Is Your AI Assistant Committing a HIPAA Violation?

Aug 05, 2026 at 12:45 pm


By Christian Epperson

The average physician now loses nearly nine hours a week to administrative work. So when a free AI chatbot offers to draft a summary or an appeal letter in seconds, it's easy to see the appeal — and easy to see why so many are doing it quietly, without realizing the risk. In 2026, a leading patient-safety organization ranked the misuse of AI chatbots as the single largest health technology hazard of the year.

Three ways it quietly becomes a HIPAA problem

  • “HIPAA-eligible” is not “HIPAA-compliant.” A tool that creates, receives, or transmits PHI on your behalf is legally a Business Associate — and needs a signed BAA before any patient data touches it.
  • “De-identified” is harder than it sounds. Clinical narratives carry enough detail that re-identification is often possible, even after obvious identifiers are removed.
  • Your patient data may train someone else's model. Free and consumer-tier AI tools often reuse submitted content to improve future versions — unless an enterprise agreement explicitly says otherwise.

Blocking AI outright rarely works. A more durable approach: a written AI use policy naming approved tools, vendor BAAs that explicitly prohibit training on your PHI, minimum-necessary access controls, and monitoring for PHI leaving the network through browser-based AI — the same way you'd watch for it leaving through email.

Christian Epperson Security Team lead with EPPTech.  

Sections: Blog



July 2026

Jul 26, 2026 at 07:40 pm by kbarrettalley

The June 2026 Issue of Birmingham Medical News is here!