HIPAA & AI
What HIPAA-ready AI actually requires
HIPAA readiness is an operating discipline—not a product badge or a single security feature.
First determine whether the organization is a HIPAA covered entity or business associate and whether the proposed workflow creates, receives, maintains, or transmits protected health information. The answer shapes contracts, responsibilities, and controls. A software vendor is not automatically a business associate merely because it sells software; access to PHI and the function performed matter.
Risk analysis defines the work
HHS describes risk analysis as foundational to Security Rule compliance. Scope every location of electronic PHI, including production systems, indexes, prompts, logs, endpoints, backups, support tooling, and vendors. Evaluate threats and vulnerabilities affecting confidentiality, integrity, and availability, document risk levels, assign corrective actions, and revisit the analysis as the environment changes.
Apply safeguards as a system
Administrative safeguards include accountable security leadership, workforce authorization, training, incident procedures, contingency planning, evaluation, and vendor oversight. Physical safeguards address facilities, workstations, and devices. Technical safeguards include access control, audit controls, integrity protections, authentication, and transmission security. Encryption is powerful, but it cannot compensate for excessive privilege or undocumented flows.
Contract for the real service
When a business associate relationship exists, written assurances must describe permitted uses and disclosures and require appropriate safeguards. Trace subprocessors and operational support, not only the primary application. Establish breach reporting, return or destruction, access to records, audit evidence, and termination responsibilities before PHI enters the service.
- Current ePHI inventory and risk analysis
- Risk treatment decisions and control owners
- Access reviews, audit records, training, and incident exercises
- Business associate agreements and subprocessor oversight
- Evaluations triggered by material technical or operational change
“HIPAA compliant” should never be treated as a blanket description detached from a particular role and use. Readiness depends on configuration, contracts, workforce practices, documented decisions, and continuous operation.
References: HHS risk-analysis guidance and HHS business-associate guidance.
