PHI changes the rules
The moment AI touches protected health information, HIPAA's Privacy and Security Rules apply. Any third-party AI provider that processes PHI becomes a Business Associate and needs a signed Business Associate Agreement (BAA) — and not every provider or plan offers one.
Compliance is organizational, not a feature we can flip on. We build the technical safeguards; your policies, staff training, and legal review complete the picture.
- A signed BAA with every vendor that touches PHI — no BAA, no PHI
- Not all AI provider tiers are BAA-eligible; we select ones that are
- Minimum-necessary: send only the PHI the task actually requires
- De-identification where the full record isn't needed
- Compliance spans people, policy, and technology — not code alone
Technical safeguards we implement
On the build side we apply the access, encryption, and logging controls HIPAA's Security Rule expects, and design so PHI is minimized or de-identified before it reaches any model that doesn't need the full record.
Where PHI shouldn't leave your environment at all, we use self-hosted models.
- Encryption of PHI in transit and at rest
- Role-based access controls and unique user IDs
- Audit logs of every access and AI query touching PHI
- De-identification or redaction before external processing where possible
- Self-hosted models for PHI that shouldn't leave your environment
- Automatic session timeouts and secure key management
Honest boundaries
We're an engineering partner, not your compliance officer or attorney, and this isn't legal advice. We won't claim a system is "HIPAA certified" — there is no such certification for software.
What we deliver are the technical safeguards and documentation that support your compliance program, working alongside your legal, privacy, and clinical teams.
- Not legal or clinical advice — pair us with your counsel and compliance staff
- No "HIPAA certified" claims (that certification doesn't exist for software)
- AI outputs are decision support, not diagnosis
- A licensed clinician stays in the loop for care decisions
- Documentation to support your own risk assessment
More on ai integrations
Frequently asked questions
Can you make our AI integration HIPAA compliant?
We build the technical safeguards HIPAA requires and select BAA-backed providers, but compliance is organizational — it also depends on your policies, staff training, and risk assessment. We work alongside your compliance and legal teams.
Can we use ChatGPT or similar consumer tools with patient data?
Not the consumer versions. PHI requires a provider that will sign a BAA, which typically means specific enterprise or API tiers — and even then, only with the right safeguards around them.
Can AI diagnose or make treatment decisions?
No — we treat AI as decision support only. A licensed clinician stays responsible for care decisions, and we build that human-in-the-loop boundary in deliberately.