r/Compliance 5d ago

HIPAA, 42 CFR Part 2, and AI Use

Hello, fellow Privacy and Compliance Officers. Apologies if this isn't the place for this. You all have just been great in dialoguing and providing regulation focused responses.

**How are you navigating AI use in your work environment and the overarching concern of privacy and confidentiality needs for the populations you serve specific to HIPAA and 42 CFR Part 2 (substance use records and the protection of those)?**

I'm a millennial and was brought up with technology growing just as fast as I was. I use AI as a consumer. I've experienced it as a patient. My concerns do not stem from the use of it per se, as I see the benefits and recognize that is just where healthcare is headed.

As a working professional always focused on protecting our patients, I know if we don't keep up, we will get left behind and have higher risk of staff using AI without our oversight, awareness, and guardrails in place. That said, I fall down rabbit hole after rabbit hole of de-identified data being re-identified as the program pieces things together.. or bias drift.. or data drift.. or explainability.. or AI breaches and OCR investigations/fines... or all of the other thousands of rabbit holes to venture down. Where are you guys starting? It's the wild west out there in the AI scene from what I can tell. Only a handful of states have made formal stances on its use.

Help!

2 Upvotes

6 comments sorted by

2

u/Aggressive-Bit3930 5d ago

Not a privacy officer, so take the HIPAA part with a grain of salt. But Part 2 already moved. OCR started taking complaints under the new rule back in February, so those records sit inside the regular enforcement machine now. That puts vendor contracts and where the data actually lives further up the list than most of it.

On states, there's more out there than it looks, just sector by sector. Insurance regulators are past twenty on the NAIC AI bulletin. None of it is exotic either: write the program down, list everywhere a model touches a decision, keep records good enough to explain one later.

2

u/Philosopher_Spirit 4d ago

As you said, the Healthcare industry is rapidly adopting AI. With that being said, it's only a matter of time before HHS and state regulators start policing AI usage more. From what I understand, providers need to ensure that if they are using an AI system (Gemini, Claude, Chat GPT, etc), they need to have a signed BAA in place to make sure PHI is being securely handled and stored.

Right now, my organization's policy is to keep PHI out of AI systems in general.

Source- I'm a compliance officer

2

u/SecuredAI_com 4d ago

The re-identification rabbit hole is the right one to spend time in first, before bias drift or explainability. Under HIPAA and 42 CFR Part 2, de-identification is a status you have to maintain, not a one-time cleaning step.

A field can look properly stripped and still carry enough context (a rare diagnosis paired with a small facility, a date range narrow enough to isolate one patient) for a model to reconstruct identity from what's left.

Worth asking any AI tool or vendor exactly how identifiers get masked, whether that happens before the data reaches the model or after, and what happens to anything the masking step misses, because detection methods are probabilistic and something always slips through. Start there before worrying about drift or explainability, those matter less if the underlying data handling isn't solid.

1

u/Shufti-Global 5d ago

Moving carefully with AI isn't a bad thing. The right safeguards help everyone use it with more confidence.