Back to Insights
AI Governance

HIPAA AI Compliance: What Healthcare Organizations Must Govern When Using AI in 2026

Entering protected health information into an AI tool without a signed Business Associate Agreement is a direct HIPAA violation. Most consumer AI platforms do not offer BAAs, do not meet the Security Rule's technical safeguard requirements, and are not designed for healthcare use. Here is what compliant AI governance looks like.

Orville Matias
Orville Matias
HIPAA AI Compliance: What Healthcare Organizations Must Govern When Using AI in 2026

$7.4M

Average Healthcare Breach Cost

Highest of any industry, 14 consecutive years (IBM 2025)

$1.5M

Maximum Civil Penalty

Per violation category per year under HIPAA

57%

Healthcare Workers

Report encountering unauthorized AI tools at their organization (Wolters Kluwer 2025)

35%

AI Data Flow Visibility

Average healthcare organization visibility into AI data flows

Here is a scenario playing out at healthcare organizations across the country right now: a clinical administrator pastes a patient's discharge summary into ChatGPT to help draft a follow-up letter. A billing coordinator uses an AI tool to summarize insurance claim details. A physician asks an AI assistant to help draft clinical documentation.

In each case, protected health information has left the healthcare organization's environment and entered a third-party AI platform — without a signed Business Associate Agreement, without evaluation of the platform's security controls, and without any record of the disclosure.

Each instance is a potential HIPAA violation. Depending on the volume and the nature of the information disclosed, each instance carries civil penalty exposure up to $1.5 million per violation category per year.

The Health Insurance Portability and Accountability Act's Privacy Rule and Security Rule were written in an era before AI was a mainstream business tool. But they apply fully to how healthcare organizations handle protected health information today — regardless of the technology involved.

The Business Associate Agreement requirement is the most immediately relevant provision. Under HIPAA, any vendor or service provider that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a "business associate" — and must sign a BAA before receiving any PHI.

⚖️ Rule

45 CFR § 164.502(e)(1): A covered entity may disclose PHI to a business associate only if the covered entity obtains satisfactory assurance, in the form of a written contract, that the business associate will appropriately safeguard the information. A Business Associate Agreement is not a nicety. It is a legal precondition for any PHI disclosure to a third-party service provider.

Consumer AI platforms — including the personal-use versions of ChatGPT, Claude, Gemini, and others — are not HIPAA business associates. They do not offer Business Associate Agreements as a standard feature. Their terms of service typically permit use of submitted data to improve their models, which is incompatible with HIPAA's use limitation requirements. Inputting PHI into these platforms is a direct HIPAA violation regardless of what the employee intended.

Some AI platforms offer HIPAA-aligned enterprise versions with BAAs available. Even where BAAs exist, the healthcare organization must evaluate whether the platform's security architecture satisfies the Security Rule's technical safeguard requirements before using it for PHI.

What the Security Rule Requires for AI Systems Processing PHI

The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic PHI. When AI systems process PHI, those systems must satisfy the Security Rule's requirements.

Technical safeguards (45 CFR § 164.312) are particularly relevant for AI:

Access Controls — Only authorized individuals may access systems that process PHI. AI tools used for PHI processing must implement role-based access controls, unique user identification, and automatic logoff provisions. Consumer AI platforms accessible with a free account and no identity verification do not satisfy this requirement.

Audit Controls — Organizations must implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use electronic PHI. AI systems must generate and retain audit logs of PHI access and processing. Most consumer AI platforms do not provide healthcare-grade audit logging.

Integrity Controls — Electronic PHI must be protected from improper alteration or destruction. AI systems processing PHI must implement controls to verify that data has not been improperly modified.

Transmission Security — When PHI is transmitted electronically, encryption is required. Data transmitted to AI APIs or platforms must be encrypted in transit, and the platform must implement appropriate encryption at rest.

Risk Analysis — Before deploying any AI system that processes PHI, the organization must conduct a risk analysis under 45 CFR § 164.308(a)(1). The risk analysis must identify threats and vulnerabilities specific to the AI system, assess the likelihood and impact of those risks, and document mitigation measures.

Shadow AI in Healthcare: The Invisible Exposure

The most significant HIPAA AI compliance risk for most healthcare organizations is not the AI tools they have formally evaluated and deployed. It is the AI tools their employees are using without authorization.

The Wolters Kluwer 2025 Healthcare AI Readiness Report found that 57% of healthcare respondents had encountered or used an unauthorized AI tool at their organization. The IBM Cost of a Data Breach Report found that healthcare organizations have, on average, only 35% visibility into what AI tools are processing their data. The gap between what employees are doing with AI and what the organization knows about is the compliance gap.

⚠️ Warning

The CB Financial Form 8-K filed in May 2026 — the first SEC cybersecurity disclosure triggered by shadow AI rather than an external attack — is the most visible public illustration of the shadow AI risk. One employee, one unauthorized AI tool, one regulatory disclosure. Healthcare organizations face the same risk under HIPAA, where the consequences include OCR investigation, civil penalties, corrective action plans, and state attorney general actions.

The pattern is consistent: the unauthorized AI use happens at the level of individual employees trying to get their work done more efficiently. The breach is discovered after the fact — often through a vendor audit, a patient complaint, or an internal security review. By that point, the disclosure has occurred, the violation is complete, and the organization's options are limited to remediation and disclosure to OCR.

OCR Enforcement in 2025–2026: What the Agency Is Prioritizing

The HHS Office for Civil Rights is the primary HIPAA enforcement agency. OCR's enforcement activity in recent years has focused heavily on areas where technical safeguards were absent or inadequate — the same category of failure that AI governance addresses.

Recent enforcement trends relevant to AI governance:

Risk analysis failures remain the most commonly cited HIPAA violation in OCR settlements. Organizations that deploy AI systems processing PHI without a documented risk analysis are accumulating the most common HIPAA enforcement risk.

Impermissible disclosures — the unauthorized disclosure of PHI to third parties — are a direct consequence of employees using consumer AI platforms. Each instance of a covered employee inputting PHI into an unauthorized AI tool is a potential impermissible disclosure under 45 CFR § 164.502.

Lack of Business Associate Agreements is specifically cited in enforcement actions where PHI was disclosed to vendors without a signed BAA. The absence of a BAA with an AI platform used to process PHI is a straightforward violation.

Audit control failures — the absence of audit logging for systems that access PHI — are increasingly relevant as AI systems process clinical data without generating the audit logs OCR expects to review in investigations.

What HIPAA-Compliant AI Governance Requires

A HIPAA-compliant AI governance program for a healthcare organization has five components:

1

AI Inventory

Identify every AI tool employees are using — across clinical, administrative, and operational functions. Include embedded AI features in existing software platforms that may have been enabled by default.

2

BAA Evaluation

For every AI tool that will process PHI, obtain a signed Business Associate Agreement before any PHI is transmitted. Verify that the BAA addresses HIPAA-required provisions, not just vendor-standard data processing terms.

3

Risk Analysis

Conduct a HIPAA Security Rule risk analysis for each AI system that will process PHI. Document threats, vulnerabilities, likelihood, impact, and mitigation measures. Update the risk analysis when AI systems change.

4

Technical Safeguards Review

Verify that each authorized AI platform implements required technical safeguards: access controls, audit logging, integrity controls, and transmission security. Document the evaluation.

5

Employee Training and Technical Controls

Train employees on HIPAA obligations when using AI and implement technical controls — approved tool lists enforced at the network level, DLP rules that prevent PHI from reaching unauthorized platforms — to enforce the policy.

The BAA Landscape for Enterprise AI Platforms

Healthcare organizations frequently ask which AI platforms offer BAAs. The landscape has evolved significantly in the last 18 months:

Microsoft Azure OpenAI Service offers a BAA as part of the Microsoft Online Services BAA for eligible Enterprise customers. Organizations using Microsoft 365 Copilot in a healthcare context must ensure their BAA covers the specific services they are using.

Google Cloud Healthcare API and Vertex AI are covered under Google's BAA for healthcare customers. Standard Google Workspace AI features require evaluation of which specific features are covered.

Amazon Web Services offers a BAA covering eligible AWS services, including certain AI and machine learning services. The BAA must be specifically activated; it is not automatic.

Anthropic, OpenAI, and others — consumer-facing AI platforms from major AI developers do not uniformly offer BAAs. Enterprise agreements and healthcare-specific partnerships vary by vendor and are evolving. Verify current BAA availability directly with each vendor before any PHI processing.

📌 Important

A signed BAA is a necessary condition for HIPAA-compliant PHI processing by an AI platform — but it is not sufficient. The platform must also implement the technical safeguards the Security Rule requires. A BAA with a platform that lacks adequate access controls, audit logging, or encryption does not make your PHI processing compliant.

The Telehealth and Remote Care Expansion

The expansion of telehealth and AI-assisted remote monitoring has created new categories of PHI processing that healthcare organizations must govern. AI tools used in telehealth platforms, remote patient monitoring, clinical documentation assistance, and care coordination software all process PHI — often at greater scale and with less visibility than traditional electronic health record systems.

The same principles apply: BAA required before PHI transmission, Security Rule safeguards required for PHI processing, risk analysis required before deployment, and audit logging required for PHI access. The telehealth context does not create HIPAA exceptions — it extends HIPAA obligations to a broader range of technology.

Organizations that deployed telehealth platforms rapidly during and after the COVID-19 pandemic often did so without full HIPAA compliance evaluation. AI features added to those platforms since deployment may not have been evaluated at all. A comprehensive AI inventory should include every telehealth platform in the organization's technology stack.

🔗 Related Service: AI Governance Program

Centience builds HIPAA-compliant AI governance programs for healthcare organizations — BAA evaluation, risk analysis, technical safeguards, and audit-ready documentation.

Learn More →

Orville Matias, Founder and CEO of Centience

Article written by

Orville Matias

Orville Matias is Founder & CEO of Centience, an AI and Technology Governance firm for regulated industries. He has 20+ years of experience building and operating compliance programs for organizations under SEC, FINRA, and HIPAA oversight.

Frequently Asked Questions

Ready to Build a Defensible Governance Program?

Centience delivers AI and technology governance built on managed infrastructure — enforceable, not just documented.

Get Your Free Governance Score