What "HIPAA-aligned" actually means when an AI vendor says it
August 5, 2026 · 5 min read"HIPAA-aligned" shows up on almost every healthcare AI vendor's homepage now, which is exactly why it's stopped meaning much on its own. It's a real, meaningful standard when a vendor can back it up - the problem is telling the difference from a phrase copied onto a slide.
A Business Associate Agreement is the floor, not the proof
A signed BAA means a vendor is legally willing to be accountable for PHI. It says nothing about whether their actual architecture protects it well. Ask what the BAA covers specifically: which systems, which data flows, and whether a subprocessor (the AI model provider itself, if it's a third party) is covered under it too.
Ask where the PHI actually goes, step by step
Does patient data get sent to a third-party model API? Is it used to fine-tune or improve that model? Is it retained by the model provider after the request completes? A vendor that has genuinely thought about this can answer in specifics. A vendor that hasn't will answer in reassurance.
Human-in-the-loop should mean a specific human, not a general promise
For anything touching patient care - a wellness check-in flag, a care plan change, a caregiver alert - there should be a named role responsible for reviewing it, a defined response window, and a documented fallback if that person doesn't respond in time. "A clinician reviews it" isn't an answer until you know which clinician, how fast, and what happens if they don't.
- A signed BAA that names the specific systems and subprocessors it covers
- A clear, specific answer on where PHI goes and whether it trains a shared model
- A named review role and response window for anything touching patient care
- A real audit log entry you can look at, not a description of one
This is the same governance discipline we apply everywhere we build, patient-care products included.