All articles
HIPAAHealthcare AIPHI

HIPAA Compliance for Healthcare AI: What You Need to Know

Anxya Health · September 1, 2026

Does HIPAA apply to AI?

Yes. If an AI system creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity or business associate, HIPAA's Privacy and Security Rules apply. The technology being "AI" does not change the obligation to safeguard PHI.

Key HIPAA building blocks

  • Privacy Rule — governs permissible uses and disclosures of PHI and patient rights.
  • Security Rule — requires administrative, physical and technical safeguards for electronic PHI (ePHI).
  • Breach Notification Rule — mandates notification when unsecured PHI is compromised.
  • Business Associate Agreement (BAA) — a contract required whenever a vendor handles PHI for you.

Practical steps for AI teams

  1. Minimise PHI — de-identify or use limited data sets wherever possible.
  2. Sign BAAs with every vendor that touches PHI, including AI providers.
  3. Encrypt ePHI in transit and at rest.
  4. Log and audit access to PHI, including prompts and model inputs.
  5. Control access with least-privilege roles and strong authentication.

De-identification helps

Properly de-identified data is not PHI, which lowers risk substantially. The Safe Harbor and Expert Determination methods are the two recognised routes.

Anxya Health supports HIPAA-aligned workflows and can provide a BAA for US customers handling PHI. This is general information, not legal advice.

We use cookies to run Anxya Health and improve your experience. Choose how we may use them. Read our Cookie Policy, Privacy Policy and Terms.