The first independent constitutional governance certification for AI systems operating in clinical, diagnostic, and health operations roles. Built on the seven pillars of the Lunara Constitution.
Apply for CertificationRegulatory Context
The EU AI Act classifies healthcare AI as high risk, triggering mandatory conformity assessments, post market monitoring, and transparency obligations. The FDA has issued guidance on AI enabled medical devices, requiring predetermined change control plans and transparency about model function. The Joint Commission is expanding AI governance review for accredited hospitals. HIPAA privacy rules constrain how AI systems handle protected health information. State level legislation is adding additional layers of clinical AI transparency requirements.
Health systems and digital health vendors are now operating in an environment where independent governance certification is becoming a procurement, accreditation, and regulatory submission requirement. The Healthcare Constitutional AI track provides that certification on a constitutional foundation.
Track Specification
Each constitutional pillar is assessed against healthcare specific requirements. The certification audit verifies compliance with both the universal constitutional standard and the track specific regulatory mapping below.
| Constitutional Pillar | Healthcare Track Requirement |
|---|---|
| I. Verified Identity
HIPAA covered entity verification, NPI validation
|
The organisation operating AI in healthcare roles must be a verified legal entity with confirmed clinical operating authority. Hospital systems must show accreditation status. Vendors must show FDA registration where applicable. Identity is established through legal registration, licensing validation, and institutional credentialing. |
| II. Declared Governance Framework
FDA Predetermined Change Control Plan, IRB protocols
|
The AI system must have a documented governance framework defining clinical use boundaries, decision authority levels, human oversight requirements, and model update protocols. For FDA regulated devices, the governance framework must align with the predetermined change control plan. For clinical decision support tools, IRB or equivalent oversight documentation is required. |
| III. Transparency of Contact
Patient notification standards, clinical disclosure rules
|
Any AI system interacting with patients, clinicians, or health operations staff must disclose its AI nature and institutional origin. Patient facing AI must provide clear disclosure that the patient is interacting with or receiving output from an AI system. Clinical AI recommendations must be traceable to their institutional source. Covert AI interaction is constitutionally prohibited under this track. |
| IV. Data Sovereignty
HIPAA Privacy Rule, 42 CFR Part 2, state privacy laws
|
Protected health information processed by AI systems must be governed by explicit data handling policies. Minimum necessary data access, purpose limitation, retention schedules, and cross border transfer restrictions must be documented. Business associate agreements must be in place for all third party AI processing of PHI. Data deidentification standards must be declared and verified. |
| V. Audit Accessibility
CMS Conditions of Participation, Joint Commission standards
|
Governance records, model decision logs, and audit trails must be accessible to legitimate counterparties including regulators, accreditation bodies, and authorised institutional reviewers. Audit logs must demonstrate clinical safety monitoring, adverse event tracking, and model performance over time. Records must be retained per applicable regulatory requirements. |
| VI. Revocability
FDA recall authority, clinical suspension protocols
|
The certification can be revoked for cause including safety incidents, governance violations, model drift beyond acceptable parameters, or failure to maintain compliance. For clinical AI, revocation protocols must include patient safety transition plans. Revocation is public, logged, and verifiable through the Lunara Registry. Reinstatement requires full reassessment. |
| VII. Proportionality
Risk based classification under EU AI Act, FDA risk categorization
|
Governance requirements scale with clinical risk. A diagnostic AI system operating in treatment advisory roles carries higher governance requirements than an administrative AI system processing scheduling data. The certification audit assesses risk classification and verifies that governance depth matches the clinical risk profile of the specific AI deployment. |
Regulatory Alignment
Certification maps to Annex III requirements for AI systems in healthcare, including risk management systems, data governance, technical documentation, transparency, human oversight, accuracy, and robustness.
Certification aligns with predetermined change control plan requirements, GMLP principles, transparency obligations, and post market surveillance expectations for AI enabled medical devices.
Data Sovereignty pillar assessment verifies HIPAA compliance for AI systems processing PHI, including minimum necessary standards, access controls, and business associate agreement coverage.
Certification documentation supports Joint Commission accreditation review by demonstrating institutional AI governance structures, accountability frameworks, and safety monitoring protocols.
Certification supports compliance with emerging state legislation requiring disclosure of AI use in clinical decision making, including Colorado AI Act, Illinois HB requirements, and similar frameworks.
Who This Track Serves
Applications are reviewed within 48 hours. Founding pilot seats available for the July 29 launch.
Apply for Certification