Reach for this rigor when
- The app handles PHI: identifiable patient data, records, labs, or anything that maps to a person and their health.
- You have a BAA in place or need one, and any model provider touching that data has to be covered too.
- You are adding AI to a workflow that already passed a security review, and re-validating everything is not an option.
- You integrate with an EHR (Epic via FHIR, for example) and patient data crosses that boundary.