AI tools are now embedded in clinical documentation, revenue cycle management, patient scheduling, and internal communications at healthcare organizations across the country. Most were deployed without a governance framework. That is the problem.
$10,000
Minimum HIPAA Penalty
Per violation, willful neglect
$50,000
Maximum Per Violation
Per violation category per year
$1.9M
Average Healthcare Breach Cost
2024 IBM Cost of Data Breach Report
5 Days
Assessment Turnaround
Centience AI Governance Assessment
HIPAA's Privacy Rule and Security Rule do not carve out an exception for artificial intelligence. If a tool touches, processes, transmits, or stores protected health information (PHI), it falls under HIPAA's obligations — regardless of whether the vendor calls it "AI," "automation," or "intelligent workflow."
Here is what a defensible AI governance program looks like for a HIPAA-regulated organization.
Why AI Creates New HIPAA Exposure
Most healthcare organizations have existing policies for data access, breach notification, and vendor management. Those policies were written before generative AI existed. They do not account for the way AI tools ingest context, retain conversation history, train on user inputs by default, or expose PHI through prompt injection.
The specific exposures include:
PHI ingestion through AI prompts. Staff using tools like ChatGPT, Microsoft Copilot, or Google Gemini may inadvertently include patient names, dates of service, diagnosis codes, or account numbers in prompts. Without technical controls preventing this, every prompt becomes a potential breach event.
Business Associate Agreements. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate and requires a signed BAA. Many AI vendors — including major platforms — either do not offer HIPAA-compliant configurations or have BAA terms that shift liability in ways most compliance officers have not reviewed.
Audit trail gaps. The HIPAA Security Rule requires covered entities to implement audit controls — hardware, software, and procedural mechanisms that record and examine activity in systems containing PHI. Most AI tools generate no audit log accessible to the covered entity.
Proposed 2025 HIPAA Security Rule Update. HHS OCR has a proposed Security Rule modernization on the May 2026 agenda that includes explicit requirements for technology asset inventories and access controls. Organizations without an AI inventory today will be non-compliant under the proposed rule before it finalizes.
The Four Pillars of an AI Governance Framework Under HIPAA
AI Inventory
Discover every AI tool touching PHI — licensed, embedded, or employee-accessed. Classify by risk level.
BAA Audit
Verify executed Business Associate Agreements cover every AI vendor processing PHI. Remediate gaps immediately.
Technical Controls
Deploy DLP, endpoint policies, and approved tool lists enforced at the network level — not just in documentation.
Workforce Training
Train all workforce members on AI acceptable use and PHI handling. Document acknowledgment.
1. AI Inventory
You cannot govern what you cannot see. The first step is a complete discovery of every AI tool in use across the organization — including tools deployed by individual departments, embedded in third-party software, or accessed via personal devices.
📌 Important
Each tool in the inventory should be evaluated for:
Organizations that skip this step will discover exposure during an HHS OCR investigation, not before it.
2. Business Associate Agreement Audit
Every AI vendor that touches PHI requires a valid BAA. This is non-negotiable under 45 CFR §164.308(b).
A BAA audit for AI should cover:
Microsoft 365 Copilot, Google Workspace with Gemini, and several major EHR vendors now offer HIPAA-aligned AI configurations — but only under specific licensing tiers and only when BAAs are executed correctly.
3. Technical Controls
Governance without enforcement is just documentation. Technical controls operationalize your policies:
4. Workforce Training and Policy
HIPAA requires covered entities to train all workforce members on policies and procedures. That obligation extends to AI usage.
Workforce training should address:
A written AI Acceptable Use Policy specific to PHI should be documented, dated, and acknowledged by all workforce members. This document is one of the first things an OCR investigator will request.
What OCR Looks for in an AI Governance Examination
HHS OCR investigations have increasingly focused on whether covered entities have conducted thorough risk analyses that account for new technologies. The 2013 HIPAA Omnibus Rule expanded this obligation, and OCR guidance since 2023 has explicitly included AI among technologies that must be addressed in the required Security Rule risk analysis.
The documentation OCR expects includes:
Organizations without this documentation face penalties under 45 CFR §164.308(a)(1). Willful neglect violations carry a minimum civil penalty of $10,000 per violation with a maximum of $50,000 — per violation category, per year.
The Centience Approach
Most governance programs fail not because policies are wrong, but because policies cannot be enforced. If you do not control the infrastructure, you cannot enforce the controls.
Centience builds AI governance programs on managed infrastructure. That means DLP rules are active on your endpoints, not just written in a policy. AI tool access is governed at the network level. Audit logs are assembled in advance, not reconstructed after an incident.
The starting point is an AI Governance Assessment that identifies every tool, maps PHI exposure, and delivers a prioritized roadmap before your next OCR examination.
Is your organization ready for a HIPAA AI governance examination?
Schedule your AI Governance Assessment. Instant results — your score in minutes.





