Decision tool
Compliance readiness checklist
Eighteen controls, ordered by what actually blocks a health-system security review rather than by regulation chapter.
Short answer
What does a health system ask before approving an AI documentation feature?
Five blockers decide most reviews: a BAA covering every subprocessor, a contractual commitment that PHI is not used for training, stated retention and deletion windows per artefact, jurisdiction-aware recording consent, and a breach-notification window shorter than the one you owe your customer. The remaining thirteen controls turn a passable review into a fast one.
Cite as: Compliance readiness checklist, Compare Healthcare API, last reviewed 2026-09-01.
Progress is local to this browser session and never transmitted or stored.
Contracts and legal basis
Model governance
Data handling
Assurance and audit
Clinical and consent controls
EHR access
Incident response
Continuity
Working order
Do these in sequence; each one unblocks the next.
- Establish the legal basis. Sign a BAA covering your vendor and every subprocessor that touches audio, transcripts or notes, with change notification and a right to object.
- Pin down data handling. Get retention and deletion windows for audio, transcripts and notes separately, plus encryption, key management and processing region in writing.
- Close the model governance gap. Obtain a contractual commitment that PHI is not used for training, and a documented description of any human review of your data.
- Collect assurance evidence. Request the current SOC 2 Type II report and penetration test summary, and read the exceptions rather than the badge.
- Build the clinical controls. Implement jurisdiction-aware consent capture, mandatory clinician review and attestation, and an edit trail that separates generated text from clinician edits.
- Prepare for failure. Confirm the vendor's breach notification window is shorter than your obligation to customers, and define a note-quality incident path separately from security incidents.
- Plan the exit. Document export formats for transcripts and notes and the deletion certification you will receive on termination.
Evidence & sources
Every factual claim on this page traces to one of the primary references below. Each entry records what it supports and its evidence tier, so documentation can be told apart from judgement.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: What a covered entity and its business associates may do with PHI, and why a signed BAA is a precondition rather than a feature.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: Administrative, physical and technical safeguards a vendor handling recorded encounter audio must implement.
U.S. Department of Health & Human Services · Regulation · Tier A — primary documentation
Supports: The contractual clauses a documentation vendor's BAA must contain.
NIST · Standard · Tier A — primary documentation
Supports: Control-level guidance auditors reference when reviewing PHI-handling architecture.
AICPA · Standard · Tier A — primary documentation
Supports: What a SOC 2 Type II report does and does not attest to during a vendor security review.
- [6]HITRUST CSF
HITRUST Alliance · Standard · Tier A — primary documentation
Supports: The certification many health systems require of documentation vendors handling PHI at scale.
U.S. Department of Health & Human Services, OCR · Regulation · Tier A — primary documentation
Supports: Breach reporting obligations that flow to you as the covered entity's business associate.
Source tiers are defined on the methodology page. Outbound links are unaffiliated and carry no commercial relationship.
Frequently asked questions
- Is a BAA enough to be HIPAA compliant?
- No. A BAA establishes the legal basis for a vendor to process PHI on your behalf; compliance also requires configured retention, access control, logging, consent handling, workforce controls and incident response on your side. HIPAA guide.
- What blocks health-system deals most often?
- Undisclosed retention windows, no contractual commitment against training on PHI, and consent handling that assumes one-party consent everywhere. All three are avoidable before the questionnaire arrives. Consent index.
- Do I need SOC 2 as well as HIPAA?
- HIPAA is a legal obligation; SOC 2 is an assurance report. Health-system security reviews typically ask for both, and asking your vendor for the report rather than the badge is the point of the exercise.