HIPAA, PHI, and AI: How Not to Accidentally Become a Non‑Compliant Data Processor
Updated: September 17, 2026
HIPAA gets dangerous for builders because it's boring. If your chatbot touches patient-identifying health info, you're handling ePHI-even if you "only pass it through" to an LLM API. This post breaks down Privacy vs Security in dev terms, the vendor/BAA trap, and the controls that matter: BAAs, encryption, least-privilege access, redaction, sane retention, and logging that won't turn into a PHI leak. read on »