Your SaaS’s AI Feature May Not Be HIPAA Compliant
AI compliance risks in healthcare are growing wherever AI touches regulated data, and AI is increasingly coming into contact with ePHI. What deserves particular attention from compliance and security teams is the seemingly innocuous AI feature inside SaaS applications that are already in use. New features arrive constantly, often switched on by default. And because they ship inside platforms you've already approved, they may never trigger the compliance review that a new product or vendor would.
Why AI Features in SaaS Expand HIPAA Compliance Scope
Your organization signed a BAA with each SaaS vendor that handles PHI. HHS requires these contracts to define the permitted uses and disclosures of PHI for the services being performed. That agreement was scoped to the product as it existed at the time. AI features change the product under the agreement.
Three things typically shift when a SaaS vendor adds AI:
New subprocessors. Many SaaS vendors do not run their own models. They utilize external AI providers. Under HIPAA, subcontractors that handle PHI are themselves business associates with direct liability. A BAA signed in 2022 may say nothing about a model provider added in 2025.
New data flows. Prompts, transcripts, and AI-generated summaries are new copies of PHI. They may be retained for abuse monitoring, cached for performance, or stored in regions you have not approved. Some vendor terms permit data use for model improvement unless you opt out.
In-scope versus out-of-scope services. HHS guidance on HIPAA and cloud computing makes clear that a cloud provider handling ePHI must be covered by a BAA. An AI assistant bolted onto a covered product is not automatically covered itself.
Why a SaaS AI feature may not be HIPAA compliant
A SaaS platform being HIPAA compliant does not mean the AI features inside it are. AI features can send ePHI to new models, vendors, and subprocessors that may sit outside your BAA. Each feature can expand your HIPAA compliance scope and expose you to non-compliance risks.
| Issue | Why it's a compliance problem | Relevant clause or source |
|---|---|---|
| Not covered by the BAA | A BAA must establish the permitted uses and disclosures of PHI. An AI feature outside the agreed services means PHI is flowing under no HIPAA assurances. | 45 CFR 164.504(e)(2): the contract must "establish the permitted and required uses and disclosures." |
| AI Feature not assessed for compliance by the vendor | Some vendors state outright that their AI features have not undergone a HIPAA compliance assessment and should not touch PHI. | NetSuite HIPAA guidance, May 2026 |
| New AI subprocessors | Subcontractors handling ePHI must be bound by equivalent contractual safeguards. Model providers added after the BAA signature are often not. | 45 CFR 164.314(a)(2): subcontractors must agree to comply via contract. |
| Data leaves the contracted environment | AI processing can occur on endpoints outside the data center your contract applies to. For example, Oracle's NetSuite AI terms disclose prompts go to OpenAI endpoints "outside of the Oracle managed datacenter". | NetSuite Supplemental Terms and Conditions, OpenAI LLM section. |
| Prompts and outputs are retained | AI transcripts, summaries, and caches are new copies of PHI. Any use or disclosure beyond what the contract permits is prohibited. | 45 CFR 164.504(e)(2)(ii)(A): no use or disclosure "other than as permitted or required by the contract." |
| Data used for model training | Training AI models on customer data is a use your BAA almost certainly never authorized, and opt-out is sometimes not possible. | Same clause as above; check the vendor's AI terms for training language. |
| AI Features and training enabled by default | Features that switch on via release notes, or the use of your data for model training, can bypass your compliance analysis. | Security Rule, 45 CFR Part 164 Subpart C: risk analysis obligations under 164.308. |
| Changeable nature of features, releases, settings, and terms of service | Feature releases and setting changes are not always predictable and require constant review by compliance teams. Moreover, vendors often change their terms of service and agreements around the collection of data for training purposes. This can make maintaining compliance more complex, risky and time consuming. | Atlassian stated customer data was never used to train AI models, then announced in April 2026 that collection for AI training begins August 17, 2026, with opt-out availability depending on subscription tier. |
SaaS Vendors Are Aware of the AI HIPAA Gap
NetSuite
In May 2026, Oracle NetSuite posted HIPAA guidance for its customers stating that its AI features have not undergone a formal HIPAA compliance assessment and should not be used in workflows involving PHI or other sensitive data subject to HIPAA requirements. This applies even to customers on NetSuite's HIPAA-eligible modules.
Oracle's supplemental terms for NetSuite AI features also disclose that prompt content for features using AI is sent to an OpenAI endpoint outside the Oracle-managed data center.
Atlassian
Atlassian's documentation states that organizations with a BAA in place for HIPAA compliance should not activate AI, and that the features use OpenAI.

Image source: About AI in Atlassian apps
Zoom
Zoom offers a BAA for healthcare customers, but some AI Companion features are automatically disabled when a covered entity signs one. Zoom itself treats parts of its AI as unsuitable for accounts handling PHI.
These are vendors being transparent. The harder problem is the vendors that are not, and the features that arrive as a release note and a default-on toggle.
Five Questions to Ask Your SaaS Vendor
- Which AI features are enabled by default, and can we disable them at the tenant level?
- Which AI subprocessors receive our data, and are they named in the BAA?
- Is our data used for model training or improvement, and is opt-out contractual or a setting?
- How long are prompts, outputs, and transcripts retained, and where?
- Is the AI feature listed as a covered service under our BAA?
How to Keep Your Data Secure With Pre-Ingress Encryption
Each organization needs to evaluate the impact of using the AI features inside its SaaS platforms. That review is necessary, but on its own, it leaves you auditing a moving target. Every new feature, default change, and terms update restarts the cycle.
One way to de-risk AI access to HIPAA-regulated data is to encrypt or tokenize the regulated data before it enters the SaaS platform. If ePHI never reaches the application in plain text, the AI features inside it, and the subprocessors behind them, have nothing to expose.
Encryption also carries a meaningful carve-out under current rules. Under the breach notification provisions at 45 CFR 164.402, an incident involving ePHI encrypted to HHS standards can fall within the breach safe harbor, meaning it may not be a reportable breach.
Proposed HIPAA Security Rule Update Will Make Encryption a Required Safeguard
The pressure to encrypt ePHI is increasing. HHS published a proposed update to the HIPAA Security Rule in the Federal Register on January 6, 2025. It would make encryption and multi-factor authentication mandatory rather than addressable, and would tighten oversight of business associates, including written verification of safeguards. As of June 2026 the proposed rule has not been finalized, and its final form and timing remain uncertain. The current Security Rule stays in force, as HHS states on its NPRM fact sheet.
Learn more: Encryption may become a required safeguard
The Cloud Data Protection Gateway Help You Stay in Control of ePHI
StratoKey's CDP Gateway secures sensitive fields before data leaves your control. Sensitive fields are encrypted pre-ingress, with keys held by you. Your SaaS platform, and by extension any AI feature or model behind it, sees only ciphertext. Workflows keep functioning.
This does not remove your HIPAA obligations, and it is not a substitute for vendor due diligence. It does shrink the surface area and gives you one consistent control that holds steady while features, settings, and service agreements keep changing. AI features will keep arriving faster than BAAs can be renegotiated. Reducing where plain text ePHI lives is a durable way to keep compliance scope under control.
Learn more: Download the HIPAA Compliance Guide
Ask Us About Securing ePHI
Please provide details so we can best assist you.
- Your SaaS’s AI Feature May Not Be HIPAA Compliant
- How Field-Level Data Tokenization Reduces Compliance Scope
- Practical Steps to Control AI Access to Regulated Data
- What to Replace ServiceNow Edge Encryption With
- ITAR & EAR Compliance for Multinationals: A SaaS Guide
- Your SaaS is Adding AI Faster Than Compliance Can Keep Up
- The Death of On-Premise and What it Means for Your Sensitive Data
- Why Data Residency Does Not Equal Data Sovereignty
- AI Creates CMMC Compliance Risks. What Can You Do About it?
- Securing the Defense Manufacturing Supply Chain for CMMC Compliance
- CMMC Flow Down Requirements 2026: What Major Defense Primes Are Requiring From Subcontractors
- Data Residency, What Is It and Why It Is So Important for Global Data Compliance
- What Is Data Tokenization and Why Is It So Important?
- GSA's CMMC Style Cybersecurity Guide, CIO-IT Security-21-112
- Final Rule Update: 48 CFR and the CMMC Contract Clause Are Now in Motion
- Meeting NIST Encryption Standards with the Cloud Data Protection Platform
- CMMC Final Rule 2025 Key Dates, Phased Rollout and Timeline for CMMC Compliance
- AI and HIPAA Compliance: The Risks and How to Reduce Your Exposure
- Why You Should Host Your Own Cloud Encryption Gateway
- What Every Federal Contractor Needs to Know About FAR Case 2017-016


