Key takeaways
- HIPAA applies to protected health information (PHI) handled by covered entities — most dental and medical practices — and by their business associates, a category that can include an AI vendor.
- HHS.gov defines a business associate as anyone who creates, receives, maintains, or transmits PHI on a covered entity's behalf — and specifically calls out AI chatbots that touch patient PHI as an example.
- If an AI tool touches PHI, you generally need a signed Business Associate Agreement (BAA) with that vendor before you use it that way — not after.
- Free, consumer-grade AI tools typically will not sign a BAA, which usually rules them out for anything involving real patient information.
- This guide is general information, not legal advice — HIPAA compliance decisions should involve your compliance officer or attorney.
A front-desk employee at a dental office types a patient's name and treatment notes into a free AI tool to draft an appointment reminder. It feels like a two-minute convenience. Under HIPAA, it can also be a reportable exposure of protected health information — because that free tool almost certainly isn't a signed business associate, and PHI touched by a non-associate outside a permitted use is exactly the kind of thing HIPAA exists to prevent.
This guide walks through the practical HIPAA rules that apply when a dental or medical office starts using AI — what counts as PHI, when you need a Business Associate Agreement, and how to tell which AI tools are even eligible to sign one.
What counts as PHI in an AI context
Protected health information is any information that relates to a patient's health condition, treatment, or payment for care, and that can be tied back to that specific patient. In a dental or medical office, that's a wider net than most staff assume — it's not just diagnosis codes and lab results. Patient names paired with appointment dates, treatment notes, insurance details, images, and even scheduling notes referencing a specific condition all count as PHI once they're connected to an identifiable person.
That means a lot of everyday front-office tasks — drafting a follow-up email, summarizing a visit note, transcribing a voicemail — touch PHI the moment they mention a real patient by name alongside any health-related detail.
Business associates and when a BAA is required
HHS.gov defines a business associate as a person or company that performs functions or services on behalf of a covered entity that involve creating, receiving, maintaining, or transmitting PHI. HHS's own guidance specifically names AI as an example of this: a third-party AI chatbot that handles symptom assessment, medical reminders, or appointment scheduling involving a patient's PHI is called out as a business associate that requires an agreement.
In practice, that means: if an AI vendor's tool is going to touch real patient PHI — not a hypothetical, redacted example, but actual patient names and health details — your practice needs a signed Business Associate Agreement (BAA) with that vendor before that use starts, not as a formality afterward.
Unless you've specifically confirmed a vendor will sign a BAA and one is in place, assume their tool cannot be used with real PHI. Most general-purpose, free-tier AI tools fall into this category — treat that as the default, not the exception.
What to check before you use an AI tool with patient data
| Question | Why it matters |
|---|---|
| Will the vendor sign a Business Associate Agreement? | If no, the tool cannot legally be used with real PHI, regardless of how it's configured |
| Does the BAA cover the specific product tier you're buying? | Some vendors offer a BAA only on enterprise or healthcare-specific tiers, not the standard business plan |
| Is patient data used to train the vendor's models? | A BAA should explicitly prohibit this — confirm it's addressed, not just implied |
| Where is the data stored, and for how long? | Retention and location terms affect your own breach-notification obligations |
| Who has access to logs of what was typed into the tool? | Support staff at the vendor may be able to see prompts — the BAA should describe their access controls |
This overlaps closely with general AI vendor vetting — see our full AI vendor security checklist for the broader 20-question version that applies beyond healthcare specifically.
Ways to use AI without touching PHI at all
Plenty of useful AI tasks in a dental or medical office don't need to touch a single real patient record:
- Drafting general patient-education content (a handout on post-extraction care) with no patient names attached
- Writing internal training materials or staff scripts
- Summarizing publicly available clinical guidelines for staff reference
- Drafting a marketing email or social post with no patient information in it
- Building a scheduling template or intake form structure — the blank form, not filled-in patient responses
When a task requires real patient information to be useful — summarizing an actual visit note, drafting a specific patient's reminder — that's the moment to confirm you're using a tool with a signed BAA, or to have a staff member do the task without AI involvement.
Human review still matters
Even with a BAA in place, AI-drafted content that will reach a patient — an appointment reminder, a billing explanation, an educational summary — should be reviewed by a person before it goes out. AI tools can misstate a treatment detail, get a date wrong, or phrase something in a way that reads as a clinical recommendation it wasn't meant to be. See our guide on human review for AI-generated content for a workable review process.
Dental practices and medical clinics have different exposure points
A dental practice's highest-exposure moments tend to be scheduling, treatment-plan summaries, and insurance pre-authorization drafts. A medical clinic's tend to add clinical documentation, lab result summaries, and referral letters into the mix — a wider surface area of PHI moving through daily workflows. Either way, the underlying rule is the same: no BAA, no real PHI, no exceptions. See our industry pages for dental practices and medical clinics for how we tailor this for each setting.
Training front-office and clinical staff
Most HIPAA-and-AI exposure in a dental or medical office doesn't come from a deliberate decision — it comes from a front-desk employee or a clinical assistant reaching for whatever tool is fastest, the same way they'd reach for a search engine. That means the training that matters most isn't a slide deck on HIPAA law; it's a short, specific walkthrough of which tools are approved for real patient data and which aren't, repeated at onboarding and again whenever a new tool gets added to the approved list.
A workable training session covers three things in under fifteen minutes: what counts as PHI in the tasks this specific role handles day to day, which AI tools (if any) are approved for that data, and who to ask when something doesn't clearly fit either category. Staff who've never thought about AI as a HIPAA question tend to pick this up quickly once it's framed around their actual daily tasks rather than the law in the abstract — a concrete example from their own workday sticks far better than a general legal explanation ever will.
Questions worth asking before you sign with an AI vendor
Beyond the BAA itself, a few follow-up questions tend to reveal how seriously a vendor takes healthcare data specifically, rather than treating it as one data type among many:
- Does the vendor have experience working with other dental or medical practices, or is healthcare a new market for them?
- Is the BAA a standard, reviewable document, or does it require lengthy custom negotiation for a small practice?
- What happens to PHI already in the system if your practice cancels the contract — is it deleted, and on what timeline?
- Does the vendor's staff undergo any HIPAA-specific training themselves?
A vendor that answers these clearly and has healthcare-specific documentation ready tends to be a safer bet than one that treats the question as unusual or needs to escalate it to someone unfamiliar with healthcare data.
Common mistakes
- Assuming "HIPAA compliant" marketing language means a BAA exists. Ask for the actual signed agreement — don't rely on a badge on the vendor's website.
- Using a free tier "just to test it out" with real patient data. Testing with real PHI on an unsigned tool is still an exposure, even if it's temporary.
- Forgetting that scanned images and voice transcripts count. PHI isn't only typed text — a photo of a chart or a recorded call can carry the same obligations.
- No designated owner for AI vendor agreements. Assign one person to track which tools have signed BAAs, so the answer isn't "I think so" when it matters.
◆ Small Business AI Kickstart
Get AI ready today.
Before it's too late.
yforest AI Labs comes to your company, trains your team, and ships your first tools.
FAQ
Does HIPAA apply to AI chatbots used for scheduling or reminders?
It can. HHS.gov specifically names a third-party AI chatbot that handles symptom assessment, reminders, or scheduling involving a patient's PHI as an example of a business associate that needs a signed agreement.
Can we use a free AI tool if we don't type in the patient's full name?
Generally, PHI is about more than a name — a treatment detail or appointment tied to any identifiable patient can still count. If real patient data is involved at all, confirm a Business Associate Agreement is in place first.
What is a Business Associate Agreement?
A BAA is a signed agreement between a covered entity (your practice) and a vendor (a business associate) that handles PHI on your behalf, requiring the vendor to safeguard that information appropriately.
Will most AI vendors sign a BAA?
Not all will, and it often depends on the specific product tier. Ask directly and get the signed agreement in hand before using real PHI — don't assume a healthcare-sounding product name means one exists.
Is this guide legal advice for our practice?
No. This is general information, not legal advice. Confirm your specific obligations with your compliance officer or an attorney familiar with HIPAA.
Sources
This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.