Big things are coming from Synapse HealthTech! We’re thrilled to announce the upcoming launch of the Synapse HealthTech Marketplace — a first-of-its-kind, AI-powered ecosystem designed to transform how healthcare data drives innovation.
"We'll self-host, so none of this applies."
Self-hosting answers: where does the data live.
Regulators are asking: who did what, to which record, under what authority, and can you show me.
Different question. Hosting doesn't answer it.
Best question from today’s teardown, from a CISO:
“If de-identification happens at your layer, what stops your layer becoming the breach?”
Honest answer: Nothing structurally.
A control plane concentrates risk by design.
Concentrated + hardened beats distributed + unknown.
The pattern I keep hitting:
Nobody has a model problem.
Everybody has a permission problem solved four separate times, in four separate features, and the fifth review starts from zero.
"We tested it thoroughly" is not evidence.
It's a character reference.
An auditor wants six fields per inference: model version, what was masked, which policy allowed it, who initiated it, what came back, immutable timestamp.
Most teams can produce three.
423 to 57.
That's how the European Parliament voted in June to delay the AI Act's high-risk obligations.
Every health-tech team read it as 16 free months.
They misread it.
And when the new rule lands:
Effective 60 days after publication.
Most provisions due 180 days after that.
240 days, total.
You are not building a PHI-safe AI architecture in 240 days if you start when the clock starts.
Two deferrals. Two biggest healthcare AI markets.
Governance programmes standing down in both.
Deferred / Deleted.
Full three-market picture (incl. UAE, where nothing was deferred): [ogletree.com/insights-resour…]