Regulation · United States

HIPAA-compliant AI assistants: why self-hosting simplifies the BAA question

In short

Under HIPAA, an AI vendor that creates, receives, maintains or transmits protected health information on behalf of a covered entity is generally a business associate, which requires a business associate agreement and Security Rule safeguards. Running the AI inside the provider's own environment keeps PHI out of third-party AI services and keeps safeguards under the provider's control.

PHI goes wherever the prompt goes

When a clinician asks an AI assistant about a patient, or a voice agent handles an appointment call, protected health information (PHI) travels with the request. If the AI runs as a third-party service, that vendor is receiving PHI.

Business associates and BAAs

A vendor that creates, receives, maintains or transmits PHI on a covered entity's behalf is generally a business associate. That means a business associate agreement, Security Rule safeguards on the vendor's side, and breach obligations that flow back to you. It also means the vendor's sub-processors, such as model providers and hosting, become part of the chain.

What self-hosting changes

If the AI system runs inside your environment:

  • PHI stays on infrastructure you already protect under the Security Rule.
  • There is no AI vendor in the PHI path to contract with for that data.
  • Logs of who asked what, and which records were used, stay with you.

If a partner operates the system for you with access to PHI, appropriate terms are still needed, but the data path is yours.

Safeguards to design in

  1. Minimum necessary: scope each agent to the sources and roles that need them.
  2. Access control: role-based, synced from your directory.
  3. Audit controls: log every query, source and action.
  4. Voice: recording notice, consent capture and retention rules for patient calls.

See also our HIPAA page and healthcare page.

General information, not legal advice. Questions? Write to sales@deepvox.ai.