AI Insights Healthcare & Medical

PHI, the Privacy Rule & Your Website: A 2026 HIPAA Playbook

June 14, 2026 7 min read

Talk to Fred

Ask Fred about Healthcare & Medical

This is the same Fred you would put on your own site. Ask about Healthcare & Medical, compliance, or how the guardrails work. Fred listens.

Most regulated industries hand an AI assistant one body of law to respect. Healthcare hands it four at once. A single patient conversation can touch protected health information, the practice of medicine, anti-discrimination law, and the rules on what data a website is allowed to share. An assistant that is careless with any one of them creates a problem your practice owns, and 2026 brought new attention to all four.

This is the standard companion to the threat piece. The threat side covers the answer that turns into a complaint or a breach. This guide covers the standard: what a compliant healthcare assistant must protect, what it must refuse, and how to deploy one without inheriting the exposure.

Four Bodies of Law in One Conversation

Start with HIPAA. The moment an assistant collects a name attached to a symptom, an appointment reason, or a medication, it is handling protected health information, and the vendor running it becomes a business associate. That status is not a formality. It requires a signed Business Associate Agreement and brings the Privacy Rule and the Security Rule to bear on how the data is stored, sent, and reached.

Then there is the practice of medicine, licensed in every state. Diagnosing a condition, recommending a treatment, adjusting a dose, telling a patient whether a symptom is serious: each is reserved for a licensed clinician. When an assistant does one of them, it is practicing without a license, in writing, under your practice’s name.

Anti-discrimination law is the third, and the one most people miss. Section 1557 of the Affordable Care Act, as rewritten by the 2024 HHS final rule, now reaches patient care decision support tools, a category that names algorithms and AI outright. Covered entities have to make reasonable efforts to find and reduce the chance that such a tool discriminates against protected groups.

The fourth risk does not live in what the assistant says at all. It lives in what the page around it quietly ships elsewhere. After the FTC’s actions against GoodRx and BetterHelp over tracking pixels, routing health-related data to outside platforms through a chat tool or the analytics beside it is its own exposure, separate from any answer on the screen.

The Acts a Compliant Assistant Refuses

Against that backdrop, the standard is defined by the answers the assistant declines to give.

Diagnosis is the clearest line. When a visitor types "do these symptoms mean I have an infection?" the only safe move is to route the question to a licensed staff member, because forming the answer is itself a clinical judgment. Treatment advice sits in the same place. Whether to start, stop, combine, or change a medication belongs to a clinician, since a friendly reply there is the practice of medicine in all but name.

Urgency is more dangerous still. Telling a patient that their chest pain is "probably nothing" or "fine to wait on until Monday" is the sentence that becomes a malpractice claim and a harmed person, so the right pattern is narrow: send urgent concerns to a clinician or emergency care, and stop. Protected health information gets the same discipline. It is gathered only under the right agreements and safeguards, and never quietly handed to a tool that sits outside them.

What the assistant does do is the entire everyday surface that needs no license. Office hours and locations, what a given visit type involves in general terms, the first steps of a scheduling request, a clean handoff of anything clinical to the people trained to answer it. That is a wide and genuinely useful job. It just stops at the licensed line.

Privacy Is a Design Decision, Not a Disclaimer

A "this is not medical advice" line under the chat box does not make the data underneath it compliant. The HIPAA obligations attach to how the assistant and the systems around it actually handle protected health information, not to the wording of a footer. Meeting the standard means a signed Business Associate Agreement with the vendor, encryption and access controls that satisfy the Security Rule, and a hard check on whether any analytics or tracking on the page is quietly carrying health-related data off to a third party. That last item is what several of the recent enforcement actions were actually about, and it lives in the page’s plumbing, not in the assistant’s answers.

Why an Instruction Fails the Standard

The shortcut everyone reaches for is the prompt. Tell the assistant never to give medical advice, never to diagnose, and treat the boundary as set.

It is not set. A language model follows an instruction when the request matches the wording it was warned about, and patients almost never use that wording. You tell it never to diagnose. The patient does not ask for a diagnosis. They write, "I’ve had a fever and a bad cough for three days, is this something I need to worry about?" The model hears a worried person asking for reassurance and reassures them, which means it just weighed a clinical symptom and offered a judgment. The instruction was loaded the whole time. It simply did not recognize the sentence that crossed into medicine.

That is the gap between an instruction and a standard. An instruction asks the model to behave. It does not stop the model from speaking. A real boundary is built into the system and decides what the assistant is allowed to say before it answers, so a diagnosis, a medication change, or an urgency call never reaches the patient no matter how the question is phrased. "Will not" is a suggestion. "Cannot" is an architecture.

What a Compliant Deployment Looks Like

Meeting the standard does not mean a practice has to do without an assistant. It means running one that was built to protect health information and to refuse the clinical line, and that keeps the record those obligations expect.

Fred is built that way. It answers from your own practice content, captures the scheduling or intake details, and routes anything clinical, anything about symptoms, medications, or urgency, to licensed staff. It runs more than 50 industry guardrail packs, and the healthcare pack is built around the practice of medicine, the handling of protected health information, and the anti-discrimination duties that now reach decision-support tools. Fred does not diagnose, does not adjust a medication, and does not tell a patient whether to worry. It cannot. It answers what it should, protects what it must, and hands the clinical work to the people licensed to do it.

The goal is not a more talkative assistant. It is one that can be shown to be incapable of practicing medicine or mishandling a patient’s record.

Frequently asked questions

Is a healthcare AI assistant covered by HIPAA?

If it collects or handles protected health information on a covered entity’s behalf, the vendor running it is a business associate, which requires a Business Associate Agreement and compliance with the Privacy and Security Rules. A disclaimer does not change that. The obligations follow the data, not the wording on the page.

What clinical questions should the assistant never answer?

Anything that amounts to diagnosing, recommending or changing treatment, or judging the urgency of a symptom. "Is this serious?" "Should I stop this medication?" and "do I need to be seen?" are clinical judgments reserved for licensed clinicians, and a compliant assistant routes them to a person rather than answering.

Does anti-discrimination law really apply to an AI assistant?

It can. Section 1557, as updated by the 2024 HHS final rule, reaches patient care decision support tools, which expressly include algorithms and AI, and expects covered entities to make reasonable efforts to identify and reduce the risk of discrimination from those tools. That makes how the assistant treats patients a compliance question, not only a customer-service one.

Put your own Fred to work.

You just talked to Fred above. The same agent answers your visitors from your content, captures the lead, and books the job, 24/7.