AI Compliance in Healthcare: HIPAA, FDA and OSHA Guidelines
Healthcare AI inherits every obligation that applies to the clinicians it augments, plus new ones specific to how it operates, and three frameworks apply in distinct, non-overlapping ways: HIPAA governs how AI handles patient data, the FDA determines whether AI qualifies as a medical device requiring premarket review, and OSHA addresses how AI systems affect healthcare worker safety. The deployment-governance gap is already wide: 71% of U.S. hospitals use predictive AI integrated into their EHRs, yet only 59% have a formal, documented approval process before AI implementation.
Key takeaways
- HIPAA applies fully and without modification to any AI system accessing, processing, or transmitting ePHI, OCR explicitly states ePHI in AI training data, prediction models, and algorithm data is protected; AI is not a carve-out
- The FDA distinguishes AI that informs clinician judgment from AI that replaces it, the latter potentially requiring premarket device review
- OSHA's workplace-safety obligations extend to AI affecting worker environments: robotic tools, automation, and alert-heavy workflows
- The biggest compliance risk is organizational: AI deployed without governance ownership, access controls, or audit infrastructure
- Real-time governance closes gaps static compliance frameworks cannot address
What does HIPAA require of healthcare AI?
The Privacy Rule, Security Rule, and Minimum Necessary standard apply unchanged: access controls and least privilege for AI systems and agents; audit controls capturing AI activity on ePHI (§164.312(b)); BAAs with AI vendors processing PHI; and minimum-necessary discipline on what data reaches models. Practically, that means PHI detection and policy enforcement in the AI request path, plus per-interaction audit records, the same expectations OCR applies to any system, applied to systems that happen to be probabilistic.
When does the FDA treat healthcare AI as a device?
The operative distinction: AI that informs clinician judgment (presenting information a clinician independently evaluates) versus AI that drives or replaces it. Clinical decision support that doesn't allow independent review of its basis, diagnostic AI, and autonomous clinical functions move toward device territory and potential premarket obligations. Organizations should classify each clinical AI use case explicitly and document the reasoning, recalls are real (FDA-cleared AI/ML devices have been recalled primarily for software issues), and "we didn't classify it" is the worst position.
What does OSHA add, and why is it overlooked?
Worker safety obligations extend to AI-shaped work environments: robotic and automated tools, workload and scheduling automation, and alert fatigue from AI-heavy clinical workflows. It rarely leads the compliance conversation, but it lands on the same governance program: inventory, risk assessment, and monitoring of AI's operational effects on staff.
What gaps are healthcare organizations creating right now?
Ungoverned pilots becoming production; shadow AI on personal accounts touching PHI; vendor/EHR-embedded AI outside the inventory; no AI-specific audit trail; and no named owner spanning clinical, IT, and compliance. Each is closable with the same move: route healthcare AI through a runtime control plane, Trussed AI's model, enforcing HIPAA-aligned policy in-line (PHI redaction, access scoping) and generating audit evidence automatically, with deployment options that keep data in your boundary.
Frequently Asked Questions
Does HIPAA apply if we de-identify data before AI processing? Properly de-identified data exits HIPAA scope, but de-identification must be verifiable and enforced in the pipeline, not assumed.
Is ambient clinical documentation AI a device? Generally positioned as informing clinician judgment with clinician review, but classification depends on function; document your analysis per tool.
Who should own healthcare AI compliance? A named senior owner (commonly CMIO/CHIO) with compliance and security as standing partners, diffuse ownership is the root cause of most gaps.
Related resources
Ready to govern your AI in production?