Table of Contents
The New Frontier of Digital Care
Artificial intelligence is officially everywhere, including the health and wellness space. AI note-takers, clinical scribes, scheduling chatbots, and treatment plan generators are just a few of the AI-powered tools that promise to save clinicians like you hours of administrative time and energy every single week.
But as a practitioner who prioritizes patient privacy above all else, this new technology—like just about every digital advancement before it (hello, cloud storage panic of the 2010s)—brings up a massive, completely valid fear: Is using these tools actually safe and legal?
When you are dealing with Protected Health Information (PHI), you cannot afford to “move fast and break things”—the infamous Silicon Valley startup mantra. Exploring and fully understanding the intersection of HIPAA and AI is vitally important, as keeping PHI secure and adhering to strict legal requirements are essential to protecting your license and your patients.
And guess what? If you’re worried about the privacy risks, your patients are, too.
I was recently at an appointment with my primary care physician, and the staff asked if I was comfortable with the doctor using an AI-based program to take notes during our visit. Being the tech-savvy, overly cautious data nerd that I am, I asked, “What is the name of the tool, and can you tell me about its data privacy policy?”
They couldn’t answer my question. They said they didn’t know. So, I declined.
Would having that note-taker have made the appointment go more smoothly? Probably. The doctor could have focused entirely on our conversation instead of splitting her attention between me and her laptop. Would it have saved her time afterward? Most likely. But was it worth the risk without me knowing exactly where my data was going? Absolutely not.
At WP Wellness, we never want you to be the provider (or the patient) in that uncomfortable situation. We’re here to help you safely integrate AI into your workflow in a way that is compliant, actively protective of patient trust, and explainable. In this article, we’re breaking down exactly what AI HIPAA compliance entails, the specific questions you need to ask to verify your vendors, and the transparency policies you should have in place so your patients understand exactly what is happening with their data.
What is HIPAA Compliance in Healthcare AI, and What Does It Entail?
To understand how to protect your practice, we first need to clear up the biggest misconception in the industry: The Department of Health and Human Services (HHS) does not pre-clear, certify, or endorse any AI product as “HIPAA compliant.” When you see a shiny “HIPAA Compliant” badge on a software vendor’s website, it’s just a marketing claim. It is a self-assessment—one that can absolutely be accurate—but it’s not a legal certification. For an AI tool to be genuinely compliant in a clinical setting, it must actively maintain strict administrative, physical, and technical safeguards—and you should always double-check them, even with a shiny badge.
At its core, AI HIPAA compliance requires:
- Zero-Training Policies: The vendor cannot legally use your patients’ PHI to train its public AI models.
- Data Encryption: All patient data must be encrypted both in transit (when being sent to the AI) and at rest (when saved on a server).
- Access Controls and Audit Logs: The software must track exactly who accessed what information, and when.
- A Signed Business Associate Agreement (BAA): This is the ultimate legal shield, and we will dive into why it is non-negotiable below.
Make AI work for you. Partner with WP Wellness to safely integrate modern tools into your practice. We’ll handle the background tech strategy to free up your time, so you can focus entirely on what you do best: delivering exceptional care.
How Can I Verify HIPAA Compliance for AI Vendors?
Because you cannot rely on marketing badges, the burden of verifying a vendor falls on you (the “Covered Entity” in legal-speak). Before you let any AI tool touch a patient’s data, you must run it through this vetting process.
1. Demand a Signed BAA
If a vendor handles PHI, they are legally considered a Business Associate. Therefore, a Business Associate Agreement (BAA) is non-negotiable. This legally binding contract states that the vendor accepts liability for safeguarding your data.
Your Action Step: Ask the vendor directly: “Will you sign a BAA?” If they hesitate, say it isn’t necessary, or only offer it on specific enterprise tiers you aren’t paying for, end the conversation immediately. Full stop.
2. Verify Data Retention, Model Training, and Encryption
The biggest risk with AI is “data leakage”—the fear that a patient’s medical history might accidentally be leaked or regurgitated by a chatbot to a stranger across the globe. As with any digital tool dealing with PHI, data must be fully encrypted at all times.
Your Action Step: When evaluating an AI tool, look past the marketing and verify these three non-negotiables directly with the vendor:
- No Model Training: They must explicitly state that your data will never be used to fine-tune or train their global base models.
- Zero Data Retention: They must immediately purge or completely redact your PHI the second your prompt is processed.
- End-to-End Encryption: Your data must be fully encrypted both in transit and at rest inside an isolated, highly secure environment.
If they can’t give you a definitive and affirmative answer to any of these three, walk away.
3. Look for Third-Party Security Audits
Self-attestation is not enough. You want to see that an independent cybersecurity firm has verified the vendor’s safeguards.
Your Action Step: Ask the vendor if they hold certifications such as SOC 2 Type II or HITRUST. While these do not directly equate to HIPAA compliance, they demonstrate that the company has maintained rigorous security controls.
4. Understand “Consumer vs. Enterprise” Tools
Many major AI vendors offer both consumer tools (which are not compliant) and enterprise tools (which are). For example, typing clinical notes into the free version of ChatGPT or the standard, public version of Google Gemini on your personal phone is a massive HIPAA violation. However, purchasing a highly secure, enterprise-level healthcare AI environment—like an eligible Google Workspace business plan with Gemini, where a BAA is executed—can be perfectly safe.
Your Action Step: Ensure you and your staff understand exactly which specific tools, accounts, and devices are approved for use. An AI tool is only compliant if you are logged into the secure, BAA-covered environment. (Bonus: If you are ready to make the switch to a secure, enterprise-level environment but aren’t sure how to do it without losing your data, check out our step-by-step guide on How to Safely Migrate Your Practice Email to Google Workspace!)
Go a Step Further for Your Patients: Implement an AI Policy and Patient Opt-Out
Even if an AI tool is 100% HIPAA compliant, you shouldn’t simply turn it on and hope your patients don’t mind or don’t notice. While HIPAA regulates how data is handled, state wiretapping laws govern how live conversations are recorded—and many states strictly require two-party consent before audio recording can begin.
As a clinical best practice, you should implement a transparent AI Policy alongside the standard Notice of Privacy Practices (NPP) your patients already receive.
Transparency builds trust. Your policy should clearly explain:
- The name and purpose of the specific AI tools you utilize in your practice.
- How you and your vendor protect their PHI—specifically highlighting that patient data is fully encrypted both “in transit” and “at rest.”
- Explicit confirmation that their audio recordings and clinical data are kept completely private, walled off from the public internet, and are never used to train public AI models.
- A clear, stigma-free option to opt out of AI usage at any time.
If a patient is uncomfortable with an AI scribe, you and your staff must be prepared to pivot back to manual note-taking without making them feel awkward or compromising the quality of their care.
What Are Some AI Agent Platforms with HIPAA BAA Compliance?
The market is rapidly evolving, but several platforms have emerged that prioritize clinical privacy and explicitly offer BAAs for healthcare professionals. While you must still go through the verification steps we listed above, these are strong starting points depending on your specialty and practice size:
- Upheal & Mentalyc: Highly popular, purpose-built AI note-takers for mental health therapists. Both offer a BAA, strict HIPAA compliance, and automatic structuring of transcripts in behavioral health formats such as SOAP and DAP.
- Freed & Heidi Health: Powerful, lightweight ambient AI scribes built for general medical practitioners and outpatient clinics. Both are simple to deploy, generate structured clinical notes, and securely purge the audio immediately after the visit.
- DeepScribe & Abridge: For large health systems or complex specialties (such as cardiology or oncology), these enterprise-grade tools integrate deeply with major EHRs like Epic and offer specialty-tuned AI models that handle complex medical terminology.
- KenzNote: A privacy-first, upload-only tool. Because there is no bot joining your live telehealth sessions, you have complete control over exactly which sessions are processed.
- BastionGPT: For those looking for a general conversational assistant (like ChatGPT) rather than just a note-taker, BastionGPT is a private, healthcare-grade alternative that signs a BAA for every plan and explicitly prevents your data from being used to train public models.
If you’re looking for front-of-house AI solutions—like website chatbots to handle patient scheduling, triage, and automated reminders—check out our breakdown of the Top AI Chatbots and Agents for Health and Wellness Practices to see how to automate your front desk safely.
Your Partner in Secure, Modern Practice Growth
It is exciting to see technology finally catching up to the administrative needs of health and wellness professionals. When used ethically and safely, AI can free you from your laptop and help you stay more present with your patients. Tasks like taking notes, organizing files, and surfacing important clinical insights are all things AI excels at, and automating them can save you a great deal of time and energy.
But patient safety and data security must always remain your top priority. If you need help vetting vendors, verifying compliance, or selecting the right tools for your specific workflow, you don’t have to navigate it alone.
That’s where a digital partner like WP Wellness comes in. We serve as a true extension of your practice, sharing the same clinical goals and empowering your growth through thoughtful strategy and secure technology—leaving you free to focus on the deep work that matters most.
Ready to build a secure, thriving digital presence?
Let’s end the tech overwhelm and compliance anxiety once and for all. Schedule a free 30-minute consultation to discover how a partnership with WP Wellness can modernize your practice and finally give you your time back.
Can I use regular ChatGPT to write my clinical notes?
No. Using the free or standard consumer version of ChatGPT, Claude, or any other publicly available Large Language Model (LLM) to process Protected Health Information (PHI) constitutes a direct HIPAA violation. OpenAI and most other major AI vendors will only sign a Business Associate Agreement (BAA) and provide the necessary encryption safeguards on their specialized Enterprise or Healthcare business plans.
What about Gemini?
As with ChatGPT, using the free consumer version of Google Gemini to process PHI is a direct HIPAA violation. However, if you use Gemini for Google Workspace on an eligible business plan, Google will sign a Business Associate Agreement (BAA). As long as the BAA is executed and your Workspace is properly configured, Gemini can be used safely and legally in your practice.
What happens if an AI vendor refuses to sign a BAA?
If a vendor refuses to sign a BAA, you cannot legally use their software to process, store, or transmit any PHI. A BAA is a federally mandated legal contract that holds the vendor liable for safeguarding your patients’ data. Using an AI tool without one is a big NO.
Does a “HIPAA Compliant” badge on a website mean the tool is safe?
Not necessarily. The U.S. government does not officially certify or provide badges for HIPAA compliance; these logos are simply vendor marketing claims. To ensure a tool is genuinely safe, you must independently verify its encryption standards, third-party security audits, and willingness to sign a BAA.