Skip to main content

HIPAA for AI in healthcare

If your software touches protected health information, healthcare buyers will not sign without evidence that you handle it correctly and will sign a Business Associate Agreement.

Which edition this covers

The HIPAA Security Rule as codified at 45 CFR Part 164, Subparts A and C

Checked against the source on 2026-09-13 · read the source

Not covered

  • The Security Rule NPRM published 6 January 2025. It is a proposal, not law, and nothing here is mapped to it.
  • The Privacy Rule (Subpart E) and the Breach Notification Rule (Subpart D), which are separate rules.
  • State health-privacy law, which can be stricter than HIPAA and is not preempted where it is.

What Trooth witnesses

Read on a schedule, republished with the date

  • Encryption posture on the systems handling data
  • Whether you publish a BAA position and how PHI is described in your disclosures
  • Sub-processors that could touch protected data
  • Your stated breach-notification channel and retention commitments

What Trooth does not do

Said plainly, so nobody guesses

  • Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
  • Confirm you are HIPAA compliant. There is no such certification, and no vendor can grant one.
  • Review your BAAs or your policies as a lawyer would.
  • Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.

Why this is worth anything to a buyer

A questionnaire answer is a claim typed once and never checked again. HIPAA here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.