Compliance

HIPAA Compliance for AI in Healthcare

By Relaya team · First published July 2026 · Last reviewed · 1 min read

The BAA Requirement

This is non-negotiable, regardless of how impressive the technology demo is.

This means they must sign a Business Associate Agreement (BAA) before any PHI is shared. If your AI receptionist handles patient names, appointment details, insurance information, or clinical notes, it's processing PHI. Ask for the BAA before the trial, not after deployment.

AI-Specific Considerations

Can model outputs inadvertently expose one patient's information to another? Where is inference processing happening, on-premises, US cloud, or overseas? Responsible AI vendors have clear answers to these questions documented in their security architecture. If a vendor can't articulate their PHI data flow clearly, that's a red flag.

Breach Preparedness

Preparedness isn't pessimism, it's professional risk management.