Case studies / eSpiral
Case study · Developer platform · Residency programs
AI in the chart. PHI never in the cloud.
eSpiral builds clinical intelligence software for hospital residency programs: hundreds of residents and their supervisors, asking an LLM about real patients all day. They installed medscrub's self-hosted proxy so the hospital never has to wonder what the model saw.
AI value is real
Residents move fast between patients and want on-demand clinical context: differentials, interactions, protocols — grounded in the actual chart.
PHI can't leave the building
Hospital compliance prohibits sending identifiable data to external AI APIs. Consumer LLMs are off the table without de-identification.
Cohorts keep arriving
Residency means constant onboarding. Every new class needs safe AI access on day one — without a fresh compliance review each July.
The developer integration
eSpiral builds the experience. medscrub guarantees what the model sees.
eSpiral's chart assistant routes every LLM call through the medscrub proxy running inside the hospital network. Identifiers are swapped for opaque tokens on the way out and put back on the way in. eSpiral's application code doesn't care which model sits behind it, and the hospital's policy lives in one place.
Inside the hospital network
"name": "Jane Doe"
"dob": "1985-03-12"
"mrn": "04412208"
"cc": "knee pain, bilateral"
medscrub proxy
self-hosted
⇄
What the AI model sees
"name": "[NAME_1]"
"dob": "[DATE_1]"
"mrn": "[MRN_1]"
"cc": "knee pain, bilateral"
All 18 HIPAA Safe Harbor identifiers, three-layer NER pipeline. Non-PHI clinical text passes through unchanged.
At scale
Hundreds of residents. One proxy policy.
Residents are heavy users, they turn over every year, and the stakes are real. That combination is what usually kills hospital AI projects in committee. Here, every eSpiral session inherits the proxy's de-identification policy, so onboarding July's new class means creating accounts, not sitting through another security review. Supervisors see the same chart-grounded answers their residents do, and the institution can say exactly what left the building: nothing with a name on it.
Resident opens a chart — the eSpiral SMART on FHIR app launches inside the EHR; no separate login, no data export.
Every LLM call routes through medscrub — identifiers tokenized before the request leaves the network, re-applied on return.
Supervision stays intact — attendings see the same chart-grounded answers, and the institution can state exactly where data goes.
“We ship AI features to hundreds of residents. medscrub is the reason our answer on data exposure is one sentence long.”
eSpiral founding team
Built for the requirements hospitals actually have.
✓ PHI never transmitted to external AI servers
✓ All 18 HIPAA Safe Harbor identifiers covered
✓ Self-hosted proxy, Docker-deployed on-premise
✓ SMART on FHIR launch — no separate login
✓ Any model behind one policy — no per-vendor BAA
✓ Resident-facing assistant with clinical guardrails
The model never sees your patients.
medscrub's API and self-hosted proxy are available for developers building HIPAA-compliant clinical tools.