HIPAA

Why AI startups need HIPAA — usually sooner than they think

You don't have to build for hospitals to end up processing health information. How PHI finds its way into AI products, when it makes you a business associate, and what to do about it before a deal depends on the answer.

By ClearCompliance teamPublished 2026-09-10Last reviewed 2026-09-10For: Founders and engineering leaders at AI startups

The pattern: PHI arrives before the compliance program does

Most AI startups don't plan to handle protected health information. Then a customer uploads documents, connects a data source, or pastes something into a prompt — and health information is suddenly flowing through the product, the model provider, the logs, and the vector store. The compliance question arrives with the data, whether or not anyone scheduled it.

For AI companies, this happens faster than in traditional software because the product's whole value is ingesting the customer's messiest, richest data. Rich data is exactly where health information lives.

When an AI startup becomes a business associate

HIPAA applies to you directly when you create, receive, maintain, or transmit PHI on behalf of a covered entity (a provider, plan, or clearinghouse) or on behalf of another business associate. That makes you a business associate with your own legal obligations under the Security Rule — not just contractual ones — and the customer will require a signed business associate agreement before real data moves.

Common AI-startup triggers:

  • A health system pilots your copilot, summarizer, or agent on real clinical or operational data.
  • A digital-health company (itself a business associate) wires your API into its stack — you become a subcontractor business associate.
  • Your scribe, voice, or document product processes recordings or files that contain patient information.

The gray zone: AI products that meet health data outside HIPAA

Plenty of AI products encounter health information without their company clearly being a business associate — and this gray zone is where founders most often get the analysis wrong in both directions. A good example is legal AI: AI associates that read entire case files for law firms routinely process medical records, because injury and employment case files are full of them. A law firm generally isn't a covered entity, so HIPAA may not formally attach — yet the data is exactly as sensitive as anything in a hospital, the firm's clients expect HIPAA-grade handling, and the moment the same product serves a covered entity the legal status flips.

Two lessons from the gray zone. First, entity status is a legal question with real edge cases — when it's genuinely unclear whose behalf you're processing data on, get qualified counsel rather than guessing. Second, buyers rarely care about the formalities: if your product touches health information, security reviews will hold you to HIPAA-grade controls either way.

Where PHI hides in an AI pipeline

The Security Rule requires you to know where ePHI lives. In an AI product, the honest inventory is longer than the architecture diagram:

  • Prompts, outputs, and conversation history
  • Fine-tuning and evaluation datasets
  • Embeddings and vector stores
  • Model-provider retention (including abuse-monitoring buffers)
  • Application logs, traces, and error trackers
  • Labeling tools and human-review queues

Each of these needs an answer for encryption, access, retention, and deletion — and every third party in the chain that touches PHI needs a BAA. "Our model provider is HIPAA-eligible" only counts when the BAA is executed and the eligible configuration is actually enabled.

A word on de-identification

"We de-identify it first" is only a defense when it meets the Safe Harbor or Expert Determination standard — and re-identification risk grows as datasets combine, which is precisely what AI pipelines do. If your architecture leans on that claim, document its basis carefully and involve an expert where the call is close.

What to actually do, in order

  1. Map your data flows and settle entity status — with counsel if it's a close call.
  2. Run a real HIPAA security risk analysis over the full AI pipeline, not just production.
  3. Close the highest-risk gaps: MFA, encryption, access reviews, logging, retention.
  4. Get BAAs signed both directions — with customers and with every subprocessor that touches PHI.
  5. Write down policies, train the team, and keep evidence — buyers will ask for proof, not intentions.

The right time to start is about a quarter before your first healthcare customer asks — because by the time the BAA lands in your inbox, the deal is already waiting on you.

Sources

HIPAA does not provide or recognize an official private certification. ClearCompliance provides readiness, implementation, and assessment services; clients remain responsible for their legal obligations. SOC 2 reports are issued by independent qualified CPA firms. ClearCompliance is not a law firm and does not provide legal advice. This article is educational and is not legal advice.

Apply this to your company.

Contact us and leave with a recommended scope, realistic timeline, and budget range.