HIPAA and AI in healthcare
HIPAA applies to any AI that creates, receives, stores, or transmits protected health information. That means you need safeguards, a business-associate agreement with the AI vendor, and minimum-necessary access controls before the tool ever sees patient data.
PHI and the business-associate agreement
If an AI vendor handles protected health information on your behalf, it is a business associate and needs a signed BAA. Sending PHI to a consumer AI tool with no BAA is itself a HIPAA violation, regardless of the tool's output.
The single most common healthcare AI mistake is a clinician pasting patient details into a public chatbot to draft a note. That transmission of PHI to a vendor without a business-associate agreement is a breach on its own. Before any AI touches patient data, confirm the vendor will sign a BAA, keeps data within a compliant environment, and does not train public models on your inputs.
Banning AI in a clinic does not stop it, it drives it into unmonitored personal accounts. Provide a HIPAA-compliant, BAA-backed tool so staff have a safe option, and the shadow use that causes breaches disappears.
Frequently asked questions.
Can I use a general AI chatbot for patient notes?
Only if the vendor signs a business-associate agreement and provides a HIPAA-compliant environment. A standard consumer chatbot with no BAA must never receive protected health information, that transmission alone is a violation.