Data Security

Is there an AI platform that is HIPAA compliant?

Back to BlogIs there an AI platform that is HIPAA compliant?

Is there an AI platform that is HIPAA compliant?

Key Facts

  • No AI tool is HIPAA compliant out of the box, compliance is a property of the deployment according to compliance analysis.
  • 90% of health systems use AI in production, highlighting widespread adoption as of 2025.
  • OCR enforcement actions targeting AI rose 340% in 2025, reflecting increased regulatory scrutiny according to regulatory analysis.
  • Standard BAAs do not address AI-specific data risks, as highlighted by a $12.5 million HIPAA settlement in 2025.
  • Only specific configurations of AI platforms support HIPAA compliance, with OpenAI offering zero-retention endpoints as of 2025.
  • Healthcare-native AI platforms, like Prosper AI and Neon Health, market themselves as HIPAA compliant with strong compliance features.
  • A comprehensive AI-specific HIPAA rule is expected in Q1 2026, mandating impact assessments and algorithm auditing to enhance data security

Why "HIPAA-Compliant AI" Is the Wrong Question to Ask

When evaluating AI platforms for healthcare, the question "Is this AI platform HIPAA compliant?" is often the first consideration. However, this question is misleading. The truth is that no AI tool is HIPAA compliant out of the box. HIPAA is a technology-neutral regulation that governs relationships and conduct, not algorithms. Compliance hinges on a combination of the right product tier, a signed Business Associate Agreement (BAA), and specific configuration choices. This distinction is crucial for healthcare practices considering AI receptionists, voice agents, or support tools.

Most AI platforms, including those from major vendors like OpenAI and Microsoft, offer HIPAA-eligible configurations. For example, OpenAI provides specific enterprise tiers and API configurations that support HIPAA compliance. However, consumer versions of ChatGPT and standard Business workspaces are not covered by a BAA and must not be used with Protected Health Information (PHI). According to industry research, OpenAI signs BAAs only for specific enterprise accounts and ChatGPT for Healthcare customers. This nuance is critical for healthcare providers to understand.

Similarly, Anthropic's Claude requires explicit activation of HIPAA compliance by a Primary Owner for Enterprise/API plans. Standard enterprise plans do not include BAA coverage without this action. Microsoft 365 Copilot can support HIPAA compliance when properly configured, but web-search queries are excluded from its BAA. A recent study found that these configurations are essential for ensuring data security and compliance.

Healthcare-native AI platforms, such as Prosper AI, Hyro, and Neon Health, market themselves as HIPAA compliant with BAAs, SOC 2 Type II reports, and encryption controls. These platforms often cater to specific healthcare workflows, providing tailored solutions that meet stringent regulatory requirements. For instance, Prosper AI offers HIPAA compliance with healthcare-specific QA built in, SOC 2 Type II certification, and encryption in transit and at rest. Agencies like Prosper AI and Neon Health focus on creating a secure environment for AI deployment in healthcare, ensuring that all data handling processes comply with HIPAA standards.

To ensure compliance, healthcare providers must verify several key aspects of an AI platform:

  • A signed BAA with the AI vendor
  • SOC 2 Type II reports and encryption controls
  • Data retention settings and sub-processor agreements
  • Organizational safeguards and configuration choices

Agents by AIQ, known for designing and operating AI agents tailored for small and mid-size businesses, understands the complexities of HIPAA compliance. Our AI receptionists and voice agents are built with these considerations in mind, ensuring that healthcare practices can leverage AI technology without compromising data security. If you're considering integrating AI into your healthcare practice, it's essential to work with a provider that prioritizes compliance and data security. For healthcare providers seeking to streamline their operations with AI, booking a call with Agents by AIQ to scope an AI agent tailored to your specific needs can be a game-changer. This approach ensures that your AI tools are not only effective but also fully compliant with HIPAA regulations.

Which AI Platforms Can Actually Be Configured for HIPAA Compliance

The short answer: yes, but only under specific conditions. No major AI platform is HIPAA compliant out of the box — compliance is a property of the deployment, not the product, according to compliance analysis. Every vendor below offers a BAA only on certain tiers, with certain configurations.

OpenAI signs BAAs only for its API on zero-retention-eligible endpoints and sales-managed Enterprise accounts, including ChatGPT for Healthcare customers, per current status reporting. Standard API endpoints retain data for 30 days, making them unsuitable for PHI; zero-retention endpoints delete request data as soon as the response is returned, but only on specific endpoints like text generation and embeddings (per this 2025 guide). Consumer ChatGPT — Free, Plus, Pro, or Team — stores conversations indefinitely, may use them for model training, and is never BAA-covered.

Anthropic Claude covers its first-party API and Claude Enterprise under a BAA, but only after the Primary Owner explicitly activates HIPAA compliance in settings. Cowork, MCP connectors, and enterprise search over third-party data fall outside the BAA, and Claude Code is covered only with zero data retention enabled (per vendor posture analysis).

Microsoft offers two paths: Azure OpenAI Service, which is covered under Microsoft's BAA and does not train on customer prompts by default, and Microsoft 365 Copilot, which can support HIPAA compliance when properly configured — though web-search queries are excluded from its BAA. Google Cloud frames HIPAA as a shared responsibility limited to BAA-covered services.

A separate category of healthcare-native platforms markets compliance as a core feature rather than an enterprise add-on:

  • Voice AI platforms — Hyro (BAA, SOC 2), TeleVox (BAA), Nuance (backed by Azure infrastructure), Observe.AI, and Prosper AI, which offers SOC 2 Type II, encryption, SSO, and a zero-day retention agreement with OpenAI (platform comparison).
  • Ambient documentation tools — Abridge, Nabla, Suki, and Microsoft Dragon Copilot, the most widely adopted clinical AI use case per KLAS; Permanente Medical Group deployed Nabla to 10,000 physicians (adoption research).
  • Local processing options — tools like AirgapAI keep PHI on-premises entirely, eliminating external vendor risk (compliance comparison).

The pattern across every vendor: coverage is tier-specific, conditional, and requires verification. At Agents by AIQ, when we scope AI agents for healthcare practices, the first question is always which deployment path can carry a BAA — not which model sounds smartest. If your team is evaluating voice agents or automation for patient-facing workflows, book a call to scope the agent and we'll walk the compliance requirements alongside the workflow design.

The Hidden Risks: BAAs, Sub-Processors, and the 2025 Enforcement Crackdown

A signed Business Associate Agreement might feel like the moment compliance is "handled." In 2025, federal regulators made it clear that feeling is wrong.

OCR enforcement actions targeting AI rose 340% in 2025, and the agency issued more AI-related guidance that year than in the previous five years combined, according to regulatory analysis. The pressure culminated in the largest HIPAA settlement of the year — $12.5 million against a major health system — which made explicit what compliance officers had been warning about: standard BAAs cannot address AI-specific data risks.

The reason is structural. A BAA covers the vendor you signed with, but AI platforms rarely operate alone. They run on cloud hosts, route data through sub-processors, and call third-party models. As compliance research explains, BAAs must flow down the stack — your AI vendor needs its own agreements with every sub-processor before PHI can lawfully move through the chain. A gap at any layer is a gap in your compliance posture.

Then there's the problem regulators called "unregistered AI": clinical and front-office staff adopting AI tools without IT or compliance involvement. New OCR guidance clarified that organizations carry liability for all AI use, authorized or not. The workforce exception offers no shield — an employee pasting PHI into an unapproved tool makes that provider a business associate, and disclosing PHI to a third-party AI tool without a BAA qualifies as a notifiable breach, per HIPAA Journal's analysis.

Several AI-specific breach triggers catch organizations off guard:

  • PHI sent to a consumer-tier AI product with no BAA in place — consumer ChatGPT plans, for example, are never covered, per compliance reviews
  • Standard API endpoints retaining data for 30 days, when only zero-retention endpoints are BAA-eligible, as OpenAI guidance shows
  • Sub-processor gaps down the vendor stack, where a BAA exists at the top layer but not below it
  • De-identified information re-identified by a vendor's AI system, which counts as a reportable breach

For practices and small healthcare businesses, this is why "can we sign a BAA?" is the wrong first question. The right questions address retention settings, sub-processor coverage, and whether the deployment keeps PHI inside a controlled boundary with every access logged. At Agents by AIQ, that scrutiny shapes how we scope any agent build touching patient data — the contract is the starting point, never the finish line. A comprehensive AI-specific HIPAA rule is expected in Q1 2026, and the organizations already auditing their full AI stack will be the ones ready for it.

Your Due Diligence Checklist: What to Verify Before Letting an AI Agent Touch PHI

A vendor saying "we're HIPAA compliant" is a marketing claim, not a legal fact. As compliance analysts point out, HIPAA governs relationships and conduct, not products — so the burden of verification falls squarely on you, the covered entity. OCR enforcement actions targeting AI rose 340% in 2025, and regulators have made clear that organizational liability extends even to tools your staff adopt without IT involvement.

Before any AI agent — whether it's answering phones, scheduling appointments, or following up on patient inquiries — touches PHI, demand documentation on every item below. This is the same standard we hold vendors to at Agents by AIQ when building agent workflows for healthcare clients.

  • A signed BAA with flow-down coverage. The vendor must have BAAs with its own sub-processors and cloud hosts before PHI can lawfully move through the stack. OCR settlements tied to missing or deficient BAAs have ranged from $31,000 to $1.55 million.
  • SOC 2 Type II and encryption. Ask for the actual report, plus confirmation of encryption in transit and at rest (e.g., AES 256, TLS) and per-tenant data isolation.
  • Zero-retention data settings and no training on customer PHI by default. Standard OpenAI API endpoints, for instance, retain data for 30 days — only specific zero-retention endpoints are BAA-eligible.
  • Audit logging, SSO, and role-based access controls, so every access to PHI is logged and restricted by role.
  • Documented uptime commitments, backup and retention policies, and a pentest or vulnerability-scanning cadence.

Watch for tier-specific traps. Consumer ChatGPT plans are never BAA-covered and must never touch PHI, and Anthropic's BAA only applies after an administrator explicitly activates HIPAA compliance in settings. A vendor's default configuration may not match its marketing page.

Finally, confirm what happens after a breach: who notifies whom, on what timeline, and what the contract says about liability. HIPAA Journal notes that disclosing PHI to a third-party AI tool without a BAA qualifies as a notifiable breach — so this checklist is not paperwork. It is the difference between a compliant deployment and a six-figure settlement, and it should be completed before the first call is ever answered.

Getting Compliant AI Agents Working in Your Practice — Without Becoming a Compliance Expert

Reading this far, you've probably noticed a pattern: HIPAA compliance for AI is less about picking the right vendor and more about configuring the deployment correctly. That's a problem if you're running a practice, because configuration is exactly the work you don't have time for.

The stakes are real. OCR enforcement actions targeting AI rose 340% in 2025, and the largest HIPAA settlement of the year — $12.5 million — made clear that standard BAAs alone cannot address AI-related data risks. Regulators now expect the full stack of controls: signed BAAs flowing down to sub-processors, PHI never leaving controlled boundaries, every access logged, and role-based permissions, as compliance engineers frame it.

This is where the DIY route breaks down for small practices. A self-serve toolkit gives you the pieces — an API key, a voice agent builder, maybe a BAA template — but leaves you to assemble the compliance layer yourself. That means verifying zero-retention endpoints, confirming sub-processor BAAs, setting up audit logging, and maintaining input policies so staff never paste PHI into the wrong field. One misconfiguration, and as HIPAA Journal notes, disclosing PHI to a non-compliant tool qualifies as a notifiable breach.

A done-for-you build shifts that burden to the team building the agent. When Agents by AIQ scopes a compliant AI receptionist or support agent for a healthcare practice, the BAA-backed configuration, PHI boundaries, and interaction logging are handled as part of the build — not handed to you as a checklist. The practical difference looks like this:

  • BAA-backed setup from day one — the vendor confirms which platforms and tiers carry BAA coverage before any patient data flows, rather than after.
  • PHI boundaries configured into the agent itself, so the receptionist answers calls and books appointments without routing protected data through non-compliant endpoints.
  • Audit logging and access controls established during implementation, aligned with the safeguards regulators expect.
  • Ongoing operation by the same team that built it, so configuration drift doesn't quietly erode your compliance posture.

The timing matters, too. A comprehensive AI-specific HIPAA rule is expected in Q1 2026, bringing mandatory impact assessments and algorithm auditing. Practices that start with a properly configured deployment now will have a foundation to build on; practices that start with a misconfigured DIY agent will have cleanup work.

None of this requires you to become a compliance expert. It requires working with a team that treats compliance as a property of the deployment — because as the research consistently shows, no AI tool is compliant out of the box.

If you're ready to stop losing calls to voicemail without putting patient data at risk, book a call to scope a compliant AI receptionist or support agent. We'll walk through your workflows, identify where PHI touches each one, and design an agent that handles the busywork while keeping your practice on solid ground.

Frequently Asked Questions

Is there an AI platform that is HIPAA compliant?
While no AI tool is HIPAA compliant 'out of the box,' several platforms can be configured to meet HIPAA standards, including OpenAI and Anthropic, with the right product tier, a signed Business Associate Agreement (BAA), and specific configuration choices, as explained by compliance experts.
What are the key requirements for HIPAA compliance in AI platforms?
To ensure compliance, healthcare providers must verify a signed BAA with the AI vendor, SOC 2 Type II reports, encryption controls, data retention settings, and sub-processor agreements, as HIPAA guidelines outline.
Can consumer versions of AI tools like ChatGPT be used with Protected Health Information (PHI)?
No, consumer versions of ChatGPT, such as Free, Plus, Pro, or Team, are not covered by a BAA and must not be used with PHI, according to OpenAI's compliance policies.
How do healthcare-native AI platforms ensure HIPAA compliance?
Healthcare-native platforms, such as Prosper AI and Hyro, market themselves as HIPAA compliant with BAAs, SOC 2 Type II reports, and encryption controls, and often cater to specific healthcare workflows, providing tailored solutions that meet stringent regulatory requirements, as seen in industry comparisons.
What are the consequences of non-compliance with HIPAA regulations in AI adoption?
Non-compliance can result in significant fines, with OCR settlements ranging from $31,000 to $1.55 million, and even a $12.5 million settlement in 2025, highlighting the importance of ensuring HIPAA compliance in AI adoption, as reported by regulatory analysis.
How can healthcare practices ensure compliance when integrating AI tools into their workflows?
To ensure compliance, healthcare practices should work with a provider that prioritizes compliance and data security, such as Agents by AIQ, which offers done-for-you AI agent builds that meet HIPAA standards, and verify the necessary requirements, including a signed BAA, SOC 2 Type II reports, and encryption controls, as recommended by compliance guides.

Navigating HIPAA Compliance in the AI-Driven Healthcare Landscape

The journey to integrating AI in healthcare is fraught with regulatory hurdles, but understanding that HIPAA compliance is about more than just checking a box is the first step. As explored, no AI platform is HIPAA compliant out of the box; compliance hinges on the right tier, a signed Business Associate Agreement (BAA), and meticulous configuration. Major players like OpenAI, Microsoft, and healthcare-native solutions like Prosper AI and Neon Health offer paths to compliance, but each requires diligent verification of data handling practices, sub-processor agreements, and organizational safeguards. As healthcare providers navigate these complexities, the importance of partnering with experts who understand these nuances cannot be overstated. For those looking to streamline operations without compromising data security, taking the next step with a provider like Agents by AIQ can make all the difference. By booking a call to scope an AI agent tailored to your specific needs, you ensure that your AI tools are not only effective but also fully compliant with HIPAA regulations, providing peace of mind and operational efficiency.

Stay in the Loop