All regulations
United States

HIPAA

Applies to AI systems that process protected health information, requiring safeguards for privacy and security wherever an AI tool touches patient data.

Who it applies to

  • Covered entities and business associates using AI
  • AI vendors processing PHI on behalf of healthcare organisations
  • Clinical, operational and administrative AI use cases

Core obligations

  • Apply administrative, physical and technical safeguards to PHI
  • Sign Business Associate Agreements with AI vendors
  • Log access and disclosures of PHI
  • Notify breaches under the HIPAA Breach Notification Rule

How Vigil24 helps

  • Flags AI tools handling PHI across your workforce
  • Tracks BAAs and vendor safeguards
  • Produces HIPAA-aligned access and breach evidence