HIPAA-Compliant AI
There is no such thing as a HIPAA-certified AI product. There is a way to deploy AI that satisfies your obligations as a covered entity, and there are several popular ways to get it wrong.
This is general information about the regulatory landscape, not legal advice. Your privacy officer and counsel own the determination for your organisation.
The core question
HIPAA does not prohibit AI. It governs disclosure of protected health information. Every practical question follows from one thing: does PHI leave your control, and if so, under what terms?
Send PHI to a third-party model and you have made a disclosure to a business associate. That is permitted, and it requires a signed BAA, a documented risk analysis covering the use, and controls proportionate to the risk. Run the model on infrastructure you control and no disclosure occurs, which removes an entire category of obligation rather than satisfying it.
Where organisations get this wrong
Assuming a BAA closes the question
It does not. The BAA allocates responsibility between you and the vendor. Your Security Rule obligations, the risk analysis, access control, audit logging and breach notification, remain yours. We regularly see a signed BAA treated as the compliance programme rather than one component of it.
Believing removing names is de-identification
HIPAA defines de-identification through Safe Harbor, which requires removing eighteen specific identifier categories, or Expert Determination. Stripping names and dates from a clinical note is neither. Free-text clinical narrative frequently re-identifies a patient through context alone.
Shadow usage
The most common actual exposure is not an architecture decision at all. It is clinical and administrative staff pasting PHI into consumer AI tools because the sanctioned option is slow or does not exist. Blocking the tools without providing an alternative moves the behaviour rather than stopping it, and moved behaviour is unmonitorable.
Why self-hosting keeps winning here
Among the covered entities we work with, the deciding factor is rarely capability or cost. It is that a self-hosted deployment makes the compliance position straightforward to establish, document and defend. PHI never leaves the environment, there is no business associate to oversee, and the answer to the auditor's question is short.
The trade is that you take on operational responsibility for the system. For most healthcare organisations of any size, that is a smaller problem than vendor oversight across a growing list of AI services.
What we build
- Ambient clinical documentation and note drafting, on-premise
- Prior authorisation packet assembly and denial appeal drafting
- Clinical and policy retrieval across your own document corpus
- Coding support and medical record chronology construction
Related
Common questions
Does a BAA make a cloud AI service HIPAA compliant?
A BAA is necessary, not sufficient. It establishes the business associate relationship and allocates responsibility. You still owe a risk analysis, access controls, audit logging and breach procedures covering that use. A signed BAA with no risk analysis behind it is a document, not a compliance position.
Can we use consumer AI tools if we remove names?
Almost certainly not. De-identification under HIPAA has two defined methods, Safe Harbor and Expert Determination, and both are stricter than removing names. Clinical narrative is notoriously hard to de-identify because context re-identifies patients even when identifiers are stripped.
Is a self-hosted model automatically compliant?
No. It removes the disclosure to a third party, which is the largest single risk, and it does not remove your obligations for access control, audit logging, encryption and workforce training. It makes the compliance position much simpler to establish and document, which is why most covered entities we work with end up there.
What about AI scribes and ambient documentation?
Widely deployed and workable, provided the vendor signs a BAA, you have run the risk analysis, and clinicians know recording is happening. The recurring gap we see is patient notification and consent practice, not the technology.
Talk through your HIPAA position
We will walk through where PHI would flow in the system you are considering, and what that means for your obligations.
Book a free consultation