Healthcare organizations can only use AI while staying HIPAA compliant if PHI is properly safeguarded, HIPAA requirements are followed, robust BAAs are secured, and vendors provide appropriate security controls. While AI promises potential efficiency and care improvements, improper use can create serious HIPAA compliance risks.
In this guide, we'll explain how AI and HIPAA intersect, the risks healthcare organizations should understand, and the best practices, like taking online HIPAA courses , for using AI tools while maintaining compliance.
Table of Contents
- How AI Is Transforming Healthcare Operations
- Common AI Applications in Healthcare Settings
- Benefits of AI in Healthcare Delivery
- Risks of AI Use in Healthcare
- Why HIPAA Compliance Matters When Using AI
- Are Popular AI Tools HIPAA Compliant?
- Key Questions to Ask Before Using AI With PHI
- Business Associates and AI Vendor Responsibility
- Business Associate Agreements and AI Vendors
- Security Safeguards AI Tools Must Have
- Protecting Patient Privacy When Using AI
- Data Integrity and Transparency in AI Systems
- Risk Assessments for AI Use in Healthcare
- Best Practices for Maintaining HIPAA Compliance With AI
- Why HIPAA Training Is Essential When Using AI
- Choosing HIPAA Training That Covers Emerging Technologies
How AI Is Transforming Healthcare Operations
Healthcare systems face rising costs, staffing shortages, increasing patient volumes, and growing demand for personalized care, so it may be no surprise that many are turning to AI-powered tools to streamline workflows and support clinical decision-making.
Roughly half of U.S. hospitals now deploy generative AI in clinical, administrative, or patient-facing roles. AI-powered tools may have the potential to improve efficiency, reduce costs, and improve patient outcomes.
Common AI Applications in Healthcare Settings
At this stage, AI adoption in healthcare is strongest where it reduces documentation burdens, automates routine workflows, and improves access to information. Stages of adoption also vary based on the degree of risk presented by a particular application.
Administrative Applications
Administrative AI applications carry the lowest risk level for adoption, since they carry little risk of immediate patient harm and are capable of granting significant operational efficiencies. It’s no surprise we’re seeing near-universal institutional pilots for various administrative functions, including in areas like:
- Documentation: According to the AMA , 21% of physicians reported using AI for documenting billing codes, medical charts, and visit notes, 20% for discharge instructions, care plans, and progress notes, and 12% for chart summaries.
- Revenue Cycle Management: According to an HMFA-FinThrive poll , 46% of hospitals and health systems use AI to streamline claims processing and accelerate reimbursement.
- Administrative Process: AI use for tasks like patient intake, scheduling, managing post-visit follow-ups, and coordinating internal communication can reportedly save clinicians 70 minutes per patient visit.
Patient-Facing Applications
Patient-facing applications are considered medium risk because they can directly affect patient safety, trust, and outcomes if used for symptom assessment or care advice.
As a result, broader chatbot adoption is focused on more low-risk customer service functions like:
- Appointment scheduling and reminders
- Routine receptionist questions
- Medication refills and reminders
- Post-care instruction reminders
According to the AMA, only 10% of physicians reported using patient-facing chatbots for customer service functions, but 14% report using translation services.
Clinical Applications
Clinical AI applications are the highest risk because using the technology in diagnosis, treatment, or prioritization can have a direct consequence on patient safety. Additionally, clinical applications require larger amounts of sensitive healthcare data for informed decisions, increasing the privacy and security concerns.
As a result, clinical applications are more focused on decision support for providers rather than any type of automation.
Clinical applications in current use include:
- Diagnostic Imaging Analysis : This is one of the most mature and widely adopted AI applications, able to support earlier detection of disease. Up to 90% of healthcare systems use AI-supported diagnostic analysis in radiology and pathology.
- Predictive Analysis : Drawing on EHR data, AI models support triage and care management by identifying high-risk patients and predicting the likelihood of readmission or deterioration. This application is in common usage; 65% of hospitals and 70% of healthcare providers report using predictive analytics for triage.
- Surgical Robotics : AI-assisted robotics are being used to improve precision and visualization in minimally invasive surgery, providing real-time guidance to surgeons who remain in control.
- EHR Agentic AI : The newest applications are being positioned to identify documentation gaps, summarize records, draft follow-up suggestions, and integrate the latest clinical guidelines. Vendors are advocating a cautious approach to adoption.
According to the AMA, 12% of physicians report using AI for assistive diagnosis and 13% for medical research and standards of care.
Benefits of AI in Healthcare Delivery
By automating repetitive tasks and reducing administrative burdens, AI has the potential to alleviate staffing shortages in the face of rising patient demand by saving time. It could also reduce human error, such as overlooking details in a long and complicated medical history. It may even improve access to care.
However, AI is not without risk, so healthcare organizations must balance the potential of innovation against their very real compliance and patient care responsibilities.
Risks of AI Use in Healthcare
One of the biggest concerns with AI use in healthcare is data privacy, security, and integrity. Weak access controls, unsecured integrations, or insufficient vendor oversight can expose sensitive patient data to bad actors.
While AI has the potential to reduce human error, it comes with its own inaccuracies. AI outputs can contain misinformation, reflect the bias present in training data, or generate recommendations without enough clinical context. Overreliance on AI, especially without human review, could allow these errors to go unnoticed.
In healthcare, the stakes of those errors and exposures are higher than in other industries because decisions can directly affect patient safety, treatment outcomes, privacy rights, and regulatory compliance. Flawed AI outputs can have serious medical, legal, and financial consequences in healthcare.
Why HIPAA Compliance Matters When Using AI
Any time you’re using AI with protected health information (PHI), the Privacy and Security requirements set forth by the Health Insurance Portability and Accountability Act (HIPAA) must be followed. HIPAA requirements apply.
HIPAA defines PHI broadly as any piece of data that can directly or indirectly lead someone to connect a patient’s identity with their medical records. The obvious examples include a patient’s name, contact information, or identifying number, but even something like a clinic location and appointment time can count.
If AI is used to process, store, or analyze PHI, the covered entity is liable for ensuring that the AI application is storing, transmitting, and using PHI in a HIPAA-compliant manner. If unauthorized disclosures, data breaches, or improper data sharing result from using AI with protected health information, the covered entity will be held responsible for a HIPAA violation.
While the Office of Civil Rights hasn’t enforced HIPAA over AI use yet, they haven’t been shy in the past about holding covered entities responsible for HIPAA violations that occurred as a result of third-party vendors of new technology. Innovation isn’t exempt from HIPAA compliance.
Are Popular AI Tools HIPAA Compliant?
When someone asks, “Is AI HIPAA compliant?” one of the first things that springs to mind is the use of consumer AI tools like ChatGPT or Google. The answer in those cases is a resounding “no.”
For AI use to be HIPAA compliant, one of the most important requirements is for the vendor to sign a business associate agreement (BAA) with the covered entity, specifying how protected health information (PHI) will be safeguarded and how each party will meet its HIPAA obligations. While some AI vendors now offer BAAs for certain enterprise and healthcare-focused products, many consumer AI tools are not designed for HIPAA-regulated use and do not provide the contractual, administrative, and technical safeguards healthcare organizations require. Organizations should never assume an AI tool is HIPAA compliant without verifying that a BAA is available and that the product includes appropriate security controls.
Key Questions to Ask Before Using AI With PHI
Later, we’ll dive into all the AI healthcare HIPAA requirements that covered entities should look for and the reasoning behind them, but for now, let’s start with a basic screening checklist for AI vendors for healthcare organizations.
Before using AI with protected health information, it’s absolutely essential to ask the following:
- Is the vendor willing to sign a business associate agreement? If not, no other questions matter. You cannot proceed with this vendor’s services.
- Does the vendor have existing business associate agreements? It’s a good sign if they’re already exercising HIPAA compliance in operations, but scrutinize their operations and BAA terms.
- How will the AI system collect, store, process, and transmit PHI? Understanding the data flow allows you to examine all exposure points and potential risks.
- How is patient data encrypted in transit and at rest? HIPAA requires encryption for data in both.
- What access controls and authentication measures are in place? PHI should be protected from unauthorized access, and each individual’s access should be limited to the minimum necessary for their role.
- Will the vendor use AI to train or improve AI models? Organizations need to understand how PHI is used to determine whether it exceeds permitted uses and patient expectations.
- Can an organization limit or opt out of data retention and model training? It’s important to maintain control over how long PHI is retained and how it is used.
- What privacy-preserving technologies are used to protect sensitive information? These can help to mitigate the privacy risks while allowing utility.
- Has the vendor completed independent security audits or compliance certifications? This can be evidence that the vendor takes security and compliance standards seriously and is confident enough in their system to allow independent validation.
- How are audit logs, monitoring, and incident tracking handled? These are necessary maintenance measures for HIPAA compliance.
- What is the vendor’s breach notification and response process? Delayed or ineffective responses on a vendor’s behalf increase a covered entity’s regulatory and legal exposure.
- Does the vendor rely on subcontractors? If so, how are vendors monitored for HIPAA compliance? Many AI vendors do use downstream services, and they’re responsible for ensuring HIPAA compliance throughout the ecosystem.
- Can the AI system explain or document how outputs are generated? Transparency is critical for validating life-or-death outputs, investigating errors, and supporting clinical decision-making.
- How does the vendor address inaccurate, biased, or inconsistent AI outputs? These can affect patient safety and compliance, so organizations need to understand how vendors test, validate, and monitor their models’ performance.
- What measures are used to prevent unauthorized changes and maintain data integrity? This is another key HIPAA requirement, but corrupted or altered data could undermine the utility of AI entirely.
- How often are security updates, risk assessments, and compliance reviews performed? Ongoing assessments are necessary to address evolving threats.
- What employee training and security policies does the vendor implement internally? Human error within the vendor is a real threat without strong training and policies.
- Can the organization fully delete or retrieve its data if the contract ends? HIPAA requires business associates to return or destroy PHI upon contract termination.
By adopting an AI vendor, a healthcare organization is essentially putting its HIPAA compliance in someone else’s hands, so due diligence before adoption should be rigorous.
Business Associates and AI Vendor Responsibility
HIPAA requires covered entities (CEs) to treat any third-party vendor that handles PHI while providing services to be treated as Business Associates (BAs) . Any AI services that involve protected health information will, therefore, qualify as a business associate.
Under HIPAA, covered entities and business associates share responsibilities for keeping PHI secure and private. One of the business associate’s responsibilities requires them to ensure that any subcontractors downstream meet HIPAA obligations as well.
Business Associate Agreements and AI Vendors
When AI vendors have access to PHI, covered entities must secure a BAA before any PHI is disclosed. Sharing PHI with a vendor who has not signed a BAA is a common type of HIPAA violation .
A compliant BAA should include:
- How the BA can use PHI. It should explicitly prohibit using PHI for anything beyond providing agreed-upon services to the CE.
- The BA’s agreement to safeguard PHI using administrative, physical, and technical measures.
- Mandatory reporting of unauthorized PHI use or breaches to the CE without reasonable delay.
- The BA’s obligation to ensure that all subcontractors and agents handling PHI will follow the same requirements as the BA.
- The BA’s duty to destroy or return all PHI, including what’s held by subcontractors, upon termination of their contract. It should also require a certificate of destruction to be furnished.
Given the stringency of a business associate agreement, AI vendors may not wish to commit to the necessary level of liability. That’s why you must always have a signed BAA in hand before providing any PHI to an AI service.
Security Safeguards AI Tools Must Have
Any AI tool used by a healthcare organization must have security practices that align with all parts of the HIPAA Security Rule .
That means an AI vendor must:
- Implement safeguards controlling physical access to systems and facilities,
- Create technical access controls to restrict electronic access to PHI and implement related oversight mechanisms,
- Leverage encryption and other measures to protect PHI at rest and in transit,
- Create administrative policies and procedures to manage HIPAA-compliant security,
- Conduct regular risk analyses for threats and gaps in security, and
- Implement ongoing risk management to minimize the likelihood of a breach or unauthorized disclosure.
Protecting Patient Privacy When Using AI
AI tools must also be fully and proactively compliant with the HIPAA Privacy Rule , meaning healthcare organizations using AI vendors should:
- Leverage safeguards like de-identification when possible, removing personal identifiers from patient records so data can be analyzed without PHI disclosure.
- Follow the “minimum necessary” standard when handling PHI, only accessing the specific data required to perform an intended function.
- Provide transparency on healthcare data usage to patients and providers with privacy policies and data usage disclosures.
- Use privacy-preserving technologies like encryption, secure cloud environments , access controls, and federated learning to safeguard PHI while allowing AI systems to generate insights.
Data Integrity and Transparency in AI Systems
Another component of HIPAA’s Security Rule is that covered entities and business associates are bound to protect ePHI from being changed, corrupted, or destroyed in an unauthorized manner. In other words, they’re required to preserve the integrity, accuracy, and reliability of patient data.
Safe AI use in healthcare requires data integrity and auditability. Healthcare organizations must be able to track how data is collected, processed, modified, and used within AI workflows so they can identify errors, detect hallucinations, and monitor system performance for safety. Auditability is also an important component of supporting regulatory compliance and investigating security or privacy incidents. Consistent data standards across systems improve interoperability and reduce confusion.
Healthcare organizations, in particular, must demand transparency from any AI tools. While it’s a matter of safety, as discussed above, it’s also an issue of compliance and patient trust. Patients, providers, and regulators will expect healthcare organizations to be able to account for how AI systems use patient data and influence decisions moving forward. The “black box” model of AI will not hold for this level of scrutiny.
Risk Assessments for AI Use in Healthcare
HIPAA’s Security Rule requires covered entities and business associates to run regular risk assessments on their systems to discover new threats, identify vulnerabilities, and measure the likelihood of security incidents. It’s the only way to keep ahead of bad actors who are constantly innovating to outsmart current security measures.
Healthcare organizations should ensure both internal and vendor-related risk assessments to understand whether vendors can meet both HIPAA and organizational security requirements before implementing AI tool use. Internal risk assessments should examine how AI systems will interact with existing workflows and impact operational or clinical processes. Vendor risk assessments should focus on the vulnerabilities introduced by the third-party AI provider, including an examination of their security controls, compliance practices, data storage methods, subcontractor relationships, and breach response procedures.
However, AI risk management can’t be treated as a one-time exercise during procurement. Since all software systems evolve over time, ongoing monitoring, regular auditing, and security testing are necessary to check for new threats or vulnerabilities introduced either by the AI tools or the internal systems they interface with. Through continuous analysis, healthcare organizations can manage the long-term operational, privacy, and compliance risks associated with AI.
Best Practices for Maintaining HIPAA Compliance With AI
When seeking to maintain HIPAA compliance for AI tools, the broad strokes of best practice include:
- Vendor Screening : Thoroughly investigate AI vendor security, privacy, integrity, and transparency practices and only move forward if they’re in line with HIPAA compliance and organizational standards.
- HIPAA Training : HIPAA compliance is only ever as strong as your employees’ understanding, especially when applying new technologies. Give your workforce a strong foundation in HIPAA requirements and best practices.
- Clear Policies : Publish clear policies for your workforce on what AI technologies to use, acceptable and unacceptable use cases, and best practices for prompting.
- Regular Audits : Conduct regular audits to ensure that privacy and security protocols are being used as intended.
Remember, HIPAA compliance is an ongoing process that must be maintained regularly.
Why HIPAA Training Is Essential When Using AI
The single-biggest source of HIPAA violations is human error, so HIPAA training for your workforce is a critical step in how to use AI while staying HIPAA compliant.
HIPAA training helps staff understand AI-related privacy and security risks so they can avoid non-compliant behaviors that lead to HIPAA violations. HIPAA training can’t be seen as a formality. It’s a safeguard against human mistakes.
Choosing HIPAA Training That Covers Emerging Technologies
As healthcare technology continues to evolve, HIPAA training programs must keep pace with the growing use of digital tools, cloud platforms, and AI-driven systems.
Concise, up-to-date training programs should clearly explain core HIPAA requirements, data protection responsibilities, best security practices, and common risk scenarios in a way that helps employees understand and apply HIPAA compliance in daily operations, regardless of what tools are being used. Role-specific HIPAA training improves understanding and retention by using real-world examples relevant to each individual.
Our role-specific HIPAA training courses provide current, accessible, and practical compliance education tailored to their role. For example, our HIPAA for Healthcare courses target roles like healthcare workers, office staff, and dental staff , and HIPAA for Business Training courses are designed for the challenges faced by roles like healthcare HR personnel, business associates, and sales reps.