Healthcare practices need PHI separation before AI
Healthcare practices should separate protected health information from business data before deploying AI because HIPAA’s Minimum Necessary Standard applies when a tool queries data on a staff member’s behalf. Under 45 CFR 164.502(b), access to PHI must be limited to what a task requires, and an AI tool with broad access to patient records can exceed that limit even if the system permits it. IBM’s 2025 Cost of a Data Breach Report found that 97% of breached organizations with an AI-related security incident said they lacked proper AI access controls.
The recommended process starts with finding where PHI actually lives, including spreadsheets, shared drives, email threads and channel messages. Data should then be classified and tagged by sensitivity and audience so systems can distinguish clinical records, financial data and general internal content before access rules are applied.
Separation depends on controls at the data layer, including environment segmentation, row-level and role-based permissions, de-identification, redaction and data loss prevention tooling. De-identified data can support analytics or model use when identity is not needed, but only if it meets HIPAA’s de-identification standard.
Any platform that creates, receives, maintains or transmits PHI should be covered by a Business Associate Agreement before going live. Consumer AI tools without a BAA, including free and standard ChatGPT tiers, should not receive patient notes or other protected data.