HIPAA and AI: What Healthcare Practices Need to Know Before Adopting Copilot
Before a healthcare practice enables Microsoft Copilot or any AI assistant, these are the HIPAA questions to answer — from BAAs to prompt hygiene to the documentation auditors expect.
- Confirm that each AI service handling protected health information is explicitly covered by a signed Business Associate Agreement before enabling it.
- Restrict AI use to your governed Microsoft 365 tenant, and make unmanaged public or personal-account AI tools unavailable to staff.
- Apply minimum-necessary access controls and train staff to limit PHI in prompts while requiring human review of all AI-generated output.
- Document AI-specific risk assessments, acceptable-use policies, staff training, signed BAAs, and access logs to demonstrate HIPAA readiness to auditors.
- Start with low-risk internal drafting workflows only after completing governance controls, then expand AI use based on documented risk review.
Microsoft Copilot and similar AI assistants promise real relief for healthcare practices drowning in documentation and administrative work. But for any organization handling protected health information (PHI), the excitement has to be tempered with a clear-eyed look at HIPAA. The good news: adoption is achievable. The requirement: you have to do the groundwork first.
The core question: where does PHI go?
Every HIPAA analysis of an AI tool starts with one question — where does the data go, and who can see it? An AI assistant that summarizes a patient email, drafts a note, or searches your files is processing PHI. Under HIPAA, you are responsible for knowing how that data is stored, transmitted, and retained, and for ensuring it stays inside controls you can account for.
If you cannot answer where the data goes, you are not ready to enable the tool — regardless of how useful it is.
Business Associate Agreements and AI vendors
Any vendor that handles PHI on your behalf is a business associate and must sign a Business Associate Agreement (BAA). This is non-negotiable. Before enabling an AI feature, confirm:
- The specific AI service is covered by a signed BAA — not just the vendor's other products.
- The BAA reflects how the AI service actually processes and retains data.
- Consumer or free tiers of AI tools are excluded, because they are rarely covered by any BAA.
A common and costly mistake is assuming that a BAA covering email or file storage automatically extends to a new AI capability. Verify it explicitly.
Copilot inside Microsoft 365: what is covered, what is not
When Copilot operates inside your organization's Microsoft 365 environment under an enterprise agreement, it is designed to respect your existing tenant boundaries and permissions, and it can fall under Microsoft's BAA. That is meaningfully different from an employee pasting patient details into a public chatbot on a personal account.
The dividing line is control. AI running inside your governed tenant, honoring your access rules, is a candidate for compliant adoption. AI running outside it is a data-exposure incident waiting to happen. Part of readiness is making the compliant path the easy one and the unmanaged path unavailable.
Minimum necessary and prompt hygiene
HIPAA's minimum-necessary principle applies to AI just as it does to any other access. Copilot inherits the permissions of the user running it, so if a staff member has broad access to patient records, the assistant does too. Tightening permissions before adoption is both a security measure and a compliance one.
Prompt hygiene matters as well. Train staff to avoid entering more PHI than a task requires, and to treat AI output as a draft that a person reviews — never as a final clinical or billing record that goes out unchecked.
The documentation auditors expect
If your use of AI is ever examined, you want to show a deliberate, documented process rather than an improvised one. At minimum, keep:
- A risk assessment that specifically addresses your AI tools and the PHI they touch.
- The signed BAA covering the AI service.
- An acceptable-use policy and evidence that staff were trained on it.
- Access and audit logs showing how the tools are used.
A safe path to adoption
A healthcare practice can adopt Copilot responsibly by working in the right order: confirm the BAA, tighten identity and access controls, restrict AI to the governed tenant, publish and train on a clear policy, and start with a low-risk workflow such as internal drafting before expanding to anything that touches patient communication.
AI does not have to be a HIPAA liability. Approached as a governance decision rather than a software toggle, it becomes a safe, auditable way to give clinical and administrative teams their time back.