PHI INPUTS: PROHIBITEDPHASE: 0 — NOT FOR PHIBAA TIER: IN BUILD
Directory

Curated, not comprehensive

Open healthcare models, with the fine print attached.

2 MODELS · 2 DEPLOYMENT PROFILES · REVIEWED 2026-07-16

No Anthropic, OpenAI, Gemini, Grok, or merely “open-weight” listings. This public directory is limited to healthcare- or biomedical-specific models and safeguards published under an Apache 2.0 open-source license. The catalog is intentionally small; license ambiguity is a reason to exclude a model, not soften the label.

Governance

How this directory is governed.

  • Verification status is recorded per field, never per row, and every field carries a source, a retrieval date, the exact configuration scope, a verification status, a reviewer, and a re-verification due date. Where we do not know, the entry says unknown.
  • Evidence has an expiry, 90 days from retrieval by default. A build containing an expired field fails, so a stale date cannot ship silently.
  • The directory is re-verified on a quarterly cycle.
  • The counts shown on this page are generated at build time from the shipped data file.
AVAILABILITY IS NOT COVERAGE

Availability listed here is not coverage for your deployment. A BAA covers specific services and specific configurations under an agreement between specific parties. Nothing in this directory creates coverage, and no model is itself HIPAA-eligible apart from the service configuration it runs in. Verify every field against your own contracts before relying on it.

Evidence

Reading the provenance chips.

VERIFIED: PRIMARY
Confirmed against the provider's own published documentation.
VERIFIED: SECONDARY
Confirmed against a reputable non-provider source.
PARTIAL
Part of the field is confirmed; the rest is not.
UNVERIFIED
Asserted somewhere, confirmed nowhere we accept.
UNKNOWN
We could not determine this. Published as such.
Catalog

Models

Healthcare foundation models

BioMistral consortium (Avignon Université / Nantes Université)

BioMistral 7B

Apache-2.0

Permissive Apache-2.0 license (most permissive in the healthcare-tuned lane), but note the Mistral-7B base and PubMed-derived training data. 2024-era model — older than the current healthcare-tuned generation.

View deployment evidence
Deployment pathRetentionTraining useZero data retentionAgreement pathRegions
Self-hosted (open weights)OPERATOR: Customer / operatorOperator-controlled — self-hosted open weights; no first-party hosted endpoint with a stated retention posture found.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
No vendor inference training-use — weights are downloaded and run by the operator.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
Not applicable — self-hosted; no external service retains data; retention control is the operator's own responsibility.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
None found — no first-party hosted service; any BAA depends entirely on the operator's chosen hosting infrastructure and configuration.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment; HIPAA/BAA responsibility sits with the operator's hosting environment and configuration
Self-hosted / any — open weights on Hugging Face; deployment region is operator-determined.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment

Infrastructure

Clinical data safeguards

Knowledgator + DS4DH, University of Geneva

GLiNER-BioMed

Apache-2.0

Infrastructure NER model, not a QA/chat model: probabilistic ML zero/few-shot biomedical entity recognition. As an ML model its detection is probabilistic — distinct from deterministic rule-based detection (see Microsoft Presidio). Candidate PHI-detection recognizer for gateway tooling.

View deployment evidence
Deployment pathRetentionTraining useZero data retentionAgreement pathRegions
Self-hosted (open weights)OPERATOR: Customer / operatorOperator-controlled — self-hosted open weights; no first-party hosted endpoint with a stated retention posture found.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
No vendor inference training-use — weights are downloaded and run by the operator.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
Not applicable — self-hosted; no external service retains data; retention control is the operator's own responsibility.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment of downloaded open weights
None found — no first-party hosted service; any BAA depends entirely on the operator's chosen hosting infrastructure and configuration.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment; HIPAA/BAA responsibility sits with the operator's hosting environment and configuration
Self-hosted / any — open weights on Hugging Face; deployment region is operator-determined.VERIFIED: SECONDARYSOURCE: huggingface.co
RETRIEVED 2026-07-16 · RE-VERIFY BY 2026-10-14 · REVIEWER: claude-code-research-lane-20260716
SCOPE: Self-hosted deployment
Corrections

Tell us what we got wrong.

If any field here is wrong, stale, or misleadingly scoped, email customerservice@healthit.comwith the model, the field, and your source. Corrections are reviewed against primary evidence and the field's provenance line is updated with a new retrieval date. We would rather publish a correction than defend an error.

AVAILABILITY IS NOT COVERAGE

Verify every field against your own contracts before relying on it. See the governance block above.