HIPAA AI Compliance: What Healthcare Teams Must Do

Photo: Tima Miroshnichenko / Pexels
Key takeaways
- Any AI tool that touches PHI needs a signed BAA before that data goes near it, no exceptions.
- Only enterprise tiers from OpenAI, Anthropic, Google and Microsoft currently offer a BAA.
- Using a tool with PHI without a BAA is a violation, even if no breach occurs.
- De-identification doesn't automatically remove the need for a BAA - when in doubt, sign one anyway.
- Document policies, training and BAAs; HIPAA enforcement weighs good-faith effort heavily.
HIPAA doesn't mention AI by name, and that's exactly where healthcare teams get caught out. Its rules apply fully to any software that creates, receives, maintains or transmits protected health information (PHI), and an AI scribe, summariser or chatbot is no exception. HIPAA AI compliance comes down to one hard rule: if a tool touches PHI, even indirectly, you need a signed contract with the vendor before that data goes anywhere near it. Skip that step and you're in violation regardless of whether a breach ever happens. Here's what that means in practice, for your policy, your vendor list and your paperwork.
What counts as PHI touching an AI tool?
More than you'd think. A name and an appointment time is PHI. A voice recording of a consultation is PHI, even before anyone transcribes it. An AI scribe listening to a clinical visit, a chatbot summarising patient messages, or an AI tool auto-drafting a discharge note all count, whether the AI 'sees' the data directly or a human pastes it in manually. The test is about the data, not the interface, and it doesn't matter whether the AI tool is the main system of record or just a side utility someone downloaded to save time.
The BAA requirement, in plain terms
Any AI vendor processing PHI on your behalf is what HIPAA calls a Business Associate. You must have a signed Business Associate Agreement with them before any PHI flows into their system, not after a trial period, not once you're sure it's useful. The BAA obliges the vendor to safeguard the data, restrict its use to the purposes you've agreed, and report breaches on a defined timeline. Without one, using the tool with PHI is a violation on its own, separate from whatever else does or doesn't go wrong afterwards.
Which AI tools actually offer a BAA?
Only the enterprise tiers, and only some of them. OpenAI offers a BAA on ChatGPT Enterprise; Anthropic offers one for Claude for Enterprise on request; Google covers it through Vertex AI and Workspace Enterprise; Microsoft covers it via Azure OpenAI and Microsoft 365 Copilot's higher licence tiers. Consumer accounts and standard business tiers from all four do not cover PHI, whatever their marketing pages imply about 'enterprise-grade security.' Always verify the specific product and tier directly with the vendor before rollout, since terms and tier names both change.
Does it matter if the data is de-identified first?
It can change the analysis but don't assume it lets you skip the BAA. HIPAA's Safe Harbor and Expert Determination methods for de-identification are specific and strict; simply removing a patient's name isn't enough if enough other detail, a rare condition, a specific appointment date, a small clinic's patient count, remains to re-identify them. If there's any doubt about whether your de-identification method meets the standard, treat the data as PHI and get the BAA signed anyway. It's the cheaper mistake to make, and the one that's far easier to defend later.
What about AI used only for admin tasks, like billing?
Billing codes, insurance claims and payment records can qualify as PHI too, especially when they're tied to a specific diagnosis or procedure. An AI tool that only touches the billing side of a practice isn't automatically exempt just because it never sees a clinical note. If the data includes anything identifying a patient alongside health-related information, a CPT code, a diagnosis-linked claim, a provider's note attached to an invoice, the same BAA requirement applies. Treat 'it's just for billing' as a reason to check more carefully, not a reason to skip the review entirely.
What your AI usage policy has to say
A generic AI policy isn't enough here. For a healthcare setting, it should state explicitly: PHI must never enter an AI tool without a signed BAA on file; approved clinical AI tools are named individually, by product and tier, not described generally as 'the AI tools we use'; and any AI-assisted clinical documentation gets reviewed by a licensed clinician before it enters the record. See our compliance hub for HIPAA for the fuller regulatory picture, or use ModelCharter's policy generator to produce one with these clauses built in.
A trial that nearly went practice-wide
A clinic operations manager at a fifteen-provider practice once trialled an AI scribe to cut down on after-hours charting. It transcribed and summarised consultations well, and clinicians liked it immediately; within two weeks, three more providers had asked to join the trial. It nearly went practice-wide before anyone asked whether the vendor would sign a BAA. It wouldn't, not on the tier being trialled, only on a pricier plan nobody had budgeted for. The practice switched to the enterprise tier, three weeks later than planned, but before a single real consultation had been recorded through the unsigned trial. The lesson stuck: check the BAA before the demo, not after clinicians are already asking to keep it.
What happens if PHI enters a tool without a BAA?
It's a HIPAA violation the moment it happens, independent of whether the data ever leaks. Enforcement looks at whether the covered entity made a reasonable, documented effort to comply, so the practical damage of an unreported gap is twofold: the underlying violation, and the absence of any paper trail showing you tried to prevent it. Both make a Department of Health and Human Services inquiry considerably worse than it needed to be, and both are entirely avoidable with a signature obtained before the first real patient conversation touches the tool.
Keep the paperwork where you can find it
Enforcement bodies look for good-faith effort as much as perfect outcomes: written policies, staff training records, signed BAAs on file, and a repeatable process for vetting new AI tools before anyone uses them clinically. Keep the BAAs somewhere findable, not buried in an eighteen-month-old inbox thread that only one former employee could ever locate. Check any AI tool you're considering against our AI Tool Risk Directory before the trial starts, and cross-reference against our GDPR and AI guide if any of your patients are also EU residents, since both sets of rules can apply to the same tool at once.
| Vendor | Tier that offers a BAA | Consumer/standard tiers |
|---|---|---|
| OpenAI | ChatGPT Enterprise | Free, Plus, Team - no BAA |
| Anthropic | Claude for Enterprise (on request) | Free, Pro - no BAA |
| Vertex AI, Workspace Enterprise | Free Gemini, standard Workspace - no BAA | |
| Microsoft | Azure OpenAI, Microsoft 365 Copilot (higher licence tiers) | Standard M365 without Copilot add-on - no BAA |
“A business associate agreement doesn't transfer a covered entity's own responsibility for protecting patient data - it sits alongside it.”