HIPAA sets federal rules to protect the privacy and security of protected health information, or PHI. PHI includes any health data that can identify a patient. Following HIPAA means obeying the Privacy Rule, which controls how PHI is used and shared, and the Security Rule, which requires technical, administrative, and physical protections for electronic PHI (ePHI). Healthcare providers like medical practices are called covered entities under HIPAA. Vendors who handle PHI for these providers are called business associates. Since many AI healthcare technologies now work with PHI, their vendors must follow HIPAA rules.
AI technologies that often use PHI include:
All these systems need access to sensitive patient data. This raises risks of breaches, wrong sharing, or using PHI for other purposes. A survey by the American Medical Association showed that the use of AI by doctors almost doubled in 2024. This shows why following HIPAA is very important in these cases.
Choosing the right AI vendor is very important to protect PHI and follow HIPAA rules. The vendor you pick affects how well patient data is secured and what controls stop data breaches. Healthcare organizations should carefully check AI vendors. They must review the vendor’s security systems, certifications, and policies for handling PHI.
In 2024, healthcare had many data breaches. The largest breach, reported by Change Healthcare, Inc. in February 2024, exposed PHI for 190 million people. Another breach hit six hospitals and affected nearly 500,000 patients. This breach was caused by an AI vendor with weak controls. These events show the serious problems caused by poor vendor choices.
Because third-party vendors do many complex AI tasks involving PHI, healthcare organizations cannot rely only on their internal rules. Risk management across the whole organization must include checking vendors. Important things to check include:
Besides technical checks, vendors must report breaches quickly. Contracts need rules that require breach notifications within 24 to 48 hours. This helps the healthcare provider respond fast and reduce harm to patients.
Business Associate Agreements (BAAs) are legal contracts between healthcare providers and AI vendors who handle PHI. Under HIPAA and the HITECH Act, BAAs are required. They explain how the vendor must protect and manage PHI.
BAAs must:
If a medical practice has no BAA with a vendor, it risks breaking HIPAA rules, which can lead to big fines and loss of patient trust. The HITECH Act says business associates can also be held responsible for violations. This makes good BAAs even more important.
BAAs should cover all vendors who provide AI services. Because AI tools often change, unapproved software or “shadow IT” can cause compliance problems if employees use AI tools that are not allowed or secure.
Employee training and governance help support vendor choices and BAAs. Workers need to understand AI risks and company rules about software use. Training should warn about shadow IT and stress the use of multi-factor authentication and other security steps.
Governance means watching AI vendors regularly, doing audits, and having plans for incidents. These steps help find problems early and keep AI workflows safe.
AI-powered workflow tools, like phone systems and administrative automation, are changing healthcare operations. Some companies offer AI phone answering systems that handle patient calls quickly while protecting privacy and security. These tools reduce work by scheduling appointments and sending messages correctly.
However, these AI tools handle PHI when they transcribe calls, capture data, or work with electronic medical records (EMR) or electronic health records (EHR). They must meet strict HIPAA rules, including:
Administrators and IT managers should check that AI vendors use HIPAA-compliant technology like encrypted cloud services and controlled access. Contracts must include breach reporting and incident response rules.
A key rule is “minimum necessary” — AI tools should only access and keep the smallest amount of PHI needed. This lowers risks if a breach happens.
Third-Party Risk Management (TPRM) is more important for healthcare organizations now. In 2024, 41% of healthcare data breaches came from third-party vendors dealing with PHI. The average breach cost almost $9.77 million. Yet, only 12% of healthcare groups have strong TPRM programs.
Boards and leaders in healthcare must approve full TPRM programs, set risk limits, and ensure enough resources. Some technology tools automate vendor risk checks, watch vendor compliance in real-time, and help manage incident responses.
Good TPRM needs clear communication about vendor incidents, fast breach reports, and teamwork across legal, IT, purchasing, and clinical areas. These efforts reduce risks from AI vendors and keep HIPAA and HITECH rules followed.
Using AI in healthcare brings special challenges for HIPAA compliance:
Healthcare leaders should focus on picking vendors who know HIPAA safeguards, making correct BAAs, providing regular staff training, and keeping clear governance systems.
By following good vendor selection, clear Business Associate Agreements, training employees, and ongoing governance, medical practices in the U.S. can handle HIPAA rules well while using AI healthcare tools to improve work.
The primary categories include Clinical Decision Support Systems (CDSS), diagnostic imaging tools, and administrative automation. Each category processes protected health information (PHI), creating privacy risks such as improper disclosure and secondary data use.
BAAs legally bind AI vendors to use PHI only for permitted purposes, require safeguarding patient data, and mandate timely breach notifications. This ensures vendors maintain HIPAA compliance when receiving, maintaining, or transmitting health information.
PHI can be shared without patient authorization only for treatment, payment, or healthcare operations (TPO). Any other use, including marketing or AI model training involving PHI, requires explicit patient consent to avoid violations.
Breaches expose sensitive patient data, disrupt IT systems, reduce availability and quality of care by delaying appointments and treatments, and risk patient safety by restricting access to critical PHI.
Careful vendor selection is essential to prevent security breaches and legal liability. It includes requiring BAAs prohibiting unauthorized data use, enforcing strong cybersecurity standards (e.g., NIST protocols), and mandating prompt breach notifications.
Employees must understand AI-specific threats like unauthorized software (‘shadow IT’) and PHI misuse. Training enforces use of approved HIPAA-compliant tools, multi-factor authentication, and security protocols to reduce breaches and unauthorized data exposure.
Covered entities and business associates must ensure PHI confidentiality, integrity, and availability by identifying threats, preventing unlawful disclosure, and ensuring employee compliance with HIPAA law.
Secondary use of PHI for AI model training requires explicit patient authorization; otherwise, such use or disclosure is unauthorized and violates HIPAA, restricting vendors from repurposing data beyond TPO functions.
Providers should enforce rigorous vendor selection with strong BAAs, mandate cybersecurity standards, conduct ongoing employee training, and establish governance frameworks to balance AI benefits with privacy compliance.
Short breach notification timelines enable quick response to incidents, limiting lateral movement of threats within the network, minimizing disruptions to care delivery, and protecting PHI confidentiality, integrity, and availability.