HIPAA for AI and Health Apps: What Founders Must Know

HIPAA for AI and health apps founders guide
HIPAA for AI and Health Apps: What Founders Must Know | Osto

HIPAA for AI and health apps: building with health data and AI raises questions the rules never named directly. Here is how HIPAA actually applies to modern AI products.

Osto Security Team8 min readCompliance & Trust

TL;DR

If your AI product processes protected health information, HIPAA applies to it exactly as it would to any other system. The model, the API behind it, and any pipeline that sees PHI can each be a business associate needing a BAA.

The new risks are around training data, prompts, logs, and third-party model providers, all places PHI can leak. The controls are familiar: encryption, access control, logging, and a BAA with every party that touches the data.

When HIPAA applies to an AI or health app

The principle is simple and unchanged: HIPAA follows the data, not the technology. If your application creates, receives, stores, or transmits protected health information on behalf of a healthcare customer, it is covered, whether the processing happens in a traditional database or inside a large language model. AI does not create an exception. If PHI goes into your product, the rules come with it.

The test has not changed
Ask the same question you would for any system: does this handle health information tied to a person, for a healthcare customer? If yes, HIPAA applies, and the fact that an AI model is involved does not change the answer.

Follow the data through the AI

The clearest way to reason about HIPAA in an AI product is to trace where PHI actually goes.

Follow the data
PHI does not stop being PHI inside an AI
Wherever patient data flows in an AI pipeline, from prompt to model to stored output, HIPAA still applies and a BAA is needed with each party that handles it.
PHI input patient data AI model / API a business associate Output / store logs, results, cache User PHI must be protected, and a BAA in place, at every stage it is handled

PHI can enter through prompts or uploads, pass through a model or third-party API, and end up in outputs, logs, or caches. Each of those stages is a place the data must be protected, and each external party that handles it may need a business associate agreement. The AI pipeline does not shrink your HIPAA scope, it can widen it.

AI providers become business associates

This is the point founders most often miss. If you send PHI to a third-party AI model or API, that provider is handling protected health information on your behalf, which generally makes them a business associate. You need a BAA with them, and not every AI provider will sign one. Choosing model providers that offer a BAA, and configuring them not to retain or train on your data, is a core HIPAA decision for an AI health product.

Before you send PHI to any AI API
Confirm the provider will sign a BAA and that your data will not be retained or used for training. If they will not, sending PHI to them is a compliance problem, no matter how good the model is.

The training-data trap

Using real patient data to train or fine-tune models is one of the biggest risks in AI health products. PHI absorbed into a model can be difficult to remove and may resurface in outputs. If you train on health data, that data and the resulting model are in scope, and you must be able to control and account for it. Wherever possible, de-identification before training dramatically reduces this risk, because properly de-identified data is no longer PHI.

The controls that matter for AI health apps

Despite the novelty of AI, the safeguards are the familiar HIPAA ones, applied to new data paths.

ControlWhat it means for an AI product
EncryptionPHI protected in transit to models and at rest in logs and stores
Access controlStrict limits on who and what can reach PHI and model data
Audit loggingA record of how PHI moves through prompts, models, and outputs
BAAsSigned with every provider and subcontractor that handles PHI
De-identificationRemoving identifiers before training or analysis where possible

The lean-team path for AI health products

An AI health startup carries all the usual HIPAA obligations plus new data paths through models and providers. The safeguards, encryption, access control, and logging over everywhere PHI flows, are the same, but the surface is larger and moves faster. Assembling that across tools while shipping an AI product is exactly where gaps open.

Build with AI without losing control of PHI.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Protect and prove control over health data across your AI pipeline on one platform mapped to HIPAA. No security team required.

Book a Demo →

Frequently asked questions

Does HIPAA apply to AI health apps?

Yes, whenever the app processes protected health information for a healthcare customer. HIPAA follows the data, not the technology, so PHI handled inside an AI model or pipeline is covered exactly as it would be in any other system.

Is an AI provider a business associate under HIPAA?

Generally yes, if you send it PHI. A third-party model or API that processes protected health information on your behalf is handling PHI, which makes it a business associate requiring a BAA. Not all AI providers will sign one.

Can I train an AI model on patient data?

Only with great care. Real PHI used in training is in scope and can be hard to remove or may resurface in outputs. De-identifying data before training dramatically reduces risk, because properly de-identified data is no longer PHI.

What should I check before sending PHI to an AI API?

Confirm the provider will sign a BAA and that your data will not be retained or used to train their models. If they will not offer a BAA, sending PHI to them is a compliance problem regardless of the model’s quality.

What controls does an AI health app need for HIPAA?

The familiar HIPAA safeguards applied to new data paths: encryption of PHI in transit and at rest, strict access control, audit logging of how PHI moves through the AI, BAAs with every provider, and de-identification before training where possible.

Does de-identified data fall under HIPAA?

Properly de-identified data, meeting HIPAA’s de-identification standards, is no longer considered PHI and falls outside those requirements. This is why de-identification is a powerful risk-reducer for AI and analytics on health data.