HIPAA compliance for AI products: why there is no official certification and what to do
Understand covered entities, business associates, BAAs, PHI safeguards, risk analysis, and private assessments without implying HHS endorsement.
Overview
Understand covered entities, business associates, BAAs, PHI safeguards, risk analysis, and private assessments without implying HHS endorsement.
What it is
HIPAA is a U.S. federal legal framework whose Privacy, Security, and Breach Notification Rules apply to covered entities and, for specified duties, business associates. HHS does not offer or recognize a general private “HIPAA certification.”
Why it matters
AI can copy PHI into prompts, embeddings, logs, outputs, monitoring, and training. Health customers need defensible evidence that contracts, risk analysis, safeguards, access, use, disclosure, and incident obligations are continuously managed.
How to obtain it or demonstrate compliance
- Determine legal scope and roles for every service, customer, data flow, business associate, and subcontractor.
- Sign compliant BAAs where required and define permitted uses, disclosures, return/destruction, incidents, and subcontractor flow-down.
- Perform an accurate and thorough risk analysis covering AI architecture, cloud, models, access, data movement, and reasonably anticipated threats.
- Implement risk management, policies, workforce training, access controls, audit controls, integrity, transmission security, contingency, vendor, and breach processes.
- Evaluate technical and non-technical compliance periodically; remediate and retain required documentation.
- If using a private assessor, describe the result accurately as an assessment or validation and never as HHS certification or immunity.
What to review
- Do not display “HIPAA certified” as if HHS certified or endorsed the company, person, product, or private assessment.
- Determine whether each customer and AI vendor is a covered entity, business associate, subcontractor, or outside HIPAA—and check stricter state and other federal laws.
- Map where PHI enters prompts, retrieval stores, logs, outputs, support tools, monitoring, analytics, backups, subprocessors, and model-training pipelines.
- Execute required business associate agreements before permitted PHI handling and ensure subcontractor obligations flow down.
- Perform and update documented risk analysis and risk management; implement administrative, physical, and technical safeguards and breach procedures.
- Use independent assessment as evidence and improvement—not a substitute for ongoing legal compliance or HHS enforcement.
What to do next
HHS states that it does not endorse or recognize private Security Rule certifications and that an external assessment does not absolve legal duties. For AI, verify whether the vendor will use PHI for model improvement, whether the use is permitted, and whether a BAA actually covers every relevant service.
Official sources and further reading
- Are organizations required to certify HIPAA Security Rule compliance? — U.S. Department of Health and Human Services
- Covered Entities and Business Associates — U.S. Department of Health and Human Services
- Artificial Intelligence Risk Management Framework: Generative AI Profile — National Institute of Standards and Technology
This article provides general educational information and is not legal advice. Rules and outcomes depend on your facts and jurisdiction. Consult a qualified local professional before acting.
Jurisdiction
United States federal law; state tests may differ
Review status
Editorially reviewed by the LegalGPT Editorial Team. Not independently reviewed by a licensed attorney.