Industries · Medical AI
Compliance for companies putting AI in front of PHI.
Medical AI diligence goes beyond standard HIPAA questions: training data lineage, de-identification claims, downstream model providers, retention, and human review. We handle the compliance program with those questions built in.
Boundary stated plainly: HIPAA compliance does not validate model safety, accuracy, or clinical fitness. This program covers data protection and security; clinical validation and AI governance beyond it are separate obligations.
The six questions every medical AI vendor gets asked.
Our AI/ML data-use review works through each one and leaves you with documented, truthful answers.
Training & evaluation data
What data trains and evaluates your models? Under what agreement was it obtained, and does that agreement actually permit model development? We document the lineage before a customer's counsel asks.
De-identification claims
"It's de-identified" only counts if it meets the Safe Harbor or Expert Determination standard — and re-identification risk grows as datasets combine. We review what your claims rest on and how they're documented.
PHI access paths
Which systems, employees, and contractors can reach PHI — including through fine-tuning pipelines, evaluation notebooks, and debugging tools? Access review scope must include the ML stack, not just production.
Downstream model providers
If PHI reaches a hosted foundation-model API, that provider is in your compliance story: BAA availability, retention behavior, and training-use terms all need verification, not assumption.
Retention & deletion
Prompts, outputs, embeddings, and logs accumulate PHI in places deletion workflows often miss. We map retention across the AI pipeline and align it with your commitments.
Human review & audit logging
Who sees model inputs and outputs for QA or labeling, under what controls? Is model activity logged well enough to investigate an incident? Both show up in customer diligence and in audits.
HIPAA program + AI-aware scope.
The core program is the same disciplined work every business associate needs — risk analysis, policies, training, vendor and BAA management, incident readiness, and SOC 2 controls. For medical AI companies we extend the scope where it matters:
- PHI data-flow inventory that includes training pipelines, evaluation sets, embeddings, prompts, and model logs
- Subprocessor review covering foundation-model and GPU providers, with BAA and retention verification
- Access reviews that include notebooks, labeling tools, and ML infrastructure
- A written AI data-use summary you can hand to customer security teams
Broader AI governance — model risk management, bias evaluation, clinical validation — is beyond a HIPAA/SOC 2 program. We say so explicitly, and can point you to appropriate specialists rather than stretching claims.
Recommended package.
Healthcare Trust Launch
Healthcare SaaS, medical AI, digital health, telehealth, and healthcare infrastructure startups that need both frameworks.
$14,500 implementation
+ $1,250/month ongoing
Plus the independent CPA audit fee, quoted separately. $1,500 discount for annual prepayment of the ongoing service.
Target: 8–14 weeks
Timelines are targets, for HIPAA readiness and SOC 2 Type 1 readiness, assuming a functioning cloud environment and responses within two business days; a Type 2 report additionally requires a 3–12 month observation period plus audit and reporting time.
Included
- Everything in HIPAA Foundations
- Everything in SOC 2 Readiness
- Unified control library mapping HIPAA safeguards to SOC 2 controls
- Deduplicated evidence plan
- Healthcare data-flow and subprocessor review
- BAA coverage review for cloud and SaaS vendors
- Minimum-necessary and access-control workflow
- + 9 more — see full inclusions
The AI/ML data-use review is included in the combined program. See the full program →
Medical AI FAQ
Does HIPAA compliance mean our model is safe or accurate?
No — and we will never imply it does. HIPAA governs how you protect and use health information; it does not validate clinical performance, model safety, or fitness for any medical purpose. Model evaluation, clinical validation, and (where applicable) FDA considerations are a separate discipline and separate obligations. Our program covers the data-protection side and is explicit about that boundary.
Can we train models on customer PHI?
Only within what your BAAs and customer agreements actually permit — many prohibit it or require de-identification first. This is a contract-and-data-governance question we review explicitly in the AI/ML data-use review, and where the answer is legally uncertain we recommend qualified counsel rather than guessing.
Our LLM provider says it's HIPAA-eligible. Enough?
It's a start, not an answer. You still need the BAA actually executed, the eligible configuration actually enabled (retention, logging, training-use settings), and your own controls around what goes into prompts. We verify configuration, not marketing pages.
Do buyers of medical AI really ask for SOC 2?
Consistently — often alongside AI-specific questionnaires about training data and model governance. The combined program builds the SOC 2 evidence base and a defensible written story for the AI questions, which is frequently what separates you from competing vendors in diligence.
Get defensible answers before diligence asks.
Contact us — we'll map your AI data flows, likely gaps, and a realistic timeline.