web analytics
Sector Rules

HIPAA and AI

Protected Health Information in AI Systems

The one-paragraph answer

HIPAA AI compliance applies whenever an AI system touches protected health information (PHI). HIPAA (Health Insurance Portability and Accountability Act) has three main rules that reach AI: the Privacy Rule governs uses and disclosures, the Security Rule requires safeguards for electronic PHI, and the Breach Notification Rule requires reporting when PHI is compromised. AI vendors processing PHI are business associates and must sign business associate agreements (BAAs). Compliance is not optional; enforcement is active.

The pain HIPAA AI compliance is causing our customers

Healthcare organizations adopting AI face immediate HIPAA questions. Can the training data include PHI? Can the vendor see PHI? Is the vendor a business associate? What safeguards does HIPAA require of AI systems? What happens if an AI system leaks PHI in a chat completion, in a log file, or in a model output? Most of these questions have clear answers under existing HIPAA law, but most healthcare organizations have never mapped their AI stack to HIPAA obligations.

What HIPAA AI compliance requires

The Privacy Rule

Uses and disclosures of PHI must be for permitted purposes (treatment, payment, healthcare operations, or with authorization). AI systems using PHI must have documented purposes and minimum-necessary access. Marketing AI, non-clinical research AI, and third-party analytics AI often need patient authorization.

The Security Rule

Administrative safeguards (policies, training, sanctions), physical safeguards (facility access, workstation security), and technical safeguards (access controls, audit logs, integrity controls, transmission security) all apply to AI systems handling electronic PHI. Encryption at rest and in transit is expected practice.

The Breach Notification Rule

Unauthorized acquisition, access, use, or disclosure of unsecured PHI triggers notification obligations to affected individuals, HHS, and (for larger breaches) the media. AI incidents can qualify as breaches: a chat completion leaking PHI, a model output containing PHI, a training log exposing PHI.

Business Associate Agreements

AI vendors processing PHI on behalf of covered entities are business associates. BAAs must be in place before PHI is shared. BAAs impose safeguard, breach notification, and subcontractor obligations on the vendor.

De-identification and AI training

De-identified data (under Safe Harbor or Expert Determination) is generally outside HIPAA. But re-identification risk is high with AI, especially generative AI. Companies training AI on de-identified data still face reputational, contractual, and (in some cases) state-law obligations. Some state laws (California, Illinois) reach beyond HIPAA's de-identification standard.

Why HIPAA AI compliance matters to you

Every covered entity (health plans, healthcare providers, healthcare clearinghouses) and every business associate processing PHI is subject to HIPAA. Penalties for violations range from $137 to $2.1 million per violation category per year, plus potential criminal penalties. Enforcement by HHS OCR is active, and state attorneys general have concurrent authority.

Interaction with state healthcare AI notice laws

State legislatures are beginning to pass AI-specific patient notice laws that interact with HIPAA compliance. Rhode Island H 7538 (signed June 2026) requires healthcare providers using AI for clinical documentation to notify patients that AI was used. California AB 3030 (effective January 1, 2025) requires healthcare providers using generative AI to communicate clinical information to patients to disclose the AI use and provide a path to reach a human. These laws do not amend HIPAA directly but add layered patient-notice obligations that HIPAA-covered entities must integrate with their existing privacy practices. Expect more states to follow this pattern.

What the research says about HIPAA AI

The academic literature on HIPAA AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“Algorithmic bias can affect AI clinical predictions and exacerbate health disparities.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“a lack of a clear understanding of how to quantify benefit or ensure patient safety”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about HIPAA AI arrives from the board, the buyer, or the regulator.

How to bring healthcare AI into HIPAA compliance: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory every AI system that touches PHI. Include the ones nobody registered: the ambient scribe, the ChatGPT tab a clinician uses to draft a letter, the vendor analytics tool nobody read the contract for. These are where the breaches come from.
  2. Get a BAA in place before PHI moves, not after. Any vendor processing PHI on your behalf is a business associate. Many major model providers offer HIPAA-compliant tiers with a BAA; the free tier is not one of them.
  3. Apply the Security Rule to the AI, not just the EHR. Access controls on the model and its training data. Audit logs. Encryption at rest and in transit. Integrity controls. These are the same safeguards, applied to a system nobody thought of as clinical infrastructure.
  4. Bias-test anything that influences a clinical decision. Section 1557 reaches algorithmic discrimination in patient care. A model that performs worse for one group is not just a quality problem, it is a potential civil rights violation.
  5. Treat an AI output containing PHI as a reportable event. Because it is one. Your breach response plan needs to contemplate a model leaking PHI into a completion, a log, or an output, and your team needs to know that counts.

Done in this order, HIPAA AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about HIPAA AI compliance

Are all AI vendors business associates?

Only if they process PHI on behalf of a covered entity or business associate. Vendors of general-purpose AI that never touch PHI are not automatically business associates.

Can we train AI on our PHI?

For treatment, payment, and healthcare operations, generally yes, subject to Privacy Rule safeguards. For non-permitted purposes, patient authorization is required.

What if the AI is a general-purpose LLM?

If PHI is sent to the model (even in a prompt), the model provider becomes a business associate and a BAA is required. Many popular LLM providers do offer HIPAA-compliant service tiers with BAAs.

Where does HIPAA AI compliance fit in SRJ's work?

The healthcare sector-rules addendum in Volume III of The Operating Discipline for AI Library™ addresses HIPAA-specific AI compliance. The AI Vendor Risk Inventory™ supports business associate management for AI vendors.

Primary sources on HIPAA AI

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning HIPAA AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including HIPAA and AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation