"Can AI be HIPAA compliant?" is the most common compliance question in healthcare AI, and most answers get it subtly wrong — either by declaring specific tools "HIPAA compliant" as if the label attached to software, or by dodging with "consult your lawyer." The correct answer is precise and useful: AI can be part of a HIPAA-compliant deployment, because HIPAA regulates protected health information and the parties who handle it, not technologies. This page explains what that means, why no certification can exist, the five conditions that actually decide a deployment's compliance, and how to evaluate any vendor's claim against checkable artifacts.
The Direct Answer: Compliance Describes the Deployment
AI can be part of a HIPAA-compliant deployment, but compliance is not a property of the technology: HIPAA regulates protected health information and the parties handling it, so an AI tool becomes compliant through how it is deployed — agreements, safeguards, and workflows around PHI — and no AI is compliant in the abstract.
The regulatory logic is worth stating plainly, because it explains everything else:
- HIPAA attaches to data and parties. When an AI technology uses PHI, HIPAA applies to that PHI whether the tool is operated by a covered entity or by a business associate — the trigger is the data, not the software category.
- Therefore no certification can exist. The Department of Health and Human Services operates no certification program for AI tools, and no third-party seal makes one "HIPAA compliant" — because compliance is determined deployment by deployment, not awarded to products.
- The correct question is: "Can this tool be deployed in a way that satisfies HIPAA for our PHI workflows?" — a question with checkable answers, which the rest of this page provides.
When a vendor markets an AI tool as "HIPAA compliant," they mean — at best — that their offering can support compliant deployments: the shorthand hides an entire deployment's worth of conditions you still own.
The Conditions That Actually Decide It

Five conditions decide: an unbroken BAA chain covering every party that touches PHI, encryption in transit and at rest, enforced role-based access, audit trails of PHI access, and HIPAA-eligible hosting for every environment the data reaches — plus the covered entity's own risk analysis binding them together.
| Condition | What it requires | Who owes it |
| BAA chain | A business associate agreement with every external party whose service can touch PHI, scoped to the features used | Each vendor in the chain; the covered entity assembles it |
| Encryption | In transit on every leg and at rest in every store the PHI reaches | Every operating party on its own segments |
| Access controls | Role-based access to the AI workflow's data and interfaces, with provisioning that actually deprovisions | Mostly the covered entity; platform features support it |
| Audit trails | Logs of who accessed PHI through the AI workflow, when, and what they did | Shared: platform captures, entity reviews |
| Eligible hosting | Every environment the data reaches is configured for HIPAA workloads | The hosting or infrastructure provider, under BAA |
The unbroken-chain principle deserves emphasis: one uncontracted subprocessor between your PHI and the model breaks the chain regardless of how compliant every other link is. And the risk analysis — the covered entity's own, documented assessment of the deployment — is what binds the five conditions into a compliance position rather than a checklist of disconnected features.
Why Consumer AI Tools Fail the Test
Free, general-purpose AI tools fail structurally, not incidentally: their terms typically permit the provider to process inputs broadly, they offer no business associate agreement, and their consumer tiers lack the access and audit controls PHI requires — which is why the same vendors sell separate enterprise configurations that can pass.
The failure has a consistent anatomy across vendors:
- Terms of service: consumer tiers generally license the provider to use inputs in ways PHI cannot tolerate — training on inputs, broad processing rights, shared infrastructure without contractual boundaries.
- No BAA: the consumer product comes with no business associate agreement, and without one there is no contractual HIPAA relationship at all — the single fastest disqualifier.
- No controls: consumer tiers expose no role-based access, audit export, or residency configuration for your workflow — the conditions above have nowhere to land.
The same vendors' enterprise offerings can pass precisely because they add those three missing pieces under contract. That asymmetry — consumer fails, enterprise can pass, at the same company — is the clearest possible demonstration that compliance lives in the deployment, not the brand.
How to Evaluate Any 'HIPAA-Compliant AI' Claim
Convert the claim into checkable artifacts: a BAA whose scope names the features you will use, documentation of encryption and access controls, an audit-trail sample, the hosting environments' eligibility, and a data-flow diagram of where PHI actually goes — a claim that cannot produce these artifacts is marketing.
| Claim | Artifact to request | Pass condition |
| "HIPAA compliant" | The BAA | Names the specific services and features you will use — not suite-level language |
| "Encrypted end to end" | Encryption documentation per leg | Covers every leg including internal hops and subprocessors |
| "Access controlled" | Access model documentation | Expresses your required role distinctions; deprovisioning demonstrated |
| "Audit logging" | Sample log export | Shows who-what-when for PHI access; exports to your systems |
| "Secure hosting" | Environment eligibility and data-flow diagram | Every environment the data reaches is eligible and mapped |
Two failure patterns are worth naming: the scope mismatch (a signed BAA that excludes the exact features your workflow uses — common where agent or API features sit outside the covered tier) and the unmapped flow (PHI reaching an environment or subprocessor no document mentions). Both are caught by the artifact table above, which is the point of converting claims into evidence. For teams whose PHI workflows justify dedicated environments, OneSource Cloud's healthcare AI infrastructure is one hosting option to evaluate against the same five conditions as any other.
FAQ
Is ChatGPT or Claude HIPAA compliant?
Not the consumer versions, and not automatically: major vendors offer HIPAA-eligible configurations under enterprise agreements with a BAA — so the answer depends on which tier, which agreement, and which features the BAA scopes. Apply the evaluation checklist to the exact configuration you would use.
Does using AI on de-identified data avoid HIPAA entirely?
Properly de-identified data falls outside PHI scope — but "properly" means a documented method (safe harbor or expert determination), not deleting names. Until that documentation exists, the workflow and its tooling remain in scope.
Who is responsible when AI touches patient data — us or the vendor?
Both, by role: the vendor acts as a business associate with contractual duties under the BAA, while your organization retains the risk analysis, workforce controls, and ultimate accountability — no agreement transfers the covered entity's obligations.