Compliance

What HIPAA Actually Requires From Your AI Vendor

Most AI vendor pitches skip the compliance conversation entirely. Here's what to actually ask before signing anything.

Sofia Martinez

Compliance & Risk Specialist

Most healthcare practices evaluating AI tools get sold on features first and compliance second — if it's discussed at all. That's backwards.

An AI tool can be impressive in a demo and still create significant compliance risk once it touches patient information. The important question isn't simply what the technology can do. It's whether the vendor can support the way your organization is required to handle protected health information.

Before signing a contract, there are a few questions worth asking.

Start With the BAA

If an AI vendor will create, receive, maintain, or transmit protected health information on behalf of your organization, determine whether a Business Associate Agreement is required and whether the vendor will sign one.

A BAA establishes important responsibilities around how protected health information is handled. It should not be treated as paperwork to complete after implementation.

If a vendor refuses to sign an appropriate agreement, pause the evaluation. A useful product isn't worth creating a compliance problem for your organization.

Understand Where Your Data Lives

"Cloud-based" doesn't tell you enough.

Ask the vendor where your data is stored, which infrastructure providers are involved, what geographic regions are used, and who may have access to the information. You should also understand how data is protected while it is being transmitted and while it is stored.

This is especially important when an AI system relies on multiple third-party services behind the scenes. The product you see in the demo may not be the only company processing your data.

Ask What Happens When Things Change

Vendor relationships don't always last forever.

An AI company could discontinue a product, change its infrastructure, get acquired, or decide to stop supporting your use case. Before committing, understand what happens to your data in each of those situations.

Ask how you can export your information, what format it will be provided in, how long the vendor retains data after termination, and how deletion is handled.

Data portability isn't something you want to negotiate after you've built your workflow around a platform.

Look Beyond the Sales Demo

A polished demo tells you what a product can do. It doesn't necessarily tell you how responsibly the vendor operates.

Ask for documentation around security, privacy, data handling, retention, subprocessors, incident response, and contractual responsibilities. The quality and clarity of those answers can tell you a lot about how seriously a vendor treats healthcare customers.

The goal isn't to eliminate every possible risk. That's rarely realistic.

The goal is to understand where the risk sits, what responsibilities your organization is taking on, and whether the vendor has the controls and contractual commitments to support them.

The best AI tool for a healthcare organization isn't necessarily the one with the longest feature list. It's the one that can deliver value without creating problems your team has to solve later.

This article is intended for general informational purposes and should not be considered legal or compliance advice. Healthcare organizations should consult qualified professionals regarding their specific obligations.

Subscribe to our newsletter

Be the first to receive practical insights, updates, and expert guidance on implementing AI across healthcare.

Subscribe to our newsletter

Be the first to receive practical insights, updates, and expert guidance on implementing AI across healthcare.

Subscribe to our newsletter

Be the first to receive practical insights, updates, and expert guidance on implementing AI across healthcare.

Create a free website with Framer, the website builder loved by startups, designers and agencies.