Data Protection

HIPAA and AI

Application of health data privacy requirements to AI systems handling protected health information.

Definition

HIPAA (Health Insurance Portability and Accountability Act) requirements apply when AI systems create, receive, maintain, or transmit protected health information (PHI). Key considerations:

  • Business Associate Agreements: Required for AI vendors processing PHI
  • Minimum necessary: AI should access only PHI necessary for its function
  • De-identification: AI training on de-identified data may avoid HIPAA requirements
  • Security Rule: AI systems must meet administrative, physical, and technical safeguards
  • Patient rights: Access and amendment rights apply to AI-processed records

HHS has issued guidance on AI and HIPAA, and is developing rules for algorithm transparency in healthcare. AI developers should determine HIPAA applicability early in development.

Sources

  • 45 CFR Parts 160 and 164
  • HHS Guidance