Skip to main content

HIPAA Compliance for AI Assistants: A CISO Checklist

AI assistants are becoming clinical productivity tools. Physicians use them to draft patient notes. Nurses summarize shift handoffs. Revenue cycle teams query billing codes. Administrative staff generate prior authorization letters. The efficiency gains are real — and so are the PHI exposure risks that most of these tools were never designed to address.

For healthcare CISOs, the question is not whether clinicians and staff will use AI assistants. They already are. The question is whether your organization has the governance infrastructure to allow AI adoption without creating HIPAA liability.

What Counts as PHI in AI Conversations

HIPAA defines 18 categories of protected health information, and AI conversations routinely contain several of them in a single prompt. A physician typing “summarize treatment options for my 67-year-old patient with Stage III NSCLC diagnosed in January” has transmitted age, diagnosis, diagnosis timing, and — depending on the context — enough information to identify an individual when combined with other available data.

The PHI categories most commonly appearing in AI prompts include patient names, dates of birth, medical record numbers, diagnosis codes (ICD-10), procedure codes, lab values with patient context, prescription details, insurance identifiers, and clinical notes. Clinicians do not think of these as “data elements subject to HIPAA” — they think of them as the information needed to get a useful answer from the AI model.

The HIPAA minimum necessary standard requires that only the minimum PHI needed for a specific purpose should be disclosed. Most AI conversations violate this standard by default, because users provide more context than necessary to get accurate responses.

HIPAA Requirements for AI Tools

Any AI tool that processes PHI is a business associate under HIPAA. This triggers specific requirements that most consumer AI services do not meet.

Business Associate Agreement. The AI provider must execute a BAA covering the specific services used, including data handling, breach notification obligations, and permitted uses. A BAA is not optional and cannot be replaced by terms of service or privacy policies. Without a signed BAA, any PHI transmitted to the AI service is an unauthorized disclosure.

Access controls. HIPAA requires role-based access with unique user identification. AI tools must integrate with your identity infrastructure — SAML, SCIM provisioning, multi-factor authentication — so that every interaction is attributable to an identified, authorized user.

Audit trail. Every interaction involving PHI must generate an auditable record: who accessed what, when, what was transmitted, and what controls were applied. The audit trail must be tamper-resistant and available for compliance examinations. “We log API calls” is not sufficient — the log must capture the content governance decisions, not just the connection metadata.

Data retention and disposal. PHI transmitted to an AI model must be subject to retention policies consistent with your organization’s HIPAA data management plan. If the AI provider uses interaction data for model training, that constitutes a secondary use that must be disclosed in the BAA and evaluated against the minimum necessary standard.

The Gap in Consumer AI Tools

Consumer AI services — including the general-purpose tiers of major providers — present specific gaps for HIPAA-regulated organizations.

No PHI detection. The tool does not inspect incoming prompts for protected health information. It processes whatever the user submits, including PHI that the user may not recognize as regulated data.

No audit trail. Conversation history is not an audit trail. HIPAA-compliant audit requires tamper-resistant logging with integrity verification, user attribution through enterprise identity systems, and content-level governance records. Chat history stored in a user’s browser does not meet this standard.

Training data risk. Many consumer AI services use interaction data to improve their models unless users explicitly opt out — and opt-out mechanisms may not meet HIPAA’s requirements for data disposition. PHI submitted to a model that trains on user data has been disclosed to every future user of that model.

No enforcement actions. When a user submits PHI, nothing stops the request. There is no BLOCK, no REDACT, no policy evaluation. The data reaches the model, the model responds, and the interaction is governed by the provider’s general terms of service rather than a BAA-defined data handling framework.

How Arbitex Addresses This

Arbitex Gateway sits between your users and the AI models, inspecting every prompt and response through a 3-tier DLP pipeline built for real-time conversational data.

PHI detection in real time. 80+ pattern matchers handle structured identifiers — medical record numbers, NPI numbers, DEA numbers, ICD-10 codes, insurance plan IDs. 40 NER recognizers detect PHI entities in natural language — patient names in clinical context, dates associated with medical events, facility references that could identify care locations. Contextual validation confirms whether detected entities are genuinely PHI or clinical terminology used in a non-patient context.

Policy enforcement per data category. HIPAA compliance bundles map detected PHI categories to enforcement actions. Patient identifiers can be configured to BLOCK — preventing the prompt from reaching the model entirely. Clinical details can be set to REDACT — replacing specific PHI with redaction markers while preserving the clinical question. The policy engine evaluates every request against your configured rules before the data leaves your governance boundary.

Tamper-resistant audit chain. Every enforcement action generates an HMAC-chained audit log entry capturing the user identity, the detected PHI categories, the policy evaluation result, the enforcement action taken, and the model response governance. These logs are designed for compliance examiner review — they answer “was PHI governed?” with documented evidence, not assertions.

HIPAA compliance framework. Pre-built HIPAA compliance bundles activate the detection patterns and enforcement rules relevant to HIPAA-regulated data categories. These bundles enforce inline DLP rules that cannot be suppressed at the organization level, ensuring that PHI governance is applied consistently regardless of individual user or group policy configurations.

Implementation Checklist

Before allowing AI assistant use in clinical or administrative workflows that may involve PHI, verify these five items:

1. BAA coverage. Confirm that every AI provider your organization routes traffic through has a signed BAA that specifically covers the AI assistant use case. Gateway-level BAA coverage through Arbitex may simplify this — but verify the scope.

2. PHI detection and enforcement. Confirm that prompts are inspected for all 18 HIPAA PHI categories before reaching the AI model. Detection without enforcement is monitoring, not governance.

3. Identity integration. Confirm that AI tool access flows through your enterprise identity stack — SAML SSO, SCIM-provisioned accounts, MFA enforcement. Anonymous or shared-account AI access is not auditable.

4. Audit trail integrity. Confirm that interaction logs include content-level governance records with tamper-resistance verification. Request a sample audit export and verify it contains the fields a compliance examiner would need.

5. Data disposition. Confirm that PHI transmitted through the AI governance layer is not used for model training, is subject to your retention policies, and can be purged on demand per your data management plan.

AI assistants will transform healthcare productivity. The organizations that adopt them successfully will be the ones that built the governance infrastructure first — not the ones that deployed the tools and hoped compliance would follow.

Explore HIPAA compliance frameworks in the Arbitex Gateway, or request a demo to see PHI detection and enforcement in your clinical workflow scenarios.


See AI governance in action.

Book a 30-minute technical walkthrough of the Arbitex Gateway.