Omar Al-Rashid
Head of AI & Blockchain
AI automation is transforming clinical and administrative workflows in US healthcare — but HIPAA doesn't bend for convenience. Here's how to build AI tools that touch PHI without turning your compliance program into a liability.
US healthcare providers are under real pressure to adopt AI — for clinical documentation, prior authorization, scheduling, and patient communication — while HIPAA's rules on Protected Health Information (PHI) haven't loosened to accommodate the pace of AI adoption. The result is a genuine engineering and vendor-management challenge: how do you get the productivity gains of AI automation without a Business Associate Agreement gap or a PHI exposure that becomes a breach report to HHS?
Before evaluating any AI vendor or building an internal tool, there's one question that determines everything else: does this system create, receive, maintain, or transmit PHI? If yes, HIPAA's Security Rule, Privacy Rule, and Breach Notification Rule all apply, and any third party involved must sign a Business Associate Agreement (BAA). A striking number of healthcare AI pilots fail compliance review not because the AI itself is unsafe, but because the vendor won't or can't sign a BAA — many consumer-grade LLM APIs fall into this category by default.
Not every AI use case needs to touch identifiable PHI. HIPAA's Safe Harbor and Expert Determination methods for de-identification, when applied correctly, remove data from HIPAA's scope entirely — which materially simplifies vendor selection and architecture. Teams building AI for population health analytics, research, or general workflow optimisation should evaluate de-identification before assuming they need a full PHI-grade pipeline.
“The healthcare organisations succeeding with AI aren't the ones avoiding PHI entirely — they're the ones who scoped exactly which workflows need it, and built a narrower, tightly governed pipeline for those, while keeping everything else de-identified.”
— Omar Al-Rashid, Head of AI & Blockchain, Alliance Corporation
Alliance Corporation builds HIPAA-aware AI automation and custom software for US healthcare providers, from BAA-covered AI architecture to workflow automation. Talk to our AI & Automation team.
Omar Al-Rashid
Head of AI & Blockchain · Alliance Corporation
Part of the Alliance Corporation leadership team, shaping technology strategy across AI, cloud and enterprise software for clients in 50+ countries.