Artificial intelligence is moving faster than the governance frameworks most healthcare organizations have in place. That gap is where compliance risk lives.
HIPAA was not designed with modern AI systems in mind, but its requirements apply regardless. If an AI tool creates, receives, maintains, or transmits Protected Health Information (PHI) — the rules still govern how that data is handled. Healthcare providers, health plans, and business associates all need to evaluate how AI solutions interact with PHI across every stage of the data lifecycle.
This isn’t a future concern. For organizations already using AI-powered documentation, clinical decision support, patient engagement platforms, or automated workflows, the compliance obligations are active now.
HIPAA Doesn’t Have an AI Exemption
The Privacy Rule, Security Rule, and Breach Notification Rule don’t carve out exceptions for AI. What has changed is the complexity of the environments these rules now govern.
When a healthcare organization deploys an AI tool, the fundamental questions remain the same: Who has access to PHI? How is it stored? How is it transmitted? What happens when something goes wrong?
What’s new is the need to answer those questions for systems that learn from data, involve third-party cloud infrastructure, and may process PHI in ways that are less transparent than traditional software.
Business Associate Agreements: Don’t Assume Coverage
When an AI vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity, that vendor may qualify as a Business Associate under HIPAA — and a signed Business Associate Agreement (BAA) is required before any PHI flows to that system.
Standard BAA language often wasn’t written with AI in mind. Organizations are increasingly adding AI-specific provisions that address:
- How and whether PHI is used to train models
- Whether customer data is isolated or shared across environments
- Data retention timelines and deletion processes
- Subprocessor disclosures and controls
- Incident detection and notification obligations
If your existing agreements don’t address these points, treat that as a gap, not a gray area.
Model Training Is a Real Risk
One of the most consequential questions to ask any AI vendor: does my data train your models?
If the answer is unclear, that’s a problem. Healthcare organizations should require explicit contractual and technical documentation that addresses:
- Whether PHI is used for model training or improvement
- Whether data is de-identified before any secondary use
- How the vendor enforces data segregation across clients
- What audit rights the covered entity retains
Assumptions here create liability. Clarity eliminates it.
Audit Controls and AI Governance
The HIPAA Security Rule requires appropriate audit controls, and AI systems aren’t exempt from that requirement. Logging access, tracking outputs used in clinical workflows, and documenting system changes all matter.
Beyond minimum compliance, stronger AI governance programs typically include:
- A current inventory of all authorized AI tools in use
- Defined approval workflows for new AI deployments
- Monitoring of access to sensitive data by AI systems
- Records of AI-generated outputs influencing clinical decisions
- Configuration documentation and change tracking
Visibility is not optional — it’s foundational to any defensible compliance posture.
What Compliance Officers Should Do Now
HIPAA compliance in an AI-enabled environment requires structured action, not reactive patching. Here’s where to focus.
Build your AI inventory.
You cannot govern what you can’t see. Create a full inventory of every AI-enabled tool in your environment, enterprise platforms, clinical applications, productivity tools, chatbots, and any department-level or employee-developed solutions. That includes tools that may have been adopted informally.
Audit your vendor agreements.
Review every relevant contract and BAA to confirm that data handling practices, security controls, retention policies, and model training terms are explicitly addressed. If they aren’t, open those conversations now before an incident forces them.
Implement appropriate technical controls.
The right controls depend on your risk profile and use cases, but common approaches for AI environments include private cloud or dedicated deployments, data loss prevention tools, PHI encryption in transit and at rest, access management and monitoring, and network segmentation.
The goal is maintaining meaningful control over sensitive information without stalling clinical operations.
Compliance Isn’t a Project. It’s a Program.
Healthcare organizations that treat AI governance as a one-time checklist will find themselves continuously behind. The technology is evolving. The guidance is evolving. The risk is ongoing.
Organizations that build structured, repeatable governance programs — with clear policies, rigorous vendor due diligence, and continuous oversight — are better positioned to adopt AI responsibly and defend their posture when regulators or auditors come asking.
RSI Security works with healthcare organizations to assess AI-related cybersecurity and compliance risks, strengthen governance frameworks, and implement the controls that support innovation while protecting patient information.

