Bedrock Guardrails Implementation for PHI / PII - Healthcare / FS / LS
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 3 captures on record
What the publisher says
As described on AWS Marketplace.
**Bedrock Guardrails out-of-box is not tuned for PHI / PII / NPI. Healthcare, life sciences, and financial services need industry-specific denied-topics taxonomies, custom PHI / PII blocklists, fairness filters, and jailbreak / prompt-injection defenses before production launch. Until now, no fixed-fee regulated-industry Bedrock Guardrails implementation SKU has existed on AWS Marketplace.**
Amazon Bedrock Guardrails is the policy-enforcement layer around Claude-powered agents operating on PHI, PII, NPI (GLBA), cardholder data (PCI DSS), and protected-class attributes. Guardrails ships with generic denied topics, content filters, PII redaction, word filters, and contextual grounding, but **none are tuned for regulated-industry contexts**. Healthcare needs medical-misinformation filters, self-diagnosis guardrails, unprescribed-medication denial, PHI-disclosure-prompt detection. Life sciences needs unapproved-indication filters, GxP deviation denial, adverse-event handling, controlled-substance advice blocks. Financial services needs unlicensed-investment-advice filters, fair-lending / disparate-impact detection, OFAC / PEP sanctions-adjacency, market-manipulation / insider-trading denial. All three need jailbreak + prompt-injection + indirect-PI defenses (OWASP Top 10 for LLM 2024/2025) tuned against adversarial corpora, not generic thresholds.
Show the rest of the publisher’s description (6 more lines)
Existing AWS Marketplace listings don't close this gap. **EnviroWay Advisory** is generalist; **AIM Consulting** is assessment-only; **DevIQ HIPAA Bedrock Review** is architecture review; **TCS 5A Framework** is methodology; **Data Reply / Altimetrik / CrowdStrike AI Red Team** are offensive testing, not defensive deployment. Off-Marketplace consulting (Slalom, Caylent, Rackspace, Deloitte) $75K–$250K custom-priced. Content-safety SaaS (Lakera Guard, Protect AI, Arthur AI) are $50K–$300K/yr subscriptions.
**Bedrock Guardrails configured + tuned.** Denied topics, **Healthcare** (medical misinformation, self-diagnosis, unprescribed-medication, PHI-disclosure prompts); **Life sciences** (unapproved indications, GxP deviations, adverse-event mishandling, controlled-substance advice); **FS** (unlicensed investment advice, fair-lending violations, OFAC/PEP, market manipulation, insider trading). Content filters tuned per industry. PII redaction (built-in + custom regex for SSN, MRN, policy/account numbers, credit cards). Word filters (clinical terminology, controlled vocabulary). Contextual grounding (RAG + relevance thresholds calibrated against test corpus). Sensitive-info filters (Comprehend Medical PHI entities; Macie PII at rest). Custom fairness filters (disparate-impact + proxy scanning). Jailbreak + PI defenses (input validation, output sanitization, indirect-PI scanning, tool-poisoning for MCP-wired agents). A/B testing harness (precision / recall / F1 / FPR). Red-team corpus (Enterprise), OWASP Top 10 for LLM.
**Reference architecture.** Guardrails per-agent around Bedrock Agents, Claude Agent SDK, MCP servers. Comprehend Medical for PHI; Macie for PII at rest. CloudTrail + Bedrock Model Invocation Logging capture every trigger + override. CloudWatch + QuickSight dashboards.
**Week-by-week.** W1 Scoping + baseline. W2 Denied topics + PII redaction (5/15/30 topics per tier). W3 Content filters + Comprehend Medical + Macie + contextual grounding + integration, Foundation closes. W4 Standard, jailbreak + PI tuning; fairness; A/B testing (45-day warranty). W5 Enterprise, custom PHI/PII blocklists; full fairness; red-team; SOC 2 + HIPAA + NIST AI RMF evidence (60-day hypercare).
**Three tiers.** Foundation $35K (3 wk; 1 industry; 5 denied-topics; 1 agent; 30-day warranty) for mid-sized regulated with single customer-facing agent. Standard $65K (4 wk; 2 industries; 15 denied-topics; jailbreak + PI tuning; fairness; A/B testing; **SOC 2 evidence**; 45-day warranty) for multi-agent / multi-industry. Enterprise $95K (5 wk; all 3 industries; 30 denied-topics; custom PHI/PII blocklists, ICD-10, drug names, sanctions lists, fair-lending proxies; full fairness; OWASP Top 10 red-team; **full SOC 2 + HIPAA + NIST AI RMF evidence**; 60-day hypercare) for large regulated, G-SIB banks, top-25 payers + pharmas. Optional Extra Denied-Topic Suite $15K each.
**Important disclosures.** Kriv does NOT develop Customer agents, Guardrails tune surrounding controls only. Does NOT operate Guardrails post-deployment (unless Managed Service retainer). Issues no SOC 2 / HIPAA / HITRUST / ISO certifications. No legal / regulatory / compliance advice. No 100% jailbreak / PI prevention guarantee, defense-in-depth, not absolute. No Bedrock Guardrails API stability guarantee. AWS + Anthropic + Bedrock + Guardrails per-text-unit consumption separate. Red-team scoped Enterprise only. No false-positive elimination guarantee. No HHS OCR / FTC / state-regulator outcome guarantee. Anthropic CPN membership does not constitute endorsement.
Highlights
Highlighted by the publisher on AWS Marketplace.
First regulated-industry Bedrock Guardrails implementation SKU on AWS Marketplace, healthcare + life sciences + FS. Industry-specific denied-topics taxonomies: healthcare (medical misinformation, self-diagnosis, unprescribed-medication, PHI-disclosure prompts); life sciences (unapproved indications, GxP deviations, adverse-event mishandling, controlled-substance advice); FS (unlicensed investment advice, fair-lending, OFAC/PEP, market manipulation, insider trading).
Denied-topics + custom PHI / PII blocklists (SSN, MRN, policy numbers, account numbers, credit cards, EINs) + word filters (clinical terminology, controlled vocabulary) + contextual grounding checks + sensitive-information filters via Amazon Comprehend Medical (PHI) + Amazon Macie (PII) + custom fairness filters (disparate-impact + protected-class proxy scanning) + jailbreak / prompt-injection defenses aligned to OWASP Top 10 for LLM Applications (2024/2025) + A/B testing harness.
A/B testing vs baseline (precision / recall / F1 / FPR reported); SOC 2 Type II Common Criteria + HIPAA §164.308 / §164.312 / §164.316 + NIST AI RMF evidence mapping per tier. Three tiers: $35K Foundation (3 weeks; 1 industry; 5 denied-topics; 1 agent); $65K Standard (4 weeks; 2 industries; 15 denied-topics; jailbreak + fairness; SOC 2 mapping); $95K Enterprise (5 weeks; all 3 industries; 30 denied-topics; red-team corpus; full SOC 2 + HIPAA + NIST AI RMF evidence; 60-day hypercare).
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

