How does enforcing row-level security on RAG retrieval satisfy HIPAA requirements?

Kastra enforces enforcing row-level security on RAG retrieval at the moment of execution and writes a signed evidence record for every retrieval. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to HIPAA, HITRUST, GDPR, 21 CFR Part 11 control families.