A field manual for regulated AI

INDEPENDENT / SOURCE-LED / 2026

Compliance lives
in the system around
the model.

A precise, source-led guide to evaluating generative AI workflows that may involve PHI. No product, plan, or prompt is compliant by name alone.

Explore the seven controls Read the direct answer

CONTROL MAP / 01—07

  1. 01Role & data
  2. 02BAA scope
  3. 03Risk analysis
  4. 04Access
  5. 05Configuration
  6. 06Workforce
  7. 07Monitoring

THE USEFUL DISTINCTION

NOT THIS

“Is this tool HIPAA certified?”

HHS does not endorse or certify specific cloud products.

ASK THIS

“Does this exact workflow meet our obligations?”

Review role, data, agreements, configuration, safeguards, and ongoing practice.

FIELD MANUAL

Start with the question your team actually has.

01
Direct answerIs ChatGPT HIPAA compliant? The accurate answer depends on the product and configuration
11 min
02
ProcurementBAA checklist for generative AI vendors
9 min
03
GovernanceA practical AI risk analysis for healthcare teams
12 min