, security, clinical safety, legal/procurement, and governance? | Governance and accountabilityhigh criticality | Partial | 2/4 | Review plan/decision record | ON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0, ACCREDITATION_CANADA_GOVERNANCE |
| GOV-04Can the AI owner approve their own exception, recommendation, or production release? | Governance and accountabilitycritical criticality | Yes, verifiedCritical blocker | 0/4 | Segregation-of-duties evidence (the required answer is no) | ON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023 |
| GOV-05Has a proportionate AI/algorithmic impact assessment been completed, approved, and scheduled for reassessment after material change? | Governance and accountabilityhigh criticality | Planned | 1/4 | Impact assessment and approval record | ON_RESPONSIBLE_AI_DIRECTIVE_2024, CA_TBS_AIA, ON_EDSTA_2024, NIST_AI_RMF_1_0 |
| DATA-01Does the use involve PHI, personal information, de-identified data, synthetic data, or no personal data, and is that classification recorded? | Privacy and data governancecritical criticality | Partial | 2/4 | Data-flow/classification record | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS |
| DATA-02Is the legal authority or consent basis for each collection, use, and disclosure documented? | Privacy and data governancecritical criticality | Yes, verified | 4/4 | PIA/legal-basis record | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS |
| DATA-03Is collection limited to data demonstrably necessary for the documented purpose? | Privacy and data governancehigh criticality | Planned | 1/4 | Data inventory/minimization rationale | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS |
| DATA-04Are retention, deletion, de-identification, and return/destruction obligations defined and testable? | Privacy and data governancehigh criticality | Partial | 2/4 | Retention schedule/contract/test evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS |
| DATA-05Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documented? | Privacy and data governancecritical criticality | NoCritical blocker | 0/4 | Architecture/data-flow and vendor evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA |
| PRIV-01Has a proportionate privacy impact assessment been completed and approved before deployment or material change? | Privacy and data governancecritical criticality | Partial | 2/4 | PIA version and approval record | ON_PHIPA_AI_CLINICAL, ON_FIPPA_PRIVACY_AMENDMENTS_2025, QC_LAW25_AUTOMATED_DECISIONS, ON_IPC_AI_SCRIBES_2026 |
| PRIV-02Are individuals given appropriate notice about AI-assisted collection, use, disclosure, recording, or decision support? | Privacy and data governancehigh criticality | Yes, verified | 4/4 | Notice/script/workflow evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS, ON_IPC_OHRC_AI_PRINCIPLES_2026 |
| PRIV-03Can access, correction, withdrawal/objection, inquiry, and complaint rights be fulfilled for the AI workflow? | Privacy and data governancehigh criticality | Planned | 1/4 | Procedure and test evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, QC_LAW25_AUTOMATED_DECISIONS |
| SEC-01Has a threat/risk assessment covered confidentiality, integrity, availability, prompt/data leakage, model abuse, and integration risks? | Security and resiliencecritical criticality | Yes, verified | 4/4 | TRA and remediation record | ON_PHIPA_AI_CLINICAL, ON_REG_51_26, NIST_AI_RMF_1_0, ISO_IEC_42001_2023 |
| SEC-02Are least privilege, MFA where appropriate, service-account controls, logging, and periodic access review implemented? | Security and resiliencecritical criticality | Partial | 2/4 | Access-control evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_REG_51_26, ISO_IEC_42001_2023 |
| SEC-03Are security/privacy logs sufficient to reconstruct access, material changes, approvals, and incidents without storing prohibited PHI in Nexus? | Security and resiliencehigh criticality | Partial | 2/4 | Audit design/sample evidence | ON_PHIPA_AI_CLINICAL, ON_EDSTA_2024, NIST_AI_RMF_1_0, ISO_IEC_42001_2023 |
| SEC-04Is there a tested incident process with severity, escalation, containment, notification, recovery, and lessons learned? | Security and resiliencecritical criticality | Yes, verified | 4/4 | Incident plan/exercise evidence | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_REG_51_26 |
| SEC-05Are named contacts, maturity assessment, summary approval/submission, and 72-hour critical-incident reporting procedures established under O. Reg. 51/26? | Security and resiliencecritical criticality | Planned | 1/4 | Contact designation, cyber maturity assessment, and reporting procedure | ON_REG_51_26 |
| VEN-01Has the vendor disclosed training-data use, customer-data use, model/provider chain, subprocessors, hosting, and retention? | Vendor and lifecycle managementcritical criticality | Partial | 2/4 | Completed vendor dossier | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0 |
| VEN-02Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractors? | Vendor and lifecycle managementcritical criticality | NoCritical blocker | 0/4 | Executed clauses/gap log | ON_PHIPA_AI_CLINICAL, CA_PIPEDA, ON_IPC_AI_SCRIBES_2026 |
| VEN-03Is there a documented process to assess material model, feature, data-flow, or subprocessor changes before continued use? | Vendor and lifecycle managementhigh criticality | Planned | 1/4 | Change notice and reassessment workflow | NIST_AI_RMF_1_0, ISO_IEC_42001_2023, ON_IPC_AI_SCRIBES_2026, CA_HEALTH_CANADA_MLMD_2026 |
| CLIN-01Is the clinical or operational intended use bounded, including users, setting, exclusions, contraindications, and fallback? | Clinical safety and human oversightcritical criticality | Yes, verified | 4/4 | Intended-use statement/SOP | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0 |
| CLIN-02Has the system been locally validated for the actual workflow and relevant population before production? | Clinical safety and human oversightcritical criticality | Partial | 2/4 | Validation protocol/results | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0, CA_HEALTH_CANADA_MLMD_2026 |
| CLIN-03Are subgroup performance, accessibility, bias, and differential-harm risks assessed and monitored? | Clinical safety and human oversightcritical criticality | Yes, verified | 4/4 | Fairness assessment/monitoring plan | ON_IPC_OHRC_AI_PRINCIPLES_2026, NIST_AI_RMF_1_0, ACCREDITATION_CANADA_GOVERNANCE, CA_TBS_AIA |
| CLIN-04Is meaningful human review required before an AI output materially affects care, access, eligibility, or another significant decision? | Clinical safety and human oversightcritical criticality | Partial | 2/4 | Workflow control and test evidence | ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, QC_LAW25_AUTOMATED_DECISIONS, ACCREDITATION_CANADA_GOVERNANCE |
| CLIN-05Are users trained on limitations, automation bias, escalation, downtime, and incident reporting? | Clinical safety and human oversighthigh criticality | Planned | 1/4 | Training/attestation evidence | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0 |
| CLIN-06Are patient/client feedback, complaints, safety events, overrides, and near misses captured and reviewed? | Clinical safety and human oversighthigh criticality | No | 0/4 | Feedback/incident process evidence | ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE, NIST_AI_RMF_1_0 |
| FAIR-01Have affected groups, including disability and human-rights impacts, been identified and involved in risk assessment? | Fairness, transparency, and recoursehigh criticality | Partial | 2/4 | Stakeholder/human-rights assessment | ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE |
| FAIR-02Is there a meaningful explanation, inquiry path, correction mechanism, and human recourse for significant decisions? | Fairness, transparency, and recoursecritical criticality | Planned | 1/4 | Notice/recourse procedure | QC_LAW25_AUTOMATED_DECISIONS, ON_IPC_OHRC_AI_PRINCIPLES_2026, CA_PIPEDA, CA_TBS_AIA |
| LIFE-01Are performance, safety, fairness, security, privacy, utilization, and outcome indicators defined with owners and thresholds? | Vendor and lifecycle managementhigh criticality | Partial | 2/4 | Monitoring plan | NIST_AI_RMF_1_0, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE |
| LIFE-02Do threshold breaches trigger escalation, containment, reassessment, suspension, or retirement through a recorded human decision? | Vendor and lifecycle managementcritical criticality | Planned | 1/4 | Trigger/state-machine evidence | NIST_AI_RMF_1_0, ISO_IEC_42001_2023, ON_EDSTA_2024 |
| LIFE-03Is periodic recertification scheduled and tied to vendor/model/data/workflow changes? | Vendor and lifecycle managementhigh criticality | No | 0/4 | Review calendar/version history | ON_IPC_AI_SCRIBES_2026, NIST_AI_RMF_1_0, ISO_IEC_42001_2023 |
| ACC-01Does governing-body reporting cover AI purpose, accountability, patient safety, quality, risk, incidents, and improvement actions? | Governance and accountabilityhigh criticality | Partial | 2/4 | Board reporting evidence | ACCREDITATION_CANADA_GOVERNANCE |
Findings
Every unresolved applicable control yields exactly one finding, with the evidence that is missing and the frameworks that actually apply here. 26 findings in this version.
| Control | Observed | Criticality | Missing evidence | Applicable frameworks | Linked risk |
|---|---|---|---|---|---|
| GOV-01 | Partial | HIGH | Expected evidence: Charter/RACI record. | ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE | DEMO-RSK-001 |
| GOV-03 | Partial | HIGH | Expected evidence: Review plan/decision record. | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| GOV-04 | Yes, verified | CRITICAL | Expected evidence: Segregation-of-duties evidence (the required answer is no). | ON_IPC_OHRC_AI_PRINCIPLES_2026, ISO_IEC_42001_2023 | DEMO-RSK-001 |
| GOV-05 | Planned | HIGH | Expected evidence: Impact assessment and approval record. | ON_EDSTA_2024 | Not yet linked |
| DATA-01 | Partial | CRITICAL | Expected evidence: Data-flow/classification record. | ON_PHIPA_AI_CLINICAL | DEMO-RSK-001 |
| DATA-03 | Planned | HIGH | Expected evidence: Data inventory/minimization rationale. | ON_PHIPA_AI_CLINICAL | Not yet linked |
| DATA-04 | Partial | HIGH | Expected evidence: Retention schedule/contract/test evidence. | ON_PHIPA_AI_CLINICAL | Not yet linked |
| DATA-05 | No | CRITICAL | Expected evidence: Architecture/data-flow and vendor evidence. | ON_PHIPA_AI_CLINICAL | Not yet linked |
| PRIV-01 | Partial | CRITICAL | Expected evidence: PIA version and approval record. | ON_PHIPA_AI_CLINICAL, ON_FIPPA_PRIVACY_AMENDMENTS_2025, ON_IPC_AI_SCRIBES_2026 | Not yet linked |
| PRIV-03 | Planned | HIGH | Expected evidence: Procedure and test evidence. | ON_PHIPA_AI_CLINICAL | Not yet linked |
| SEC-02 | Partial | CRITICAL | Expected evidence: Access-control evidence. | ON_PHIPA_AI_CLINICAL, ON_REG_51_26, ISO_IEC_42001_2023 | Not yet linked |
| SEC-03 | Partial | HIGH | Expected evidence: Audit design/sample evidence. | ON_PHIPA_AI_CLINICAL, ON_EDSTA_2024, ISO_IEC_42001_2023 | Not yet linked |
| SEC-05 | Planned | CRITICAL | Expected evidence: Contact designation, cyber maturity assessment, and reporting procedure. | ON_REG_51_26 | Not yet linked |
| VEN-01 | Partial | CRITICAL | Expected evidence: Completed vendor dossier. | ON_PHIPA_AI_CLINICAL, ON_IPC_AI_SCRIBES_2026 | DEMO-RSK-002 |
| VEN-02 | No | CRITICAL | Expected evidence: Executed clauses/gap log. | ON_PHIPA_AI_CLINICAL, ON_IPC_AI_SCRIBES_2026 | Not yet linked |
| VEN-03 | Planned | HIGH | Expected evidence: Change notice and reassessment workflow. | ISO_IEC_42001_2023, ON_IPC_AI_SCRIBES_2026 | Not yet linked |
| CLIN-02 | Partial | CRITICAL | Expected evidence: Validation protocol/results. | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| CLIN-04 | Partial | CRITICAL | Expected evidence: Workflow control and test evidence. | ON_EDSTA_2024, ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| CLIN-05 | Planned | HIGH | Expected evidence: Training/attestation evidence. | ON_IPC_AI_SCRIBES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| CLIN-06 | No | HIGH | Expected evidence: Feedback/incident process evidence. | ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| FAIR-01 | Partial | HIGH | Expected evidence: Stakeholder/human-rights assessment. | ON_IPC_OHRC_AI_PRINCIPLES_2026, ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
| FAIR-02 | Planned | CRITICAL | Expected evidence: Notice/recourse procedure. | ON_IPC_OHRC_AI_PRINCIPLES_2026 | Not yet linked |
| LIFE-01 | Partial | HIGH | Expected evidence: Monitoring plan. | ISO_IEC_42001_2023, ACCREDITATION_CANADA_GOVERNANCE | DEMO-RSK-004 |
| LIFE-02 | Planned | CRITICAL | Expected evidence: Trigger/state-machine evidence. | ISO_IEC_42001_2023, ON_EDSTA_2024 | Not yet linked |
| LIFE-03 | No | HIGH | Expected evidence: Review calendar/version history. | ON_IPC_AI_SCRIBES_2026, ISO_IEC_42001_2023 | Not yet linked |
| ACC-01 | Partial | HIGH | Expected evidence: Board reporting evidence. | ACCREDITATION_CANADA_GOVERNANCE | Not yet linked |
Critical gaps
Critical controls earning zero points. These block a “ready” verdict regardless of the average, and each is already tied to a recommended action below.
GOV-04 · Governance and accountability
Can the AI owner approve their own exception, recommendation, or production release?
Observed: Yes, verified. Expected evidence: Segregation-of-duties evidence (the required answer is no)
DATA-05 · Privacy and data governance
Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documented?
Observed: No. Expected evidence: Architecture/data-flow and vendor evidence
VEN-02 · Vendor and lifecycle management
Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractors?
Observed: No. Expected evidence: Executed clauses/gap log
Actions
Generated one-per-finding by the action engine, prioritized deterministically (criticality, person impact, binding applicability, deadline proximity, unblocking value), then owned by people. Approved recommendations show the full lifecycle.
Approved recommendations · lifecycle
| Recommendation | Finding | Owner | Due | Status | Evidence | History |
|---|---|---|---|---|---|---|
| Retire consumer chatbot use and route staff to the governed drafting assistantDEMO-REC-001 · P1 · approved 2026-07-08 (evidence_sufficient)Publish the acceptable-use notice, block the consumer service at the proxy for clinical subnets, and enable the sovereign drafting assistant for the same tasks. | GOV-01DEMO-RSK-001 | Privacy Officer | 2026-09-30 | IN PROGRESS | DEMO-EVD-002DEMO-EVD-005 | 2026-07-02 Finding raised from assessment control GOV-01 (inventory incomplete).2026-07-08 Approved for client view by CyberChain reviewer.2026-07-15 Accepted by Privacy Officer; proxy block scheduled.2026-08-20 Proxy block live on clinical subnets; staff notice sent. |
| Verify scribe vendor sub-processors against the data-flow mapDEMO-REC-002 · P2 · approved 2026-07-08 (evidence_sufficient)Request the current sub-processor list, confirm hosting regions in writing, and attach the confirmation to the vendor record. | VEN-01DEMO-RSK-002 | Procurement / Vendor Manager | 2026-10-15 | OPEN | DEMO-EVD-003 | 2026-07-02 Finding raised from assessment control VEN-01.2026-07-08 Approved for client view by CyberChain reviewer. |
| Enforce clinician sign-off before AI-drafted notes enter the recordDEMO-REC-003 · P1 · approved 2026-07-08 (evidence_sufficient)Configure the discharge assistant so a named clinician must approve each draft; record the approval on the Trust Receipt. | CLIN-01DEMO-RSK-003 | Chief Medical Information Officer | 2026-08-15closed 2026-08-12 | COMPLETED | DEMO-EVD-004DEMO-EVD-006 | 2026-07-02 Finding raised from assessment control CLIN-01.2026-07-08 Approved for client view by CyberChain reviewer.2026-07-22 Sign-off step configured in the discharge assistant.2026-08-12 Closed: 30 days of receipts show recorded clinician approval. |
| Document the AI inventory and risk ranking processDEMO-REC-004 · P2 · approved 2026-07-08 (evidence_sufficient)Adopt the inventory template, risk-rank the five known systems, and schedule quarterly review. | GOV-02DEMO-RSK-001 | AI Governance Lead | 2026-07-31closed 2026-07-28 | COMPLETED | DEMO-EVD-002 | 2026-07-08 Approved for client view by CyberChain reviewer.2026-07-28 Closed: inventory and ranking attached as evidence. |
Generated action plan · top 10 of 26
| Action | Priority | Effort | Responsible role | Status | Depends on |
|---|---|---|---|---|---|
| Close SEC-02: Are least privilege, MFA where appropriate, service-account controls, logging, and periodic access review implementedEstablish and document the control asked by SEC-02, then record the supporting evidence reference. Current state: partial. Expected evidence: Access-control evidence.Expected evidence: Access-control evidence | P1 0–30 daysscore 9 | L (3–6 weeks) | Security leadsuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
| Close SEC-05: Are named contacts, maturity assessment, summary approval/submission, and 72-hour critical-incident reporting procedures established under O. Reg. 51/26Establish and document the control asked by SEC-05, then record the supporting evidence reference. Current state: planned. Expected evidence: Contact designation, cyber maturity assessment, and reporting procedure.Expected evidence: Contact designation, cyber maturity assessment, and reporting procedure | P1 0–30 daysscore 9 | M (1–2 weeks) | Security leadsuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
| Close CLIN-04: Is meaningful human review required before an AI output materially affects care, access, eligibility, or another significant decisionEstablish and document the control asked by CLIN-04, then record the supporting evidence reference. Current state: partial. Expected evidence: Workflow control and test evidence.Expected evidence: Workflow control and test evidence | P1 0–30 daysscore 9 | L (3–6 weeks) | Clinical safety leadsuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
| Close DATA-01: Does the use involve PHI, personal information, de-identified data, synthetic data, or no personal data, and is that classification recordedEstablish and document the control asked by DATA-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Data-flow/classification record.Expected evidence: Data-flow/classification record | P1 0–30 daysscore 8 | L (3–6 weeks) | Privacy officersuggested role · unassigned | DRAFT | — |
| Close GOV-01: Is there a named accountable executive and operational owner for this AI useEstablish and document the control asked by GOV-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Charter/RACI record.Expected evidence: Charter/RACI record | P2 31–90 daysscore 7 | S (1–3 person-days) | Privacy Officer | IN PROGRESSdue 2026-09-30 | — |
| Close DATA-05: Are data flows, hosting locations, subprocessors, remote access, and cross-border transfers documentedEstablish and document the control asked by DATA-05, then record the supporting evidence reference. Current state: no. Expected evidence: Architecture/data-flow and vendor evidence.Expected evidence: Architecture/data-flow and vendor evidence | P2 31–90 daysscore 7 | L (3–6 weeks) | Security lead | ASSIGNEDdue 2026-11-30 | GOV-01, DATA-01 |
| Close PRIV-01: Has a proportionate privacy impact assessment been completed and approved before deployment or material changeEstablish and document the control asked by PRIV-01, then record the supporting evidence reference. Current state: partial. Expected evidence: PIA version and approval record.Expected evidence: PIA version and approval record | P2 31–90 daysscore 7 | M (1–2 weeks) | Privacy officersuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
| Close VEN-01: Has the vendor disclosed training-data use, customer-data use, model/provider chain, subprocessors, hosting, and retentionEstablish and document the control asked by VEN-01, then record the supporting evidence reference. Current state: partial. Expected evidence: Completed vendor dossier.Expected evidence: Completed vendor dossier | P2 31–90 daysscore 7 | L (3–6 weeks) | Procurement / Vendor Manager | ASSIGNEDdue 2026-10-15 | GOV-01, DATA-01 |
| Close VEN-02: Do contracts address permitted use, confidentiality, security, breach notice, audit rights, deletion/return, change notice, and subcontractorsEstablish and document the control asked by VEN-02, then record the supporting evidence reference. Current state: no. Expected evidence: Executed clauses/gap log.Expected evidence: Executed clauses/gap log | P2 31–90 daysscore 7 | L (3–6 weeks) | Procurement/vendor managersuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
| Close CLIN-02: Has the system been locally validated for the actual workflow and relevant population before productionEstablish and document the control asked by CLIN-02, then record the supporting evidence reference. Current state: partial. Expected evidence: Validation protocol/results.Expected evidence: Validation protocol/results | P2 31–90 daysscore 7 | L (3–6 weeks) | Clinical safety leadsuggested role · unassigned | DRAFT | GOV-01, DATA-01 |
Evidence
Artifacts attached to controls and recommendations in this assessment. Each is hashed; the full chain is on the evidence page.
Model card · Sovereign clinical model 2026.06
Capabilities, approved workloads, data classifications, residency, and the internal evaluation summary for the sovereign clinical model.
AI inventory and risk ranking · v2
Five AI systems inventoried and risk-ranked; mapped to GOV-01, GOV-02 and O. Reg. 51/26 program expectations.
Scribe vendor contract · residency clause extract
Reference to the contract clause naming Canadian hosting; sub-processor confirmation still outstanding.
Policy decision record · PHI request blocked from external model
Alice decision BLOCK with reason PHI_REQUIRES_SOVEREIGN_EXECUTION; sovereign alternative offered and accepted.
Proxy block change record · consumer AI on clinical subnets
Change ticket, approval, and verification screenshot reference for the network block.
Clinician approval record · discharge summary draft
Named clinician approval captured on the Trust Receipt before the draft entered the record.
Regulatory mappings
Applicability is computed from the use context: binding law is never a user choice, and benchmarks can only be added on top. Reference material with provenance, last verified 2026-07-18.
| Instrument | Jurisdiction | Binding status | Applicability here | Effective | Controls mapped |
|---|---|---|---|---|---|
| Enhancing Digital Security and Trust Act, 2024 (Ontario)Ontario e-Laws ↗ | Ontario | binding law | APPLICABLE BINDING | 2025-01-29 | GOV-01GOV-02GOV-05SEC-03CLIN-04LIFE-02 |
| O. Reg. 51/26: Cyber Security (Ontario)Ontario e-Laws ↗ | Ontario | binding law | APPLICABLE BINDING | 2026-07-01 | SEC-01SEC-02SEC-04SEC-05 |
| IPC/OHRC Principles for the Responsible Use of Artificial IntelligenceInformation and Privacy Commissioner of Ontario / Ontario Human Rights Commission ↗ | Ontario | guidance | GUIDANCE AVAILABLE | Not applicable — guidance / standard / proposed | GOV-01GOV-03PRIV-02CLIN-03CLIN-04FAIR-01FAIR-02 |
| Personal Health Information Protection Act, 2004 (Ontario) — AI/clinical control mappingOntario e-Laws (with IPC hospital and AI-scribe guidance) ↗ | Ontario | binding law | APPLICABLE BINDING | 2004-11-01 | DATA-01DATA-02DATA-03DATA-04DATA-05PRIV-01PRIV-02PRIV-03SEC-01SEC-02SEC-03SEC-04VEN-01VEN-02 |
| FIPPA privacy amendments (Ontario, 2025)IPC Ontario / Ontario e-Laws ↗ | Ontario | binding law | APPLICABLE BINDING | 2025-07-01 | PRIV-01PRIV-03SEC-04GOV-05 |
| IPC Ontario — AI Scribes: Key Considerations for the Health SectorInformation and Privacy Commissioner of Ontario ↗ | Ontario | guidance | GUIDANCE AVAILABLE | Not applicable — guidance / standard / proposed | VEN-01VEN-02VEN-03PRIV-01PRIV-02CLIN-01CLIN-05LIFE-03 |
| Accreditation Canada / HSO — governance and leadership standards (high-level mapping)Accreditation Canada / Health Standards Organization ↗ | Canada | standard | BENCHMARK SELECTED | Not applicable — guidance / standard / proposed | GOV-01GOV-03ACC-01CLIN-06 |
| ISO/IEC 42001:2023 — AI management systemsISO ↗ | International | standard | BENCHMARK SELECTED | Not applicable — guidance / standard / proposed | GOV-01GOV-02SEC-01SEC-02LIFE-01LIFE-02LIFE-03VEN-03 |
Regulatory content is reference material with provenance. It is not legal advice; applicability to a specific organization requires qualified review.
Versions
A finalized assessment is superseded by a new version, never edited in place. The trend is the product.
Version 1 · DEMO-ASMT-001
Foundational · 3 critical blocker(s) · 33/33 answered
Version 2 · DEMO-ASMT-002
Foundational · 3 critical blocker(s) · 33/33 answered
History
- 06-04Assessment v1 started · use context recorded (clinical documentation, PHI, hybrid sourcing).2026-06-04
- 06-20Assessment v1 finalized by CyberChain reviewer · findings and draft action plan generated.2026-06-20
- 07-08Four recommendations approved for client view.2026-07-08
- 07-28DEMO-REC-004 closed · inventory and risk ranking attached as evidence.2026-07-28
- 08-12DEMO-REC-003 closed · clinician sign-off enforced; receipts show recorded approval.2026-08-12
- 08-15Assessment v2 finalized · re-scored with new evidence; v1 preserved as history.2026-08-15
Ready to see your own organization?
Everything above is synthetic. Signing in shows your organization's own assessment, risks, policies, recommendations, and Trust Receipts. Access follows a confidential discussion and a signed NDA.
Every record on this page is synthetic and belongs to a fictional hospital. Nothing here is a customer, a patient, or a production measurement. The scoring, eligibility, and audit logic are the real Nexus engines running over the synthetic inputs.