HIPAA Compliance in the Age of AI

HIPAA compliance in the age of AI means the same rules that have always governed protected health information, or PHI, now have to be applied to a new category of tools: software that can read, summarize, extract, draft, and act on medical and claims data using artificial intelligence.

HIPAA does not have a carve-out for AI. If a system creates, receives, maintains, or transmits PHI on behalf of a covered entity or business associate, HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule apply to it, regardless of whether a person or a model is doing the work.

That creates real questions for claims organizations, med-legal offices, and healthcare-adjacent businesses that are adopting AI tools faster than their compliance programs are being updated to handle them.

What HIPAA actually regulates

HIPAA applies to covered entities (health plans, healthcare providers, and healthcare clearinghouses) and their business associates: any vendor or contractor that creates, receives, maintains, or transmits PHI on the covered entity's behalf.

Three rules matter most in an AI context:

  • The Privacy Rule, which governs how PHI may be used and disclosed
  • The Security Rule, which requires administrative, physical, and technical safeguards for electronic PHI
  • The Breach Notification Rule, which sets requirements for reporting unauthorized access or disclosure

PHI is broadly defined. It includes not just diagnoses and treatment notes, but names, dates, claim numbers, employer information, and any other identifier that can be linked to an individual's health information.

Does HIPAA apply to AI tools that process medical records?

Yes. If an AI tool reads, summarizes, extracts data from, or drafts content based on documents containing PHI, it is processing PHI, and HIPAA applies in the same way it would to any other software performing that function.

The label "AI" does not change the legal analysis. What matters is whether PHI passes through the system, where it is stored, who can access it, and what the vendor is contractually permitted to do with it.

This applies whether the AI capability is built into a claims platform, offered as a standalone product, or accessed through a general-purpose model that an employee pastes information into directly.

When does an AI vendor become a HIPAA business associate?

An AI vendor becomes a business associate the moment it creates, receives, maintains, or transmits PHI on behalf of a covered entity, and a signed business associate agreement, or BAA, is required before that happens.

A BAA with an AI vendor should address:

  • Permitted and required uses of PHI
  • A prohibition on using PHI to train or improve models unless separately authorized
  • Required administrative, physical, and technical safeguards
  • Breach notification timelines and obligations
  • Flow-down requirements for any subcontractors or subprocessors
  • Data return or destruction requirements at the end of the relationship
  • Audit and inspection rights

Many popular consumer AI tools do not offer a BAA at all. Without one, using those tools with PHI is not a gray area. It is a HIPAA violation, and it is one of the most common ways organizations end up exposed as employees adopt AI tools informally.

Where AI intersects PHI in claims and med-legal workflows

AI capabilities are increasingly built into or layered on top of the everyday tools that claims and med-legal teams already use. Common touchpoints include:

  • Extracting data from intake forms, first reports of injury, and medical records
  • Summarizing medical records, depositions, and case files
  • Drafting correspondence, status updates, and record requests
  • Classifying and routing incoming documents
  • Preparing materials for a claim review or medical-legal report
  • Answering questions about a claim file using natural language

Each of these touchpoints is an opportunity for PHI to be processed, stored, or transmitted outside the boundaries an organization intended, especially when a tool was adopted for convenience rather than evaluated through a compliance process.

The minimum necessary standard and AI

HIPAA's minimum necessary standard requires that access to and use of PHI be limited to the minimum needed to accomplish the intended purpose. Applied to AI, this means a tool that only needs a claimant's work-status information should not have standing access to an entire medical file.

In practice, this means scoping what an AI system can see field by field and document by document, rather than granting broad access because it is technically convenient. A system built to draft appointment confirmations does not need visibility into litigation notes or financial reserves.

Can PHI be used to train AI models?

Only if the covered entity has authorized it and the arrangement is documented in the business associate agreement. Absent that authorization, PHI should not be used to train, fine-tune, or otherwise improve a vendor's models.

This is a meaningful risk with general-purpose AI tools, where data submitted by users can be retained and used to improve the underlying model unless the vendor offers, and the customer enables, a zero-retention or no-training configuration. Organizations should confirm in writing whether PHI submitted to an AI tool is retained, for how long, and whether it is used for any purpose beyond completing the immediate task.

De-identification is not automatic

HIPAA recognizes two methods for de-identifying data: the Safe Harbor method, which requires removing eighteen specific identifiers, and the Expert Determination method, which requires a qualified statistical assessment that re-identification risk is very small.

An AI-generated summary is not automatically de-identified just because it condenses a document. Names, dates, claim numbers, and other identifiers frequently persist into summaries, drafts, and extracted fields unless a system is specifically designed and verified to remove them. Vendor claims that data is "anonymized" should be verified against the actual HIPAA standard, not taken at face value.

Access controls and audit logging

The Security Rule requires specific technical safeguards for systems that touch electronic PHI, including access control, audit controls, integrity controls, and transmission security.

For an AI system, that translates into concrete requirements:

  • A dedicated identity for the AI system, separate from any individual employee's credentials
  • Role-based permissions limiting which claims, documents, and fields it can reach
  • Encryption of PHI both in transit and at rest
  • A complete log of every record the system accessed, read, or modified
  • A clear record of what the system directly extracted from a source versus what it inferred or generated
  • The ability to immediately suspend or revoke the system's access

That last distinction matters more with AI than with traditional software: an audit trail that cannot separate a fact taken directly from a document from a conclusion the system generated makes it much harder to investigate an error or a disputed disclosure.

Human oversight and accountability

HIPAA does not relieve a covered entity of responsibility because a task was performed by AI rather than a person. Legal accountability for the handling of PHI stays with the covered entity, regardless of which tool touched the data.

Actions with real consequences for a claimant or patient, sending correspondence that discloses PHI to a new party, releasing records, or making determinations based on AI-generated output, should go through a documented human review step before anything leaves the system. Low-risk, easily reversible tasks can reasonably run with lighter oversight; disclosures and irreversible actions should not.

Common AI-related HIPAA risks

Most AI-related HIPAA problems are not exotic. They tend to fall into a small number of recurring patterns:

  • Employees pasting PHI into consumer AI tools that have no BAA in place ("shadow AI")
  • AI vendors with subprocessors that were never disclosed or covered by a BAA
  • PHI retained by a vendor for model training without authorization
  • Summaries or extracted fields attached to the wrong claim or the wrong individual
  • Insufficient logging, making it impossible to reconstruct what an AI system accessed or produced
  • Malicious or malformed content in a document causing an AI system to take an unintended action

Questions to ask before adopting an AI tool that touches PHI

Before any AI tool is connected to systems containing PHI, an organization should be able to get clear answers to the following:

  • Will the vendor sign a business associate agreement?
  • Where is PHI stored and processed, and which subprocessors are involved?
  • Is PHI used to train or improve the vendor's models?
  • What encryption standards apply to data at rest and in transit?
  • How is access controlled, scoped, and logged?
  • What are the data retention and deletion policies?
  • How are errors, exceptions, and uncertain cases escalated to a person?
  • What independent certifications does the vendor hold, such as SOC 2 or HITRUST?

A vendor that cannot answer these questions clearly, or that treats a BAA as optional, is not ready to touch PHI.

A practical path to compliant AI adoption

Organizations that adopt AI successfully under HIPAA tend to follow a similar sequence rather than rolling a tool out broadly on day one.

  1. Map where PHI currently flows before introducing any new tool
  2. Choose one narrow, well-defined workflow to start with
  3. Confirm a business associate agreement is signed and covers the specific use case
  4. Scope the tool's access to the minimum data it needs
  5. Turn on logging and audit trails before go-live, not after
  6. Require human review for any disclosure or high-consequence action
  7. Monitor performance and exceptions, then expand scope deliberately

Document intake and internal summarization are typically easier to govern than tasks that involve external disclosure. Starting narrow makes it possible to catch gaps in a BAA, a logging configuration, or an access control before they affect a large volume of PHI.

Frequently asked questions

Does HIPAA prohibit the use of AI?

No. HIPAA does not prohibit AI. It requires that any system touching PHI, AI-based or not, operate under the same safeguards, agreements, and accountability HIPAA has always required.

Do I need a business associate agreement with an AI company?

Yes, if the AI tool will create, receive, maintain, or transmit PHI on your organization's behalf. This applies to specialized healthcare AI products and to general-purpose AI tools used with PHI.

Can general-purpose AI tools be used with PHI?

Only if the vendor offers a business associate agreement and the specific product tier or configuration being used is covered by it. Many free or consumer versions of popular AI tools do not qualify, even if an enterprise version of the same product does.

Who is liable if an AI tool causes a HIPAA breach?

The covered entity remains responsible for PHI under HIPAA. A business associate agreement can allocate liability and remediation obligations between the organization and the vendor, but it does not remove the covered entity's own compliance obligations.

Is data safe to process with AI once it has been de-identified?

De-identification substantially reduces risk, but only if it meets HIPAA's Safe Harbor or Expert Determination standard. Data that a vendor casually describes as "anonymized" should be verified against that standard before being treated as outside HIPAA's scope.

The bottom line

AI adoption and HIPAA compliance are not in conflict. They require the same discipline organizations have always needed for any system touching PHI: a signed business associate agreement, access limited to the minimum necessary, encryption and audit logging, human review of consequential actions, and a documented process for choosing and expanding AI use cases.

The organizations that run into trouble are rarely the ones that adopt AI. They are the ones that let it in through the side door, without a BAA, without logging, and without anyone deciding what the tool should and should not be allowed to see.


This article provides general information about HIPAA compliance and AI technology. It does not constitute legal, compliance, or security advice.