HIPAA
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the United States federal law whose implementing regulations govern how health care providers, health plans, clearinghouses, and their contractors may use, disclose, and protect identifiable health information. Congress enacted it as Public Law 104-191 on August 21, 1996, to "improve portability and continuity of health insurance coverage in the group and individual markets" and to "simplify the administration of health insurance."[1][2] The privacy and security regime that now dominates the acronym comes from subtitle F of title II, the Administrative Simplification provisions, which added a new part C to title XI of the Social Security Act. Section 264 of the Act directed the Secretary of Health and Human Services (HHS) to send Congress recommendations on standards for the privacy of individually identifiable health information and, if Congress had not legislated within 36 months, to promulgate final regulations itself.[1][2]
For artificial intelligence in health care, HIPAA is the gate. It decides whether a model vendor may touch patient records at all, on what contractual terms, and what happens when the arrangement fails. HHS has taken the position that electronic protected health information does not stop being protected when it is fed into a model: in its January 2025 rulemaking the Department wrote that "ePHI, including ePHI in AI training data, prediction models, and algorithm data that is maintained by a regulated entity for covered functions is protected by the HIPAA Rules and all applicable standards and specifications."[2]
The law is also narrower than most people assume. It reaches only a defined set of entities and their subcontractors, it stops entirely at the boundary of de-identified data, and the technical de-identification method it sanctions was written against a threat model that predates modern machine learning.
Statutory origins and the four rules
HIPAA itself contains almost none of the privacy text that practitioners work with. The operative material sits in regulations at 45 CFR parts 160 and 164, issued and revised over roughly two decades.
| Rule | Codification | Origin |
|---|---|---|
| Privacy Rule | 45 CFR part 160 and subparts A and E of part 164 | Section 264 of HIPAA[2] |
| Security Rule | 45 CFR part 160 and subparts A and C of part 164 | Final rule published February 20, 2003 (68 FR 8334)[2] |
| Breach Notification Rule | 45 CFR part 164, subpart D | HITECH Act of 2009[2] |
| Enforcement Rule | 45 CFR part 160, subparts C through E | HIPAA and HITECH[2] |
The Security Rule went through a 1998 proposal (63 FR 43242) before the 2003 final rule, and was substantively revised only once afterwards.[2] The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted February 17, 2009 as part of the American Recovery and Reinvestment Act, extended the Security Rule's safeguard and documentation requirements directly to business associates and made them civilly and criminally liable for violations.[2] HHS implemented that through the 2013 Omnibus Rule, published January 25, 2013 and effective March 26, 2013.[13] A 2021 amendment to HITECH requires HHS to consider a regulated entity's adoption of recognized security practices when making certain enforcement determinations.[2] Under 45 CFR 160.105, regulated entities must comply with a new or modified standard no later than 180 days after its effective date.[2]
Covered entities, business associates, and PHI
A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a covered transaction.[3] A business associate is a person or company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, or that provides services to it, among them legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, and financial services, where providing the service involves disclosure of PHI.[3] Since 2013 the definition also reaches downstream: a subcontractor to whom a business associate delegates a function involving PHI is itself a business associate, so the obligations follow the data through the supply chain rather than stopping at the first vendor.[3][13]
Protected health information (PHI) is individually identifiable health information transmitted or maintained in any form. It excludes employment records held by a covered entity acting as an employer, education and certain treatment records covered by FERPA, and information about people who have been dead for more than 50 years.[3] Electronic PHI (ePHI) is the subset transmitted by or maintained in electronic media, and it is the only thing the Security Rule addresses.[3][6]
Two constraints shape every vendor integration. First, the minimum necessary standard: when using, disclosing, or requesting PHI, a covered entity or business associate "must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose," subject to exceptions for treatment disclosures, disclosures to the individual, and authorized uses.[4] Second, a covered entity may disclose PHI to a business associate only after obtaining satisfactory assurances, documented in a written contract, that the associate will safeguard it.[4]
That contract is the business associate agreement (BAA). Under 45 CFR 164.504(e) it must bind the associate to use PHI only as the contract or law permits, apply appropriate safeguards, report unauthorized uses and breaches, flow the same restrictions down to subcontractors, support individual rights of access, amendment, and accounting, make records available to the Secretary, and return or destroy PHI at termination.[5] A covered entity that knows of a pattern of material breach by its associate and fails to remedy or terminate is itself out of compliance.[5]
Security Rule mechanics
The Security Rule requires regulated entities to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit, to protect against reasonably anticipated threats and impermissible disclosures, and to ensure workforce compliance.[6] It is deliberately technology neutral: entities may adopt any measures that reasonably and appropriately implement the standards, weighing size, complexity, technical capability, cost, and the probability and criticality of risks.[6]
The rule's most consequential design choice is the split between required and addressable implementation specifications. Required specifications must be implemented. Addressable ones must be assessed, implemented if reasonable and appropriate, and otherwise documented with an equivalent alternative.[6] Encryption of ePHI is addressable rather than required, sitting under the access control standard at 45 CFR 164.312(a)(2)(iv), so an entity may decline to encrypt provided it documents why encryption is not reasonable and appropriate in its environment and implements an equivalent alternative measure.[2] The National Institute of Standards and Technology publishes an implementation guide, NIST SP 800-66r2, released in February 2024 to supersede the 2008 revision.[16]
Breach notification and enforcement
A breach is an acquisition, access, use, or disclosure of PHI not permitted by the Privacy Rule that compromises its security or privacy, with narrow exceptions for good-faith internal access and for disclosures the recipient could not reasonably have retained.[7] Any impermissible use or disclosure is presumed to be a breach unless the entity shows a low probability of compromise using four factors: the nature and extent of the identifiers involved, who the unauthorized person was, whether the information was actually acquired or viewed, and the extent of mitigation.[7] The presumption matters for AI deployments, because it puts the burden on the deploying organization rather than on regulators.
Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery.[8] Breaches affecting 500 or more individuals go to the Secretary at the same time as the individual notices; smaller breaches are logged and reported within 60 days after year end.[9] OCR states that it investigates every breach affecting 500 or more individuals.[15]
Civil money penalties at 45 CFR 160.404 run in four culpability tiers, with statutory amounts adjusted annually for inflation under 45 CFR part 102.[10] In an April 30, 2019 notification of enforcement discretion, HHS said it would apply a separate annual cap per tier rather than a single cap across all of them.[14]
| Tier | Minimum per violation | Maximum per violation | Annual limit applied since 2019 |
|---|---|---|---|
| Did not know | $100 | $50,000 | $25,000 |
| Reasonable cause | $1,000 | $50,000 | $100,000 |
| Willful neglect, corrected | $10,000 | $50,000 | $250,000 |
| Willful neglect, not corrected | $50,000 | $50,000 | $1,500,000 |
The scale of the problem the rules are meant to address grew sharply. HHS reported that between 2018 and 2023 the number of reported breaches of unsecured PHI rose 100 percent and the number of individuals affected rose 950 percent, with hacking up 260 percent and ransomware up 264 percent.[2] More than 160 million individuals were affected by large breaches in 2023 alone, a record at the time.[2] The 2024 compromise of the clearinghouse Change Healthcare was reported to HHS on July 19, 2024 with an initial estimate of 100 million individuals affected, and its parent company told Congress the figure might reach roughly one third of the United States population.[2]
De-identification and its limits
HIPAA stops where identifiability stops. Health information that does not identify an individual, and for which there is no reasonable basis to believe it can be used to identify one, is not individually identifiable health information at all.[11] A vendor that receives only de-identified data is therefore not handling PHI and does not need a BAA, which is why so much health AI training runs on de-identified corpora.
There are exactly two sanctioned routes. Expert determination requires a person with appropriate statistical and scientific knowledge to conclude, and document, that the risk is very small that the information could be used alone or in combination with other reasonably available information to identify someone.[11] Safe harbor requires stripping 18 categories of identifiers.[11]
| Category | Identifier |
|---|---|
| A | Names |
| B | Geographic subdivisions smaller than a state |
| C | Date elements other than the year, with special handling for ages above 89 |
| D | Telephone numbers |
| E | Fax numbers |
| F | Email addresses |
| G | Social Security numbers |
| H | Medical record numbers |
| I | Health plan beneficiary numbers |
| J | Account numbers |
| K | Certificate and license numbers |
| L | Vehicle identifiers |
| M | Device identifiers and serial numbers |
| N | Web URLs |
| O | IP addresses |
| P | Biometric identifiers |
| Q | Full-face photographs and comparable images |
| R | Any other unique identifying number, characteristic, or code |
Between full PHI and de-identified data sits the limited data set, which may retain town or city, state, and ZIP code along with dates, provided the recipient signs a data use agreement that limits the purpose to research, public health, or health care operations, requires safeguards and incident reporting, and forbids re-identification.[11] Research uses of full PHI without individual authorization require an IRB or privacy board waiver based on minimal privacy risk, with plans to protect and destroy identifiers.[12]
Machine learning has put pressure on all of this. A 2019 study in Nature Communications by Luc Rocher, Julien Hendrickx, and Yves-Alexandre de Montjoye estimated using a generative model that 99.98 percent of Americans would be correctly re-identified in any dataset from 15 demographic attributes, and that ZIP code, date of birth, gender, and number of children alone would identify 79.4 percent of the Massachusetts population with high confidence.[28] Medical images are worse. In 2022 Kai Packhäuser and colleagues trained a network on the ChestX-ray14 dataset (112,120 frontal chest radiographs from 30,805 patients) and matched pairs of images to the same patient with an AUC of 0.9940 and 95.55 percent accuracy, still succeeding 86 percent of the time across a twelve-year age gap.[29] The safe harbor list names full-face photographs and biometric identifiers but not diagnostic images, which fall, if anywhere, under the catch-all in category R.[11] Techniques such as differential privacy, federated learning, synthetic data generation, and homomorphic encryption are all responses to the same gap between the regulatory definition of identifiability and what a trained model can recover.
PHI in training data and model memorization
The other direction of leakage is memorization by the model itself. Nicholas Carlini and co-authors showed in 2020 that hundreds of verbatim sequences could be extracted from GPT-2, an early large language model, including names, phone numbers, and email addresses that appeared in only a single training document.[30] In 2023 Milad Nasr, Carlini, and colleagues published a divergence attack that pushed a production chatbot out of its assistant persona and made it emit training data at 150 times the normal rate, concluding that current alignment techniques do not eliminate memorization.[31] HHS cited this line of work directly in its 2025 rulemaking, warning that "generative AI tools have produced in their output the names and personal information of persons included in the tools' sources of training data" and that similar training on patient data by regulated entities "could result in impermissible uses and disclosures."[2]
The Department's practical instruction is that AI belongs inside the existing risk analysis. A regulated entity's risk analysis "must include consideration of, among other things, the type and amount of ePHI accessed by the AI tool, to whom the data is disclosed, and to whom the output is provided," and any AI software that creates, receives, maintains, or transmits ePHI, or that is trained on it, would have to appear in the written technology asset inventory the Department proposed to require.[2] HHS pointed regulated entities to the NIST AI Risk Management Framework as a supporting resource.[2] The same rulemaking noted the other side of the ledger: attackers use generative models for phishing and social engineering at scale, so defenders will likely have to invest in AI to counter AI.[2]
Business associate agreements with AI vendors
A cloud provider handling ePHI is a business associate. Microsoft states this about itself plainly: "When a covered entity engages the services of a cloud service provider, such as Microsoft, the cloud service provider is a business associate under HIPAA."[22] OCR's cloud guidance, quoted in the 2025 proposal, tells covered entities to understand the specific cloud environment well enough to run their own risk analysis and to enter into appropriate BAAs.[2]
The major AI platforms all offer BAAs, but through different mechanisms and with different carve-outs.
| Provider | How the BAA works | AI services in scope | Notable exclusions |
|---|---|---|---|
| Amazon Web Services | Customers must enter into an AWS BAA before using any HIPAA-eligible service with PHI[21] | Amazon Bedrock, Amazon SageMaker AI, Amazon Comprehend Medical, Amazon Transcribe including AWS HealthScribe, AWS HealthLake, AWS HealthImaging, Amazon Q Business[21] | Per-service and per-model exclusions are listed inline, for example specific Bedrock models and SageMaker Studio Lab[21] |
| Microsoft | BAA offered "through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates"[22] | Azure and Azure Government, Microsoft 365 Copilot and Copilot Chat, Microsoft Healthcare Bot Service[22] | Microsoft will not sign a customer's own BAA form[22] |
| Google Cloud | "Google will enter into Business Associate Agreements with customers as necessary under HIPAA"; the customer reviews and accepts the BAA through Google's privacy compliance process[23] | Cloud Healthcare API, Document AI, Gemini Enterprise, Gemini Code Assist, Gemini in BigQuery, Cloud Vision, Cloud Natural Language, AI Platform Training and Prediction[23] | Only listed products are covered[23] |
| OpenAI | Customers execute an "OpenAI Business Associate and Healthcare Addendum"; the organization is then provisioned for Eyes Off or Safety Retention so BAA-eligible endpoints can process PHI[24] | BAA-eligible API endpoints under zero data retention or equivalent controls[24] | "Web Search with live internet access is not HIPAA eligible and is not covered by a BAA"[24] |
| Anthropic | "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans"; an Enterprise Primary Owner accepts it in organization settings under Data and privacy[25][26] | First-party API and HIPAA-enabled Claude Enterprise organizations[25][26] | "Enabling HIPAA doesn't bring every feature under your BAA"; Claude Code is covered only with zero data retention enabled, and Cowork is not yet covered[26] |
The lists are not written at a uniform level of detail. Microsoft's names the platform, Azure, rather than individual services running on it such as Azure OpenAI Service, while AWS and Google Cloud enumerate individual products and, in the AWS case, individual models.[21][22][23]
Two points recur across all five. First, coverage is per service and often per feature, so a compliant deployment can be broken by turning on a single uncovered integration. Second, "HIPAA compliant" is a marketing phrase, not a status a regulator confers. Google Cloud says outright that "there is no certification recognized by the US HHS for HIPAA compliance and that complying with HIPAA is a shared responsibility between the customer and Google," and Microsoft makes the same disclaimer, adding that holding a BAA does not by itself make the customer compliant.[22][23]
Research data carries its own layer. PhysioNet, which distributes the widely used MIMIC clinical datasets, states that its Credentialed Data Use Agreement "explicitly prohibits sharing access to the data with third parties, including sending it through APIs provided by companies like OpenAI, or using it in online platforms like ChatGPT," and instead points researchers to arrangements where the model provider does not train on or routinely review the inputs.[27] Vendors selling ambient clinical documentation, such as Abridge and Ambience Healthcare, sit squarely inside this regime, since a recording of a patient encounter made by a provider is individually identifiable health information under the definitions.[3][32][33] HHS itself cited ambient AI scribes and model-generated summaries of electronic health records as examples of clinical AI already in production.[2]
The 2025 Security Rule proposal
On January 6, 2025, HHS published a notice of proposed rulemaking, "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information," at 90 FR 898 through 1022, with comments closing March 7, 2025.[2][17] It would be the first substantive rewrite of the Security Rule since 2013.
The central change would collapse 45 CFR 164.306(c) and (d) into a single paragraph and remove the distinction between addressable and required implementation specifications, so that regulated entities must comply with both the standards and the specifications. HHS wrote that OCR's enforcement experience led it to conclude that "addressable" is widely misunderstood to mean optional, and that the rule's flexibility lies "in allowing them to choose the manner in which they meet the standards and implementation specifications, not whether they meet them."[2] The proposal follows a 2022 National Committee on Vital and Health Statistics recommendation that the Department eliminate the choice not to implement a specification and instead require either the specification itself or a documented reasonable alternative.[2]
Other proposed requirements include encryption of ePHI with limited exceptions, a written technology asset inventory and a map of how ePHI moves through systems, multi-factor authentication across relevant systems and for privilege changes, automated vulnerability scanning at least once every six months, penetration testing by a qualified person at least once every 12 months, restoration of critical systems and data within 72 hours, and audits of Security Rule compliance at least once every 12 months.[2]
The provision with the largest effect on AI procurement is business associate verification. Under proposed 45 CFR 164.308(b)(2)(ii), a regulated entity would have to obtain written verification from each business associate at least once every 12 months that the associate has deployed the technical safeguards required by 164.312, supported by a written analysis of the associate's relevant electronic information systems performed by someone with appropriate cybersecurity knowledge, plus a written certification from a person authorized to act for the associate.[2] Applied to a model vendor, that converts a signature on a BAA into an annual technical attestation.
HHS estimated first-year compliance costs of roughly $4,655 million for regulated entities and $4,659 million for health plan sponsors, about $9.3 billion in total.[2] As of July 2026 the Federal Register listed no final rule under the proposal's regulatory identification number, 0945-AA22, so the existing 2013 text remains in force.[17] A separate Privacy Rule proposal on coordinated care, first published in January 2021, also remained pending; HHS held a Tribal consultation on it in January 2026.[18]
What HIPAA does not cover
HIPAA reaches covered entities and their business associates and nothing else.[3] A consumer wellness app, a wearable, a symptom-checker chatbot sold directly to the public, or a data broker buying prescription data is generally outside it, no matter how sensitive the data. The Federal Trade Commission fills part of that gap through the Health Breach Notification Rule, amended in a final rule published May 30, 2024 and effective July 29, 2024, which requires vendors of personal health records and related entities "that are not covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals, the FTC, and, in some cases, the media of a breach of unsecured personally identifiable health data."[19] Separately, HHS aligned the confidentiality rules for substance use disorder treatment records at 42 CFR part 2 more closely with HIPAA in a final rule published February 16, 2024, effective April 16, 2024.[20]
The other boundary is de-identification, and it is the one AI systems keep crossing. Once data clears safe harbor or expert determination it leaves the regulated world entirely, with no ongoing obligation, no breach reporting, and no contractual chain, even though the re-identification literature suggests the underlying assumption of anonymity is weaker than the rule assumes.[11][28][29]
See also
References
- ^Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, 110 Stat. 1936 (August 21, 1996). govinfo.gov/...PLAW-104publ191
- ^U.S. Department of Health and Human Services, "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information," proposed rule, 90 FR 898 (January 6, 2025). govinfo.gov/...2024-30983.pdf
- ^45 CFR 160.103, definitions (business associate, covered entity, protected health information, electronic protected health information, subcontractor). law.cornell.edu/...160.103
- ^45 CFR 164.502, uses and disclosures of protected health information: general rules. law.cornell.edu/...164.502
- ^45 CFR 164.504, uses and disclosures: organizational requirements (business associate contracts). law.cornell.edu/...164.504
- ^45 CFR 164.306, security standards: general rules. law.cornell.edu/...164.306
- ^45 CFR 164.402, definitions of breach and unsecured protected health information. law.cornell.edu/...164.402
- ^45 CFR 164.404, notification to individuals. law.cornell.edu/...164.404
- ^45 CFR 164.408, notification to the Secretary. law.cornell.edu/...164.408
- ^45 CFR 160.404, amount of a civil money penalty. law.cornell.edu/...160.404
- ^45 CFR 164.514, other requirements relating to uses and disclosures of protected health information (de-identification, limited data set). law.cornell.edu/...164.514
- ^45 CFR 164.512, uses and disclosures for which authorization or opportunity to agree or object is not required. law.cornell.edu/...164.512
- ^"Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules," final rule, published January 25, 2013, effective March 26, 2013. federalregister.gov/...otification-rules-under-the
- ^U.S. Department of Health and Human Services, "Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties," 84 FR 18151 (April 30, 2019). govinfo.gov/...2019-08530
- ^Office for Civil Rights, "Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information." ocrportal.hhs.gov/...breach_report.jsf
- ^Jeffrey A. Marron, "Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide," NIST SP 800-66r2, February 2024. nvlpubs.nist.gov/...NIST.SP.800-66r2.pdf
- ^Federal Register document listing for RIN 0945-AA22, "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information" (comments closed March 7, 2025). federalregister.gov/...rotected-health-information
- ^U.S. Department of Health and Human Services, "Tribal Consultation on Proposed Modifications to the HIPAA Privacy Rule," January 14, 2026. federalregister.gov/...s-to-the-hipaa-privacy-rule
- ^Federal Trade Commission, "Health Breach Notification Rule," final rule published May 30, 2024, effective July 29, 2024. federalregister.gov/...th-breach-notification-rule
- ^U.S. Department of Health and Human Services, "Confidentiality of Substance Use Disorder (SUD) Patient Records," final rule published February 16, 2024, effective April 16, 2024. federalregister.gov/...isorder-sud-patient-records
- ^Amazon Web Services, "HIPAA Eligible Services Reference." aws.amazon.com/...hipaa-eligible-services-reference
- ^Microsoft, "Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health (HITECH) Act," Microsoft Learn compliance offerings. learn.microsoft.com/...offering-hipaa-hitech
- ^Google Cloud, "HIPAA compliance on Google Cloud." cloud.google.com/...hipaa
- ^OpenAI, "Your data" (API data controls, zero data retention, Eyes Off, Business Associate and Healthcare Addendum). developers.openai.com/...your-data
- ^Anthropic, "Business Associate Agreements (BAA) for Commercial Customers." support.claude.com/...baa-for-commercial-customers
- ^Anthropic, "HIPAA-ready Enterprise plans." support.claude.com/...hipaa-ready-enterprise-plans
- ^PhysioNet, news post on responsible use of credentialed PhysioNet data with online AI services. physionet.org/...gpt-responsible-use
- ^Luc Rocher, Julien M. Hendrickx, and Yves-Alexandre de Montjoye, "Estimating the success of re-identifications in incomplete datasets using generative models," Nature Communications 10, 3069 (July 23, 2019). pmc.ncbi.nlm.nih.gov/...PMC6650473
- ^Kai Packhäuser, Sebastian Gündel, Nicolas Münster, Christopher Syben, Vincent Christlein, and Andreas Maier, "Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data," Scientific Reports 12, 14851 (2022). pmc.ncbi.nlm.nih.gov/...PMC9434540
- ^Nicholas Carlini et al., "Extracting Training Data from Large Language Models," arXiv:2012.07805 (December 14, 2020; revised June 15, 2021). arxiv.org/...2012.07805
- ^Milad Nasr et al., "Scalable Extraction of Training Data from (Production) Language Models," arXiv:2311.17035 (November 28, 2023). arxiv.org/...2311.17035
- ^Abridge, company site (AI-powered clinical documentation). abridge.com
- ^Ambience Healthcare, company site (real-time clinical documentation and coding). ambiencehealthcare.com
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
v1 · 4,235 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Reviewer note: Independent adversarial fact-check at creation (wanted175 campaign, 2026-07-24): every claim verified against primary sources by a dedicated verification agent; corrections applied before publication.
Cite this page: AI Wiki. "HIPAA." aiwiki.ai, updated 24 Jul 2026, fact-checked 24 Jul 2026. CC BY 4.0. https://aiwiki.ai/wiki/hipaa