
Chat Thinks. Cowork Works.

Your AI Now Signs Its Work. Invisibly.

“HIPAA-Ready” Is Not “HIPAA-Compliant.” Know the Difference.
Big news landed quietly this summer for anyone running a healthcare-adjacent business: Claude now offers HIPAA-ready plans. On Enterprise plans, you can execute a Business Associate Agreement, the BAA, and set up a version of Claude built to process protected health information, through a self-serve flow with an implementation guide.
If you run a practice, a clinic, or any operation touching PHI, this is genuinely significant, and it is easy to misunderstand. So let’s do both halves honestly: why this matters, and why the phrase is HIPAA-ready, not HIPAA-compliant.
Why the BAA is a big deal
A BAA means the AI vendor accepts legal responsibility as a business associate under HIPAA. That’s not marketing language; it’s liability they’re taking on. For two years, the honest advice to health practices was to keep patient data far away from general AI tools. A BAA changes the foundation of that advice, and it signals something bigger: the major AI companies are engineering seriously for regulated industries, and that pace is accelerating.
Why you’re still the compliant one
Here’s the part nobody selling AI will lead with. A HIPAA-ready platform is one link in your chain. Compliance is the whole chain, and the chain is yours. If you connect a compliant AI to an insecure system, or give it the ability to publish freely while it holds patient data, you’ve built the breach yourself out of compliant parts. The setup process will walk you through locking things down; take that walk seriously, and ask the tool directly, every time you wire a new connection: does this method still meet HIPAA standards? Your other platforms, your training, your processes, your designated officer, all still yours.
Also yours: skepticism about your existing software’s “AI features.” When your records platform announces built-in AI, it’s usually running a badly outdated model locked in place at integration time. The interesting question isn’t whether your EMR has AI inside it; it’s whether a current, HIPAA-covered AI can connect to your EMR. If there’s no connector today, there likely will be soon. Regulated industries are where every AI vendor is racing.
The pattern that works at every plan level
Here’s the technique I love most from this month’s Roundtable, because it requires no Enterprise plan and no BAA: prompt at the diagnosis level, not the patient level. One of my members in a clinical field never types anything identifying. Instead: what are the most evidence-based treatments for this diagnosis, give me five percentage-based goals for it, make objectives increase-decrease structured. All the drafting speed, zero PHI in the conversation. The same thinking produces reports and workflows where the AI works on de-identified outputs while decisions involving real patient data stay inside your compliant systems. “Minimum necessary info” was always the principle; it’s also the practical bridge until your BAA is in place.
One more honest note: even with a BAA, I stay conservative about personal data in any AI, mine or anyone’s, and I’d tell you to as well. The rules of thumb that served you before still serve you now. This news expands what’s possible; it doesn’t retire your judgment, and none of this is legal advice. If you’re PHI-heavy, an hour with your compliance counsel before setup is the cheapest insurance you’ll buy this year. And if your content reaches European audiences, the new EU transparency rules are a separate conversation I’ve covered here: https://tablelandpartners.com/eu-ai-content-rules-business/.
- HIPAA-ready plan + executed BAA = the platform’s half. Enterprise tier, self-serve setup.
- Your half never transfers: processes, training, your other systems, your designated officer.
- Every new connection gets the question: “Does this method still meet HIPAA standards?”
- Don’t overrate your EMR’s built-in “AI.” Ask whether current AI can connect to your EMR instead.
- Prompt at the diagnosis level, not the patient level, at every plan tier.
- PHI-heavy? One hour with compliance counsel before anything goes live.
This post came out of a real conversation at the AI Essentials Roundtable, the small group I run for business owners who want to actually use AI instead of just reading about it. We meet every other week, screen-share real builds, and steal each other’s wins. If that sounds useful, details are here: tablelandpartners.com/ai_essentials_roundtable


