Solution

HIPAA compliance for ai companies

Training data, inference logs, and model outputs are all places ePHI ends up when nobody drew the boundary.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Training data, inference logs, and model outputs are all places ePHI ends up when nobody drew the boundary.

What you get

  • Data flow mapping for training, fine-tuning, and inference paths
  • De-identification and Safe Harbor / Expert Determination documentation
  • Model provider and GPU subprocessor BAA chain
  • Prompt and output logging retention controls

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

Can we train models on our customers' PHI?

Only if the BAA explicitly permits it, and most do not — training is rarely a service performed for the covered entity. The safe paths are de-identifying to the §164.514 standard first, or negotiating the use expressly. Assuming silence means yes is how AI companies end up in breach of their own BAAs.

Do foundation model providers sign BAAs for their APIs?

Several do, but only on specific tiers or endpoints, usually with zero-retention configurations required. The BAA covers their layer, not your prompt construction or output handling. We track which of your model providers are under BAA and whether the endpoints you actually call are the covered ones.

Are prompts and model outputs ePHI?

If they contain identifiable health information, yes — both directions. That pulls your inference logs, eval datasets, and human-review queues into scope, which is exactly where retention is usually unlimited and access is usually broad. Scoped retention and access controls on those stores are non-negotiable.

If we de-identify the data, are we out of HIPAA scope?

Properly de-identified data is not PHI, so yes — but 'properly' is the load-bearing word. Rich clinical records rarely pass Safe Harbor cleanly, and re-identification risk grows with dataset richness. Expert Determination is often the honest route, and you need the determination documented, not just asserted.

What do health system buyers actually ask AI vendors?

Whether their data trains your models, your full subprocessor and GPU provider chain, how outputs are reviewed, and where inference logs live and for how long. A current risk analysis and a mapped data flow answer most of it — the trust centre lets you answer once instead of per-deal.

Is our AI company a business associate at all?

If you create, receive, maintain, or transmit PHI on behalf of a covered entity — yes, with full Security Rule obligations. Direct-to-consumer wellness products may fall outside HIPAA, but the FTC's Health Breach Notification Rule and state privacy laws fill that gap, so 'not a BA' is not the same as 'unregulated'.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo