Home · Glossary · HIPAA
Enterprise AI glossary · Compliance & Regulation

HIPAA

The US Health Insurance Portability and Accountability Act — sets the rules for handling Protected Health Information (PHI) and shapes how US healthcare can use AI on clinical data.

Definition

What HIPAA means in practice

The Health Insurance Portability and Accountability Act governs the handling of Protected Health Information by US covered entities and their business associates. AI implications: any vendor processing PHI must execute a Business Associate Agreement, prompts to a cloud LLM that contain PHI are a controlled disclosure, and audit-trail expectations apply to model outputs that influence care. HIPAA permits cloud LLM use under a BAA in principle, but the BAA-review timeline at most covered entities has stretched to multiple quarters, which is why MindMap's US healthcare deployments are increasingly on-premise — by the time the cloud BAA closes, the on-prem deployment is already in production.

Go deeper
EU AI Act compliance architecture →

All 62 terms, in plain language

Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.

Browse the glossary →Talk to an engineer →