Skip to content

Compliance

HIPAA

PHI inside AI workflows. Redaction activity and access records that support the Privacy and Security Rules.

At a glance

Who this covers, and who enforces it

Covered entities and business associates whose AI systems create, receive, maintain, or transmit protected health information (PHI).

HIPAAFramework
Instrument
HIPAA Privacy, Security, and Breach Rules
Enforced by
HHS Office for Civil Rights
Applies to
Covered entities and business associates
Penalties
Tiered civil money penalties; criminal referral possible
Breach notice
No later than 60 days to affected individuals

Requirements

What it asks for

  • 1Minimum necessary use of PHI
  • 2Access controls and audit trails
  • 3Breach detection and notification
  • 4Business associate accountability

Evidence mapping

What PRISM records against each requirement

Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.

HIPAA
Minimum necessary use
Guardrails redact and block PHI on paths that shouldn’t see it, with a full event log.
Access controls
Projects & Team scope who can view traces that contain PHI.
Breach detection
Scores & Alerts surface anomalous access or output patterns.
Business associate accountability
Export & Audit gives a covered entity the evidence its BA agreement requires.

Primary source

Read the actual text

Everything on this page is drawn from HHS — The HIPAA Privacy Rule. The capture is live, not a paraphrase — go straight to the source and check us.

hhs.gov
Capture of HHS — The HIPAA Privacy Rule
Live capture, 24 Aug 2026Open the source ↗

Evidence, not certification

This page describes HIPAA’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. HIPAA compliance remains your organization’s responsibility, in consultation with qualified counsel.

Ask us about your framework

Tell us how HIPAA applies to your systems and we'll show you the evidence path.