The HIPAA Journal recently announced a free webinar focused on a question every healthcare security leader should be asking right now: Is AI putting your practice at risk? The premise is straightforward — and alarming in its accuracy. Artificial intelligence has quietly embedded itself into healthcare workflows, often without security teams, compliance officers, or even practice leadership knowing it is there. Transcription services, scheduling assistants, ambient clinical documentation tools, patient communication platforms, and even the productivity suites your staff already use are now shipping with AI features enabled by default. Every one of them is a potential vector for impermissible disclosure of protected health information (PHI).
This is not a theoretical concern. In my 15+ years working healthcare incident response and compliance engagements, the most damaging exposures I have seen were rarely the result of sophisticated attackers — they were the result of well-meaning staff adopting convenient tools that nobody had vetted. AI has industrialized that risk.
Why This Matters Now
The healthcare sector is in the middle of an uncontrolled AI adoption cycle. Unlike previous technology waves, AI capabilities are not arriving through procurement — they are arriving through feature updates to software your practice already owns. Microsoft 365 Copilot, AI-powered transcription baked into telehealth platforms, ambient listening tools from EHR vendors, and consumer-grade chatbots used by front-desk staff to draft patient communications are all live in practices today.
The regulatory stakes are severe. Under HIPAA, an impermissible disclosure of PHI to an AI vendor without a Business Associate Agreement (BAA) in place can constitute a reportable breach — triggering HHS Office for Civil Rights (OCR) investigation, mandatory patient notification, potential civil monetary penalties, and in egregious cases, Corrective Action Plans that put your compliance program under federal oversight for years. OCR has been increasingly aggressive in enforcement, and state attorneys general are now layering their own actions on top of federal penalties. Several states have also enacted or proposed AI-specific healthcare legislation that compounds the exposure.
The core problem the webinar addresses — where AI is hiding in your practice — is the right framing. You cannot govern what you have not inventoried.
Where AI Is Actually Hiding in Your Practice
Based on engagements we have conducted for healthcare clients over the past 18 months, these are the most common blind spots:
Ambient clinical documentation tools. AI scribes that listen to patient encounters and generate chart notes are exploding in popularity because they genuinely reduce physician burnout. But they capture audio containing PHI, transmit it to third-party infrastructure for processing, and in some product tiers use that data for model training. If your clinicians adopted one without a BAA and a security review, you have a live compliance violation in progress.
Embedded AI in existing SaaS. Your practice management system, your EHR, your billing platform, and your email suite have all shipped AI features in the last two years. Many are opt-out rather than opt-in. Staff may be summarizing patient emails with AI assistants, auto-drafting responses to portal messages, or using AI scheduling tools — all touching PHI — under vendor terms that never contemplated HIPAA obligations.
Consumer AI tools used by staff. This is the hardest to control. A billing specialist pastes a denied claim — complete with patient name, date of birth, diagnosis codes, and insurance details — into a consumer chatbot to draft an appeal letter. A nurse uses a personal AI assistant to help word a difficult patient message. Each instance is an impermissible disclosure, and none of it shows up in your DLP stack because it happens over consumer accounts on personal or unmanaged devices.
AI features in telehealth and patient engagement platforms. Automated intake chatbots, AI triage tools, and sentiment analysis on patient surveys all process PHI. Vendors in this space vary wildly in their HIPAA maturity — some will sign a BAA; others explicitly disclaim healthcare use in their terms of service.
Medical device and imaging AI. Diagnostic AI embedded in imaging modalities and monitoring equipment processes PHI at the edge and often phones home to vendor cloud services. These devices frequently sit outside the scope of traditional IT asset inventories.
The Specific HIPAA Risk Categories
When I assess AI risk in a healthcare environment, I map findings against four concrete violation patterns:
1. Impermissible disclosure (45 CFR §164.502). Any PHI sent to an AI vendor without a BAA, or used by that vendor for purposes beyond the service agreement (such as model training), is a disclosure violation. This is the most common failure mode and the easiest to commit accidentally.
2. Minimum necessary violations (45 CFR §164.502(b)). AI tools often ingest entire records, full conversation transcripts, or complete message threads when only a fraction of that data is needed for the task. Blanket AI access to an EHR or mailbox is almost never defensible under the minimum necessary standard.
3. Security Rule gaps (45 CFR §164.312). AI integrations frequently bypass your access controls, audit logging, and transmission security requirements. If an AI plugin reads your EHR via an API token held by an individual clinician rather than a governed service account, your audit trail is broken and your access review process is meaningless for that data flow.
4. Breach notification obligations (45 CFR §§164.400–414). Here is the part practices consistently underestimate: if PHI was disclosed to an unsecured AI platform, the burden is on you to demonstrate the data was not retained, not used for training, and not further disclosed. Vendor marketing claims are not evidence. Without contractual guarantees and technical verification, you may be unable to prove a low probability of compromise — which means breach notification is the default outcome.
Executive Takeaways
Given that this news item concerns governance and compliance rather than a specific technical exploit, the defensive value here is organizational. These are the actions I recommend healthcare security and compliance leaders take immediately:
1. Conduct a shadow AI inventory now. Do not wait for an OCR investigation to discover your AI footprint. Survey every department, review SaaS contracts for recently added AI features, interview clinicians about documentation tools, and check network telemetry for traffic to consumer AI platforms. Treat this with the same rigor as a shadow IT discovery exercise — because that is exactly what it is.
2. Establish an AI acceptable use policy before you need it. Your policy must clearly state: no PHI in any AI tool without an executed BAA and security review; no consumer AI accounts for any work involving patient data; and a defined approval path for new AI tools. A policy that exists only on paper is better than nothing, but pair it with technical enforcement where possible — web filtering categories for known AI services, CASB controls, and conditional access policies.
3. Execute BAAs or kill the tool. For every AI service touching PHI, you need a Business Associate Agreement that explicitly addresses data retention, model training prohibitions, subcontractor flow-down, and breach notification timelines. If a vendor will not sign a BAA, the answer is not a risk acceptance memo — it is removing the tool from PHI workflows. Train staff that convenience does not override this requirement.
4. Add AI to your risk analysis. HIPAA's Security Rule requires an accurate and thorough risk analysis. If your most recent assessment predates your practice's AI adoption, it is stale. Update it to cover AI data flows, vendor AI subprocessors, and the specific threat of PHI ingestion into external models. OCR investigators ask for the risk analysis first — it must reflect your actual environment, including AI.
5. Build an AI governance committee with clinical representation. The decisions about which AI tools are safe are not purely technical or purely legal — they involve clinical workflow tradeoffs. A standing committee with IT security, compliance/privacy, HIM, and clinical leadership can evaluate tools once rather than fighting the same battle department by department.
6. Invest in workforce training specific to AI and PHI. Generic HIPAA training does not address the scenario of a staff member pasting patient data into a chatbot. Update your training program with concrete, realistic examples of AI-related violations, and make reporting of accidental disclosures a non-punitive process. You want staff to tell you when they made a mistake — the alternative is discovering it during a breach investigation.
The Framework Question
The webinar promises a simple framework for using AI while remaining HIPAA compliant, and that is the right goal. AI is not optional in modern healthcare — the efficiency gains in documentation, coding, and patient communication are too significant to forgo, and blanket prohibition simply drives usage underground. The practices that will navigate this successfully are the ones that build a governed adoption pipeline: inventory, assess, contract (BAA), technically control, train, and monitor.
The practices that will end up in OCR's breach portal are the ones still assuming AI is something happening somewhere else.
Register for the webinar if this topic touches your environment — and if you are a covered entity or business associate in 2026, it does. Then move immediately to the inventory step. You cannot remediate exposure you have not mapped, and the clock on any existing impermissible disclosures is already running.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.