Skip to main content
Compliance Doctrine

HIPAA and AI in healthcare

HIPAA applies to any AI that creates, receives, stores, or transmits protected health information. That means you need safeguards, a business-associate agreement with the AI vendor, and minimum-necessary access controls before the tool ever sees patient data.

5 min read/Written by Perry Luzier/Reviewed

PHI and the business-associate agreement

If an AI vendor handles protected health information on your behalf, it is a business associate and needs a signed BAA. Sending PHI to a consumer AI tool with no BAA is itself a HIPAA violation, regardless of the tool's output.

The single most common healthcare AI mistake is a clinician pasting patient details into a public chatbot to draft a note. That transmission of PHI to a vendor without a business-associate agreement is a breach on its own. Before any AI touches patient data, confirm the vendor will sign a BAA, keeps data within a compliant environment, and does not train public models on your inputs.

Sanctioned beats forbidden

Banning AI in a clinic does not stop it, it drives it into unmonitored personal accounts. Provide a HIPAA-compliant, BAA-backed tool so staff have a safe option, and the shadow use that causes breaches disappears.

Questions

Frequently asked questions.

Can I use a general AI chatbot for patient notes?

Only if the vendor signs a business-associate agreement and provides a HIPAA-compliant environment. A standard consumer chatbot with no BAA must never receive protected health information, that transmission alone is a violation.

Want this built into your operation?

We install the systems described here as owned infrastructure. Start with a diagnostic of where your business actually loses time and margin.