HIPAA and AI
HIPAA and AI refers to how the US Health Insurance Portability and Accountability Act applies when AI systems create, receive, store, or transmit protected health information. There is no special AI exemption: covered entities and their business associates must meet the same Privacy, Security, and Breach Notification Rule requirements, including a business associate agreement with any AI vendor handling PHI.
01why it matters for a business
Healthcare organizations have some of the strongest use cases for AI, such as clinical documentation, intake, prior authorization, scheduling, and patient communication, and some of the strictest obligations. The core question is simple: will this AI system touch PHI? If yes, the vendor processing it is generally a business associate, which requires a BAA, and the system must meet Security Rule safeguards such as access controls, audit logs, and encryption.
Many consumer AI tools are not offered under a BAA, so entering PHI into them can be a violation however useful the result. Several major model providers and cloud platforms do sign BAAs for specific services, typically enterprise or API offerings, which makes compliant AI achievable. The minimum necessary standard generally applies too: send the model only the PHI the task requires. HIPAA sets a federal floor, and state privacy laws can add obligations.
02what it looks like in practice
A multi-site physical therapy group wants AI to draft visit notes from therapist dictation. Before building, it confirms that the transcription and model providers will sign BAAs covering the specific services used, configures the deployment so data is not retained for training, restricts access by role, logs every access to the drafts, and keeps the therapist as reviewer and signer of every note. The AI saves documentation time; the compliance posture matches any other system handling PHI.
03common mistakes
- Using consumer AI accounts with patient information because the output is helpful.
- Assuming a vendor's HIPAA-compliant marketing covers your use. Get the BAA and check which services it covers.
- Forgetting logs, prompts, and retrieved documents, which may contain PHI too.
- Sending entire records when the task needs a few fields.
04related terms
- Protected health information (PHI)Protected health information (PHI) is individually identifiable health information held or transmitted by a HIPAA covered entity or its business associate, in any form.
- Business associate agreement (BAA)A business associate agreement (BAA) is a contract required by HIPAA between a covered entity, such as a provider or health plan, and a vendor that creates, receives, maintains, or transmits protected health information on its behalf.
- EHR integrationEHR integration is connecting an electronic health record system, such as Epic, Oracle Health, or athenahealth, with other software so patient, scheduling, clinical, and billing data can flow between them.
- Private LLMA private LLM is a language model deployment in which your data and prompts stay inside an environment you control or have contractually isolated, rather than a shared consumer service.
- SOC 2SOC 2 is an attestation report, defined by the American Institute of Certified Public Accountants (AICPA), in which an independent CPA firm examines a service organization's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
05where insomnia club fits
Insomnia Club builds AI for healthcare operations with HIPAA requirements in the design: BAA-covered services, minimum necessary data, role-based access, and audit logging, with your counsel as the final word on compliance.
see AI implementation →tell us what keeps you up at night.
Scoped by the people who ship it. Priced before we start.
book a call drop your number