AI Compliance Intelligence

HIPAA

U.S. Department of Health & Human Services (HHS) · privacy-health

IssuerU.S. Department of Health & Human Services (HHS)
Categoryprivacy-health
Reviewed

All AI Compliance frameworks → · Official source →

Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.

Editorial overview

The Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules regulate protected health information (PHI) held by covered entities and their business associates in the United States.

Scope

  • Privacy Rule: uses and disclosures of PHI
  • Security Rule: administrative, physical, and technical safeguards for electronic PHI
  • Breach Notification Rule: notification obligations after certain breaches

Relevance to AI products

Healthcare AI products that create, receive, maintain, or transmit PHI typically require Business Associate Agreements and Security Rule-aligned controls. HIPAA does not provide a government-issued “HIPAA certified” seal for AI vendors; compliance is a legal obligation assessed against the Rules.

Limitations & caveats

  • Marketing claims of “HIPAA compliant” should be validated against BAAs, architecture, and legal review
  • De-identification standards (Safe Harbor / Expert Determination) matter for training and analytics use cases

Related frameworks

Related industries

Related technologies

Related glossary terms

Why it matters

HIPAA is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.

Last reviewed

Sources

Correction request

If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.

All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →