Projects

Open source infrastructure for behavioral health systems. All published under the bh-healthcare organization. Apache 2.0.

bh-audit-schema

GitHub Audit Event Standard - v2.0

A canonical, versioned audit event standard for behavioral healthcare systems. Defines the structure of an audit event as JSON Schema, with compliance mappings to the HIPAA Security Rule, SOC 2 Trust Services Criteria, 42 CFR Part 2, and, for the agent controls added in v2.0, NIST AI RMF and ISO/IEC 42001.

v2.0 splits the single actor field into three attribution roles, authenticating, acting, and authorizing, and requires a delegation object for agent-mediated actions, so an AI agent working under a clinician's credentials can be audited truthfully. Conditional validation rejects an unattributed agent action by construction, and a new OVERRIDE action records a human interrupting an agent session. Ships with a FHIR R5 AuditEvent profile and a reference translator, checked in CI against a corpus of 7 positive and 13 negative examples. v1.1 remains available for producers that have not migrated.

RFC-0003, attribution assurance. Published 23 August 2026. Defines an attribution object carrying an assurance level of verified, bound, asserted, or unattributed, alongside an open method string, with four conditional validation rules. Public comment closes 6 September 2026. Targets v2.1.

bh-fastapi-audit

PyPI FastAPI Audit Middleware - v1.1.1

Pure ASGI middleware for emitting PHI-safe audit events from FastAPI applications. Non-blocking async emission, runtime schema validation with three failure modes, configurable DENIED outcome tracking with custom denial callbacks, schema version negotiation for gradual migration, and pluggable sinks.

Later releases added tamper-evident trails via SHA-256 chain hashing, a bh-audit verify CLI and programmatic chain verifier, a DynamoDB sink with three secondary indexes for compliance queries, a JSONL ledger sink, and opt-in privacy-first telemetry. Emits bh-audit-schema v1.1; for v2.0 agent attribution today, use bh-audit-logger.

bh-audit-logger

PyPI Generic Audit Logger - v2.0.0

Framework-agnostic audit event emitter for any Python application. Built for Lambdas, workers, data pipelines, CLI tools, and anything that isn't FastAPI but still needs compliant audit logging. Zero required dependencies in core, with optional extras for a DynamoDB sink, the verify CLI, and runtime schema validation.

v2.0 makes bh-audit-schema v2.0 the default emission target, which makes this the reference emitter for agent attribution, delegation, and OVERRIDE events.

bh-mcp-attribution

GitHub Prototype MCP Attribution Enforcement - v0.1.0.dev0

Attribution-enforcing audit emission for Model Context Protocol servers and gateways. Resolves the authenticating, acting, and authorizing identities behind a tool call, refuses to emit an event that cannot name an authorizing human, and writes bh-audit-schema v2.0 events. This is the reference implementation of the enforced emission tier that bh-audit-schema RFC 0001 defined and left unbuilt.

Context resolution has four fixed precedence levels bound to an assurance level that is not configurable: a token on the session is verified, an operator-configured static binding is bound, a per-call _meta block is asserted, and nothing is unattributed and denies the call. Recording the assurance alongside the identity is what keeps the enforced-tier claim accurate, since otherwise a deployment resolving every call at asserted emits events indistinguishable from verified ones. The local durable write fails closed before the call; the remote ship to a sink fails open and alarms.

Nothing is released and no live agent traffic has been audited. The design is under RFC review until 2026-09-06 and five of six decisions are open. The repository became public and RFC-0002 was published on 23 August 2026, both ahead of the implementation, because keeping the work private until release would have collapsed the design into a single timestamp. The schema dependency is pinned exactly to 2.0.0 and moves to 2.1.0 at v0.1.0.

bh-sentinel

GitHub Pre-release Clinical Safety Signal Detection - core v0.1.2 / ml v0.2.3

Multi-layer NLP pipeline for detecting clinical safety signals in unstructured behavioral health text. Pattern matching with negation and temporal detection, sentence-level zero-shot transformer inference, NRC emotion lexicon, and configurable rules engine. 40 clinical flags across 6 domains mapped to C-SSRS. Every flag includes evidence spans, basis descriptions, and confidence scores so clinicians can independently review. Designed for zero PHI egress and FDA Non-Device CDS compliance.

Two independently installable packages: bh-sentinel-core (deterministic, no ML dependencies) and bh-sentinel-ml (transformer layer). The ML layer runs a pinned INT8 ONNX build of RoBERTa-large-MNLI in process and labels each flag as pattern-only, transformer-only, or corroborated across both. Text in, flags out, clinician decides.

Not yet production ready. Clinical validation and calibration against labeled clinical data, plus a reference AWS deployment, are v0.3 deliverables.