HIPAA and AI: Can Healthcare Providers Use an AI Assistant?
Clinicians want AI for the same reasons everyone does: notes, summaries, drafting, admin. But the moment protected health information (PHI) enters the picture, HIPAA sets rules that most consumer AI tools simply do not meet.
The core requirement: a Business Associate Agreement
Under HIPAA, any vendor that handles PHI on your behalf is a Business Associate and must sign a Business Associate Agreement (BAA). No BAA, no PHI, full stop. Most consumer AI products do not offer a BAA, which means putting a patient's information into them is a disclosure to a third party outside the HIPAA framework. That is the violation, regardless of how careful you were with the wording.
Why "I removed the name" is not enough
De-identification under HIPAA is a specific standard. Removing a name does not de-identify a record if the remaining details could reasonably identify the patient. Dates, rare conditions, location, and the combination of ordinary facts can re-identify someone. Assuming your quick edit met the Safe Harbor or Expert Determination standard is a risk most practices should not take casually.
What a compliant AI setup requires
- A signed BAA with the AI provider, or an architecture where PHI never leaves your control in the first place.
- Processing on infrastructure the provider controls, not anonymously brokered through APIs you cannot audit.
- No training on your content, so patient information cannot surface in a model that answers a stranger later.
- Access controls and an audit trail, the same expectations you apply to any system touching PHI.
Where private AI fits
Private AI that runs on infrastructure the provider controls and never trains on your content narrows the exposure surface dramatically, and a provider operating in this category can put a BAA in place because the architecture was built for exactly this. The point is not to fear AI; it is to use the kind that was designed for regulated data instead of the kind designed for consumer scale.
The short version
HIPAA does not ban AI; it bans handing PHI to a vendor with no BAA and no controls. Consumer AI usually offers neither. A private AI built for confidentiality, with a BAA and no training on your content, is how a practice gets the leverage without the violation. This is general information, not legal or compliance advice; confirm your setup with your compliance officer.
Private AI that was built for this
Kiyomi runs on Jah, private AI on infrastructure Kiyomi controls. Your core chats are processed privately, never sold or shared, and never used to train a model. It is the AI you can use when confidentiality is not optional.
Try Kiyomi free — then $25/mo for everything.