Regulation

HIPAA and AI: What Providers Have to Get Right

Health Insurance Portability and Accountability Act of 1996, and the Privacy, Security, Breach Notification and Enforcement Rules made under it

Last updated

Free tool

AI Vendor Breach Exposure Calculator

Every AI tool that touches protected health information is a door someone else is guarding on your behalf.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

Regulator

HHS Office for Civil Rights

Who it applies to

  • Covered entities: health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a covered transaction
  • Business associates: any vendor that creates, receives, maintains or transmits protected health information on behalf of a covered entity, which includes essentially every clinical AI vendor
  • Subcontractors of business associates, who are business associates in their own right, which is why the model hosting provider behind your vendor is in scope
  • Not, in general, a consumer wellness app a patient chooses to use directly, which falls under Federal Trade Commission authority instead

Penalties

Civil monetary penalties are tiered by culpability, from unknowing through wilful neglect, with annual caps per violation category. The dollar figures are adjusted for inflation, so check the current amounts published by HHS rather than a secondary summary. Criminal penalties are available for knowing wrongful disclosure, and enforcement in practice often arrives as a corrective action plan with monitoring rather than a headline fine.

Deadlines

Dates that already bind, and dates still ahead.

DateWhat happens
Privacy Rule compliance date for most covered entities.
Security Rule compliance date for most covered entities.
Omnibus Rule compliance date. Business associates became directly liable for the Security Rule and for parts of the Privacy Rule, which is the provision that makes an AI vendor's own posture your concern.
Compliance date for the final rule aligning 42 CFR Part 2 substance use disorder records more closely with HIPAA. Relevant to any agent that touches behavioural health records.

What changed in 2026

Movement by year, newest first. Where nothing in the text moved, that is recorded too.

  • 2026

    No HIPAA rule specific to artificial intelligence took effect. What changed is expectation rather than text: security reviews of AI vendors are now routine rather than exceptional, and questions about retention of audio and about model training are being asked at procurement rather than after an incident.

    The Part 2 alignment rule reached its compliance date in February, which matters for any agent handling substance use disorder records. If you are deploying in a practice that treats those patients, that is a separate consent regime and not something to assume your HIPAA controls already cover.

  • 2025

    HHS Office for Civil Rights published a notice of proposed rulemaking in January 2025 to strengthen the Security Rule, including proposals around asset inventories, encryption, multi factor authentication and more frequent testing. It is a proposal. Check the current status at HHS before relying on any summary of it, including this one.

  • 2024

    The final rule aligning 42 CFR Part 2 with HIPAA was published, with compliance required by February 2026. For providers, the practical effect is that substance use disorder records carry additional consent requirements that an agent processing records has to respect rather than flatten.

  • 2013

    The Omnibus Rule made business associates directly liable for compliance. This is the provision that turns a vendor question into a legal one: an AI vendor processing your patients' data is not merely a supplier, it is regulated in its own right, and so is its subcontractor.

Does HIPAA cover artificial intelligence?

It covers the data, not the technology. There is no AI clause and no AI exemption. If a tool creates, receives, maintains or transmits protected health information on your behalf, the vendor is a business associate and the existing rules apply exactly as they would to a billing company.

That is good news, because it means you already know the framework. It is also why the phrase HIPAA compliant on a vendor website means very little on its own. No product is compliant. A deployment is compliant, and you are the one who has to make it so, whether the tool is an AI medical scribe or an intake agent.

What has to be in the business associate agreement?

HHS publishes sample provisions, and any vendor agreement should be read against them rather than accepted as a form. The clauses that matter most for AI tools are the ones the sample does not anticipate.

  • Permitted uses. Does the agreement permit use of your data to improve or train the vendor's models? If it is silent, assume the answer is one you would not have agreed to.
  • Subcontractors. Which model providers and cloud services sit behind the product, and are they flowed down?
  • Retention and destruction. How long is raw audio kept, and what happens at termination?
  • Breach notification timing. Vendor timelines are often longer than the ones you have to meet.
  • Audit rights. What can you actually inspect.

We work through the same list on every readiness audit, and the procurement checklist turns it into questions you can send before booking a demo.

What about training models on patient data?

This is the question that most often has a different answer to the one a buyer assumed. Some vendors do not train on customer data at all. Some do, with de-identification. Some offer it as a contractual option. All three can be workable, and only one of them is a surprise.

Ask three things. Is my data used to train shared models. If de-identification is claimed, by which method and who verified it. Can I decline without losing product function. Get the answers in the agreement rather than in an email from a sales engineer, because the sales engineer will have moved on before your first audit.

What does the Security Rule actually require?

A risk analysis, then safeguards proportionate to what that analysis found, then documentation of both. The rule is deliberately not a checklist, which frustrates buyers who want one, and is the reason two organisations can reach different defensible answers.

For AI tools, the risk analysis has to consider things the rule's authors were not imagining: audio recordings of clinical conversations, prompt and response logs that may contain PHI, and third party model providers in the chain. None of that is exotic under the rule. It just has to be written down and controlled like anything else, and it has to appear in the same register as the rest of your estate rather than in a spreadsheet the project team keeps.

Our approach to that documentation is set out under AI governance and compliance.

HIPAA generally permits use of PHI for treatment, payment and health care operations without additional authorisation, so a documentation tool used in treatment usually does not need a separate HIPAA authorisation. That is not the whole answer.

Recording is governed by state law, and consent requirements for recording a conversation vary. Substance use disorder records under 42 CFR Part 2 carry their own consent rules. And beyond the law there is the practical point: patients who discover a recording tool they were not told about respond badly, and rightly. Tell them, always, in plain words.

What do enforcement patterns suggest you should prioritise?

Published resolutions have long clustered around unglamorous failures: no current risk analysis, weak access control, unencrypted devices, and slow breach response. Model behaviour has not been the theme.

The practical reading is that an AI deployment is far more likely to be judged on the basics wrapped around it than on anything novel. Get the risk analysis current, get access control right, log everything, and be able to show the paperwork. That is also the least interesting advice in this field, which is probably why it keeps needing repeating.

If you are shortlisting vendors, our comparison page records what each one publicly documents about agreements and data handling, and says plainly where we could not verify a claim.

Official sources

Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.

Questions we get asked

Is ChatGPT HIPAA compliant?

A general consumer chat product used without a business associate agreement is not an appropriate place for protected health information. Some providers of large language models offer enterprise arrangements that include a BAA and controls on data use. The question to ask is not whether a brand is compliant, but whether you have an executed agreement covering the specific service and configuration you intend to use.

Do we need a BAA with every AI vendor?

With every vendor that handles protected health information on your behalf, yes. A tool that never touches PHI, such as one that only summarises published guidance, does not need one. Be careful with that judgement, because dictation, scheduling notes and support tickets carry PHI more often than people expect.

Can we de-identify data and skip HIPAA?

Properly de-identified data falls outside HIPAA, but the standard is specific: either the Safe Harbor method with its enumerated identifiers removed, or a documented expert determination. Free text clinical notes and audio are hard to de-identify reliably. Treat a vendor's claim as something to verify, not to accept.

Who is liable if the AI vendor causes a breach?

Both parties can face exposure. The business associate is directly liable under the Security Rule, and the covered entity remains responsible for its own obligations including breach notification to affected individuals. Contractual indemnities allocate cost between you. They do not move the regulatory duty.

Does HIPAA say anything about AI accuracy or bias?

No. HIPAA is a privacy and security statute. Accuracy, safety and bias sit with other regimes and with your own clinical governance, including FDA oversight where a tool crosses into a medical device function, and state law in a growing number of jurisdictions. Do not read HIPAA compliance as any statement about whether a tool works.