Practice Flow
Menu

HIPAA

HIPAA and AI are not in conflict. Unmanaged AI use is.

The risk in most practices is not the tool the owner approved. It is the four in ten healthcare workers who say they know a colleague using AI their organization never sanctioned.

Wolters Kluwer Health, survey of 500+ healthcare workers, 2025


How we work safely

Three rules we hold on every engagement.

01

Tools that operate under a BAA

We work only with AI tools that can operate under a Business Associate Agreement, so patient data stays under the same standards the rest of your practice already follows. Where a workflow would need a tool your practice has not sanctioned, we flag it for whoever governs that decision. We do not sanction tools for you.

02

No patient data in training

No PHI enters a tool during a session. Hands-on work runs on synthetic or de-identified examples, and where a workflow has to be demonstrated in your EHR, it runs against a test patient on a shared screen. Real charts stay on the screens of the people entitled to see them.

03

A written record you can hand to anyone

Every engagement leaves a written record of what was used, what was built and what was found, including the AI already in use that nobody approved. It is written to be read by your compliance lead, your counsel or an auditor without translation.


Shadow AI

Ask your team which AI tools they actually use.

The list will be longer than the one you approved. It usually includes a personal account, an app someone downloaded, and a workaround that started as a favour to a colleague.

None of it is malicious. It is faster, and the person doing it is trying to get through their day. It is also where patient information ends up, in tools with no agreement behind them and no record of what was sent.

What we usually find

  • Personal AI accounts handling work that contains patient information
  • Extensions and downloaded apps nobody reviewed
  • No written policy, and no record of who uses what

What replaces it

  • Business accounts under agreements, with training turned off
  • A sanctioned tool list your whole team can name
  • A written record of what is in use, kept current

We surface what is in use. What gets sanctioned is the practice's decision, and it stays that way.


Where we stop

We are not your auditor and not your counsel.

We design the work so compliance holds, we tell you what we find, and we write it down in language anyone can read. That is the honest boundary of what an AI transformation partner should claim.

Certification, audit and legal sign-off belong to the people you already use for them. Any firm that offers you all of it in one engagement is selling something.


Questions

What practices ask before they start.

Do the AI tools you use operate under a BAA?

Yes. We work only with tools that offer and sign Business Associate Agreements, which holds them to the same standards as any other business associate your practice works with. We confirm that coverage as part of every engagement, against the stack your practice has already sanctioned.

Will patient data touch an AI tool during training?

No. Sessions run on synthetic or de-identified data. Where something has to be shown inside your EHR, it runs against a test patient. Staff then repeat the workflow on real charts at their own stations, under your existing access controls.

My staff are already using AI tools I did not approve. What happens then?

That is the most common thing we find, and finding it is part of the work rather than a problem with your practice. We identify what is actually in use, tell you plainly where the exposure sits, and recommend what to replace it with. What gets sanctioned is your decision, not ours.

Do we get documentation we can show a compliance officer?

Yes. Every engagement produces a written record of the tools used, the workflows built, the training delivered and what we found. It is written in plain English so it can go straight to whoever asks for it.

Our EHR already has AI features built in. Are those covered?

Usually, under your existing agreement with the EHR vendor. Those features are often the fastest thing to turn on, because the agreement is already in place and nobody was ever shown how to use them. A good deal of what we do is exactly that.

Are you our HIPAA auditor?

No, and we will not pretend otherwise. We are not your compliance auditor and we are not your counsel. We design engagements so compliance holds, we surface what we find, and we document it. Sign-off belongs to the people you already trust with it.


Questions about your own setup?

Twenty minutes, and we will talk through what your team is actually using and where the exposure sits. No engagement required to have that conversation.

Book a call