Boxwood installation

Install the app. Connect the Azure account your organization controls.

Boxwood runs on each user's computer. Your organization creates the Azure resource, owns the API key, and enters it directly into Boxwood. Ironwood does not need to receive that key.

Your computer will show a security warning.

Boxwood's installers are not code-signed yet. Windows may say it protected your PC or does not recognize the publisher. macOS may say it cannot verify the developer or check the app for malicious software. This is expected for the installer from our private download page. The exact steps for continuing safely are below.

Walkthrough video

The complete setup in under two minutes.

The video gives you the route. The written instructions below contain the exact checks and compliance notes.

Before the call

Decide who owns Azure for the organization. That person should control billing, the resource, and key rotation.

Azure owner

Creates the subscription and resource, deploys the models, records the BAA evidence, and distributes the credential inside the organization.

Boxwood user

Installs the app and enters the Azure resource name and API key on their own computer.

If that is not you

Ask the Azure owner for the resource name and Key 1 or Key 2 through the organization's approved password manager. Do not send the key to Ironwood.

Part 1

Install Boxwood

Mac

  1. Open the private download page, sign in with your approved email, and choose Apple Silicon for an M-series Mac or Intel for an older Intel Mac.
  2. Open the DMG and drag Boxwood into Applications.
  3. In Applications, right-click Boxwood and choose Open. Confirm Open when macOS says the developer cannot be verified.
  4. If macOS still blocks it, open System Settings → Privacy & Security and choose Open Anyway for Boxwood.
  5. Launch Boxwood. Leave the first-run screen open while the Azure owner finishes Part 2.

Windows

  1. If an older Boxwood or T3 build is installed, remove it first: Settings → Apps → Installed apps → Boxwood → Uninstall.
  2. Open the private download page, sign in with your approved email, and download the latest Windows version.
  3. Run the setup EXE. When Microsoft Defender SmartScreen says it protected your PC, choose More info → Run anyway.
  4. Windows may also say the publisher is unknown. Continue only if you downloaded the file directly from the private Boxwood page.
  5. Finish the installer and open Boxwood from the Start menu. Defender may make this take several minutes.
  6. Leave the first-run screen open while the Azure owner finishes Part 2.

You should have: Boxwood installed and the first-run form asking for a local username, password, Azure resource name, and Azure API key.

Part 2

Create the organization's Azure resource

Do this while signed in to the organization's Azure account. The organization—not Ironwood—owns the subscription, resource, billing relationship, and credential.

01

Confirm the Azure customer and subscription

Open portal.azure.com. Confirm the subscription is active and the legal customer is the covered entity, business associate, or other organization that should own this workload.

Use an organization account when possible. Record the agreement type and retain a redacted billing or subscription screenshot for the compliance file.

02

Create Azure OpenAI

In the Azure portal, choose Create a resource and search for Azure OpenAI. Select Create.

Choose the subscription, create or select a resource group, choose a region where the required models are generally available, enter a unique resource name, and use the Standard S0 tier.

The resource name is the short name you entered here. Boxwood does not want the full endpoint URL.

03

Deploy the models with these exact names

Deployment nameUsed for
gpt-5.6-solDefault
gpt-5.6-terraLower-cost option
gpt-5.6-lunaLowest-cost option

Use generally available model versions and a deployment geography the organization has approved. Boxwood refers to the deployment name, so the names must match exactly.

For Standard deployments, choose the organization's preferred model-version upgrade policy. “Once the current version expires” avoids an early change while still preventing a retired version from simply stopping. This can update a compatible version inside a deployment; it does not create a new model family such as GPT-6.

04

Copy the resource name and key

Open the Azure OpenAI resource, then Resource Management → Keys and Endpoint. Copy the resource name and either Key 1 or Key 2.

Put the key into the organization's approved password manager. Do not paste it into email, ordinary chat, a shared document, or a support message to Ironwood.

05

Set a budget alert

In Azure Cost Management, create a monthly budget for the Boxwood resource group and send actual-cost and forecast alerts to the Azure owner. A budget warns the organization; it does not automatically stop usage.

You should have: One organization-owned Azure OpenAI resource, three correctly named deployments, the short resource name, one API key, and a budget alert.

When Boxwood moves to a new model family:the organization's Azure owner will normally deploy the new models in this same resource. A Boxwood update can switch the app to those deployments, but the API key currently entered in Boxwood cannot create Azure deployments. Ironwood will publish the exact names and availability requirements before the app changes its default.

Microsoft references: create an Azure OpenAI resource and deploy a model, model upgrade policies, and Azure budgets.

Part 3

Record the BAA and HIPAA setup evidence

Microsoft states that its HIPAA BAA is incorporated through the Product Terms and Data Protection Addendum for qualifying covered entities and business associates using in-scope services. There is ordinarily no separate Azure BAA to sign. That does not make the workload compliant by itself.

01

Confirm the contract path

Record the legal Azure customer, active agreement, subscription, and confirmation that the organization has not opted out of the HIPAA BAA.

02

Keep the current Microsoft documents

Download the current BAA and Azure Compliance Offerings or service-scope evidence from the Microsoft Service Trust Portal. Keep the version and review date.

03

Record the deployed service

Save redacted evidence of the resource region, Azure OpenAI service, model versions, deployment types, and general-availability status. Do not include keys.

04

Make the abuse-monitoring decision

Default Azure abuse monitoring can store flagged content for possible human review. Modified abuse monitoring is a separate approval. Before production PHI, the organization should document that it accepts the default posture or obtain modified monitoring or written Microsoft/legal confirmation.

05

Keep public search free of PHI

Public web search is not a PHI destination. Boxwood applies a private-data check before search, but users should still keep patient, client, account, and private case identifiers out of search prompts.

Do not begin production PHI use from this page alone. The organization remains responsible for its risk analysis, access controls, minimum-necessary rules, incident response, and legal/compliance approval.

Microsoft references: Azure and HIPAA, data and privacy, and abuse monitoring. Last checked July 27, 2026.

Part 4

Finish Boxwood on each computer

01

Create the local Boxwood account

Choose a username and a unique password of at least eight characters. This account belongs to this computer.

02

Enter the Azure connection

Paste the short Azure resource name and Key 1 or Key 2 into the first-run form. Boxwood stores the credential on that computer; Ironwood does not receive it.

03

Choose the default model

In Settings, keep Sol as the default or choose Terra or Luna to lower usage costs. Each user can see their estimated monthly usage there.

04

Run a synthetic test

Before using confidential data, ask Boxwood to create a folder named boxwood-setup-test and a file named ready.txt containing “Boxwood is connected.” Confirm the file exists.

05

Repeat for the team

Install Boxwood on each licensed user's computer. For the early rollout, the Azure owner distributes the same Azure resource name and key through the organization's password manager. If a user leaves or the key is exposed, rotate the Azure key and replace it in Boxwood Settings on every computer.

You should have: Boxwood running on each computer, connected directly to the organization's Azure resource, and verified with synthetic data.

Stuck on a step?

Send the step number and the exact error. Do not send an Azure key, password, patient record, client file, or screenshot containing confidential data.

Ask an installation question