For Health Systems · EHR Vendors · Pharmacy Networks

The prescription. The dispensing. The chart. The patient. Proven at every hand.

The order does not transmit, the dispense does not complete, and the chart does not open unless the accountable human signed for it, or signed the boundary it falls inside. Not the prescribing identity alone, every acting party: the clinician ordering, the pharmacist dispensing, the patient consenting. Each signs on their own device. What survives afterwards is hash-chained and non-repudiable, built for DEA and state board audit.

The Problem

Hospital workflows still run on shared authentication. Computer-on-wheels carts pass between clinicians with cached sessions. Passwords live on sticky notes because infection-control policy forbids touching the keyboard cover twice. Shift handoffs leave terminals unlocked for thirty minutes. The hospital owns the hardware and the credential cache. It does not own a record of who was in the chair at the exact moment a controlled-substance order left the EHR.

The pharmacy counter is a second, quieter gap. A prescription is picked up by whoever presents the card and knows the address. The pharmacist approves the dispense on a terminal a colleague unlocked an hour ago. The DEA receives an audit trail that says a prescription was dispensed, not cryptographic evidence that the pharmacist of record was present, that the patient of record received, or that the two sides agreed.

After-hours chart access is the third gap, increasingly urgent under modern privacy frameworks. A clinician at home at 2am opens a patient chart from a personal device. The EHR logs the access; the patient learns nothing, or learns months later from a breach notification. HIPAA minimum-necessary is a regulatory intent, the evidence that the doctrine was upheld does not exist in the audit trail.

The common thread: conventional authentication answers one question, who is logged in, while the regulatory and ethical frameworks require answers to harder ones. Who acted. Who received. Whose consent. SSO, EHR session management, and EPCS checkbox flows cannot produce those answers at the specificity the frameworks assume.

What Yuthent Provides

Three places authentication does not reach. Three places Yuthent does.

The mobile-first clinician. Replace the shared keyboard with the device already in the clinician's pocket. The EHR surfaces the order on the clinician's enrolled phone; the parameters are visible; the clinician presses. The secure element produces an Authoritative-tier proof bound to the exact order, a hardware-bound EC P-256 key, biometric enforced at the device hardware layer, aligned with DEA EPCS and 21 CFR Part 11. The hospital workstation never held a password, because it never needed one, and infection control keeps its hands off the keyboard.

The cryptographic handshake at the pharmacy counter. Two sides, two devices, one agreement. The pharmacist confirms dispensing on their enrolled device; the patient confirms receipt on theirs. Both proofs enter the hash-chained ledger, bound to the same prescription identifier. A disputed dispense, a controlled-substance reconciliation, or a regulator examining a suspect counter finds a single object: a cryptographic handshake between the two humans who agreed at that counter, at that moment, over that exact prescription.

Patient-centric consent for remote chart access. A clinician attempts to open a chart from outside the network, outside standing care-team relationships, outside approved hours, and the access does not proceed. The control plane routes an Explicit-tier push to the patient's own enrolled device: who is requesting, which chart, which clinical context. The chart opens if, and only if, the patient has cryptographically consented, with immediate patient-side revocation and a webhook to your SIEM for every consent event.

For AI Agents

The clinical agent can draft. Only the clinician can sign.

Clinical AI is moving from documentation into ordering, and EU AI Act Article 14 makes human oversight of high-risk medical AI a legal requirement, not a policy preference. A logged click is not oversight. A signature is.

01

The prescriber signs the clinical bounds once

A mandate is signed on the prescriber's own enrolled device: which order types the agent may place, how many in a day, until when. Inside those bounds template-compliant documentation and routine lab orders proceed without paging the clinician. Article 14 oversight is the signature on those bounds, not an interruption on every order.

02

Outside it, the named prescriber signs

A controlled substance, a high-risk intervention, a record release outside the standing scope: the order stops and surfaces on the licensed clinician's enrolled device with the exact parameters. A biometric press produces an Authoritative-tier proof bound to that order. The agent can prepare and request, only the enrolled human can authorize.

03

No mandate, no order

If no mandate covers the agent, or the one it names has expired or been revoked, the order does not transmit, and revocation takes effect on the next attempt rather than at the end of a session. A prompt-injected or mis-scoped model reaches the gate and produces nothing, and the attempt lands in your audit stream in real time.

Capability Surface

The primitives under every clinical use case above.

Hash-chained per-actor audit trail

Every Authoritative action is chained to the prior action by the same actor. Altering one record breaks every record after it. Daily tenant anchors. Exportable for DEA audit, state board review, or internal investigation.

Hardware-bound, un-extractable keys

EC P-256 keypairs live inside StrongBox, TEE, or Secure Enclave. The key never leaves the device. A biometric enrollment change cryptographically destroys it. The right to authorize is not transferable by credential sharing.

Push-based Explicit and Authoritative approvals

Action requests route to the acting human's device with the exact parameters. Any modification post-approval invalidates the payload hash. The proof binds to the exact parameters delivered to the device.

Time-boxed scoped grants

In-person link enrollment, supervised onboarding, remote video enrollment, and delegated access each operate through signed, scoped, time-limited grants. Revocable from the control plane at any moment.

Offline-capable signing at the point of care

Once a clinician's device is enrolled, biometric verification and Explicit-tier signing require no network, proofs hold in a durable on-device queue and sync on reconnection. Authoritative-tier orders, including controlled substances, require the synchronous server co-signature by design and are refused rather than queued when the device is offline. Field clinics, disaster response, and humanitarian operations share the evidentiary floor of a tertiary urban hospital.

Long-term audit retention

Action records leave hot storage on a daily archival export. Seven-year cold audit retention is contracted separately, which is the horizon a health system's own record-retention obligations run to.

Regulatory Alignment

What each framework will not let you run without.

DEA EPCS

Two factors of independent categories, biometric enforced at the device secure element. Hash-chained audit trail per prescriber. Architected for DEA audit with export through the control plane.

HIPAA Security and Privacy Rules

Authentication and audit controls strengthened well beyond conventional EHR deployments. Per-action non-repudiation. Minimum-necessary access supported by patient-consented Explicit-tier gating on remote chart openings.

21 CFR Part 11

Electronic signatures with unique identification, non-repudiation, and trustworthy audit trails. Hash-chain integrity with daily anchors supports Part 11 audit-trail requirements.

EU AI Act · Article 14

Clinical AI touching diagnosis, triage, or ordering is high-risk under Annex III, and Article 14 requires affirmative human oversight, with the high-risk compliance deadline in December 2027. A per-action, hardware-bound prescriber signature is that oversight in evidentiary form: proof the accountable human approved the specific act, not a process document saying someone should have. Exposure runs to €15M or 3% of worldwide turnover (Art 99(4)).

State e-prescribing mandates

Architected for the strictest state requirements for controlled-substance prescribing and clinician-of-record chain-of-custody. Evidence format defensible in state board review.

HITRUST and NIST SP 800-66

Control mappings supported through the control plane's audit export and the per-action cryptographic evidence record.

Alongside Your Stack

Yuthent does not replace Epic, Cerner, Allscripts, your internal build, or the pharmacy dispensing system. It is the cryptographic evidence layer beneath all of them: your clinical system continues to own the record, and Yuthent owns the proof. Integration is a thin service wrapper on the action path, every high-stakes clinical action and every consent event produces an exportable receipt, landing in the tenant audit view in real time through the control plane and the webhook stream.

Deployment Readiness

First deployments are paid engagements with a named integration scope, a defined regulatory objective, and a cryptographic evidence target. The first deployment ships on one flow: controlled-substance prescribing, two-sided pharmacy dispensing, or patient-consent-gated chart access. The control plane is live from day one, the first proofs you see are your own, and the first audit export you pull lands in a bucket you own.

Questions

Answered plainly.

Does Yuthent see patient data or PHI?

No. Biometric matching executes on the acting person's device and never leaves it. The control plane receives action metadata, an order identifier and payload hash, a counter, a device attestation, and the proof, never the chart, the prescription contents, or any PHI beyond what you choose to hash into the signature.

Can a clinical AI agent authorize a controlled-substance order?

No. A gated clinical action requires the named prescriber's fresh, hardware-bound biometric proof at the moment of the order. An agent can prepare and request; only the enrolled clinician can authorize, and EU AI Act Article 14 is written on exactly that assumption for high-risk clinical AI.

Does it work at the point of care without a network?

Yes, once the device is enrolled: biometric verification and action signing run offline, with proofs held in a durable on-device queue that syncs on reconnection. Enrollment is a supervised, connected step, and the highest-assurance tier requires a synchronous server co-signature by design.

Does it replace our EHR or e-prescribing workflow?

No. Epic, Cerner, Allscripts, or your internal build continues to own the record and the workflow. Yuthent is a thin service wrapper on the action path that adds the per-action cryptographic evidence layer, exportable for DEA audit, state board review, or internal investigation.

Does Yuthent deploy in the cloud or on-prem?

Hosted multi-tenant on Yuthent's Google Cloud. Because only metadata leaves the device, hosted is sufficient for most health systems. Dedicated cloud and on-prem are available on request and scoped during a first deployment.

Start a first deployment.

Tell us the flow you want to protect. We will come back with a working integration proposal. First call within five business days.