Every week, another AI vendor lands in a practice manager’s inbox promising smarter scheduling, faster documentation, or seamless integration with the tools your staff already uses. The pitch is compelling. The marketing says “HIPAA-ready.”
So why isn’t that enough to sign the contract?
Because “HIPAA-ready” is a marketing term. What actually protects your practice is the Business Associate Agreement (BAA) and, more specifically, which AI features and integrations are covered inside it.
For healthcare practices exploring AI, understanding this distinction is an important part of evaluating whether an AI tool can be used in a HIPAA-compliant environment.
A Real Example: When “HIPAA-Ready” Met the Fine Print
Jay Thomas, one of our compliance consultants at Shared IT, recently worked with a doctor’s office that was ready to move forward with Anthropic Enterprise, the business version of the Claude AI assistant. The client was excited. Anthropic markets its Enterprise plan as HIPAA-ready, and the practice was especially drawn to the idea of connecting it to tools their staff already lived in every day, like Outlook, along with Excel for reporting.
On paper, it looked like a done deal. But Jay didn’t stop at the marketing page. He requested access to Anthropic’s detailed Business Associate Agreement documentation and Implementation Guide, materials that aren’t publicly posted and have to be specifically requested from the vendor.
That extra step mattered.
Buried in the documentation was a critical distinction: while Anthropic does offer BAA coverage for its core API and HIPAA-ready Enterprise chat environment, several of the integrations the client actually wanted to use were explicitly excluded. Office-style integrations, including the kind that would connect to Outlook, fell outside the scope of covered services. The Excel-focused features the client was counting on for reporting were still in beta, and Anthropic’s own documentation is clear that beta features are not covered under the BAA at all.
In other words:
The underlying AI product was HIPAA-ready. The specific configuration the client wanted to build their workflow around was not.
Why HIPAA Compliance for AI Matters More Than It Seems
This isn’t a knock on any one vendor. It’s how enterprise software works. Platforms roll out new integrations and features constantly, and BAA coverage doesn’t automatically expand to match.
For a healthcare practice, the gap between “the product is compliant” and “the feature I plan to use is compliant” can mean:
- Compliance exposure. Running protected health information (PHI) through an uncovered feature can create a HIPAA compliance issue, regardless of intent or what the general marketing implied.
- Wasted investment. Contracts get signed, staff get trained, and workflows get rebuilt, only to discover the intended use case has to be scrapped or reworked.
- Operational disruption. Reworking an AI rollout after go-live costs far more in time and goodwill than catching the gap during evaluation.
How to Evaluate HIPAA-Ready AI Tools
1. Never take “HIPAA-ready” at face value.
Request the actual BAA and any implementation or coverage guide before you commit. If a vendor won’t share it, that’s an important consideration before moving forward.
2. Verify HIPAA compliance feature by feature, not product by product.
An AI platform can be generally HIPAA-ready while specific integrations, beta features, or add-ons sit outside the agreement entirely. Make sure the exact tools and workflows your practice plans to use are covered.
3. Loop in an experienced IT and compliance partner before you sign, not after.
Vetting BAAs, cross-referencing feature-level coverage, and asking AI vendors the right follow-up questions is exactly the kind of due diligence that’s easy to skip when you’re focused on running a practice.
The Bottom Line on HIPAA-Compliant AI for Healthcare
AI has real potential to reduce administrative burden in healthcare. But adopting AI safely means treating vendor claims as a starting point for questions, not a substitute for verification.
A few hours of diligence upfront, done by someone who knows what to look for, is a lot less costly than a compliance incident or a rebuilt workflow six months down the road.
If your healthcare practice is evaluating a new AI tool and wants a second set of eyes on the BAA before you sign, Shared IT is here to help you ask the right questions before they become expensive ones.









