HIPAA and AI: What Medical Businesses Need to Know

Every AI tool that touches patient data in a medical practice — scheduling, transcription, billing, chatbots — has to answer one question before it goes near real patients: is it HIPAA compliant? The honest answer is more nuanced than a vendor’s marketing page usually admits, because “HIPAA compliant” is not a certification anyone hands out; it’s a set of safeguards a practice and its vendors are responsible for implementing correctly.

Disclaimer: This content is for general informational purposes only and is not legal advice. Consult a healthcare compliance attorney before adopting any AI tool that will process protected health information (PHI).

What HIPAA Actually Requires of AI Vendors

Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your practice’s behalf is a “business associate” and must sign a Business Associate Agreement (BAA) with your practice. This applies to AI scribes, cloud-based scheduling tools, AI chatbots, and any transcription service — if the tool ever sees or stores PHI, it needs a signed BAA, full stop. A tool that refuses to sign one, or whose terms of service explicitly exclude healthcare use, should not be connected to real patient data regardless of how good its marketing looks.

Common AI-HIPAA Mistakes Practices Make

The most frequent compliance gap is using a general-purpose AI tool — a consumer chatbot, a free transcription app, a personal note-taking tool — for something that touches PHI because it’s convenient or a staff member already knows it, without checking whether a BAA is even available. Consumer versions of many popular AI tools explicitly exclude healthcare use in their terms; the enterprise or “healthcare” tier of the same product may be fine, but they are not interchangeable. Always check which specific product tier and terms apply, not just the vendor’s name.

Training Data and AI Model Risk

A separate concern is whether a vendor uses your practice’s data to train their underlying AI model. Reputable healthcare AI vendors will explicitly state that customer data is not used for model training, or offer an opt-out; if a vendor’s policy is silent or unclear on this point, ask directly before signing. This matters because HIPAA’s minimum-necessary standard and de-identification rules govern how PHI can be used beyond the immediate purpose it was collected for.

A Practical Vendor Checklist

Before adopting any AI tool that will touch PHI: (1) confirm a signed BAA is available and get it executed before go-live, not after; (2) ask whether your data trains their model, and get an opt-out in writing if you want one; (3) confirm where data is stored and whether it’s encrypted at rest and in transit; (4) check the vendor’s data-retention and deletion policy; (5) involve your compliance officer or legal counsel in reviewing the contract, not just IT.

Where to Verify the Rules Yourself

HIPAA’s official text and guidance is published by the U.S. Department of Health and Human Services. For business-associate requirements specifically, see HHS’s guidance on business associates, and for general HIPAA compliance resources see HHS.gov/hipaa.

Related reading: AI for Patient Communication and AI Medical Transcription Tools.

Scroll to Top