Are AI Applications HIPAA Complaint?
Artificial intelligence is everywhere, and in healthcare, it’s no different. Chatbots now help patients understand lab results while AI tools summarize clinical notes in seconds. Each new application promises more efficiency and better care. It also raises a critical question for covered entities and business associates: Is this AI tool HIPAA compliant, and under what conditions?
The answer is not a simple yes or no. Compliance depends on what data the tool touches, how it stores and transmits that data, who controls the model, and how vendors handle business associate agreements. As AI technology evolves, privacy officers, compliance teams, and front-line staff must navigate gray areas that did not exist when HIPAA first took effect.
This guide walks through the intersection of HIPAA and AI so you can make informed decisions. You will review what HIPAA requires, how AI tools can complicate compliance, what is changing in 2026, and the practical steps you can take to keep your AI workflows, vendors, and workforce training aligned with HIPAA.
Table of Contents
- Understanding HIPAA and Artificial Intelligence
- HIPAA’s Role in Protecting Patient Data (PHI)
- Why AI Applications in Healthcare Must Meet HIPAA Standards
- The Importance of Business Associate Agreements (BAAs) for AI Vendors
- The Promise and Challenges of AI in Healthcare
- Why Industrial Maintenance Is a Great Career Choice
- Vendor Accountability and Data Governance
- Is ChatGPT HIPAA Compliant?
- HIPAA-Compliant AI Tools for Healthcare Organizations
- How to Ensure HIPAA Compliance in AI Health Apps
- Train for the Future of HIPAA and AI in Healthcare
Understanding HIPAA and Artificial Intelligence
HIPAA and artificial intelligence intersect any time an AI tool touches protected health information (PHI). HIPAA still sets the baseline rules for privacy, security, and breach notification, but AI changes how data is collected, processed, and shared behind the scenes. To use AI safely in healthcare, you must understand both the law and the technology.
HIPAA’s Role in Protecting Patient Data (PHI)
HIPAA establishes national standards for how covered entities and their business associates handle PHI. The Privacy Rule governs when PHI can be used or disclosed, while the Security Rule requires safeguards, like access controls, encryption, and audit logs, for electronic PHI (ePHI).
Together, these rules are designed to limit who can see patient data, how it’s protected, and how organizations respond if something goes wrong. Any workflow that stores, transmits, or analyzes PHI (including AI-driven workflows) must be compliant with this framework.
Why AI Applications in Healthcare Must Meet HIPAA Standards
AI tools don’t get a “pass” just because they’re innovative. Suppose an AI application is used to document visits, analyze radiology images, triage patients, or automate outreach using PHI. In that case, it must meet the same HIPAA standards as your EHR or billing system.
That means AI systems require appropriate administrative, physical, and technical safeguards: role-based access, secure hosting, encryption in transit and at rest, risk analyses, and ongoing monitoring for new threats.
Recent guidance and proposed updates to the Security Rule specifically highlight cybersecurity expectations for technologies that process ePHI, including AI-powered tools.
The Importance of Business Associate Agreements (BAAs) for AI Vendors
If you’re an AI vendor that creates, receives, maintains, or transmits PHI on your behalf, you must have a Business Associate Agreement (BAA) in place. The BAA legally requires the vendor to safeguard PHI, follow the Security Rule, flow down requirements to subcontractors, and report security incidents and breaches.
Many cloud and AI platforms now offer HIPAA-eligible services and will sign BAAs (for example, Azure OpenAI can be configured for HIPAA-regulated use), but that alone doesn’t guarantee compliance. Covered entities still need to confirm which features are covered by the BAA, how the vendor uses or trains on data, and whether any PHI leaves the protected environment through logs, model training, or third-party integrations.
The Promise and Challenges of AI in Healthcare
AI is reshaping healthcare in ways that go far beyond simple chatbots. In 2025, health systems are using artificial intelligence to scan imaging studies faster, spot subtle patterns in large datasets, and support clinical decisions in real time. With the right safeguards, these tools can help clinicians work more efficiently and give patients a better experience.
Here are some use cases of what AI in healthcare looks like:
Case #1: AI Diagnostics in Radiology and Pathology
AI diagnostics are one of the most visible use cases. In radiology and pathology, machine learning models can flag suspicious lesions, compare current and prior images, and prioritize urgent cases for human review. These tools don’t replace clinicians, but they can help catch issues earlier and reduce the risk of missed findings.
Case #2: Predictive Analytics for Risk and Population Health
Predictive analytics tools look across thousands of records to identify patterns and forecast risk. Health systems are using them to flag patients at high risk for readmission, sepsis, falls, or chronic disease complications. When used well, these models support earlier outreach, more targeted care plans, and better population health management.
Case #3: AI EHR Assistants and Clinical Documentation
On the documentation side, AI-powered EHR assistants are changing how clinicians chart. These tools can surface relevant data from the patient’s record, suggest orders, and help structure visit notes. They give clinicians more time to focus on patients instead of screens.
Case #4: Voice-to-Text and Ambient Transcription Tools
Voice-to-text transcription and ambient “listening” tools can capture the conversation during a visit and generate a first draft of the clinical note. Some systems also suggest diagnoses, billing codes, or follow-up tasks based on what was said. This can significantly cut documentation time, but it also means sensitive audio and text data are flowing through AI systems.
As powerful as these tools are, every one of these use cases depends on access to sensitive health information. As AI becomes more deeply embedded in clinical workflows, organizations must ask harder questions about data privacy, security, and vendor practices. That’s where HIPAA and AI compliance come together.
How Enterprise-Grade AI Can Meet HIPAA Standards
Some enterprise AI platforms are designed to be used with PHI when properly configured. Examples include Azure OpenAI and Google Vertex AI, which can run models in HIPAA-eligible environments and sign BAAs.
When combined with strong internal controls, they can support compliance through:
Encryption in transit and at rest
Network and access controls (e.g., VPCs, role-based access)
Logging and audit trails for who accessed what data and when
Clear data retention and deletion policies
Even then, the platform is only one piece of the puzzle. You still need policies, technical safeguards, and training to make sure staff use these tools correctly.
Vendor Accountability and Data Governance
HIPAA compliance with AI is about accountability. Strong data governance, like knowing where PHI lives, who can access it, and how it’s used, is essential before implementing any AI workflow.
Covered entities must:
Verify whether the vendor is a business associate and get a signed BAA if PHI is involved
Understand how the vendor processes, stores, and protects data (including any model training or subcontractors)
Integrate the AI tool into their existing risk analysis, access control, and incident response plans
Checklist: Before You Adopt an AI Tool
Before rolling out any AI in a clinical workflow, make sure you can answer “yes” to questions like:
Does the vendor sign a BAA?
Is PHI encrypted at rest and in transit?
Where is data stored, and for how long? (logs, backups, training data)
Can we restrict access with roles, SSO, and network controls?
Are there audit trails so we can see who accessed what and when?
Does the tool train on our data by default, or can we disable that?
Have we included this system in our HIPAA risk analysis and policies?
If you can’t get clear answers, the tool probably isn’t ready for PHI.
Is ChatGPT HIPAA Compliant?
Short answer: No. ChatGPT and similar public AI tools (like Gemini or Claude) are not HIPAA-compliant. They don’t sign Business Associate Agreements (BAAs), and their standard terms don’t guarantee the protections required for PHI. That means you cannot safely enter identifiable patient information into these public interfaces.
Why Consumer AI Tools Like ChatGPT Aren’t HIPAA-Compliant
Using AI with PHI can expose organizations to HIPAA privacy and security violations. Public AI tools are built for general use, not regulated healthcare data.
They typically:
Don’t offer a HIPAA BAA for their standard web or mobile apps
May log or retain prompts and outputs for service improvement
Don’t give covered entities full control over data residency, retention, or access
New Limits on Health-Related Advice From ChatGPT
In 2025, OpenAI began restricting ChatGPT from providing personalized health and legal advice in many regions, reflecting growing concern about safety and liability. That change is a reminder that consumer AI tools are not clinical decision-support systems and shouldn’t be treated as such.
Even where those restrictions don’t apply, organizations must remember that public ChatGPT is not HIPAA-compliant and should never be used to process identifiable patient information.
HIPAA-Compliant AI Tools for Healthcare Organizations
When people talk about HIPAA-compliant AI tools, they’re really talking about a combination of technology and legal/technical safeguards. No AI platform is magically compliant on its own.
It becomes part of a HIPAA-compliant solution when:
The vendor signs a Business Associate Agreement (BAA) if they create, receive, maintain, or transmit PHI.
PHI is protected with encryption in transit and at rest.
You have access controls, audit logs, and risk management processes around how the tool is used.
TIP: If a vendor refuses to sign a BAA, they legally cannot handle PHI under HIPAA.
Which AI Tools Are HIPAA-Compliant? *
AI Tool / Platform | Type | HIPAA-Eligible When… | Notes |
Azure OpenAI Service | Cloud AI (Microsoft Azure) | Used within a HIPAA-covered Azure subscription with a Microsoft BAA in place. | Access via Azure; must follow Microsoft’s HIPAA configuration guidance. |
Google Vertex AI | Cloud AI (Google Cloud) | Deployed as a covered service under Google Cloud’s HIPAA BAA and secured per best practices. | Supports VPC, CMEK, and detailed logging to help meet HIPAA safeguards. |
AWS Generative AI Services | Cloud AI (AWS) | Run in an AWS HIPAA account using HIPAA-eligible services under an AWS BAA. | Follows AWS’s shared responsibility model; you still configure security. |
OpenAI API (Not ChatGPT) | API access to models | Used under an enterprise/API agreement with a signed BAA and zero/controlled data retention. | Public ChatGPT UI is not HIPAA-compliant; only API with BAA can be. |
Keragon | AI-powered workflow automation | Used as a healthcare automation platform under its HIPAA-focused terms and safeguards. | Built specifically for healthcare workflows and HIPAA-aligned automations. |
*When properly configured, limited to HIPAA-eligible services, and covered by a signed BAA. Always confirm with the vendor and your compliance team.
This table isn’t exhaustive, but it shows the pattern: look for HIPAA-eligible cloud services plus a BAA, then layer your own policies, access controls, and training on top.
How to Ensure HIPAA Compliance in AI Health Apps
The way AI tools collect, store, and transform data can easily create new compliance risks. To keep your AI health apps aligned with HIPAA, it helps to follow a clear, step-by-step approach:
1. Conduct an AI-Specific Risk Assessment
Start by treating each AI tool like a new system that must go through your standard HIPAA risk analysis, plus some AI-specific checks. For every AI workflow, document:
What PHI goes in (text, images, audio, video)
Where that data travels and is stored (logs, caches, backups, training sets)
Who can access inputs, outputs, and model configurations
What could go wrong (data leakage, biased outputs, model misuse, vendor breach)
You can align this work with your existing HIPAA Security Rule risk assessment and use the NIST AI Risk Management Framework (AI RMF) as a reference. NIST’s AI RMF outlines how to govern, map, measure, and manage AI risks across the lifecycle so organizations can deploy “trustworthy” AI systems in high-stakes areas like healthcare.
2. Encrypt All PHI in Transit and at Rest
Any AI system that handles PHI should follow HIPAA’s technical safeguards for ePHI, including strong encryption. That means:
Encryption in transit (e.g., TLS) for data moving between clients, APIs, and back-end services
Encryption at rest for databases, object storage, model logs, and backup media
Clear keys and key-management policies (who can decrypt what, and how quickly access can be revoked)
Don’t forget “hidden” data stores like log files, prompt histories, and temporary caches inside AI services. If PHI can appear there, it needs the same protection as your EHR. Strong encryption, combined with access controls and monitoring, is one of the core recommendations for staying HIPAA compliant in the age of AI.
3. Review Vendor BAAs and System Access Controls
Next, look closely at your vendors and how people access the AI tool:
BAA first: If the vendor creates, receives, maintains, or transmits PHI, they’re a business associate. You need a signed Business Associate Agreement that spells out security responsibilities, incident reporting, and subcontractor obligations.
HIPAA-eligible services only: For cloud or AI platforms, confirm which services are HIPAA-eligible under the BAA and restrict PHI to those components.
Access controls: Enforce least-privilege access using SSO, role-based permissions, and, where possible, network controls (VPCs, IP allowlists, private endpoints).
Audit trails: Ensure the tool records who accessed the system, what data they touched, and what actions they took so you can investigate incidents and meet HIPAA’s audit requirements.
If a vendor won’t sign a BAA or can’t explain how they protect PHI, that tool should not be used with patient-identifiable data.
4. Create Internal Policies for AI Usage and Workforce Training
Finally, even the most secure AI platform can be misused if staff don’t know the rules. Create clear internal policies that answer questions like:
Which AI tools are approved for PHI, and which are strictly off-limits (e.g., public ChatGPT)?
What types of data are allowed in prompts, uploads, and training sets?
Who is responsible for validating AI outputs before they influence patient care, billing, or documentation?
How should employees report suspected AI-related privacy or security incidents?
Back those policies with regular HIPAA and AI training so your workforce understands the risks and practical do’s and don’ts.
Train for the Future of HIPAA and AI in Healthcare
HIPAA and AI are moving targets. In 2025, HHS and the Office for Civil Rights (OCR) are sharpening their focus on how AI tools handle PHI, discrimination risk, and cybersecurity.
Recent guidance makes it clear that HIPAA still applies to AI-driven decision tools, and proposed updates to the HIPAA Security Rule emphasize stronger encryption, risk management, and incident response in a world where AI, cloud, and ransomware are everyday realities.
Beyond HIPAA, states are stepping in with new privacy and AI laws that impact healthcare, from transparency and accountability requirements to rules for health insurers and patient-care decision tools.
As more states regulate the use of AI in clinical and insurance settings, healthcare organizations can expect growing expectations around documenting how AI is used, monitoring for bias, and transparency with patients when AI supports care decisions.
At the same time, explainable AI (XAI) is becoming more important for audits and oversight. Regulators, internal compliance teams, and external auditors all need to understand why an AI system recommended a certain diagnosis, risk score, or coverage decision.
Frameworks from NIST and emerging XAI research in healthcare highlight explainability as a pillar of trustworthy, auditable AI. This makes it easier to investigate errors, demonstrate fairness, and show that AI-assisted decisions still meet HIPAA and civil rights requirements.
Stay ahead of HIPAA and AI compliance requirements by training your healthcare team with 360training’s expert-led online HIPAA courses. As an online training provider with over 20 years of experience educating the workforce in regulatory compliance, we offer a full catalog of HIPAA training courses tailored to the needs of various healthcare roles. Employees will be able to study at their own pace, whenever and wherever is best.
Enroll today to get started.







