← The Health AI Toolkit

HIPAA, BAAs and security basics

Can you put this information into an AI tool? Start with whether HIPAA applies to your practice, then check the agreement and how the tool handles the information.

Insurance-based and cash-pay practice guide →

When does HIPAA apply?

Start with the organization’s role. HIPAA covers health plans, health care clearinghouses, and health care providers that transmit health information electronically in a HIPAA-standard transaction. For a practice, that includes electronic insurance claims, eligibility inquiries and referral authorization requests — including those a billing service sends on its behalf. Using email or an electronic chart alone does not establish this status.

  • Insurance-based practice: electronic claims or eligibility checks generally establish covered-provider status. Outsourcing billing does not remove that responsibility.
  • Cash-pay visit at a covered practice: the patient’s protected health information remains protected. Paying cash does not opt that encounter out of HIPAA.
  • Entirely cash-pay practice: assess whether any covered electronic transactions occur, including through another party. If the practice is outside HIPAA, professional confidentiality, applicable state privacy law, consumer protection and contracts still matter. The FTC Health Breach Notification Rule covers certain personal-health-record vendors and related entities; it is not a blanket rule for every cash-pay clinic.
  • Vendor working for a covered practice: creating, receiving, maintaining or transmitting PHI for covered functions can make it a business associate. The work creates that status; signing a contract is not the trigger.

What information counts? Protected health information (PHI) is individually identifiable information about health, care or payment held or transmitted by a covered entity or business associate, subject to the rule’s exclusions. It can be spoken, on paper or digital: a visit recording, transcript, intake form or billing record can qualify. Electronic PHI is called ePHI; the Security Rule specifically protects that electronic information. Removing a name alone does not establish de-identification.

Read the HHS Privacy Rule summary and the insurance and cash-pay workflow guide.

What is a BAA?

A business associate agreement (BAA) is the written agreement governing a business associate’s handling of PHI for a covered entity. An AI transcription service or cloud provider handling that information can be a business associate, even if it only stores encrypted data and cannot read it. Business associates also have direct obligations under parts of HIPAA.

The agreement sets permitted uses and disclosures, safeguards, incident and breach reporting, support for patient rights, obligations for subcontractors handling PHI, and return or destruction of information at the end of service where feasible. Subcontractors handling PHI need the appropriate agreements too. Your agreement with one vendor does not automatically cover a separate app you connect to it.

Before using patient data: confirm that the applicable BAA is actually in place for your organization and account, then check the covered plan, features, integrations, retention settings and permitted purposes. A vendor offering a BAA does not make every version of its product suitable for every workflow. A free account can qualify when its actual terms and scope do.

A BAA does not supply patient permission for every use or certify your practice as compliant. HIPAA permits many treatment, payment and operations uses without a separate authorization, but recording consent, other laws and uses beyond those permissions need their own assessment. Employees acting within their workforce role do not each need a BAA; sharing with another provider for treatment does not, by itself, make that provider your business associate.

See HHS business associate guidance and the account-by-account BAA setup guide.

A practical security routine

The Security Rule calls for administrative, physical and technical safeguards that protect the confidentiality, integrity and availability of ePHI. For a small practice, that means assigning responsibility and documenting risks as well as configuring the tools. These are useful starting actions:

  1. Map the data and name an owner. List where forms, recordings, transcripts, prompts, outputs, logs and backups go; who can access them; and how long they remain. Use that map in a documented risk analysis and risk management plan. Revisit it when workflows or vendors change.
  2. Protect individual accounts. Use organization-managed accounts, unique credentials, a password manager and multi-factor authentication (MFA). Prefer phishing-resistant options such as security keys or supported passkeys. Give each person only the access their work needs; remove it promptly when roles change or people leave.
  3. Secure devices and connections. Keep software patched, encrypt sensitive information in storage and transit, use screen locks, and protect physical devices and paper files. Include staff phones, downloaded files and work done from home in the plan.
  4. Control sharing and retention. Approve integrations and recipients before connecting them. Avoid public sharing links for patient information. Send only what the task needs; set a retention and deletion policy that respects medical-record and other legal requirements.
  5. Practice recovery and response. Back up necessary records and test restoring them. Review access and activity logs. Decide whom staff should contact after a lost device, suspicious login or mistaken disclosure, and who handles incident assessment and required notifications.
  6. Train the team and test the workflow. Rehearse with fictional data, including what to do if a patient declines recording or a tool fails. Teach staff to spot phishing and report mistakes. Review AI drafts for clinical accuracy before using them in care; that is a separate check from privacy and security.

This routine is not a complete HIPAA program. Required policies, workforce training, patient rights and breach duties still need to be addressed. The recommendations here, including MFA and encryption, are practical safeguards; they do not turn every suggested setting into a universal legal mandate. HHS distinguishes the currently effective Security Rule from proposed changes.

Start with the current HHS Security Rule summary and NIST’s MFA guidance.

Follow one visit all the way through

Consider a visit recording that becomes a transcript, an AI draft and a reviewed EHR note. Check the recorder’s account and recording permissions, the transcription and AI services’ applicable BAAs and settings, and the EHR destination. Then check the less visible copies: synced folders, meeting participants, emailed summaries, logs and retained audio. Decide which copies belong in the medical record and how to handle the rest under your retention policy.

Ask three separate questions: May we use the information for this purpose? Is every recipient and service authorized to handle it? Is the resulting clinical work accurate enough to use? A good answer to one does not settle the other two.

Check the obligations for your role

Covered entityclinician, practice, health plan

  • HIPAA
  • State medical privacy law

Confirm the applicable BAA, covered services, approved configuration and safeguards. A vendor’s willingness to sign is only a starting point.

Business associatehandling PHI for a covered entity

  • HIPAA duties + BAA
  • Your contract terms

Your work with PHI can establish business-associate status before any agreement is signed. Confirm your direct HIPAA duties, contract terms and agreements with PHI-handling subcontractors.

Outside HIPAAconfirm status; cash-pay alone does not decide it

  • Applicable state privacy law
  • FTC Act §5
  • FTC Health Breach Rule if applicable

A provider’s HIPAA status depends on covered electronic transactions, including those performed on its behalf. Non-covered operators still need to assess professional, state, consumer-protection and contractual obligations.

Researchassess the actual study and protocol

  • Research rules as applicable
  • Institutional protocol
  • HIPAA if applicable

Confirm institutional and protocol permissions before sharing. Quality work is not automatically regulated human-subjects research; de-identification does not override protocol or contractual limits.

Primary sources

This orients; it does not advise. Reach your own conclusion with your own counsel. Not legal advice, and no professional relationship is created.