ComplianceHIPAAReading · ~3 min · 95 words deep

HIPAA

US federal law protecting patient health data · any AI vendor handling PHI must sign a BAA.

Text reviewed October 5, 2026

TL;DR

US federal law protecting patient health data · any AI vendor handling PHI must sign a BAA.

Level 1

HIPAA (Health Insurance Portability and Accountability Act) protects Protected Health Information (PHI) in the US. Any vendor that processes PHI on behalf of a covered entity (hospital, clinic, insurer) must sign a Business Associate Agreement (BAA) and implement administrative, physical, and technical safeguards. For AI, HIPAA affects any healthcare use case: clinical documentation, patient triage, medical imaging analysis, clinical decision support.

Level 2

HIPAA has two main rules: Privacy Rule (uses and disclosures of PHI) and Security Rule (administrative, physical, technical safeguards for electronic PHI). Violations are tiered by culpability from "did not know" to "willful neglect." The HIPAA Omnibus Rule extended direct liability to business associates. AI providers serving healthcare must offer a BAA · OpenAI offers one for enterprise accounts, AWS for Bedrock healthcare customers, Google Cloud Healthcare API. Logging and model training on PHI are particularly risky; providers typically opt-out of training on healthcare customer data. HIPAA does not preempt stricter state laws (California CMIA).

Level 3

HIPAA 45 CFR 164 defines required and addressable implementation specifications. The 2023 HHS proposed rule would update the Security Rule with modern cryptography and MFA requirements. Breach notification (Section 164.410) requires notifying HHS within 60 days for breaches > 500 records. De-identification under Safe Harbor (§164.514(b)(2)) or Expert Determination lets PHI leave the protected zone. Synthetic data, federated learning, and differential privacy are emerging approaches for HIPAA-compliant AI training.

The takeaway for you
If you are a
Curious · Normie
  • ·US law protecting your medical records
  • ·Why doctors have you sign privacy forms
  • ·AI companies handling health data need special agreements
If you are a
Builder
  • ·Sign a BAA before sending any PHI to an AI API
  • ·Opt out of training · most providers allow this for healthcare customers
  • ·Use Safe Harbor de-identification where possible
If you are a
Investor
  • ·Healthcare AI is the largest vertical with compliance moat
  • ·BAA-enabled providers capture enterprise healthcare contracts
  • ·Enforcement actions are rising · 2023 had record HHS OCR fines
If you are a
Researcher
  • ·HIPAA Privacy Rule + Security Rule
  • ·BAA extends liability to business associates
  • ·Violations tiered by culpability
Gecko's take

HIPAA is the single largest gate on AI revenue in healthcare. BAA-ready providers ship; the rest cannot touch the vertical.

OpenAI (enterprise), Anthropic (for healthcare customers), AWS Bedrock, Google Cloud Healthcare API, Microsoft Azure OpenAI for healthcare. Smaller providers vary.