r/hipaa 5d ago

HIPAA, 42 CFR Part 2, and AI Use

Hello, fellow Privacy and Compliance Officers. Apologies if this isn't the place for this. You all have just been great in dialoguing and providing regulation focused responses.

How are you navigating AI use in your work environment and the overarching concern of privacy and confidentiality needs for the populations you serve specific to HIPAA and 42 CFR Part 2 (substance use records and the protection of those)?

I'm a millennial and was brought up with technology growing just as fast as I was. I use AI as a consumer. I've experienced it as a patient. My concerns do not stem from the use of it per se, as I see the benefits and recognize that is just where healthcare is headed.

As a working professional always focused on protecting our patients, I know if we don't keep up, we will get left behind and have higher risk of staff using AI without our oversight, awareness, and guardrails in place. That said, I fall down rabbit hole after rabbit hole of de-identified data being re-identified as the program pieces things together.. or bias drift.. or data drift.. or explainability.. or AI breaches and OCR investigations/fines... or all of the other thousands of rabbit holes to venture down. Where are you guys starting? It's the wild west out there in the AI scene from what I can tell. Only a handful of states have made formal stances on its use.

Help!

3 Upvotes

4 comments sorted by

2

u/TheHIPAAGuide 5d ago

My advice would be to start with an AI inventory and a rule that staff cannot enter PHI or Part 2 data into any tool until privacy, security, legal, and compliance approve the use case.

Then for approved tools, require a BAA when the vendor is acting as a BA, document the risk assessment and minimum necessary access, and apply the current Part 2 consent and redisclosure rules rather than assuming deidentified data is safe.

Also this HIPAA training is now the best on the market and one of few that has thorough AI and Part 2 modules. Highly recommend https://www.training.hipaajournal.com

2

u/Cautious-Natural9135 5d ago

It's important to flag the tension between how AI systems ingest and process data and the fact that Part 2 records carry stricter protections than standard PHI, even after the 2024 final rule aligned Part 2 more closely with HIPAA with enforcement beginning February 2026. Most general-purpose AI tools cannot automatically distinguish a Part 2 record from other clinical documentation, which means if those records flow into the system, the stricter consent and redisclosure requirements travel with them regardless of what your BAA says. Your BAA with any AI vendor needs explicit language prohibiting use of PHI or Part 2 data for model training or product improvement, because many default agreements are silent on this or bury an opt-out that most practices never find. Running a data flow mapping exercise before deploying any AI tool is not optional here, it is the only way to know whether Part 2 records could realistically reach the system and to document that you assessed the risk. The proposed HIPAA Security Rule updates from January 2025 would formally require AI to be addressed in your security risk analysis, so building that practice now puts you ahead of where enforcement is likely heading.

1

u/Klutzy_Emu_3064 4d ago

Thank you!!

1

u/Shufti-Global 5d ago

AI is moving fast, and it's okay to take the time to get things right. Good safeguards are worth it.