OrchestriAI
Back to the field guide
HealthcareExplainer5 min read

What HIPAA actually says about AI tools in your practice

A BAA matters when an AI vendor handles PHI, but the agreement, product eligibility, configuration, and full data path all need to be checked.

By Shariq Riaz

In this guide

A BAA matters when an AI vendor handles PHI, but the agreement, product eligibility, configuration, and full data path all need to be checked.

3 sections5 cited sources5 min read

"HIPAA compliant" in a product page is not enough to approve an AI tool for patient data. You need to know which product and features are covered, what data they process, and how the deployment is configured.

What HIPAA governs

HIPAA applies to covered entities, business associates, and relevant subcontractors when they create, receive, maintain, or transmit Protected Health Information. PHI is individually identifiable health information held in that regulated context, such as a patient name paired with a diagnosis or appointment record. HHS explains the relationship and contract requirements in its business associate guidance.

If an AI vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity or business associate, the parties generally need a Business Associate Agreement. A BAA is necessary in that relationship, but it does not make every feature or configuration safe to use.

Where the product check breaks down

Product names alone are not enough. OpenAI lists specific HIPAA-eligible products and features; Anthropic says its BAA covers qualifying services but not ordinary Claude Free, Pro, Max, or general Claude for Work chat products in its BAA guidance; and Google documents which Workspace Gemini configurations can support HIPAA workloads.

Pasting a patient note into a consumer or otherwise uncovered AI product can create an impermissible disclosure. Check the current contract and eligible-services list rather than assuming a vendor's consumer, business, and API products have the same status.

This doesn't make AI off-limits for clinical or administrative work. It means the specific service must be approved for the intended data and use. Confirm the signed BAA, eligible features, retention settings, subprocessors, access controls, and whether the tool sends data to another service.

Some administrative tasks, such as drafting generic training material, can be done without PHI. Other administrative work contains patient-specific data even when no clinical decision is involved. Classify the data, not just the task name.

The practical checklist

Before using an AI tool with PHI: Is your organization covered by the right BAA? Is the exact product and feature eligible? Are retention, logging, connectors, and access configured correctly? Does the workflow send data to any uncovered service? Have you completed the required risk analysis?

If the vendor will not cover the service under a BAA, do not send PHI to it on behalf of a regulated organization. De-identification or a different eligible service may be an option, but that decision belongs in the organization's privacy and security review.

A signed agreement is only one control. HHS treats risk analysis as foundational, so the review also has to cover the actual architecture and operating process.

References used in this article

5 links
Shariq Riaz

Written by

Shariq Riaz

AI Automation Engineer · CPHIMS · PMP · CBAP

11 years in enterprise IT at Fortune 500 companies. Now I build custom AI automations for healthcare, real estate, financial services, and freight forwarding teams.

Have a system in mind?

Bring the workflow, constraint, or integration problem. I’ll help you map the practical next step.

Book a call