Glossary

DEFINITION

HIPAA

The U.S. Health Insurance Portability and Accountability Act, which sets privacy and security rules for individually identifiable health information held by covered entities.

In depth

HIPAA (Health Insurance Portability and Accountability Act, 1996) governs how covered entities — providers, plans, clearinghouses — and their business associates handle Protected Health Information (PHI). The Privacy Rule restricts disclosure; the Security Rule requires administrative, physical, and technical safeguards; the Breach Notification Rule mandates reporting. HIPAA does not directly regulate consumer-facing AI services like ChatGPT, but the moment a covered entity or business associate sends PHI to an AI service that has not signed a Business Associate Agreement (BAA), that transmission becomes a disclosure event the covered entity is responsible for.

Examples

  • A clinician pasting a patient's chart note into ChatGPT for summarisation — a disclosure event because OpenAI is not a BAA-covered partner.
  • A medical biller routing claim data through an unsanctioned AI tool to draft appeal letters.
  • A health-plan analyst using a personal Gemini account to forecast utilisation from member-level data.

How Locke handles hipaa

Locke detects patterns consistent with PHI — MRNs, ICD-10/CPT codes, NPIs, demographic combinations — locally, before any text reaches an AI tool. Because Sonomos itself never sees the data, no new BAA is required. See the Healthcare page for the full regulatory walk-through.

See the product