AI and HIPAA Compliance: How to Navigate Compliance

Artificial intelligence can draft notes, transcribe calls, answer scheduling questions, and prepare follow-up messages.

Thus, healthcare providers can use AI tools to improve efficiency in patient care.

However, AI and HIPAA compliance must work together to ensure patient data remains protected and that healthcare organizations meet their regulatory obligations. 

AI systems can receive vast amounts of patient data through prompts, recordings, documents, and generated responses. But weak controls can expose protected health information and other sensitive information to cyberattacks or improper disclosure.

Statistics show healthcare breaches affected 289 million individuals in 2024. The HHS Office for Civil Rights report says large healthcare breaches total 242.9 million, and another 340,618 for smaller incidents. Hacking accounted for 81% of large breaches.

With such stats, healthcare organizations need approved AI practices, vetted vendors, technical safeguards, human review, and secure communication channels.

In this article, we’ll discuss AI and HIPAA compliance, what healthcare organizations should assess before adoption, and how iPlum’s HIPAA compliance solution helps ensure secure patient communication.

Table of Contents

1. How is AI affecting HIPAA compliance?

2. Where AI systems encounter protected health information

3. Which HIPAA requirements apply to AI?

4. Can AI use de-identified healthcare data?

5. How to evaluate AI vendors for HIPAA compliance

6. Why secure patient communication is still crucial 

7. How iPlum secures communication around an AI-enabled ecosystem

8. Frequently asked questions about AI and HIPAA compliance

9. Use AI through approved and secure ecosystems

10. Portable Hot Spot

11. Warming Plate

12. Coffee Maker

How is AI affecting HIPAA compliance?

The Health Insurance Portability and Accountability Act of 1996 established federal standards for the protection of sensitive medical information. 

HIPAA requires safeguarding patient health information (PHI) when a regulated organization or its vendor creates, receives, maintains, or transmits it.

HIPAA does not contain a separate rule for artificial intelligence (AI). Even so, existing HIPAA rules apply when AI systems process PHI for a HIPAA-covered entity or business associate.

Saying “AI tools must comply with HIPAA’s Privacy and Security Rules” simplifies the legal structure. In legal terms, covered entities and business associates carry the regulatory obligations. 

Therefore, a healthcare provider cannot transfer responsibility merely by buying a service marketed as HIPAA-compliant AI.

AI technology also changes how healthcare data moves.

 AI applications can create prompts, embeddings, transcripts, outputs, and vendor logs from the same health care data. AI models can also retain information through training or logs, if contracts and settings permit.

Therefore, privacy officers need to examine the full data lifecycle rather than only the final output.

Where AI systems encounter protected health information

AI in healthcare reaches far beyond clinical diagnosis. Routine digital health operations can send patient information to several types of AI solutions, including:

Generative AI tools

Clinicians can use generative AI to summarize charts, draft referrals, prepare patient instructions, or structure notes. Prompts and generated text can contain protected health information (PHI).

Ambient transcription services

Ambient tools record appointments and create notes. Therefore, the vendor can process PHI from audio recordings, transcripts, diagnoses, medications, and visit details.

Virtual assistants and patient engagement tools

Virtual assistants can schedule appointments, collect symptom information, send reminders, or answer billing questions. HHS lists a third-party AI chatbot that processes patient PHI on a provider portal as an example of a business associate. 

Predictive analytics and clinical AI

Predictive analytics can use electronic records to estimate readmission, deterioration, or treatment outcomes. These AI systems can function effectively only with suitable healthcare data, but more data does not guarantee accuracy.

Healthcare organizations should address clinical validation, bias, accuracy, and patient safety alongside HIPAA compliance. 

A human-in-the-loop model requires a clinician to review AI-generated decisions before they affect patient care. AI should assist rather than replace human judgment.


Which HIPAA requirements apply to AI?

Several HIPAA requirements govern how healthcare organizations introduce AI, including:

The HIPAA Privacy Rule governs permitted data use

The HIPAA Privacy Rule controls how a covered entity can use or disclose protected health information. HIPAA's Privacy Rule permits specific uses for treatment, payment, health care operations, and other authorized purposes.

The minimum necessary rule generally limits PHI use, disclosure, and requests to the amount reasonably required for the task. Therefore, a billing assistant should not receive an entire medical history for a narrow billing task.

That said, healthcare providers should define who can access PHI and which AI functions they can use. 

In addition, consumer chatbot accounts should not process PHI unless the service, contract, settings, and environment meet applicable HIPAA requirements.

AI vendors can become business associates

An AI vendor generally becomes a business associate when it creates, receives, maintains, or transmits PHI on behalf of a covered entity. Before the vendor can process PHI, the parties generally need a business associate agreement.

The BAA should define permitted data use, safeguards, incident reporting, PHI return or destruction, and subcontractor duties. 

BAAs establish legal responsibilities for protecting PHI. Moreover, appropriate agreements must bind subcontractors processing the same PHI.

A signed business associate agreement is essential, but it does not make a poorly configured service compliant. Vendor evaluation must also examine retention, model training, permissions, audit logging, incidents, and account termination.

It is worth noting that failure creates serious compliance risk.

HHS caps the maximum penalty at $2,190,294 for a single violation involving uncorrected willful neglect. The figure serves as the calendar-year cap for lower tiers. That said, the claim that HIPAA penalties can reach $2.19 million per violation needs that context.

The HIPAA Security Rule applies to electronic PHI

The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic PHI. 

Relevant security controls encompass access controls, audit controls, integrity measures, authentication, and transmission security. 

For AI systems, safeguards should address prompts, files, outputs, logs, APIs, and backups. Role-based access controls should restrict access to PHI to authorized users. Audit trails should record access, AI processes, changes, and exports. Integrity controls should reveal unauthorized alteration of ePHI.

Encryption provides another layer of data security.

Vendors can use AES-256 for data at rest and TLS 1.3 for data in transit, although HIPAA does not prescribe those exact technologies.

Current HIPAA treats encryption as addressable rather than unconditional. A regulated entity must apply it when it is reasonable and appropriate following its risk assessment. Otherwise, it must document the decision and, where appropriate, apply a suitable alternative. 

The HHS proposed rule would expressly require encryption of ePHI at rest and in transit, as well as multi-factor authentication, with limited exceptions. 

It would also require annual compliance audits, asset inventories, network maps, and vulnerability scans. However, the current Security Rule remains in effect. 

AI systems belong in HIPAA risk assessments

HIPAA-covered entities and business associates must assess the threats and vulnerabilities affecting ePHI. 

Therefore, AI systems that create, receive, maintain, or transmit electronic PHI should be included in routine HIPAA Security Rule risk assessments.

The assessment should examine:

  • Data inputs, outputs, logs, embeddings, and backups
  • Unauthorized access, credential theft, and external attacks
  • Prompt injection and accidental disclosure
  • Model-training and data-retention settings
  • EHR and messaging integrations
  • Vendor and subcontractor access
  • Data integrity, breach detection, and response

A live inventory of applications and data pipelines shows privacy officers where patient data travels. Next, continuous monitoring and reassessment can identify vendor changes, new features, and altered data flows. 

Such work is crucial for ongoing HIPAA compliance, regulatory compliance, data privacy, and patient privacy.

The NIST AI Risk Management Framework can complement this process through its Govern, Map, Measure, and Manage functions. However, the voluntary framework does not replace HIPAA requirements or other privacy laws.


Can AI use de-identified healthcare data?

A HIPAA-eligible AI environment can process identifiable PHI when HIPAA permits the use, a required BAA is in place, and suitable safeguards protect the information.

Even so, de-identification can reduce exposure when an AI task does not require identity. The HIPAA Privacy Rule recognizes two de-identification methods:

  • Safe Harbor: Remove 18 categories of identifiers and have no actual knowledge that the remaining information can identify the individual.
  • Expert Determination: Obtain a documented determination from a qualified expert that the identification risk is very small.

Healthcare organizations should ensure that data de-identification uses a single method before treating a dataset as de-identified. Removing names alone does not meet Safe Harbor.

AI algorithms can combine datasets and infer identity. HHS states that properly de-identified information retains a very small, non-zero chance of being linked to a patient. 

NIST also warns of re-identification through cross-dataset analysis and training-data leakage. 

Therefore, contracts should, where appropriate, prohibit attempts to re-identify data. Organizations should reassess de-identification as external datasets and AI models change. Data thought to be anonymous can be re-identified.


How to evaluate AI vendors for HIPAA compliance

No universal federal certification automatically makes an AI product HIPAA-compliant. Consequently, healthcare organizations must vet vendors before integrating AI.

Ask the following questions during vendor evaluation:

  • Will the vendor sign a BAA for the selected service and account?
  • Can the vendor or its subcontractors use patient data to train AI models?
  • Where does the service store prompts, outputs, and logs?
  • How long does it retain data?
  • Which encryption, access controls, and authentication measures protect ePHI?
  • Does audit logging record access and modifications by users and AI processes?
  • How quickly will the vendor report a suspected security event?
  • Can administrators export audit trails?
  • What happens to PHI after contract termination?
  • How does the vendor test clinical accuracy, bias, and data integrity?

In addition, confirm that the service will operate in a HIPAA-eligible environment. 

Some AI vendors provide a BAA only for selected enterprise services or configurations. Consumer accounts can follow different data practices.

Healthcare organizations should establish written policies for handling PHI with AI tools. Address approved uses, prohibited inputs, human review, incidents, retention, and sanctions. 

While at it, conduct regular risk assessments of AI tools and revise training as AI practices and regulations evolve.


Why secure patient communication is still crucial 

An approved AI system addresses only the information processed inside that service. Patient calls, texts, voicemail, and documents can expose PHI before AI receives it.

For example, a clinician might use approved AI to draft a response. Yet a personal number can place patient health information outside business accounts, access restrictions, archiving policy, and signed vendor agreements.

Therefore, healthcare organizations need a secure communication channel around the AI ecosystem. The channel should allow patient communication to use controlled calling, secure texting, and voicemail services designed for health care privacy and security.


How iPlum secures communication around an AI-enabled ecosystem

iPlum does not validate external AI models or make another AI vendor compliant. 

Rather, it secures the communication layer where patient information enters and leaves the workflow.

First, iPlum adds a separate HIPAA business number to an existing smartphone for patient calls, secure texts, and voicemail.

In addition, an iPlum Professional or Enterprise account can provide a signed Business Associate Agreement. iPlum also provides AES-256 data encryption, secure texting, communication logs, password protection, archiving, backup, and a cloud management console. 

With iPlum, clinicians can use secure texting for protected health information. Meanwhile, patients get a free iPlum account or the app-less portal for encrypted communication.

A controlled workflow can operate as follows:

  1. A patient sends a secure message through iPlum.
  2. An authorized clinician reviews the message.
  3. An approved AI service receives only the minimum necessary information under a BAA.
  4. The AI drafts a response or summary.
  5. A clinician checks the output for accuracy, tone, and clinical safety.
  6. The clinician sends the final response through iPlum secure texting.
  7. Diagnoses, treatment decisions, and follow-up actions are entered into the EHR.

iPlum's business account can create subaccounts and remove access after role changes or departures. Meanwhile, logs, archiving, voicemail, business hours, auto-text replies, and call routing add structure for patient engagement.

The point is, while AI can improve efficiency, patient trust still depends on disciplined communication.


Frequently asked questions about AI and HIPAA compliance

Is AI automatically HIPAA compliant?

No. HIPAA compliance depends on the use case, PHI, BAA, account settings, security measures, user behavior, and ongoing review.

Can a healthcare provider enter PHI into an AI chatbot?

Yes, when HIPAA permits the use, and the service can process PHI under a BAA, approved configuration, and suitable safeguards.

Does an AI vendor need a BAA?

Generally, yes, when the vendor creates, receives, maintains, or transmits PHI for a covered entity or business associate.

Can AI use de-identified patient data?

Yes. However, the organization must use Safe Harbor or Expert Determination before treating the information as non-PHI.

Does HIPAA require multi-factor authentication and encryption?

Current HIPAA requires authentication, while encryption remains addressable. The proposed rule would expressly require MFA and encryption at rest and in transit, subject to limited exceptions.


Use AI through approved and secure ecosystems

AI can improve clinical and administrative work, but healthcare organizations must protect PHI throughout the workflow. 

First, identify which AI tools access patient information. Then review vendor contracts, sign BAAs, restrict user access, monitor activity logs, and verify AI-generated content before it affects patient care.

Secure communication is equally important. 

iPlum gives healthcare providers a dedicated business number for HIPAA-compliant calling, secure texting, voicemail, archiving, and account administration. 

Click below to sign up for iPlum to protect patient communication as your organization adopts AI.

Sign up for iPlum

Tags
No items found.
Download Our APP Now!