Running clinical AI under HIPAA and GDPR at the same time
Health projects arrive with both regimes attached. It is cheaper to treat that as one architecture question.
By Windmill Editorial Team, Product and delivery

Health projects tend to arrive with both regimes attached. The client is European, the data is patient data, and somewhere in the chain there is a US partner. Teams often treat that as two compliance exercises. It is cheaper to treat it as one architecture question.
Two constraints settle most of it. Where the data physically sits: we run these workloads in Swiss and EU cloud isolation, which removes the transfer argument before it starts rather than documenting a justification for it afterwards. What the model is allowed to retain: zero training on client data, contractually, across every model vendor in the chain. This is the clause people assume is standard and frequently is not.
Sprints run on sanitised data with no connection to live patient records, which is covered separately.
None of this is exotic. It is ordinary architecture applied early, which is considerably less expensive than the same architecture applied after a risk review has already said no.
Working on a related product or operating question?
Explore the four ways Windmill can help shape direction, prove value, build for production or evaluate a live system.
Related Insights
From SaaS to self-built in weeks, not months: Why we created Audra Vibe
We replaced Jira and Tempo with Audra Vibe, an internal platform shaped around how our team actually works.
2026-04-22Audra Eval: How we hold our own AI work accountable
Audra Eval is our evaluation and quality-gate layer. It tests accuracy, citations and model drift before and after release.