Ambient scribes are in the exam room, AI is drafting patient messages, and phone agents are booking appointments. HIPAA did not change; what changed is how many vendors now touch protected health information. AboveBoard turns HIPAA, the new state disclosure laws and the Joint Commission's responsible-AI guidance into forty controls, an independent review and a verified score for your compliance officer, your payers and your board.
Any AI vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate and needs a business associate agreement before PHI flows. The Security Rule's risk analysis has to include AI tools, the minimum-necessary standard applies to what you paste into them, and the breach-notification clock starts when an AI tool exposes PHI. OCR investigates on complaint, and a patient who learns their visit was recorded without notice is a complaint.
California AB 3030 (effective Jan 1, 2025) requires a disclaimer and instructions for reaching a human on generative-AI patient communications about clinical information. Texas TRAIGA (Jan 1, 2026) requires healthcare providers to disclose AI use in treatment under its companion provisions (Baker Botts, Jul 2025). Utah's AI Policy Act requires licensed professionals to disclose generative AI in high-risk interactions (as amended 2025). Colorado SB 26-189 (Jan 1, 2027) covers healthcare decisions: notice, a 30-day explanation after an adverse outcome, human review and three years of records (Seyfarth, May 2026). Connecticut SB 5 (Oct 1, 2026) also reaches healthcare (Ropes & Gray, Jun 2026).
The Joint Commission and the Coalition for Health AI issued Responsible Use of AI in Healthcare guidance in September 2025 and launched a voluntary RUAIH certification on June 2, 2026, open to any healthcare organization. It covers governance, data management, risk and bias mitigation, safety monitoring, and transparency and training (Fierce Healthcare, Jun 2026). Hospital systems will pursue it, and will start asking the practices they refer to and contract with what their AI governance looks like.
Payer credentialing, health-system affiliation and value-based contracts increasingly carry AI questions, and liability and cyber underwriters are adding AI questionnaires and endorsements (Fenwick, Jun 2026). Half of privacy and security professionals admit entering non-public data into generative AI tools (Cisco, Apr 2025); in a practice, that data is PHI.
Ambient AI scribes that record the visit and draft the note, AI inbox-message drafting inside the EHR, dictation and transcription. These generate the medical record, so the clinician's sign-off is the control that matters most.
AI phone agents and scheduling bots, website chatbots that answer clinical-adjacent questions, appointment reminders and patient-portal replies, translation. Each one talks to patients, and each one is covered by the new disclosure laws.
Coding and charge-capture assistants, prior-authorization automation, claims-denial drafting, ChatGPT and Copilot for letters, policies and referrals. Often on personal accounts, often with PHI pasted in.
Forty controls, eight per domain, scored on evidence. Here is how they read when the data is PHI and the reviewer could be OCR.
A written AI policy adopted by leadership, a named owner (compliance officer, practice administrator or medical director) with authority to switch off a tool, an inventory of AI tools and use cases with risk ratings, and AI governance folded into the HIPAA compliance program.
Evidence examples: the policy with its approval date; the register listing the scribe, inbox drafting, phone agent and billing AI with an owner and a risk rating for each; the HIPAA compliance-program section that cross-references AI; the obligations memo covering AB 3030, Texas and Utah disclosure duties.
PHI classified so staff know it never enters an unapproved tool, an approved-tool list, a BAA plus no-training and retention terms for every approved vendor, single sign-on, retention rules for audio and drafts, patient notice and consent for recording, and AI tools included in the Security Rule risk analysis.
Evidence examples: the BAA and vendor terms review log for the scribe vendor, with the training-on-data clause and audio-retention period highlighted; the Security Rule risk analysis entry for AI tools; the patient notice and consent script for ambient recording.
A clinician reviews and signs every AI-drafted note and message before it enters the record or reaches a patient; notes are sampled for accuracy; the incident plan covers an AI tool exposing PHI or a harmful drafting error and maps to breach notification; vendor model changes are tracked; AI-assisted notes are identifiable in the chart.
Evidence examples: the documentation policy stating the AI draft is not the note until signed; the monthly note-sampling log with corrections; the incident-plan section referencing HIPAA breach notification; the EHR flag that tags AI-generated drafts.
Training completed by 90%+ of clinicians, front-desk, billing and administrative staff; role-specific modules; reviewer training for clinicians on what an AI note gets wrong; signed acknowledgments; a leadership governance session.
Evidence examples: the completion report alongside the annual HIPAA training record; the acknowledgment file; the clinician reviewer-training deck and attendance.
Patients are told when AI is involved in their care communications and when a visit is recorded; "AI-powered care" claims are reviewed; payer and health-system questionnaires are answered from a standard bank; complaints involving AI have an owner and a response time.
Evidence examples: the AB 3030 disclaimer on generated patient messages; the posted AI-use statement in the waiting room and on the website; the last three payer or health-system AI questionnaires, consistent with each other.
No practice is listed at any level with a zero on G1 (written policy), D3 (vendor terms reviewed) or O1 (human review before client-facing output). In a practice, O1 is the clinician's signature on the note.
Read the full rubricThe AI and vendor-security sections are answered once from verified evidence, with a registry link. Affiliation and credentialing teams get consistency.
The application's AI questions map to G1, D2, D3, O1, O3 and W1. Attach the report and the year-stamped badge. Coverage decisions remain the carrier's.
A plain-English report by domain with gaps and fixes. Practices heading toward Joint Commission RUAIH certification use the evidence file as their starting point.
AboveBoardAI issues a score and a verification under a private, voluntary standard; it is not HIPAA certification (no such thing exists), not Joint Commission certification, not clinical validation of any AI tool, and not legal advice. It verifies that your AI governance practices exist and are evidenced on the review date. See What is an AI audit?
Take the free Snapshot. List every AI feature in the EHR, phone system, website and billing stack, plus the general assistants staff use. Note which ones touch PHI. That is your register.
Confirm a BAA and reviewed terms for every PHI-touching tool; retire the ones you cannot paper. Adopt an AI acceptable-use policy (our template has healthcare notes) and add AI to your Security Rule risk analysis.
Write the documentation rule: the AI draft is not the note until a clinician signs it. Post the AI-use statement and script the recording notice. Roll out Academy Foundations and collect acknowledgments.
Start a monthly note-sampling log. Add the AI section to your incident plan. Start the full assessment; Snapshot answers carry over.
Growth Firm (50–249) $18,000; Established Firm (250–999) $42,000; Enterprise (1,000+) from $75,000. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy Foundations. Dental, behavioral health, therapy, specialty and multi-site groups are all in scope.
If the tool creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a business associate agreement before PHI is shared. Ambient scribes, AI inbox-drafting tools, transcription services and coding assistants all handle PHI. The BAA is necessary but not sufficient: you also need to know whether the vendor trains on your data, how long audio and drafts are retained, and who its sub-processors are.
Increasingly, yes. California AB 3030 (effective Jan 1, 2025) requires a disclaimer and human-contact instructions on generative-AI patient communications about clinical information. Texas requires healthcare providers to disclose AI use in treatment under its 2026 AI law (Baker Botts, Jul 2025), and Utah requires licensed professionals to disclose generative AI in high-risk interactions. Recording a visit also raises state consent rules. Most practices adopt a short verbal notice plus a posted statement, and document it.
No. The Joint Commission, with the Coalition for Health AI, launched its voluntary Responsible Use of AI in Healthcare certification on June 2, 2026, open to any healthcare organization (Fierce Healthcare, Jun 2026). AboveBoardAI is a private, voluntary standard for firms that use AI, priced for practices of 10 to 1,000 people, and it covers the same governance ground: policy, data, human oversight, training and transparency. Many practices treat AboveBoard as the practical first step, or as the governance program for non-clinical operations.
No. AboveBoard does not test AI models or clinical tools and never certifies that an output is correct. It verifies that the practices which catch errors exist and are evidenced: a clinician signs every AI-drafted note, notes are sampled for quality, incidents are logged and acted on, and vendors are monitored.
AboveBoardAI is priced annually by headcount: $7,500 for practices of 1 to 49 people, $18,000 for 50 to 249, $42,000 for 250 to 999 and from $75,000 for 1,000 or more. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy training for all staff. See pricing.