# HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives

> Healthcare · AI Course · MED-1
> Source: https://ibl.ai/solutions/medical-healthcare/course/hipaa-compliant-ai
> Last updated: 2026-08-25

**What HIPAA actually requires of an AI deployment — the BAA analysis, Security Rule safeguards, minimum necessary, and the architecture that keeps PHI inside your boundary.**

## The Short Answer

**HIPAA does not prohibit AI on PHI; it governs who receives it and under what terms. ibl.ai deploys inside the covered entity's own environment where you own all the code and the data, so no third party receives PHI, no BAA chain is created, and minimum necessary is enforced at retrieval rather than promised in a contract.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Healthcare](https://ibl.ai/solutions/medical-healthcare)

## Course facts

- **Level:** Foundational
- **Duration:** 5.5 hours across 8 modules
- **Format:** Cohort workshop with BAA review labs
- **Modules:** 8
- **Catalog code:** MED-1
- **Frameworks covered:** HIPAA Privacy Rule, HIPAA Security Rule, 45 CFR Part 164, NIST CSF 2.0

## What is this course about?

HIPAA does not prohibit AI on PHI; it governs who may receive it and under what terms. This course covers de-identification and why Safe Harbor usually fails on clinical text, when an AI vendor becomes a business associate, Security Rule safeguards mapped to an AI system, and minimum necessary applied to model context and retrieval.

## Who is this course for?

- Privacy officers and HIPAA compliance staff
- Healthcare CIOs and CISOs
- Clinical informatics leaders
- General counsel and contracting staff

### What do I need before starting?

- Familiarity with your organization's HIPAA program
- No technical background required

## What will I be able to do afterwards?

- Classify data as PHI, de-identified, or limited data set correctly
- Determine when an AI vendor becomes a business associate
- Read a BAA for subcontractor, breach, and termination exposure
- Map Security Rule safeguards onto an AI system
- Apply minimum necessary to model context and retrieval

## What does each module cover?

### Module 1 — What counts as PHI in an AI workflow?

Identifying PHI across the surfaces an AI system touches, including prompts and logs. _(45 min)_

**Objectives**

- Classify data across an AI workflow
- Identify PHI in prompts, context, and logs
- Recognize where PHI appears unexpectedly

**Topics:** PHI definition · PHI in prompts and logs · Context assembly · Unexpected surfaces

**Activity:** Trace PHI through an AI workflow including prompts, retrieval context, and logs.

### Module 2 — Why does Safe Harbor fail on clinical text?

De-identification methods and why narrative clinical text resists both of them. _(50 min)_

**Objectives**

- Compare Safe Harbor and expert determination
- Explain why clinical narrative resists de-identification
- Determine when de-identification is a viable strategy

**Topics:** Safe Harbor · Expert determination · Clinical narrative · Re-identification risk

**Activity:** Attempt Safe Harbor de-identification on clinical notes and find what remains identifying.

### Module 3 — When is an AI vendor a business associate?

The business associate analysis applied to hosted AI services and their subcontractors. _(45 min)_

**Objectives**

- Apply the business associate analysis
- Identify the subcontractor chain
- Determine which arrangements require a BAA

**Topics:** Business associate definition · Subcontractor chains · Conduit exception limits · BAA requirements

**Activity:** Analyze three AI vendor arrangements for business associate status.

### Module 4 — How do you read a BAA?

The clauses that determine exposure — subcontractors, breach notification, termination, and return. _(50 min)_

**Objectives**

- Locate the decisive BAA clauses
- Assess breach notification timing
- Evaluate termination and data return terms

**Topics:** Subcontractor provisions · Breach notification · Termination · Data return and destruction

**Activity:** Redline a real AI vendor BAA and mark every clause creating exposure.

### Module 5 — How do Security Rule safeguards map to AI?

Administrative, physical, and technical safeguards applied to an AI system. _(50 min)_

**Objectives**

- Map safeguards onto an AI deployment
- Identify safeguards that need AI-specific implementation
- Document the risk analysis

**Topics:** Administrative safeguards · Technical safeguards · Audit controls · Risk analysis

**Activity:** Map Security Rule safeguards onto an AI system and identify the gaps.

### Module 6 — How does minimum necessary apply to model context?

The requirement applied to what gets assembled into a prompt and retrieved into context. _(45 min)_

**Objectives**

- Apply minimum necessary to retrieval and context
- Prevent over-assembly of PHI into prompts
- Design role-scoped retrieval

**Topics:** Minimum necessary · Context over-assembly · Role-scoped retrieval · Enforcement

**Activity:** Audit a workflow for context over-assembly and reduce it.

### Module 7 — What do you do when PHI reaches the wrong place?

Breach analysis for AI-specific exposure paths, which behave differently from a database breach. _(45 min)_

**Objectives**

- Identify AI-specific exposure paths
- Run the breach risk assessment
- Determine notification obligations

**Topics:** AI exposure paths · Breach risk assessment · Notification determination · Documentation

**Activity:** Tabletop a PHI exposure through a retrieval permissions failure.

### Module 8 — Building the PHI data-flow diagram

The workshop module: a complete data-flow diagram with safeguard mapping for one agent. _(50 min)_

**Objectives**

- Produce a complete PHI data-flow diagram
- Map safeguards to each flow
- Identify residual risk

**Topics:** Data-flow diagramming · Safeguard mapping · Residual risk · Documentation

**Activity:** Complete the diagram and safeguard mapping, then review with the privacy officer.

## What is the capstone project?

**HIPAA compliance package for one AI use case.** Produce a complete package: PHI classification across the workflow, business associate analysis, BAA redline, Security Rule safeguard mapping, minimum necessary implementation, a data-flow diagram, and a breach response annex.

_Deliverable:_ A compliance package the privacy officer could sign and OCR could inspect.

## How are learners assessed?

- PHI trace must include prompts, retrieval context, and logs
- BAA redline scored against the decisive-clause list
- Minimum necessary audit with over-assembly remediated

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Compliance Training Agent](https://ibl.ai/solutions/medical-healthcare/agent/compliance-training-agent)
- [Documentation Agent](https://ibl.ai/solutions/medical-healthcare/agent/documentation-agent)
- [Knowledge Management Agent](https://ibl.ai/solutions/medical-healthcare/agent/knowledge-management-agent)
- [IT Help Desk Agent](https://ibl.ai/solutions/medical-healthcare/agent/it-help-desk-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [HIPAA](https://www.hhs.gov/hipaa/index.html) — U.S. Department of Health and Human Services. Primary HIPAA guidance for covered entities and business associates.
- [45 CFR Part 164](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164) — Electronic Code of Federal Regulations. The Privacy and Security Rule text analyzed throughout.
- [Office for Civil Rights](https://www.hhs.gov/ocr/index.html) — HHS. Enforcement guidance and breach notification requirements.
- [Cybersecurity Framework](https://www.nist.gov/cyberframework) — NIST. Control structure supporting the Security Rule safeguard mapping.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2's de-identification exercise should fail. Participants attempt Safe Harbor on real-shaped clinical narrative and discover how much identifying detail survives, which is the lesson.
- Module 1 must include logs and prompts explicitly. Organizations map PHI in databases and miss it entirely in AI telemetry, which is where most exposure now sits.
- Use synthetic clinical notes throughout. Real PHI cannot be used in a workshop under any circumstance, and synthetic notes can be built to contain the specific challenges each module needs.
- Have the privacy officer co-deliver. HIPAA application varies by organization and a generic course produces conclusions the privacy office will reject.
- Module 6's context over-assembly is the most common technical violation and the least recognized. Make the audit concrete.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives course cover?

HIPAA does not prohibit AI on PHI; it governs who may receive it and under what terms. This course covers de-identification and why Safe Harbor usually fails on clinical text, when an AI vendor becomes a business associate, Security Rule safeguards mapped to an AI system, and minimum necessary applied to model context and retrieval. It runs 5.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: HIPAA compliance package for one AI use case.

### Who should take HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives?

It is written for Privacy officers and HIPAA compliance staff, Healthcare CIOs and CISOs, Clinical informatics leaders, General counsel and contracting staff. Prerequisites: Familiarity with your organization's HIPAA program; No technical background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for healthcare teams that cannot send work to a public AI tool.

### How do we get access to HIPAA-Compliant AI: PHI, BAAs, and Where the Data Lives?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for healthcare cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Healthcare courses

- [Clinical Documentation with AI: Ambient Notes and Review](https://ibl.ai/solutions/medical-healthcare/course/clinical-documentation-with-ai): Deploy ambient documentation safely — accuracy in clinical language, the attestation requirement, note bloat, and measuring whether it returns clinician time.
- [Medical Coding with AI: ICD-10, CPT, and Denial Prevention](https://ibl.ai/solutions/medical-healthcare/course/medical-coding-with-ai): AI-assisted coding that improves accuracy rather than just speed — code suggestion, documentation gap detection, denial prevention, and staying clear of upcoding.
- [Prior Authorization Automation with AI Agents](https://ibl.ai/solutions/medical-healthcare/course/prior-authorization-automation): Compress the highest-friction administrative process in healthcare — payer requirement lookup, packet assembly, status tracking, and appeal drafting.
- [Patient Education Agents: Health Literacy and Safety](https://ibl.ai/solutions/medical-healthcare/course/patient-education-agents): Patient-facing AI that explains conditions and discharge instructions safely — reading level, language access, scope boundaries, and symptom escalation.
- [AI in Clinical Decision Support: Evidence, Limits, and Liability](https://ibl.ai/solutions/medical-healthcare/course/ai-clinical-decision-support): Deploy clinical decision support responsibly — evidence grounding, automation bias, transparency obligations, and where liability actually lands.
- [When Your AI Becomes a Medical Device: FDA and SaMD](https://ibl.ai/solutions/medical-healthcare/course/fda-samd-when-ai-becomes-a-device): The regulatory boundary between clinical software and a regulated device — the CDS exemption, SaMD classification, and what changes when a model updates.
