Use this no-login checklist to organize evidence before a healthcare AI vendor demo, pilot, or security review. It helps teams request HIPAA / BAA, PHI handling, security, retention, subprocessor, audit, and incident response documentation. It does not certify HIPAA compliance, confirm BAA sufficiency, approve a vendor, or replace legal, privacy, security, compliance, clinical, billing, coding, reimbursement, or procurement review. Do not enter PHI, patient examples, credentials, private contract terms, NDA material, or security questionnaire text into public notes.
Evidence sections
| Section | Evidence to request | Owner to route |
|---|---|---|
| Vendor role | Whether the vendor receives, creates, maintains, transmits, stores, or processes PHI for a covered entity or business associate workflow. | Privacy / compliance / legal |
| BAA path | BAA availability, covered services, permitted uses, required uses, safeguards, breach terms, and return or destruction terms. | Legal / privacy |
| PHI data flow | Data types, source systems, destinations, logs, support access, analytics, backups, exports, and deletion path. | Security / privacy / IT |
| Subprocessors | Subprocessor list, services performed, PHI access, flow-down obligations, geography, and change notice process. | Security / legal |
| Retention and deletion | Retention period, deletion procedure, backup handling, account termination, and support-ticket data handling. | Security / privacy |
| Model training and product improvement | Whether customer data, prompts, transcripts, notes, claims, metadata, or derived data can be used for training, benchmarking, human review, or product improvement. | Privacy / legal / AI governance |
| Access controls and audit logs | Role-based access, least privilege, SSO, admin access, support access, audit log retention, and audit log exportability. | Security / IT |
| Incident response | Security incident notice, breach notification workflow, investigation support, contact path, and evidence preservation. | Security / legal / compliance |
| Security artifacts | Security page, SOC 2 or equivalent artifacts if available, penetration test summary if shareable, risk assessment materials, encryption notes, and hosting documentation. | Security |
| Workflow boundary | Which users, settings, data types, AI outputs, and downstream actions are in scope or out of scope for review. | Workflow owner / procurement |
Use this with PHI flow review
Pair this checklist with the PHI Use Risk Analyzer. Use the PHI worksheet to map data movement, then use this checklist to request evidence for contracts, safeguards, subprocessors, retention, access, logging, and incident response.
For a broader demo or procurement screen, use the Healthcare AI Vendor Readiness Checker before routing evidence to reviews, compare pages, or internal reviewers.
Official-source review path
Start with HHS business associate guidance and HHS Security Rule guidance. Use NIST AI RMF and the NIST Cybersecurity Framework as risk-management vocabulary, not as proof that a vendor is HIPAA compliant.
- HHS Business Associates
- HHS Security Rule Guidance
- NIST AI Risk Management Framework
- NIST Cybersecurity Framework
Continue your HealthAIdir research
- Read buyer guides for HIPAA-compliant AI tools, AI and PHI review, vendor security and BAA review, and healthcare AI vendor evaluation.
- Review glossary references for HIPAA, BAA, PHI, HIPAA-compliant AI, model training exclusion, and audit log.
What this checklist does not do
This checklist does not certify HIPAA compliance, determine whether a BAA is sufficient, approve a vendor, interpret contract language, validate security claims, or decide whether PHI may be used in a workflow. Route the evidence to qualified legal, privacy, security, compliance, clinical, billing, coding, reimbursement, procurement, and workflow reviewers before making operational decisions.