Why the Claim Needs Verifying
Under HIPAA, a vendor that processes PHI on your behalf is a business associate, and your practice retains exposure for how they handle it. 'HIPAA compliant' printed on a website is a marketing statement, not evidence. Due diligence means getting specific answers in writing before any patient data moves.
The Six Questions
1. Will you execute a BAA before receiving any PHI? 2. What encryption protects data in transit and at rest — specifically? 3. Who inside your organisation can access our data, and how is that restricted? 4. How is staff vetted and trained? 5. Can you produce audit logs of access to our records? 6. What is your breach notification procedure and timeline?
Questions Specific to AI Vendors
AI introduces two additional questions that traditional vendors never faced. Is our patient data used to train your models, and can we opt out? And where is inference actually performed — on infrastructure you control, or through a third-party API that becomes a subcontractor in your compliance chain? Both deserve written answers.
What a Good Answer Looks Like
Concrete, specific, and offered without friction. Our answers: BAA executed before any PHI is exchanged; 256-bit TLS in transit and AES-256 at rest; role-restricted access limited to the staff assigned to your account; background-checked staff under confidentiality agreements with annual training; immutable audit logs; and documented breach procedures. The full detail sits on our HIPAA compliance page.
Bring Your Compliance Officer In Early
The cheapest time to involve compliance is before selection, not after a contract is signed. Any vendor worth choosing will hand over security documentation for review on request. Ask us for ours — it is the same packet we give to hospital compliance teams.