Healthcare Compliance Governance
HIPAA AI Audit Readiness Checklist for Health Systems
What a compliance officer needs on file before an OCR investigator or a routine HIPAA Security Rule review asks how the health system's AI systems handle protected health information, and why the risk analysis itself is the single most common gap.
A HIPAA AI audit readiness checklist confirms that every AI system touching protected health information has a documented risk analysis, a named accountable owner, access controls mapped to the Security Rule, a business associate agreement where a vendor is involved, and audit logs an OCR investigator can review without delay.
hipaa ai audit what
What a HIPAA AI Audit Readiness Checklist Actually Covers
A HIPAA AI audit readiness checklist confirms that every AI system touching protected health information has a documented risk analysis, a named accountable owner, access controls mapped to the Security Rule, a business associate agreement where a vendor is involved, and audit logs an OCR investigator can review without delay.
The checklist itself is not new. HIPAA has required a risk analysis under 45 C.F.R. 164.308(a)(1)(ii)(A) since the Security Rule took effect. What changed is what counts as in scope. Ambient documentation scribes, prior-authorization automation, imaging triage models, and patient-facing chatbots all touch protected health information now, and each one has to be added to the same inventory, risk-tiering, and testing process that used to apply only to the EHR and a handful of connected systems.
Most health systems already have a HIPAA compliance program. The gap this checklist closes is narrower: whether that program's risk analysis has actually been updated to name each AI system, describe how it uses PHI, and document who reviews its output before it reaches a patient or a claim. A program that has not been refreshed since before the AI system went live is the finding an examiner will look for first.
hipaa ai risk analysis finding
Why Risk Analysis Failures Are the Most Cited HIPAA AI Finding
Missing or inadequate risk analysis is the single most common deficiency behind HHS Office for Civil Rights enforcement actions, and OCR has been actively working through a dedicated Risk Analysis Initiative since late 2024.
OCR's Risk Analysis Initiative produced seven separate enforcement actions in its first six months, from fall 2024 through April 2025, with settlements ranging from $10,000 to $350,000. Every one of those actions cited the same underlying deficiency: a failure to conduct an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI, the exact language of 45 C.F.R. 164.308(a)(1)(ii)(A).
That pattern matters for AI specifically because a risk analysis written before an organization deployed an AI system, by definition, cannot describe how that system handles PHI. Health systems that treat their existing risk analysis as still current after adding an AI tool are carrying the exact gap OCR's initiative has been built to find.
hipaa ai checklist steps
The HIPAA AI Audit Readiness Checklist, Step by Step
The checklist runs in a fixed order: inventory the AI systems, refresh the risk analysis to name each one, confirm access controls and logging, check vendor agreements, document human review points, and assemble the packet an examiner would ask for.
1. Inventory every AI system touching PHI
List ambient scribes, prior-authorization tools, imaging or diagnostic AI, patient chatbots, and any AI features inside the EHR itself, including ones added by a vendor update rather than a formal project.
2. Refresh the Security Rule risk analysis for each system
Update or extend the existing risk analysis so it names each AI system individually, describes how it uses PHI, and assesses its specific risks and vulnerabilities rather than treating it as covered by the general EHR analysis.
3. Map access controls and audit logging
Confirm role-based access to each AI system's PHI inputs and outputs, and that audit logging captures who accessed what, and when, at the level HIPAA's audit control standard expects.
4. Confirm business associate agreements cover the AI vendor
Check that the BAA with each AI vendor, and any subprocessor that vendor uses for model hosting or fine-tuning, explicitly covers the AI system's handling of PHI, not just the underlying platform.
5. Document human review and override points
Record where a clinician or staff member reviews or can override an AI system's output before it affects a clinical or billing decision, and keep evidence that the review actually happens.
6. Assemble the exam-ready packet
Bring the inventory, the refreshed risk analysis, BAAs, access and audit logs, and staff training records together in a form a non-technical investigator can follow without asking the health system to reconstruct it under deadline.
hipaa ai audit urgency
Why This Is Urgent for Health Systems Right Now
Large healthcare data breach reports to HHS OCR stayed elevated in 2025, and OCR's enforcement attention is concentrated on the same risk analysis gap that AI rollouts tend to create.
HHS OCR received 710 reports of breaches affecting 500 or more individuals in 2025, a rate of roughly two large breaches a day and about twice the frequency seen in 2018. That volume keeps OCR's investigative attention active across the sector, and every one of those investigations starts by asking for the risk analysis.
A health system rolling out ambient AI documentation, AI-assisted prior authorization, or an AI triage tool without updating that risk analysis first is adding exposure at the exact moment OCR's Risk Analysis Initiative is looking hardest for it.
kriv ai hipaa engagement
What a Kriv AI HIPAA Audit Readiness Engagement Includes
A typical engagement starts with the AI system inventory and a gap assessment against the existing risk analysis, then closes each gap with documentation an examiner can review directly.
The engagement begins by inventorying every AI system touching PHI and comparing it against the current risk analysis to identify what is missing. From there it produces the refreshed risk analysis language, an access-control and audit-logging review, a BAA gap check against each AI vendor, and the documentation packet itself, built so compliance staff can hand it to an investigator without last-minute assembly.
Because most of the underlying HIPAA program is usually sound, the work concentrates on the AI-specific gap: naming the systems, documenting how each one uses PHI, and proving the human-review points that matter to an examiner actually happened.
rates work
Rates for This Work
Rates below are floors, not fixed quotes. Final scope depends on how many AI systems are in the inventory and how recently the underlying risk analysis was last updated.
| Track | Hourly Rate | Model | Minimum |
|---|---|---|---|
| Enterprise / Health System | From $200/hr | Fixed-scope or retainer | $8,000 |
| Fractional Compliance Governance Lead | $300-$400/hr | Part-time, ongoing | $8,000 |
| Specialized Advisory | $400-$700/hr | Hourly, per-session | Varies |
get real quote
How to Get a Real Quote
A real quote needs a rough count of the AI systems already in production or pilot and when the current risk analysis was last updated.
Bring the number of AI tools touching PHI across clinical and administrative workflows, whether any OCR inquiry or complaint is already in motion, and the date of the last risk analysis update. That is enough to scope a fixed engagement or a retainer against the rates above rather than the floor.
Sources
Cited sources
- HIPAA Journal, 2025 Healthcare Data Breach Report: 710 large breaches (500+ records) reported to HHS OCR in 2025, a rate of roughly two large healthcare data breaches a day.
- Feldesman LLP on OCR's Risk Analysis Initiative: seven HIPAA enforcement actions in its first six months (fall 2024 through April 2025), settlements from $10,000 to $350,000, each citing failure to conduct an accurate and thorough risk analysis under 45 C.F.R. 164.308(a)(1)(ii)(A).
Straight answers
Frequently asked questions about HIPAA AI Audit Readiness Checklist for Health Systems
What does a HIPAA AI audit readiness checklist cover?
It confirms every AI system touching protected health information has a documented risk analysis naming that system, access controls and audit logging mapped to it, a business associate agreement covering the AI vendor, and evidence of any human review point before the AI's output reaches a patient or a claim.
Why is risk analysis the most common HIPAA AI audit finding?
Because a failure to conduct an accurate and thorough risk analysis under 45 C.F.R. 164.308(a)(1)(ii)(A) is the deficiency cited in nearly every OCR enforcement action, and a risk analysis written before an AI system was deployed cannot describe how that system actually handles PHI.
What is OCR's Risk Analysis Initiative?
A dedicated HHS Office for Civil Rights enforcement initiative launched in fall 2024 that produced seven enforcement actions in its first six months, with settlements from $10,000 to $350,000, each one citing a failure to conduct a thorough risk analysis.
Does a health system need a separate risk analysis for each AI tool?
Not necessarily a separate document, but the existing Security Rule risk analysis has to be extended to name each AI system individually and describe how it uses PHI. Treating a new AI tool as automatically covered by an older, general risk analysis is the gap OCR looks for.
Do business associate agreements need to specifically cover AI vendors?
Yes. The BAA with an AI vendor, and any subprocessor it uses for hosting or fine-tuning, needs to explicitly cover that vendor's handling of PHI through the AI system, not just the underlying software platform.
How urgent is this for health systems in 2026?
HHS OCR received 710 reports of large healthcare data breaches in 2025, about two a day, keeping OCR's investigative attention active across the sector while its Risk Analysis Initiative continues to target the exact gap most AI rollouts create.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call