What HIPAA Buyers Need From an AI Vendor's Governance
Selling AI into healthcare means clearing a governance bar most vendors miss. Here is what HIPAA-covered buyers actually require before they let your model near PHI.
Selling AI to a healthcare buyer is not selling AI with a stricter security questionnaire. It is a different sale, because protected health information changes what your governance has to prove. A hospital cannot let your model touch patient data on a promise. They need a Business Associate Agreement, a documented data path, and evidence that a bad output cannot become a bad clinical decision without a human in the way. Vendors who treat healthcare like any other enterprise deal stall in review for months and often never close. The governance bar is the product here, more than the model is.
What do HIPAA-covered buyers require from an AI vendor?
Start with the non-negotiable: a signed Business Associate Agreement. If your AI system creates, receives, maintains, or transmits PHI on behalf of a covered entity, you are a business associate under HIPAA, and no compliant hospital will proceed without the BAA. This is not a formality you negotiate away. It is the entry ticket. Understand it before the first call, the way you would any DPA negotiation with a vendor, because the structure is similar and the stakes are higher.
Then they want the data path. Where does PHI go, which of your subprocessors touch it, is it used to train models, and how is it deleted. A vendor who cannot produce a clean subprocessor list and a precise answer to where enterprise data actually goes does not clear healthcare review. The default assumption on the buyer side is that your model retains and learns from everything, and you have to affirmatively disprove it with documentation, not assurances.
Why healthcare governance is a different bar
Two reasons. First, the data is regulated at the record level, so "we encrypt everything" is table stakes and not the interesting question. The interesting question is minimization: are you collecting and retaining only the PHI you actually need, and can you prove it. Second, and larger, is the clinical stakes. A wrong output in most software is an inconvenience. A wrong output in a clinical workflow can hurt a patient. That raises the human-oversight requirement from a nice-to-have to a hard control.
This is why healthcare buyers probe your failure behavior harder than most. They want to know that your system falls back to deterministic or human review when it is unsure, not that it confidently guesses. They want to know who is accountable when the AI is wrong, and the answer had better be a named human process, not "the model." A model that presents a clinical suggestion as certainty when it is not is disqualifying, which makes showing confidence without fake precision a real requirement, not a UX nicety.
What to prepare before you sell into healthcare
Get these ready before you pitch, not after they ask.
- The BAA, pre-drafted. Have your version ready and know which terms you can flex. Scrambling for a BAA after interest signals you are new to healthcare, and that scares buyers.
- A PHI data-flow diagram. One clear picture of where protected data enters, moves, rests, and exits, with every subprocessor named.
- A minimization statement. What PHI you collect, why each field is necessary, and your retention and deletion policy.
- Human-oversight evidence. Documented proof that a clinician or qualified human reviews or can override any output that affects care.
- A decision audit trail. The ability to reconstruct any single AI output, which comes from keeping data lineage on every output.
The bar is the moat
Healthcare governance is expensive to build, which is exactly why it is worth building. The BAA, the data minimization, the oversight controls, the audit trail: each one filters out competitors who wanted an easy enterprise sale. Clear the bar and you are selling into a market that pays well and switches vendors reluctantly, because re-clearing the governance bar with a new vendor is painful for the buyer too. That reluctance is your retention.
I build governance as the product in regulated verticals for this reason. My venture CaseSolo applies the same discipline to legal work, where privileged data and duty to a client raise a comparably strict bar. The underlying automation across my portfolio runs on Girard AI, which treats data minimization and decision provenance as defaults so a healthcare or legal review is an export rather than a rebuild. In these markets the governance is not the cost of the sale. It is the sale.