A physician turns to ChatGPT to summarize a patient note. An office manager opens Claude to draft patient communications. A biller wonders if Gemini could help draft an appeal letter. But before using AI with protected health information (PHI), there’s one key question every healthcare professional should answer: Is this tool HIPAA compliant?

Not all AI tools are. Whether an AI application can be used in a healthcare setting depends on how it handles PHI, the safeguards it provides, and whether the vendor meets HIPAA requirements. This guide explains what HIPAA requires, where many AI tools fall short, and how healthcare providers can evaluate AI before bringing it into their workflows.

A compliance professional using an AI program | Are AI Applications HIPAA Compliant

Summary

AI applications can be used in a HIPAA-compliant way, but no tool is automatically “HIPAA compliant.” Before using AI with protected health information (PHI), healthcare organizations must confirm that the vendor will sign a Business Associate Agreement, protects data with appropriate security controls, provides access logs and role-based permissions, clearly explains how data is stored and retained, and does not use PHI to train its models. Organizations should also include AI in their HIPAA risk assessments, approve specific tools and use cases, establish written AI policies, and train employees on when PHI may—and may not—be entered into an AI application.

What HIPAA Requires When Using AI

HIPAA doesn’t mention artificial intelligence by name, but its requirements still apply whenever an AI application creates, receives, maintains, or transmits PHI.

When adopting any AI tool, ask two questions:

  • Will the tool have access to PHI?
  • Can the vendor meet HIPAA’s legal and security requirements?

Those answers form the foundation of using AI responsibly in healthcare.

How PHI Fits Into the AI Picture

PHI includes far more than medical records. Patient names, dates of birth, diagnoses, medications, clinical notes, appointment details, insurance information, and any other data that can identify an individual in connection with their healthcare are all considered PHI.

If that information is entered into an AI application, HIPAA applies. For example, copying a patient note into an AI writing assistant to improve grammar or summarize documentation may seem harmless, but the application is now processing PHI. AI applications should be evaluated the same way you would assess any other vendor that handles patient information.

Why Business Associate Agreements Are Non-Negotiable

If an AI vendor creates, receives, maintains, or transmits PHI on your behalf, HIPAA generally requires a signed Business Associate Agreement (BAA).

A BAA establishes how the vendor will safeguard PHI and defines each party’s responsibilities under HIPAA. Many consumer AI tools do not offer BAAs, which means they should not be used with PHI. Without this agreement, using an AI tool with PHI can create a HIPAA compliance issue regardless of how useful or secure the application appears to be.

Why Most AI Tools Are Not HIPAA Compliant

Thousands of AI tools are now available, but most were designed for general business or personal use, not healthcare. As a result, many lack the safeguards healthcare organizations need to protect patient information and meet HIPAA requirements.

The Problem With Consumer AI Tools

Free and consumer-grade AI applications usually aren’t built for handling PHI. Common gaps include:

  • No BAA available
  • Data may be retained or used for model training
  • Limited audit logging
  • Minimal access controls
  • Little transparency around data storage and retention

These aren’t minor gaps that can be solved by changing a privacy setting or opting out of model training. They’re fundamental compliance requirements that should be evaluated before introducing any AI tool into a workflow involving patient information.

Common HIPAA Pitfalls When Using AI Tools

Many healthcare groups start using AI to improve efficiency, not realizing they’ve introduced new compliance risks. When a department downloads a new tool or an employee experiments with an AI assistant without proper oversight, seemingly harmless decisions can create HIPAA exposure.

Here are some of the common ways healthcare providers inadvertently create HIPAA exposure when adopting AI tools.

Using AI Without a Signed BAA

Using an AI tool that processes PHI without a signed BAA is one of the most common compliance mistakes. This often happens when an employee uses AI to summarize a patient note, rewrite a clinical document, or draft a patient communication without realizing PHI has been shared with a third party. Even a single incident can create serious HIPAA risk.

Leaving AI Out of Your Risk Assessment

The HIPAA Security Rule requires covered entities and business associates to conduct an ongoing risk analysis of systems that create, receive, maintain, or transmit electronic protected health information (ePHI). AI tools should be included in that process.

Your HIPAA risk assessment should identify what PHI an AI tool accesses, how the data is protected, and whether appropriate safeguards are in place. As AI adoption grows, regularly review your technology inventory to identify unapproved AI applications already being used.

Weak Access Controls and Missing Audit Trails

HIPAA requires more than protecting PHI. You also need to be able to demonstrate who accessed it and when.

Many AI tools lack role-based permissions, detailed audit logs, or centralized administrative controls. If your organization can’t demonstrate how PHI is being accessed within an AI application, that gap may become apparent during an audit or investigation.

AI Tools That Train on Your Data by Default

Many AI platforms retain customer inputs or use them to improve their models unless specific contractual and technical safeguards are in place.

Before using an AI tool with PHI, understand whether data is retained, whether it is used for model training, and how those practices are documented. If a vendor uses PHI for purposes beyond providing its service, it creates significant HIPAA risk.

Which AI is HIPAA Compliant?

Some AI vendors have built products specifically for healthcare, but there is no government certification that makes an AI tool “HIPAA compliant.”

Instead, evaluate whether the vendor supports HIPAA requirements. At a minimum, look for:

  • A signed BAA
  • Encryption of PHI in transit and at rest
  • Role-based access controls
  • Audit logging
  • Clear data retention policies
  • Contractual assurance that PHI will not be used to train AI models

Healthcare-specific AI platforms are often a safer starting point than general-purpose tools, but every vendor should be evaluated through your risk assessment and vendor review process prior to implementation.

How to Use AI in a HIPAA-Compliant Way

Using AI in healthcare isn’t just about choosing the right vendor. You also need the policies, processes, and training to ensure AI is used appropriately. Before rolling out any AI tool that may interact with PHI, focus on three key steps.

Run an AI-Specific Risk Assessment First

Evaluate every AI tool that handles PHI before it’s deployed.

Your assessment should identify what PHI the tool will access, how it protects that information, whether the vendor offers a BAA, and whether any security gaps exist. Documenting those findings is an important part of maintaining an effective HIPAA compliance program. Compliancy Group can help you build a risk assessment process that accounts for AI tools alongside the rest of your HIPAA program.

Build Internal Policies for AI Use

Develop written policies that define how AI may be used with PHI.

Those policies should identify approved AI tools, prohibit the use of consumer AI with patient information, establish data handling requirements, and explain how employees should report potential AI-related privacy or security incidents.

Train Your Workforce on AI and HIPAA Compliance

Ensure employees understand which AI tools are approved, when PHI can be used with AI, and when it cannot.

AI guidance should become part of workforce HIPAA training, since workforce training is one of the OIG Seven Elements of an Effective Compliance Program and a direct HIPAA requirement. As with any compliance policy, employees are far more likely to follow expectations when they understand both the rules and the reasons behind them.

AI Can Support Healthcare, But Compliance Still Comes First

AI offers endless opportunities to improve efficiency across healthcare, but it doesn’t change an organization’s HIPAA responsibilities.

When introducing any AI application that may interact with PHI, evaluate the vendor, complete a risk assessment, establish clear policies, and train your workforce on appropriate use.

Compliancy Group helps healthcare professionals put those safeguards into practice. Whether you’re conducting HIPAA risk assessments, managing policies and procedures, training employees, tracking vendors, or documenting compliance activities, The Guard provides a centralized platform to support the ongoing oversight that HIPAA requires, even as new technologies like AI become part of everyday healthcare.

Frequently Asked Questions

Yes, any AI vendor that will access, process, store, or transmit PHI on behalf of your organization must sign a BAA before use begins.

 

If an AI tool is used in a way that never involves PHI, for example, generating marketing copy or drafting internal meeting agendas, a BAA may not be necessary. When in doubt, evaluate the specific use case before deployment.

Yes, AI tools can be used with PHI when the vendor supports HIPAA requirements, a BAA is in place, and your organization has implemented appropriate security controls, policies, and oversight.

HIPAA compliance depends on both the technology and how it is used.

Using an AI application that exposes PHI without appropriate safeguards can result in a HIPAA violation.

 

Depending on the circumstances, organizations may face Office for Civil Rights (OCR) investigations, corrective action plans, financial penalties, and reputational harm. In some cases, self-disclosing the incident to OCR can help demonstrate good faith and may influence how the case is handled, but the best way to avoid these outcomes is to evaluate AI tools before they become part of your workflow.