HIPAA

Safeguard PHI without sending it anywhere.

Compiled inspects communications and governs clinical AI agents inside your environment, so protected health information never leaves your control. Real-time, auditable, and aligned to your HIPAA safeguards. BAA available.

HIPAA Security RulePHI safeguardsRisk analysisBAA availableClinical AI governanceIn-tenantZero data egressAudit trail
0
Bytes of PHI transmitted to Compiled or any vendor cloud
In-tenant by construction
BAA
Business Associate Agreement available
Required for HIPAA-covered use cases
Real-time
Inline governance of clinical AI agent actions
Before the action completes
164.308
Security Rule section — administrative safeguards including risk analysis
45 CFR Part 164
Regulatory landscape

The rules and what they require

HIPAA's Security Rule and Privacy Rule together establish the minimum technical and administrative safeguards required to protect electronic protected health information. The introduction of AI agents into clinical workflows — agents that access EHR systems, scheduling platforms, and patient records — creates new risk categories that the existing HIPAA risk analysis obligation requires covered entities to assess and address.

01
45 CFR 164.308 — Security Rule, Administrative Safeguards

Risk analysis and risk management

Section 164.308(a)(1) requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. This is not a one-time exercise — it is an ongoing obligation that must be updated when new technology, including AI agents, is introduced into the environment. The HHS Office for Civil Rights has consistently cited inadequate risk analysis as the root cause in enforcement actions.

  • Documented risk analysis covering all systems that create, receive, maintain, or transmit ePHI
  • Assessment of risks introduced by AI agents accessing EHR and scheduling systems
  • Risk management plan with implemented security measures to reduce identified risks
  • Ongoing review and updates as the environment changes
02
45 CFR 164.312 — Security Rule, Technical Safeguards

Access controls, audit controls, and transmission security

Section 164.312 requires technical safeguards including access controls limiting ePHI access to authorized persons and software, audit controls that record and examine access activity, and transmission security ensuring ePHI is not intercepted in transit. AI agents that query EHR systems, retrieve patient records, or initiate scheduling actions are subject to these technical safeguard requirements — and most organizations have not extended their audit and access-control infrastructure to govern agent behavior.

  • Access controls on AI agent permissions to ePHI-containing systems
  • Audit logs of agent access to patient records and scheduling data
  • Transmission security: ePHI not transmitted beyond the covered entity's environment
  • Automatic logoff and session controls for agent sessions accessing ePHI
03
Business Associate Agreements

Vendor obligations and BAA coverage

Any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate and must execute a BAA. A surveillance vendor that processes communications containing PHI — or an AI governance tool that intercepts agent actions involving patient data — is a business associate. The architecture of the tool determines whether PHI is actually transmitted: if inspection happens inside the covered entity's own environment, the ePHI is never transmitted to the vendor.

  • BAA required for any vendor whose tool processes or accesses ePHI
  • Compiled BAA available for covered-entity deployments
  • In-tenant architecture means PHI is never transmitted to Compiled — eliminating a category of BAA exposure
  • Documented data flows demonstrating where ePHI is processed and by whom
Risk reality

The clinical AI governance gap

Healthcare organizations are deploying AI agents at speed: patient intake bots, scheduling agents, clinical decision-support tools, and care-coordination assistants that reach directly into EHR systems and patient records. These agents operate faster than any human review and against no real-time control. When an agent retrieves or outputs PHI improperly — sending it to an unauthorized recipient, including it in a response that is logged outside a secure environment, or sharing it across a boundary that violates the minimum-necessary standard — the violation has already occurred by the time it appears in an audit log.

HIPAA's risk analysis obligation requires organizations to assess these risks before deploying AI systems that touch ePHI. A risk analysis that identifies the risk without implementing a technical control to address it is an incomplete risk management program. The OCR's enforcement history shows that inadequate risk analysis, not merely breach of PHI, is independently actionable.

The governance challenge is compounded by the architecture of most AI surveillance tools: they process communications in a vendor cloud, which means PHI in those communications is being transmitted to a business associate. In-tenant inspection removes this exposure structurally rather than contractually.

Risk scenarios

Where clinical AI creates HIPAA exposure

Agent retrieving PHI for an unauthorized requesterBlock

A clinical scheduling agent is queried by an internal tool that is not authorized to access patient scheduling data. The agent would retrieve a patient's appointment history and diagnosis context and return it in the response. Compiled intercepts the request before the agent action completes, blocks the retrieval, and logs the attempt with the policy that was matched.

PHI appearing in an unencrypted communication channelFlag

A care-coordination agent generates a message summary that includes a patient's name, date of birth, and diagnosis and routes it to a general-purpose communication channel rather than the secure messaging system. Compiled recognizes the PHI pattern in the outbound message and flags it before it is sent, routing a finding to the compliance queue.

Minimum-necessary standard violationBlock

A patient intake agent responds to an administrative query with a full patient record — including clinical notes, prior authorizations, and insurance information — when only the appointment date was needed. Compiled detects that the response scope exceeds the authorization context of the request and blocks it, preventing a minimum-necessary violation.

EHR access outside normal operating hoursFlag

An AI agent accessing EHR data initiates a bulk patient record query outside normal clinical hours and outside its defined operational scope. The behavioral pattern — volume, timing, and scope mismatch against normal access patterns — is flagged in real time, before the records are retrieved or transmitted.

How Compiled works

PHI never leaves your environment

Compiled deploys inside your Azure tenant or on-premises environment. Every communication and every AI-agent action involving patient data is inspected inside your boundary. PHI is never transmitted to Compiled or to any vendor-operated infrastructure.

In-tenant by construction

PHI is inspected inside your own environment. No transmission to a vendor cloud means no ePHI exposure through the surveillance tool itself — and a structurally simpler BAA conversation.

Real-time agent governance

Compiled sits inline in the path of AI agent actions. Every action that touches patient data receives a verdict — allow, flag, or block — before it completes. A violation is prevented, not discovered after the fact.

Minimum-necessary enforcement

Antibodies can be configured to your defined scope policies. An agent action that retrieves more PHI than the context authorizes is recognized as a policy violation, not just an anomaly.

Full audit trail

Every inspection decision is logged in your environment with a timestamp, policy attribution, and verdict. The audit trail required by the Security Rule's audit control safeguard is generated automatically.

BAA available

A Business Associate Agreement is available for all covered-entity deployments. The in-tenant architecture ensures that Compiled does not create, receive, maintain, or transmit ePHI on your behalf — but we provide a BAA to cover any ambiguity.

Your own clinical policies

Compile your own PHI access policies, minimum-necessary standards, and clinical AI usage guidelines into antibodies. Your specific restrictions become enforced recognizers, not a checklist dependent on post-hoc review.

Audit readiness

What you produce for an OCR investigation or audit

OCR investigations and HIPAA audits typically focus on whether the covered entity had appropriate safeguards in place and whether those safeguards were operating. Compiled produces a structured record from inside your own environment that documents both.

TimestampUTC timestamp of each agent action or communication involving patient data, to the millisecond
Agent identityThe specific AI agent or system that initiated the action, recorded in the finding
Action scopeWhat patient data was accessed, requested, or output — preserved in the finding inside your environment
VerdictAllow, flag, or block — rendered before the action completed, demonstrating a real-time control was in place
Policy attributionThe specific HIPAA safeguard section or your own clinical policy that the finding matched
Reviewer outcomeIf flagged, the compliance team's review decision and disposition, logged in your environment
Risk analysis supportAggregate finding data exportable to support your ongoing risk analysis documentation under 45 CFR 164.308(a)(1)
FAQ

Questions from privacy and compliance officers

Chat with usBook a 30-minute walkthroughHealthcare