HIPAA and AI Safety: What Compliant Really Means

Compliant is not a badge you can buy. For a dental practice weighing an AI tool, it means specific things: a signed BAA, a clear answer to where data goes, and a review that holds up to scrutiny.

The friction: compliant sounds like a yes or no, and it is not

Every AI vendor will tell you they are HIPAA compliant. It sounds like a settled yes or no, so it is tempting to check the box and move on. The friction this post removes is that false simplicity. Compliant is not a certificate you buy once. It is a set of specific commitments and practices, and the only way to trust a vendor's claim is to know what those specifics are and ask for them.

This matters most when patient information is involved, which for a documentation tool is the whole point. So it is worth knowing exactly what to look for, and what a serious answer sounds like.

A BAA is the floor, not the finish

The business associate agreement is the baseline. Under HIPAA, any vendor that handles protected health information on your behalf should sign a BAA that spells out how they protect it and what happens if something goes wrong. If a vendor will not sign one, the conversation is over. But a signed BAA is the floor, not proof of everything above it. It commits a vendor to obligations; it does not by itself describe how the tool actually handles your data day to day.

  • Ask whether they sign a BAA at all, and for which plans or editions.
  • Read what the BAA actually commits them to, not just that one exists.
  • Ask what happens to your data if you stop using the tool.

Where does the data go?

The most useful safety question is the most concrete one: where does patient data go, and who can see it? A good vendor can answer plainly. What is collected, where it is processed, how it is protected in transit and at rest, whether it is used to train models, and who inside the company can access it. Vague or shifting answers to these questions are the real warning sign, more than any missing logo.

For a documentation tool grounded in the encounter, this is especially important, because the transcript and the note contain exactly the information HIPAA is written to protect. You want a clear, checkable account of the path that data takes.

What compliant really means

Put together, compliant is not one thing. It is a signed BAA, a design built for HIPAA from the start, honest answers about where data lives and moves, access controls that limit who can see what, and provisioning that fits how your organization manages people. Chairside is built for HIPAA, offers a BAA for enterprise, and supports SSO and SCIM for provisioning.

On formal attestation, we are deliberately careful with our words. We are targeting SOC 2 Type II. We describe it as targeting, in progress, and not yet certified, because the honesty of that claim is exactly what a serious reviewer checks, and a vendor that overstates it has already told you something about how they will treat the rest.

Compliant is not a badge. It is a set of commitments you can read, verify, and hold a vendor to.

How Chairside treats compliance

For DSO procurement and security review

At the group level, this stops being a solo judgment call and becomes a committee process. Security and IT will have their own list, and they should.

DSO procurement sidebar: expect to review the BAA terms, a data flow description, access controls, SSO and SCIM support, and the current status of SOC 2 (targeting, with evidence of the work in progress). Ask for these in writing, run a pilot on one or two locations under the same controls you would use at scale, and expand on what the review actually shows rather than on the pitch.

We would rather answer a hard security question honestly than win a review by overstating a certification. If your reviewer wants to go deep on any of the above, that is the conversation we want to have.

An honest limit

No vendor, including us, can make patient data risk-free, and anyone who says otherwise is overselling. What a serious vendor can do is be specific, be checkable, and be honest about what is done and what is still in progress. If a practice already has a security setup it trusts and a documentation approach that clears its own review, that is a real position, and adding a tool should meet that same bar, not lower it.