FAQ · HIPAA

Is On Premises AI HIPAA compliant?

For practices that want to use AI with patient records and need to know where that leaves them under HIPAA.

Short answer

Buying our system does not make a practice HIPAA compliant. No product can. HIPAA applies to your organization and how it handles patient information. What we install runs the AI model on a machine in your office, so the questions and files your staff give it are not sent to an outside AI company. You still have to cover the system in your own risk analysis and policies.

HHS doesn’t certify HIPAA software

The Department of Health and Human Services does not certify or endorse software or hardware, and it doesn’t recognize any private “HIPAA certified” seal. When a vendor uses that phrase, it usually means an outside firm reviewed the vendor’s own controls. That can be worth knowing. It tells you nothing about how your office will use the product.

HIPAA covers health plans, clearinghouses, and providers that handle billing and other standard transactions electronically. It also covers the business associates that handle patient information for them. The Security Rule requires each of them to do a risk analysis and put safeguards in place based on what it finds. Include the AI system in that analysis, the same as you would a new EHR or file server.

What changes when the AI runs in your office

With a cloud AI tool, what staff type and upload goes to the vendor’s servers. If someone pastes in a chart note, that vendor is now handling patient information for you, and you need a business associate agreement (BAA) with them before it happens.

With On Premises, the model runs on a machine plugged into your network. Prompts and uploaded files are processed there, and the model doesn’t need the internet to answer. Anything else the machine connects to, like backups, model downloads, or our remote support, is set up to your rules and written into the deployment scope. Each of those belongs in your risk analysis too.

You still carry the same HIPAA duties. What changes is the list of outside companies you have to account for.

Who handles what

The system

  • Runs the AI model on hardware in your office
  • Gives each person their own login and chat history
  • Keeps usage records on your system, not ours
  • Changes models only when you approve
  • Stays yours, data included, if you cancel

Your practice

  • Covering it in your risk analysis
  • Deciding who gets an account, and closing accounts when people leave
  • Keeping the machine in a room that locks
  • Telling staff what they may upload
  • Wiping drives before the hardware is retired or resold

That second list is a starting point, not a full compliance program.

Decide during scoping whether the drives need to be encrypted and who holds the keys. It matters if the machine is ever stolen. Under the Breach Notification Rule, patient data encrypted to HHS’s standard, with the key kept safe, isn’t treated as unsecured.

Do you need a BAA with On Premises?

It depends on whether we can get to patient information. HHS says that selling software alone doesn’t make a vendor a business associate. Our remote monitoring covers hardware health: uptime, temperatures, load, and drive health. It doesn’t read prompts, documents, or chat history.

Hands-on support is different. If we log in to fix the chat app while patient records are stored on the machine, we could see them. If our support would give us that access, a BAA has to be signed before it starts. Raise it on the first call so it’s settled before install.

What about ChatGPT, Claude, and Copilot?

Each of those vendors offers a BAA for some products, but coverage depends on the exact product, plan, and settings, and it changes. Free and personal accounts are generally not covered. Before anyone pastes patient information into one, check the vendor’s current documentation and make sure the agreement is signed.

Even with a BAA in place, the data still goes to the vendor’s servers. The BAA sets the rules for how they handle it. If you want patient data to stay in the building, the model has to run in the building.

Try it on synthetic records first

Our pilot runs one of your workflows on a demo machine for half a day. It can run on made-up records shaped like yours, so no patient data has to be involved. You get a written go or no-go at the end.

This page is general information, not legal advice. Talk to your privacy officer or counsel about your own obligations. See our Terms for how site content should be read.

Last updated: September 22, 2026