HIPAA & Compliance

What Does HIPAA Compliance Actually Mean for AI Tools?

"HIPAA compliant" gets used loosely. Some vendors mean it; some are bluffing. Here's what HIPAA actually requires of AI tools, what a Business Associate Agreement does, and the questions every clinician should ask before letting any AI tool touch patient data.

By MedAI Directory · May 7, 2026

Updated September 14, 2026: we corrected the status of the HIPAA Security Rule update (still a proposal), updated penalty amounts for 2026, and refreshed which OpenAI and Anthropic plans can be covered by a BAA.

"HIPAA compliant" might be the most-abused phrase in healthcare AI marketing. Vendors put it in headlines, sales decks, and footer badges. Some genuinely earn the label. Some don't. And many fall into a confusing middle category — they're not lying, exactly, but they're also not what most clinicians assume when they read the words.

This is the explainer most clinicians need but rarely get: what HIPAA actually requires of AI tools, what a Business Associate Agreement (BAA) is, what the difference is between "HIPAA compliant" and "HIPAA eligible," and the specific questions to ask any vendor before you let their tool touch a single piece of patient data.

This is not legal advice. It is, however, an honest summary of how HIPAA and AI actually intersect in 2026, written for clinicians who would rather understand the rules than memorize them.

What HIPAA actually is

HIPAA — the Health Insurance Portability and Accountability Act of 1996 — sets the federal floor for how Protected Health Information (PHI) must be handled in the United States. It's enforced by the Department of Health and Human Services, specifically through the Office for Civil Rights (OCR). HIPAA breaks into three rules that matter for AI:

  • The Privacy Rule governs when PHI can be used or disclosed. Roughly: only for treatment, payment, healthcare operations, or with patient authorization.
  • The Security Rule governs how electronic PHI must be protected. It requires administrative, physical, and technical safeguards including access controls, encryption, audit logging, and risk analysis.
  • The Breach Notification Rule governs what happens when something goes wrong. Covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI. HHS must be notified within 60 days for breaches affecting 500 or more people, and annually for smaller breaches.

For AI tools, the Security Rule does most of the heavy lifting. The current rule requires a documented risk analysis, access controls, and audit controls. Encryption is technically an "addressable" specification — you must implement it or document why an equivalent alternative is reasonable — but in practice any AI vendor handling PHI should encrypt in transit (TLS 1.2 or higher) and at rest (AES-256). A pending HHS proposal would make encryption and multi-factor authentication mandatory.

What counts as PHI

This is the part most clinicians get wrong. PHI is broader than people assume. It's not just "patient name plus diagnosis." Under HIPAA, PHI is any health information that can be used — directly or indirectly — to identify an individual.

The HIPAA Privacy Rule lists 18 specific identifiers that, when combined with health information, make data PHI:

  • Names
  • Geographic data smaller than a state (zip codes, street addresses)
  • Dates directly related to an individual (birth, admission, discharge)
  • Phone numbers, fax numbers, email addresses
  • Social Security numbers, medical record numbers, insurance plan numbers
  • License numbers, vehicle identifiers, device serial numbers
  • IP addresses, biometric identifiers
  • Photos and any other unique identifying number or code

If you paste a transcript that says "37-year-old male with hypertension" with no other identifiers into an AI tool, that's typically not PHI. If you paste "John Smith, 37, hypertension" — or even "the patient I saw in Newark today, hypertension" — that is PHI. AI tools that touch any of this data fall under HIPAA.

What a BAA is and why it matters

The single most important concept to understand is the Business Associate Agreement (BAA).

Under HIPAA, anyone who processes PHI on behalf of a covered entity (a healthcare provider, health plan, or healthcare clearinghouse) is a "business associate." That includes cloud hosting providers, EHR vendors, billing companies, and yes — AI tool vendors.

A BAA is a legally binding contract between the covered entity and the business associate that:

  1. Defines exactly how PHI can be used
  2. Specifies the technical safeguards required
  3. Names what happens in the event of a breach
  4. Establishes the business associate's legal liability

A vendor without a BAA is not HIPAA compliant for your use case, regardless of what their marketing says. The BAA is the legal instrument that makes the relationship compliant. No BAA, no compliance — even if the vendor has every technical safeguard in the world.

This sounds like a technicality, but it's not. The penalties for sharing PHI with a non-BAA-covered vendor are real: HIPAA civil money penalties, as adjusted for inflation effective January 28, 2026, range from $145 per violation at the lowest tier ("did not know") to $2,190,294 at the highest ("willful neglect, not corrected"), with a calendar-year cap of $2,190,294 for violations of an identical provision. (Since 2019, OCR has applied lower annual caps to the lower tiers as a matter of enforcement discretion.) A single careless paste of patient data into a non-compliant AI tool can technically be a violation.

"HIPAA compliant" vs "HIPAA eligible"

This distinction trips up many clinicians.

  • "HIPAA compliant" is a claim that a tool, as actually used, meets HIPAA requirements. This is almost always wrong as a blanket statement. Compliance depends on configuration, BAA coverage, and how you use the tool.
  • "HIPAA eligible" means the vendor will sign a BAA and the technology can be configured to support compliant use. The compliance still depends on you implementing it properly.

When OpenAI, Anthropic, Google, AWS, and Microsoft describe their healthcare offerings, they almost always use language like "support HIPAA compliance" or "HIPAA eligible" — not "HIPAA compliant." This is precise, not evasive. The tool can be used compliantly, but the vendor cannot guarantee that the customer's specific implementation is compliant.

If a vendor's marketing says "100% HIPAA compliant" with no qualifiers, that's a yellow flag. If they can't show you their BAA template, that's a red flag.

The ChatGPT, Claude, and Gemini question

The most common question clinicians ask is whether they can use ChatGPT, Claude, or Gemini to help with clinical work. The answer is more nuanced than the marketing suggests.

ChatGPT Free, Plus, and Business: Not covered by a BAA, so not for PHI. ChatGPT Enterprise and Edu: OpenAI says only customers with a sales-managed Enterprise or Edu account are eligible for a BAA; without one signed, treat them as off-limits for PHI too. ChatGPT Health, the consumer health service OpenAI launched in January 2026, is not covered by a BAA.

ChatGPT for Healthcare (launched January 2026): Can support HIPAA compliance. This is an enterprise-only product designed for hospitals and clinical environments. It includes BAA coverage, audit logs, customer-managed encryption keys, and data residency options. It is sales-managed only — there is no self-serve sign-up. Health systems named at launch included AdventHealth, Baylor Scott & White Health, Boston Children's Hospital, Cedars-Sinai, HCA Healthcare, Memorial Sloan Kettering, Stanford Medicine Children's Health, and UCSF.

OpenAI API (with BAA): Can support HIPAA compliance for developers building healthcare applications. Eligible customers can request a BAA.

Claude (Anthropic): The consumer products (Claude Free, Pro, Max, Team) are not covered by Anthropic's BAA. Anthropic offers BAA coverage for its API and for a "HIPAA-ready" configuration of its sales-assisted Enterprise plan. Products outside that scope — including the consumer apps — are not covered.

Google Gemini: The consumer Gemini products are not HIPAA compliant. Google Cloud offers HIPAA coverage through specific configured services (such as Vertex AI) that require a BAA and proper configuration.

The pattern across all of these: consumer chat interfaces are off-limits for PHI; developer APIs with proper BAA coverage and configuration can be used compliantly.

This means that if a clinician opens ChatGPT.com to ask "summarize this patient note," they're committing a HIPAA violation — even if they think the tool is "AI from a big company." The compliance lives in the contract, not the brand.

What a HIPAA-compliant AI tool actually does

When you evaluate any AI tool that will touch PHI, here's what you should expect to see — and what to push back on if it's missing.

Encryption in transit and at rest. TLS 1.2 or higher for data moving between systems. AES-256 for data stored on disk. This is the bare minimum. Any vendor who can't articulate this is not ready for healthcare.

A signed BAA. The vendor must offer one. Read it before you sign. It should specify what the vendor can and can't do with your data, breach notification timelines, audit rights, and indemnification terms. If a vendor says "we'll send you the BAA after you sign up," that's a process issue — but if they can't produce one at all, walk away.

Audit logs. The system must log who accessed what data and when, and those logs must be retained long enough to support breach investigation. (HIPAA requires security documentation to be kept for six years, and many organizations apply a similar horizon to audit logs.) Ask specifically: "Can you produce audit logs on demand showing every access to a specific patient's record?"

No training on your data. Most reputable healthcare AI vendors guarantee in writing that PHI is never used to train models. This should be in the BAA, not just the marketing page. If a vendor's contract allows them to use your data to improve models, that's a problem.

De-identification or zero retention. Many tools handle PHI by either de-identifying it before sending to the underlying language model, or by retaining no audio/text after processing is complete. Either approach can be compliant; both have tradeoffs.

Access controls. Multi-factor authentication, role-based access (so a receptionist can't see clinical notes she shouldn't), and the ability to revoke access immediately when staff leave.

Breach notification. Your BAA should require the vendor to notify you within 24-48 hours of discovering a breach. This gives you time to meet HIPAA's 60-day patient notification deadline.

Compliance is a partnership

Here's the part vendors don't always emphasize: buying a HIPAA-compliant tool doesn't make your practice HIPAA compliant.

The vendor is responsible for the security of their infrastructure — the servers, the encryption, the model architecture. That's their half of compliance.

You're responsible for everything else: training your staff to use the tool correctly, configuring access controls, documenting your risk analysis, conducting workforce HIPAA training that specifically covers AI usage, and ensuring patient consent where your Notice of Privacy Practices requires it.

A practice can buy a perfectly HIPAA-compliant AI tool and still be in violation if a staff member uses it carelessly — pasting full patient records into a different non-compliant chatbot, sharing logins, or skipping the audit logs review that HIPAA expects.

Questions to ask any AI vendor

A short, practical checklist before you sign anything. If a vendor can't answer all of these clearly, push harder or move on:

  1. Will you sign a BAA? If yes, can I review the template before signing the main contract?
  2. What encryption do you use in transit and at rest? (Expect: TLS 1.2+ and AES-256)
  3. Where is patient data stored, and for how long?
  4. Is patient data ever used to train your models or anyone else's? (The right answer is no, and it should be in the BAA)
  5. What audit logs do you maintain, and can I request them on demand?
  6. What's your breach notification timeline? (Should be 24-48 hours)
  7. Are you SOC 2 Type II certified? (Not required for HIPAA, but a strong signal of mature security practices)
  8. What happens to my data if I stop using the service? (Should be deleted within a defined timeframe)

A vendor that breezes through these questions confidently is doing the work. A vendor that hedges, deflects, or sends you to a sales call before answering is not.

The 2026 enforcement reality

In January 2025, HHS proposed the first major update to the HIPAA Security Rule in more than 20 years. It is still a proposal. As of September 2026, HHS lists final action as a long-term item targeted for July 2027, and the current Security Rule remains in effect. The proposal would require technology asset inventories and network maps, mandatory encryption and multi-factor authentication, and stronger business associate oversight — requirements that would squarely reach AI tools.

The practical takeaway: you don't need to wait for a final rule. Practices using AI tools that touch PHI should already maintain a documented inventory, run risk analyses on those tools, and maintain BAAs for each one — same as any other vendor.

For most practices, this is manageable. It just requires treating AI tools as serious vendors rather than convenience apps.

Practical recommendations

For solo practitioners and small practices:

  • Use only AI tools that explicitly offer BAAs covering your use case
  • Verify the BAA exists before you sign the main contract
  • Keep a simple list of every AI tool you use with PHI, and the date its BAA was signed
  • Train your staff (and yourself) that consumer chat tools — ChatGPT, Gemini, Claude — are off-limits for any patient data, ever

For larger groups:

  • Conduct a "shadow AI" inventory at least quarterly to catch unsanctioned tool usage
  • Include AI-specific modules in your annual HIPAA training
  • Run a tabletop exercise involving an AI vendor breach scenario
  • Update your Business Associate vendor list to flag which vendors are AI-specific

For everyone:

  • The right AI tool, used correctly, can save hours per day and improve documentation quality without compromising compliance
  • The wrong tool — or the right tool used carelessly — can cost your practice tens of thousands of dollars in penalties and damage your patients' trust
  • Compliance is not a checkbox. It's a continuous practice. Start small, document as you go, and don't take vendor marketing at face value

For a curated list of AI tools that have been vetted for HIPAA compliance and BAA availability, browse our directory. Each listing summarizes what the vendor publicly states about HIPAA and BAA availability, and flags when a BAA isn't publicly documented — confirm directly with the vendor before signing.

This article is informational, not legal advice. HIPAA enforcement and rules change regularly. Verify current vendor compliance status directly with vendors and consult qualified counsel for your specific practice.

Tags
hipaabaacompliancephiai-safetybusiness-associate-agreement
Keep reading

Related articles

HIPAA & Compliance

AI Disclosure Laws Are Here: What the 2026 State Rules Mean for Your Practice

HIPAA is no longer the only rulebook for clinical AI. In 2025 and 2026, California, Texas, Utah, Illinois, and others passed laws governing whether you tell patients an AI was involved in their care — and they hit AI scribes and patient-messaging tools directly. Here is what is actually in effect.

Reviews

Glass Health Review 2026: An AI Scribe With a Differential Diagnosis Engine (Read the Terms First)

Glass Health pairs ambient scribing with a cited differential diagnosis for $0 to $200 a month. We cover the features, pricing and independent studies, plus what most reviews skip: ads on the two cheapest plans, individual terms that authorize model training on PHI, and a BAA you have to opt in to.

HIPAA & Compliance

The AI Model Card in Your EHR: What HTI-5 Would Delete, and How to Read Yours First

Since January 2025, every certified EHR has had to publish a plain-language disclosure of what its built-in AI was trained on, how it was validated, and what it should never be used for — free, at a public link. ASTP/ONC has proposed deleting that requirement. Here is how to find yours before it goes, and why your standalone AI scribe was never covered by it in the first place.

HIPAA & Compliance

FDA Just Moved the Line Between a Clinical Tool and a Regulated Device

In January 2026, the FDA rewrote its clinical decision support guidance and pushed more AI software outside its oversight. Single recommendations are now allowed, documentation tools got clearer footing, and generative AI got almost no framework at all. Here is what changed — and why 'no FDA clearance needed' tells you nothing about whether a tool works.