NewMissing Records Detection: flags every visit, provider, and date missing from the file. See how →

Content HubSamples › Templates & tools

Templates & tools

HIPAA-compliant intake checklist

The questions to settle in writing before an AI vendor touches protected health information: who signs the business associate agreement, where the data physically lives, who can read it and whether that is logged, whether your files are reused for training, and what happens to everything when you leave. One page, answered in writing or not at all.

ChecklistFreeUpdated 2026-09-08

What’s inside

  • The agreement questions: BAA scope, subcontractors, and who is actually liable
  • Residency and deployment: cloud, private, on-premise, and what your matters need
  • Access and logging: who on the vendor side can open a file, and is it recorded
  • The reuse question people forget: are your records training someone's model
  • Exit: what happens to your data the day you stop paying

Built for Legal nurse consultants · IME / QME physicians · Expert witnesses · PI lawyers · Life care planners · Claims adjusters. Every line traces to HIPAA compliant AI medical record review, which is published in full on this site, so you can check the tool against the reasoning behind it.

Checklist

HIPAA-compliant intake checklist

15 checks in 5 sections. Every line names the failure it catches. Drawn from HIPAA compliant AI medical record review.

1Agreements3 checks

  • A business associate agreement is signed before any file movesWithout it, the disclosure itself is the problem, whatever the vendor's security looks like.
  • The BAA names every subcontractor that will touch protected health informationA vendor's own subprocessors inherit your obligations; unnamed ones inherit them invisibly.
  • Breach notification timing is stated in days, not 'promptly'Your own notification clock starts whether or not the vendor has told you yet.

The remaining 4 sections, 12 more checks, open below.

  • 2Residency and deployment3 checks
  • 3Access and logging3 checks
  • 4Reuse3 checks
  • 5Exit3 checks

Sources

Nothing in this tool is invented. Every line traces to a page published in full on this site, verified 2026-09-08.

Common questions

What is the first thing to settle with an AI vendor?

A signed business associate agreement, before any file moves. Without it, the disclosure itself is the problem, whatever the vendor's security looks like.

Why does data residency matter if everything is encrypted?

Encryption protects the data. Residency decides who can compel access to it. They are separate controls and a vendor sometimes answers only for the first.

Does Medrecords AI answer these questions itself?

Yes, on the Trust Center and the HIPAA and BAA page. The checklist is written so you can hold any vendor to it, including us.

How Medrecords AI does this work

The tool above is yours to run by hand. This is what the software does with the same file.

Test it on a file you already have.
Send one real record set. You get back a cited chronology and decide for yourself whether the read holds up.

More from Templates & tools

Last verified: 2026-09-08 · ← All samples and tools