You've probably noticed the pattern by now. Your staff uses AI for drafts, summaries, research. It saves time. Then someone asks it a question that actually matters -- something involving a patient, a client file, a pending matter -- and the conversation stops cold. Either someone remembers the policy, or worse, no one does.
The wall isn't arbitrary. It's structural.
Why the obvious AI tools can't help with your real work
ChatGPT, Claude, Westlaw CoCounsel, UpToDate Expert AI -- these are all cloud products. When you send them a query, the text of that query, including anything you paste into it, travels to a data center operated by a third party. For general questions, that's fine. The moment a patient name, a medical record number, a client matter, or a privileged communication enters that conversation, you've moved regulated data outside your control.
Under HIPAA, that's a disclosure event unless you have a Business Associate Agreement in place and the vendor has been properly configured for your environment. Under attorney-client privilege, it's a potential waiver. Most practices and firms using these tools have not completed that review. OCR's December 2024 Security Rule update went further: AI systems now have to appear in your mandatory technology asset inventory. Shadow AI -- staff using consumer tools without IT's knowledge -- is an explicit enforcement category.
This isn't a compliance lecture. It's an explanation of why the tools that work for everything else genuinely cannot work for the queries that would help you most.
What "private AI" actually means
The phrase gets used loosely. What it means in practice: a language model running on hardware physically located at your site, processing your data without it ever leaving your network. Not a contractual promise that a cloud vendor won't misuse your data. Not an enterprise plan with a BAA that still routes your queries through AWS. Hardware, in the room, running locally.
That distinction matters because it's the only configuration where the compliance question is settled by physics rather than paperwork.
IT CloudLink builds and manages that system for healthcare, legal, and regulated businesses in the Los Angeles area and beyond. The model -- a 35-billion parameter reasoning system running on dedicated GPU hardware -- handles queries against your own documents: patient records, case files, prior matters, internal protocols. It can cross-reference clinical literature or case law, reason across multiple sources, and generate a documented reasoning chain. That chain is locally owned and producible if you ever need it for audit, malpractice defense, or regulatory review.
For general queries that don't touch sensitive data, the system routes to frontier models (Claude, ChatGPT) and logs what leaves. Staff uses one interface. You see everything.
The three things this solves that nothing else does
The tools your attorneys or physicians are already paying for -- Westlaw, LexisNexis, UpToDate -- are genuinely useful for what they do. They answer from their publishers' content. They don't have access to your files, your patient population history, or your prior matters. And they expose no programmatic interface that would let a private system query them on your behalf at SMB pricing. Their AI features are built for the platform, not for integration with your document corpus.
Private on-premises AI solves three things those tools cannot:
First, it works with your actual documents. A physician can ask a question that references this patient's history against current clinical literature. An attorney can ask how a prior matter's outcome bears on a current filing. Neither is possible with a tool that only knows what the publisher put in its database.
Second, it generates a documented record. Every query, every source consulted, every model response is logged locally with a timestamp and user attribution. You own that log. If a regulator or opposing counsel ever asks what AI was used and how, you have an answer.
Third, it closes the shadow AI boundary. Instead of hoping staff follows a policy they find inconvenient, you give them a fast, capable AI tool for sensitive work. The boundary is enforced by the system, not by willpower.
What this looks like for your organization
The service runs on appliance hardware IT CloudLink installs on-site. Tier 1 is built for a solo or small practice -- roughly 1 to 10 seats -- and is sized for up to about five people running queries at the same time. Tier 2 covers a mid-sized practice, roughly 11 to 25 seats, at up to about ten at once. Tier 3 is for larger or multi-site organizations, 25 seats and up, sized per location. Seat bands are indicative; exact sizing is scoped with you before anything is quoted. All three come under a managed service agreement -- IT CloudLink handles installation, maintenance, and monitoring. You don't manage the AI infrastructure. You use it.
There are two ways to structure that agreement. In Model A, IT CloudLink owns the appliance and operates it for you -- you're paying for the service, not the hardware. In Model B, you own the hardware outright and IT CloudLink runs it under contract. Either way, the minimum term is 12 months, and exact pricing is scoped to your practice before anything is quoted.
Support response times scale with tier as well. Standard support starts at next-business-day response for Tier 1, moving to same-day response for Tier 2 and Tier 3. Priority support cuts that down to four business hours for Tier 1, two hours for Tier 2, and one hour for Tier 3.* Hardware issues follow a similar pattern, though the specifics vary by tier. Tier 1 Priority ships a loaner unit and restores yours within two business days. Tier 2 Priority moves to next-business-day restoration. Tier 3 targets that same next-business-day window at its larger scale.
Year 1 includes an UpToDate Pro Plus group subscription for medical practices (up to five seats for Tier 1) at IT CloudLink's cost, bundled as part of the onboarding. The private stack handles what UpToDate cannot touch.
The conversation worth having
If you run a healthcare practice, law firm, financial services operation, or any regulated business in the Los Angeles area and beyond, the question isn't whether AI would help your work. You already know the answer to that. The question is whether you can use it on the work that actually matters -- and right now, for most practices, the answer is no.
That's a solvable problem.
Contact IT CloudLink to discuss your practice's setup.
*Response times apply during business hours. After hours, response defaults to the next business day. On-site redundant configurations can enable faster after-hours response -- including expedited overnight hardware replacement in Tier 3 (example: as fast as ~8hr) -- with exact terms scoped at the time of engagement.
For technical readers: the full architecture -- inference stack, API integrations, competitive gap analysis, and data flow -- is published as a reference document at rondthaler.dev.