Technology guide
Generative AI and HIPAA
A focused review of prompts, outputs, model providers, retention, RAG, human review, and PHI leakage.
Reviewed August 2026
Key considerations
- Prompts, completions, embeddings, evaluation data, logs, and support records may all carry sensitive information.
- The model's public or private label does not answer BAA, retention, access, or governance questions.
- Automated output should have review and escalation appropriate to the use case.
Questions to ask
- What enters the model and what persists after the request?
- Can vendor personnel or subprocessors access prompts, outputs, or embeddings?
- How are prompt injection, leakage, hallucination, and model changes monitored?