← All frameworks
Binding

HIPAA

US HHS / OCR · Washington DC, US · effective 1996 (Security Rule 2005)

US health-data protection. For AI, governs PHI used to train or run clinical/administrative models — access controls, audit trails, minimum-necessary and breach notification.

Who must comply
  • ▸Covered entities (providers, plans, clearinghouses)
  • ▸Business associates incl. AI vendors handling PHI
Penalties

Up to $1.9M per violation category per year; criminal penalties possible.

Key obligations
Safeguards
Administrative, physical & technical safeguards for PHI.
Minimum necessary
Limit PHI use/disclosure to what's required.
Audit controls
Log access to PHI in AI pipelines.
Breach notification
Notify within 60 days of a breach of unsecured PHI.
Sectors in scope
Healthcare providersHealth plansHealth-tech / AI diagnosticsPharma
Threats & cybersecurity it addresses
PHI exfiltrationModel memorisation of patient dataUnauthorised secondary use
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping

Charter Art. 22, 33, 47

Governed MCP tools — open source, pip/npx install