Home / Projects / Private LLM (air-gapped)
Case study 05 · Air-gapped · HIPAA · On-prem

Private LLM (air-gapped)

On-network large language model with zero external egress for PHI-adjacent work.

RoleBuilt and operated
PeriodFeb 2026 – present
Stack
LinuxDockerOllamaOpen-WebUI
Data handlingHIPAA · On-prem

Nothing leaves the network. That is the whole point.

Problem

Staff wanted LLM help with documents and code, but hospital policy forbids sending anything sensitive to public AI services.

Approach

Stood up a Linux server inside the network, containerised Ollama and Open-WebUI, and served open-weight models with no internet route. Documented the PHI boundary and who may use it for what.

Architecture

Docker Compose stack; model weights pulled once then locked; per-user auth in Open-WebUI; no outbound connectivity.

On-prem Linux host→Docker Compose→Ollama (models)→Open-WebUI (auth)→No egress

By the numbers

NoneEgress
Ollama + Open-WebUIStack
On-prem LinuxHosting

Outcome

Secure, self-hosted AI available to approved staff; foundation for later RAG work over internal documents.

What I would tell your team

Ask me how this maps onto your EHR, your interface engine and your security review. I can walk through the data flow, the failure modes we hit at go-live, and what I would do differently the second time.

Talk about a similar system
← PreviousAI Call Center
Next →FHIR Sepsis Alerts