Before signing with a healthcare AI vendor, confirm they’ll sign a Business Associate Agreement; ask exactly what happens to patient data after the contract ends, whether it’s used to train models, which subcontractors or underlying AI models touch it, and what security certifications back those claims. “HIPAA compliant” is a marketing phrase; a signed BAA and specific written answers protect your organization.
Every healthcare AI vendor will tell you they’re “HIPAA compliant.” It’s on the homepage, in the sales deck, in the first reply to your RFP. The problem is that HIPAA doesn’t hand out compliance certificates; it’s a framework of obligations, not a badge a vendor either has or doesn’t. The organizations that get burned aren’t the ones who skipped vetting entirely; they’re the ones who accepted the claim at face value instead of asking what’s actually in the contract.
The questions below separate a vendor with real safeguards from one that’s simply good at the word “compliant.”
Key Takeaways
- “HIPAA compliant” is not a certification; a signed Business Associate Agreement (BAA) is the actual legal protection to look for.
- Ask explicitly whether your data can be used to train the vendor’s models; many platforms allow this by default unless the contract says otherwise.
- Data doesn’t have to disappear when a contract ends unless you’ve confirmed the deletion terms in writing.
- If the vendor’s AI runs on another company’s model, that subcontractor needs its own BAA covering the same protections.
- SOC 2 and similar certifications are useful evidence of security practices, but they don’t substitute for HIPAA compliance or a BAA.
Why “HIPAA Compliant” Isn’t the Right First Question
Every healthcare organization evaluating an AI platform starts with the same question: Is it HIPAA compliant? It’s the natural question, but it’s also incomplete: HIPAA compliance is a framework of administrative, physical, and technical safeguards that both the covered entity and the vendor must implement and maintain, not a single certification a vendor either holds or doesn’t.
There’s also a delegation problem worth naming directly: regulators have made clear that a covered entity can’t hand off its HIPAA obligations to an AI vendor just by using the tool. Using AI doesn’t relieve your organization of responsibility for protecting patient data, which is exactly why the vetting questions below matter more than the vendor’s marketing language.
First: Confirm the Vendor Is Actually a Business Associate
Before getting into specific safeguards, confirm whether the vendor is even in scope for HIPAA. HHS frames this as three questions:
- Does the vendor provide services or perform functions for a healthcare provider, health plan, or clearinghouse?
- Are those services integral to your organization’s operations?
- Is there a contractual relationship for those services?
If the answer to all three is yes, the vendor is a business associate under HIPAA and must sign a BAA before handling PHI; this now explicitly includes AI tools. HHS’s own guidance names a third-party AI chatbot handling symptom assessment or scheduling through PHI as a textbook business associate example, so this isn’t a gray area for most clinical or administrative AI tools.
The Core Questions to Ask Every Healthcare AI Vendor
1. Will you sign a Business Associate Agreement covering this specific product?
Get this in writing before any PHI changes hands, and make sure the BAA covers the actual data flows your use case involves. A generic BAA template that predates the AI feature you’re buying may not cover it. A vendor that hesitates or offers only a general compliance statement instead of a BAA is a clear warning sign.
2. Will our data be used to train or improve your models?
Ask this explicitly and get the answer in writing inside the contract, not a sales call. Default policies at many AI platforms permit training on customer inputs unless an enterprise agreement specifically prohibits it; silence on this point usually means the vendor’s default applies, and that default may not be in your favor.
3. What happens to our data when the contract ends?
HIPAA requires a business associate to return or destroy PHI at the end of a relationship, with narrow exceptions for genuine infeasibility. Vendors sometimes stretch that exception to justify holding onto data as a training asset; ask for the specific deletion timeline and process, not a reference to “applicable regulations.”
4. Does your AI rely on another company’s model or API?
Many healthcare AI products are built on top of third-party foundation models. If so, that underlying provider is a subcontractor and needs its own BAA with your vendor, covering the same PHI protections your vendor promised you. Ask the vendor to name the specific models or APIs involved and confirm the subcontractor chain is fully covered; a BAA with your vendor alone doesn’t protect you if their AI provider isn’t equally bound.
5. What technical safeguards protect data in transit and at rest?
Look for specifics: encryption standards for stored and transmitted data, role-based access controls, multi-factor authentication, and audit logging of who accessed what PHI and when. Push back on vague assurances (“we take security seriously”) without technical detail.
6. What independent certifications or audits back this up?
SOC 2 Type II reports and similar third-party attestations aren’t a HIPAA requirement, but they’re useful, verifiable evidence that a vendor’s security controls have actually been tested rather than self-described. Ask what’s been independently audited and ask to see the report or a summary. A vendor willing to undergo outside testing and share the results is a good sign.
7. Does the tool apply minimum-necessary and de-identification controls?
HIPAA’s minimum-necessary standard means PHI should only be used or disclosed to the extent needed for the task. Ask whether the vendor’s system filters or de-identifies data before it reaches the AI model, or whether staff could inadvertently submit more detail than a task requires. This is one of the more common gaps in real-world AI deployments.
8. How does the vendor handle breach notification?
Confirm the specific notification timeline the vendor commits to if PHI is compromised on their end, and how that maps to your own breach notification obligations under HIPAA. This should be a defined contractual term, not a general promise to “notify promptly.”
Reassuring Answer vs. Red Flag Answer
| Question | Red Flag Answer | Reassuring Answer |
| “Will you sign a BAA?” | “We’re fully HIPAA compliant, so it’s not necessary” | “Yes — here’s our standard BAA covering this product” |
| “Do you train on our data?” | No clear answer, or buried in a general privacy policy | Written, explicit prohibition unless you opt in |
| “What happens at contract end?” | “We retain data per our standard retention policy” | Specific deletion timeline and process, in writing |
| “Do you use third-party AI models?” | Declines to name the underlying provider | Names the model/API and confirms its own BAA with them |
| “What’s your security evidence?” | “We take security seriously” | Named certifications, offers to share audit reports |
How Deep Data Insight Approaches Healthcare Data
This vetting process is one Deep Data Insight goes through from the other side of the table regularly, building AI and data science solutions for healthcare organizations handling sensitive claims and patient data, including the DDI Grouper and Risk technology for healthcare insurance claims analysis and work reflected in the RDDT medical AI case study.
Our position is that healthcare clients shouldn’t have to take a vendor’s word for how their data is handled; they should be able to request independent testing and validation of the systems and controls involved and get a straight answer.
- Custom AI and data science solutions built around each client’s specific data-handling requirements, not a one-size-fits-all product
- A discovery-first process that surfaces data privacy and compliance requirements before architecture decisions are locked in
- Willingness to support independent testing and validation of the systems and controls handling client data
Read more about our approach on the Artificial Intelligence services page, or see how these same data-handling questions show up in connected healthcare devices and IoT.
The Bottom Line
A vendor’s homepage will always say “HIPAA compliant.” What actually protects your organization is a signed BAA that covers your specific use case, a written answer on model training and data retention, a confirmed subcontractor chain if third-party models are involved, and independently verifiable security evidence. Ask for all four before you sign, not after.
FAQs
Is every healthcare AI vendor automatically a HIPAA business associate?
Not automatically; it depends on what the vendor does. A vendor is a business associate if it generates, receives, keeps, or sends protected health information on a covered entity’s behalf to perform a function for that entity. An AI chatbot that handles symptom assessment or scheduling using patient data is a business associate; a vendor with no access to PHI is not.
What’s the difference between a vendor being “HIPAA compliant” and having a signed BAA?
HIPAA does not certify companies or products as compliant; there’s no seal to check for. A signed Business Associate Agreement is the actual legal instrument that obligates a vendor to protect PHI and defines what happens to it. “HIPAA compliant” without a BAA in hand is a marketing claim, not a guarantee.
Can an AI vendor use our patient data to train its models?
Only if your contract explicitly prohibits it and the vendor honors that. Many AI platforms retain inputs and outputs for model training by default unless a specific enterprise agreement says otherwise. Hence, this needs to be a written, unambiguous term, not an assumption.
What happens to our data when the contract with an AI vendor ends?
Under HIPAA, a business associate must return or destroy PHI when a contract ends, with a narrow exception if doing so is genuinely infeasible. Ask vendors to spell out their deletion timeline and process in writing rather than relying on a general compliance statement.
Does SOC 2 certification mean a vendor is HIPAA compliant?
No. SOC 2 and HIPAA are separate frameworks that overlap; a SOC 2 report can be useful evidence of security controls. Still, it doesn’t substitute for a BAA or confirm HIPAA compliance on its own.
What if the AI vendor uses another company’s AI model behind the scenes?
Then there’s a subcontractor chain to verify: your vendor needs its own BAA with that underlying AI provider, covering the same PHI protections your vendor promised you. Ask vendors to name which third-party models or APIs they rely on and confirm that chain in writing.
How much should we worry about shadow AI in our organization?
It’s worth treating as a real risk. Staff sometimes use AI tools outside procurement’s visibility, which routes around any BAA an organization has negotiated. Vetting questions matter less if PHI is also flowing through unapproved tools nobody has reviewed.
