Compliance
Alex Bendersky
Healthcare Technology Innovator

HIPAA Compliance AI in 2026: Critical Security Requirements You Can't Ignore

Last Updated on -  
September 23, 2026
Time
min Read
‍The Top 20 Voices in Physical Therapy You Should Be Following for Innovation, Education, and Impact
SPRY
September 23, 2026
•
5 min read
Sam Tuffun
PT, DPT
Expertise in rehabilitation, outpatient care, and the intricacies of medical coding and billing.
Summary
HIPAA Compliance AI in 2026: Critical Security Requirements You Can't Ignore

Webinar

From Claims Delays to Clean Approvals: How AI Helps Clinics Win

September 17, 2025
1 p.m. - 2 p.m. EST
Tired of Forms? Automate Prior Auths
Used by PT, OT & rehab clinics to reduce prior auth delays.

AI-Native Prior Authorization for Rehab Therapy Clinics

Automate 80% of workflows, reduce denials by 75%, and secure approvals one week before appointments—all while preparing for CMS’s 2026 mandate.
Book a Demo
Summary for this page

A quick AI-generated overview extracted directly from the content of this page.

Summary: As of September 2026, the proposed HIPAA Security Rule update from January 2025 remains unfinalized (non-binding target: July 2027), but healthcare organizations still face real, current AI compliance obligations. Key obligations include:

  • Ensuring AI systems comply with the existing HIPAA Security Rule, particularly regarding the use of protected health information (PHI).
  • Adhering to the minimum necessary standard, which mandates that AI tools access only the PHI essential for their functions.
  • Complying with 45 CFR 92.210, the Section 1557 nondiscrimination rule already in force, which requires identifying and mitigating bias risk in AI-based patient care decision tools.
  • Implementing robust de-identification methods to utilize health data without violating HIPAA protections.

Organizations leveraging AI, such as SPRY, can streamline compliance while enhancing healthcare delivery through innovative solutions.

HIPAA Compliance AI in 2026: Critical Security Requirements You Can't Ignore

Healthcare organizations are leaning harder on artificial intelligence every quarter, and PHI-handling AI tools are following right behind. A October 2025 industry survey found that 95% of healthcare organizations already have employees with PHI access using AI tools in their day-to-day work, yet a quarter of those organizations have never formally approved any AI use at all, and 83% of IT and compliance leaders say they're worried about the security risk this creates. Healthcare providers increasingly deploy artificial intelligence systems that process protected health information (PHI), yet many fail to address the unique compliance challenges these technologies present.

Healthcare organizations must understand how HIPAA and AI intersect across clinical and operational workflows. Implementing a HIPAA-compliant chatbot or AI medical scribe requires rigorous security controls beyond standard IT systems. Meanwhile, AI security challenges in healthcare continue to multiply as models become more sophisticated and access greater volumes of sensitive data. This article examines the HIPAA artificial intelligence compliance requirements healthcare organizations face heading into 2027, separating what's already legally required today from what's still proposed and not yet final — a distinction that matters, because the headline HIPAA Security Rule update has been delayed more than once. We'll explore specific obligations for protecting patient data while leveraging AI's transformative potential in healthcare delivery.

HIPAA Security Rule Scope for AI Systems in 2026

The HIPAA Security Rule establishes foundational requirements that AI systems processing protected health information (PHI) must follow. As healthcare organizations increasingly deploy artificial intelligence solutions, these systems must comply with the existing privacy and security framework despite their complex data needs — and a proposed overhaul of that framework is still working its way through the federal rulemaking process. The table below summarizes where the key rules actually stand as of this writing.

Rule or GuidanceCurrent Status (Sept 2026)What It Means for AI in Healthcare
HIPAA Security Rule NPRM (proposed Jan. 2025)Not final. Moved to HHS's "Long-Term Actions" agenda; non-binding target of July 2027 for a final rule.The existing Security Rule — not the proposed one — still governs AI today. Mandatory MFA, encryption, and 6-month vulnerability scans are not yet legal requirements, though they're a reasonable roadmap to follow.
Section 1557 AI Nondiscrimination Rule (45 CFR 92.210)Final and currently in force; effective May 6, 2024.Covered entities must identify AI-based patient care decision tools that use protected-class variables and take reasonable steps to mitigate discrimination risk.
OCR "Dear Colleague" letter on AI (Jan. 31, 2025)Active sub-regulatory guidance, not a standalone legal mandate.Recommends written AI-use policies, human override of AI decisions, staff training, and patient disclosure when AI materially affects care decisions.
FDA Clinical Decision Support software guidanceUpdated January 2026.Eases device-level oversight for transparent, single-recommendation CDS tools, but opaque "black box" models and generative AI in time-critical settings should still expect device-level scrutiny.

Permissible Use of PHI in AI Workflows

Healthcare organizations must recognize that introducing AI does not alter traditional HIPAA rules governing PHI usage. AI tools can access, use, and disclose protected health information only for explicitly permitted purposes under HIPAA regulations. For example, AI models analyzing patient records for treatment optimization fall under permitted treatment purposes, whereas training models with PHI for research typically requires patient authorization.

Furthermore, healthcare entities using AI for clinical decision support must incorporate these systems into their risk analysis and management processes. The Office for Civil Rights has stated that the HIPAA Security Rule governs electronic PHI (ePHI) used in both AI training data and algorithms developed by regulated entities. Consequently, organizations must regularly update their analysis to address technological changes, documenting how AI software — including tools built on platforms like SPRY AI — interacts with or processes ePHI.

Minimum Necessary Standard for AI Data Access

The minimum necessary standard presents unique challenges for AI systems that typically thrive on comprehensive datasets. This core HIPAA protection requires that AI tools access and use only the PHI strictly necessary for their intended purpose. According to HHS guidance, the minimum necessary standard applies to most uses and disclosures of PHI, with limited exceptions including disclosures for treatment purposes.

To implement this standard effectively for AI systems, organizations must:

  • Establish clear policies identifying which AI applications need access to PHI
  • Define the specific categories of PHI each AI system requires
  • Document justifications when an entire medical record is necessary
  • Implement technical controls limiting data access based on roles and purposes

The challenge lies in balancing data minimization requirements against AI performance needs. Healthcare organizations must develop protocols ensuring AI tools receive sufficient data for accuracy without excessive PHI exposure. This often requires implementing granular data access policies and permissions that dynamically adjust based on contextual factors and user roles.

De-Identification Requirements under Safe Harbor and Expert Determination

De-identified health information falls outside HIPAA protection, offering organizations flexibility when using such data in AI systems. HIPAA provides two methods for de-identification: Safe Harbor and Expert Determination.

The Safe Harbor method requires removing 18 specific identifiers from datasets, including names, geographic subdivisions smaller than states, dates (except years), contact information, identifiers like Social Security numbers, and biometric data. Although straightforward, this approach can sometimes remove so much valuable information that the resulting dataset becomes less useful for AI applications.

The Expert Determination method offers a more nuanced approach. Under this method, a qualified expert applies statistical and scientific principles to ensure the risk of re-identification is "very small". Experts employ techniques including:

  • Suppression - omitting specific information
  • Generalization - broadening data elements like age ranges
  • Perturbation - introducing controlled random variation

For AI systems processing unstructured data like clinical notes, advanced natural language processing can assist by identifying and redacting PHI from text with high accuracy. Additionally, AI vendors must document their de-identification methodology thoroughly and schedule periodic reviews as technology advances.

Healthcare organizations deploying AI in 2026 must choose the appropriate de-identification method based on their specific use case, considering both compliance requirements and the need to maintain data utility for effective AI performance.

AI-Specific Risk Assessment and Lifecycle Management

Effective cybersecurity in healthcare depends on thorough identification and management of AI systems that process patient data. The proposed HIPAA Security Rule update — still not final as of this writing — would require entities using AI tools to include those tools in their risk analysis and vendor risk management activities. Importantly, this is already a sound practice under the current Security Rule's general risk-analysis requirement, so organizations shouldn't wait for a final rule to start. This section outlines essential practices for maintaining HIPAA compliance AI throughout the technology lifecycle, whether you're managing documentation tools, scheduling AI, or the broader AI-driven EHR features now standard in modern practice management platforms.

Inventorying AI Assets Interacting with ePHI

Comprehensive asset inventories form the foundation of effective AI security. OCR investigations frequently discover that organizations do not know where all electronic PHI resides in their systems. For AI systems specifically, covered entities must document all technologies that "create, receive, maintain, or transmit ePHI" — a discipline that matters just as much during an EHR or practice-management data migration, when PHI briefly exists in more places than usual.

An effective AI inventory should include:

  • Hardware components: Servers, workstations, and devices hosting AI applications
  • Software elements: AI algorithms, models, and supporting applications
  • Data assets: Training datasets, prediction models, and algorithm data containing ePHI

Each inventory entry should contain detailed information about the AI system, including vendor details, version numbers, and individuals accountable for maintenance. HHS guidance recommends comparing inventory listings against network scanning results to identify previously unknown or "rogue" devices or applications that might pose risks to ePHI.

Moreover, federal agencies are already required to conduct annual inventories of their AI use cases under the Advancing American AI Act. Healthcare organizations should adopt similar practices, ensuring all AI applications processing PHI are documented, regardless of whether they were developed internally or acquired from vendors.

Lifecycle Risk Analysis for AI Model Updates

Unlike traditional software, AI systems evolve through updates and retraining, necessitating ongoing security assessment. Privacy officers must conduct AI-specific risk analyses tailored to address these dynamic data flows and training processes.

During risk analysis, organizations must consider:

  • The volume and categories of ePHI accessed by AI tools
  • Which parties receive AI-generated reports containing patient data
  • How AI systems transmit ePHI to other entities or applications

Findings should be prioritized and tracked — many compliance teams use a simple risk-severity ranking (critical, high, medium, low) so remediation effort goes to the highest-impact gaps first, rather than being addressed in whatever order they were discovered.

In practice, most organizations should proceed cautiously with fully in-house AI security management. As one healthcare security expert has put it, even a well-resourced internal security team is often still building AI-specific expertise, since these monitoring technologies are themselves relatively new. Many organizations reasonably partner with specialized vendors for advanced AI security monitoring until internal capabilities mature.

Patch Management for AI Vulnerabilities

AI systems face unique vulnerabilities requiring specialized patch management. In 2024, security researchers at Tenable identified critical vulnerabilities in Microsoft's Azure Health Bot Service — a HIPAA-eligible healthcare chatbot platform — including a server-side request forgery flaw that could have allowed cross-tenant access to other customers' data before Microsoft patched it. The incident, later detailed by Healthcare IT News, underscores why prompt remediation of AI-adjacent infrastructure matters as much as patching the AI model itself.

The still-proposed HIPAA Security Rule update would specify that covered entities conduct vulnerability scanning at least every six months and penetration testing at least annually, and that disaster recovery plans restore critical systems within 72 hours of a loss event. None of this is legally required yet, but it reflects where OCR's thinking is heading, and organizations that adopt these cadences now will be ahead of a final rule rather than scrambling to catch up.

Effective AI vulnerability management covers both the AI technologies themselves and any security tooling built on artificial intelligence. Organizations should implement multi-layered approaches, including:

  • Regular scanning for outdated code or anomalies in AI systems
  • Immediate application of security patches when vulnerabilities are identified
  • Retraining and verification of AI models after updates to ensure security integrity

For healthcare entities utilizing AI, patch management becomes particularly crucial as these systems often have access to sensitive patient information across multiple applications. Accordingly, organizations must establish clear workflows for promptly implementing security updates while minimizing disruption to clinical operations.

Vendor Oversight and Business Associate Agreements (BAAs)

Managing AI vendors in healthcare settings demands specialized oversight beyond conventional technology relationships. As AI continues to expand its role in processing patient information — from AI-assisted prior authorization to automated scheduling and billing — it requires robust governance frameworks around third-party relationships.

Security Verification Requirements for AI Vendors

Healthcare organizations must obtain documented security verification from AI technology partners before allowing access to protected health information. If the proposed HIPAA Security Rule update is finalized as written, all regulated entities contracting with AI developers would need to formally incorporate written, annual business associate verification into their security risk analysis — not just a signed BAA on file, but evidence the safeguards are actually in place. The table below is a practical checklist for vetting an AI vendor today, ahead of any final rule.

Verification ItemWhat to Request From the Vendor
Signed BAAA current Business Associate Agreement naming the specific AI product and data flows involved, not a generic template.
Encryption evidenceWritten confirmation that ePHI is encrypted at rest and in transit, rendering it "unusable, unreadable, and indecipherable" if intercepted.
Training data disclosureWhether your PHI is used to train or fine-tune shared/foundation models, or is isolated to your own instance.
Breach notification termsA specific, contractual notification window (many organizations now negotiate 24–48 hours) rather than vague "prompt notification" language.
Subcontractor (fourth-party) listWhich downstream vendors or model providers the AI tool itself relies on.

BAA Clauses for AI-Driven Data Processing

Traditional BAAs require significant enhancement when AI systems process protected health information. Breach notification clauses in particular need precise timelines. The still-pending Security Rule NPRM proposes requiring business associates to notify covered entities "without unreasonable delay, but no later than 24 hours" after activating their contingency plans — and many forward-looking organizations are already writing similarly tight windows into new AI vendor contracts rather than waiting for that requirement to become law.

BAAs must clearly outline technical safeguards specific to AI implementations, including:

  • Encryption standards for stored PHI
  • Secure data transmission protocols
  • Access control measures with role-based permissions

Furthermore, BAA language should address the unique risks associated with AI model training, ensuring that vendors comply with the minimum necessary standard when using PHI.

Third-Party Risk Integration into Security Risk Analysis

Healthcare organizations must incorporate AI vendor relationships into their overall security risk analysis. This integration involves collaborating with vendors to review the technology assets — including any AI software that interacts with electronic PHI.

The interconnected nature of today's technology environment means fourth-party vendors (your vendor's vendors, such as the underlying model provider) could also put sensitive health information at risk. Organizations should implement continuous vulnerability monitoring coupled with regular risk assessment schedules.

To maintain oversight, healthcare entities should develop centralized evidence and agreement tracking systems. AI-powered review solutions can help analyze questionnaire results and streamline due diligence procedures, yet manual verification remains essential for critical security controls.

Joint tabletop exercises simulating PHI breach scenarios offer another effective method for evaluating vendor preparedness while strengthening collaborative response capabilities across organizational boundaries.

Emerging AI Risks in Clinical and Operational Settings

Artificial intelligence applications in clinical settings create unique security vulnerabilities that extend beyond traditional HIPAA concerns. As healthcare providers deploy these technologies, understanding emerging risks becomes essential for maintaining HIPAA compliance and AI standards.

Generative AI in Patient-Facing Applications

Clinicians increasingly integrate generative AI tools into clinical workflows to analyze health records, identify risk factors, assist in disease detection, and draft real-time patient summaries — the same category of work AI medical scribes now handle for many therapy practices. These applications offer significant workflow advantages, yet simultaneously introduce substantial privacy risks.

Governance is lagging adoption. A March 2026 Wolters Kluwer/Ipsos survey of physicians and nurses found that only 27% of clinicians said their organization had published AI policies at all, and awareness gaps were even wider: just 21% of physicians and 36% of nurses knew whether their organization had a policy authorizing generative AI use in the first place. Despite that, 48% of clinicians surveyed reported using generative AI daily. Separately, an October 2025 healthcare AI governance report found that a quarter of organizations have not formally approved any AI use, even though 95% already have PHI-access employees using AI tools, and 75% of IT and compliance leaders worry staff mistakenly assume everyday tools are "automatically HIPAA compliant."

Patient-facing chatbots and virtual assistants may collect protected health information in ways that raise unauthorized disclosure concerns, especially when these tools weren't designed with HIPAA safeguards. Healthcare providers experimenting with generative AI must implement strict policies governing how employees use these tools. Processing identifiable patient data through public, consumer-grade generative AI platforms without a BAA typically violates HIPAA rules and creates significant security vulnerabilities.

Black Box Models and Explainability Challenges

AI systems often function as "black boxes," making decisions without providing clear explanations for their reasoning. This opacity creates fundamental challenges for HIPAA and FDA compliance alike, primarily because regulators demand transparency and accountability.

The FDA updated its clinical decision support (CDS) software guidance in January 2026, and the update cuts both ways. On one hand, it eases device-level oversight for CDS tools that give a single, clinically appropriate recommendation with fully transparent, clinician-reviewable logic. On the other hand, it explicitly maintains that "where models are opaque (for example, black-box large language models), time-critical, or directive in nature, device oversight should still be expected." In other words, transparent AI got a lighter compliance touch in 2026, while black-box and generative models used for high-stakes clinical decisions did not. For compliance officers, this opacity still creates real audit challenges, making it difficult to validate precisely how protected health information flows through AI systems.

Bias Detection and Health Equity Implications

AI models trained on biased datasets may perpetuate or amplify existing healthcare disparities. Bias can emerge from multiple sources:

  • Data bias - Underrepresentation of protected groups, missing data patterns, and differential informativeness across populations
  • Algorithmic bias - Design choices that inadvertently encode healthcare disparities into decision processes
  • Interaction bias - Overreliance on automation, feedback loops reinforcing errors, and alert fatigue among clinicians

Under 45 CFR 92.210 — the Section 1557 nondiscrimination regulation, in force since May 6, 2024 and still active as of this writing — covered entities must make reasonable efforts to identify AI-based patient care decision support tools that use race, color, national origin, sex, age, or disability as an input variable, and take reasonable steps to mitigate the risk of discrimination from their use. Therefore, organizations must rigorously test AI systems across diverse populations to ensure equity in healthcare outcomes, not just accuracy in aggregate.

Regular audits with independent validation play a crucial role in identifying potential biases. Many organizations are establishing dedicated governance committees for continuous algorithm quality control to monitor AI performance, identify biases, and implement necessary updates.

Compliance Readiness and Staff Enablement

Organizational readiness for HIPAA compliance AI requires structured training programs and monitoring systems. AI literacy is increasingly treated as a compliance requirement in its own right, with staff needing appropriate skills to interpret AI outputs and recognize when to escalate issues.

AI Governance Training for Clinical and IT Teams

Effective AI training constitutes a key risk mitigation strategy, requiring implementation and oversight from governance committees. Training programs should be:

  • Role-specific - Physicians may need training on AI diagnostic tools, while administrative staff require education on scheduling applications
  • Risk-calibrated - More robust training for higher-risk AI applications
  • Certification-based - Focused on AI ethics, healthcare data privacy, and compliance documentation

Cross-functional development bridges technical, clinical, privacy, security, and compliance perspectives. With this in mind, organizations should schedule periodic skills evaluations to ensure teams meet evolving compliance standards, especially given how quickly regulatory guidance is shifting.

Audit Trails for AI Decision-Making

Detailed audit trails form the backbone of AI compliance documentation. HIPAA-regulated entities must implement automated tracking systems for every data access event. Effective audit trails encompass three interconnected categories: user identification, system access logs, and application activity.

For AI systems specifically, audit components should track user authentication, timestamp information, IP addresses, and specific application activities. Organizations must designate IT team members to actively monitor these logs, together with restricting audit trail access to those directly responsible for security monitoring.

Monitoring Regulatory Guidance from OCR and HHS

In addition to internal controls, organizations must continuously monitor regulatory updates, since the pace of change here has been unusually fast. In its January 2025 "Dear Colleague" letter on AI nondiscrimination, the Office for Civil Rights recommended several specific measures for AI oversight:

  • Review published research on AI risks
  • Implement written policies governing AI tool use
  • Train staff on proper AI utilization
  • Allow qualified humans to override AI decisions

With attention to patient disclosure, healthcare organizations should inform patients when AI tools are used in clinical decision-making that could affect them. As covered above, 45 CFR 92.210 already requires covered entities to identify patient care decision support tools that employ protected-characteristic variables and take reasonable steps to mitigate discrimination risk — this is current law today, not a future proposal.

Frequently Asked Questions

Is the proposed HIPAA Security Rule update from January 2025 final yet?

No. As of September 2026, the NPRM remains proposed. HHS closed the public comment period in March 2025 after receiving thousands of comments, then moved the rule to its "Long-Term Actions" regulatory agenda with a non-binding target of July 2027 for final action. The current HIPAA Security Rule — not the proposed one — is what's legally enforceable today.

Does HIPAA require us to tell patients when AI is used in their care?

There's no blanket HIPAA requirement to disclose every use of AI, but two related obligations push in that direction: OCR's AI guidance recommends disclosure when AI materially affects a care decision, and the Section 1557 nondiscrimination rule (45 CFR 92.210) requires identifying and mitigating bias risk in AI-based patient care decision tools that use protected-class variables. Many organizations choose to disclose AI use proactively as a trust and compliance best practice.

Can we use de-identified PHI to train an AI model without patient authorization?

Yes, provided the data is properly de-identified under either the HIPAA Safe Harbor method (removing all 18 specified identifiers) or the Expert Determination method (a qualified statistician certifies re-identification risk is very small). Properly de-identified data falls outside HIPAA's PHI protections.

Is our AI vendor automatically a HIPAA business associate?

If the AI tool creates, receives, maintains, or transmits ePHI on your behalf, the vendor is a business associate and needs a signed BAA before it touches any PHI — regardless of whether the vendor calls itself an "AI platform," a "chatbot," or anything else. This applies to fourth-party subcontractors and underlying model providers too.

What should our practice do now, while the Security Rule update is still pending?

Treat the proposed requirements — encryption, multi-factor authentication, six-month vulnerability scans, documented AI asset inventories — as a practical roadmap rather than waiting for finalization. Choosing practice management and documentation tools built with these safeguards already in place makes that transition easier when a final rule does arrive.

Conclusion

Healthcare organizations face a genuinely unusual compliance environment heading into 2027: the marquee HIPAA Security Rule update has been delayed to a non-binding 2027 target, even as AI adoption accelerates and a separate nondiscrimination rule for AI-based clinical decision tools is already in force. The intersection of artificial intelligence and protected health information demands rigorous security controls across multiple dimensions, and the fact that one major rule remains "proposed" is no excuse to wait.

Effective HIPAA compliance for AI systems requires comprehensive approaches to several critical areas. First, healthcare entities must thoroughly understand permissible PHI usage within AI workflows while strictly adhering to minimum necessary standards. Additionally, proper de-identification through either Safe Harbor or Expert Determination methods remains essential when deploying AI solutions.

Risk management takes center stage as organizations inventory AI assets, analyze lifecycle risks, and implement robust patch management protocols. Vendor oversight presents equally significant challenges, necessitating enhanced Business Associate Agreements specifically designed for AI-driven data processing.

Emerging risks further complicate compliance efforts. Black box and generative AI models continue to face explainability scrutiny even as transparent clinical decision support tools get a lighter regulatory touch, while bias detection remains crucial for maintaining equitable healthcare delivery under 45 CFR 92.210. Consequently, staff enablement through targeted training and comprehensive audit trails must support these technical safeguards.

Healthcare organizations cannot afford to overlook these requirements as AI becomes deeply integrated into clinical and operational workflows. Though compliance demands significant investment, potential penalties for violations far outweigh implementation costs. The strategic implementation of these security requirements ultimately protects both patient privacy and organizational integrity while enabling responsible AI innovation in healthcare delivery.

Share on Socials:

Reduce costs and improve your reimbursement rate with a modern, all-in-one clinic management software.

Get a Demo
Table of Content
Have a question? Ask someone who actually knows

Case Study

90% Engagement Lift & 70% Reduction in Check-In Time at Excel Therapy

Read Case Study

Ready to Maximize Your Savings?

See how other clinics are saving with SPRY.

Transform Your

Compliance

Practice Today

See How SPRY Addresses Unique

Compliance

Challenges