What is a HIPAA compliant AI agent?

Cheryl Chai
Cheryl Chai
Product marketing lead
What is a HIPAA compliant AI agent?

Key takeaways

  • A HIPAA compliant AI agent needs a signed Business Associate Agreement whenever the vendor acts as a business associate, along with safeguards for electronic PHI that actually hold up under review.
  • That means access controls that limit who sees what, audit logs that can reconstruct an incident, and a documented breach procedure with a real deadline attached.
  • Delight.ai is a HIPAA compliant AI agent for healthcare customer support, holding a HIPAA Type I report and a SOC 2 Type II report, with Trust OS giving your team visibility into every action the agent takes.

Gartner found that 91% of customer service leaders felt pressure from executive leadership to implement AI in 2026. In healthcare, that pressure immediately requires a compliance review, given the sensitive nature of the information AI agents handle. Leaders at health commerce businesses need to know whether an AI agent can support patient service without exposing protected health information (PHI) or slowing procurement.

The phrase "hipaa compliant AI agent" appears throughout vendor marketing, yet HIPAA compliance depends on the full deployment. Contracts, data flows, safeguards, policies, and the customer's own operating practices all shape the answer.

For proactive outreach and self-service booking, the evaluation starts with the agent's role and every system that receives patient data. Delight.ai's healthcare AI agent is designed for administrative patient interactions such as scheduling, insurance questions, billing support, reminders, and follow-ups, with security controls built for regulated environments.

What is a HIPAA compliant AI agent?

A HIPAA compliant AI agent is an AI system configured and operated to meet applicable HIPAA Privacy, Security, and Breach Notification Rule obligations when it creates, receives, maintains, or transmits PHI. No model name or vendor label establishes compliance on its own. The organization, vendor, deployment, and workflow must work together to protect the data.

An AI agent enters HIPAA's scope when it handles PHI for a covered entity or business associate. A conversation can qualify when it connects identifiable information to care or payment, including:

  • A patient confirming an appointment associated with their provider record.
  • A patient asking about insurance coverage tied to their account.
  • A patient requesting a prescription refill through a provider's service channel.

The U.S. Department of Health and Human Services (HHS) explicitly names an AI chatbot that handles patient PHI for medical reminders or appointment scheduling as an example of a business associate, a HIPAA term for any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf. 

That status means the company selling or operating the AI agent, the vendor, must sign a Business Associate Agreement with the healthcare organization, safeguard the data under HIPAA's Security Rule, and notify the organization if a breach occurs, obligations that apply whether or not the vendor calls itself "HIPAA compliant."

What does HIPAA compliance require from an AI agent?

HIPAA compliance requires administrative, physical, and technical safeguards suited to the risks of the deployment. The following 5 areas form a practical vendor review, though they do not replace a formal risk analysis or legal and security review.

A signed Business Associate Agreement (BAA)

A Business Associate Agreement (BAA) is a written contract that governs a vendor's use and disclosure of PHI when the vendor acts as a business associate. It must define permitted uses, require appropriate safeguards, address incident reporting, and extend relevant obligations to subcontractors. The HHS business associate guidance explains when the relationship applies and what the agreement must cover.

Confirm that the BAA covers the proposed AI workflows, data, subprocessors, and services. Commercial availability alone is insufficient if the contract excludes the product tier or data flow your team plans to use.

Encryption in transit and at rest

Encryption in transit and at rest is a strong baseline for an AI agent that handles electronic PHI (ePHI). The current HIPAA Security Rule treats encryption as an addressable implementation specification, which means a regulated entity must assess whether it is reasonable and appropriate and document any equivalent alternative. A vendor should identify the protocols it uses, where encryption begins and ends, and how it manages keys.

Naming the actual encryption specifics gives a security team something concrete to assess, rather than a compliance label taken on faith. Delight.ai is one example: it encrypts patient data at rest with AES-256 and in transit with TLS 1.3, per its published security practices.

Access controls and audit logging

Access controls and audit logging should show that authorized people and systems can reach only the ePHI their roles require. HIPAA requires access controls and authentication for any system touching ePHI, along with a way to record and examine activity after the fact, which for an AI agent means confirming it verifies who or what is asking before it hands over a record, not just that a password exists somewhere in the stack.

Delight.ai's own role-based access control for AI agents works this way, scoping exactly what each team or workflow can reach. For an AI workflow, reviewers should be able to trace the records accessed and the actions completed.

A scheduling agent, for example, may need appointment availability and a verified patient identity. Giving that workflow unrestricted access to clinical notes would expand exposure without supporting the task.

Minimum-necessary PHI handling

Minimum-necessary PHI handling limits uses, disclosures, and access to the information needed for the intended purpose. A booking confirmation generally does not need a patient's full visit history, so the workflow should request and expose a smaller data set.

Retention deserves a separate answer because HIPAA's minimum-necessary standard does not establish one universal deletion period for every record. The vendor should explain which data it stores, why it stores it, where it resides, who can retrieve it, and how retention settings align with your legal and operational requirements. The HHS Security Rule summary provides the current framework for risk-based safeguards and access management.

Breach notification timelines

HIPAA breach notification timelines depend on the affected party and the nature and size of the breach. A business associate must notify the covered entity after discovering a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days. Contracts often require faster notice so the covered entity can investigate and meet its own obligations.

The BAA should spell out the contractual notification deadline and exactly who to call first, since a vendor that only commits to HIPAA's 60-day outer limit can still leave your team finding out about a breach weeks after the fact. HHS's Breach Notification Rule guidance explains the duties for covered entities and business associates.

How do you evaluate whether an AI agent platform is actually HIPAA compliant?

You evaluate whether an AI agent platform supports HIPAA compliance by reviewing the contract, independent reports, data architecture, and operational evidence for the exact deployment. These 4 questions move the review beyond a homepage claim.

Is a BAA offered by default, or gated behind a premium tier?

A BAA must be available for the product, plan, and workflow that will handle PHI. Ask the vendor to identify any pricing, hosting, feature, or subprocessor conditions before procurement advances, then have legal and security teams confirm that the agreement covers the intended use.

Does the report cover how controls are designed, or how they perform over time?

The report's scope tells you whether an assessor reviewed control design at a point in time or tested control operation across a defined period.

HIPAA Type I reportHIPAA Type II report
What it attestsControls were suitably designed at a specified dateControls were suitably designed and operated effectively during the review period
Evidence windowA single point in timeA defined period
What it tells a buyerThe control design met the assessment criteriaThe controls were tested across the stated period

Ask the vendor for the report itself, not just the label, so you can see which criteria the auditor tested against, what period it covered, and any exceptions noted, since a one-line compliance claim can't tell you whether the report actually covers the workflow you're deploying. Delight.ai holds a HIPAA Type I report alongside a SOC 2 Type II report, with each report described according to its scope.

Where does patient data flow?

Patient data should flow only through systems and subprocessors approved for the intended HIPAA-regulated workflow. A useful architecture review answers 5 questions.

  • Third-party access — does PHI reach a third-party model provider, and under what terms?
  • Model training — can any of that data train future models?
  • Data residency — which regions store it?
  • Retention window — how long do records remain available?
  • Deletion — how does deletion actually work?

This review should follow the data from the first patient message through integrations, logs, analytics, backups, and exports. A gap anywhere in that path can undermine controls at the conversational layer.

How deep is the audit trail?

The audit trail should let your team examine system activity involving ePHI and investigate the agent's actions. HIPAA requires mechanisms that record and examine relevant information-system activity, while each organization determines the detail needed through its risk analysis.

Delight.ai combines full audit logs with a governance and observability layer called Trust OS. Your team can review the agent's behavior and maintain control over what it may do, while a timestamped activity trail records actions during multi-step work. That trail supports internal review, incident response, and ongoing oversight.

How does this apply to proactive outreach and appointment booking?

HIPAA applies to proactive outreach and appointment booking when those workflows involve PHI for a covered entity or business associate. Each message must fit the organization's privacy and security program, the approved purpose, the patient's communication preferences, and the vendor's contracted data handling.

Delight.ai organizes administrative patient support across 3 stages:

  • Connect takes care of the pre-visit work — scheduling, insurance or prior-authorization verification, and registration.
  • Once care is underway, Support manages check-in and authorization status, and delivers approved care instructions.
  • After the visit ends, Continue closes the loop with order or lab-result notifications, follow-up scheduling, and refill coordination.

Channel changes should preserve context and controls. Omnipresence carries conversation context across chat, SMS, email, voice, WhatsApp, and in-app experiences, allowing a patient interaction to continue without an unnecessary restart. Your team still determines which channels and message content are appropriate for each workflow.

The bottom line

A credible HIPAA review connects the claim to evidence across contracts, controls, data flows, and auditability. Delight.ai gives healthcare support leaders a starting point most vendors can't match on paper alone, a HIPAA Type I report and a SOC 2 Type II report each scoped and described on its own terms, encryption and role-based access controls that actually get audited, and Trust OS's logs standing in for evidence instead of a promise. 

Its healthcare AI agent doesn't provide clinical guidance, clinical decision support, or medical recommendations, it handles the scheduling, order, and service side of care and hands off to your team when clinical judgment is needed.

Review Delight.ai's security and compliance practices with your legal and security stakeholders as you evaluate the deployment.

Frequently asked questions