Compliance terminal

HIPAA AI risk audit

Five questions a carrier already knows how to ask. Score is exposure, 0–100. High is bad.

01

Do you have a written AI Acceptable Use Policy signed by every clinician?

Underwriters and OCR investigators treat unsigned ChatGPT drafts as no policy.

02

Do patients give documented consent before any ambient recording starts?

State consent + biometric-voice statutes (WA MHMDA, IL BIPA, NV SB 370) stack on HIPAA.

03

Is every AI-drafted note reviewed and attested by a licensed provider before sign-off?

70% of ambient-scribe drafts in one 2025 simulation contained at least one error. HITL is the underwriting line.

04

Has every AI tool that touches PHI a BAA plus a documented no-training / retention review?

Shadow tools (personal ChatGPT, Otter, consumer notetakers) are the #1 OCR finding in 2026 AI complaints.

05

Do you run a quarterly chart audit of AI-assisted documentation?

45 CFR § 164.308(a)(1)(ii)(D) requires information-system activity review. AI notes are in scope.

Exposure score

0/5 answered

/100

Answer all five to unlock the prescription.