Blog

HIPAA-Compliant AI Tools for Medical Practices: What's Safe (and What's Not)

Your staff just pasted patient information into ChatGPT. You don't know about it yet. But it happened.


Your staff just pasted patient information into ChatGPT.

You don't know about it yet. But it happened. Someone had a question about intake workflows, copy-pasted an example, and hit send.

That's a breach. It doesn't feel like one, but it is.

This is the gap between using AI in healthcare and using HIPAA-compliant AI in healthcare. And most practices don't know the difference until something goes wrong.

Why This Gap Exists

AI is incredibly useful in healthcare. It speeds up charting. It automates reminders. It handles intake. The problem: The tools that work best (ChatGPT, Claude, Gemini) aren't HIPAA compliant. Using them with patient data is a compliance violation.

But your staff doesn't know that. They see an AI tool that solves a problem, so they use it.

The compliance gap creates risk:

  • HIPAA violations: $100–$50,000+ in fines
  • Breach notification costs: $10,000–$100,000+
  • Reputation damage: Patients lose trust
  • Operational disruption: Handling a breach is chaos

Most practices think they're fine because their EHR is compliant. But the EHR isn't where the breach happens. It happens when someone uses a non-compliant AI tool because it's faster or easier.

What Actually Qualifies as HIPAA-Compliant

HIPAA compliance isn't a checkbox. It requires:

  • A Business Associate Agreement (BAA)
  • Encryption in transit and at rest
  • Access logging and audit trails
  • Contractual liability if there's a breach
  • Specific technical safeguards

Many AI vendors will say they're compliant. Few actually are. And fewer still are willing to sign a BAA.

The confusion is real. One vendor claims compliance. You ask for a BAA. They say "we're compliant but we don't do BAAs." That's not compliant.

The Problem Isn't the Tool, It's the Workflow

We've worked with practices that had the right tools but the wrong workflow.

Example: A mental health practice using a HIPAA-compliant charting AI (good). But then staff were copy-pasting summaries into Slack for quick consultation (bad). Slack isn't HIPAA-compliant. Breach.

Another example: A dental office using a HIPAA-compliant patient reminder system (good). But the admin was using ChatGPT to draft responses to patient reviews that included practice-specific details (bad). Breach risk.

The tools weren't the problem. The workflow was.

This is where it gets complex. You need:

  • The right tools (HIPAA-compliant vendors with BAAs)
  • The right workflow (staff trained on what can and can't go into which systems)
  • The right oversight (auditing which tools are being used for what)

Most practices try to do this themselves. Most get it wrong.

What We See Most Often

Practices think they're compliant because:

  • Their EHR is compliant ✓
  • They have a privacy policy ✓
  • They've trained staff "not to share data" ✓

But they're actually at risk because:

  • Staff are using non-compliant AI tools for convenience
  • There's no enforcement or monitoring
  • Nobody knows which tools handle what data
  • There's no audit trail of who used what, when

Eventually, someone finds out. Or a breach happens. Or an audit catches it.

The practices that get fined aren't always the ones who got hacked. They're the ones who knowingly used non-compliant tools or failed to oversee their staff's tool usage.


This is complex enough that most practices need outside perspective.

The right vendor decisions depend on your specific workflows. The right oversight depends on your team. And the cost of getting it wrong is too high to guess.

Let's talk about AI compliance for your practice →