← The Health AI Toolkit

Does HIPAA apply to your practice?

Start with whether HIPAA applies to your practice. Then check the task and the information you plan to share.

Setup review · About 20 min to try; setup approval may take longer.

Bring: The practice’s status and the information used in the proposed workflow.

Make: Questions for the practice’s privacy or legal lead.

Jump to the copyable prompt ↓

Guide sources and teaching inputs checked . Vendor directory claims retain their own review dates.

Payment model alone does not decide HIPAA status

An insurance-based practice commonly conducts HIPAA-standard electronic transactions. For a provider, that transaction test—not simply accepting insurance or using an EHR—is central to covered-entity status. A billing service may conduct those transactions on the provider’s behalf.

Cash-pay does not automatically mean outside HIPAA. A covered practice’s cash-pay encounters do not lose their protections because the patient pays directly. A genuinely non-covered practice still needs to assess applicable state law, professional confidentiality, contracts and consumer-protection obligations.

Insurance-based practice: begin with the approved clinical stack

For chart summaries, scribes, record updates and patient messages using PHI, start with your organization’s approved account, covered services and workflow. Verify the executed BAA where required, feature scope, access roles, retention and downstream processors. A product listed in a directory is not approval for your specific use.

For public literature searches, blank templates or fictional teaching cases, you can often avoid sharing patient information altogether. Keep records out of browser search queries, screenshots, support tickets and development logs. A useful boundary is a public research task alongside a separately approved clinical record workflow.

For prior-authorization or billing letters, draft from verified facts in the approved workflow. Have the responsible person check diagnoses, dates, medical necessity and payer requirements. Do not let persuasive wording create unsupported clinical claims.

Cash-pay practice: write down the same operational boundaries

First document whether the practice is a covered entity or business associate; ask the practice’s privacy or legal lead when uncertain. Then make an approved-tool list, define access and retention, explain material uses to patients as required, and retain clinician review for decisions and communications.

For operators outside HIPAA, the FTC Health Breach Notification Rule applies to qualifying personal-health-record vendors and related entities; it is not a blanket rule for every cash-pay clinic. State requirements vary. New York’s physician professional-conduct rules, for example, address unauthorized disclosure of identifiable patient information.

For memberships and care packages, separate a quote, an unpaid checkout and a completed payment. Verify the current service and renewal status before changing an account. Use reviewed templates to explain scope, price and follow-up; an AI-generated promise should not expand the care you actually provide.

Classify the workflow, not just the tool

Public paper → research draft: keep it public and check the evidence. Identifiable chart → AI summary: evaluate the regulated data path. Patient message → proposed chart change: add clinical approval and verified record handling. Fictional records → prototype: keep it fictional through the entire exercise. Marketing or newsletter systems should not quietly receive chart information.

These are starting points for a workflow review, not a legal determination about your practice. Document who owns approval and revisit it when a connector, feature or vendor plan changes.

Patient permission is a separate question

HIPAA permits many treatment, payment and health-care-operations uses without a separate patient authorization, subject to the applicable rules. That does not authorize every AI disclosure. A patient’s agreement does not replace required vendor agreements, safeguards or your organization’s approval.

For recording or ambient documentation, separately check applicable recording law, organizational policy and how patients are informed or offered an alternative. Technical access to a microphone or chart is not the same as permission for the proposed use.

Copy a prompt to try

Compare business records before acting

Practice ops

Compare these fictional business records: {{fictional_records}}.
Build a dated table of completed transactions, unpaid checkouts, active products
and renewal notices. State the source for each entry and any conflict.
Do not treat an unpaid checkout as a purchase or an old notice as current status.
Propose the smallest action and list the facts I must verify first.
Do not cancel, purchase, refund, send or change anything.

The talk’s membership example illustrates checking status before a consequential action. Use fictional records to practice and confirm permissions before connecting real accounts.

Check before you use the result

  • Confirm covered-entity or business-associate status.
  • Review the particular workflow and account.
  • Keep clinical records out of marketing and newsletter systems.
  • Check patient permission and recording requirements separately.

Sources to check

Next: Get a BAA in place before sharing PHI →Explore the practical workflows →