Compliance / HIPAA

PHI does not belong in a prompt. Prove where it went.

A discharge summary pasted for rewording. A clinic call transcribed by a bot on someone's phone. Shadow AI in healthcare is not hypothetical, it is Tuesday. The question compliance owns: which tools, which workflows, and what do the vendors' terms actually say.

Evidence support, not legal advice. Whether any specific flow implicates HIPAA duties is for your privacy officer and counsel; the audit supplies the observed facts they triage from.
The exposure paths

How PHI reaches AI vendors nobody vetted

Three recurring paths, each innocent at the point of action, each producing the same compliance question.

The paste path

Clinical notes, referral letters and patient emails pasted into chatbots for drafting help. Names, conditions and dates travel together, which is what makes it PHI rather than prose.

The transcription path

Meeting bots and dictation apps hear entire consultations. Intake breadth makes this the highest-exposure path: it captures what nobody would knowingly paste.

The embedded path

AI features arriving inside scheduling, billing and communication SaaS the organization already uses. The vendor was assessed; the feature came later, on its own subdomain.

The common denominator: no BAA, no risk analysis, no entry in any vendor register, because nobody upstream knew the flow existed. Discovery is the control that unlocks every other control.

Triage

Reading an audit report with HIPAA eyes

The report's flags map to a healthcare triage order. This is the pass a privacy officer makes on page two.

Flag on a found tool
Why it matters here
Typical first move
Transcription category
Whole-conversation intake: consultations, case reviews, patient calls potentially captured.
Identify the users and workflows same week; verify consent practices and vendor terms.
Trains by default
Content entered may become training data, beyond any deletion request's reach.
Block for clinical workflows; migrate need to a contracted alternative.
Terms not stated
No commitments to rely on, and the majority case at 85.5% of tools.
Treat as unvetted; no PHI-adjacent use until the vendor answers or an enterprise agreement exists.
High sovereignty flag
Processing under jurisdictions your counsel flags complicates every downstream question.
Escalate to legal with the tool's user list attached.
High user counts in clinical segments
A workflow, not an individual: a ward or department has normalized the tool.
Department-level conversation plus a sanctioned replacement, not individual discipline.

The audit itself is triage-friendly: it reads hostnames, identities and timestamps, never note content. Uploads are discarded after the run; reports are deletable before the 90-day expiry.

Worked scenario

A clinic group's thirty-day look

A multi-site outpatient group, FortiGate at each site, FSSO on staff segments. Sample data; the shape repeats across healthcare audits.

What the export showed

  • Thirty days of web-filter logs, all sites: 27 AI tools across staff segments.
  • Two consumer chatbots with 160+ combined users, one "medical scribe" trial in a single department, one dictation app on roaming laptops.
  • The scribe's terms: silent on training. The dictation app: trains unless opted out.

What compliance did with it

  • Dictation app blocked same week; scribe trial paused pending a BAA-backed contract, which the vendor ultimately signed.
  • Chatbot demand answered with an enterprise assistant under negotiated terms, then the consumer domains blocked.
  • The report PDF filed with the risk analysis; re-audit scheduled quarterly. The FortiGate guide walks the identical mechanics.

Note what did not happen: no individual clinician was disciplined for the discovery itself. Shadow AI in clinical settings is nearly always workflow pressure, and the durable fix is a sanctioned outlet plus measurement.

Compliance artifacts

What the audit contributes to the HIPAA file

Generic-safe mapping to the documents healthcare compliance teams already maintain.

Risk analysis input

An observed inventory of AI flows, dated per period, is exactly the kind of "reasonably anticipated" evidence risk analyses are built from.

Vendor and BAA queue

Tools in real use without agreements surface with user counts attached, which is the prioritization the BAA backlog needs.

Incident scoping

When a concern arises, a targeted window export answers which tools and which identities in an afternoon, before panic sets the narrative.

Training content

The report's real findings, anonymized, make workforce training concrete: these tools, these categories, this is why the sanctioned list exists.

Insurer and questionnaire answers

Cyber-liability forms now ask about AI usage controls. "Quarterly log-based audit, reports on file" is a one-line answer with attachments.

The trend narrative

Quarter-over-quarter deltas, fewer unsanctioned tools, rising sanctioned share, document a functioning program rather than a one-off cleanup.

See what a finished audit looks like

Three pages of sample data: flags, verdicts, per-identity rows and the control evidence statement your file wants. No signup to read it.

Open the sample report
Healthcare specifics

Details that change the read in clinical settings

Shared workstations blur identity

  • Nursing-station machines log as devices or IPs, not people. Read those rows as workflow evidence, which is usually the actionable level anyway.

Guest and patient Wi-Fi is its own lane

  • Patient-network AI usage is expected and largely out of scope. Segment-level attribution keeps it from polluting staff findings.

Legitimate clinical AI exists

  • Sanctioned diagnostic and documentation AI under proper agreements is the goal state, not a finding.
  • The sanctioned split keeps the distinction visible: contracted tools on one side, shadow arrivals on the other.

The audit does not read notes

  • Hostname-level evidence means no PHI enters the audit itself: no prompt content, no URLs beyond the hostname, nothing to add to your PHI inventory.
FAQ

HIPAA and shadow AI questions

Is staff use of AI chatbots a HIPAA violation?

That determination belongs to your privacy officer and counsel per flow. What the audit settles is the factual layer: which tools, which identities, what the vendor terms said on a given date.

Do AI vendors need BAAs?

Vendors touching PHI in a covered workflow generally enter that conversation, and shadow tools by definition never had it. The report's user counts prioritize which vendors to approach first.

What is the riskiest AI category in healthcare?

Transcription and dictation, because intake is total: whole consultations rather than selected pastes. Triage those rows first.

Does uploading hospital logs expose PHI?

The audit reads hostnames, identities and timestamps; URL paths are dropped at parse, uploads are discarded after the run, and reports are deletable early. That description is written for your review packet.

How often should healthcare organizations audit?

Quarterly as the floor, monthly where tool churn is high. Insurer questionnaires and risk-analysis refreshes both consume the same reports.

What about clinicians' personal devices?

Off-network use is outside log evidence and inside policy and training. State the scope; the on-network findings usually supply the urgency for both.

Find the flows before the questionnaire does

Thirty days of logs, one upload, and your privacy officer works from facts. The free preview shows the totals today.

Run the free audit