All insights
AI for Aging & Patient Care

What "HIPAA-aligned" actually means when an AI vendor says it

August 5, 2026 · 5 min read

"HIPAA-aligned" shows up on almost every healthcare AI vendor's homepage now, which is exactly why it's stopped meaning much on its own. It's a real, meaningful standard when a vendor can back it up - the problem is telling the difference from a phrase copied onto a slide.

A Business Associate Agreement is the floor, not the proof

A signed BAA means a vendor is legally willing to be accountable for PHI. It says nothing about whether their actual architecture protects it well. Ask what the BAA covers specifically: which systems, which data flows, and whether a subprocessor (the AI model provider itself, if it's a third party) is covered under it too.

Ask where the PHI actually goes, step by step

Does patient data get sent to a third-party model API? Is it used to fine-tune or improve that model? Is it retained by the model provider after the request completes? A vendor that has genuinely thought about this can answer in specifics. A vendor that hasn't will answer in reassurance.

Human-in-the-loop should mean a specific human, not a general promise

For anything touching patient care - a wellness check-in flag, a care plan change, a caregiver alert - there should be a named role responsible for reviewing it, a defined response window, and a documented fallback if that person doesn't respond in time. "A clinician reviews it" isn't an answer until you know which clinician, how fast, and what happens if they don't.

  • A signed BAA that names the specific systems and subprocessors it covers
  • A clear, specific answer on where PHI goes and whether it trains a shared model
  • A named review role and response window for anything touching patient care
  • A real audit log entry you can look at, not a description of one

This is the same governance discipline we apply everywhere we build, patient-care products included.