AI Patient Records: 6 Critical HIPAA Rules for 2026

AI Patient Records: 6 Critical HIPAA Rules for 2026

On September 1, 2026, OpenAI announced that healthcare organizations can now connect Epic environments directly to ChatGPT, with AdventHealth, Cedars-Sinai, HCA Healthcare, Memorial Sloan Kettering and UCSF among the launch partners. Dr. Alex Wissner-Gross flagged it in The Innermost Loop on September 4 with a single line — “ChatGPT reads Epic health records” — filed under the observation that intelligence is colonizing everything. He is right, and for anyone who runs a medical practice, that one line is a compliance project. AI patient records are no longer a hypothetical.

AI patient records

What Actually Happened

Two things shipped at once. First, an electronic health record integration that pulls what OpenAI calls “authorized patient context” from Epic into ChatGPT for Healthcare, so a clinician can ask what changed since the last visit or which labs to review before an appointment. That is AI patient records in the plainest sense of the phrase. Second, a Healthcare Public Data plugin wiring in nine official sources including PubMed, DailyMed, CMS Coverage, RxNorm and ClinicalTrials.gov.

Two details in OpenAI’s own announcement matter more than the demo. The first: “With an applicable Business Associate Agreement, customers can use ChatGPT Work, Codex, apps, and plugins in the same workspace to support HIPAA-compliant workflows.” That is a condition, not a description. The second: “The EHR integration is not available for individual accounts.” The enterprise deployment is the governed one. Individual accounts sit outside it — and so does the consumer ChatGPT already on your staff’s phones.

What It Means for Your Practice

If you own a dental group, a med spa, a weight-loss clinic, a telehealth practice or any other provider organization, AI patient records just moved from “someone will build this eventually” to “your competitors are piloting it this quarter.” The efficiency case is real — OpenAI says physicians rated 99.1% of responses safe across 4,363 ratings spanning 27 clinical use cases, and and, for each of the five connected data sources tested, more than 93% of responses rated “good” or better for accuracy.

Read the numbers behind AI patient records the way a defense lawyer reads them. Out of 4,363 ratings, roughly 39 were not rated safe. Up to seven percent of responses fell short of “good.” Those are the vendor’s own figures, generated in the vendor’s own evaluation, and they are perfectly respectable for software. They are not a legal standard, and they are not a defense. The clinician still signs the note.

Meanwhile, the federal agency that polices this has been quiet. We are aware of no HHS Office for Civil Rights guidance document, FAQ or enforcement action specifically addressing large language models. What OCR did do, in a page refresh dated July 30, 2026, was add to its list of business associate examples a “Third-party vendor Artificial Intelligence (AI) chatbot on a provider’s patient portal that provides services involving the patient’s PHI such as symptom assessment, medical reminders, and appointment scheduling.” One bullet, no roadmap. Anyone building a workflow around AI patient records is expected to work out the rest without an agency map.

Six HIPAA Rules Before AI Patient Records Leave the Chart

1. The BAA is the gate, and most people have never read theirs

Under 45 C.F.R. § 164.502(e)(1)(i), you may hand protected health information to a vendor only if you obtain “satisfactory assurance that the business associate will appropriately safeguard the information,” documented in a written contract. Section 164.504(e)(2)(ii) then dictates what that contract must say: ten specific promises at (e)(2)(ii)(A) through (J), plus the permitted-use terms at (e)(2)(i) and the right to terminate for a material breach at (e)(2)(iii). Two bite hardest on AI patient records. The vendor must bind its own subcontractors “to the same restrictions and conditions.” And at termination it must, “if feasible,” return or destroy all protected health information and “retain no copies” — or, where that is not feasible, extend the contract’s protections to that data and limit further use indefinitely. Ask a model vendor which of those two branches it is actually on, and watch the conversation get interesting. Sign before the first record moves, not after — no AI patient records project should start with an unsigned BAA.

2. Your real exposure is the consumer account, not the enterprise one

OpenAI expressly excludes individual accounts from the EHR integration. Nothing stops a physician from pasting a chart note into personal ChatGPT anyway, and that is a disclosure outside any BAA. Under 45 C.F.R. § 164.402, an impermissible disclosure “is presumed to be a breach unless” you can demonstrate a low probability of compromise using the four-factor risk assessment. The burden is yours, and the notification clock under § 164.404(b) runs “without unreasonable delay and in no case later than 60 calendar days after discovery.” Sanctioned AI patient records access is a governance problem. Unsanctioned access is a breach investigation.

3. Minimum necessary does not switch off because the tool is fast

Section 164.502(b) still requires “reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose.” Yes, there is an exception at § 164.502(b)(2)(i) for disclosures to or requests by a provider for treatment — but it is narrower than the marketing implies, and it does not cover the operational and administrative uses that make AI patient records attractive in the first place. Define the scope per use case, in writing.

4. This is a new information system, and the Security Rule knows it

An accurate and thorough risk analysis under § 164.308(a)(1)(ii)(A) is Required, not addressable, and a new AI pipeline touching ePHI triggers one. Audit controls under § 164.312(b) are a standard, so they are mandatory. Encryption at § 164.312(a)(2)(iv) and (e)(2)(ii) is labeled “Addressable,” which means documented reasoning — not optional. Treat AI patient records as a system, not a feature. And do not wait for the rules to modernize: the January 2025 proposal to make encryption and multifactor authentication mandatory, 90 Fed. Reg. 898, has still not been finalized. The Unified Agenda has it parked in long-term actions with a July 2027 target, and HHS’s own summary of the rule — content reviewed August 7, 2026 — still describes the Security Rule “currently in effect.” Today’s Security Rule is the 2013 one.

5. Vendor accuracy statistics are a negotiating position, not a shield

Allocate the risk in the contract or inherit it by default. Who owns an error from AI patient records that reaches the chart? What are the indemnity, audit and log-retention terms? Does the agreement bar training on your data, and does it survive termination? These are the same questions we work through in AI vendor contracts and AI training clauses, and they land harder when the subject matter is clinical. Then call your carrier: a growing number of policies carve out AI-driven loss, which we covered in business insurance AI exclusions. Coverage gaps do not announce themselves.

6. Patients are bringing their own AI, and HIPAA does not follow the data

Under § 164.524(c)(3)(ii), a patient may direct you to send a copy of their record “directly to another person designated by the individual,” so long as the request is in writing, signed, and clearly identifies the designee and where to send the copy. You generally have 30 days to act, with one 30-day extension available. One qualification the compliance vendors skip: in Ciox Health, LLC v. Azar, No. 18-cv-0040 (D.D.C. Jan. 23, 2020), a federal court vacated the third-party directive insofar as it reached beyond electronic copies of an electronic health record, and HHS’s own standing notice confirms the § 164.524(c)(4) patient-rate fee cap does not apply to third-party directives. Know which version of the rule you are operating under.

Once that file lands in a consumer AI tool the patient chose, HIPAA does not travel with it — the FTC’s Health Breach Notification Rule, 16 C.F.R. Part 318 as amended effective July 29, 2024, expressly “does not apply to HIPAA-covered entities” and instead reaches the health apps that are not covered. Your job is not to police the patient’s software. It is to make sure your right-of-access workflow is clean, because that is the part OCR audits — and because patient-initiated AI patient records requests are only going to increase.

What This Costs If You Get It Wrong

Civil money penalties under § 160.404 run in four culpability tiers. As adjusted by HHS on January 28, 2026 and codified at 45 C.F.R. § 102.3, the current per-violation ranges are $145 to $73,011 if you did not know; $1,461 to $73,011 for reasonable cause; $14,602 to $73,011 for willful neglect corrected within 30 days; and $73,011 to $2,190,294 for willful neglect left uncorrected. The calendar-year cap for identical violations is $2,190,294 in every tier. Those amounts are inflation-adjusted annually, so date-check them before you quote them to anyone. Against those numbers, the legal spend to set up AI patient records correctly is rounding error.

What Howard East Clients Should Do Now

Four things, in order. First, inventory reality: ask your staff, without blame, what AI tools they are already using and what they have pasted into them. That conversation is uncomfortable once and expensive if you skip it. Second, execute or refresh a BAA with every AI vendor that touches ePHI, and actually read it against the required terms at § 164.504(e)(2) — see our note on defining confidential information for how loose definitions create gaps.

Third, run the risk analysis and write an AI acceptable-use policy that names sanctioned tools, prohibits consumer accounts for anything clinical, and sets a reporting path — that policy is what turns AI patient records from an exposure into a controlled process. Fourth, if you are buying or selling a practice, add AI usage and BAA coverage to diligence; undocumented ePHI sitting in a third-party model is a real liability that follows the entity.

Call counsel before the pilot goes live, not after the first incident. If you are structuring a healthcare transaction where this shows up in diligence, our M&A practice at Howard Law Group handles it, and the underlying vendor agreements are ordinary contract work done with the regulation open on the desk. Clinics already navigating a regulated niche — see our guides on GLP-1 weight-loss clinics and ketamine and telehealth practices — have the most to lose from a sloppy AI patient records rollout, because they are already visible to regulators.

Ready to put AI patient records on a compliant footing? Book a consultation with Howard East to review your business associate agreements, AI acceptable-use policy and Security Rule risk analysis before your practice connects anything to a model.

This article is for informational purposes only and does not constitute legal advice. HIPAA compliance is fact-specific and state law may impose additional requirements; consult counsel about your particular circumstances. Regulatory citations are current as of September 5, 2026.

Share This on

Table of Contents

 

 

Howard East is a business-first law firm built for companies and owners who need clear answers, decisive action, and results that hold up under pressure. We focus on complex commercial litigation, corporate and transactional work, and administrative matters—handling everything from deal structure and risk allocation to disputes that threaten the business itself. Our approach is practical and direct: we learn the business, identify the leverage points, and execute a strategy designed to protect your position and maximize outcomes. Clients choose Howard East because we combine high-end legal precision with real-world judgment, responsive communication, and an uncompromising commitment to integrity.

Ready to Protect Your Art and Your Money?

Howard East attorneys work with artists, managers, and creatives on holding company formation, brand deals, IP protection, and outside general counsel retainers.

Related Posts