HIPAA <> AI Webinar
Say Yes to AI Without Failing an Audit
MCP gives AI access to the systems your organization runs on. In healthcare that only works when PHI can be stopped before it reaches the model, every call is attributable to a person, and a BAA is in place.
In this webinar, VP of AI at Usercentrics, Michael Yaroshefsky, will show you:
- how to filter PHI out before it reaches the model
- how to keep an audit trail that works as a HIPAA access record
- how to stop agents from routing around the gateway entirely
Thursday, October 1st at 1 PM ET
RSVP for Free. Can’t make it live? We’ll send you the recording

The Presenter
Michael “Yaro” Yaroshefsky is the VP of AI at Usercentrics. He also founded MCP Manager, which Usercentrics acquired in 2026. Yaro’s AI security and governance expertise has appeared in leading tech publishers like The New Stack, AI Journal, and CIO.com.
Trusted by companies like:
What HIPAA asks for and how MCP gateways help
PHI never reaches the model
The control everything else rests on. Gateway rules inspect every message in both directions and block, redact, mask, replace, or hash PHI inline. Detection runs on regex for MRNs and SSNs, plus Presidio, Bedrock Guardrails or Lakera for clinical free text.
Minimum necessary, enforced
HIPAA Security Rule. Capability-based access control and per-team tool provisioning decide which agents reach which systems, with a fail-closed allowlist. An assistant built for scheduling never gets handed clinical write tools.
Audit controls
Section 164.312. Every call is logged with the requesting identity, the tool invoked, the payloads and the enforcement verdict, so you can reconstruct exactly what any AI touched, when, and under whose identity.
Nobody routes around it
A control you can actually attest to. Disable direct connectors in your AI client and allowlist the gateway, so every MCP call is governed rather than merely encouraged. Static egress IPs let a sensitive upstream accept traffic only from MCP Manager.
PHI hides in free text
Content, not just location. PHI does not stay in the systems you expect it in. Rules inspect what a tool actually returns, so a patient name inside a document in someone’s personal drive is caught on content rather than missed by a folder rule.
Incident readiness
Continuous, not periodic. Real-time alerts on policy violations and content-filter triggers, break-glass kill switches that disable a host, connection or identity instantly, and rules that fail closed so a detector outage denies PHI rather than passing it.
The Three Questions a HIPAA Review Asks:
And What MCP Manager Offers
01
Will you sign a BAA?
Yes. MCP Manager signs Business Associate Agreements with covered entities and business associates, and can either provide its own or countersign yours.
BAAs are available on select enterprise plans. Your MCP Manager contact sets it up.
02
Can we keep the logs long enough?
Every MCP call is recorded with the identity, the tool, the payloads and the enforcement verdict, which is what makes the log usable as a HIPAA access record.
In-platform retention runs from 14 days up to a year or more depending on plan, and periods beyond 12 months can be configured. For indefinite, compliance-grade retention, forward the stream to your own collector and keep it as long as you like.
03
Can we connect systems without sending PHI?
That is the point of the gateway. PHI is detected and stripped on the way through, so a system you have had to keep disconnected becomes one your teams can query.
Redact, mask, hash or block, per rule, set to fail closed. The model sees the answer without the patient.
What you can put in front of your compliance officer
Every claim below is enforced at the gateway, and evidenced in the log:
- PHI is stopped before the model sees it
- Each agent reaches only the least data its task requires
- Every action ties back to a named person, not a service account
- No AI client can reach a system except through the gateway
- A detector outage denies PHI instead of passing it
- The access record lives in our SIEM, on our retention schedule
Built by a company whose whole business is provable data handling.
MCP Manager is built by Usercentrics, Europe’s largest consent management platform, active in more than 100 countries and processing billions of consent signals every month across millions of websites and apps.
Deciding what data is allowed to flow, and proving it afterwards, is the job Usercentrics has done since long before AI made it urgent. Review the security posture at the Usercentrics trust center, and the pre-signed DPA at mcpmanager.ai/dpa.
