Research and explain
Read approved policies, records, and external sources, then prepare a cited brief or recommendation.
AI for HIPAA-regulated work
Boxwood gives healthcare teams private AI tools for billing, denials, underpayments, coverage checks, reporting, and other work involving PHI. Files remain stored on your system. Boxwood sends the content needed for each task to your organization's private Azure OpenAI deployment—not a public chatbot.
No application makes an organization compliant by itself. The BAA, configuration, access controls, policies, risk analysis, and actual use all matter.

Local workbench + your Azure deployment


What it can do
Read approved policies, records, and external sources, then prepare a cited brief or recommendation.
Work through remittance files, billing exports, patient paperwork, contracts, or other records and flag what needs attention.
Draft reports, spreadsheets, checklists, letters, and other deliverables with the source material still available for review.
Use the coding agent to create an internal tool or turn a repeated process into an agent your team can run again.
The compliance path
A BAA-covered model endpoint is necessary, but it is not sufficient. The agent also needs narrow access, defined tools, reviewable work, and operating policies that match the job.
Source files, credentials, artifacts, and durable work history remain in the local Boxwood workbench.
Approved inference context uses the Azure OpenAI deployment configured for your organization.
The agent works from the files, information sources, and software approved for the job.
Results can stay linked to their supporting records so the person using the agent can inspect the work.
HIPAA-compliant coding agent
Boxwood is built on a coding-agent harness. You can ask it to create a small internal app, connect an approved data source, change the workflow, or turn a successful task into a reusable agent. The same deployment controls still apply to every file, model request, connector, and external service it uses.

Questions buyers ask
HIPAA compliance applies to the full deployment and the way an organization uses it—not to an AI model or application in isolation. Boxwood is designed to support HIPAA-regulated work through a local workbench, scoped access, customer-controlled Azure OpenAI inference, and reviewable results. Your organization still needs the right BAA coverage, configuration, policies, risk analysis, and operating controls.
Boxwood includes a coding agent that can build internal tools and reusable workflows inside the same controlled workbench. Whether a particular deployment is HIPAA compliant depends on the complete technical and administrative setup, including every service the agent can reach.
The source files and durable work stay in the local workbench. When a task needs AI inference, the approved context for that step uses your organization’s configured Azure OpenAI deployment. Boxwood does not describe this as zero network egress.
Examples include billing reconciliation, underpayment review, denial follow-up preparation, insurance-verification work, patient-record paperwork, policy research, reporting, spreadsheet work, and custom internal tools. The first pilot should start with a job the team already understands and can verify.
See the deployment
We will show how Boxwood handles the work, where the information goes, and which controls your organization still needs around it.