Industry guide
HIPAA for AI Companies
A governance and product-risk starting point for AI companies that may process PHI in models, prompts, outputs, or telemetry.
Reviewed August 2026
Key considerations
- Data can persist in prompts, logs, evaluations, embeddings, support tools, or model-improvement workflows.
- Model quality does not answer contractual, retention, access, audit, or incident questions.
- Use-case approval and human review should match the consequence of the workflow.
Starting points
- Map all input, output, telemetry, retention, and subprocessors.
- Define approved uses, access controls, testing, auditability, and incident response.
- Be precise about BAA scope and customer responsibilities.