← All frameworks
Binding
HIPAA
US HHS / OCR · Washington DC, US · effective 1996 (Security Rule 2005)
US health-data protection. For AI, governs PHI used to train or run clinical/administrative models — access controls, audit trails, minimum-necessary and breach notification.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Covered entities (providers, plans, clearinghouses)
- ▸Business associates incl. AI vendors handling PHI
Penalties
Up to $1.9M per violation category per year; criminal penalties possible.
Key obligations
Safeguards
Administrative, physical & technical safeguards for PHI.
Minimum necessary
Limit PHI use/disclosure to what's required.
Audit controls
Log access to PHI in AI pipelines.
Breach notification
Notify within 60 days of a breach of unsecured PHI.
Sectors in scope
Healthcare providersHealth plansHealth-tech / AI diagnosticsPharma
Threats & cybersecurity it addresses
PHI exfiltrationModel memorisation of patient dataUnauthorised secondary use
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 22, 33, 47
Governed MCP tools — open source, pip/npx install