HIPAA and AI: What Medical Practices Must Know Before Adopting
A plain-English guide to HIPAA compliant AI tools for Capital Region medical practices: what BAAs actually require, where the compliance line sits, and how to start safely.
Most physicians are already using AI, whether their compliance officer knows it or not. According to the American Medical Association, nearly two-thirds of physicians (66%) reported using health AI in 2024, up from 38% in 2023 — a 78% jump in a single year. A more recent AMA survey puts the figure above 80%. The tools are already in the building.
For an independent specialty group, imaging center, or behavioral health practice in Albany, Troy, or Saratoga, that raises an uncomfortable question: how much of this AI use is actually HIPAA-compliant — and how much is a compliance event waiting to happen? This guide walks through what you need to understand before you approve (or discover) AI in your practice.
"HIPAA compliant AI" is not a badge a vendor can award itself
The first thing to unlearn is the marketing phrase. When a vendor stamps "HIPAA compliant AI tools" on its website, that claim means less than it appears to. HIPAA compliance is not a certification a software product earns. It's a function of how your practice — the covered entity — uses the tool, what safeguards are in place, and what agreements you've signed.
A tool can be built in a way that supports compliance. But the same tool, used carelessly, can still produce a violation. Pasting a patient's chart note into a free public chatbot to "clean up the wording" is a breach regardless of how secure that chatbot's servers are, because you've sent Protected Health Information (PHI) to a vendor with no obligation to protect it. The technology isn't the whole story; the workflow around it is.
This is why healthcare AI compliance is really a governance problem, not a shopping problem. You don't buy your way to compliance. You build a process and then choose tools that fit inside it.
The Business Associate Agreement is the real gatekeeper
Here's the single most practical test for any AI in a medical practice under HIPAA: will the vendor sign a Business Associate Agreement (BAA)?
A BAA is a contract in which a vendor that handles PHI on your behalf legally commits to protecting it and accepts liability for mishandling it. Under HIPAA, any vendor whose product touches PHI must sign one. No BAA, no PHI — full stop.
This one question quietly disqualifies a large share of the AI tools your staff might reach for. Many free, consumer-grade chatbots explicitly will not sign a BAA, which makes them unsuitable for anything involving patient data. The paid, enterprise, or healthcare-specific versions of those same tools often will — but you have to ask, get it in writing, and read what it actually covers. The U.S. Department of Health and Human Services publishes the requirements and sample BAA provisions directly, which is a far better reference than any vendor's summary.
A useful rule for your team: if a tool handles PHI and hasn't signed a BAA, it doesn't get used for PHI. That single sentence, enforced, prevents most of the informal-AI risk in a small practice.
Why the stakes are higher in healthcare than almost anywhere else
Regulators and cyber insurers treat health data as high-risk for a reason. According to IBM's Cost of a Data Breach report, the average healthcare data breach cost nearly $10 million in 2024 — the highest of any industry, a distinction healthcare has held for years running. That figure was corroborated by Healthcare Dive.
Be honest about what that number is and isn't. It's a national industry average across hospital systems and large organizations. A two-physician Albany practice is not going to face a $10 million event. But the figure explains why PHI is treated as radioactive: the downside of getting it wrong is severe, and AI adds new ways to get it wrong — data leaving your control through a tool nobody vetted, or a confident-sounding AI output that's simply incorrect.
That second risk deserves emphasis. For a medical practice, a confident wrong answer is a clinical or compliance problem, not a minor inconvenience. AI drafting tools can fabricate details, misstate dosages, or invent plausible-sounding facts. Anything an AI produces that touches a patient record, a claim, or a clinical decision needs a human review step before it counts. Keep the human in the loop, and prefer tools that show you their sources so a person can verify them.
Where AI genuinely earns its keep in a practice
None of this means avoid AI. The AMA data shows adoption because the wins are real: physicians report using it for documentation, chart and visit notes, discharge instructions, billing codes, and translation. Notice what these have in common — they're the document-heavy, re-keying-heavy back-office tasks that pile up when you can't hire fast enough in a tight local job market.
The safest starting points are the workflows where AI drafts and a human approves, and where you can keep PHI inside vetted, BAA-covered systems:
- Ambient documentation that drafts a visit note the clinician then edits and signs.
- Prior-authorization and intake support that pulls together the paperwork for a human to check.
- Reducing re-keying between your EHR and billing system, where staff currently retype the same data twice.
The common thread: AI handles the drudgery, a person owns the outcome. If you're weighing whether your practice is even ready for this, our no-hype overview of what AI can actually do sets realistic expectations.
Adoption is rising, but so is caution — and that's the right posture
The AMA's own numbers capture the tension honestly. Enthusiasm is growing: the share of physicians more excited than concerned rose to 35% in 2024. But concern hasn't vanished — 25% remained more concerned than excited, and roughly two in five felt equally both. The AMA has publicly called for governance and oversight of AI use rather than a free-for-all.
That balanced posture is exactly right for a regulated practice. AI is promising and requires guardrails. Both things are true.
A practical checklist you can run this week
- Inventory the shadow AI. Ask your staff, plainly and without blame, what AI tools they already use and for what. You can't govern what you can't see.
- Draw the PHI line. Any tool touching patient data needs a signed BAA. Everything else is off-limits for PHI.
- Verify agreements in writing. Request the BAA from each vendor and confirm the exact features it covers.
- Require a human review step for anything AI produces that touches a record, claim, or clinical decision.
- Get penalty specifics from the source. For current HIPAA civil-monetary-penalty tiers, use HHS.gov directly, not a vendor's blog.
For a broader look at keeping data safe inside AI tools generally, our practical guide to business data privacy covers the same instincts applied outside the exam room.
If you'd like a second set of eyes on where AI could safely save your practice hours — and where it absolutely shouldn't go — Albany AI Consulting offers a free, no-obligation AI assessment for Capital Region practices. We'll map the low-risk wins and flag the compliance boundaries before you spend a dollar.
Sources
- 2 in 3 physicians are using health AI—up 78% from 2023 — American Medical Association
- More than 80% of physicians use AI professionally — American Medical Association
- Cost of a data breach: The healthcare industry — IBM
- Average cost of healthcare data breach nearly $10M in 2024 — Healthcare Dive
- Sample Business Associate Agreement Provisions & HIPAA for Professionals — U.S. Department of Health and Human Services
Wondering what AI could do for your business?
Twenty minutes. One workflow. A straight answer.