HIPAA for AI in healthcare
If your software touches protected health information, healthcare buyers will not sign without evidence that you handle it correctly and will sign a Business Associate Agreement.
Which edition this covers
The HIPAA Security Rule as codified at 45 CFR Part 164, Subparts A and C
Checked against the source on 2026-09-13 · read the source
Not covered
- The Security Rule NPRM published 6 January 2025. It is a proposal, not law, and nothing here is mapped to it.
- The Privacy Rule (Subpart E) and the Breach Notification Rule (Subpart D), which are separate rules.
- State health-privacy law, which can be stricter than HIPAA and is not preempted where it is.
What Trooth witnesses
Read on a schedule, republished with the date
- Encryption posture on the systems handling data
- Whether you publish a BAA position and how PHI is described in your disclosures
- Sub-processors that could touch protected data
- Your stated breach-notification channel and retention commitments
What Trooth does not do
Said plainly, so nobody guesses
- Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
- Confirm you are HIPAA compliant. There is no such certification, and no vendor can grant one.
- Review your BAAs or your policies as a lawyer would.
- Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.
Why this is worth anything to a buyer
A questionnaire answer is a claim typed once and never checked again. HIPAA here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.