Enter the certificate ID from a LegisCert™ seal, registry listing, or LegisGate™ Build report. You will see registry status, the record integrity hash, and adopter-facing obligations cited to source — for prospects, procurement teams, and anyone who needs to inspect before they sign.
This is a transparency record from a regulatory mapping analysis — not legal advice and not a regulatory outcome certificate.
Verify a certificate
Enter a certificate ID.
Certificate IDs appear on every certified record — on the seal, in the registry, and on LegisGate™ Build reports. Each ID is unique; formats include LC-2026-00001 and LC-7K4P-9XQE.
Confirms the certificate is active in the registry
Shows the SHA-256 integrity hash for the mapping record
Lists adopter-facing obligations with authoritative citations
Supply-chain summary when published on the assessment
Customer transparency handout
Customer Transparency Packet
MedScribe AI
Provider
Northwind Health AI, Inc.
Website
https://www.northwindhealthai.example
Your role
Deployer / adopter (if you use this product)
Markets
United States · European Union
Industries
Healthcare · Clinical documentation
Report ID
PRR-2026-00148
Issued
24 June 2026
For deployers and adopters evaluating MedScribe AI
This handout reproduces the deployer-facing transparency record from a LegisGate Build analysis. It cites regulatory responsibilities you may inherit if you adopt this product — based on its declared architecture, markets, and clinical use case.
It is initial findings for orientation and guidance, not legal advice. Additional obligations may apply depending on your jurisdiction, specialty, and deployment model.
Declared upstream AI stack and vendor intelligence summary
LegisCert integrity verification block with QR lookup
Path to a full assessment scoped to your organization
This packet is a transparency handout from a provider regulatory report. It helps procurement, privacy, and clinical leaders understand cited deployer duties before adoption — it does not replace counsel review or a deployment-specific assessment.
01
Deployer regulatory responsibilities
Cited obligations for organizations that deploy or adopt this product.
Part 2 reflects initial regulatory responsibilities you may inherit if you adopt this product, based on its declared architecture, markets, industries, and data flows. Your actual obligations depend on how you deploy the tool, what decisions it influences, and which jurisdictions and sectors you operate in — which may trigger regulations beyond those listed here. Treat this as a cited transparency starting point, not an exhaustive map. For a full assessment of your use case, run LegisGate Report with your location, industry, and deployment context.
01
HIPAA — Privacy & Security
If you deploy in US healthcare →
You must execute a HIPAA Business Associate Agreement with Northwind Health AI, Inc. before any PHI flows to this tool.
If you are a HIPAA covered entity, you cannot route PHI to this tool until a Business Associate Agreement is executed with the provider — a hard gate before any production deployment.
When your organization adopts this tool, you remain the HIPAA covered entity and the vendor becomes your business associate for PHI processed in the workflow. 45 CFR § 164.504(e) requires a BAA before any PHI is disclosed to or processed by the vendor.
Citation
45 CFR § 164.504(e)
Binding regulation · deterministic rule
Enforcement exposure
$100–$50,000 per violation / $25K–$1.5M annual cap / corrective action
Civil monetary penalties (per violation category)
$100 – $50,000 per violation45 CFR § 160.404
Annual cap (identical violations)
$25,000 – $1,500,00045 CFR § 160.406
OCR corrective action
Resolution agreement or CAP may be required
02
EU AI Act — Deployer (high-risk)
If you deploy in the EU/EEA →
You inherit deployer duties — human oversight by competent staff, log retention, and operational monitoring.
EU customers adopting a high-risk clinical AI tool inherit full deployer obligations — oversight, monitoring, and logging cannot be delegated back to the vendor.
Under EU AI Act Article 26, deployers of high-risk AI systems must use the system according to instructions, assign human oversight to competent staff, monitor operation, and keep automatically generated logs for at least six months unless law requires longer retention.
Citation
EU AI Act Art. 26
Binding regulation · validated template
Enforcement exposure
Up to €35M / 7% global turnover (AI Act) / member-state oversight
Administrative fines (AI Act)
Up to €35M or 7% of worldwide annual turnoverEU AI Act Art. 99
Deployer duty breach
Human oversight, logging, and incident reporting obligations applyEU AI Act Art. 26
03
EU AI Act — Deployer (high-risk)
If you deploy in the EU/EEA →
You must inform patients who are subject to the high-risk system.
EU deployers must tell patients when they are subject to a high-risk AI system — ambient scribes in exam rooms need a clear notice strategy.
Article 26(11) requires deployers to inform natural persons that they are subject to the use of a high-risk AI system. For ambient clinical documentation, patients may not realize conversation audio is processed by AI.
Citation
EU AI Act Art. 26(11)
Binding regulation · validated template
Enforcement exposure
Up to €35M / 7% global turnover (AI Act) / transparency duties
Administrative fines (AI Act)
Up to €35M or 7% of worldwide annual turnoverEU AI Act Art. 99
Transparency to affected persons
Inform patients subject to high-risk AI useEU AI Act Art. 26(11)
04
GDPR — Data protection
If you deploy in the EU/EEA →
You must establish a lawful basis and Article 9 condition for the clinical data this tool processes.
EU healthcare customers must establish their own lawful basis and Article 9 condition for clinical data the scribe processes — the vendor cannot do this for them.
Deploying MedScribe in an EU clinic means processing health data about patients. GDPR Article 9 requires a specific condition (commonly healthcare treatment under Member State law, or explicit consent where appropriate).
Citation
GDPR Art. 6, 9
Binding regulation · validated template
Enforcement exposure
€20M / 4% / €10M / 2% / 72h / Unlimited
Higher tier maximum (Art. 83(5))
€20M or 4% of global annual turnoverGDPR Art. 83(5)
Standard tier maximum (Art. 83(4))
€10M or 2% of global annual turnoverGDPR Art. 83(4)
Supervisory authority notification deadline
72hGDPR Art. 33
Aggravating/mitigating factors
Unlimited discretion under Art. 83(2)GDPR Art. 83(2)
05
US State — AI disclosure
If you deploy in US states with AI disclosure requirements →
You must disclose AI use to patients where state law requires it.
Several US states now require healthcare providers to disclose when AI assists clinical documentation or decision-making — your customers must comply locally.
State legislatures are adding AI transparency duties for healthcare — for example Colorado's AI Act (phased enforcement from 2026) and emerging medical-AI disclosure bills require practitioners to tell patients when AI materially assists care or documentation.
Citation
State medical-AI disclosure laws
Official guidance · validated template
Enforcement exposure
State-dependent — civil penalties / AG enforcement / practice restrictions
Enforcement varies by state
Colorado, California, and others impose disclosure duties with distinct remedies
Deployer responsibility
Confirm patient-facing disclosure workflows with counsel for each state of practice
02
Upstream AI stack & vendor disclosure
Declared subsystems, risk levels, and vendor intelligence from the Build record.
Aggregate upstream risk: High
Vendor intelligence: 1 of 1 upstream profile completed
Confirm record integrity and certificate status at www.legiscert.com/verify.
Part 1 confirms this certificate is active, reproduces the Build report integrity hash, and shows the declared product scope and supply chain. Part 2 lists initial cited deployer obligations from that analysis — not a full regulatory assessment of your organization.
Run LegisGate Report with your organization's context when you need obligations mapped to your stack.
Need obligations for your location, industry, and use case? Run LegisGate Report with your deployment context at legisgate.com/build.
Registry status
What each status means.
Status tells you whether the named certification record is current in the public registry. It is separate from record integrity, which confirms the underlying mapping file has not been altered.
Active
This certification is current as of today.
Expired
This certification has lapsed and is no longer current.
Superseded
A newer certification has replaced this one.
Withdrawn
This certification has been withdrawn from the registry.
Two verification values
What builders publish — and what reviewers inspect.
Tool makers use LegisCert™ to publish a source-cited obligation record with an integrity hash. Reviewers use the same verification route to confirm the file is unaltered and read what was disclosed — without contacting the vendor.
Value one
Record integrity
The SHA-256 hash on every Build report lets anyone re-hash their copy of the mapping file and confirm it matches the certified record.
Value two
Cited obligations
Adopter-facing responsibilities are listed with authoritative citations — the public transparency record from the mapping analysis, not internal roadmaps or marketing summaries.
Finding a certificate ID
Where stakeholders encounter IDs.
Certificate IDs travel with the certified record — on Build reports, holder websites, in the registry, and in public embeds.
01
On a LegisGate™ Build report
Build reports include a verification block with the certificate ID, SHA-256 hash, and link to legiscert.com/verify. Transparency handouts include a QR code beside the seal that opens the same lookup.
02
On the holder's website
Organizations that display the LegisCert™ mark link the seal or badge to the public verification URL for that certificate ID.
03
In the public registry
Search the LegisCert™ Registry by holder, scope, or certificate ID and open the verification route from any listing.
04
In embed code
Badge and seal embed snippets include the verification URL so third parties can resolve the record independently.
Continue inspecting
Verification is one step in a broader record.
Use the registry to search records, read the standard to understand what certification covers, or review how organizations display the LegisCert™ mark on their own sites.