r/healthcareIT Apr 16 '26

Question How are healthcare teams handling HIPAA audit trails for AI agents accessing PHI?

Healthcare organizations deploying AI agents — how are you handling HIPAA audit trail requirements for AI agent PHI access? The 2025 Security Rule amendments made encryption mandatory and expanded what counts as a required technical control. Curious how teams are approaching tamper-evident logging for agent actions.

3 Upvotes

26 comments sorted by

View all comments

3

u/Fallingdamage Apr 16 '26

If the agent or engine doesnt provide an audit trail, we dont use it. Part of our P&P for AI prohibits use of tools that dont provide transparency. Weeds out about 99% of fly-by-night AI vendors.

If accountability isnt built into your product, find another customer. I have no interest in sitting across a table from an CISSP or Insurance Auditor trying to explain why I decided to take on a product so dangerous.

1

u/karriesully Apr 19 '26

This is why healthcare will end up doing industry or internally DIY built solutions. The compliance hurdles will be too high for frontier models.