JFly.Ai article on the HIPAA questions to ask before letting AI touch patient data.

JFly.Ai Book a call

Local & Health

The HIPAA Questions to Ask Before You Let Any AI Touch Patient Data

A signed BAA, a written no to training on your patient data, and the red flags that turn a vendor demo into a penalty. Ask these first.

What you'll walk away with

  • No signed BAA, no deal. Any vendor whose AI touches protected health information must sign a Business Associate Agreement, with zero exceptions.
  • Ask in writing whether your patient data trains their model. The answer must be no. PHI feeding a training set is a line you do not cross.
  • The penalties are real. The willful-neglect tier runs into the millions per year, and small clinics are not exempt.
  • Know the safe path your PHI takes versus the landmine path, and never let an AI give unlicensed medical advice to a patient.
  • Compliance is a design decision made before launch, not a disclaimer added after. The safe setup and the shortcut look identical until the audit.

The most dangerous sentence in a HIPAA conversation is the vendor saying trust me, we are compliant. Compliant is not a vibe. It is a signed document and a set of specific answers, and if a vendor is rushing you to a demo before they will give you those answers, that is the whole tell.

We run three companies on the same system we build for clients, and the fastest way we have found to separate a real vendor from a slick one is to ask five plain questions and watch how fast they answer. A practice or med-spa owner wants the front-desk and intake time back. Fair. But the way you get it back safely is boring, documented, and settled before a single patient record moves. Here is what to refuse to sign, and what to demand, before any AI touches a chart.

01

Will you sign a Business Associate Agreement? No BAA, walk away.

This is the first and non-negotiable question. Any vendor whose product creates, receives, maintains, or transmits PHI on your behalf is a business associate under HIPAA and must sign a BAA. Missing BAAs are one of the most common findings in enforcement actions against small practices. If a vendor hedges, delays, or offers a demo instead of a signed BAA, that is your answer. Walk.

The JFly move

We treat the signed BAA as the price of entry before anything connects, not a form we chase later. Every vendor in your setup that touches PHI has a current agreement on file, period.

02

Does my patient data train your model? The answer must be no.

Get this in writing. Many general AI services reserve the right to use inputs to improve their models. For PHI, that is disqualifying. Your patients' data must not become part of anyone's training set. The safe answer is a clear, contractual no-training-on-your-data commitment, backed by the technical setup to enforce it, not a friendly verbal assurance on a sales call.

Before you connect anything

The vendor-vetting checklist

  • Signed BAA on file Must be yes
  • No training on your PHI, in writing Must be yes
  • PHI path documented and encrypted Must be yes
  • Scope limited to logistics, no clinical advice Must be yes
  • Access controls and audit log Must be yes

Any no is a stop, not a negotiation. One missing answer sends you back to the vendor, not forward to a launch.

How to use this: a practical operator checklist grounded in real HIPAA obligations, the BAA requirement, encryption, and access controls. General guidance, not legal certification. Confirm your setup with your compliance advisor.
The JFly move

We select and configure the AI layer specifically so patient data is never used for training, and we show you where that is locked in the contract and the config, not just claimed on a sales call.

Compliant is not a vibe. It is a signed BAA and a written no to training on your patient data. If a vendor offers a demo before they will give you those, that is your answer.
JJ Walker, Founder, JFly.Ai

03

Where exactly does my PHI go, and who can see it?

You should be able to draw the path your patient data takes: what is stored, where, for how long, who has access, and how it is encrypted in transit and at rest. If a vendor cannot draw that map plainly, they either do not know or do not want you to know. The safe path keeps PHI inside a controlled, BAA-covered environment. The landmine path routes it through a consumer service with no protections.

The shape of the risk

Where your PHI goes: the safe path vs the landmine

Patient data captured Safe path BAA-covered AI environment Encrypted storage, access controlled Used only for logistics Safe ✓ Landmine path Consumer AI service, no BAA Inputs may train the model, no controls Hazard ⚠
What this is: a conceptual data-flow contrast, not a specific product diagram. The safe path is the standard to build to. The landmine path is the one to refuse. Confirm your own map with your compliance advisor.
The JFly move

We diagram exactly where your PHI travels in your setup, the safe path versus the path we refuse to build, so you can see the data flow instead of trusting a promise about it.

04

Understand the penalty, so the risk is not abstract.

HIPAA penalties are tiered by culpability and inflation-adjusted every year. The willful-neglect tier, where a violation is known and not corrected, carries per-violation minimums in the tens of thousands and annual caps that reach into the millions. Small solo and clinic practices have absorbed six-figure fines for exactly the failures on this list: missing BAAs, no risk assessment, mishandled access. This is not a big-hospital problem, and it is general information rather than legal advice.

Side by side

Compliant setup vs the shortcut that triggers a penalty

What we look atCompliant setupThe shortcut
BAASignedNone or vague
Model training on PHIContractually noUnspecified
Data pathDocumented, encryptedUnknown, consumer service
ScopeLogistics onlyDrifts into clinical advice
Penalty exposureDiligence on recordWillful-neglect tier
How to read it: a framing table anchored to real HIPAA obligations and the real tiered penalty structure. Penalty language is kept to tiers and ranges, not a single per-incident figure. General information, not legal advice; confirm with your compliance advisor.
The JFly move

We build the setup so the willful-neglect trap never applies: agreements in place, data handling documented, and a clear record that you did the diligence, so a shortcut never becomes a penalty.

05

Never let AI give unlicensed medical advice.

An intake bot answering scheduling questions is fine. An AI drifting into what sounds like clinical guidance to a patient is a different and serious problem. The line is bright: automation handles logistics, licensed humans handle medicine. A setup that lets AI answer a symptom question as if it were a provider is a liability you do not want, separate from HIPAA entirely.

The JFly move

We scope the AI to logistics only, scheduling, intake forms, reminders, and routing, with hard guardrails against anything that reads as clinical advice, and a clean handoff to your staff for anything medical.

06

Lock it down before deployment, not after the first incident.

The compliant setup and the shortcut look identical on launch day. The difference only shows up under audit or after a breach, and by then the choice is made. The questions on this list are a pre-deployment checklist, not a post-incident cleanup. The practices that stay safe settle all of this before a single patient record moves.

The JFly move

We run the vetting before anything goes live: BAA signed, no-training confirmed, data path mapped, scope limited to logistics. Deploy after the diligence, not before it.

None of this is a reason to avoid AI in a practice. The front-desk and intake hours are real, and getting them back is worth doing. It is a reason to make one decision up front: settle the BAA, the no-training answer, the data path, and the scope before you connect anything. Do that, and the same AI that scares you becomes the quietest, most boring part of your week. Skip it, and the demo you loved becomes the finding an auditor reads back to you.

Questions we get

Is AI HIPAA compliant for medical practices?
AI can be used compliantly, but no AI is compliant by default. Compliance depends on a signed Business Associate Agreement with any vendor that touches PHI, a contractual guarantee that your patient data does not train their model, a documented and encrypted data path, and scope limited to logistics rather than clinical advice. Miss any of those and the same AI becomes a liability.
What is a BAA and why does it matter for AI vendors?
A Business Associate Agreement is the contract HIPAA requires whenever a vendor creates, receives, maintains, or transmits protected health information on your behalf. Any AI service handling patient data is a business associate and must sign one. Missing BAAs are among the most common findings in enforcement actions against small practices, so no signed BAA means no deal.
How big are HIPAA penalties for a small practice?
Penalties are tiered by culpability and are inflation-adjusted annually. The willful-neglect tier carries per-violation minimums in the tens of thousands with annual caps reaching into the millions, and small solo and clinic practices have absorbed six-figure fines for missing BAAs and risk assessments. It is not only a large-hospital risk. This is general information, not legal advice.
Can an AI receptionist answer patients' medical questions?
It should not. The safe line is that automation handles logistics, scheduling, intake, reminders, and routing, while licensed humans handle anything clinical. An AI that answers a symptom question as if it were a provider creates liability separate from HIPAA, so the setup should have hard guardrails and a clean handoff to staff for anything medical.

Let's Build Your AiOS.

Book a call and we will help you deploy AI without a HIPAA landmine: BAA signed, data path mapped, scope locked.

Book a call

Blueprint → Build → Partner · Denver + remote