Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Artificial Intelligence in Healthcare

Health and Human Services Office for Civil Rights (OCR) addressed the use of artificial intelligence (AI) in healthcare environments while maintaining HIPAA compliance.

HIPAA rules apply to AI technology that processes Protected Health Information (PHI):

  • Encryption: PHI must be encrypted. Verify the AI tools encrypt data in transit and data at rest.
  • Logging out: Technology that stores PHI must automatically log out after a certain amount of time.
  • Unique logins: Anyone with access to PHI must have a unique login that can be audited.
  • Security measures: AI technologies must use sophisticated, robust security measures, such as secure data handling protocols.
  • AI Vendors: Vendors must meet HIPAA compliance standards and a Business Associate Agreement (BAA) needs to be signed by the Covered Entity and the AI vendor.
  • Data sharing and consent: Patient consent needs to be in place and confirmed prior to implementing AI. Ensure the use of AI language aligns with data sharing.

AI systems in healthcare process sensitive data like diagnoses, reports, clinical images, and genetic information. The misuse or leakage of this data could have serious consequences for patients’ privacy and ultimately a HIPAA breach for the organization.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP