
2026 HIPAA Security Rule Changes and Your AI Tools
The 2026 HIPAA Security Rule changes drop the addressable safeguard loophole and mandate MFA. What that means for psychologists vetting AI vendors.
2026 HIPAA Security Rule Changes and AI Tools
Somebody on your team signed up for an AI note tool with a work email. You found out three months later. Maybe it was a trial, maybe it's still running, and now you're the person who has to figure out whether ePHI went through it and whether anyone ever executed a BAA. If you run a group of more than about eight clinicians, you have lived some version of this. The 2026 HIPAA Security Rule changes make that scenario much more expensive because the wiggle room that used to let you say "we considered it and it wasn't reasonable and appropriate" is going away. Here's what changed, what it means for the AI tools already sitting inside your practice, and how to build a vendor file that survives an actual audit.
What the 2026 HIPAA Security Rule changes actually do
The short version. HHS put out a proposed rule in January 2025, and the headline item is the death of the required-versus-addressable distinction. Under the old Security Rule, a bunch of the meaningful controls (encryption, unique user IDs, automatic logoff) were "addressable," which, in practice, meant that many practices documented a rationale for not implementing them and moved on. hipaajournal.com has a piece on when AI technology and HIPAA collide, and the gist is that eliminating the addressable category tightens expectations around risk management, encryption, and resilience. Guess who feels that first. Practices running AI on patient data.
The other pieces you should have on your radar:
MFA on everything. Not on the EHR only. Multifactor authentication across systems that touch ePHI, including the admin console of whatever AI vendor your clinicians are using. If your intake coordinator logs into a transcription tool with a password and nothing else, that's a finding.
Encryption at rest and in transit, full stop. No more documenting why you skipped it.
A real technology asset inventory and network map. You have to know what systems exist, where the data sits, and how it moves. Most practices I've talked to can't produce this in under a week, and honestly, some can't produce it at all.
Annual security risk analysis, plus vulnerability scanning every six months and penetration testing annually. Written. Dated. Signed by someone.
72-hour restoration. Critical systems back up and running inside 72 hours after an incident, with contingency plans tested at least once a year.
Business associate verification. This is the one people underestimate. You don't just collect a BAA; you have to verify annually that your business associates actually have the required safeguards in place, with written certification from a subject matter expert.
[KEY TAKEAWAY: The 2026 HIPAA Security Rule changes convert "we thought about it" into "show me the documentation and the test results."]
Fair caveat before you build your whole Q3 around this: the rule was proposed, comment periods were held, and final compliance dates have shifted. Check the current status before you write policy. The 2026 changes roundup at ComplyCreate also notes HHS has signaled forthcoming OCR guidance specifically on AI and PHI, covering when AI vendor agreements need BAAs and who's accountable for AI-generated health information. So more is coming.

Do the 2026 HIPAA Security Rule changes apply to AI tools?
Yes, and the answer was already yes before 2026. Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate. None of that is a 2026 invention. What's new is how little tolerance there is for a vague BAA and a marketing page that says "enterprise-grade security."
Two things changed materially for AI specifically.
First up. There's an alert from Amundsen Davis on AI in health care and HIPAA compliance that spells it out: ePHI sitting within AI training data or predictive models is protected like any other ePHI. Read that twice if you've ever agreed to a TOS with an "improving our services" clause. That clause is now doing real legal work against you.
Second, the verification requirement means you can't outsource trust. Your BAA is the floor. On top of it, you need evidence: an active SOC 2 report, an ISO 27001 certificate with the scope statement attached, documented retention behavior, and a straight answer about data residency. There's a decent primer on HIPAA compliance for AI in healthcare that goes through how the Privacy Rule, the Security Rule, and Breach Notification all stack onto an AI rollout. Worth twenty minutes if you're the person in your org who inherited compliance without asking for it.
For multi-site groups, the practical problem isn't understanding the rule. It's that your ePHI is scattered across a scheduling platform, an EHR, a shared drive, someone's transcription app, and a folder of protocol PDFs, and nobody can draw the map. That fragmentation is both a documentation and a security problem. We wrote more about that in privacy and security in AI-powered report writing.
Red flags in an AI vendor's terms of service
I read a lot of these. The same phrases keep showing up.
"We may use de-identified or aggregated data to improve our services." The aggregate loophole. It sounds harmless. It means your clinical content is training material, and de-identification standards for narrative clinical text are genuinely contested. If a vendor won't define their de-identification method, treat this as a no.
Silence on retention. If the TOS says nothing about how long data is stored, the answer is indefinitely. Ask for the number in days. A vendor with zero retention will tell you immediately because it's their favorite thing to say. Worth reading up on "Zero Data Retention AI: Privacy Architecture for Psychology" before that call, so you know what follow-up questions to ask.
No named subprocessors. Every AI vendor uses model providers underneath. If they won't list them, you can't assess where the data physically goes, and data residency is now something you're expected to know.
A BAA you have to ask for three times. Or worse, a BAA that only covers the "core service," with the AI features subject to a separate consumer TOS. Read the scope clause, then read it again slowly.
Security page with logos, no reports. Badges are not evidence. Ask for the SOC 2 Type 2 report under NDA and the ISO 27001 statement of applicability. If they can't produce them, you have your answer.
How to evaluate AI tools under the 2026 HIPAA Security Rule changes
Here's the vendor file I'd want sitting in a shared folder for every AI tool your org touches, one folder per vendor, reviewed annually.
The executed BAA, with AI-specific provisions covering training use, subprocessors, and breach notification timelines.
Current attestations. SOC 2 Type 2, ISO 27001, and any third-party verification. Note the report period. A SOC 2 from 2023 is a historical artifact.
A written retention answer. Days, not adjectives.
Data residency. Which country, which region, and whether that changes under failover.
MFA support and enforcement. Not "we offer it." Can you enforce it org-wide as an admin and see who hasn't enrolled? The HIPAA MFA requirement is only useful if you can prove enforcement, not availability.
Their incident response and recovery commitments, mapped against your 72-hour obligation.
Your own annual verification note. Who checked, when, and what they looked at. One paragraph. It's the difference between a program and a pile of PDFs.
For the report-writing side specifically, this is where Psynth ended up in our stack, mostly because the security posture was documented before we asked rather than assembled afterward. Zero retention, HIPAA, PIPEDA, and GDPR alignment, ISO 27001, SOC 2 Type 2, and third-party verification through AIS. It's also the reason clinicians can pull assessment data into a first draft without three unvetted tools quietly appearing on the network. If you're building a comparison set, our roundup of HIPAA Compliant AI Tools for Psychologists in 2026 covers what to check across vendors.

Where to start if your vendor list is currently nobody's job
Do the inventory first. Not the policy, not the training deck. Pull your SSO logs and your expense reports and find out what's actually running. Most groups I've worked with find two to four tools they didn't know about, usually adopted by a well-meaning clinician who was drowning in report backlog and solved it themselves at 9 pm on a Thursday.
Then triage. Anything touching ePHI without a BAA gets shut off this week. Everything else goes into the folder structure above, with an owner's name on it.
The uncomfortable part of the 2026 HIPAA Security Rule changes is that shadow IT is now a compliance failure with your signature on it. The useful part is that it gives you a reason to consolidate. Fewer tools, better documented, actually verified. Psynth is one of the places where that consolidation paid off for us, because the synthesis work that used to spawn side tools now happens in one audited place.
Common questions about the 2026 HIPAA Security Rule changes
When do the 2026 HIPAA Security Rule changes take effect?
The rule was issued as a proposal in January 2025, and the dates have shifted multiple times, so check the current HHS posting before you commit anything to policy. Plan the work now, date the policy later.
Does a small solo practice have to do all of this?
Yes. Size doesn't get you an exemption. The scale of your risk analysis is smaller; the requirement isn't.
Is an AI report drafting tool a business associate?
If it touches ePHI, yes, and you need a signed BAA plus annual verification that the safeguards are real.
Compliance work is never what you wanted to spend your quarter on, and it's rarely what makes anyone's clinical week better, but a clean vendor file is the difference between an audit that takes an afternoon and one that takes a month. Our Trust Center lists exactly how Psynth handles MFA, encryption, and retention if you're building your own vendor file, and you can verify compliance status at our trust center rather than taking a blog post's word for it.
Frequently Asked Questions
What LLM providers does Psynth use, and are they HIPAA compliant?
Psynth holds commercial healthcare-grade agreements with Claude (Anthropic), Gemini (Google), and OpenAI. Each agreement includes explicit zero-retention and no-training clauses, with signed BAAs.
What about PHIPA, HIA, and other provincial health-privacy laws?
Psynth is provisionally compliant with provincial health-privacy regimes including Alberta's HIA, Ontario's PHIPA, British Columbia's PIPA, and the Personal Health Information Acts (PHIA) of Nova Scotia, Manitoba, and Newfoundland and Labrador, supported by Canadian data residency and audit logging.
How to make AI HIPAA compliant?
AI systems become HIPAA compliant when designed with clear safeguards for patient privacy and data integrity. HIPAA compliance depends on encryption, audit trails, and strict role-based access controls. Vendors must complete regular audits and sign a BAA confirming shared responsibility for PHI security.
How can a practice standardize report templates in Psynth?
Organization templates can be published for shared use and locked to protect an approved structure. Granular role-based access controls let the organization determine who can maintain shared templates, while psychologists use that foundation and retain responsibility for each report’s final content.
How do I start using Psynth?
Start a free trial directly in the Psynth app, then email support@psynth.ai to redeem the AU and NZ pricing offer.





