Skip to content

Decision tool

Compliance readiness checklist

Eighteen controls, ordered by what actually blocks a health-system security review rather than by regulation chapter.

Written by Compare Healthcare API Editorial DeskReviewed by Technical ReviewLast reviewed Rubric v1.0

Short answer

What does a health system ask before approving an AI documentation feature?

Five blockers decide most reviews: a BAA covering every subprocessor, a contractual commitment that PHI is not used for training, stated retention and deletion windows per artefact, jurisdiction-aware recording consent, and a breach-notification window shorter than the one you owe your customer. The remaining thirteen controls turn a passable review into a fast one.

Cite as: Compliance readiness checklist, Compare Healthcare API, last reviewed 2026-09-01.

0/18 complete6 of 6 blockers open

Progress is local to this browser session and never transmitted or stored.

Contracts and legal basis

Model governance

Data handling

Assurance and audit

Clinical and consent controls

EHR access

Incident response

Continuity

Working order

Do these in sequence; each one unblocks the next.

  1. Establish the legal basis. Sign a BAA covering your vendor and every subprocessor that touches audio, transcripts or notes, with change notification and a right to object.
  2. Pin down data handling. Get retention and deletion windows for audio, transcripts and notes separately, plus encryption, key management and processing region in writing.
  3. Close the model governance gap. Obtain a contractual commitment that PHI is not used for training, and a documented description of any human review of your data.
  4. Collect assurance evidence. Request the current SOC 2 Type II report and penetration test summary, and read the exceptions rather than the badge.
  5. Build the clinical controls. Implement jurisdiction-aware consent capture, mandatory clinician review and attestation, and an edit trail that separates generated text from clinician edits.
  6. Prepare for failure. Confirm the vendor's breach notification window is shorter than your obligation to customers, and define a note-quality incident path separately from security incidents.
  7. Plan the exit. Document export formats for transcripts and notes and the deletion certification you will receive on termination.

Evidence & sources

Every factual claim on this page traces to one of the primary references below. Each entry records what it supports and its evidence tier, so documentation can be told apart from judgement.

  1. U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation

    Supports: What a covered entity and its business associates may do with PHI, and why a signed BAA is a precondition rather than a feature.

  2. U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation

    Supports: Administrative, physical and technical safeguards a vendor handling recorded encounter audio must implement.

  3. U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation

    Supports: The contractual clauses a documentation vendor's BAA must contain.

  4. NIST · Standard · Tier A — primary documentation

    Supports: Control-level guidance auditors reference when reviewing PHI-handling architecture.

  5. AICPA · Standard · Tier A — primary documentation

    Supports: What a SOC 2 Type II report does and does not attest to during a vendor security review.

  6. HITRUST Alliance · Standard · Tier A — primary documentation

    Supports: The certification many health systems require of documentation vendors handling PHI at scale.

  7. U.S. Department of Health & Human Services, OCR · Regulation · Tier A — primary documentation

    Supports: Breach reporting obligations that flow to you as the covered entity's business associate.

Source tiers are defined on the methodology page. Outbound links are unaffiliated and carry no commercial relationship.

Frequently asked questions

Is a BAA enough to be HIPAA compliant?
No. A BAA establishes the legal basis for a vendor to process PHI on your behalf; compliance also requires configured retention, access control, logging, consent handling, workforce controls and incident response on your side. HIPAA guide.
What blocks health-system deals most often?
Undisclosed retention windows, no contractual commitment against training on PHI, and consent handling that assumes one-party consent everywhere. All three are avoidable before the questionnaire arrives. Consent index.
Do I need SOC 2 as well as HIPAA?
HIPAA is a legal obligation; SOC 2 is an assurance report. Health-system security reviews typically ask for both, and asking your vendor for the report rather than the badge is the point of the exercise.

Continue