HIPAAHealthcare AIPHI
HIPAA Compliance for Healthcare AI: What You Need to Know
Anxya Health · September 1, 2026
Does HIPAA apply to AI?
Yes. If an AI system creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity or business associate, HIPAA's Privacy and Security Rules apply. The technology being "AI" does not change the obligation to safeguard PHI.
Key HIPAA building blocks
- Privacy Rule — governs permissible uses and disclosures of PHI and patient rights.
- Security Rule — requires administrative, physical and technical safeguards for electronic PHI (ePHI).
- Breach Notification Rule — mandates notification when unsecured PHI is compromised.
- Business Associate Agreement (BAA) — a contract required whenever a vendor handles PHI for you.
Practical steps for AI teams
- Minimise PHI — de-identify or use limited data sets wherever possible.
- Sign BAAs with every vendor that touches PHI, including AI providers.
- Encrypt ePHI in transit and at rest.
- Log and audit access to PHI, including prompts and model inputs.
- Control access with least-privilege roles and strong authentication.
De-identification helps
Properly de-identified data is not PHI, which lowers risk substantially. The Safe Harbor and Expert Determination methods are the two recognised routes.
Anxya Health supports HIPAA-aligned workflows and can provide a BAA for US customers handling PHI. This is general information, not legal advice.