This article presents a seven-layer reference architecture for trusted-source generative artificial intelligence in healthcare information services, derived from fourteen years of enterprise data-platform engineering practice including six years building and operating generative AI platforms serving healthcare professionals globally. The work advances a specific argument: the principal limit on trustworthiness in healthcare-domain generative AI is no longer foundation-model capability but data-platform architecture, specifically the architecture governing source curation, retrieval, citation enforcement, and content versioning. The seven layers address source curation and authentication, content ingestion and versioning, retrieval-augmented generation pipeline, healthcare-professional identity and audience tailoring, generation and citation enforcement, audit and quality surveillance, and practitioner feedback. The article is grounded in production engineering evidence, including an independent peer-reviewed evaluation published in Circulation (American Heart Association, 2024) demonstrating a 19.3 percentage-point accuracy improvement attributable entirely to platform-layer interventions. Three production failure patterns and a five-level organizational maturity model are presented. Applicable regulatory frameworks addressed include HIPAA Security Rule, ONC information-blocking rules, NIST AI Risk Management Framework (AI RMF 1.0), and the EU Artificial Intelligence Act (Regulation 2024/1689).
Anil Kumar Kandalam (2026) studied this question.