Scrutineer.ai

Scrutineer · By framework

HIPAA compliant AI agents and HIPAA AI compliance

A health system will not let your agent near a chart until its security team has read your BAA, your subprocessor list and your risk analysis. The question it asks is narrow: what can the agent see, who can make it act, and where does the PHI go next.

Scrutineer maps your agent controls to the HIPAA Security Rule, tracks a BAA for every model and tool vendor in the loop, and keeps the evidence those reviews ask for. Compliance software, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HIPAA AI agents

A BAA with your model provider is necessary, and it is not enough

Once your agent handles PHI for a hospital, clinic or health plan, your company is a business associate, and every vendor that creates, receives, maintains or transmits that PHI for you is a subcontractor that owes you its own BAA under 45 CFR 164.308(b)(2) and 164.314(a)(2)(iii). The model API is the obvious one. The ones teams forget are the rest of the agent loop: the vector database holding embedded notes, the tracing or evaluation tool that stores full prompts and completions, the memory store that keeps conversation history, the speech-to-text service behind a voice agent, and every external tool the agent can call. Model provider BAAs, where offered, usually cover named endpoints under specific retention settings, so the configuration you run is part of the evidence, not a footnote.

A system prompt is not an access control

Telling an agent not to read psychotherapy notes is an instruction, and the Security Rule asks for a technical control. 164.312(a)(1) requires access control and 164.312(a)(2)(i) requires unique user identification, which for an agent means its own service identity with credentials scoped to the records its task needs, not a shared admin token. 164.312(b) requires audit controls, so you should be able to show, per request, which records the agent read or wrote and which human user invoked it. Minimum necessary under 164.502(b) and 164.514(d) turns into concrete limits: narrow FHIR scopes, field-level filtering before data reaches the prompt, and conversation memory that expires instead of accumulating a patient history nobody asked for.

HHS has already said where AI goes in your HIPAA program

The January 6, 2025 Security Rule proposal (90 FR 898) states that ePHI in AI training data, prediction models and algorithm data maintained for covered functions is protected by the HIPAA Rules, and that a risk analysis covering an AI tool must consider the type and amount of ePHI it accesses, to whom the data is disclosed and to whom the output is provided. It also proposes a written technology asset inventory that would list AI software interacting with ePHI. The proposal is not final, but the risk analysis duty it describes already applies under 164.308(a)(1). Hospital buyers have their own clock too: since May 1, 2025, 45 CFR 92.210 requires covered entities to identify patient care decision support tools that use race, color, national origin, sex, age or disability and mitigate the risk of discrimination, so expect questions about your inputs.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your agent controls to every HIPAA Security Rule standard and implementation specification, with the agent treated as its own identity rather than a feature of the app
  • Keeps an inventory of every vendor in the agent loop (model API, embeddings, vector store, tracing, memory, speech, external tools) with BAA status and the endpoint or setting it covers
  • Records the minimum necessary decision for each agent task: which record types and fields it may reach, and why
  • Collects audit evidence that ties each agent read and write to the invoking user, so you can answer a hospital that asks what the agent saw
  • Runs the 164.308(a)(1) risk analysis against the agent data flow, including prompts, outputs, logs and any training or fine-tuning use of PHI
  • Answers health system security questionnaires and AI addenda from the same mapped controls, so the answer matches the evidence
  • Assesses AI agent vendors from the buyer side, for a clinic or health plan that has to approve one, using the same HIPAA control set
  • Adds SOC 2 and ISO 42001 on the same library when enterprise buyers ask for a report or an AI management system on top of HIPAA
HIPAA AI agents readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Who your agent works for decides the rules

Which rules reach an AI agent, by who it works for

Most HIPAA AI guides assume HIPAA always applies. It does not: the same agent can be a business associate, a consumer app under the FTC, or a tool a hospital must screen for bias, depending on who it serves and what it touches. This is how the obligations split, and what is net-new beyond a SOC 2 program.

Situation Your role Rules that apply What the buyer asks for Net-new work beyond SOC 2
Agent vendor serving hospitals, clinics or health plans Business associate HIPAA Security Rule, breach notice to the customer within 60 days (164.410), your BAA terms Signed BAA, risk analysis, subprocessor list, often a SOC 2 Type 2 report BAAs for every AI subprocessor, agent identity and audit trail, PHI kept out of traces and logs
Agent vendor that wants to train or fine-tune on customer PHI Business associate, limited to the uses the BAA permits HIPAA permitted uses (164.504(e)), or de-identification under 164.514(b) A training data clause in the BAA and a data flow showing where PHI goes Written permitted-use record, or a documented de-identification method before training
Consumer health app with an AI agent, sold direct to patients Usually not a business associate FTC Health Breach Notification Rule (16 CFR 318), FTC Act Section 5 App store review and a privacy policy that matches behavior Breach notice to individuals and the FTC, and to media at 500 or more residents of a state
Certified health IT developer shipping a predictive model Developer, often also a business associate ONC HTI-1 decision support intervention transparency (45 CFR 170.315(b)(11)) plus HIPAA Source attributes describing training data, validation and intended use Maintaining the published source attributes alongside your HIPAA evidence
Hospital or clinic deploying an agent in patient care Covered entity HIPAA plus Section 1557 at 45 CFR 92.210, in force since May 1, 2025 Not applicable, this is the buyer An inventory of decision support tools, a bias mitigation record, and a vendor assessment of each agent
Agent that only ever sees de-identified data Outside HIPAA for that data De-identification standard at 164.514(b) Proof of the method used Expert determination or safe harbor record, and controls that stop re-identified data flowing back

Good questions

Questions about HIPAA AI agents

Yes. An AI agent can be operated in a HIPAA compliant way when the company running it meets the Security Rule for the agent, signs a BAA with each customer, holds a BAA with every vendor that touches PHI in the agent loop, limits the agent to minimum necessary data, and logs what it reads and writes. Compliance belongs to the organization, not to the model.
No AI model is HIPAA compliant on its own, and HHS does not certify AI products. Some model providers sign a business associate agreement for specific API endpoints and settings, which makes it possible to build a compliant system on them. Whether that system is compliant depends on your configuration, access controls, logging and the rest of your HIPAA program.
The company running the agent needs a BAA with each covered entity or business associate customer whose PHI the agent handles, and a BAA with every subcontractor that receives PHI for it, under 45 CFR 164.308(b)(2). That includes the model API, the vector store, prompt tracing tools, memory stores and any external tool the agent sends PHI to.
HIPAA has no AI-specific rule yet, so the existing Security Rule applies to AI systems that handle ePHI: a risk analysis that covers the AI data flow, access control with unique identities, audit controls, integrity and transmission protections, BAAs with subcontractors, and minimum necessary limits. HHS proposed in January 2025 that AI software touching ePHI be listed in a written technology asset inventory.
HIPAA applies to AI whenever the AI creates, receives, maintains or transmits protected health information for a covered entity or business associate. HHS stated in its 2025 Security Rule proposal that ePHI in AI training data, prediction models and algorithm data maintained for covered functions is protected. An AI tool that only processes properly de-identified data falls outside HIPAA for that data.
Only if HIPAA permits that use. A business associate may use PHI only as its BAA allows, so training on customer PHI needs an explicit contract basis, and many health systems refuse it. The common alternative is to de-identify the data first under 164.514(b), by safe harbor or expert determination, and document the method before training starts.
No. A prompt instruction is not a technical safeguard. The Security Rule expects access control under 164.312(a)(1), so restrict what the agent can retrieve with scoped credentials, narrow API or FHIR scopes and field filtering before data reaches the model. Then log each access under 164.312(b) so you can prove what it actually saw.
Health systems send a security questionnaire, often with an AI addendum, and ask for a signed BAA, a recent risk analysis, a subprocessor list including the model provider, data retention and training terms, and usually a SOC 2 Type 2 report. Since May 2025 covered entities also have to screen patient care decision support tools for discriminatory inputs under 45 CFR 92.210.
No. Scrutineer is compliance software: it maps your agent controls to the Security Rule, tracks a BAA for every AI subprocessor, collects access and audit evidence, and answers security questionnaires from the same record. HIPAA compliance stays your responsibility, and any SOC 2 or HITRUST report comes from an independent assessor. HIPAA alone runs on the Essentials plan.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification