AI Help for Doctors › Guides › HIPAA checklist for AI tools
What to check before you adopt any AI tool in your practice
Almost every AI tool a medical practice buys will touch patient data at some point. That is where the risk lives. Below is a plain checklist to run before you sign anything. It will not take long, and it can keep you out of real trouble.
Read this as a starting point, not as a ruling. This page is educational only. It is not legal, compliance, or medical advice. Every item here is a question for your own compliance or IT lead to confirm with the vendor. The Agentic AI Index does not review, endorse, certify, or clear any tool for HIPAA, and lists tools only so you can find and compare them.
First, what does HIPAA actually require?
HIPAA is the federal law that protects patient health information. The letters stand for the Health Insurance Portability and Accountability Act. The part that matters here is simple: you have to protect protected health information, often shortened to PHI. PHI is any detail that ties a person to their care, such as a name with a diagnosis, a visit note, a chart, a message, or a bill.
Your electronic health record, or EHR, the digital chart your practice runs on, is full of PHI. So is the audio of a visit, the draft note an AI scribe writes, and the text thread a patient sends about a refill. The moment an outside tool can see any of that, HIPAA is in play. That is the lens for everything below.
Get a signed Business Associate Agreement first
A Business Associate Agreement, or BAA, is the contract that lets an outside vendor handle PHI on your behalf. It binds the vendor to protect that data the way HIPAA expects. No signed BAA means the tool should not touch patient data. Full stop.
This is the single most important check on the page. Get the BAA signed before the tool goes live, not after. A vendor built for medical use will sign one without a fuss. If a vendor stalls, will not sign, or tells you their product does not need a BAA while it clearly handles PHI, treat that as your answer and walk away. Your compliance or IT lead should confirm the signed BAA in writing and keep a copy with your records.
Ask where the data is stored, and how
Once a tool holds patient data, you want to know where it lives and how it is guarded. Ask the vendor these in writing:
- Where is the data processed and stored, and is it kept apart from other customers' data?
- Is it encrypted while stored and while it travels across the internet? Encryption means the data is scrambled so a thief cannot read it.
- How long does the vendor keep it, and can you require them to delete it?
- What happens to your data if you cancel the service?
Save the answers. Your compliance or IT lead decides whether they clear your practice's bar. A crisp written answer tells you something good. A vague one tells you something too.
Confirm the vendor will not train its models on your data
Some AI tools learn from the information people feed them. You do not want your patients' data becoming training material for a model that other practices, or the public, might later touch. Ask the vendor plainly: do you use our patient data to train your models, and can we turn that off in the contract?
Many medical AI tools state that they do not train on your patient data, and some let you switch off any such use by contract. Get that promise in the written agreement, not just on a marketing page. If a vendor cannot give a clear, written answer, that is a warning sign worth heeding.
Set up patient consent before you record a visit
An ambient AI scribe, the kind of tool that listens to a visit and drafts the note, records or transcribes the conversation. Patients should know that is happening. Many states also have laws about recording a conversation, and those laws vary.
The safe habit is straightforward: tell the patient that a tool is capturing the visit to help write the note, note that they agreed, and give anyone who is uncomfortable an easy way to decline. Exactly what your state requires, and how you word it, is a question for your compliance lead. Build the consent step into your intake so it happens every time, not just when someone remembers.
Check who can see the data
Access control means deciding who can open patient data and making sure no one else can. Inside your practice, each person should see only what their job needs. On the vendor's side, ask who at the company can access your content and under what controls.
A few practical questions: Does each staff member get their own login instead of a shared one? Can you require multi-factor sign-in, where a code or app confirms it is really them? Does the tool keep a log of who looked at what? Can you remove a person's access the day they leave? These are the controls that keep a small mistake from becoming a large one.
Read the breach terms before you sign
A breach is when patient data is seen, taken, or exposed by someone who should not have it. It can happen to any vendor, so the contract needs to say what happens next. Look for three things: how fast the vendor tells you, what information they give you, and who covers the costs and the required notices.
Speed matters because HIPAA sets deadlines for telling patients and the government after a breach. If a vendor is slow to notify you, your practice can miss those deadlines and fall out of compliance through no fault of your own. Have your compliance lead read these terms closely before you sign.
The checklist, in one place
Copy this and run it past your compliance or IT lead for any AI tool you are considering:
- Signed BAA in place before the tool touches patient data.
- Data storage location known, encrypted at rest and in transit, deletable on request.
- No model training on your patient data, confirmed in the contract.
- Patient consent for recorded visits, built into intake and matched to your state's rules.
- Access controls: individual logins, multi-factor sign-in, access logs, and a clean way to remove access.
- Breach terms: fast notice, clear information, and responsibility spelled out.
- A human on every clinical output before it leaves the practice.
Common questions
What is a Business Associate Agreement, and do I need one for an AI tool?
A Business Associate Agreement, or BAA, is a written contract that lets a vendor handle patient data on your behalf under HIPAA, the federal patient-privacy law. If an AI tool will see any patient information, you need a signed BAA before it touches that data. If a vendor will not sign one, do not put patient information into the tool. This is a check for your own compliance or IT lead to confirm, not a claim to take from the vendor's website.
Can I use a free consumer AI chatbot for patient notes?
Not with real patient information, unless the vendor has signed a Business Associate Agreement with your practice. Most general consumer AI tools do not sign a BAA and may use what you type to train their models. Putting patient information into a tool like that can be a HIPAA violation. Use only tools built for medical use that will sign a BAA, such as an ambient scribe like Abridge, and let your compliance or IT lead review the terms first.
Do I need patient consent to record a visit with an AI scribe?
Often, yes. Many states have laws about recording a conversation, and your patients should understand that a tool is capturing the visit. The safe habit is to tell the patient, note their agreement, and give them a way to decline. What your state and your own policies require is a question for your compliance lead. This page is educational only and is not legal or compliance advice.
How do I know where an AI vendor stores my patients' data?
Ask the vendor in writing. Find out where the data is processed and stored, whether it is encrypted while stored and while moving across the internet, how long they keep it, and whether you can require deletion. Keep the written answers with your records. Your compliance or IT lead decides whether the answers meet your practice's standard.
Will an AI vendor use my patient data to train its models?
It depends on the vendor, so you have to ask and get it in writing. Many medical AI tools state that they do not train their models on your patient data, and some let you turn any such use off by contract. A messaging tool like Klara or a practice system like Tebra should be able to answer this clearly. Confirm it in the agreement rather than trusting a marketing page.
What should the breach terms in an AI contract say?
A breach is when patient data is seen, taken, or exposed by someone who should not have it. Your agreement should say how fast the vendor tells you if that happens, what information they will give you, and who is responsible for the costs and the required notices. HIPAA sets deadlines for notifying patients and the government, so slow vendor notice can put your practice out of compliance. Have your compliance lead review these terms before you sign.
Does The Agentic AI Index check these tools for HIPAA compliance?
No. This site lists tools so you can find and compare them. It does not review, endorse, certify, or clear any tool or vendor for HIPAA or for anything else. Every item on this checklist is your practice's own compliance or IT lead to verify with the vendor. Nothing here is legal, compliance, or medical advice.
Want help running these checks?
Tell us your area and we will point you to a local AI consultant who works with medical practices. They can handle the vendor questions, the BAA review, and the setup so the tools go live the right way.
Find a local AI pro →