HIPAA compliant LLM gateway · one API, one BAA
Garrison is the LLM gateway for healthcare teams that want the newest models without a contract process per provider. One-click BAAs with every AI model company, tokens at list price. When a provider covers a new model, so do we.
Stop managing contracts. Start shipping.
Built for teams that move
Closed labs, the three clouds, the open-weight hosts, and the new labs, behind one agreement with Garrison.
Choose the plan where nothing is kept. Prompts and responses live in memory for the call and nowhere else.
Names, dates, numbers and the rest of the Safe Harbor list are stripped from prompts and responses before anything is kept. The clause that allows it is explicit in your BAA.
Caller, model, tokens, cost and time on every request, kept six years to match the Security Rule's documentation retention period. Exportable for your auditor.
# the whole migration
client = OpenAI(
base_url="https://api.garrisonhealthsystems.com/v1",
api_key=os.environ["GARRISON_API_KEY"],
)
client.chat.completions.create(
model="anthropic/claude", # or any provider/model
messages=[...],
)
provider/model. Switch by changing the string.What each provider asks of you today
The left column is each provider's own published route. The right column is yours.
| Provider | Their route to a BAA | Your route |
|---|---|---|
| OpenAI | Email sales. Zero Data Retention or Modified Abuse Monitoring on the account. Covers listed endpoints only. | covered |
| Anthropic | Contact sales. A dedicated organization with HIPAA controls. One organization per agreement. 30-day retention. | covered |
| Google Gemini | Through a Vertex AI account, under the cloud's BAA, for the models the cloud lists as eligible. | covered |
| Llama, Qwen, DeepSeek | A host's enterprise tier (Together, Fireworks, Baseten, Groq), each with its own agreement and minimum. | covered |
| Kimi K3, Jev | No BAA published. No route at any price. | covered |
| Next month's lab | Unknown. | we sign with them, you do not |
Pricing
Two plans. The difference is retention. The pricing page has the detail.
Standard retention. Identifiers on the HIPAA Safe Harbor list are removed, then usage data is kept as your BAA permits. The de-identification clause is explicit in the agreement.
Nothing is kept. Prompts and responses exist only in memory for the length of the call. The plan most enterprise security reviews ask for.
FAQ
Every request you send through Garrison, to every provider on the list. Garrison is your business associate under HIPAA. Your security review sees one sub-processor list, maintained by us.
When the provider covers it, we do. On AWS, Azure and Google that is the day a model goes generally available. On the OpenAI and Anthropic APIs it is when the model is on their covered list. We never route patient data to preview or beta models.
Identifiers on the HIPAA Safe Harbor list: names, dates finer than year, ages over 89, contact details, record and account numbers, addresses, and the rest of the eighteen. The clause that lets Garrison do this is written into your BAA.
Retention. On the standard plan, de-identified usage data is retained under the terms of your BAA. On zero retention, nothing is kept. Token prices are the same on both.
No. You pay the provider's published price on every token, on both plans.
Start
Tell us where to send the agreement. A key follows the signature.