← Back to articles
Safety · Privacy & Compliance

Is Your Medical AI HIPAA-Compliant? A Clinician's Checklist

· 6 min read ·

Medically reviewed by Dr. L · General Medicine, UK

Blueprint-style line illustration of medical data privacy and HIPAA compliance: a padlock inside a shield, a locked document, and a protected data network on a dark navy background.

“Is this tool HIPAA-compliant?” is one of the most common, and most misunderstood, questions clinicians ask about medical AI. The misunderstanding is in the framing: compliance is not a sticker a tool earns once and displays forever. It is a function of how the vendor handles your patients’ data and what they will commit to contractually. Here is what actually matters before you type a patient detail into any AI tool.

What HIPAA compliance actually means for an AI tool

In the US, HIPAA governs how protected health information (PHI) is used and disclosed. When a clinician or health system uses an outside vendor to process PHI, that vendor becomes a business associate, and the relationship has to be governed by a contract. So “is it HIPAA-compliant?” really decomposes into two practical questions:

  1. Does the vendor handle PHI in a way that meets HIPAA’s privacy and security requirements?
  2. Will the vendor sign a Business Associate Agreement (BAA) with your organization?

If the answer to either is no, the tool is not appropriate for identifiable patient data, no matter how strong its encryption or how reassuring its marketing. The U.S. Department of Health & Human Services maintains the authoritative guidance on this for health professionals.

The single most important question: is there a BAA?

The BAA is the load-bearing element. It is the legal instrument that binds a vendor to protect the PHI you share with it and to use it only as permitted. Without a signed BAA in place, entering PHI into a third-party tool is a HIPAA violation regardless of the tool’s technical safeguards.

This is why general-purpose consumer chatbots are a problem for patient data: most do not offer a BAA for their consumer products. Some vendors offer enterprise or API tiers that do include a BAA, but the everyday consumer app usually is not covered. Never assume; confirm.

Most evidence tools don’t need PHI at all

Here is the reassuring part. A large share of clinical AI use does not involve patient-identifiable data in the first place. Asking “what’s the first-line management for X?” or “what does the latest guideline say about Y?” is a general clinical question, no PHI required. Tools built around evidence retrieval are designed for exactly this kind of query.

Used this way, general questions, no patient identifiers, these tools sidestep the PHI issue entirely. The discipline is simple: keep the question general, and never paste a patient’s identifiable details to “make it specific.”

De-identification is not a loophole

Clinicians sometimes assume that deleting the name makes a case safe to share. It does not. HIPAA recognizes 18 identifiers, and data is only de-identified when all of them are removed (or a formal statistical determination is made). Dates of service, a rare diagnosis, age over 89, and geographic specifics can re-identify a patient in combination. Treat partial redaction as insufficient and assume identifiable detail is still PHI.

Compliance is jurisdictional

HIPAA is a US framework. Clinicians in the EU and UK answer to the GDPR and national rules, which carry their own, sometimes stricter, requirements around consent, data residency, and processing. A tool that is fine for a US clinician may have a different posture in Europe. Check the framework that governs your jurisdiction, not just HIPAA. Tools that publish a clear GDPR posture alongside HIPAA, as Vera Health does, make this easier to assess.

A quick checklist before you enter patient information

  • Is there a signed BAA between the vendor and your organization? If not, no PHI.
  • Does the tool’s intended use include patient-specific data, or is it built for general clinical questions?
  • What is the data-retention and training policy: is your input used to train models, and can you opt out?
  • Which jurisdiction governs you (HIPAA, GDPR, national law), and does the tool meet it?
  • Default to general questions. If a query can be answered without identifiers, keep it that way.

Compliance is ultimately about a habit, not a logo: confirm the BAA, keep questions general where you can, and never let a tool’s polish substitute for verifying how it handles your patients’ data.

References

Frequently asked

Is medical AI HIPAA-compliant?
It depends entirely on the specific tool and how you use it. HIPAA compliance is not a property a tool simply has, it depends on whether the vendor handles protected health information appropriately and will sign a Business Associate Agreement (BAA) with your organization. Some clinical AI tools offer a BAA and are suitable for PHI; many evidence tools are built for general clinical questions and are not intended for patient-specific data. Always confirm the vendor's posture before entering identifiable information.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a contract, required under HIPAA, between a covered entity (like a clinician or hospital) and a vendor that handles protected health information on its behalf. It legally binds the vendor to safeguard that data. If a medical AI vendor will not sign a BAA, you should treat the tool as unsuitable for any identifiable patient information, full stop, regardless of its security marketing.
Can I enter patient information into ChatGPT or other general chatbots?
Generally no. Consumer, general-purpose chatbots typically do not offer a BAA, which means entering protected health information into them is not HIPAA-compliant. Some vendors offer enterprise or API tiers with a BAA for appropriate use cases; the consumer product usually is not one of them. When in doubt, do not enter identifiable patient data.
Does removing the patient's name make data HIPAA-safe?
Not on its own. HIPAA defines 18 identifiers, and properly de-identified data must have all of them removed or be statistically certified as de-identified. Dates, rare diagnoses, geographic detail, and other combinations can re-identify a patient even without a name. Treat partial redaction as insufficient, and assume identifiable detail remains PHI unless formally de-identified.