A health system that runs Miso gives an approved vendor an endpoint. The vendor's application uses the models and providers the system has already approved, under the system's agreements. The vendor never holds the system's provider credentials, and its model is pinned to the version it validated.
Miso is OpenAI-compatible. Name the route you're registered for and, where the policy requires it, the patient the request is about. The rest of your integration stays as it is.
Its BAAs with Anthropic, Azure, and Bedrock cover your traffic through the gateway. You negotiate none of them.
The model-and-data section of the questionnaire becomes a registry entry: your name, your routes, your purpose, your pinned model. Diligence on your application is still the system's to do.
Human review, disclosure, subject identification: what's expected comes back with each call.
The pages of the monthly report that cover your traffic are sent to you, for your auditors and your other customers.
When the system approves a new provider or version, it can offer you the move. You agree before your pin changes.
Model selection belongs to the system's own teams. Your route runs on the version you validated.