A healthcare company is deploying an LLM-based patient triage assistant using NVIDIA NIM microservices on-premises. To comply with HIPAA, they need to ensure that no protected health information (PHI) is transmitted to external services. Which deployment approach best meets this requirement?
Hosting the NIM microservice locally keeps all data within the company's network, preventing PHI from leaving the premises. Using local model weights ensures no external API calls are made for inference, thereby complying with HIPAA's data residency and privacy requirements.
Why this answer
The correct approach is to host the NIM microservice locally and use local model weights. This ensures that all data, including PHI, remains within the company's secure network and is never transmitted to external services, satisfying HIPAA's strict privacy and data residency requirements.
Exam trap
The trap here is assuming that a business associate agreement or encryption alone is sufficient to comply with HIPAA when the requirement explicitly forbids any external transmission of PHI.