HIPAA-compliant software and AI for practices: the PHI map first, then the build
Most practices we talk to have had an AI tool vetoed by compliance, and the veto was usually right. Then we build to it: BAA chain, scoped access, de-identification before a model, audit trail, residency and retention on your terms.
What to know before you buy anything
3 things that decide this
- 01HIPAA names no certification at all. No product is HIPAA certified, and a vendor badge saying so is marketing, which is exactly why buyers fall back on asking for SOC 2 Type II or HITRUST instead.
- 02A signed BAA is a promise about handling, not a control, and it doesn't cover subcontractors automatically. Every business associate in the chain needs its own agreement, including the model provider sitting behind an AI feature.
- 03Where PHI travels is an architecture decision made in week one, not a questionnaire answered after launch. Which fields you collect, what gets de-identified before a model sees it, and who can prove which records a named person opened on a given day are the three that cost the most to retrofit.
- Source systemYour EHR, PMS or PIMS holds the record and stays the chart.
- Our layerScoped to role and patient; identifiers stripped or tokenised here.
- Model or vendorUnder a BAA, in your region, with no training on your data.
- LoggingWho read what, when, retained on your schedule.
- OutputMapped back to the patient inside your system, never the model's.
That's the one-page map, and it is the first thing we write for a healthcare build. Your compliance officer reads it, marks it up and signs it before the pilot rather than after.
What a compliant architecture actually commits you to
The BAA chain, signed before anything moves
Every business associate touching PHI signs one, and the obligation flows down to their subcontractors. That includes the model provider, the telephony carrier, the transcription service and the hosting platform. A cloud provider's agreement covers its own infrastructure duties and stops there; how you configure the service, what you store and who can reach it is yours.
PHI scoped to role and patient, and de-identified before a model
Access is filtered at the query and tested at the endpoint as each role, because a hidden field on the front end is no control if the API still returns it. Before a model sees anything, Safe Harbor's identifiers are removed or tokenised. Mapping back to the patient happens in your system, not the model's.
An audit trail and access logs you can query
A breach question asks which records one named person opened, and on which day. Ordinary request logs can't answer that after the fact, so somebody has to design for the question. We log the read, not only the write, and we make the log reviewable rather than merely written to a file nobody opens.
Region, residency and retention on your terms
You choose where PHI is processed and stored, how long recordings, transcripts and derived data live, and when they're deleted. Nothing trains on your data. Those choices go into the map as values your compliance officer can check, not as a paragraph of assurance in a contract.
Monitoring, and the clinician's sign-off near care
Anything close to a clinical decision ships with monitoring and a human signature designed in. Your clinician signs every note and makes every clinical call. The software schedules, verifies, drafts and reminds; it doesn't diagnose, and your staff post payments, not the system.
Where a badge stops and architecture starts
You'll see the same line on almost every health-tech vendor's page: HIPAA compliant, SOC 2, BAA available on paid plans. Read it as three separate claims, because only two of them mean anything. HIPAA names no certification and no approval body, so nothing about a product is HIPAA certified. SOC 2 Type II and HITRUST are real audits, and they say a set of controls held over a period, which is useful and is still not the same as saying your build is safe.
What HIPAA actually does is make the practice responsible for how the software is built and configured. Two clinics on the same vendor, on the same plan, with the same signed BAA, can land in completely different places depending on what they collect, who they let in and what they log. That responsibility doesn't transfer with a signature, which is why the questionnaire arrives after a breach rather than before one.
So we hand you the map instead of the badge. One page: which system holds what, which vendor touches it, which region it sits in, what's logged, what's retained, and which fields get de-identified before a model ever sees them. Your compliance officer can veto a line of it, and the veto is cheap in week one. Retrofitting the same decision into a live clinical system is the expensive path, done under pressure, with a regulator's clock running.
- 01No product is HIPAA certified. Ask instead what the vendor logs, what it retains, and who else in the chain has signed.
- 02A BAA obliges safeguarding and breach reporting. It doesn't build a control and it doesn't move liability.
- 03Either way the map is yours, and you can hand it to another vendor.
Where patient information travels is the first design decision, made on paper, with your compliance officer
Most practices we talk to have had an AI tool vetoed by compliance, and the veto was usually right: the vendor couldn't say where the data went, wouldn't sign a BAA that covered every party in the chain, or trained on inputs. So every build starts with a one-page PHI map: which system holds what, which vendor touches it, which region, what's logged, what's retained, and which fields get de-identified before a model ever sees them.
What follows is simple to state, and we put it in writing. A BAA with every business associate in the chain before any PHI moves. Access scoped to the role and the patient, never practice-wide. No training on your data. An audit trail of who saw what. And the clinical decision, the diagnosis and anything that touches care stays with a clinician; the software schedules, verifies, drafts and reminds.
- 01BAA with every vendor in the chain, signed before anything is built.
- 02PHI scoped to role and patient; de-identified where a model is involved; audit trail on every access.
- 03Region, residency and retention set by you; nothing trains on your data; break-glass access documented, because emergency access is itself a requirement.
“They will treat your vision like their own and build it that way.”
Ron Klabunde · Founder, SmartREI ↗
“I am extremely happy with the results and would highly recommend Hashlogics to anyone.”
Daniel Khin · CEO, PremiumAudit.io
Some of the systems we have shipped
- AuditFree. We read where patient information travels in the automation you're considering, what your current vendors have signed, and what your systems log today.
- DiagnoseWe map the path into your EHR or PMS, sit with your front desk and billing for an afternoon, and write the PHI map.
- BuildFixed price from the diagnostic. BAA signed first. Tested on your real schedule and real claims, de-identified where it should be.
- RunMonitoring, a named engineer, and the first two months of maintenance free.
Best fit: a practice or group with two or more providers, a front desk that's saturated, and an EHR or PMS you've outgrown in places. Not a fit yet: a solo provider who needs the phone picked up, and we'll say so. You can stop after any stage; the audit note is yours either way.
Before you book
01Is ChatGPT HIPAA compliant?+
Consumer ChatGPT is not a place for PHI. There's no BAA behind a personal or team subscription, so pasting a patient's chart note into it is a disclosure you can't account for. Enterprise and API offerings are a different matter: where a BAA is available and the terms say your inputs don't train the model, they can sit inside a compliant architecture. That's a component, not a compliance status. You still have to scope access, strip or tokenise identifiers before the call, log what was sent, and decide where it's processed.
02Can you certify our software as HIPAA compliant?+
Nobody can, and a vendor who says otherwise hasn't checked. HIPAA names no certification and no approving body. What we can do is build to the Security Rule's safeguards, document each decision in the PHI map, and emit the evidence a SOC 2 Type II or HITRUST audit will ask for as the system runs. Your privacy officer and your counsel own the compliance call; this is engineering.
03What does de-identification actually involve?+
Two paths exist under the rule: expert determination, or Safe Harbor's list of 18 identifiers removed. Safe Harbor is stricter than teams expect, because it takes all geography smaller than a state, all date elements except the year, and every age over 89. Free-text notes defeat it routinely, since clinicians write dates, employers and locations into narrative. So we treat free text as identified until a scrubber and a human both say otherwise.
04Does using AWS or Azure make our system compliant?+
No. A cloud provider signs an agreement covering its own infrastructure obligations, and that's where its coverage ends. Configuration, what you store, who can reach it and what you log all stay with you. Two teams on identical infrastructure land in completely different places, which is the whole reason the map exists.
05Do we need SOC 2 or HITRUST as well?+
HIPAA requires neither, so it turns on who's buying from you. Digital health startups and most commercial buyers accept SOC 2 Type II. Health systems and payers increasingly specify HITRUST, and some make it a contractual precondition. Ask your three biggest prospects what their security team demands before you spend a year on the wrong one.
06What happens if the AI touches something clinical?+
It ships differently. Operational work like scheduling, verification, claims and reminders is where most practices should start, and it carries a lower bar. Anything nearer a clinical decision gets monitoring, an audit trail and a clinician's sign-off designed in from the first commit, and there's a separate question about when software becomes a regulated medical device that we'll walk through with you.
07Is this the whole of what you do for practices?+
No. This page is the architecture the rest sits on. Our AI front desk answers, screens and books. RCM automation runs eligibility, verification, prior auth, claims and denials. EHR integration is the plumbing, and custom software covers multi-location operations, dashboards and the patient portal. The healthcare hub walks the whole chain.
A senior engineer, not a sales rep
Abdul Basit founded Hashlogics in 2017, and the team runs from Lahore with a US LLC. Clients rate the work 5.0 on Clutch, and in 2026 it was named Best AI-Native Software House of the Year at TechNova. TrialTriage, an AI clinical-trial matching system for oncology, is one of the systems we built and can show you.
Your audit call is with an engineer who has read call logs, schedules and denial reports like yours. Bring last month's numbers if you have them, and we'll work from those.
- BAA and NDA before the first conversation about real data.
- No pitch on the call. A note you could hand to another vendor.
- Fixed price after the diagnostic, so the number isn't a guess.

Go deeper
- AI, automation and custom software for practices →The whole chain, from the 4:50 call to the next visit.
- AI front desk for practices →The 4:50 call answered, screened and booked into your schedule.
- RCM automation for practices →Eligibility, verification, prior auth, clean claims, denials worked.
- EHR integration for practices →FHIR, HL7 and vendor APIs; intake and documentation into the chart.
- Custom software for practices →Multi-location operations, dashboards, portal and patient communication.
- How do you build HIPAA-compliant AI? →Where PHI enters an AI pipeline and what must be true at each point.
- HIPAA-compliant AI receptionist →What compliant actually means for a phone line.
- When does my software become a regulated medical device? →The line between practice software and a regulated device.
- De-identification is where clinical AI gets real →Why Safe Harbor is stricter than teams expect, and free text defeats it.
- HIPAA software compliance guide →Required versus addressable safeguards, in the words HHS uses.
- HIPAA →What the rule covers, and who it makes responsible.
- PHI (protected health information) →Health data plus anything that points at a person.

