The number of healthcare data breaches keeps going up. In 2023, over 540 organizations told the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) about breaches. These affected more than 112 million people. In 2022, there were 590 breaches affecting around 48.6 million people. This shows that breaches are happening more often and affecting more people. More healthcare providers are using electronic health records, telehealth, and cloud-based solutions. This makes it easier for hackers to attack.
HIPAA has rules that healthcare groups must follow to protect protected health information (PHI). These rules include the Privacy Rule, Security Rule, Breach Notification Rule, Omnibus Rule, and Enforcement Rule. Together, these rules say healthcare providers must limit who can see sensitive data, encrypt electronic PHI (ePHI), tell people quickly if their data was breached, and check risks regularly.
Data breaches can cost healthcare groups a lot of money in fines. For example, in 2020, one provider had to pay $6.85 million because they did not properly control who accessed data. Besides fines, breaches can make patients lose trust and hurt the healthcare group’s reputation.
Artificial intelligence (AI) is used in healthcare for things like helping doctors diagnose illnesses, scheduling patients, predicting health trends, and automating billing. But using AI also creates new challenges for following HIPAA rules. Todd L. Mayover, an attorney and data privacy expert, says it is important to make sure AI follows HIPAA rules when it works with PHI. This helps avoid unauthorized data access and other problems.
The main issue is how AI systems handle PHI:
If these issues are not handled, healthcare groups risk fines and criminal penalties, especially if violations happen because of neglect.
HIPAA rules change over time. In 2024 and after, there are updates to improve patient privacy and make processes easier. For example, the time for responding to patient requests for PHI will shorten from 30 days to 15 days. Also, there will be better protections for sensitive health data like reproductive health information.
As more organizations use AI, rules must change to keep up. New regulations focus on data anonymization, clear policies on AI use, and Business Associate Agreements (BAAs) with AI vendors. BAAs are contracts that make sure third-party providers handling PHI follow HIPAA laws.
The U.S. Department of Justice (DOJ) updated its Evaluation of Corporate Compliance Programs (ECCP) to include risks from new technologies like AI. Healthcare groups must now add AI risk management to their overall compliance plans. The DOJ expects healthcare groups using AI to:
Deputy U.S. Attorney General Lisa Monaco said, “Fraud using AI is still fraud.” This shows that the DOJ is serious about punishing bad AI use in healthcare compliance.
The OCR has stepped up enforcement. They are doing more audits and fines. These target big healthcare groups and smaller ones that may not have strong IT resources. In 2024, breaches affected 168 million people. OCR now uses a risk-based method for investigations.
Common reasons for breaches include:
Good risk analysis, multi-factor authentication, and ongoing employee cybersecurity training are now standard best practices. The OCR updated its Security Risk Assessment (SRA) Tool to help small and medium providers find and fix security gaps. Healthcare leaders should also include telehealth security due to its growth.
OCR also checks business associates more. Business associates must be carefully chosen and monitored. If they break rules, the main healthcare groups can face penalties. This means checking vendors is very important.
Healthcare groups use AI to improve tasks like appointment scheduling, patient communication, and answering phones. AI automation can lower staff workload and make operations run better. But it also brings compliance questions.
For example, AI companies like Simbo AI provide automated phone answering that talks to patients. These services might collect or handle sensitive patient information.
To follow HIPAA when using AI automation, organizations should:
AI automation can also help reduce human mistakes. For example, it can automate audit logs, detect unusual access, and help find breaches. Using these technologies can manage risks better.
Using AI ethically in healthcare is getting more attention along with legal rules. The HITRUST AI Assurance Program shows industry efforts to make AI risk management clear and responsible. Ethical questions include:
Many AI providers give solutions to healthcare groups. This can raise privacy issues. Some vendors know compliance and security, but risks of unauthorized access or carelessness remain. Checking vendors carefully, making strong contracts, and auditing AI providers often can reduce these risks.
Healthcare groups should tell patients when AI is used in their care. Letting patients choose to accept or refuse AI aligns with respectful care and legal rules.
Healthcare administrators, owners, and IT managers in the U.S. should do the following to keep up with HIPAA and AI:
By doing these things, healthcare groups can use new technologies to help patients while meeting strict HIPAA rules. They protect the sensitive information millions of people trust them with.
Using AI with HIPAA rules needs constant care from healthcare leaders and IT staff. AI can help with workflows and data, but groups must focus on following rules, using AI ethically, and keeping patient privacy safe. This makes healthcare safer and more trustworthy.
The main requirements include adhering to the Privacy Rule, Security Rule, Breach Notification Rule, Omnibus Rule, and Enforcement Rule, which collectively ensure the protection and integrity of patients’ ePHI.
The Privacy Rule focuses on protecting personal health information (PHI), providing patients access to their data, and limiting disclosures without consent under strict circumstances.
The Security Rule sets guidelines for administrative, physical, and technical safeguards to protect electronic PHI (ePHI) from unauthorized access and breaches.
Affected patients must be notified within 60 days of a breach discovery, and breaches impacting 500 or more individuals must be reported to the media and HHS.
The Omnibus Rule outlines how violations of HIPAA regulations are audited and penalized, ensuring covered entities and business associates maintain compliance.
Proposals include reducing timeframes for providing PHI, simplifying consent processes, and enhancing privacy around reproductive health information.
Apps should implement full disk, virtual disk, and file encryption methods, along with secure transport layers like SSL and HTTPS to protect sensitive data.
IAM is crucial for restricting access to ePHI, ensuring strong authentication methods are in place, and tracking access logs for accountability.
AI poses challenges such as data privacy risks, transparency issues in data handling, and compliance burdens with third-party AI vendors needing BAAs.
BAAs ensure that third-party vendors handling ePHI comply with HIPAA regulations, providing a layer of security and accountability for patient data management.