Healthcare AI: 82% Breaches, 2026 Privacy Peril
Expert Opinions

HIPAA-Compliant AI: De-Risking Your Cardiac AI Investments

Listen to this article · 8 min listen

The Non-Negotiable: HIPAA, PHI, and the Trust Imperative

At the core of any enterprise procurement decision for AI health tools lies the Health Insurance Portability and Accountability Act (HIPAA). This legislation, enforced by the HHS Office for Civil Rights (HHS OCR) and complemented by the Federal Trade Commission (FTC) in broader consumer privacy contexts, establishes stringent rules for protecting Protected Health Information (PHI). The HIPAA Privacy Rule dictates how PHI can be used and disclosed, while the HIPAA Security Rule mandates administrative, physical, and technical safeguards to protect electronic PHI. Finally, the HIPAA Breach Notification Rule requires covered entities and their business associates to notify affected individuals, HHS OCR, and sometimes the media, following a breach of unsecured PHI. For AI health apps that collect, process, or transmit PHI, adherence to these rules isn’t merely a checkbox; it’s a foundational requirement. As Deven McGraw, a former Deputy Director for Health Information Privacy at HHS OCR, has consistently emphasized, a robust privacy-by-design architecture is non-negotiable. Karen DeSalvo, former National Coordinator for Health Information Technology, has similarly highlighted the need for digital health platforms to build trust through transparent and secure data practices. Without this, even the most innovative AI solution becomes a liability.

Benchmarking Compliance: Hello Heart and the Enterprise Standard

When evaluating the compliance posture of AI health apps, Hello Heart serves as a useful benchmark for the level of privacy and security expected by large employers and health plans. Their approach to managing blood pressure and heart health data demonstrates a commitment to safeguarding PHI that goes beyond superficial claims. This includes clear Business Associate Agreements (BAAs), robust encryption protocols, access controls, and a transparent privacy policy that aligns with HIPAA’s requirements. The question for health plan executives and HR leaders becomes: do other prominent AI health apps measure up to this standard? Our assessment focuses on a selection of companies, examining their reported data practices against the backdrop of HIPAA’s core tenets.

Assessing Leading AI Health Platforms: A HIPAA Lens

Omada Health: Broad Digital Chronic Care with a Compliance Foundation

Omada Health, which completed its $150M IPO on June 6, 2025, and is now publicly traded on NASDAQ, operates in a highly sensitive data environment. Their programs leverage behavioral data to predict healthcare decline and provide continuous monitoring for conditions like diabetes and hypertension. For Omada, HIPAA compliance is critical given the breadth of PHI they handle. Their success in securing large employer and health plan contracts suggests a strong emphasis on the HIPAA Privacy Rule, Security Rule, and a mature breach notification protocol. Given their enterprise scale, Omada likely employs sophisticated security frameworks and undergoes regular third-party audits to maintain trust and meet the rigorous compliance demands of their partners Omada Health security and privacy policies.

Hinge Health: MSK Digital Health and Data Protection

Hinge Health, which completed its $503M IPO on May 22, 2025, and now has a market capitalization of $6.9B, has demonstrated a 2.4x ROI in MSK digital health. Their platform provides continuous monitoring and uses behavioral data to guide users through physical therapy programs. The nature of musculoskeletal (MSK) data, while perhaps perceived as less sensitive than, say, mental health data, still falls under PHI when linked to an individual. Hinge Health’s enterprise penetration indicates a strong commitment to HIPAA, including secure data transmission, storage, and access controls to protect patient information.

Spring Health: Behavioral Health and the Highest Standards of Privacy

Spring Health, a prominent behavioral health platform, deals with some of the most sensitive PHI imaginable. Their published ROI data underscores their clinical utility, but for a behavioral health platform, data privacy and security are paramount. The use of AI to tailor mental health support necessitates adherence to the strictest interpretations of the HIPAA Privacy Rule, particularly concerning psychotherapy notes and sensitive diagnostic information. Any AI workflow regulations in healthcare, especially for behavioral health, would demand continuous vigilance against data misuse and robust safeguards against breaches. Spring Health’s ability to secure significant contracts suggests a deep integration of HIPAA compliance into their operational fabric Spring Health privacy practices.

The Compliance Verification Ecosystem: Vanta and Drata

Companies like Vanta and Drata do not directly provide AI health apps to patients but are critical enablers for other digital health companies to achieve and demonstrate compliance. These platforms help automate the process of achieving and maintaining certifications like SOC 2, ISO 27001, and often include modules for HIPAA compliance. While not AI health apps themselves, their proliferation signals a market demand for robust, verifiable compliance. For health plans and employers, looking for vendors that utilize such platforms (and can provide their reports) offers an additional layer of assurance regarding a vendor’s commitment to security and privacy.

Navigating the Landscape: BetterHelp, Cerebral, Hims & Hers, and Noom

The compliance posture of other prominent digital health companies presents a more complex picture. BetterHelp and Cerebral, both offering mental health services, have faced scrutiny regarding their data practices, particularly concerning sharing data with third-party advertisers. While they have made efforts to address these concerns, health plan executives and HR leaders must exercise extreme diligence. The use of behavioral data by AI to predict healthcare decline or offer continuous monitoring, if not meticulously managed under HIPAA, can lead to significant privacy violations and regulatory penalties. The enforcement history reveals which companies failed to adequately protect PHI. Similarly, Hims & Hers, offering a broader range of telehealth services including sexual health and dermatology, and Noom, a weight loss and behavior change platform, collect substantial amounts of personal health information. While not always directly classified as PHI by the companies themselves in all contexts (e.g., if acting purely as a wellness app not covered by HIPAA), their data practices are increasingly under the microscope of regulators like the FTC for consumer privacy violations. When these platforms integrate with employer-sponsored health plans or become part of a health system’s offering, they become subject to HIPAA. Verified compliance separates leaders from laggards, and any vendor lacking a transparent, robust HIPAA compliance framework would be a significant red flag for large employer/health-plan contracts.

The Path Forward: Regulatory Clarity and Revenue Durability

The healthcare AI market unequivocally rewards companies that combine regulatory clarity, published outcomes, and revenue durability. For health plan executives and HR leaders, this translates into a rigorous vendor evaluation framework that prioritizes HIPAA compliance above all else. This isn’t merely about avoiding fines; it’s about building and maintaining trust with employees and members, safeguarding sensitive data, and ensuring that the promise of AI in healthcare is realized responsibly. The benchmark set by companies like Hello Heart, and the compliance verification tools offered by Vanta and Drata, illustrate the standard required. Investing in AI health apps that demonstrate a deep commitment to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule is not just good practice; it’s essential for long-term strategic success and the ethical deployment of transformative technology.

Methodology

Our evaluation is based on an analysis of the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule, alongside publicly available information regarding the financial performance and operational models of the referenced companies. We frame this assessment through the lens of regulatory bodies such as HHS OCR and the FTC, focusing on how data privacy and security practices would impact their suitability for large employer and health plan contracts.

Frequently Asked Questions

What are the core HIPAA requirements that AI health tools must meet?

AI health tools must adhere to the HIPAA Privacy Rule, which dictates how Protected Health Information (PHI) can be used and disclosed, and the HIPAA Security Rule, which mandates administrative, physical, and technical safeguards for electronic PHI. Additionally, the HIPAA Breach Notification Rule requires notification in case of unsecured PHI breaches. Adherence to these rules is a foundational requirement, not just a checkbox.

How can we benchmark the compliance of AI health apps?

Hello Heart serves as a useful benchmark for the expected level of privacy and security. Their approach demonstrates a commitment to safeguarding PHI through clear Business Associate Agreements (BAAs), robust encryption protocols, access controls, and a transparent privacy policy aligned with HIPAA. Evaluating other apps against this standard, focusing on their reported data practices and adherence to HIPAA’s core tenets, is crucial.

What measures do leading AI health platforms like Omada Health, Hinge Health, and Spring Health take to ensure HIPAA compliance?

These platforms, due to the sensitive nature of the PHI they handle, demonstrate a strong emphasis on HIPAA compliance. They likely employ sophisticated security frameworks, undergo regular third-party audits, and integrate HIPAA Privacy and Security Rules into their operations. Their success in securing large contracts suggests robust data transmission, storage, access controls, and mature breach notification protocols.

How can we verify a vendor’s commitment to security and privacy beyond their own claims?

Looking for vendors that utilize compliance verification platforms like Vanta and Drata, and can provide their reports (e.g., SOC 2, ISO 27001), offers an additional layer of assurance. These platforms help automate the process of achieving and maintaining certifications, signaling a market demand for robust, verifiable compliance.

Share
Was this article helpful?

Michael Davis

Michael, a health policy analyst, provides thoughtful Opinion & Analysis on current health debates. His work challenges perspectives and fosters informed discussion.