HIPAA and AI assistants: what a practice can automate and what it can't
The question isn't whether artificial intelligence is HIPAA compliant. It's what information each workflow touches, and that changes the answer entirely.
Saturday, eleven in the morning. Someone messages a dental practice in Plantation on WhatsApp: "do you take Cigna? anything Monday afternoon?"
Nobody answers until Monday. By then that person has an appointment somewhere else.
When I suggest to a practice that they automate that reply, the conversation always stops at the same place: "but is that HIPAA compliant?"
It's the wrong question, which is why it has no answer. HIPAA doesn't certify technology. There is no "HIPAA-approved software" seal you buy and you're done. The question that can be answered is a different one: what information does this particular workflow touch?
What protected health information actually is
The rule defines protected health information — PHI — as information meeting three conditions at once: it's created or received by a health care provider, plan or similar entity; it relates to a person's health, to the care they receive, or to payment for that care; and it identifies that person or could reasonably be used to identify them (45 CFR §160.103).
All three have to be true together. That's the door almost nobody notices.
The distinction that settles most cases
Two questions that look alike and are legally different:
"Do you take Cigna?" — no patient is mentioned. That's business information, same as your hours or your address. Answering it touches nobody's health information.
"I'm María Pérez and I want an appointment Monday" — now an identifiable person is connected to health care. That is protected information.
And here's the part that surprises nearly everyone: being protected information doesn't mean using it is forbidden. The rule permits using and disclosing it for treatment, payment and health care operations without prior authorization (45 CFR §164.506).
HHS says it plainly about appointment reminders: "Yes, appointment reminders are considered part of treatment of an individual and, therefore, can be made without an authorization" (official FAQ). Another answer confirms no prior consent is needed to schedule over the phone either (FAQ 260).
In practice: booking, reminding, giving your hours or confirming which insurance you accept are things you can automate. Not because they fall outside HIPAA, but because the rule expressly permits them and none of them require opening anyone's chart.
That covers the overwhelming majority of what a practice loses on a Saturday.
Where it starts to weigh
It changes when the conversation goes clinical: symptoms, reason for the visit, test results, medication, prior history.
That information is still protected, but it also changes in kind: it stops being logistics and becomes medical content. An automated assistant has no business touching it, and in my view shouldn't try.
The rule we apply is simple: when a conversation crosses that line, the assistant stops answering and hands it to a person. It doesn't improvise a clinical answer, doesn't ask for symptom details, and doesn't store that part of the conversation as if it were one more data point.
There's one obligation worth knowing too: if a patient asks to receive communications by another means or at another location, the provider must accommodate that request when reasonable, and can't require them to explain why (45 CFR §164.522(b)). If someone doesn't want to be messaged on WhatsApp, you need to be able to honor that.
What a BAA is and why the whole chain needs one
Anyone who creates, receives, maintains or transmits protected information on the practice's behalf is what the rule calls a business associate (45 CFR §160.103). Each one needs a signed agreement — the BAA — setting out what they can do with the information, what safeguards they apply, how they notify a breach, and what happens to the data when the contract ends (45 CFR §164.504(e)).
Two things that get expensive when ignored.
Encryption doesn't get anyone off the hook. HHS's Office for Civil Rights was explicit about cloud providers: they are business associates "even if the CSP cannot view the ePHI because it is encrypted and the CSP does not have the decryption key" (cloud computing guidance). Your vendor not reading the data doesn't take them out of the chain.
Subcontractors count too. The definition expressly includes anyone a business associate delegates to, and that subcontractor needs their own agreement. If your automation vendor leans on a third party to host or process, that third party is in scope.
There's an exception called the conduit exception, but it's far narrower than people assume: it covers those who merely transport information without accessing it, like the postal service or an internet provider. HHS explained it when publishing the 2013 rule: an entity that maintains protected information is a business associate and not a conduit, "even if the entity does not actually view the protected health information" — the difference being the transient versus persistent nature of the access (official preamble, 78 FR 5571).
A messaging platform that stores conversation history is not a conduit. It's a business associate.
Five questions before you sign with anyone
- Will you sign a BAA? If the answer is slow or conditional, you already have your answer.
- Who are your subcontractors and do you have an agreement with each? Ask for the list. A serious vendor has it ready.
- What exactly is stored, where, and for how long? What isn't kept can't leak.
- What happens when a conversation turns clinical? If the answer is "the system responds," walk away.
- How and how fast do you notify me of a breach? It belongs in the contract, with a deadline.
One warning about vendors marketing themselves as "HIPAA-compliant AI": HHS has issued no guidance specific to artificial intelligence and HIPAA. Anyone claiming their product is certified under an AI standard that doesn't exist is selling something they can't back. What does exist is the same old rule applied to a new kind of vendor: if it touches protected information, it's a business associate and it signs a BAA.
The only claim I'll make about us
We sign BAAs with medical and dental practices, and what we build doesn't store clinical information. The assistant handles what's in the script approved with the practice — hours, insurance accepted, availability, booking, reminders — and anything outside that goes to a person on the team.
That isn't a promise of compliance, which is a promise nobody can make on your behalf. It's a description of how the thing is built.
If you're deciding this week
Do this on paper: write down the ten questions you get most by phone and by message. Mark which are logistical and which are clinical.
You'll find nearly all of them are logistical. That's exactly the part that can be automated without going anywhere near anyone's chart, and it's the part you're losing on Saturdays.
Then take it to your attorney or your compliance officer along with the questions above. Let the decision come out of that conversation, not out of a web page — including this one.