The Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules regulate protected health information (PHI) held by covered entities and their business associates in the United States.
AI Compliance Intelligence
HIPAA
U.S. Department of Health & Human Services (HHS) · privacy-health
All AI Compliance frameworks → · Official source →
Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.
Editorial overview
Scope
- Privacy Rule: uses and disclosures of PHI
- Security Rule: administrative, physical, and technical safeguards for electronic PHI
- Breach Notification Rule: notification obligations after certain breaches
Relevance to AI products
Healthcare AI products that create, receive, maintain, or transmit PHI typically require Business Associate Agreements and Security Rule-aligned controls. HIPAA does not provide a government-issued “HIPAA certified” seal for AI vendors; compliance is a legal obligation assessed against the Rules.
Limitations & caveats
- Marketing claims of “HIPAA compliant” should be validated against BAAs, architecture, and legal review
- De-identification standards (Safe Harbor / Expert Determination) matter for training and analytics use cases
Related frameworks
Related industries
Related technologies
Related glossary terms
Why it matters
HIPAA is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.
Last reviewed
Sources
Correction request
If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.
All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →