Key Takeaways
AI Is Becoming Part of Everyday Practice Operations
Physicians and practice owners are finding new ways to use artificial intelligence. AI can draft communications, assist with scheduling, generate marketing content, summarize information, support documentation, and automate routine administrative tasks.
Some uses may involve protected health information (PHI). Others may not. That distinction matters.
HIPAA does not prohibit a practice from using AI, but it does regulate how covered entities and their business associates use and disclose PHI. If an AI tool receives patient information, the practice needs to understand what happens to that information and whether the appropriate protections are in place.
The best time to address those questions is before the tool becomes part of your practice’s workflow.
Does HIPAA Apply to the AI Tool You’re Considering?
HIPAA applies to protected health information held or transmitted by covered entities and their business associates. Using an AI platform does not change those obligations. HHS HIPAA Privacy Rule guidance
Start by asking a simple question: Will this AI tool receive PHI?
For example, asking an AI platform to suggest general topics for a practice newsletter generally presents a different issue than entering a patient’s symptoms, diagnosis, treatment history, or appointment information into the same platform.
Before approving an AI tool, identify the information employees could enter into it, including:
- Patient names and contact information
- Diagnoses, symptoms, and treatment information
- Medical records
- Appointment or billing information
- Photographs, recordings, or other patient media
- Any combination of information that could identify a patient
If PHI will be involved, the practice should determine whether the proposed use is permitted and what safeguards are required.
Can doctors put patient information into AI tools?
No blanket rule makes every AI platform permissible or impermissible under HIPAA. The answer depends on the particular tool, how it is configured and used, the information involved, and the contractual and security protections in place.
A physician should not assume that a widely available AI platform is appropriate for PHI simply because it is secure or commonly used. Instead, careful review of the tool and conversations with the vendor may be necessary to determine whether it is a good option for a practice. This is true whether the tool is a chatbot on the practice website or generative AI used to write social media posts.
What Should You Ask an AI Vendor Before Using Its Tool?
A vendor’s website may describe its AI platform as secure, private, or HIPAA compliant. Those statements can be useful starting points, but they are not a substitute for understanding the actual service. Before adopting an AI tool that may handle sensitive practice information, ask:
- What happens to information submitted to the platform? Find out whether information is stored, how long it is retained, and whether it is used to train or improve AI models.
- Who can access the information? Understand the vendor’s access controls and whether third parties or subcontractors will receive the information.
- Can the practice control or delete its data? The agreement should make clear what happens to information during and after the relationship.
- How is the information protected? Review the vendor’s security practices and responsibilities if information is compromised.
- What does the contract actually say? Privacy policies and marketing materials do not necessarily tell the whole story. Review the service agreement, data-processing terms, Business Associate Agreement (BAA), and other documents governing the relationship.
This review is particularly important when an AI tool deals with clinical notes or connects directly to an electronic health record (EHR), patient portal, scheduling system, or another system containing PHI.
When Does an AI Vendor Need a BAA?
An AI vendor may be a business associate when it performs certain functions or provides services on behalf of a covered entity that involve access to PHI. In those circumstances, HIPAA generally requires a written business associate agreement addressing the vendor’s responsibilities for protecting that information.
For example, an AI company that processes PHI on behalf of a medical practice may have a very different relationship with the practice than a consumer AI platform being used for general brainstorming.
The technology itself does not determine whether a BAA is required. The practice needs to look at what the vendor is doing, on whose behalf it is acting, and whether PHI is involved.
If a vendor will handle PHI for the practice, do not rely solely on the vendor’s statement that it is HIPAA compliant. Determine whether the appropriate agreement is in place and whether its terms actually address the service you intend to use.
Set Rules for AI Use Before Employees Start Using It
Even when a practice carefully evaluates an AI vendor, problems can arise if employees use AI tools differently from the way the practice intended. A written AI policy can establish clear expectations before that happens. A practice’s policy might address:
- Which AI tools employees may use
- What types of information may be entered into those tools
- When PHI may and may not be used
- Who can approve a new AI platform
- When a human must review AI-generated work
- How employees should handle AI-generated errors
- Whether practice-owned accounts are required
- What information employees may not submit to consumer AI platforms
A practice can permit AI while establishing boundaries around its use. Employees may begin using AI independently once a tool becomes part of their everyday workflow.
A Pre-Implementation AI Compliance Checklist
Before your practice adopts an AI tool, ask these eight questions:
- What exactly will the tool do? Define the specific task rather than evaluating “AI” as a general category.
- Will the tool receive PHI? Identify exactly what patient information, if any, will be submitted.
- Does the tool actually need that information? Consider whether the task can be completed with less information.
- How will the vendor use and retain the information? Review its data practices, privacy terms, and security documentation.
- Is a BAA required? Determine whether the vendor will function as a business associate and whether an appropriate agreement is in place.
- What does the contract say about your data? Look beyond the marketing materials and review the actual agreement.
- Who can use the tool? Establish appropriate access and make sure employees understand the practice’s rules.
- What other laws apply? HIPAA is not the only consideration. State privacy, healthcare, employment, and professional regulations may impose additional requirements depending on the technology and how it is used.
For example, practices using AI for clinical documentation may face additional considerations involving patient consent, accuracy, and state law. Illinois mental and behavioral health practices may also face AI requirements specific to that setting.
If you are considering an AI platform that will handle patient or confidential practice information, Jackson LLP’s healthcare attorneys can identify potential legal and compliance concerns before you commit. We provide complimentary consultations. Book yours today.
What to Know Before Bringing AI Into Your Practice
AI can be useful for practices, but adopting a new AI tool should be treated like adopting any other technology that touches sensitive practice information.
Before signing up, connecting the tool to your EHR, or allowing employees to use it, determine what information it will receive, how that information will be used and stored, what the vendor’s contract requires, and what HIPAA and state laws apply. The goal is to make sure the technology fits within your practice’s legal and operational framework before it becomes part of everyday workflow.
If you are considering an AI tool for your practice, Jackson LLP’s healthcare attorneys can review the technology, agreements, and compliance considerations before you put it into use.
Free Attorney Consultation
Frequently Asked Questions About HIPAA and AI
Is AI allowed in healthcare?
Yes. HIPAA does not generally prohibit healthcare practices from using artificial intelligence. The compliance analysis depends on how the technology is used, what information it receives, and what protections apply.
Can doctors use AI with patient information?
Potentially, but physicians should not assume that any AI platform is appropriate for PHI. The practice should evaluate the tool’s data practices, security measures, contractual terms, and whether a business associate relationship and BAA are required.
Does HIPAA apply to AI tools?
HIPAA can apply when a covered entity or business associate uses an AI tool to create, receive, maintain, or transmit PHI. The specific requirements depend on the information involved and how the technology is being used.
Are AI tools automatically HIPAA compliant?
No. A vendor’s claim that an AI tool is HIPAA compliant does not by itself establish that the tool is appropriate for your particular use. Practices should review the technology, contracts, security measures, and data practices before using the tool with PHI.
Should a medical practice have an AI policy?
A written AI policy can establish consistent rules for employees and reduce the risk of unauthorized use. It can identify approved tools, restrict the submission of PHI, and establish when human review is required.


