Back to blog

Using AI in a HIPAA world: what healthcare practice owners need to know

HIPAA, healthcare data, and AI

AI is changing how practices document visits, triage messages, schedule patients, surface clinical risk, and run the revenue cycle. The pace is fast and the marketing is louder than the substance. Underneath all of it, the legal floor has not moved. HIPAA still governs Protected Health Information, and it does not care whether the system handling that information is a person, a database, or a machine learning model.

For a practice owner, that means the question is not whether AI is allowed. It is whether the way you are using it lines up with the rules you are already required to follow.

Four kinds of AI showing up in healthcare

Not every "AI tool" works the same way. The label gets used loosely, and the differences matter when you decide what to put it in front of and how much oversight it needs.

Autonomous AI. Tools that act on their own inside a defined task. Diabetic retinopathy screening that returns a result without a clinician reading the image. Imaging tools that flag abnormalities. Continuous-monitoring systems that alert when a patient's numbers move the wrong way. The benefit is speed. The catch is liability and oversight, because the system is making a call and someone has to own it.

Augmented intelligence. Tools that recommend, but do not decide. Decision support that suggests a differential. Risk models that flag patients likely to be readmitted. Population analytics that show who to call this week. A clinician stays in the loop. These are easier to govern, but easy enough to over-rely on if no one questions the output.

Automation with AI capabilities. Software that runs administrative work using machine learning or natural-language processing under the hood. Tools that pull data from clinical notes for coding, predict denials, gather prior-authorization documentation, or forecast no-shows. For HIPAA, these usually fit under "healthcare operations." That does not exempt them from access controls, audit trails, training, or a Business Associate Agreement when a vendor is involved.

Generative AI. Tools that produce new content. Ambient scribes that draft notes from a recorded encounter. Drafting assistants for patient instructions or referral letters. Chatbots that answer patient questions using context from the chart. Translation that produces full sentences instead of word-for-word output. Useful, fast, and the most likely category to leak Protected Health Information to a place it should not be if the guardrails are not set up first.

How HIPAA applies to all of it

HIPAA's Privacy, Security, and Breach Notification Rules were written to be technology-neutral. That is the whole point. They apply to PHI regardless of whether a person, a script, or a transformer model is touching it.

A few things follow from that:

The legal framework is not new. What is new is the operational reality that a single staff member can paste a chart note into a public chatbot in three seconds and never tell anyone.

Where state law adds another layer

HIPAA is the federal floor. A growing number of states have layered stricter rules on top of it for AI specifically. Texas is one example. Others are following.

Common state-level requirements include:

If you operate across state lines, the strictest applicable rule wins. Workforce training has to reflect that, not just the federal baseline.

The risks that catch practices off-guard

The breaches that happen with AI usually do not look like the ones you trained your staff on five years ago. Two show up most often.

Inadvertent disclosure. A staff member pastes a real chart note, message, or imaging report into a tool that has not been approved. Sometimes it is a public chatbot. Sometimes it is a free trial plug-in someone installed without telling IT. The information is now in a system you do not control, and that is a reportable event.

Confabulation. AI tools, especially generative ones, will sometimes produce confident-sounding output that mixes unrelated or partially related facts together. A summary of the visit that includes something the patient never said. A draft instruction that contradicts the actual prescription. If staff treat AI output as ground truth and it lands in the chart unverified, the documentation is wrong and the downstream decisions get worse with it.

The slower-moving risks: data leakage when models phone home, model drift as the underlying tool changes behavior over time, and over-reliance from staff who stop catching errors because they trust the assistant.

The way to manage all of this is not to ban AI. It is to make sure there is a path for staff to flag anomalies, that interactions are logged, and that there is a real owner for evaluating new tools and monitoring the ones already in use.

Training your team to use AI without creating a breach

The most useful AI training for healthcare staff is not a slide deck on the four privacy principles. It is a clear, scenario-based walkthrough of the actual tools they touch, what they can put into them, and what they have to validate before acting on the output.

A short list that we have found works:

The point is not to slow your team down. It is to get the value out of these tools without shipping PHI to places it does not belong.

A short list before you adopt any AI tool in a practice

Before a tool sees a single line of PHI:

  1. Confirm the vendor will sign a HIPAA-compliant Business Associate Agreement.
  2. Ask where data goes, where it is processed, and whether it is used to retrain any model.
  3. Verify the security posture you would want from any vendor: SOC 2 Type II at minimum, encryption in transit and at rest, audit logs, and clear access controls.
  4. Map the tool's behavior against the strictest state-level rules that apply to where you operate.
  5. Decide who owns oversight, what gets logged, and how often the tool is reviewed.

AI does not replace the legal framework. It just gives you faster ways to break it if you skip the basics. Practices that do this carefully end up with tools that pay back hours every week. The ones that do not, end up explaining to a regulator why a chart note showed up on someone else's server.

Sources

  1. HIPAA compliance checklist · The HIPAA Journal.
  2. HIPAA Business Associate Agreement requirements · The HIPAA Journal.
  3. AHIMA on the HIPAA minimum necessary standard · The HIPAA Journal.
  4. HIPAA and AI laws in Texas · The HIPAA Journal.
  5. HIPAA AI training for healthcare staff · HIPAA Training.
  6. HIPAA, healthcare data, and artificial intelligence by Steve Alder · The HIPAA Journal, February 5, 2026.

Working through this for your practice?

We help practices set up AI the right way from day one

An operations audit. We map your current tools, your team's actual workflows, and what to fix before you scale anything.