BLACKSIG SYSTEMS/Resources/Is AI HIPAA Compliant for a Dental or Medical Practice

// Resources

Is AI HIPAA Compliant? What a Dental or Medical Practice Has to Check in 2026

The question that stops every AI conversation in a practice, answered from the buyer’s side rather than the vendor’s. What your practice has to have in place, which tools count as business associates, what happens when the vendor is the one breached, and the seven questions that sort vendors on one call.

Last updated · 2026-10-06

The short version

No software is HIPAA compliant, because HIPAA does not certify software. Compliance is a set of safeguards your practice puts in place plus a signed business associate agreement with every vendor that touches protected health information, and HHS names a third-party AI chatbot on a patient portal as an example of a business associate. So the question to ask a vendor is not whether they are compliant, it is whether they will sign a BAA, where the data goes, and whether your information is used to train their models. One more thing worth knowing before you sign: when a vendor is breached, the notification duty still lands on your practice. This page sets out what to check. It is not legal advice, and your own counsel or compliance adviser should see any agreement before you sign it.

Is AI HIPAA compliant?

No AI tool is HIPAA compliant, because HIPAA does not certify software. The wording matters because vendors sell against it.

HIPAA regulates covered entities and their business associates, not products. The Office for Civil Rights does not pre-clear, certify or endorse any software as HIPAA compliant, and no federal HIPAA certification, seal or registry exists. A vendor's "HIPAA compliant" badge is a marketing claim about their own practices, not a government finding.

What does exist is a test for whether a vendor is in scope. If a vendor creates, receives, maintains or transmits protected health information on your behalf, it is a business associate, and a written business associate agreement has to be in place before any PHI reaches it. HHS's own business associates guidance gives, as an example of a business associate, a third-party AI chatbot on a provider's patient portal providing services involving patient PHI such as symptom assessment, medical reminders and appointment scheduling. An AI phone agent that hears a patient's name, number and reason for calling is in exactly that position.

So the practical question for a practice is a sequence. Does this tool touch PHI. Will the vendor sign a BAA. What does the BAA say about using your data to train models. Where is the data stored and who can reach it. And does the way you have configured it match what your risk analysis says.

Three of those five are about your practice rather than the vendor, which is the part the vendor pages leave out. This page sets out what to check. It is not legal advice, and your own counsel or compliance adviser should see any agreement before you sign it.

Which AI tools count as a business associate?

Any AI tool that hears, reads or stores patient information on your behalf counts as a business associate, which is most of the useful ones.

ToolTouches PHIBAA requiredWhat practices get wrong
AI phone agent answering patient callsYes, from the first sentence of the callYesAssuming the phone vendor's BAA covers the AI layer sitting on top of it
AI scheduling or recall messagingYes, name plus appointment data is PHIYesTreating SMS as outside scope because it is "just a reminder"
Ambient clinical documentation or AI scribeYes, the entire encounterYesNot asking where recordings are stored or how long for
Insurance and claims AIYesYesOverlooking the clearinghouse and the AI vendor as separate business associates
Imaging AIYesYesAssuming the imaging vendor's existing agreement extends to a new AI module
General consumer chatbots used by staffYes, the moment somebody pastes a patient detail inA consumer tier usually cannot provide oneStaff using a personal account for a letter about a real patient
Marketing analytics and website trackingOften yesYes where it doesTracking pixels on pages that reveal a condition or a provider
AI used only on de-identified or synthetic dataNo, if de-identification meets the standardNoCalling data de-identified when it still carries dates and a zip code

Two rows deserve emphasis. Staff using a free consumer AI account for anything patient related is the most common exposure in small practices, and it is a training and policy problem rather than a technology one; does a small business need an AI policy covers how to write the rule. And every service in the chain needs its own agreement: the model provider, the telephony or SMS gateway, the transcription service and the cloud host are separate business associates even when one vendor presents them as a single product.

What has to be in place before an AI tool touches patient data?

Nine things have to be in place before an AI tool touches patient data, and your practice owns most of them.

A signed BAA with each vendor in the chain, executed before any PHI flows, not after the pilot.

A current security risk analysis that includes the new tool. Missing or inadequate risk analysis is the failure OCR cites most often in small-practice enforcement, and its dedicated Risk Analysis Initiative had reached 13 settlements by April 2026 according to the enforcement tracking published by Medcurity.

A written answer on training. The BAA should prohibit the vendor from using your PHI to train, improve or refine its models without your explicit authorisation. Silence in a contract is not a prohibition.

Access controls and unique accounts, so you can say who heard what. Shared logins defeat every audit question that follows an incident.

Encryption in transit and at rest, confirmed in writing rather than assumed from a web page.

Audit logs you can actually retrieve, covering what the system did and which staff member approved it.

Minimum necessary configuration. An AI agent that only needs to book appointments should not be able to read clinical notes, and most tools ship with more access than the job requires.

A documented human path. What happens when the system cannot understand a caller, and who it hands to. That is a compliance question as much as a service one, because the fallback is where disclosures to the wrong person happen.

Written incident expectations: how fast the vendor tells you about a security incident, in what form, and who in your practice receives it. Default contract language is usually vaguer than the Breach Notification Rule timeline you will be working to.

What happens if the AI vendor is the one that gets breached?

If the AI vendor is breached, your practice still notifies the patients, and the vendor's penalty may be a fraction of your cleanup.

The clearest illustration in this market arrived in 2026. OCR announced a settlement on 5 March 2026 with MMG Fusion, LLC, a Maryland software company that sold patient communication and marketing tools to dental practices and acted as a business associate. A threat actor breached its network in December 2020, took patient data and posted it on the dark web. Reporting on the settlement, including a client alert from Saul Ewing, describes names, phone numbers, addresses, dates of birth and appointment details for roughly 15 million individuals, a complaint filed with OCR in January 2023, and findings of impermissible disclosure, failure to conduct an accurate and thorough risk analysis, and failure to notify the affected covered entities. The monetary settlement was $10,000, with a three-year corrective action plan, an amount OCR tied to the company's financial condition. The company is no longer operating.

Read the last two findings together and the lesson for a practice is uncomfortable. The vendor did not tell the covered entities, which means the practices could not notify their patients on time, and the notification duty was still theirs. A vendor that fails and then disappears leaves the obligation exactly where it started, and the corrective action plan in this case had to reach successor entities to get those notifications sent at all.

What to do about it is contractual rather than technical. Name a notification window in the BAA in hours rather than "promptly". Require a named contact. Ask what happens to your data if the company is acquired or shuts down, and get the answer in the agreement. Keep your own copy of anything you would need to reconstruct a patient list. And run the vendor through the same risk analysis you run on yourself, because OCR's view is that you are responsible for who you choose.

Is the compliance work worth it for a practice our size?

The compliance work is worth it where the tool removes documentation or front-office load, and the clinical evidence is now better than the marketing.

The Permanente Medical Group rolled out ambient AI documentation across Northern California and reported the result in NEJM Catalyst as Ambient Artificial Intelligence Scribes: Learnings after 1 Year and over 2.5 Million Uses. Across 7,260 physicians and 2,576,627 patient encounters between October 2023 and December 2024, it reported 15,791 hours of documentation time saved, with 84% of surveyed physicians describing a positive experience, citing reduced mental workload and better recall of appointment details.

An independent multi-site study published in JAMA in April 2026 put more modest numbers on the same effect. Lisa Rotenstein and colleagues, with Rebecca G. Mishuris as senior author, compared 8,581 ambulatory clinicians across Mass General Brigham, Emory Healthcare, UCSF, Yale New Haven Health and UC Davis, of whom 1,809 adopted an AI scribe, in Changes in Clinician Time Expenditure and Visit Quantity With Adoption of Artificial Intelligence-Powered Scribes: A Multisite Study. Documentation time fell by 16.0 minutes and total EHR time by 13.4 minutes per eight scheduled patient hours, about a tenth of the documentation load, and clinicians who used a scribe on more than half their visits saw roughly double the reduction in EHR time and three times the reduction in documentation time.

Neither number is a promise for a six-chair dental practice, and the gap between the two is the honest picture: a single organisation reporting its own rollout lands higher than an independent comparison across five. What they establish together is that the gain is real, that it concentrates in documentation and front-office handling, and that it scales with how consistently the thing gets used. That is also where the compliance work is most tractable: a defined data flow, one vendor, one BAA, one configuration to get right. The capability by capability picture for practices, each marked proven, working or early, is on our dental and medical board.

The decision we would push back on is a tool that touches patient data to produce a benefit nobody has measured. Compliance work costs real attention, so spend it where the arithmetic is clear, and the method for establishing that is in how to measure whether AI automation is saving money.

What is changing in the HIPAA rules in 2026 and 2027?

What is changing is the Security Rule: it is being rewritten, the proposal is more prescriptive than what exists today, and the final rule has slipped.

OCR published a Notice of Proposed Rulemaking on 6 January 2025, the first substantial Security Rule update since the 2013 Omnibus Rule. The comment period closed on 7 March 2025 with 4,745 comments received. A final rule was tentatively scheduled for May 2026 and has not been published; the HIPAA Journal's tracking of the rulemaking now puts the target at July 2027, and once a final rule lands it would take effect 60 days later with roughly 240 days to comply on most provisions.

Three proposed changes matter for a practice buying AI tools. A written inventory of technology assets plus a network map, covering everything that affects the confidentiality, integrity or availability of electronic PHI, which is exactly the document that tells you how many AI vendors are in your environment. Encryption of electronic PHI at rest and in transit as a requirement with limited exceptions, rather than a judgment call. And removal of the distinction between "required" and "addressable" implementation specifications, which has been the gap small practices lean on.

None of that is in force yet and the dates may move again. The practical consequence is that the safeguards worth building now are the ones the proposal would make mandatory anyway: know what you run, encrypt it, log who did what, and keep the agreements current. A practice that does those four things is in a better position whenever the final rule lands.

Our own position on data handling in systems we build sits alongside this: we design the data flow before the build, the system runs on our infrastructure and we operate it from there, and what the system is allowed to see is a decision taken on purpose rather than a default. The general version of that is in is AI automation safe with my business data.

How do we check an AI vendor before signing?

You check an AI vendor with seven questions, and the answers sort vendors in a single call.

Ask thisA good answer sounds likeA bad answer sounds like
Will you sign a BAA, and can we see it nowYes, here is the template, before the pilot"We are HIPAA compliant" with no document
Is our PHI used to train your modelsNo, and the BAA says so in writing"Your data is secure"
Which subprocessors touch PHIA named list: model provider, telephony, transcription, hosting"Everything is handled in-house"
Where is data stored and for how longNamed region, stated retention, documented deletionNobody on the call knows
How fast do you notify us of a security incidentA stated number of hours and a named contact"Promptly"
What access does the tool have in our systemsOnly what the task needs, listedFull access because it was easier to configure
What do we get if we leave, or if you shut downAn export, our records, a documented handoverA conversation to have later

Two answers should end the evaluation: a vendor that will not provide a BAA at all, and a vendor that cannot say which companies are in their processing chain. Both are common, and both mean the risk is yours without the paperwork to match.

Frequently asked questions

How much does HIPAA compliant AI cost a practice?

What moves the number is how many tools touch patient data, whether each vendor's enterprise tier is the one that includes a BAA, how much configuration and staff training the rollout needs, and whether anybody inside the practice is keeping the risk analysis current. Consumer tiers of general AI tools are cheap and usually cannot provide a BAA, which makes them the wrong comparison. BLACKSIG does not publish a rate card, and scope gets set on the call after the strategy work has said which processes are worth automating. The cost drivers are broken down in how much AI automation costs.

How does a HIPAA compliant AI setup actually work in a practice?

Data flow first: what the tool hears or reads, where it goes, who can see it, how long it stays. Then a BAA with each vendor in the chain, access limited to what the task needs, encryption in transit and at rest, logging of what the system did and who approved it, and a defined handover to a person when the system cannot complete something. Then the risk analysis gets updated to include the new tool, and staff get told what they may and may not put into it.

Is a HIPAA compliant AI vendor better than building something inside our own systems?

Different trade. A specialist vendor gives you a product that already works and a BAA they have signed many times, and you accept their data flow and their roadmap. Building inside your own environment gives you control over exactly what the system sees and keeps fewer companies in the chain, at the cost of somebody having to design and operate it. For most single-site practices the vendor route is right for one or two obvious jobs; a group with several locations and multiple systems usually needs the joins built, which is the work we do. The in-house comparison is in automation consultant versus in-house.

Can our front office be automated without putting patient data at risk?

Yes, with the scope set deliberately. An agent that books, reschedules and confirms needs the calendar and a patient's contact details, and nothing clinical. Keeping it to that is a configuration decision, and it is the difference between one vendor seeing appointment data and one vendor seeing a chart. Start with the workflow that needs the least information to do its job, measure it, then decide about the next one.

Can we use ChatGPT or a similar tool for patient letters?

Not on a consumer account, because free and personal tiers generally do not come with a business associate agreement, and without one any PHI you paste in is an impermissible disclosure regardless of intent. Business and enterprise tiers from the major providers can be covered by an agreement, which changes the answer, so check which tier you are actually on and whether your organisation has an executed BAA for it. Then write the rule down for staff, because the exposure here is somebody being helpful at 5pm.

Related resources

Find out where AI belongs in your practice

We map how your practice actually runs, decide where AI is worth using, then our engineering team builds what the plan calls for and we run it from there. We own the outcome, not the deliverable.