QuestionQ38

AI Safety, Security, and Governance

A medical device company wants to provide an AI assistant with reports of medical procedures that used the company’s devices. To safeguard patient privacy, the AI assistant must reveal patient personally identifiable information (PII) only to surgeons. For engineers, the AI assistant must redact PII. The AI assistant must reference only medical reports that are less than 3 years old.

The company stores reports in an Amazon S3 bucket immediately after each report is published. The company has already configured an Amazon Bedrock knowledge base. The AI assistant uses Amazon Cognito for user authentication.

Which solution meets these requirements?

Explanation

Amazon Bedrock Guardrails sensitive-information filters can anonymize PII in model responses. Applying the guardrail appropriate to the authenticated Cognito group allows PII to remain available to surgeons while masking it for engineers. An S3 Lifecycle expiration rule removes reports older than three years, and scheduled daily synchronization updates the Amazon Bedrock knowledge base for S3 additions, changes, and deletions, so expired reports are no longer eligible for retrieval.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!