A hospital in the Midwest fed three years of patient discharge summaries into a generative AI tool last year. The goal was noble — predict readmission risk and improve outcomes. The problem? Those summaries contained protected health information, and the AI vendor had no business associate agreement in place. Within six months, an OCR investigation was underway.

That scenario is playing out across healthcare right now. HIPAA and AI are colliding faster than most compliance officers can keep up. If your organization is using — or even considering — artificial intelligence tools that touch patient data, you need to understand exactly where the regulatory guardrails sit.

And yes, this applies even if someone on your team just typed a patient question into ChatGPT.

Why "HIPAA and AI" Is the Compliance Question of 2026

AI adoption in healthcare isn't theoretical anymore. Ambient listening tools transcribe physician-patient conversations in real time. Large language models draft clinical notes. Predictive algorithms flag high-risk patients before they walk through the door.

Every one of these tools has the potential to create, receive, maintain, or transmit PHI. And that's the exact language the HIPAA Privacy Rule uses to define what triggers compliance obligations under 45 CFR Part 164.

Here's what I've seen in the field: most organizations treat AI like they treated cloud computing a decade ago. They adopt first and ask compliance questions later. That approach already cost Banner Health $1.25 million in a 2023 settlement with OCR after a breach affecting nearly 3 million individuals — and while that case involved hacking rather than AI specifically, the underlying lesson is identical. If you don't assess risk before you deploy technology, HHS will hold you accountable after something goes wrong.

The Business Associate Agreement Problem Nobody Wants to Talk About

I've reviewed dozens of AI vendor contracts this year alone. Here's the pattern I keep finding: organizations sign up for an AI-powered tool, the vendor's terms of service say nothing about HIPAA, and nobody on the compliance team reviews the arrangement until a breach forces the issue.

Under HIPAA, any vendor that handles PHI on your behalf is a business associate. Period. That includes the company whose AI model processes your patient data, the cloud provider hosting the model, and sometimes the subcontractors training it.

What a Valid BAA With an AI Vendor Must Cover

  • Permitted uses and disclosures of PHI — the AI vendor can only use patient data for the purposes you specify.
  • Safeguards — the vendor must implement administrative, physical, and technical protections for ePHI, including encryption and access controls.
  • Breach notification obligations — the vendor must report any unauthorized access or disclosure to your organization within the timeframes HIPAA requires.
  • Return or destruction of PHI — when the contract ends, the vendor must return or destroy all patient data. This includes training data sets.
  • No use of PHI for model training without authorization — this is the new frontier. If the vendor feeds your patients' data back into its general model, that's a disclosure you likely never authorized.

If your AI vendor won't sign a BAA, you cannot send them PHI. Full stop.

The $1.9 Million Lesson from Banner Health — And What AI Makes Worse

OCR's enforcement record makes the stakes clear. The Banner Health settlement involved a failure to conduct an adequate risk analysis before a cyberattack exposed millions of records. The corrective action plan required organization-wide risk analysis and workforce training.

AI multiplies this risk. Every new AI tool you deploy is a new system that stores, processes, or transmits ePHI. Each one needs its own risk assessment under the HIPAA Security Rule. Each one needs documented policies. Each one needs trained staff who understand the boundaries.

In my experience, this is where organizations fail most often. They train their workforce on HIPAA basics once a year and assume that covers emerging technology. It doesn't. Your staff need specific guidance on what they can and cannot do with AI tools and patient data.

Our HIPAA Introduction Training 2026 covers foundational compliance requirements that apply directly to new technology deployments, including AI.

Can You Use AI Without Violating HIPAA?

Yes. But only if you build the compliance infrastructure first.

Here's the short answer for anyone searching this question: HIPAA does not ban AI. It requires that any technology handling PHI meet the same Privacy, Security, and Breach Notification Rule standards that apply to every other system in your organization. That means risk analysis, business associate agreements, minimum necessary standards, workforce training, and technical safeguards like encryption and audit controls.

A Practical Checklist Before You Deploy Any AI Tool

  • Conduct a risk assessment specific to the AI tool, not just your annual organization-wide assessment.
  • Execute a BAA with the vendor before any PHI enters the system.
  • Apply minimum necessary — only feed the AI the specific data elements it needs, not entire patient records.
  • Verify encryption — ePHI must be encrypted both in transit and at rest within the AI system.
  • Enable audit logging — you need to track who accessed what data through the AI tool and when.
  • Train your workforce — every staff member who interacts with the tool must understand the HIPAA boundaries.
  • Document everything — OCR investigators look for written policies, not verbal assurances.

Remote Workers and AI: A Dangerous Combination Without Training

Here's a scenario I encounter constantly. A remote medical coder uses an AI transcription tool on a personal laptop to speed up chart reviews. The tool is cloud-based. The laptop has no endpoint protection. There's no BAA with the transcription vendor. The coder has never received HIPAA training specific to remote work.

That single workflow violates at least four HIPAA requirements.

Remote healthcare work is here to stay, and so is AI. The combination demands targeted training that goes beyond generic annual compliance refreshers. Our HIPAA Training for Remote Healthcare Workers addresses exactly these scenarios — including how to evaluate AI tools for compliance when you're working outside the traditional office environment.

What HHS Has Actually Said About AI and HIPAA

HHS has not issued a standalone AI regulation under HIPAA — yet. But the agency has made its position clear through existing guidance and enforcement patterns.

In December 2023, HHS released a strategic plan for AI that explicitly states existing HIPAA requirements apply to AI systems handling PHI. There is no AI exception. The Privacy Rule's minimum necessary standard applies. The Security Rule's risk analysis requirement applies. The Breach Notification Rule applies if an AI system exposes PHI.

OCR Director Melanie Fontes Rainer has repeatedly emphasized that covered entities bear responsibility for the technology they deploy — including AI. If your AI vendor causes a breach, you're still on the hook for notification and potential penalties.

Where Enforcement Is Heading

I expect OCR to bring its first AI-specific enforcement action within the next 12 to 18 months. The pattern is predictable: a covered entity deploys an AI tool without a risk assessment or BAA, a breach occurs, and OCR steps in. The settlement will likely reference failures in risk analysis, business associate oversight, and workforce training — the same violations that have driven eight-figure enforcement actions in the past.

Don't wait for that headline to land before you act.

Your Three Next Steps

If you've read this far, you already know your organization needs to address HIPAA and AI head-on. Here's where to start:

  • Audit every AI tool your organization currently uses or plans to use. Identify which ones touch PHI.
  • Close the BAA gap. For every AI vendor handling PHI, execute a compliant business associate agreement immediately.
  • Train your workforce. Generic HIPAA training won't cut it anymore. Your staff need to understand AI-specific risks. Browse our full HIPAA training catalog to find the right course for your team's role and work environment.

AI will transform healthcare. That's not a question. The question is whether your organization will be on the right side of compliance when it does.