Public certificate verification

Confirm a certificate and read the obligations.

Enter the certificate ID from a LegisCert™ seal, registry listing, or LegisGate™ Build report. You will see registry status, the record integrity hash, and adopter-facing obligations cited to source — for prospects, procurement teams, and anyone who needs to inspect before they sign.

This is a transparency record from a regulatory mapping analysis — not legal advice and not a regulatory outcome certificate.

Verify a certificate

Enter a certificate ID.

Certificate IDs appear on every certified record — on the seal, in the registry, and on LegisGate™ Build reports. Each ID is unique; formats include LC-2026-00001 and LC-7K4P-9XQE.

  • Confirms the certificate is active in the registry
  • Shows the SHA-256 integrity hash for the mapping record
  • Lists adopter-facing obligations with authoritative citations
  • Supply-chain summary when published on the assessment

A transparency record from a regulatory mapping analysis — not a regulatory outcome certificate.

LegisCert seal

Customer transparency handout

Customer Transparency Packet

MedScribe AI

Provider
Northwind Health AI, Inc.
Website
https://www.northwindhealthai.example
Your role
Deployer / adopter (if you use this product)
Markets
United States · European Union
Industries
Healthcare · Clinical documentation
Report ID
PRR-2026-00148
Issued
24 June 2026

For deployers and adopters evaluating MedScribe AI

This handout reproduces the deployer-facing transparency record from a LegisGate Build analysis. It cites regulatory responsibilities you may inherit if you adopt this product — based on its declared architecture, markets, and clinical use case.

It is initial findings for orientation and guidance, not legal advice. Additional obligations may apply depending on your jurisdiction, specialty, and deployment model.

This handout includes
  • Cited deployer regulatory responsibilities (Part 2 obligations)
  • Declared upstream AI stack and vendor intelligence summary
  • LegisCert integrity verification block with QR lookup
  • Path to a full assessment scoped to your organization

This packet is a transparency handout from a provider regulatory report. It helps procurement, privacy, and clinical leaders understand cited deployer duties before adoption — it does not replace counsel review or a deployment-specific assessment.

01

Deployer regulatory responsibilities

Cited obligations for organizations that deploy or adopt this product.

Part 2 reflects initial regulatory responsibilities you may inherit if you adopt this product, based on its declared architecture, markets, industries, and data flows. Your actual obligations depend on how you deploy the tool, what decisions it influences, and which jurisdictions and sectors you operate in — which may trigger regulations beyond those listed here. Treat this as a cited transparency starting point, not an exhaustive map. For a full assessment of your use case, run LegisGate Report with your location, industry, and deployment context.

HIPAA — Privacy & Security

If you deploy in US healthcare →

You must execute a HIPAA Business Associate Agreement with Northwind Health AI, Inc. before any PHI flows to this tool.

If you are a HIPAA covered entity, you cannot route PHI to this tool until a Business Associate Agreement is executed with the provider — a hard gate before any production deployment.

When your organization adopts this tool, you remain the HIPAA covered entity and the vendor becomes your business associate for PHI processed in the workflow. 45 CFR § 164.504(e) requires a BAA before any PHI is disclosed to or processed by the vendor.

Citation

45 CFR § 164.504(e)

Binding regulation · deterministic rule
Enforcement exposure

$100–$50,000 per violation / $25K–$1.5M annual cap / corrective action

Civil monetary penalties (per violation category)
$100 – $50,000 per violation45 CFR § 160.404
Annual cap (identical violations)
$25,000 – $1,500,00045 CFR § 160.406
OCR corrective action
Resolution agreement or CAP may be required

EU AI Act — Deployer (high-risk)

If you deploy in the EU/EEA →

You inherit deployer duties — human oversight by competent staff, log retention, and operational monitoring.

EU customers adopting a high-risk clinical AI tool inherit full deployer obligations — oversight, monitoring, and logging cannot be delegated back to the vendor.

Under EU AI Act Article 26, deployers of high-risk AI systems must use the system according to instructions, assign human oversight to competent staff, monitor operation, and keep automatically generated logs for at least six months unless law requires longer retention.

Citation

EU AI Act Art. 26

Binding regulation · validated template
Enforcement exposure

Up to €35M / 7% global turnover (AI Act) / member-state oversight

Administrative fines (AI Act)
Up to €35M or 7% of worldwide annual turnoverEU AI Act Art. 99
Deployer duty breach
Human oversight, logging, and incident reporting obligations applyEU AI Act Art. 26

EU AI Act — Deployer (high-risk)

If you deploy in the EU/EEA →

You must inform patients who are subject to the high-risk system.

EU deployers must tell patients when they are subject to a high-risk AI system — ambient scribes in exam rooms need a clear notice strategy.

Article 26(11) requires deployers to inform natural persons that they are subject to the use of a high-risk AI system. For ambient clinical documentation, patients may not realize conversation audio is processed by AI.

Citation

EU AI Act Art. 26(11)

Binding regulation · validated template
Enforcement exposure

Up to €35M / 7% global turnover (AI Act) / transparency duties

Administrative fines (AI Act)
Up to €35M or 7% of worldwide annual turnoverEU AI Act Art. 99
Transparency to affected persons
Inform patients subject to high-risk AI useEU AI Act Art. 26(11)

GDPR — Data protection

If you deploy in the EU/EEA →

You must establish a lawful basis and Article 9 condition for the clinical data this tool processes.

EU healthcare customers must establish their own lawful basis and Article 9 condition for clinical data the scribe processes — the vendor cannot do this for them.

Deploying MedScribe in an EU clinic means processing health data about patients. GDPR Article 9 requires a specific condition (commonly healthcare treatment under Member State law, or explicit consent where appropriate).

Citation

GDPR Art. 6, 9

Binding regulation · validated template
Enforcement exposure

€20M / 4% / €10M / 2% / 72h / Unlimited

Higher tier maximum (Art. 83(5))
€20M or 4% of global annual turnoverGDPR Art. 83(5)
Standard tier maximum (Art. 83(4))
€10M or 2% of global annual turnoverGDPR Art. 83(4)
Supervisory authority notification deadline
72hGDPR Art. 33
Aggravating/mitigating factors
Unlimited discretion under Art. 83(2)GDPR Art. 83(2)

US State — AI disclosure

If you deploy in US states with AI disclosure requirements →

You must disclose AI use to patients where state law requires it.

Several US states now require healthcare providers to disclose when AI assists clinical documentation or decision-making — your customers must comply locally.

State legislatures are adding AI transparency duties for healthcare — for example Colorado's AI Act (phased enforcement from 2026) and emerging medical-AI disclosure bills require practitioners to tell patients when AI materially assists care or documentation.

Citation

State medical-AI disclosure laws

Official guidance · validated template
Enforcement exposure

State-dependent — civil penalties / AG enforcement / practice restrictions

Enforcement varies by state
Colorado, California, and others impose disclosure duties with distinct remedies
Deployer responsibility
Confirm patient-facing disclosure workflows with counsel for each state of practice
02

Upstream AI stack & vendor disclosure

Declared subsystems, risk levels, and vendor intelligence from the Build record.

Aggregate upstream risk: High

Vendor intelligence: 1 of 1 upstream profile completed

Azure OpenAI GPT-4o (via Azure OpenAI Service)High

hosted_api · Microsoft / OpenAI

Research: complete

Clinical note retrieval (vector index over templates & prior notes)Moderate

retrieval_rag · Northwind Health AI, Inc.

Clinical workflow & coding suggestion layerHigh

domain_logic · Northwind Health AI, Inc.

Visit capture, prompt orchestration & EHR integrationHigh

orchestration · Northwind Health AI, Inc.

Encrypted visit storage (US-East / EU-West regions)Moderate

data_store · Northwind Health AI, Inc.

03

LegisCert verification

Confirm record integrity and certificate status at www.legiscert.com/verify.

Part 1 confirms this certificate is active, reproduces the Build report integrity hash, and shows the declared product scope and supply chain. Part 2 lists initial cited deployer obligations from that analysis — not a full regulatory assessment of your organization.

LegisCert™ seal
LegisCertAI tool regulatory transparency
Scan to verify
SHA-256 integrity hash29d8b78d487be53127be987f5af835a583440007433c411c03da3bb8b812014c
04

Full assessment for your deployment

Run LegisGate Report with your organization's context when you need obligations mapped to your stack.

Need obligations for your location, industry, and use case? Run LegisGate Report with your deployment context at legisgate.com/build.

This page reproduces cited obligations from a LegisGate Build transparency report. It is not legal advice, not a regulatory outcome certificate, and does not replace review by qualified counsel.

Open certificate record →
Registry status

What each status means.

Status tells you whether the named certification record is current in the public registry. It is separate from record integrity, which confirms the underlying mapping file has not been altered.

Active

This certification is current as of today.

Expired

This certification has lapsed and is no longer current.

Superseded

A newer certification has replaced this one.

Withdrawn

This certification has been withdrawn from the registry.

Two verification values

What builders publish — and what reviewers inspect.

Tool makers use LegisCert™ to publish a source-cited obligation record with an integrity hash. Reviewers use the same verification route to confirm the file is unaltered and read what was disclosed — without contacting the vendor.

Value one

Record integrity

The SHA-256 hash on every Build report lets anyone re-hash their copy of the mapping file and confirm it matches the certified record.

Value two

Cited obligations

Adopter-facing responsibilities are listed with authoritative citations — the public transparency record from the mapping analysis, not internal roadmaps or marketing summaries.

Finding a certificate ID

Where stakeholders encounter IDs.

Certificate IDs travel with the certified record — on Build reports, holder websites, in the registry, and in public embeds.

01

On a LegisGate™ Build report

Build reports include a verification block with the certificate ID, SHA-256 hash, and link to legiscert.com/verify. Transparency handouts include a QR code beside the seal that opens the same lookup.

02

On the holder's website

Organizations that display the LegisCert™ mark link the seal or badge to the public verification URL for that certificate ID.

03

In the public registry

Search the LegisCert™ Registry by holder, scope, or certificate ID and open the verification route from any listing.

04

In embed code

Badge and seal embed snippets include the verification URL so third parties can resolve the record independently.

Continue inspecting

Verification is one step in a broader record.

Use the registry to search records, read the standard to understand what certification covers, or review how organizations display the LegisCert™ mark on their own sites.