What is this course about?
HIPAA does not prohibit AI on PHI; it governs who may receive it and under what terms. This course covers de-identification and why Safe Harbor usually fails on clinical text, when an AI vendor becomes a business associate, Security Rule safeguards mapped to an AI system, and minimum necessary applied to model context and retrieval.
Who is this course for?
- Privacy officers and HIPAA compliance staff
- Healthcare CIOs and CISOs
- Clinical informatics leaders
- General counsel and contracting staff
What do I need before starting?
- Familiarity with your organization's HIPAA program
- No technical background required
What will I be able to do afterwards?
- Classify data as PHI, de-identified, or limited data set correctly
- Determine when an AI vendor becomes a business associate
- Read a BAA for subcontractor, breach, and termination exposure
- Map Security Rule safeguards onto an AI system
- Apply minimum necessary to model context and retrieval
What does each module cover?
What counts as PHI in an AI workflow?
45 minIdentifying PHI across the surfaces an AI system touches, including prompts and logs.
Objectives
- Classify data across an AI workflow
- Identify PHI in prompts, context, and logs
- Recognize where PHI appears unexpectedly
Topics
Activity. Trace PHI through an AI workflow including prompts, retrieval context, and logs.
Why does Safe Harbor fail on clinical text?
50 minDe-identification methods and why narrative clinical text resists both of them.
Objectives
- Compare Safe Harbor and expert determination
- Explain why clinical narrative resists de-identification
- Determine when de-identification is a viable strategy
Topics
Activity. Attempt Safe Harbor de-identification on clinical notes and find what remains identifying.
When is an AI vendor a business associate?
45 minThe business associate analysis applied to hosted AI services and their subcontractors.
Objectives
- Apply the business associate analysis
- Identify the subcontractor chain
- Determine which arrangements require a BAA
Topics
Activity. Analyze three AI vendor arrangements for business associate status.
How do you read a BAA?
50 minThe clauses that determine exposure — subcontractors, breach notification, termination, and return.
Objectives
- Locate the decisive BAA clauses
- Assess breach notification timing
- Evaluate termination and data return terms
Topics
Activity. Redline a real AI vendor BAA and mark every clause creating exposure.
How do Security Rule safeguards map to AI?
50 minAdministrative, physical, and technical safeguards applied to an AI system.
Objectives
- Map safeguards onto an AI deployment
- Identify safeguards that need AI-specific implementation
- Document the risk analysis
Topics
Activity. Map Security Rule safeguards onto an AI system and identify the gaps.
How does minimum necessary apply to model context?
45 minThe requirement applied to what gets assembled into a prompt and retrieved into context.
Objectives
- Apply minimum necessary to retrieval and context
- Prevent over-assembly of PHI into prompts
- Design role-scoped retrieval
Topics
Activity. Audit a workflow for context over-assembly and reduce it.
What do you do when PHI reaches the wrong place?
45 minBreach analysis for AI-specific exposure paths, which behave differently from a database breach.
Objectives
- Identify AI-specific exposure paths
- Run the breach risk assessment
- Determine notification obligations
Topics
Activity. Tabletop a PHI exposure through a retrieval permissions failure.
Building the PHI data-flow diagram
50 minThe workshop module: a complete data-flow diagram with safeguard mapping for one agent.
Objectives
- Produce a complete PHI data-flow diagram
- Map safeguards to each flow
- Identify residual risk
Topics
Activity. Complete the diagram and safeguard mapping, then review with the privacy officer.
What is the capstone project?
HIPAA compliance package for one AI use case
Produce a complete package: PHI classification across the workflow, business associate analysis, BAA redline, Security Rule safeguard mapping, minimum necessary implementation, a data-flow diagram, and a breach response annex.
Deliverable: A compliance package the privacy officer could sign and OCR could inspect.
How are learners assessed?
- PHI trace must include prompts, retrieval context, and logs
- BAA redline scored against the decisive-clause list
- Minimum necessary audit with over-assembly remediated
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for healthcare.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- HIPAA
U.S. Department of Health and Human Services
Primary HIPAA guidance for covered entities and business associates.
- 45 CFR Part 164
Electronic Code of Federal Regulations
The Privacy and Security Rule text analyzed throughout.
- Office for Civil Rights
HHS
Enforcement guidance and breach notification requirements.
- Cybersecurity Framework
NIST
Control structure supporting the Security Rule safeguard mapping.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 2's de-identification exercise should fail. Participants attempt Safe Harbor on real-shaped clinical narrative and discover how much identifying detail survives, which is the lesson.
- Module 1 must include logs and prompts explicitly. Organizations map PHI in databases and miss it entirely in AI telemetry, which is where most exposure now sits.
- Use synthetic clinical notes throughout. Real PHI cannot be used in a workshop under any circumstance, and synthetic notes can be built to contain the specific challenges each module needs.
- Have the privacy officer co-deliver. HIPAA application varies by organization and a generic course produces conclusions the privacy office will reject.
- Module 6's context over-assembly is the most common technical violation and the least recognized. Make the audit concrete.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives course cover?
HIPAA does not prohibit AI on PHI; it governs who may receive it and under what terms. This course covers de-identification and why Safe Harbor usually fails on clinical text, when an AI vendor becomes a business associate, Security Rule safeguards mapped to an AI system, and minimum necessary applied to model context and retrieval. It runs 5.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: HIPAA compliance package for one AI use case.
Who should take HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives?
It is written for Privacy officers and HIPAA compliance staff, Healthcare CIOs and CISOs, Clinical informatics leaders, General counsel and contracting staff. Prerequisites: Familiarity with your organization's HIPAA program; No technical background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for healthcare teams that cannot send work to a public AI tool.
How do we get access to HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for healthcare cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.