The practical answer
A healthcare AI MVP should begin with a narrow workflow and a clear statement of whether it handles PHI, influences clinical decisions, or could fall within FDA oversight. "HIPAA compliant" is not a feature that can be attached to a model or hosting provider in isolation.
HIPAA responsibilities
When a service creates, receives, maintains, or transmits ePHI for a covered entity or business associate, HHS generally treats it as a business associate and requires an appropriate BAA. The covered entity and its vendors must also implement the administrative, physical, and technical safeguards required for their roles.
A provider offering a BAA only establishes contractual availability for eligible services and configurations. The customer must still configure access, logging, retention, incident response, workforce procedures, and risk management correctly.
FDA considerations
Some clinical decision-support functions are excluded from the device definition, while others remain medical devices. FDA's January 2026 final guidance focuses on factors such as intended user, intended use, whether the clinician can independently review the basis for a recommendation, and whether the function meets the statutory criteria for non-device CDS.
Do not publish a blanket statement that a healthcare AI product is outside FDA oversight. Review the intended use and claims before development and again before launch.
Safer MVP use cases
- Administrative scheduling and routing
- Source-linked policy or benefits search
- Document classification for staff review
- Drafting non-clinical communications
- Summarizing records for an authorized professional, with source access
Clinical recommendations, triage, diagnosis, treatment, and patient-facing symptom guidance require substantially more validation, governance, and regulatory analysis.
Production checklist
- Data-flow diagram showing every system and subprocessor
- BAAs where required
- Minimum-necessary data and role-based access
- Audit logging and incident response
- Human review and source traceability
- Representative clinical or operational evaluation sets
- Monitoring for drift, missing data, and harmful outputs
- A documented fallback when the model is unavailable or uncertain
Cost and ROI
Build cost depends on integration, validation, security, and regulatory scope. Any published price should be labelled as the provider's own estimate and dated. ROI should be calculated from the organization's baseline rather than presented as a guaranteed industry result.
Fact-check sources
- HHS: HIPAA and cloud computing
- HHS: HIPAA Privacy Rule
- FDA: Clinical Decision Support Software guidance
- NIST AI Risk Management Framework
- NIST Secure Software Development Framework
- OWASP Top 10 for LLM Applications
- OWASP Top 10 for Agentic Applications 2026
Sources and product documentation can change. Recheck time-sensitive pages on the publication date.