Scrutineer · By framework
HIPAA compliant AI agents and HIPAA AI compliance
A health system will not let your agent near a chart until its security team has read your BAA, your subprocessor list and your risk analysis. The question it asks is narrow: what can the agent see, who can make it act, and where does the PHI go next.
Scrutineer maps your agent controls to the HIPAA Security Rule, tracks a BAA for every model and tool vendor in the loop, and keeps the evidence those reviews ask for. Compliance software, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HIPAA AI agents
A BAA with your model provider is necessary, and it is not enough
Once your agent handles PHI for a hospital, clinic or health plan, your company is a business associate, and every vendor that creates, receives, maintains or transmits that PHI for you is a subcontractor that owes you its own BAA under 45 CFR 164.308(b)(2) and 164.314(a)(2)(iii). The model API is the obvious one. The ones teams forget are the rest of the agent loop: the vector database holding embedded notes, the tracing or evaluation tool that stores full prompts and completions, the memory store that keeps conversation history, the speech-to-text service behind a voice agent, and every external tool the agent can call. Model provider BAAs, where offered, usually cover named endpoints under specific retention settings, so the configuration you run is part of the evidence, not a footnote.
A system prompt is not an access control
Telling an agent not to read psychotherapy notes is an instruction, and the Security Rule asks for a technical control. 164.312(a)(1) requires access control and 164.312(a)(2)(i) requires unique user identification, which for an agent means its own service identity with credentials scoped to the records its task needs, not a shared admin token. 164.312(b) requires audit controls, so you should be able to show, per request, which records the agent read or wrote and which human user invoked it. Minimum necessary under 164.502(b) and 164.514(d) turns into concrete limits: narrow FHIR scopes, field-level filtering before data reaches the prompt, and conversation memory that expires instead of accumulating a patient history nobody asked for.
HHS has already said where AI goes in your HIPAA program
The January 6, 2025 Security Rule proposal (90 FR 898) states that ePHI in AI training data, prediction models and algorithm data maintained for covered functions is protected by the HIPAA Rules, and that a risk analysis covering an AI tool must consider the type and amount of ePHI it accesses, to whom the data is disclosed and to whom the output is provided. It also proposes a written technology asset inventory that would list AI software interacting with ePHI. The proposal is not final, but the risk analysis duty it describes already applies under 164.308(a)(1). Hospital buyers have their own clock too: since May 1, 2025, 45 CFR 92.210 requires covered entities to identify patient care decision support tools that use race, color, national origin, sex, age or disability and mitigate the risk of discrimination, so expect questions about your inputs.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your agent controls to every HIPAA Security Rule standard and implementation specification, with the agent treated as its own identity rather than a feature of the app
- Keeps an inventory of every vendor in the agent loop (model API, embeddings, vector store, tracing, memory, speech, external tools) with BAA status and the endpoint or setting it covers
- Records the minimum necessary decision for each agent task: which record types and fields it may reach, and why
- Collects audit evidence that ties each agent read and write to the invoking user, so you can answer a hospital that asks what the agent saw
- Runs the 164.308(a)(1) risk analysis against the agent data flow, including prompts, outputs, logs and any training or fine-tuning use of PHI
- Answers health system security questionnaires and AI addenda from the same mapped controls, so the answer matches the evidence
- Assesses AI agent vendors from the buyer side, for a clinic or health plan that has to approve one, using the same HIPAA control set
- Adds SOC 2 and ISO 42001 on the same library when enterprise buyers ask for a report or an AI management system on top of HIPAA
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Who your agent works for decides the rules
Which rules reach an AI agent, by who it works for
Most HIPAA AI guides assume HIPAA always applies. It does not: the same agent can be a business associate, a consumer app under the FTC, or a tool a hospital must screen for bias, depending on who it serves and what it touches. This is how the obligations split, and what is net-new beyond a SOC 2 program.
| Situation | Your role | Rules that apply | What the buyer asks for | Net-new work beyond SOC 2 |
|---|---|---|---|---|
| Agent vendor serving hospitals, clinics or health plans | Business associate | HIPAA Security Rule, breach notice to the customer within 60 days (164.410), your BAA terms | Signed BAA, risk analysis, subprocessor list, often a SOC 2 Type 2 report | BAAs for every AI subprocessor, agent identity and audit trail, PHI kept out of traces and logs |
| Agent vendor that wants to train or fine-tune on customer PHI | Business associate, limited to the uses the BAA permits | HIPAA permitted uses (164.504(e)), or de-identification under 164.514(b) | A training data clause in the BAA and a data flow showing where PHI goes | Written permitted-use record, or a documented de-identification method before training |
| Consumer health app with an AI agent, sold direct to patients | Usually not a business associate | FTC Health Breach Notification Rule (16 CFR 318), FTC Act Section 5 | App store review and a privacy policy that matches behavior | Breach notice to individuals and the FTC, and to media at 500 or more residents of a state |
| Certified health IT developer shipping a predictive model | Developer, often also a business associate | ONC HTI-1 decision support intervention transparency (45 CFR 170.315(b)(11)) plus HIPAA | Source attributes describing training data, validation and intended use | Maintaining the published source attributes alongside your HIPAA evidence |
| Hospital or clinic deploying an agent in patient care | Covered entity | HIPAA plus Section 1557 at 45 CFR 92.210, in force since May 1, 2025 | Not applicable, this is the buyer | An inventory of decision support tools, a bias mitigation record, and a vendor assessment of each agent |
| Agent that only ever sees de-identified data | Outside HIPAA for that data | De-identification standard at 164.514(b) | Proof of the method used | Expert determination or safe harbor record, and controls that stop re-identified data flowing back |
Good questions
Questions about HIPAA AI agents
Keep reading
Guides that go deeper on this framework
HIPAA compliance checklist
The Security Rule safeguards in the order a business associate should build them, agent or not.
Read the guideBest HIPAA risk assessment software
Which tools produce the 164.308(a)(1) risk analysis a hospital asks to see before it approves your agent.
Read the guideBest AI vendor risk management software
How health systems and other buyers score AI vendors, and what they ask an agent company for.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification