The HIPAA-Compliant AI Playbook for Small Practices

Practical mapping of 45 CFR 164 to common AI use cases, remediation, and priorities.

Top 7 AI use cases (ranked by ROI vs risk)

  1. Clinical scribe / documentation assistant — 10x ROI, high PHI exposure. First priority: BAA + Zero Data Retention or on-prem model.
  2. Patient intake automation (forms & triage) — High ROI, medium risk. Requires validation + safe storage.
  3. Billing & RCM automation (no PHI in prompts) — High ROI, low-medium risk. Keep PHI out of the prompt context.
  4. Telehealth triage assistant (redact before model) — 2–3x ROI, high risk. Redaction pipeline required before any PHI hits the model.
  5. Patient communication drafts (secure pipeline, no PHI) — Moderate ROI, low risk when de-identified.
  6. Knowledge-base summarization (de-identified corpora) — 1–2x ROI, low risk. Works well with off-the-shelf models.
  7. Image-assist diagnostics — 4–10x ROI, very high risk. Requires clinical validation, governance, and FDA SaMD classification review.

45 CFR 164 mapped to practical AI controls

Rule sectionRequirementAI control
164.308(a)(1)Risk analysisAI data flow diagram + retention policy review
164.308(a)(5)Workforce trainingStaff AI-use policy + annual tabletop exercise
164.312(a)(2)(iv)EncryptionConfirm TLS in transit + AES-256 at rest for all AI vendor storage
164.312(c)(1)Integrity controlsSigned BAAs + audit logging on AI outputs
164.312(e)(2)(ii)Encryption in transitHTTPS-only endpoints; no PHI over unencrypted channels
164.314(a)(1)BAA with business associatesBAA required before any AI vendor touches PHI
164.316(a)Policies & proceduresWritten AI acceptable-use policy, updated annually

Quick-start checklist (30 minutes)

  1. List every AI tool staff is using today
  2. For each tool, confirm whether a BAA exists or can be signed
  3. Identify PHI touchpoints (EHR exports, uploads, copy-paste into AI prompts)
  4. Block consumer AI tools (ChatGPT free, Gemini free) on practice endpoints via policy + DNS filter
  5. Sign BAA or migrate to a vendor with BAA + Zero Data Retention for any PHI use case

Want us to walk through this with you? Book a call.