Checklist · 5 minute read
HIPAA AI Compliance Checklist
An AI system handling protected health information meets HIPAA expectations when it is within the risk analysis, every vendor touching PHI has a business associate agreement, data use follows minimum necessary, access is role-based and logged, PHI is encrypted, audit logs capture access and disclosures, retention follows policy, workforce is trained, and breach procedures cover AI incidents.
Any AI system that creates, receives, maintains, or transmits protected health information is inside HIPAA, and the safeguards apply to it as they do to any other system, with some AI-specific twists: prompts and retrieval are new PHI flows, model providers are business associates, and logs can become unintended PHI stores. This checklist walks through the expectations. It complements hipaa compliant ai, ai and hipaa business associate agreements, and the AI safety in healthcare operations whitepaper. This is general guidance, not legal advice.
Who should use this checklist?
Privacy and security officers, compliance teams, and engineering owners at covered entities and business associates deploying AI that may touch PHI.
Is the system in scope and in the risk analysis?
- Data flows are mapped; any flow that creates, receives, maintains, or transmits PHI places the system in scope.
- The system is included in the HIPAA risk analysis with AI-specific threats: prompt injection, leakage through outputs and logs, provider exposure.
- Risk management decisions and safeguards are documented.
- The system is in the organization's AI register with a privacy classification.
Reference: healthcare ai compliance.
Are business associate agreements in place?
| Vendor type | BAA required if PHI is handled | Status |
|---|---|---|
| Model provider (API or hosted) | Yes | |
| Inference or hosting platform | Yes | |
| Vector, search, or database services holding PHI | Yes | |
| Observability, logging, and tracing tools capturing prompts or outputs | Yes | |
| Transcription and speech services | Yes | |
| Integration and workflow platforms | Yes | |
| Subprocessors of any of the above | Yes, via the vendor's BAA and subcontractor terms |
Vendors without a BAA cannot receive PHI; use redaction, private deployment, or a different vendor. Reference: private llm vs public api.
Does data use follow minimum necessary?
- Prompts include only the PHI the task requires; identifiers are redacted or tokenized where not needed.
- Retrieval returns only authorized, necessary records.
- Logs and traces store the minimum, with redaction; full content is access-controlled.
- Memory, caching, and embeddings of PHI follow explicit policy.
- Outputs disclose only what the recipient needs and may receive.
Reference: ai data leakage prevention.
Are access controls enforced?
- Users authenticate through the identity provider with MFA.
- AI access to records is under the user's own permissions; retrieval filters by role and relationship.
- The AI system has its own identity with least-privilege, revocable credentials.
- Emergency access, termination, and review procedures cover AI access.
- Patient-facing systems verify identity before any PHI disclosure.
Reference: ai access control.
Is PHI protected in transit and at rest?
- Encryption covers prompts, outputs, embeddings, indexes, logs, and backups.
- Key management follows organizational standards.
- Network isolation protects private deployments; egress is controlled.
- Device and endpoint controls cover workforce access to AI tools.
Reference: the AI agent security architecture whitepaper.
Does audit logging meet expectations?
- Logs capture who accessed what PHI through the AI system and when.
- AI-mediated disclosures (to users, patients, or downstream systems) are recorded.
- Administrative and security events are logged.
- Logs are protected, retained per policy, and reviewable, with operational logs redacted.
- Log review procedures include AI systems.
Reference: how to build an ai audit trail.
Are integrity, retention, and disposal handled?
- Integrity controls prevent unauthorized alteration of records and AI outputs entering the record.
- Clinician or staff review and signature precede any AI-drafted content entering the record.
- Retention for prompts, outputs, transcripts, and derived artifacts follows policy and record requirements.
- Disposal cascades to embeddings, caches, and backups.
Reference: how to build a clinical documentation assistant.
Is the workforce trained and are policies updated?
- Policies address AI use with PHI, including prohibited uses of unapproved tools.
- Workforce training covers the AI system's limits, verification duties, and incident reporting.
- Sanctions for policy violations apply to AI misuse.
- Shadow AI risks are addressed through approved alternatives and monitoring.
Reference: shadow ai risks and ai acceptable use training.
Are breach procedures AI-aware?
- Incident response covers AI-specific incidents: leakage through outputs, prompt injection exfiltration, provider incidents, log exposure.
- Breach risk assessment and notification procedures apply to AI incidents.
- Vendor breach notification terms are in BAAs.
- The playbook has been exercised with an AI scenario.
Reference: ai incident response checklist.
Are patient rights and transparency addressed?
- Patients receive notice where they interact with AI and are told how to reach a person.
- Access, amendment, and accounting of disclosures procedures account for AI data flows.
- Consent requirements for recording and transcription are met.
Reference: ai transparency notices.
How should gaps be handled?
BAA and access-control gaps block PHI processing. Minimum-necessary, encryption, and logging gaps block production launch. Training and procedure gaps are closed before go-live with owners and dates. Record findings in the risk analysis.
How FISTA Solutions supports HIPAA-aligned AI
FISTA Solutions builds healthcare AI with BAAs confirmed before PHI flows, minimum-necessary data handling in prompts, retrieval, and logs, access under the user's permissions, encryption and isolation, audit trails designed for HIPAA review, clinician sign-off on any content entering the record, and AI-aware incident procedures. The AI enablement practice delivers the compliant platform, AI agents automate administrative workflows within it, and forward deployed engineers work with your privacy and security officers. The record behind the approach is 150+ projects with 99.9% uptime.
This checklist is general guidance, not legal advice. To assess an AI system against HIPAA expectations, message FISTA on WhatsApp, or read ai in healthcare for the sector context.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Is using an LLM with patient data HIPAA compliant?
It can be when the implementation meets the safeguards: a business associate agreement with the model provider and any subprocessor, minimum-necessary data in prompts, encryption, role-based access, audit logging, retention controls, inclusion in the risk analysis, and breach procedures. Compliance is a property of the implementation, not the model.
02Which vendors need a business associate agreement for AI?
Any vendor that receives, stores, or processes PHI on your behalf: model providers, hosting and inference platforms, vector and search services holding PHI, observability and logging tools capturing prompts, transcription services, and integration providers. Vendors that will not sign cannot receive PHI.
03How does minimum necessary apply to AI?
Prompts and retrieval include only the PHI the task requires; identifiers are redacted or tokenized where the model does not need them; logs and traces store the minimum with redaction; and memory or caching of PHI follows explicit policy. Design reviews check each data flow against the standard.
04What audit logging does HIPAA expect of AI systems?
Records of who accessed what PHI through the system and when, AI-mediated disclosures, administrative actions, and security events, retained per policy and reviewable, with content redacted in operational logs and full records access-controlled.
05Is this checklist legal advice?
No. It is a general engineering and governance orientation to HIPAA expectations for AI systems. Covered entities and business associates should confirm requirements with their privacy and security officers and counsel.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.