An AI operating system that handles scheduling, reminders, intake, or any patient communication is processing protected health information. That makes the vendor a business associate under HIPAA. "HIPAA compliant" on a website is not enough; what matters is how the vendor answers specific questions.
For background on what compliance means in practice, see our guide to HIPAA-compliant healthcare AI OS. Below are the questions to ask every vendor.
Contracts and Accountability
1. Will you sign a Business Associate Agreement, and on which plans?
Good answer: Yes, on every plan, before any PHI is shared. A BAA available only as an enterprise add-on is a warning sign.
2. Which subcontractors process our PHI, and do you have BAAs with them?
Good answer: A current list of subprocessors, including cloud and AI model providers, each covered by a BAA or equivalent agreement.
3. What independent security attestations do you have?
Good answer: A current SOC 2 report available under NDA, plus recent penetration testing results.
AI and Data Handling
4. Is our patient data used to train AI models?
Good answer: A clear, contractual answer about whether PHI is used for training, and if so, how it is de-identified and under what terms.
5. Where is PHI processed and stored?
Good answer: Specific cloud regions and services, all covered by the vendor's security program.
6. How long is PHI retained, and how is it deleted?
Good answer: A defined retention policy and a documented deletion process at contract end.
Technical Safeguards
7. Is data encrypted in transit and at rest, including in AI processing?
Good answer: Yes, by default, at every layer, not as a configuration option.
8. How is access controlled across our locations?
Good answer: Role-based access by organization, region, and location, with single sign-on and multi-factor authentication.
9. What is logged, and can we export audit logs?
Good answer: Access to PHI and administrative actions are logged, and logs can be exported on demand.
Operations and Patient Communication
10. How does the AI verify patient identity before discussing PHI?
Good answer: A defined verification step before sharing appointment or health details by phone or message.
11. How are clinical or sensitive conversations escalated?
Good answer: Clear routing to licensed staff with conversation context, and a record of the handoff.
12. What is your breach notification process?
Good answer: A documented incident response plan with notification timelines written into the BAA.
| Area | Tool adapted for healthcare | AI OS built for HIPAA |
|---|---|---|
| BAA | Add-on or unavailable | Included on every plan |
| Subprocessors | Not disclosed | Listed and covered |
| Encryption | Partial or optional | In transit and at rest, by default |
| Access control | Account-level | Role-based by location |
| Audit logs | Limited | Exportable on demand |
Why This Matters More for Multi-Location Organizations
A compliance gap at one practice is a problem. The same gap replicated across fifty locations is a platform-level risk, and one that will surface in diligence. Choosing one HIPAA-built AI OS for every location also means one BAA, one security review, and one set of controls instead of a different vendor at every site.
How Samara Approaches HIPAA
Samara is built for healthcare, with a signed Business Associate Agreement included on every plan, encryption in transit and at rest, and access controls designed for multi-location organizations. Review our HIPAA and security and compliance pages, read about HIPAA and SOC 2 compliant AI agents, or book a demo and bring these 12 questions.
Frequently Asked Questions
Is any AI tool HIPAA compliant if it signs a BAA?
No. A BAA is necessary but not sufficient. The vendor must also implement HIPAA's administrative, physical, and technical safeguards across the whole system, including AI model processing.
Do we need a separate BAA for each location?
Typically not. A multi-location organization can usually sign one BAA that covers all locations using the platform, which is another advantage of standardizing on one AI OS.
What is the most commonly overlooked HIPAA question for AI vendors?
Whether patient data is used to train AI models, and which subprocessors, including AI model providers, handle PHI.