HIPAA and AI
Application of health data privacy requirements to AI systems handling protected health information.
Definition
HIPAA (Health Insurance Portability and Accountability Act) requirements apply when AI systems create, receive, maintain, or transmit protected health information (PHI). Key considerations:
- Business Associate Agreements: Required for AI vendors processing PHI
- Minimum necessary: AI should access only PHI necessary for its function
- De-identification: AI training on de-identified data may avoid HIPAA requirements
- Security Rule: AI systems must meet administrative, physical, and technical safeguards
- Patient rights: Access and amendment rights apply to AI-processed records
HHS has issued guidance on AI and HIPAA, and is developing rules for algorithm transparency in healthcare. AI developers should determine HIPAA applicability early in development.
Sources
- •45 CFR Parts 160 and 164
- •HHS Guidance
Related Terms
Medical AI
AI systems used in healthcare for diagnosis, treatment recommendations, patient monitoring, and clinical decision support....
Data Governance
Policies, roles and processes that ensure data used across the AI lifecycle is fit for purpose, traceable, secure and managed in line with legal and operational requirements....
De-identification
The process of removing or obscuring personal identifiers from data to protect individual privacy....