HIPAA, passed in 1996, sets rules to protect health information that can identify a patient. HIPAA has two main sets of rules for data protection: the Privacy Rule and the Security Rule. The Privacy Rule controls how health information is used and shared. The Security Rule sets safeguards to keep electronic health information safe, complete, and available.
Covered entities under HIPAA include healthcare providers, health plans, and healthcare clearinghouses. These providers often work with outside vendors or service providers called business associates. Business associates help handle health information. They include IT service providers, cloud hosting companies, billing firms, and more AI technology vendors.
Business Associate Agreements (BAAs) are legal contracts between covered entities and business associates. These contracts explain how health information must be protected, what data can be used, how breaches are handled, and which security steps must be followed. The HITECH Act updates made business associates responsible for HIPAA violations too, making BAAs very important.
AI vendors bring new tools to healthcare like systems to help doctors decide treatments, software for imaging, and office automation like phone answering services. But these tools usually need access to a lot of protected health information. This access can risk breaches or sharing info without permission if not managed well.
A BAA creates trust between healthcare providers and AI vendors. It makes sure AI vendors use health info only for allowed purposes, keep it safe, tell the provider quickly if there is a breach, and limit data use according to HIPAA rules. Without a strong BAA, healthcare providers face legal trouble, fines, and privacy problems.
According to Gil Vidals, CEO of HIPAA Vault, 50% to 66% of violations come from problems with business associates. This shows how many breaches start with weak vendor oversight or poor contracts. So, medical practices should require a strong BAA before using AI tools.
Not covering these parts in the BAA leaves medical practices open to breaches and legal problems.
Use of AI in healthcare grew a lot in 2024, with doctor use almost doubling, says the American Medical Association. AI tools might help patient care and office work, but they also increase chances of breaking HIPAA rules. The healthcare field had record data breaches in 2024 and 2025, many linked to AI vendor systems.
For example, Change Healthcare, a big healthcare company, said a breach affected 190 million people. Also, one data breach exposed 483,000 patient records across six hospitals because of a problem in an AI workflow vendor system. These cases show that using AI without good controls or agreements can cause big data leaks.
Healthcare leaders need to know that AI systems often connect to electronic health records, imaging files, billing systems, and other sources of health info. So, protecting these connections with contracts and technical safety steps is very important.
Being careful with vendors is now very important for healthcare groups. The 2025 HIPAA Security Rule updates require stronger cybersecurity. This means ongoing vendor checks, multi-factor login, easier audits, and good record keeping.
Healthcare groups should do in-depth risk checks before choosing any AI vendor. These checks look at the vendor’s security set up, like how they encrypt data, control access, respond to incidents, and their compliance certifications such as HITRUST or SOC 2.
Automation tools like Censinet RiskOps™ help by automating vendor risk reviews, keeping documents in one place, creating compliance reports, and providing real-time monitoring. This can reduce human mistakes and speed up compliance work.
It’s important to have someone in the medical practice responsible for vendor management. This person makes sure contracts are followed and can act fast if problems happen.
Failing to manage vendors well can lead to costly fines. The average cost of healthcare breaches in 2025 is more than $10 million.
Even with good BAAs and vendor checks, employee mistakes are still a risk. Some workers use unapproved AI tools without telling anyone, called “shadow IT.” This can cause compliance problems.
Almost half of healthcare groups in 2025 said they do not monitor employee use of AI well enough. Without clear rules on how to use AI with protected health information, staff might accidentally expose data or break HIPAA rules.
David Ginsberg, CEO of PrivaPlan Associates, advises healthcare teams to create clear AI compliance rules and train workers well. Training should cover HIPAA basics, allowed AI use, how to report problems, and cybersecurity steps.
Using multi-factor login, controlling who can access data, and doing regular compliance checks help stop unauthorized exposure.
Medical offices across the US are quickly using AI tools for front-office tasks, like automated phones and AI answering services. Companies like Simbo AI offer phone automation designed to manage patient appointments, questions, and office communication.
Though these tools can make work smoother and improve patient experience, they also handle health information. This raises privacy issues under HIPAA.
These AI tools are usually business associates, so they need BAAs that ensure they follow HIPAA Privacy and Security Rules. Medical teams should watch for:
Automation platforms that use AI need regular risk reviews and updated vendor contracts to match new cybersecurity rules.
The American Medical Association reports that admin automation tools are a key type of AI with HIPAA compliance challenges because they work with patient data.
If medical practices do not follow HIPAA when working with AI vendors, they can face:
Because of these risks, medical admin and IT staff must make sure BAAs with AI vendors are complete, enforceable, and kept up to date with the latest HIPAA rules.
For medical practice admins, owners, and IT managers in the US, managing AI vendor relationships is required for safe and legal healthcare.
By doing these steps, medical practices can improve care workflows without risking patient privacy or security rules under HIPAA.
The primary categories include Clinical Decision Support Systems (CDSS), diagnostic imaging tools, and administrative automation. Each category processes protected health information (PHI), creating privacy risks such as improper disclosure and secondary data use.
BAAs legally bind AI vendors to use PHI only for permitted purposes, require safeguarding patient data, and mandate timely breach notifications. This ensures vendors maintain HIPAA compliance when receiving, maintaining, or transmitting health information.
PHI can be shared without patient authorization only for treatment, payment, or healthcare operations (TPO). Any other use, including marketing or AI model training involving PHI, requires explicit patient consent to avoid violations.
Breaches expose sensitive patient data, disrupt IT systems, reduce availability and quality of care by delaying appointments and treatments, and risk patient safety by restricting access to critical PHI.
Careful vendor selection is essential to prevent security breaches and legal liability. It includes requiring BAAs prohibiting unauthorized data use, enforcing strong cybersecurity standards (e.g., NIST protocols), and mandating prompt breach notifications.
Employees must understand AI-specific threats like unauthorized software (‘shadow IT’) and PHI misuse. Training enforces use of approved HIPAA-compliant tools, multi-factor authentication, and security protocols to reduce breaches and unauthorized data exposure.
Covered entities and business associates must ensure PHI confidentiality, integrity, and availability by identifying threats, preventing unlawful disclosure, and ensuring employee compliance with HIPAA law.
Secondary use of PHI for AI model training requires explicit patient authorization; otherwise, such use or disclosure is unauthorized and violates HIPAA, restricting vendors from repurposing data beyond TPO functions.
Providers should enforce rigorous vendor selection with strong BAAs, mandate cybersecurity standards, conduct ongoing employee training, and establish governance frameworks to balance AI benefits with privacy compliance.
Short breach notification timelines enable quick response to incidents, limiting lateral movement of threats within the network, minimizing disruptions to care delivery, and protecting PHI confidentiality, integrity, and availability.