Buyer guide

HIPAA Compliant AI Tools: What the Phrase Actually Means

Last updated

Free tool

AI Readiness Assessment

Twelve factual questions on data access, governance and change capacity.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

How we evaluated

This page does two jobs. It explains what the phrase HIPAA compliant means when applied to an AI product, and it records what each vendor in our registry publicly documents about its position. Everything here was checked in August 2026 against vendor websites, published privacy and security material, and HHS guidance. We take no commissions, referral fees or paid placements from any vendor listed.

The column that carries the weight is publicly documented business associate agreement. We mark it yes only where the vendor states in public material that it signs one. Not published means we could not find that statement, not that a vendor refuses to sign. Most healthcare AI vendors will sign an agreement when asked, and several of the entries marked not published almost certainly do. The distinction still matters, because what a vendor publishes can be checked before a sales call, and what a salesperson says on a call cannot.

We do not verify certifications ourselves. Where a vendor claims SOC 2, HITRUST or ISO 27001 we record the claim and tell you to ask for the report. A badge on a marketing page is a claim; a current report with a defined scope is evidence. The two get conflated constantly, and the scope is where the interesting detail hides.

Nothing on this page is legal advice. It is a procurement aid built from public sources, and it points at primary HHS material so you can check the underlying rules yourself. If a fact here is wrong or has aged, write to [email protected] and we will correct it and move the checked date. The same vendor registry feeds our scribe comparison and every other comparison on this site, so a correction propagates.

At a glance

Every cell is checkable against the vendor material published on the review date above.

Healthcare AI tools by category and published HIPAA posture, checked August 2026
ToolCategoryPublicly documented BAAPublished EHR integrationsPricing published
AbridgeAmbient documentationYesEpicNo
Microsoft Dragon CopilotAmbient documentationYesEpic, Oracle Health, MEDITECH, athenahealthNo
Ambience HealthcareAmbient documentationYesEpicNo
SukiAmbient documentationYesEpic, Oracle Health, athenahealth, MEDITECHNo
DeepScribeAmbient documentationYesEpic, athenahealthNo
NablaAmbient documentationYesEpicPlan tiers published, amounts not shown
FreedAmbient documentationYesNone publishedYes
Heidi HealthAmbient documentationYesNone publishedFree tier published
Sunoh.aiAmbient documentationYesEpic, Oracle Health, athenahealth, eClinicalWorksYes
WaystarRevenue cycleYesEpic, Oracle Health, MEDITECH, athenahealth, VeradigmNo
AvailityPayer connectivityYesEpic, Oracle Health, athenahealth, Veradigm, NextGenFree tier published
RhymePrior authorizationNot publishedNone publishedNo
Latent HealthPrior authorizationNot publishedNone publishedNo
Cohere HealthPrior authorization, payer sideYesNone publishedNot sold to providers
AnteriorPrior authorization, payer sideNot publishedNone publishedNot sold to providers
Assort HealthVoice agentsYesEpic, athenahealthNo
HyroVoice agentsYesEpic, Oracle HealthNo
Hello PatientVoice agentsYes, stated explicitlyathenahealth, eClinicalWorks, NextGen, VeradigmNo
Infinitus SystemsVoice agents, outboundYesNone publishedNo
AriniVoice agents, dentalNot publishedDental systems onlyNo
PhreesiaPatient intakeYes, stated in privacy materialCount published, systems not namedNo
NotableWorkflow automationYesEpic, Oracle Health, athenahealthNo
Luma HealthPatient accessNot publishedEpic, Oracle Health, MEDITECH, eClinicalWorks, athenahealth, NextGenNo
ClearwavePatient intakeNot publishedNone publishedNo

The vendors

One card each: where the product is the right answer, what it costs, and what it costs you to run.

  • Enterprise ambient documentation built for hospital security review, which is the stage at which most scribe purchases stall.

    Pricing

    Pricing on request, negotiated per health system.

    HIPAA posture

    BAA available

    Signs business associate agreements and sells into environments that run full security assessments. The open questions in contract are raw audio retention and any model training rights, both of which are negotiable at this end of the market.

    Published EHR integrations

    • epic

    Strengths

    • Built to survive a health system security review
    • Contract terms are negotiable, including retention and training
    • Deep Epic presence means fewer integration unknowns

    Trade-offs

    • No published pricing
    • Retention and training terms are not published, only negotiated
    • Procurement timeline measured in months
  • The clearest published HIPAA statement among self serve scribes, and the only one in this group that publishes both a price and a BAA position.

    Pricing

    Published pricing. Checked August 2026, a starting rate of 149 US dollars per user per month is shown as a limited time offer against a listed rate of 199 US dollars.

    HIPAA posture

    BAA available

    States in its published FAQ that it signs business associate agreements as required under HIPAA, and adds that no hardware or software is HIPAA compliant by itself and that users must meet their own obligations. That second sentence is the most honest thing any vendor on this page says.

    Published EHR integrations

    • epic
    • oracle-health
    • athenahealth
    • eclinicalworks

    Strengths

    • Publishes both a price and an explicit BAA statement, which is rare
    • States plainly that compliance is shared rather than delivered by the product
    • Named integrations across four major EHRs

    Trade-offs

    • Published price is framed as a limited time rate, so it may move
    • Compliance detail beyond the FAQ is thin
    • Positioned around one EHR family, which shapes the integration depth
  • A revenue cycle platform, which means the data it touches is financial and clinical at once, and the agreement has to cover both.

    Pricing

    Pricing on request. Typically structured against claim or transaction volume.

    HIPAA posture

    BAA available

    Contracts as a business associate across eligibility, authorization and claim work. Because authorization packets carry clinical attachments, ask specifically about subprocessors and about retention of those attachments rather than only of claim data.

    Published EHR integrations

    • epic
    • oracle-health
    • meditech
    • athenahealth
    • veradigm

    Strengths

    • Established business associate relationship across a wide provider base
    • Broad published EHR coverage
    • Financial and clinical data handled under one agreement

    Trade-offs

    • No published pricing
    • Breadth of data types means the agreement needs closer reading
    • Subprocessor list is not published
  • Voice creates protected health information in real time with no screen for a human to check, which raises the bar on identity verification.

    Pricing

    Pricing on request. No pricing is published on the vendor site.

    HIPAA posture

    BAA available

    Handles inbound patient calls as a business associate. For any voice vendor, the questions that matter most are what the agent will disclose before identity is verified, and what is retained from recordings and transcripts.

    Published EHR integrations

    • epic
    • athenahealth

    Strengths

    • Sells into health systems that run formal security review
    • Completes bookings in the EHR rather than creating message queues
    • Established in a category where compliance questions are hardest

    Trade-offs

    • No published pricing
    • Public compliance detail on the main site is limited
    • Recording and transcript retention terms are contractual, not published
  • The most explicit published position in this comparison, and a useful benchmark for what a vendor can reasonably be asked to publish.

    Pricing

    Pricing on request. The vendor states pricing is customised by organisation size, workflows and modules used.

    HIPAA posture

    BAA available

    Its published privacy material states that it acts as a business associate of healthcare providers and enters into business associate agreements requiring it to safeguard patient information under HIPAA. It also publicly cites HITRUST CSF, SOC 2 Type 2 and PCI Level 1 certification.

    Strengths

    • Business associate status stated in published privacy material, not just claimed in sales
    • Three named certifications, including HITRUST and PCI
    • Long operating history under these obligations

    Trade-offs

    • Does not name its EHR integrations publicly
    • Modular pricing makes the compliance scope depend on which modules you buy
    • Payment handling adds PCI obligations alongside HIPAA ones
  • Included as the counterexample: strong published certifications, no public business associate agreement statement we could find.

    Pricing

    Pricing on request. No pricing is published on the vendor site.

    HIPAA posture

    No published BAA

    Displays HIPAA, SOC 2, ISO 27001 and TX-RAMP marks. We could not find a public statement that it signs business associate agreements as of August 2026. Certification marks and an executed agreement are different things, and only one of them is enforceable by you.

    Published EHR integrations

    • epic
    • oracle-health
    • meditech
    • eclinicalworks
    • athenahealth
    • nextgen

    Strengths

    • Broadest published EHR list of any vendor on this page
    • More certification marks than most competitors display
    • Covers several access workflows under one platform

    Trade-offs

    • No public business associate agreement statement we could verify
    • A HIPAA mark on a website is not evidence of an executed agreement
    • No published pricing

What does HIPAA compliant actually mean for an AI tool?

It means less than the badge implies, and the gap is where organisations get into trouble. HIPAA regulates covered entities and their business associates. It regulates organisations and their conduct, not software. There is no federal certification scheme for products, and HHS does not endorse, certify or approve any vendor as HIPAA compliant.

So when a vendor site carries a HIPAA badge, the honest translation is that the vendor believes its product can be used by a covered entity without breaking the rules, provided the covered entity configures and supervises it properly. Sunoh.ai says this out loud in its own FAQ, noting that no hardware or software is HIPAA compliant by itself and that users must meet their own obligations. Every vendor on this page could truthfully say the same thing. Most do not.

What that means in practice is that the burden does not transfer with the purchase order. You remain accountable for the disclosure, the access controls, the workforce training and the incident response. The vendor becomes accountable to you through a contract. Understanding that split is the whole of this page, and the rest of it is detail. Our HIPAA and AI compliance page sets out the underlying obligations in full.

What must a business associate agreement actually cover?

The business associate agreement is the instrument that makes a vendor answerable to you. HHS publishes sample provisions, and every serious vendor's paper starts from something close to them. The clauses that matter for AI specifically go beyond the sample.

  • Permitted uses and disclosures. Precisely what the vendor may do with the data, and explicitly whether product improvement counts as a permitted use. This is the clause where model training hides.
  • Subcontractors. AI vendors run on other people's infrastructure and often other people's models. You need the list and the requirement that subcontractors are bound by equivalent terms.
  • Retention and return or destruction. How long inputs, outputs, audio and transcripts are kept, and what happens at termination.
  • Breach notification timing. The rule sets an outer limit; a good agreement sets a shorter internal one, because you have your own clock to meet.
  • Audit and evidence rights. The right to see current certification reports, not just to be told they exist.

Read the agreement before the pilot, not after. Pilots are where protected health information moves under no agreement at all, and the fact that it was only a trial is not a defence. The procurement checklist puts these into a form you can send to a vendor.

How should an AI tool handle protected health information?

Four controls carry most of the weight, and all four are checkable before you buy.

Minimum necessary. The tool should receive only the data it needs for its function. An ambient scribe needs the encounter; it does not need the whole chart. A phone agent needs to confirm an identity; it does not need a problem list. Vendors that ask for broad access because it is simpler are asking you to carry their integration cost as risk.

Encryption in transit and at rest. Table stakes now, and any vendor that cannot answer this crisply has told you something important about the rest of its programme.

Access control and audit logging. Who at the vendor can see your data, under what circumstances, and is that access logged in a way you can review. Support access is the usual gap: a support engineer reproducing a bug is looking at real patient data unless the vendor has built for that case.

Segregation. Whether your data is logically separated from other customers, and whether outputs generated for you can surface anywhere else. This becomes the training question, which is important enough for its own section.

Does the vendor train its models on your data?

Ask in writing, and read the answer twice. This is the single most consequential question in an AI procurement and the one most often answered with a sentence that sounds reassuring while committing to nothing.

The answers you will meet fall into four groups. Some vendors state that customer data is never used for training. Some use de-identified data for training, in which case the de-identification method and who validates it are the questions. Some use data for training with customer consent, where the default setting is what matters. And some say nothing, which in a negotiation means the right is retained.

The reason this deserves its own clause is that model training is generally not a treatment, payment or operations use. If your agreement permits training as product improvement, you have permitted a disclosure for the vendor's commercial benefit, and you should have decided that deliberately rather than discovered it later. Enterprise buyers can usually negotiate this out. Self serve buyers accept the standard terms, which is a real difference between the two ends of every category on this page, and one our scribe pricing comparison traces through to the price.

What do SOC 2, HITRUST and ISO 27001 actually tell you?

They tell you a vendor has been examined against a control framework. None of them is a HIPAA certification, because no such thing exists.

  • SOC 2 Type 2 reports on whether controls operated effectively over a period, usually six to twelve months. It is the most common claim in this market. Ask for the report and read the scope section, because a report can cover a narrow slice of a company.
  • HITRUST CSF is the most demanding of the three in a healthcare context and maps to HIPAA requirements explicitly. Phreesia publicly claims it, which is a meaningful signal.
  • ISO 27001 certifies an information security management system. It is a good sign and is not healthcare specific.
  • TX-RAMP and similar state programmes matter if you are a public entity in that state and are otherwise a general positive signal.

The practical rule: a certification without a current report and a stated scope is a logo. Ask for the report under a mutual non disclosure agreement, and note the date. Certifications lapse, and a vendor that grew fast in the last eighteen months may be operating well outside the scope its last report covered.

Which healthcare AI tools publish what?

The table above records what each vendor in our registry documents publicly, grouped by category. Three patterns are worth naming.

First, the ambient documentation market publishes more than any other category. Every scribe vendor we track publicly documents a business associate agreement, which reflects a market that has been through hundreds of hospital security reviews and learned what buyers ask. Compare the same column for the prior authorization vendors, where three of five publish nothing, and the maturity difference is visible.

Second, published pricing and published compliance detail correlate loosely with each other and strongly with self serve distribution. Vendors selling to individual clinicians publish because they have to; vendors selling to health systems negotiate instead. Neither is better, but they demand different diligence from you. The prior authorization comparison, the phone agent comparison and the patient intake comparison each work through their own category in detail.

Third, voice is the category where the gap between what is published and what matters is widest. A scribe's risk is largely retention and training. A phone agent's risk includes what it will say to an unverified caller in real time, and no vendor publishes that behaviour.

What should you ask a vendor before signing?

Ten questions, in writing, before money moves. The written answers are the artefact; a demo is not.

  1. Will you sign a business associate agreement, and may we see your standard form now?
  2. Is our data used to train or improve your models, in identified or de-identified form?
  3. Which subprocessors and model providers touch our data, and where are they located?
  4. How long are inputs, outputs, audio and transcripts retained, and what happens at termination?
  5. Which of your staff can access our data, under what conditions, and is that access logged?
  6. What certifications do you hold, what is the scope, and when was the last report issued?
  7. How quickly will you notify us of a suspected breach, and through which channel?
  8. Where does the data physically reside?
  9. What happens to our data and our configuration if you are acquired?
  10. Can we export our data, in what format, and at what cost?

Question nine is asked least and matters more each year, because this market consolidates. If you want these run as a structured assessment against your own risk register, that is what our AI governance and compliance work covers, and vendor selection sequences it before you are emotionally committed to a product.

What happens when something goes wrong?

Plan for it before it happens, because the clock starts at discovery and not at the point you finish investigating. Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals without unreasonable delay and no later than sixty calendar days after discovery of a breach, and a business associate must notify the covered entity within the same outer limit. Breaches affecting five hundred or more individuals carry additional notification obligations to HHS and to the media.

The AI specific complication is discovery. A model that includes another patient's information in a note, or a phone agent that discloses to an unverified caller, may not trigger any alert. It surfaces when a human notices. That is why your acceptance testing should include deliberate probing for these failure modes, and why the first month of any deployment needs a review process rather than a dashboard.

Decide in advance who at your organisation owns the call, what evidence the vendor must supply and how fast, and how you would reconstruct what the tool did. If the vendor cannot produce an audit trail of what it processed and returned, you cannot investigate, and the sixty days will pass regardless.

Where should you start?

Start with an inventory, not a purchase. Most organisations already have AI in the building, usually because a clinician signed up for a free scribe tier or a department bought a tool on a card. Knowing what is already processing patient data is the cheapest risk reduction available to you, and it is usually uncomfortable reading.

Then set a standard that applies to everything, so each purchase is not renegotiated from first principles: a signed agreement before any pilot, a written model training position, retention terms in the contract, and a named owner for every tool. Attach it to your procurement process rather than to an individual, so it survives that person's departure. The AI readiness assessment gives you a starting picture, and the ambient documentation use case shows what that standard looks like applied to the tool most organisations buy first.

Organisations that do this well are not the ones with the strictest policy. They are the ones whose policy is short enough that a department head can follow it without calling legal, and specific enough that a vendor cannot answer it with a badge.

Official sources

The primary material behind the compliance claims on this page.

Questions we get asked

Is there such a thing as a HIPAA compliant AI tool?

Not strictly. HIPAA regulates covered entities and business associates, not software, and no federal body certifies products as compliant. A tool can be used in a compliant way when the vendor signs a business associate agreement, handles protected health information appropriately, and you configure and supervise it properly. The obligation stays with you.

What is a business associate agreement and do we always need one?

It is the contract that binds a vendor handling protected health information on your behalf to HIPAA obligations. You need one before any protected health information reaches the vendor, including during a pilot or a free trial. HHS publishes sample provisions, but AI purchases need extra clauses on model training, subprocessors and retention.

Does SOC 2 or HITRUST mean a vendor is HIPAA compliant?

No. They are examinations against control frameworks, and HITRUST maps to HIPAA requirements but does not certify compliance. Ask for the current report and read its scope, because a report can cover a narrow part of a company. A badge on a marketing page is a claim, not evidence.

How do we find out if a vendor trains its models on our data?

Ask in writing and require the answer in the contract. Acceptable answers state either that customer data is never used for training, or exactly what de-identified use is made and who validates the de-identification. Silence in an agreement generally means the right is retained by the vendor.

Why do some vendors show as not publishing a BAA?

Because we record it as yes only where the vendor documents it publicly. Not published means we could not find that statement, not that a vendor refuses. Several of those vendors likely sign agreements on request. The distinction is a procurement signal: published claims can be checked before a sales call.

How fast must a breach be reported?

Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than sixty calendar days after discovery, and business associates must notify the covered entity within that outer limit. Breaches affecting five hundred or more individuals carry additional obligations to HHS and the media.

Do you take money from any of these vendors?

No. No commissions, no referral fees, no paid placements and no affiliate links. Our revenue is advisory work for provider organisations. This page exists because most HIPAA compliance claims in this market are marketing, and the difference between a badge and an executed agreement is worth explaining once, properly.