Back to Insights
AI Governance

AI Governance Under HIPAA: What Regulated Healthcare Organizations Must Do Now

HIPAA's Privacy and Security Rules apply to AI tools handling protected health information. Here is what a defensible AI governance framework looks like for healthcare organizations operating under federal oversight.

Orville Matias
Orville Matias
AI Governance Under HIPAA: What Regulated Healthcare Organizations Must Do Now

AI tools are now embedded in clinical documentation, revenue cycle management, patient scheduling, and internal communications at healthcare organizations across the country. Most were deployed without a governance framework. That is the problem.

$10,000

Minimum HIPAA Penalty

Per violation, willful neglect

$50,000

Maximum Per Violation

Per violation category per year

$1.9M

Average Healthcare Breach Cost

2024 IBM Cost of Data Breach Report

5 Days

Assessment Turnaround

Centience AI Governance Assessment

HIPAA's Privacy Rule and Security Rule do not carve out an exception for artificial intelligence. If a tool touches, processes, transmits, or stores protected health information (PHI), it falls under HIPAA's obligations — regardless of whether the vendor calls it "AI," "automation," or "intelligent workflow."

Here is what a defensible AI governance program looks like for a HIPAA-regulated organization.

Why AI Creates New HIPAA Exposure

Most healthcare organizations have existing policies for data access, breach notification, and vendor management. Those policies were written before generative AI existed. They do not account for the way AI tools ingest context, retain conversation history, train on user inputs by default, or expose PHI through prompt injection.

The specific exposures include:

PHI ingestion through AI prompts. Staff using tools like ChatGPT, Microsoft Copilot, or Google Gemini may inadvertently include patient names, dates of service, diagnosis codes, or account numbers in prompts. Without technical controls preventing this, every prompt becomes a potential breach event.

Business Associate Agreements. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate and requires a signed BAA. Many AI vendors — including major platforms — either do not offer HIPAA-compliant configurations or have BAA terms that shift liability in ways most compliance officers have not reviewed.

Audit trail gaps. The HIPAA Security Rule requires covered entities to implement audit controls — hardware, software, and procedural mechanisms that record and examine activity in systems containing PHI. Most AI tools generate no audit log accessible to the covered entity.

Proposed 2025 HIPAA Security Rule Update. HHS OCR has a proposed Security Rule modernization on the May 2026 agenda that includes explicit requirements for technology asset inventories and access controls. Organizations without an AI inventory today will be non-compliant under the proposed rule before it finalizes.

The Four Pillars of an AI Governance Framework Under HIPAA

1

AI Inventory

Discover every AI tool touching PHI — licensed, embedded, or employee-accessed. Classify by risk level.

2

BAA Audit

Verify executed Business Associate Agreements cover every AI vendor processing PHI. Remediate gaps immediately.

3

Technical Controls

Deploy DLP, endpoint policies, and approved tool lists enforced at the network level — not just in documentation.

4

Workforce Training

Train all workforce members on AI acceptable use and PHI handling. Document acknowledgment.

1. AI Inventory

You cannot govern what you cannot see. The first step is a complete discovery of every AI tool in use across the organization — including tools deployed by individual departments, embedded in third-party software, or accessed via personal devices.

📌 Important

OCR guidance since 2023 explicitly includes AI among technologies that must be addressed in the required Security Rule risk analysis. An AI inventory is not optional — it is the foundation of a defensible risk analysis.

Each tool in the inventory should be evaluated for:

  • Whether it can access, process, or store PHI
  • Whether a BAA exists with the vendor
  • Whether the tool operates in a HIPAA-compliant configuration
  • Who authorized deployment and when
  • Organizations that skip this step will discover exposure during an HHS OCR investigation, not before it.

    2. Business Associate Agreement Audit

    Every AI vendor that touches PHI requires a valid BAA. This is non-negotiable under 45 CFR §164.308(b).

    A BAA audit for AI should cover:

  • Which AI platforms currently have executed BAAs
  • Whether those BAAs cover the specific AI features in use (enterprise AI agreements often have narrower scope than the tools employees actually use)
  • Which platforms have no BAA at all and must be restricted immediately
  • Renewal dates and termination clauses
  • Microsoft 365 Copilot, Google Workspace with Gemini, and several major EHR vendors now offer HIPAA-aligned AI configurations — but only under specific licensing tiers and only when BAAs are executed correctly.

    3. Technical Controls

    Governance without enforcement is just documentation. Technical controls operationalize your policies:

  • Endpoint policies that block PHI from being submitted to non-approved AI platforms
  • Data loss prevention (DLP) rules configured to detect and block PHI patterns (SSNs, MRNs, dates of service, diagnosis codes) from reaching external AI endpoints
  • Approved AI tool list enforced at the network and device level, not just in a policy document
  • Session logging for approved AI tools that creates the audit trail required under the Security Rule
  • 4. Workforce Training and Policy

    HIPAA requires covered entities to train all workforce members on policies and procedures. That obligation extends to AI usage.

    Workforce training should address:

  • What constitutes PHI and why it must not enter unapproved AI tools
  • Which AI tools are approved, under what conditions, and with what restrictions
  • How to report suspected PHI incidents involving AI tools
  • Consequences of policy violation
  • A written AI Acceptable Use Policy specific to PHI should be documented, dated, and acknowledged by all workforce members. This document is one of the first things an OCR investigator will request.

    What OCR Looks for in an AI Governance Examination

    HHS OCR investigations have increasingly focused on whether covered entities have conducted thorough risk analyses that account for new technologies. The 2013 HIPAA Omnibus Rule expanded this obligation, and OCR guidance since 2023 has explicitly included AI among technologies that must be addressed in the required Security Rule risk analysis.

    The documentation OCR expects includes:

  • A current, dated risk analysis that includes AI tools
  • Policies and procedures addressing AI use and PHI
  • Evidence of workforce training
  • BAA inventory including AI vendors
  • Remediation plans for identified gaps
  • Organizations without this documentation face penalties under 45 CFR §164.308(a)(1). Willful neglect violations carry a minimum civil penalty of $10,000 per violation with a maximum of $50,000 — per violation category, per year.

    The Centience Approach

    Most governance programs fail not because policies are wrong, but because policies cannot be enforced. If you do not control the infrastructure, you cannot enforce the controls.

    Centience builds AI governance programs on managed infrastructure. That means DLP rules are active on your endpoints, not just written in a policy. AI tool access is governed at the network level. Audit logs are assembled in advance, not reconstructed after an incident.

    The starting point is an AI Governance Assessment that identifies every tool, maps PHI exposure, and delivers a prioritized roadmap before your next OCR examination.

    Is your organization ready for a HIPAA AI governance examination?

    Schedule your AI Governance Assessment. Instant results — your score in minutes.

    Book Your AI Governance Assessment

    Orville Matias, Founder and CEO of Centience

    Article written by

    Orville Matias

    Orville Matias is Founder & CEO of Centience, an AI and Technology Governance firm for regulated industries. He has 20+ years of experience building and operating compliance programs for organizations under SEC, FINRA, and HIPAA oversight.

    Ready to Build a Defensible Governance Program?

    Centience delivers AI and technology governance built on managed infrastructure — enforceable, not just documented.

    Get Your Free Governance Score