AI scribes, automated prior authorizations, ChatGPT for clinical notes, AI-powered billing — healthcare practices are adopting these tools fast. Most are doing it without a single HIPAA document in place for any of them. That gap is a liability that's growing by the month.
Here's what the law actually requires — and what you need to do before your next AI tool goes live.
The HIPAA question that matters first
Before anything else: does this AI tool touch ePHI?
ePHI (electronic Protected Health Information) includes any individually identifiable health information in electronic form — names, dates, diagnoses, treatment notes, billing codes tied to a patient, appointment records. If an AI tool creates, receives, processes, stores, or transmits any of that, HIPAA applies.
That covers a wider net than most practices realize. An AI scribe that records patient conversations? ePHI. A chatbot that helps patients book appointments? Likely ePHI. An automated billing platform? Definitely ePHI. Even a general-purpose AI tool where staff have typed in patient details — even once — has touched ePHI.
Using the free or standard consumer version of ChatGPT with patient data is a HIPAA violation. OpenAI does not offer a Business Associate Agreement for consumer accounts. No BAA means no legal basis to share ePHI, regardless of how you use the tool.
What HIPAA requires when AI touches ePHI
Three things must happen before any AI vendor handles patient data on your behalf:
- A signed Business Associate Agreement (BAA). If the vendor processes ePHI for you, they are a Business Associate under HIPAA. A BAA must be in place before data is shared — not after. Verbal agreements and vendor privacy policies do not substitute for a signed BAA.
- Inclusion in your Security Risk Analysis. The SRA required under 45 CFR §164.308 must cover all systems that create, receive, maintain, or transmit ePHI. Every AI tool that touches patient data must be in scope — documented, assessed for risk, and covered by your Risk Management Plan.
- Workforce training on AI use. Staff who use AI tools to handle patient data must be trained on appropriate use, prohibited actions (e.g., entering ePHI into non-BAA tools), and incident reporting. Undocumented AI use by staff is a compliance gap even if the tool itself is covered.
The BAA problem most practices miss
Getting a BAA from a vendor is not the same as having a compliant BAA. Many vendor-provided BAAs are written to minimize vendor liability — not to satisfy your obligations as a covered entity.
A compliant BAA must address: permitted uses and disclosures of ePHI, the vendor's obligation to report breaches, subcontractor requirements, data return or destruction at contract termination, and your right to audit. A one-page vendor form that says "we take security seriously" is not a BAA.
CLAS by Fred offers BAA review and negotiation as a standalone service. If you're unsure whether your current vendor agreements are enforceable, that's a short engagement worth doing before your next renewal — or your next audit.
ISO 42001 and the governance layer above HIPAA
HIPAA sets the floor for AI in healthcare. ISO 42001 — the international standard for AI Management Systems — addresses the governance layer above it: how AI decisions are documented, how bias is assessed, how human oversight is maintained, and how AI risks are managed across the organization.
For healthcare practices, ISO 42001 is not yet legally required. But it is becoming a differentiator in payer contracts, partnership agreements, and patient trust. More importantly, building an AI governance framework now — while your AI footprint is still small — is far cheaper than retrofitting one after a breach or regulatory complaint.
A practical pre-deployment checklist
Before any new AI tool goes live in your practice:
- Confirm whether the tool will touch ePHI
- Verify the vendor offers a HIPAA-compliant BAA — and get it signed
- Review the BAA terms, not just sign and file it
- Add the tool to your Security Risk Analysis scope
- Write or update your AI Acceptable Use Policy to cover the new tool
- Train any staff who will use the tool on permitted and prohibited use
- Document the deployment decision and who approved it
This takes a few hours done properly. It avoids a situation that can cost six figures and six months of remediation if it goes wrong.
The liability shift that's already underway
OCR has signaled that AI-related HIPAA violations are a priority enforcement area. HHS guidance published in 2024 makes clear that covered entities cannot outsource HIPAA accountability to their AI vendors — the practice is responsible for its AI ecosystem, including tools the vendor markets as "HIPAA-ready." That marketing claim is meaningless without a signed BAA and a compliant implementation.
The practices that will navigate this well are not the ones with the most sophisticated AI tools. They're the ones who built governance before the auditors started asking.