HIPAA Compliance Checklist for AI Use in Healthcare
A HIPAA checklist for AI should not begin with software names. It should begin with data flow. Where does PHI originate? Who copies it? Which AI tools are used? Where is content transmitted? What is stored? Who can review it? What happens when the user makes a mistake?
Start with vendor classification. If an AI vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity or business associate, the organization needs to analyze whether a BAA is required. HHS guidance makes clear that business associate relationships are based on functions involving PHI, not marketing claims.
Next, confirm product eligibility. A vendor may support HIPAA workflows only through specific services. OpenAI allows eligible customers to request a BAA. Anthropic offers HIPAA ready Claude Enterprise paths that require administrator action and a signed BAA. The practical rule is simple: do not assume the consumer tool, team plan, beta feature, connector, or casual login is covered.
Third, document permitted uses. The BAA and internal policy should define what kinds of PHI may be used, by whom, in which environments, and for what purposes. If the answer is 'employees will know,' the policy is not real.
Fourth, configure technical controls. That includes SSO, access controls, logging, retention settings, approved connectors, encryption, and administrative review. The HHS Security Rule proposal points toward stronger cybersecurity expectations for ePHI, so healthcare organizations should assume weak configuration will age badly.
Fifth, control input. This is the step most checklists miss. The organization must prevent users from accidentally pasting PHI into unapproved AI surfaces. KorGuard handles this locally, before transmission. It identifies regulated data, warns users in real time, and can block or de identify content based on policy.
Sixth, train with real examples. Do not train only on definitions. Show employees what risky prompts look like. A patient name plus a diagnosis is obvious. A claim denial plus a member ID is also risky. A screenshot, referral note, therapy summary, imaging order, or billing appeal may contain identifiers employees miss.
Seventh, prepare breach response. The HIPAA Breach Notification Rule requires notice to affected individuals and to HHS on specific timelines after breaches of unsecured PHI. AI workflows need incident procedures: how to identify exposure, preserve audit evidence, determine affected individuals, and decide whether notification is required.
Eighth, review shadow AI regularly. Ask employees what they actually use. Monitor approved environments. Scan for unapproved domains where legally and technically appropriate. Use point of input protection to reduce dependence on self reporting.
A serious AI compliance checklist is not 'get a BAA and move on.' It is vendor eligibility, configuration, user behavior, input prevention, audit evidence, and breach response. KorGuard's role is focused: stop the bad prompt before it becomes a compliance problem.
Sources & Further Reading
Stop PHI before it leaves the device.
Schedule a 15-minute walkthrough of the local-only detection pipeline.
Schedule a Call