Skip to main content

Guardrails for AI input/output validation in healthcare, with DICOM support

Project description

Healthcare AI Guardrails

PyPI Python Versions CI License Typed

Lightweight validation guardrails for AI model inputs/outputs in healthcare workflows, with first-class DICOM support.

Features

  • Declarative YAML spec for checks on input and output data
  • Built-in validators: numeric ranges, choices, required fields
  • Specific DICOM validators: patient age, modality, patient sex, patient position, slice thickness, pixel spacing, image orientation, SOP Class UID, BodyPartExamined, PhotometricInterpretation, pixel intensity range, KVP, X-Ray Tube Current, Exposure Time, Protocol Name, and RT Structure Set ROI presence.
  • Generic DICOM validators: check if a tag's value is in a list, check a tag's value representation (VR), and check if a tag's numeric value is within a range.
  • Output structure validation via JSON Schema
  • Simple Python API and CLI (hc-guardrails)
  • HL7 v2 support: basic field, value-in-list, regex, and numeric range checks via simple path syntax (e.g., PID-5.1)
  • HL7 v3 (XML) support: XPath-based validators for exists, value-in-list, regex, and numeric range with namespace support

Install (users)

Install from PyPI - https://pypi.org/project/healthcare-ai-guardrails:

pip install healthcare-ai-guardrails

This installs the Python API and a CLI named hc-guardrails.

Quick CLI check:

hc-guardrails examples/spec.example.yaml examples/output.sample.json --mode output

If you’re validating DICOM, pydicom and numpy are already included as dependencies.

Install (contributors)

Dev install (includes test, lint tools, and pre-commit):

python -m venv .venv
source .venv/bin/activate
pip install -e .[dev]
pre-commit install

With uv (fast Python package manager):

curl -LsSf https://astral.sh/uv/install.sh | sh
uv venv
source .venv/bin/activate
uv pip install -e .[dev]
pre-commit install

See CONTRIBUTING.md for full contributor guidelines.

Quick start

Spec (examples/spec.example.yaml):

  • Input: verify DICOM patient age in [18, 90], modality in {CT, MR}, patient sex in {M,F,O}, slice thickness/pixel spacing ranges, and sane image orientation
  • Output: ensure probability ∈ [0, 1] and match a JSON Schema

Run on a DICOM file:

hc-guardrails examples/spec.example.yaml path/to/file.dcm --mode input

Run on a JSON output:

hc-guardrails examples/spec.example.yaml path/to/output.json --mode output

Autocontouring tutorial (CT + RTSTRUCT)

See examples/tutorials/ for a small end-to-end example that validates a CT input and an RT Structure Set output.

Run the Python walkthrough:

python examples/tutorials/autocontouring_tutorial.py

HL7 v2 (ADT/ORM/ORU etc.)

You can validate HL7 v2 messages using a lightweight path syntax: SEG-Field[rep].Comp.Sub (1-based indices). Examples:

  • MSH-9.1 → Message type (e.g., ADT)
  • PID-5.1 → Family name
  • PID-3[2].1 → Second repetition of PID-3, first component

Example spec: examples/hl7v2.example.yaml (preferred naming; examples/hl7.example.yaml retained for compatibility). Run against the provided sample message (or any .hl7 file starting with MSH):

hc-guardrails examples/hl7v2.example.yaml examples/hl7v2.sample.hl7 --mode input

HL7 v3 (XML/CDA/CCDA)

Validate HL7 v3 XML using XPath with namespaces.

Example spec: examples/hl7v3.example.yaml. Run against the provided sample XML (or any HL7 v3 XML document):

hc-guardrails examples/hl7v3.example.yaml examples/hl7v3.sample.xml --mode input

HL7 v2 vs FHIR

  • HL7 v2: Pipe-delimited messages (MSH/PID/OBR/OBX…). Use the HL7 v2 validators and path syntax above (SEG-Field[rep].Comp.Sub). The CLI auto-detects HL7 v2 when the file starts with MSH.
  • FHIR: JSON or NDJSON resources (Patient, Observation, Bundle, etc.). Treat these as JSON and validate using json_schema plus the generic validators (range, choice, required_fields). You can author a JSON Schema for your resource(s) and reference it directly in the YAML spec.

Example (FHIR Patient minimal schema):

output:
  - type: json_schema
    name: fhir_patient_minimal
    schema:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      required: ["resourceType", "id"]
      properties:
        resourceType:
          const: "Patient"

Or run the same checks via CLI using the YAML spec:

# Input (CT)
hc-guardrails examples/tutorials/autocontouring_tutorial.yaml path/to/ct.dcm --mode input

# Output (RTSTRUCT)
hc-guardrails examples/tutorials/autocontouring_tutorial.yaml path/to/rs.dcm --mode output

Python API

from healthcare_ai_guardrails import GuardrailRunner
from healthcare_ai_guardrails.validators.dicom import (
    DICOMPatientAgeCheck,
    DICOMModalityCheck,
    DICOMPatientSexCheck,
    DICOMPatientPositionCheck,
    DICOMSliceThicknessCheck,
    DICOMPixelSpacingCheck,
    DICOMImageOrientationCheck,
    DICOMKVPCheck,
    DICOMTubeCurrentCheck,
    DICOMExposureTimeCheck,
    DICOMProtocolNameCheck,
    DICOMRTStructureCheck,
)
from healthcare_ai_guardrails.validators.generic_dicom import (
    DICOMGenericNumericRangeCheck,
    DICOMGenericValueInListCheck,
    DICOMGenericTagTypeCheck,
)
import pydicom

runner = GuardrailRunner(
    [
        # Specific Validators
        DICOMPatientAgeCheck(min_years=18, max_years=90),
        DICOMModalityCheck(allowed_modalities=["CT", "MR"]),
        DICOMPatientSexCheck(allowed=["M", "F", "O"]),
        DICOMPatientPositionCheck(allowed=["HFS", "FFP", "FFS"]),
        DICOMSliceThicknessCheck(min_mm=0.5, max_mm=5),
        DICOMPixelSpacingCheck(min_mm=0.2, max_mm=2.0),
        DICOMImageOrientationCheck(tolerance=1e-3),
        DICOMKVPCheck(min_kvp=80, max_kvp=140),
        DICOMTubeCurrentCheck(min_ma=100, max_ma=500),
        DICOMExposureTimeCheck(min_ms=50, max_ms=200),
        DICOMProtocolNameCheck(allowed=["Axial Brain", "Sagittal Spine"]),
        DICOMRTStructureCheck(required_rois=["Heart", "Lungs"]),
        # Generic Validators
        DICOMGenericValueInListCheck(
            tag="Manufacturer", allowed_values=["SIEMENS", "GE"]
        ),
        DICOMGenericTagTypeCheck(tag="PatientName", expected_vr="PN"),
        DICOMGenericNumericRangeCheck(tag="BeamNumber", min_val=1, max_val=10),
    ]
)

ds = pydicom.dcmread("/path/to/file.dcm")
results = runner.run(ds)
for r in results:
    print(r.name, r.passed, r.message)

YAML Spec schema

Specific DICOM validators:

  • dicom_patient_age_rangemin_years, max_years, inclusive (default: true)
  • dicom_modality_allowedallowed_modalities: ["CT", "MR", ...]
  • dicom_patient_sex_allowedallowed: ["M", "F", "O"]
  • dicom_patient_position_allowedallowed: ["HFS", "FFP", "FFS"]
  • dicom_slice_thickness_rangemin_mm, max_mm, inclusive
  • dicom_pixel_spacing_rangemin_mm, max_mm, inclusive
  • dicom_image_orientation_sanetolerance (default: 1e-3)
  • dicom_kvp_rangemin_kvp, max_kvp, inclusive
  • dicom_tube_current_rangemin_ma, max_ma, inclusive
  • dicom_exposure_time_rangemin_ms, max_ms, inclusive
  • dicom_protocol_name_allowedallowed: ["Axial Brain", ...]
  • dicom_rt_structure_presentrequired_rois: ["Heart", ...]

Generic DICOM validators:

  • dicom_generic_numeric_rangetag, unit, min_val, max_val, inclusive
  • dicom_generic_value_in_listtag, allowed_values: [...]
  • dicom_generic_tag_type_checktag, expected_vr

Other generic validators:

  • rangepath: [..], min, max, inclusive
  • choicepath: [..], allowed: [...], case_insensitive
  • required_fieldspaths: [[..], [..]]

Output validators:

  • json_schemaschema: {..} (JSON Schema Draft 2020-12 compatible via jsonschema)
  • All generic validators above

Example output schema:

output:
  - type: json_schema
    name: output_schema
    schema:
      type: object
      required: ["probability", "label"]
      properties:
        probability:
          type: number
          minimum: 0
          maximum: 1
        label:
          type: string

Development

Supported Python: 3.9–3.13 (tested in CI on Linux; library is pure Python and should work across platforms).

Run tests locally:

pytest -q

With uv:

uv run pytest -q

Lint/type-check (optional suggestions):

pip install ruff mypy
ruff check .
mypy src

Code style:

pip install black
black .

With uv:

uv pip install black
uv run black .

Notes

  • DICOM tags used include: PatientAge, PatientBirthDate, StudyDate, SeriesDate, ContentDate, Modality, PatientSex, PatientPosition, SliceThickness, PixelSpacing, ImageOrientationPatient, KVP, XRayTubeCurrent, ExposureTime, ProtocolName, SOPClassUID, StructureSetROISequence.
  • Age parsing supports Y/M/W/D suffixes (per DICOM), falls back to birthdate computation.
  • Validators never raise; failures are returned as ValidationResult and can be surfaced as warnings or errors.

Contributing

PRs welcome! See CONTRIBUTING.md for setup instructions, how to add validators, and the PR checklist.

To create DICOMs in tests, use create_test_dicom from healthcare_ai_guardrails.testing.dicom_factory.

Releases and changelog

Maintainers (publishing):

  • Create a GitHub Release on the main branch. The workflow runs tests across Python 3.9–3.13, builds the sdist and universal wheel, and publishes to PyPI.
  • Ensure the repository has PYPI_API_TOKEN set in Secrets.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

healthcare_ai_guardrails-0.4.0.tar.gz (25.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

healthcare_ai_guardrails-0.4.0-py3-none-any.whl (24.9 kB view details)

Uploaded Python 3

File details

Details for the file healthcare_ai_guardrails-0.4.0.tar.gz.

File metadata

  • Download URL: healthcare_ai_guardrails-0.4.0.tar.gz
  • Upload date:
  • Size: 25.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for healthcare_ai_guardrails-0.4.0.tar.gz
Algorithm Hash digest
SHA256 5177239ef4262a649791b1d376303b320e7b453e0b124b651bf5ac8ec8aaa0fc
MD5 bf4aee0d02f557906483dc859dc4459a
BLAKE2b-256 17d590836911aded7a24a0f96ae75a7b0075d3acddaf6b507d84469fd6c4d098

See more details on using hashes here.

Provenance

The following attestation bundles were made for healthcare_ai_guardrails-0.4.0.tar.gz:

Publisher: release.yml on SamPIngram/healthcare-ai-guardrails

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file healthcare_ai_guardrails-0.4.0-py3-none-any.whl.

File metadata

File hashes

Hashes for healthcare_ai_guardrails-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e0144afcf171a7193adc93e818aeddf4e01baeb08089de8a3ae325677a7b1180
MD5 1bfdb3ee411138196a3cf871b2456f18
BLAKE2b-256 e92f8a07bc9e321608d2470db6f006d5431c2ff54b53077d66d71aad9da5b08a

See more details on using hashes here.

Provenance

The following attestation bundles were made for healthcare_ai_guardrails-0.4.0-py3-none-any.whl:

Publisher: release.yml on SamPIngram/healthcare-ai-guardrails

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page