It never sees your raw schema
The model is shown a curated set of business views with clean names and written definitions — not your hospital tables, and not patient identity columns for users who are not cleared.
Two questions decide whether a hospital IT head says yes: can this slow down or corrupt our clinical system, and who can see patient data. Both are answered below without hedging.
The login Prism uses on your hospital system has read rights and nothing more. It is not technically capable of writing to a clinical system. Your DBA creates it and can verify the grant.
Analysis never runs against the database your wards and billing counters depend on. Month-end reporting cannot slow down a discharge.
A department head sees their department, a unit head their unit. The restriction is applied by the platform to every query, including queries produced by the Ask box.
Names and contact numbers are hidden unless a user is specifically cleared, and each time they are viewed it is recorded. Most management dashboards work on aggregates and never need identity at all.
Hospital database passwords are encrypted with a key held outside the database and are never displayed again after entry. A database dump alone does not yield access to your system.
Every login, every report run, every question asked and the exact query it produced — recorded with the user, the time and the result count. When an auditor asks who saw what, there is an answer rather than an assurance.
Twenty years, bootstrapped, still owned by the people who built it. 1,000+ hospitals across India and 12+ countries.
Worth being precise about, because most vendors are vague here.
The model is shown a curated set of business views with clean names and written definitions — not your hospital tables, and not patient identity columns for users who are not cleared.
Unit and department restrictions are applied by the platform after the query is generated. The model is never asked to add a filter, because anything that can be asked can also be persuaded.
The Ask box connects through a database account with read permission only. Even if every other safeguard failed, that permission holds.
The audit trail is a dashboard, not a table nobody opens.
Illustrative data shown.
One hospital, one month of your data, and the exception list from your own billing.