Quick answer (updated August 2026): No AI tool is HIPAA-compliant on its own. Tools are HIPAA-eligible, meaning the vendor will sign a Business Associate Agreement (BAA), the contract that makes it legally responsible for patient data. Compliance comes from that signed BAA plus your configuration, policies, and training. Skip the BAA and every prompt containing patient information is a potential violation, priced at $141 to $71,162 each under HHS’s January 2026 penalty schedule.
This article is general information for practice owners, not legal advice. Confirm decisions with your compliance counsel. Unlike every vendor page ranking for this search, we sell no software and take no commissions, so we have no tool to steer you toward.
Why “HIPAA-compliant AI tool” is the wrong question
“HIPAA-compliant AI tool” is a category error. HIPAA regulates you, the covered entity, and the business associates you share protected health information (PHI) with. It does not certify products. There is no HHS-recognized HIPAA certification for any software; Google states on its own compliance page that “there is no certification recognized by the US HHS for HIPAA compliance and… complying with HIPAA is a shared responsibility.”
So the honest vocabulary is HIPAA-eligible: the vendor offers a BAA covering the product you intend to use. Whether your use of it is compliant depends on three things stacked on top of that contract: how the tool is configured (retention, access, excluded features), what workflows you allow it into, and whether your staff follow the policy you wrote. A vendor can hand you a flawless BAA on Monday and your front desk can break compliance by Tuesday with one pasted chart note in a personal account. The question to ask is never “is this tool compliant?” It is “can this tool be operated compliantly in my practice, and have we done the operating?”
What a BAA actually is, in plain English
A Business Associate Agreement is the signed contract that makes an outside vendor legally responsible for the patient data you hand it. The HIPAA Privacy Rule at 45 CFR § 164.502(e)(1)(i) says a practice may disclose PHI to a vendor only with “satisfactory assurances that the business associate will appropriately safeguard the information,” documented in that written agreement. The Security Rule repeats the requirement for electronic PHI at 45 CFR § 164.308(b)(1), and HHS’s Office for Civil Rights publishes plain-language guidance on who counts as a business associate.
Who signs: you (the covered entity) and the vendor (the business associate). If the AI vendor routes PHI to subcontractors, such as the company hosting the underlying model, those subcontractors need their own downstream agreements. The required contract terms live at 45 CFR § 164.504(e): permitted uses, safeguards, breach reporting, subcontractor flow-down, and return or destruction of data at termination.
What to verify before you sign:
- Exact scope. Does the BAA cover the specific product, plan tier, and features you will use? Vendors routinely exclude certain features or require special configurations.
- Training use. Does the vendor use your data to train models, and where is that disclaimed in writing?
- Retention. How long are prompts, outputs, and audio kept? Is a zero-retention option available?
- Subcontractors. Which companies touch PHI downstream, and are they bound by agreements?
- Breach terms. Notification duties and timelines.
Where the five major AI platforms stand on BAAs
Every practice-facing AI product (scribes, phone agents, intake bots) is built on one of a handful of platforms. Here is what each platform publishes, verified against their own pages in July 2026. Policies change; confirm the current page before you rely on it.
| Platform | BAA available? | What the vendor publishes |
|---|---|---|
| OpenAI | Yes, for the API and sales-managed ChatGPT Enterprise/Edu | BAA for the API by request (baa@openai.com). Verbatim: “we don’t offer a BAA for ChatGPT Business.” Consumer Free/Plus have no published BAA path. |
| Anthropic (Claude) | Yes, for the Claude API and Claude Enterprise | Commercial Terms bar training on customer content. Consumer plans (Free/Pro/Max) are explicitly excluded; some features are covered only with zero data retention. |
| Microsoft Azure | Yes, included by default | The BAA is included “through the Microsoft Online Services Data Protection Addendum by default.” Azure, including Azure OpenAI, is an in-scope service. |
| AWS (Amazon Bedrock) | Yes, self-service via AWS Artifact | Amazon Bedrock appears on the AWS HIPAA Eligible Services Reference, with model-level exclusions noted on the list as of July 2026. AWS customers agree not to use eligible services with PHI “without first entering into an AWS business associate agreement.” |
| Google Cloud | Yes, for covered services | “Google will enter into Business Associate Agreements with customers as necessary under HIPAA.” Coverage is per-product; check the current covered-services list for the exact product you plan to use. |
Two patterns matter for a small practice. First, the BAA lives at the business or API tier on every platform; no vendor offers one on a consumer account. Second, “the platform signs BAAs” never means “everything on the platform is covered.” Scope is per-product, per-feature, and sometimes per-configuration.
Classify any tool in one minute: three labels
You do not need a compliance department to sort your AI stack. In our assessment work we label every tool prescription one of three ways, and the same labels work for anything a vendor pitches you:
- BAA-available. The vendor will sign a BAA covering the product and features you would use. Eligible for PHI workflows once the BAA is signed and the configuration matches its terms.
- BAA-required. The workflow touches PHI (charting, intake, scheduling with patient identifiers, claims, call handling), so whatever tool fills it must be BAA-available, signed, and configured. If the vendor hedges, the tool is disqualified for that workflow regardless of how good the demo looks.
- Not-for-PHI. The tool has no BAA path, or you choose not to sign one. It can still earn its keep in workflows that never see patient data: marketing copy, job postings, internal SOPs, supply research.
The discipline is drawing the PHI boundary first and shopping second. Most “is this tool safe?” confusion dissolves once you ask which side of the line the workflow sits on. Our guide to AI for healthcare practices walks through which practice workflows sit on which side.
What violations actually cost in 2026
The penalty numbers most vendor blogs quote are stale. Under HHS’s annual inflation adjustment published in the Federal Register on January 28, 2026, civil penalties now run in four tiers: $141 to $71,162 per violation where the practice did not know and could not reasonably have known; $1,424 to $71,162 for reasonable cause; $14,232 to $71,162 for corrected willful neglect; and a $71,162 minimum for uncorrected willful neglect. The annual cap is $2,134,831 per violation type. (OCR’s 2019 enforcement-discretion notice applies lower annual caps in practice for the lower tiers.)
Two more facts belong in your risk picture, both date-stamped mid-2026. First, OCR has announced no enforcement action targeting an AI vendor or AI-specific use to date. Second, that grace period is narrowing: OCR’s proposed Security Rule update (NPRM, January 6, 2025) would explicitly pull AI tools into the risk analysis and risk management your practice is already required to run. Proposed, not final, but it tells you where enforcement is headed.
The shadow-AI problem is already inside your practice
The biggest HIPAA exposure in most small practices is not the tool you are evaluating. It is the tools your staff already use. MIT Project NANDA’s preliminary 2025 research (52 interviews, 153 leader surveys, 300+ public deployments) found that while only 40% of companies had purchased an official LLM subscription, workers from over 90% of companies surveyed reported regular use of personal AI tools for work. There is no reason to believe medical front offices are the exception.
A medical assistant summarizing a visit note in a personal ChatGPT account is disclosing PHI to a vendor with no BAA, on a consumer tier where, per OpenAI’s own privacy page, data from individual services can be used for training. That is the exact scenario the Privacy Rule’s business-associate requirement exists to prevent. The fix is not a ban memo. Bans push usage underground. The fix is a short written policy naming what may and may not touch AI, plus a sanctioned, BAA-covered alternative that is genuinely easier than the workaround. Staff use consumer AI because it helps; give them the compliant version of the help.
Eight questions to ask any AI vendor before PHI touches it
Send these in writing and keep the answers with your compliance records. A vendor comfortable with HIPAA answers all eight without flinching.
- Will you sign a BAA covering the exact product, plan, and features we intend to use? Which features are excluded from it?
- Is our data used to train your models or your subcontractors’ models? Where do your terms say so?
- How long are prompts, outputs, uploads, and audio retained? Do you offer zero data retention?
- Which subcontractors process our PHI, and are they bound by downstream agreements?
- What are your breach notification duties and timelines under the BAA?
- Can we export audit logs showing who accessed what, and when?
- What happens to our data when we terminate: return, deletion, and proof of deletion?
- What independent security audits (for example SOC 2 Type II) can you share, and how current are they?
Refusals, vagueness, or “our platform is HIPAA-certified” (no such certification exists) are each a disqualifying answer for any PHI workflow.
The right order of operations
Vendor pages skip this because it does not sell software: compliance is a sequence, and the tool comes last. The order that keeps a small practice out of trouble is the one already implied by the Security Rule. First, update your security risk analysis to name the AI workflow and the PHI it touches; the proposed OCR rule would make this explicit. Second, get the BAA signed and read its scope. Third, configure the tool to match the BAA: retention settings, access controls, excluded features off. Fourth, write the one-page staff policy, including what stays out of personal accounts. Fifth, train the team and pilot one bounded workflow before expanding.
If you want the economic side of that sequence, which workflows repay automation first and what the tools cost, start with our plain-English guide to AI for small businesses or the healthcare-specific breakdown, including how to evaluate AI scribes without taking a vendor’s word for it.
Bottom line
There is no such thing as a HIPAA-compliant AI tool, only HIPAA-eligible tools operated compliantly. Eligibility means the vendor signs a BAA for the exact product and features you use; all five major AI platforms offer one at their business or API tiers, and none offers one on consumer accounts. Compliance is the BAA plus your configuration, policy, and training, in that order. Get the sequence right and the penalty schedule ($141 to $71,162 per violation, capped at $2,134,831 per year per provision as of January 2026) stays someone else’s problem.
Sources
- Cornell Law School LII, 45 CFR § 164.502: Uses and disclosures of PHI (Privacy Rule BAA requirement). https://www.law.cornell.edu/cfr/text/45/164.502
- Cornell Law School LII, 45 CFR § 164.308: Administrative safeguards (Security Rule BAA requirement). https://www.law.cornell.edu/cfr/text/45/164.308
- HHS Office for Civil Rights, “Business Associates” guidance. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
- OpenAI Help Center, “How can I get a Business Associate Agreement (BAA) with OpenAI for the API Services?” (updated July 2026). https://help.openai.com/en/articles/8660679
- OpenAI, “Enterprise privacy at OpenAI” (updated January 2026). https://openai.com/enterprise-privacy/
- Anthropic Privacy Center, Business Associate Agreement article. https://privacy.claude.com/en/articles/8114513
- Microsoft Learn, “HIPAA & HITECH Act” (updated June 2026). https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech
- AWS, “HIPAA Eligible Services Reference” (updated July 2026). https://aws.amazon.com/compliance/hipaa-eligible-services-reference/
- Google Cloud, “HIPAA Compliance on Google Cloud” (updated July 2026). https://cloud.google.com/security/compliance/hipaa
- Federal Register, “Annual Civil Monetary Penalties Inflation Adjustment,” HHS, January 28, 2026. https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- HHS, HIPAA Security Rule NPRM fact sheet (proposed rule, January 6, 2025). https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
- HHS Office for Civil Rights, Resolution Agreements index (enforcement record). https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
- MIT Project NANDA, “The GenAI Divide: State of AI in Business 2025” (preliminary report, July 2025). https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf