Covered entityclinician, practice, health plan
- HIPAA
- State medical privacy law
Confirm the applicable BAA, covered services, approved configuration and safeguards. A vendor’s willingness to sign is only a starting point.
Can you put this information into an AI tool? Start with whether HIPAA applies to your practice, then check the agreement and how the tool handles the information.
Insurance-based and cash-pay practice guide →Start with the organization’s role. HIPAA covers health plans, health care clearinghouses, and health care providers that transmit health information electronically in a HIPAA-standard transaction. For a practice, that includes electronic insurance claims, eligibility inquiries and referral authorization requests — including those a billing service sends on its behalf. Using email or an electronic chart alone does not establish this status.
What information counts? Protected health information (PHI) is individually identifiable information about health, care or payment held or transmitted by a covered entity or business associate, subject to the rule’s exclusions. It can be spoken, on paper or digital: a visit recording, transcript, intake form or billing record can qualify. Electronic PHI is called ePHI; the Security Rule specifically protects that electronic information. Removing a name alone does not establish de-identification.
Read the HHS Privacy Rule summary and the insurance and cash-pay workflow guide.
A business associate agreement (BAA) is the written agreement governing a business associate’s handling of PHI for a covered entity. An AI transcription service or cloud provider handling that information can be a business associate, even if it only stores encrypted data and cannot read it. Business associates also have direct obligations under parts of HIPAA.
The agreement sets permitted uses and disclosures, safeguards, incident and breach reporting, support for patient rights, obligations for subcontractors handling PHI, and return or destruction of information at the end of service where feasible. Subcontractors handling PHI need the appropriate agreements too. Your agreement with one vendor does not automatically cover a separate app you connect to it.
Before using patient data: confirm that the applicable BAA is actually in place for your organization and account, then check the covered plan, features, integrations, retention settings and permitted purposes. A vendor offering a BAA does not make every version of its product suitable for every workflow. A free account can qualify when its actual terms and scope do.
A BAA does not supply patient permission for every use or certify your practice as compliant. HIPAA permits many treatment, payment and operations uses without a separate authorization, but recording consent, other laws and uses beyond those permissions need their own assessment. Employees acting within their workforce role do not each need a BAA; sharing with another provider for treatment does not, by itself, make that provider your business associate.
See HHS business associate guidance and the account-by-account BAA setup guide.
The Security Rule calls for administrative, physical and technical safeguards that protect the confidentiality, integrity and availability of ePHI. For a small practice, that means assigning responsibility and documenting risks as well as configuring the tools. These are useful starting actions:
This routine is not a complete HIPAA program. Required policies, workforce training, patient rights and breach duties still need to be addressed. The recommendations here, including MFA and encryption, are practical safeguards; they do not turn every suggested setting into a universal legal mandate. HHS distinguishes the currently effective Security Rule from proposed changes.
Start with the current HHS Security Rule summary and NIST’s MFA guidance.
Consider a visit recording that becomes a transcript, an AI draft and a reviewed EHR note. Check the recorder’s account and recording permissions, the transcription and AI services’ applicable BAAs and settings, and the EHR destination. Then check the less visible copies: synced folders, meeting participants, emailed summaries, logs and retained audio. Decide which copies belong in the medical record and how to handle the rest under your retention policy.
Ask three separate questions: May we use the information for this purpose? Is every recipient and service authorized to handle it? Is the resulting clinical work accurate enough to use? A good answer to one does not settle the other two.
Confirm the applicable BAA, covered services, approved configuration and safeguards. A vendor’s willingness to sign is only a starting point.
Your work with PHI can establish business-associate status before any agreement is signed. Confirm your direct HIPAA duties, contract terms and agreements with PHI-handling subcontractors.
A provider’s HIPAA status depends on covered electronic transactions, including those performed on its behalf. Non-covered operators still need to assess professional, state, consumer-protection and contractual obligations.
Confirm institutional and protocol permissions before sharing. Quality work is not automatically regulated human-subjects research; de-identification does not override protocol or contractual limits.
This orients; it does not advise. Reach your own conclusion with your own counsel. Not legal advice, and no professional relationship is created.