Templates & tools
HIPAA-compliant intake checklist
The questions to settle in writing before an AI vendor touches protected health information: who signs the business associate agreement, where the data physically lives, who can read it and whether that is logged, whether your files are reused for training, and what happens to everything when you leave. One page, answered in writing or not at all.
What’s inside
- The agreement questions: BAA scope, subcontractors, and who is actually liable
- Residency and deployment: cloud, private, on-premise, and what your matters need
- Access and logging: who on the vendor side can open a file, and is it recorded
- The reuse question people forget: are your records training someone's model
- Exit: what happens to your data the day you stop paying
Built for Legal nurse consultants · IME / QME physicians · Expert witnesses · PI lawyers · Life care planners · Claims adjusters. Every line traces to HIPAA compliant AI medical record review, which is published in full on this site, so you can check the tool against the reasoning behind it.
HIPAA-compliant intake checklist
15 checks in 5 sections. Every line names the failure it catches. Drawn from HIPAA compliant AI medical record review.
1Agreements3 checks
- A business associate agreement is signed before any file movesWithout it, the disclosure itself is the problem, whatever the vendor's security looks like.
- The BAA names every subcontractor that will touch protected health informationA vendor's own subprocessors inherit your obligations; unnamed ones inherit them invisibly.
- Breach notification timing is stated in days, not 'promptly'Your own notification clock starts whether or not the vendor has told you yet.
The remaining 4 sections, 12 more checks, open below.
2Residency and deployment3 checks
- You know which country and which cloud region the data physically sits inJurisdiction decides who can compel access to the file.
- An on-premise or private deployment is available for the matters that need oneSome records should never leave your infrastructure, and that has to be possible before you need it.
- Backups and disaster-recovery copies stay inside the same jurisdictionA compliant primary region with an offshore backup is not a compliant deployment.
3Access and logging3 checks
- You know who on the vendor's side can open a file, and under what circumstancesSupport access is still access.
- Every access to protected health information is logged, and you can obtain the logA log you cannot request is a log you cannot rely on.
- Encryption is stated for data in transit and at rest, separatelyThe two are different controls and vendors sometimes answer only for one.
4Reuse3 checks
- The vendor states in writing that your files are not used to train modelsA tool can be fully encrypted and still reuse your files; encryption does not solve that.
- Your records are not used to enrich a dataset or benchmark shared with anyone elseFiles that leave for someone else's benefit are a problem separate from security.
- Any aggregate or de-identified reuse is described specifically, not waved through'De-identified' covers a wide range of practices, some of which you would refuse.
5Exit3 checks
- You know what happens to your data when you stop using the serviceDeletion terms agreed at signup are the only ones you get at the end.
- Deletion is confirmable, with a stated timeline and a certificate on requestAn unverifiable deletion promise is an assumption, not a control.
- You can export your own work product in a usable format before you leaveData you cannot get out is data you have to keep paying to reach.
Sources
Nothing in this tool is invented. Every line traces to a page published in full on this site, verified 2026-09-08.
- HIPAA compliant AI medical record review — https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/
- Medrecords AI security and compliance — https://medrecords.ai/security/
Common questions
What is the first thing to settle with an AI vendor?
A signed business associate agreement, before any file moves. Without it, the disclosure itself is the problem, whatever the vendor's security looks like.
Why does data residency matter if everything is encrypted?
Encryption protects the data. Residency decides who can compel access to it. They are separate controls and a vendor sometimes answers only for the first.
Does Medrecords AI answer these questions itself?
Yes, on the Trust Center and the HIPAA and BAA page. The checklist is written so you can hold any vendor to it, including us.
How Medrecords AI does this work
The tool above is yours to run by hand. This is what the software does with the same file.