# HIPAA Vendor Intake Checklist for AI Medical Record Review

> The agreement, residency, access, reuse and exit questions to settle in writing before an AI vendor touches protected health information. Free checklist.

Canonical page: https://medrecords.ai/content-hub/samples/hipaa-vendor-intake-checklist/

---
[Content Hub](https://medrecords.ai/content-hub/) › [Samples](https://medrecords.ai/content-hub/samples/) › Templates & tools

Templates & tools

## HIPAA-compliant intake checklist

The questions to settle in writing before an AI vendor touches protected health information: who signs the business associate agreement, where the data physically lives, who can read it and whether that is logged, whether your files are reused for training, and what happens to everything when you leave. One page, answered in writing or not at all.

By [Ahmed Jemaa](https://medrecords.ai/authors/ahmed-jemaa/) , Co-Founder & CEO of Medrecords AI · Published 8 Sep 2026

Checklist — Free — Updated 2026-09-08

### What’s inside

- The agreement questions: BAA scope, subcontractors, and who is actually liable
- Residency and deployment: cloud, private, on-premise, and what your matters need
- Access and logging: who on the vendor side can open a file, and is it recorded
- The reuse question people forget: are your records training someone's model
- Exit: what happens to your data the day you stop paying

Built for Legal nurse consultants · IME / QME physicians · Expert witnesses · PI lawyers · Life care planners · Claims adjusters. Every line traces to [HIPAA compliant AI medical record review](https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/) , which is published in full on this site, so you can check the tool against the reasoning behind it.

Free · printable · no card

Checklist

### HIPAA-compliant intake checklist

15 checks in 5 sections. Every line names the failure it catches. Drawn from [HIPAA compliant AI medical record review](https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/) .

#### 1Agreements3 checks

- **A business associate agreement is signed before any file moves** — Without it, the disclosure itself is the problem, whatever the vendor's security looks like.
- **The BAA names every subcontractor that will touch protected health information** — A vendor's own subprocessors inherit your obligations; unnamed ones inherit them invisibly.
- **Breach notification timing is stated in days, not 'promptly'** — Your own notification clock starts whether or not the vendor has told you yet.

The remaining 4 sections, 12 more checks, open below.

- 2Residency and deployment3 checks
- 3Access and logging3 checks
- 4Reuse3 checks
- 5Exit3 checks

#### 2Residency and deployment3 checks

- **You know which country and which cloud region the data physically sits in** — Jurisdiction decides who can compel access to the file.
- **An on-premise or private deployment is available for the matters that need one** — Some records should never leave your infrastructure, and that has to be possible before you need it.
- **Backups and disaster-recovery copies stay inside the same jurisdiction** — A compliant primary region with an offshore backup is not a compliant deployment.

#### 3Access and logging3 checks

- **You know who on the vendor's side can open a file, and under what circumstances** — Support access is still access.
- **Every access to protected health information is logged, and you can obtain the log** — A log you cannot request is a log you cannot rely on.
- **Encryption is stated for data in transit and at rest, separately** — The two are different controls and vendors sometimes answer only for one.

#### 4Reuse3 checks

- **The vendor states in writing that your files are not used to train models** — A tool can be fully encrypted and still reuse your files; encryption does not solve that.
- **Your records are not used to enrich a dataset or benchmark shared with anyone else** — Files that leave for someone else's benefit are a problem separate from security.
- **Any aggregate or de-identified reuse is described specifically, not waved through** — 'De-identified' covers a wide range of practices, some of which you would refuse.

#### 5Exit3 checks

- **You know what happens to your data when you stop using the service** — Deletion terms agreed at signup are the only ones you get at the end.
- **Deletion is confirmable, with a stated timeline and a certificate on request** — An unverifiable deletion promise is an assumption, not a control.
- **You can export your own work product in a usable format before you leave** — Data you cannot get out is data you have to keep paying to reach.

### Sources

Nothing in this tool is invented. Every line traces to a page published in full on this site, verified 2026-09-08.

- [HIPAA compliant AI medical record review](https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/) — https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/
- [Medrecords AI security and compliance](https://medrecords.ai/security/) — https://medrecords.ai/security/

### Common questions

#### What is the first thing to settle with an AI vendor?

A signed business associate agreement, before any file moves. Without it, the disclosure itself is the problem, whatever the vendor's security looks like.

#### Why does data residency matter if everything is encrypted?

Encryption protects the data. Residency decides who can compel access to it. They are separate controls and a vendor sometimes answers only for the first.

#### Does Medrecords AI answer these questions itself?

Yes, on the Trust Center and the HIPAA and BAA page. The checklist is written so you can hold any vendor to it, including us.

### How Medrecords AI does this work

The tool above is yours to run by hand. This is what the software does with the same file.

[Product — **Medical Chronology** — The medical timeline that builds itself, synced to every source page. Read more →](https://medrecords.ai/product/chronology/?src=content-hub-samples-hipaa-vendor-intake-checklist) [Product — **Verifiable AI citations** — If we can't cite it, we don't say it. Click any line to its source. Read more →](https://medrecords.ai/product/citations/?src=content-hub-samples-hipaa-vendor-intake-checklist) [Guide — **HIPAA compliant AI medical record review** — The published guide every line of this tool was drawn from. Read more →](https://medrecords.ai/guides/hipaa-compliant-ai-medical-record-review/)
Test it on a file you already have.
Send one real record set. You get back a cited chronology and decide for yourself whether the read holds up.
[Test a file](https://medrecords.ai/test-a-file/?src=content-hub-samples-hipaa-vendor-intake-checklist) [Book a demo](https://medrecords.ai/demo/?src=content-hub-samples-hipaa-vendor-intake-checklist)

### More from Templates & tools

[Fillable Medical Chronology Template](https://medrecords.ai/content-hub/samples/medical-chronology-template/) [IME Report Red-Flag Checklist](https://medrecords.ai/content-hub/samples/ime-report-red-flag-checklist/) [Workers' Comp IME Prep Checklist](https://medrecords.ai/content-hub/samples/workers-comp-ime-prep-checklist/) [Life Care Plan Cost-Projection Worksheet](https://medrecords.ai/content-hub/samples/life-care-plan-cost-projection-worksheet/) [The Chronology Bench Rubric](https://medrecords.ai/content-hub/samples/chronology-bench-rubric/) [Medical Record Review Cost Calculator](https://medrecords.ai/content-hub/samples/medical-record-review-cost-calculator/)
Last verified: 2026-09-08 · [← All samples and tools](https://medrecords.ai/content-hub/samples/)
