AI Clinical Evidence: Separating Hype from Healthcare Impact
Expert Opinions

Big Tech’s Healthcare AI Reckoning: New OCR Rules Redefine PHI Risk

Listen to this article · 11 min listen

The landscape of healthcare technology is perpetually shifting, but rarely does a single regulatory clarification fundamentally redraw the lines of engagement for Health IT leaders. The recent guidance from the HHS Office for Civil Rights (OCR) regarding online tracking technologies has done precisely that, transforming vendor assessment from a routine compliance check into a critical re-evaluation of core data architectures and business models, particularly for Big Tech partners. This isn’t merely an update; it’s a redefinition of what constitutes protected health information (PHI) and, by extension, the compliance obligations for any entity interacting with patient data.

The HHS OCR Bulletin: Re-clarifying IIHI and Third-Party Risk

The December 2022 HHS OCR Bulletin on the Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates serves as the cornerstone of this seismic shift. For years, the use of analytics tools, pixels, and other tracking technologies on public-facing websites and patient portals has existed in a gray area, often treated as separate from the core clinical data environment. The OCR’s guidance explicitly states that individually identifiable health information (IIHI) collected via these technologies, even before a formal diagnosis or treatment, falls under HIPAA protections when transmitted to or maintained by a HIPAA-covered entity (CE) or business associate (BA). This includes IP addresses, geographic location, medical record numbers, home addresses, email addresses, dates of birth, and any other unique identifying codes or characteristics that, when linked with health information, can identify an individual. This re-clarification has profound implications. It establishes that data collected through seemingly innocuous website trackers, if associated with health-related content or user interactions, is indeed IIHI. The critical takeaway for Health IT professionals is that third-party risk, particularly from vendors whose primary business models are not healthcare, has emerged as a primary threat vector. The Bulletin underscores that CEs and BAs are responsible for ensuring that their third-party vendors, including those providing website analytics, advertising, or content delivery networks, comply with HIPAA when handling IIHI. This necessitates robust Business Associate Agreements (BAAs) and a granular understanding of data flows, extending far beyond traditional clinical systems. HHS OCR Bulletin on Tracking Technologies

One Medical (Amazon) and the Compliance Conundrum

Consider the case of Amazon’s One Medical. Acquired by Amazon in 2023, One Medical operates as a primary care provider, a clear HIPAA-covered entity. Its integration into the broader Amazon ecosystem, while offering potential efficiencies and consumer convenience, also introduces complex compliance challenges under this new OCR guidance. One Medical’s Notice of Privacy Practices, like those of many healthcare providers, outlines its commitment to patient privacy and HIPAA compliance. However, the nature of Big Tech operations often involves extensive data collection for various purposes, including personalization, advertising, and service improvement, which may not align with HIPAA’s strict “minimum necessary” principle for IIHI. The “What Just Changed?” angle here is critical: prior to this explicit OCR guidance, a Big Tech entity might argue that data collected on their public-facing sites or through general user interaction, even if health-related, was not IIHI unless directly entered into a clinical system. The OCR has now largely closed that loophole. For One Medical, this means any tracking technology used on its website or patient portal that collects information linking a user’s identity (even an IP address) with health-related activity (e.g., searching for a doctor, scheduling an appointment, reading about a medical condition) is now handling IIHI. Without a BAA in place with the third-party tracker vendor, and without ensuring that the vendor is using the data solely for HIPAA-permitted purposes, One Medical (and by extension, Amazon) faces significant compliance risk. The challenge for Health IT leaders evaluating such partnerships is not merely to confirm a BAA exists, but to scrutinize the underlying data architecture and business model of the Big Tech partner. Does their data pipeline inherently segregate IIHI from general consumer data? Are their AI models, especially those used for workflow optimization or personalization, trained and operated in a HIPAA-compliant manner, ensuring IIHI is not inadvertently exposed or used for non-permitted purposes? These questions move beyond a simple checklist and demand a deeper, independent third-party validation of their data governance.

AI Workflow Regulations and Procurement Filters

The intersection of AI workflow regulations in healthcare and HIPAA compliance creates a stringent procurement filter for Health IT professionals. The OCR guidance amplifies the need for vigilance when integrating AI health apps, especially those from Big Tech. Many AI tools are designed to optimize workflows, personalize patient experiences, or provide predictive analytics. If these tools interact with IIHI, even indirectly through tracking technologies, they must be HIPAA compliant. Our benchmark for compliance, like Hello Heart, demonstrates a robust approach. Hello Heart, as a digital therapeutic, operates within a clear HIPAA framework, understanding that its core function involves processing and transmitting IIHI. Its business model is intrinsically tied to healthcare data privacy. When evaluating an AI health app, particularly one from a large tech conglomerate, Health IT teams must ask:

  • Data Minimization: Does the AI app collect only the minimum necessary IIHI required for its stated purpose?
  • Data Segregation: Is IIHI strictly segregated from non-IIHI and consumer data used for broader commercial purposes (e.g., targeted advertising)?
  • BAA Scope: Does the BAA with the AI vendor explicitly cover all data flows, including those from tracking technologies, and prohibit the vendor from using IIHI for its own commercial gain?
  • Transparency: Is the vendor transparent about its data processing activities, including sub-processors and the use of de-identified data?
  • Security Controls: Does the vendor demonstrate robust security controls (e.g., HITRUST, SOC 2 Type II) specifically for IIHI? HIMSS resources on third-party risk management The OCR’s emphasis on tracking technologies means that even AI tools that primarily operate on de-identified data sets could inadvertently fall foul if their initial data capture mechanisms on a CE’s or BA’s website involve IIHI before de-identification.

    Flagging Non-Compliant Data Practices: A Vendor Evaluation Framework

    For Health IT professionals, a revised vendor evaluation framework is imperative. The new OCR guidance means that data practices previously considered benign or outside HIPAA’s direct purview are now firmly within its scope. This necessitates a proactive approach to flagging AI health apps and platforms whose data practices would disqualify them from large employer or health plan contracts. Here are specific red flags to watch for, anchored in the “Threat/Vulnerability Explainer” approach:

  • Absence of Comprehensive BAAs for Tracking Technologies: If an AI vendor or its sub-processors utilize tracking technologies on a CE’s or BA’s website and cannot produce a BAA covering these specific data flows, this is a critical vulnerability. Many Big Tech companies, accustomed to broad data collection, may lack the granular BAAs required for healthcare-specific tracking.
  • Undifferentiated Data Pools: Vendors who commingle IIHI with general consumer data for purposes like “improving services” or “personalizing user experience” without strict HIPAA-compliant controls and explicit patient consent for each specific use case present a significant threat. This is a common practice in consumer tech that is now explicitly problematic in healthcare.
  • Lack of Clear Opt-Out Mechanisms for Tracking: While patient consent is paramount, the OCR guidance also implies that CEs and BAs must ensure tracking technologies are configured to respect patient choices, including clear opt-out mechanisms that prevent the collection of IIHI for non-treatment, non-payment, or non-healthcare operations purposes.
  • AI Models Trained on Unsegregated Data: If an AI health app’s models are trained on datasets that include IIHI alongside consumer data, and the vendor cannot demonstrate robust de-identification processes or clear HIPAA-compliant consent for such training, it represents a compliance risk. The line between “de-identified” and “re-identifiable” is increasingly scrutinized.
  • Vague Privacy Policies Regarding Third-Party Sharing: Public disclosures from vendors should clearly articulate how IIHI is shared with third parties, including tracking technology providers. Ambiguous language or a lack of specificity regarding data use and sharing with “partners” or “affiliates” should trigger deeper scrutiny.
  • Inability to Demonstrate Data Flow Mapping: A compliant vendor should be able to precisely map all data flows, identifying where IIHI is collected, processed, stored, and transmitted, including by all sub-processors and tracking technologies. A lack of this granular understanding is a significant vulnerability. As Foley & Lardner’s Health Care Law Today might advise, the onus is on the covered entity to perform rigorous due diligence, not just on the primary vendor, but on their entire data ecosystem, especially concerning AI and tracking technologies. Top-tier Health Law Blog on HIPAA and AI

    The Path Forward: Prescriptive Guidance for Health IT Leaders

    The new OCR guidance is a call to action for Health IT professionals. It mandates a shift from reactive compliance to proactive risk management, particularly in the context of Big Tech partnerships and AI health apps. First, conduct an immediate and thorough audit of all third-party tracking technologies deployed on your organization’s websites, patient portals, and any digital health platforms where IIHI may be collected or accessed. Identify every pixel, cookie, and analytics script. Second, review and renegotiate Business Associate Agreements (BAAs) with all vendors implicated by these tracking technologies. Ensure BAAs explicitly address the collection, use, and disclosure of IIHI via tracking, and prohibit its use for commercial purposes not permitted by HIPAA. If a vendor refuses to sign a compliant BAA, they must be removed. Third, implement a robust AI health HIPAA compliance checklist for all new and existing AI health apps. This checklist must go beyond general security and privacy to specifically address data minimization, segregation, consent mechanisms, and the provenance of training data, with a strong emphasis on independent third-party validation of these claims. Fourth, establish a continuous monitoring program for third-party vendor compliance. This includes regular audits, penetration testing, and ongoing assessment of vendor data practices. The threat of non-compliance is not static; it evolves with technology and regulatory interpretation. The era of assuming that general website data is distinct from HIPAA-protected health information is over. For Health IT leaders, this means that partnering with Big Tech, while offering innovative solutions, now demands an even higher level of scrutiny. The compliance posture of an organization like Hello Heart, built from the ground up with healthcare privacy in mind, serves as a critical benchmark. Vendors failing to meet this standard, particularly those whose core business models rely on broad data monetization, will increasingly find themselves disqualified from the stringent procurement filters of large employers and health plans. In summary, the core shift is the re-clarification of IIHI to explicitly include data collected via online tracking technologies, fundamentally impacting how third-party tech partners must handle patient data. The primary action for Health IT leaders is an urgent need for deeper BAA scrutiny and granular data flow analysis, extending to every digital touchpoint where IIHI might be collected. This evolving dynamic between healthcare compliance and consumer tech integration demands a proactive, risk-averse posture, ensuring that innovation never compromises patient privacy.

Frequently Asked Questions

What is the key takeaway from the December 2022 HHS OCR Bulletin for Health IT professionals?

The bulletin clarifies that individually identifiable health information (IIHI) collected via online tracking technologies, even before a formal diagnosis, falls under HIPAA protections when transmitted to or maintained by a HIPAA-covered entity or business associate. This significantly expands the scope of what constitutes PHI and highlights third-party vendor risk.

What types of data, when collected through online tracking technologies, are now considered IIHI under the new OCR guidance?

Data such as IP addresses, geographic location, medical record numbers, home addresses, email addresses, dates of birth, and any other unique identifying codes or characteristics that, when linked with health information, can identify an individual, are now considered IIHI if collected via online tracking technologies on a CE or BA’s site.

How does this new OCR guidance impact the use of third-party vendors, especially those not primarily in healthcare?

The guidance emphasizes that CEs and BAs are responsible for ensuring their third-party vendors, including those providing website analytics or advertising, comply with HIPAA when handling IIHI. This necessitates robust Business Associate Agreements (BAAs) and a detailed understanding of data flows, extending beyond traditional clinical systems.

What specific challenges does the OCR guidance present for Health IT leaders evaluating partnerships with Big Tech entities like Amazon’s One Medical?

Health IT leaders must scrutinize the Big Tech partner’s underlying data architecture and business model to ensure IIHI is segregated from general consumer data. They must also confirm that AI models are trained and operated in a HIPAA-compliant manner, preventing inadvertent exposure or non-permitted use of IIHI.

Share
Was this article helpful?

Michael Davis

Michael, a health policy analyst, provides thoughtful Opinion & Analysis on current health debates. His work challenges perspectives and fosters informed discussion.