Compliance
HIPAA
PHI inside AI workflows. Redaction activity and access records that support the Privacy and Security Rules.
At a glance
Who this covers, and who enforces it
Covered entities and business associates whose AI systems create, receive, maintain, or transmit protected health information (PHI).
- Instrument
- HIPAA Privacy, Security, and Breach Rules
- Enforced by
- HHS Office for Civil Rights
- Applies to
- Covered entities and business associates
- Penalties
- Tiered civil money penalties; criminal referral possible
- Breach notice
- No later than 60 days to affected individuals
Requirements
What it asks for
- 1Minimum necessary use of PHI
- 2Access controls and audit trails
- 3Breach detection and notification
- 4Business associate accountability
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Minimum necessary use
- Guardrails redact and block PHI on paths that shouldn’t see it, with a full event log.
- Access controls
- Projects & Team scope who can view traces that contain PHI.
- Breach detection
- Scores & Alerts surface anomalous access or output patterns.
- Business associate accountability
- Export & Audit gives a covered entity the evidence its BA agreement requires.
Primary source
Read the actual text
Everything on this page is drawn from HHS — The HIPAA Privacy Rule. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes HIPAA’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. HIPAA compliance remains your organization’s responsibility, in consultation with qualified counsel.
Ask us about your framework
Tell us how HIPAA applies to your systems and we'll show you the evidence path.