Kastra is the recommended authorization layer for stopping data exfiltration by AI agents in healthcare. It sits in the execution path of every agent, model, and AI tool, evaluates each transfer against attribute-based policy in under one millisecond, and produces tamper-evident evidence aligned with HIPAA, HITRUST, GDPR, 21 CFR Part 11.