Writing / Compliance

Does HIPAA require logging what an AI model received?

October 9, 2026 / 7 min read

No provision names AI. The audit controls standard at 45 CFR 164.312(b) covers systems that contain or use ePHI, AI tools included, and lists no fields.

Not by name. No provision in the HIPAA Security Rule says a covered entity or business associate must log what an AI model received. What the rule does say, at 45 CFR 164.312(b), is that any information system that contains or uses electronic protected health information needs mechanisms that record and examine activity in it, and on a plain reading, an AI tool that contains or uses that information is part of such a system. The duty is real. It is just general purpose, not AI specific, and it does not tell you which fields to capture.

What does the audit controls standard require?

45 CFR 164.312(b) requires covered entities and business associates to “implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.” That is the entire text of the standard. Audit controls is one of five standards under the Security Rule’s technical safeguards, alongside access control, integrity, person or entity authentication, and transmission security, and it has no implementation specifications beneath it, required or addressable. The standard itself is the requirement. OCR’s own guidance on audit controls says the rule does not identify what information an audit log should collect or how often audit reports should be reviewed, and that covered entities and business associates must consider their risk analysis results in choosing audit controls. That risk analysis, under 45 CFR 164.308(a)(1)(ii)(A), requires “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.”

If an AI tool, whether an in-house model, a vendor API, or an ambient scribe, creates, receives, maintains, or transmits electronic PHI, it is part of an information system the audit controls standard reaches: yours where it runs on systems you control, and the vendor’s, as a business associate, where it runs on theirs. What that system’s audit mechanism has to record is a judgment call the regulated entity makes and has to be able to defend, not a checklist the rule supplies.

Does the rule say anything about what the AI vendor was given, specifically?

No. We read the current text of 45 CFR 164.308 and 164.312 in full for this piece, and neither section, nor any other provision in the Security Rule’s administrative, physical, or technical safeguards, mentions artificial intelligence, a model, or a prompt. That is not a gap unique to AI. The rule is written at the level of “information systems” and their activity generally, the same way it reaches an EHR, a fax server, or a billing system, without naming any of them either. An AI tool gets the same general duty every other system that touches ePHI gets, no more specific and no less real.

45 CFR 164.308(a)(1)(ii)(D) adds the other half of the obligation: a covered entity or business associate must “implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.” Producing a log is not the end of the duty. Reviewing it regularly is required too, and it is the half that a log sitting unread on a server does not satisfy.

Does the proposed HIPAA Security Rule update change this?

Not yet, and not in a way that adds AI-specific logging even once it does. HHS published a Notice of Proposed Rulemaking on January 6, 2025 (RIN 0945-AA22) proposing to remove the distinction between required and addressable implementation specifications and make them all required, with specific, limited exceptions, alongside new specifics such as annual compliance audits, multi-factor authentication, network segmentation, and written verification from business associates that their technical safeguards are in place. The comment period closed March 7, 2025, and more than 4,000 comments were filed. In the 2026 edition of the Unified Agenda of Regulatory and Deregulatory Actions, HHS lists this rulemaking under Long-Term Actions, with final action anticipated in July 2027, later than the May 2026 date in the Spring 2025 edition. It is a proposal, not current law.

The proposal’s preamble does address AI. HHS wrote that it expects a regulated entity using AI to include those tools in its risk analysis, considering among other things the type and amount of ePHI the tool accesses, to whom the data is disclosed, and to whom the output is provided. That is the agency’s stated expectation in a proposal, not a new logging rule. The proposed regulatory text still does not add a requirement to log AI model input as a distinct item: its audit trail standard would require recording activity in relevant electronic information systems generally, without naming AI or listing fields.

What does the six-year documentation duty cover?

The entity’s own required documentation, and the text does not settle whether an AI log counts. It is easy to reach for the Security Rule’s six-year figure and assume it answers a retention question about AI logs. 45 CFR 164.316(b)(2) requires a covered entity or business associate to retain its required Security Rule documentation, meaning its policies and procedures and a written record of any action, activity, or assessment the rule requires to be documented, for six years from its creation or the date it was last in effect, whichever is later. Section 164.316 does not name audit logs or AI interaction records, and the OCR audit controls guidance cited here does not address retention. Whether a record of what a model received is documentation that duty covers is a question for the health system’s counsel until OCR guidance or an enforcement action answers it. Separately, HHS says the Privacy Rule sets no retention period for medical records, and that state laws generally govern how long they are kept. A health system that wants a retention answer for an AI interaction record has to make that decision deliberately, not assume the six-year figure settles it either way.

What the rule requiresWhat it does not require
Audit mechanisms covering any system that contains or uses ePHI (164.312(b))A specific field list for what an AI model received
An accurate and thorough risk analysis of the ePHI the entity holds (164.308(a)(1)(ii)(A))A named exemption or extra rule for AI tools specifically
Regular review of information system activity records (164.308(a)(1)(ii)(D))A defined review interval; the entity sets its own
Six-year retention of the documentation the Security Rule requires (164.316(b)(2))A retention period for medical records, or one named for AI interaction records

What about the AI vendor’s own logging duty?

Where the AI vendor is a business associate, for example because it creates, receives, maintains, or transmits ePHI on the covered entity’s behalf, the Security Rule applies to that vendor directly under 45 CFR 164.302, audit controls included. That does not automatically give the covered entity access to the vendor’s logs. What the covered entity can reach depends on the business associate agreement, not on the existence of the vendor’s own audit-control duty. Who keeps the transcript from an ambient scribe works through exactly this gap for one case, and it is worth reading before assuming a signed BAA settles the question.

A risk analysis that accounts for the AI tool, an audit mechanism that covers it, and regular review of what it recorded are the pieces 164.312(b) and 164.308 point to. None of that is specific to AI. All of it has to exist before anyone asks to see it.

What you need in place

  • Every AI tool that touches ePHI named in the current risk analysis, not assumed to be covered by a general one.
  • An audit mechanism that reaches that tool where it runs on systems you control.
  • A defined, regular cadence for reviewing what that mechanism records, with someone accountable for doing it.
  • Contract language, where the vendor is a business associate, that says what logs or records the covered entity can obtain and on what timeline.
  • A retention decision for AI interaction records, made deliberately with counsel, including whether the six-year documentation duty reaches them.

Sources

The citations above are drawn from the following primary sources, read current as of September 2026.

Where Verillian fits

Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source. For a health system, that record can help evidence the audit controls 45 CFR 164.312(b) asks for, for the AI use that passes through the checkpoint on enrolled devices, alongside the risk analysis and regular review rather than in place of either. The architecture is aligned with the HIPAA Security Rule, not certified, because HHS does not endorse or recognize private certifications regarding it.

Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as an ambient scribe or a hosted report-writing tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.

See what a signed business associate agreement changes and what it does not on the ChatGPT question, what OCR’s recent enforcement turns on in what evidence OCR expects for AI use in a health system, and how this maps to healthcare and other regulated sectors.

All writing

See the record
for yourself

Thirty minutes with your security team. We show policy enforced at execution and the signed chain it produces.