HIPAAmart

Technology · 9 min read

AI and HIPAA

A practical framework for evaluating generative AI, PHI leakage, retention, vendors, prompts, and governance.

Reviewed August 2026

Definition

AI and HIPAA analysis focuses on how health information moves through models, prompts, outputs, logs, vendors, and human workflows—not on the label of the AI product alone.

In practice

  • A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.

Who this applies to

  • Healthcare organizations evaluating AI tools
  • AI vendors and model providers
  • Product, security, privacy, and compliance teams

What the rule asks for

  • Determine whether PHI enters the model, prompt, output, telemetry, or support workflow.
  • Evaluate vendor terms, retention, access, subprocessors, and BAA obligations where applicable.
  • Apply access controls, testing, human review, and incident response to AI-enabled workflows.

How teams put it into practice

  • Create an approved-use register for AI tools and prohibit unreviewed PHI entry.
  • Test prompts and outputs for leakage, memorization, over-disclosure, and unsafe automation.
  • Document model changes, monitoring, data flows, and accountable owners.

Common mistakes

  • Assuming a private workspace or enterprise plan automatically resolves HIPAA obligations.
  • Ignoring prompt history, embeddings, vector stores, logs, and vendor support access.
  • Treating an AI-generated answer as a substitute for professional review.

Questions that come up

Can I put PHI into a public AI chatbot?

Do not enter PHI into an AI service until privacy, security, contractual, retention, and data-use questions have been reviewed and approved for that specific workflow.

References