HIPAA compliance checklist: 7 questions to ask any AI billing vendor
Can AI billing software be HIPAA compliant? Yes — with the right safeguards. Seven questions about BAAs, PHI handling, and audit trails to ask before you sign.

Can AI billing software be HIPAA compliant? Yes. HIPAA doesn’t prohibit AI — it regulates how protected health information (PHI) is used, stored, and disclosed, whoever or whatever is doing the work. Compliance is a property of the vendor’s safeguards, not of the technology label. These seven questions separate vendors who have done that work from vendors who have done a landing page.
The seven questions
- Will you sign a Business Associate Agreement? Any vendor that touches PHI on your behalf is a business associate under HIPAA, and a signed BAA is the non-negotiable baseline. No BAA, no pilot.
- Is PHI used to train models? The answer you want is a clear no — or training only on data de-identified to HIPAA’s standards. Vague answers here are the single biggest red flag in the category.
- How is data encrypted? In transit and at rest, with keys managed properly. This should be a boring, instant answer.
- Who can access PHI, and is every access logged? Look for role-based access under the minimum-necessary standard, and audit logs that cover the vendor’s own staff — not just your users.
- Can we see exactly what the AI said to each patient? Every message and call involving PHI should be reviewable, word for word. If the vendor can’t show you the conversation, you can’t supervise the disclosure.
- What is the breach process? Business associates have notification obligations. Ask for the concrete timeline and who calls whom — before you ever need it.
- Where do complex cases go? Disputes and hardship conversations should escalate to named humans with the account context attached. Compliance includes what happens when the AI correctly steps aside.
Red flags that end the conversation
- Hesitation about signing a BAA, or a BAA full of carve-outs.
- We use your data to improve our models — with no de-identification specifics.
- No action-level audit trail — summaries instead of the actual patient interactions.
- Black-box behavior sold as intelligence: if they can’t explain what it did, you can’t defend it in an audit.
In healthcare, trust in AI is earned the unglamorous way: a signed BAA, a complete audit trail, and a human to escalate to.
For the record, this checklist is also our own bar: how Reclaimly handles security and HIPAA compliance — BAA included.
Related reads
View all in Security
AI Noise
The AI Noise Is Deafening — But Days to Pay Tells the Real Story
Healthcare is drowning in AI noise — clinical models, coding automation, denials prediction, workforce tools, scheduling optimization, and every flavor of “intelligent” workflow.
By Robert Ashner

AI
What is AI medical billing? A plain-English guide for practices
AI medical billing, explained without the buzzwords: what AI agents actually do with patient balances, how it differs from billing automation, and how to evaluate it.
By Reclaimly Team

Patient billing
Why patients don’t pay their medical bills — and what actually changes it
Most unpaid patient balances aren’t about unwillingness. They’re about confusion, timing, and effort. Here’s what the billing process looks like from the patient’s side — and what practices can change.
By Reclaimly Team