Compliance
HIPAA Compliance for AI in Healthcare
By Relaya team · First published July 2026 · Last reviewed · 1 min read
The BAA Requirement
This is non-negotiable, regardless of how impressive the technology demo is.
This means they must sign a Business Associate Agreement (BAA) before any PHI is shared. If your AI receptionist handles patient names, appointment details, insurance information, or clinical notes, it's processing PHI. Ask for the BAA before the trial, not after deployment.
AI-Specific Considerations
Can model outputs inadvertently expose one patient's information to another? Where is inference processing happening, on-premises, US cloud, or overseas? Responsible AI vendors have clear answers to these questions documented in their security architecture. If a vendor can't articulate their PHI data flow clearly, that's a red flag.
Breach Preparedness
Preparedness isn't pessimism, it's professional risk management.