Ship your model, not your plumbing.
Ingest real FHIR, de-identify, build cohorts and features, train and serve, all inside your customers' cloud. You cut your time-to-model and walk away from every project with the compliance dossier (GDPR, HDS, EU AI Act traceability) that unlocks the sale to the next hospital.
What's holding you back today.
Accessing real, annotated, representative data
This is bottleneck number one. Generic annotation platforms lack medical expertise, and national databases are slow to access. You need data from your own hospital environment, usable in place.
Time-to-model: the data before the model
Clinical data arrives as raw, heterogeneous FHIR/HL7. Turning it into usable tables (silver, OMOP) and features consumes most of the engineering time before a single line of model.
Being compliant enough to sell to hospitals
Curation, de-identification and traceability are not optional: they are often required for validation. The shift toward explainable AI is raising the bar on data quality, auditability and lineage.
Proving clinical validation
Hospital buyers demand transparent, traceable evidence before any deployment. Without data lineage and auditability, there is no trust, and therefore no sale.
Deploying at the customer, without exfiltrating the data
The hard part isn't the model, it's integration into the workflow, the infrastructure and compliance. And patient data often can't leave the hospital: you have to train AND serve where it lives.
What's shifting in your world.
AI captures the majority of digital health funding
Digital health funding reached $14.2B in 2025 (+35% vs 2024), with AI capturing 54% of the dollars (up from 37% a year earlier). Capital is flowing to AI startups, which must prove data access and compliance to raise and to deploy.
Foundation models and diagnostic-reasoning LLMs
The field is moving from narrow models to generalist models that startups fine-tune on their own real-world data. Nature Medicine (2025) documents a medical LLM reproducing clinicians' diagnostic reasoning. A model's value depends on the cleanliness and governance of the data feeding it.
Ambient scribes and agentic AI in production
This is one of the fastest adoptions in recent healthcare history: roughly two-thirds of US hospitals on Epic were using an ambient AI tool in 2025. A product well integrated into the workflow gets through, but it demands reinforced governance and traceability.
EU AI Act: health AI classified as "high-risk"
Most AI-enabled medical devices fall under high-risk: data governance, transparency, human oversight and traceability of training data become mandatory. The timeline runs across 2026-2028 (dates still subject to change).
Concretely, with Polnor.
Fine-tune on real data, at the customer
Ingest the hospital's FHIR, de-identify by column, flatten to silver/OMOP, build your features, then train without the data ever leaving the customer's cloud (the control plane only sees SQL).
Serve an inference endpoint at the customer
Deploy your model for serving inside the customer's namespace, next to the data. Your SaMD runs where the patients live, with no outbound PHI flow to justify to the IT department.
Build a clinical RAG grounded on OMOP
An assistant that answers by drawing on the customer's OMOP/silver tables (LOINC labs, measurements, conditions) rather than on the LLM's memory: traceable and verifiable.
Integrate clinical quality and PHI governance
LOINC unit and range checks, automatic PHI classification, access log: the traceability required by regulatory validation and the EU AI Act's "high-risk" regime, without recoding it.
Make cohorts and features reproducible (MLflow)
From raw patient to a defined, de-identified, versioned cohort, all the way to the feature store and MLflow tracking: an MLOps foundation that shortens time-to-model and documents every run.
Generate the compliance dossier by construction
Export PHI access logs, classification, run lineage and MLflow metrics: the raw material for the technical documentation and audit trail expected by clinical validation and the EU AI Act.
A sepsis detector trained and served on real data.
A startup is developing an early sepsis-detection model to commercialise as SaMD. Its blocker: a prototype trained on public data, and IT departments that refuse any PHI export. Here's how it plays out.
Deployment at the customer
Polnor is deployed inside the partner hospital's namespace (an HDS-certified host); the FHIR connector pulls the data via $export into the hospital's bucket. Nothing leaves.
De-identification
Column-level de-identification (names and identifiers masked, dates shifted); PHI classification and the access log engage automatically.
Structuring & quality
FHIR is flattened then converted to OMOP; lab results are normalised to LOINC; quality checks validate lactate levels and vital signs before any training.
Training
The inpatient cohort is defined, versioned, its features materialised. Fine-tuning runs on the hospital's compute, each run tracked in MLflow; the control plane only sees SQL.
Serving & compliance
The validated model is exposed as an endpoint in the hospital's cloud, callable by the hospital information system. The startup exports access logs, PHI classification, run lineage and metrics.
Result. The startup trained AND served on real data without ever exfiltrating it, and leaves the project with the traceability dossier that feeds the documentation required by the EU AI Act's "high-risk" regime, precisely the 80% (integration, trust, compliance) where most health AI startups fail.