Your clinicians are using ChatGPT to draft patient notes. Your ambient scribe vendor never signed a BAA. Your AI triage tool has never had a bias audit. All three are active HIPAA exposure — and HHS OCR is watching AI in healthcare more closely than ever.
12 questions · 5 minutes · Instant compliance score
A hospitalist uses ChatGPT to summarize a patient's discharge summary before dictating a follow-up note. The prompt includes the patient's name, diagnosis, medication list, and lab values — all protected health information. OpenAI's consumer product has no signed Business Associate Agreement with your organization. That single prompt is a reportable HIPAA breach under the HIPAA Privacy Rule. Across a department, it's a pattern that triggers an HHS OCR investigation. The covered entity is liable even if the clinician acted unilaterally — because the organization has no AI acceptable use policy that prohibits consumer AI tools for PHI-containing workflows.
HIPAA Privacy Rule · 45 CFR § 164.502The cardiology department deploys an ambient AI scribe — a voice-recording tool that transcribes patient encounters in real time. The vendor's product team moves fast and the procurement process is informal. No Business Associate Agreement is executed before go-live. The vendor's servers process every recorded patient-physician conversation, including diagnoses, complaints, and treatment discussions. Under the HIPAA Security Rule, any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate — and operating without a BAA is an immediate HIPAA violation with a potential penalty floor of $100 per violation (up to $25,000 per year for identical violations). With dozens of recorded encounters per day, exposure compounds fast.
HIPAA Security Rule · 45 CFR § 164.308 · BAA RequirementAn AI-powered patient scheduling and triage tool prioritizes appointment slots based on predicted no-show rates — a model trained on historical data that correlates zip code, insurance type, and visit history with no-show likelihood. In practice, the model consistently deprioritizes patients from lower-income zip codes and those on Medicaid, because those groups had higher no-show rates in training data. This is algorithmic bias producing disparate impact along race, disability, and economic status lines — triggering Section 1557 of the ACA (non-discrimination in health programs), FTC Section 5 exposure, and potential HHS OCR scrutiny if the bias correlates with a protected class. No bias audit was ever conducted before deployment. Under the EU AI Act, AI used in access to healthcare is classified high-risk under Annex III — requiring documented bias testing before deployment regardless of where your patients are located.
ACA Section 1557 · FTC Section 5 · EU AI Act Annex IIIAfter your 12-question assessment, GovernIQ generates a personalized $299 Compliance Action Plan — specific to your organization type, AI tools in use, PHI exposure points, and state-specific requirements. Not a template. Built from your answers.
Written policy that prohibits consumer AI tools for PHI-containing workflows, defines approved tools categories, and maps to the HIPAA Privacy Rule, Security Rule, and HHS OCR guidance on AI in clinical settings.
Checklist for evaluating whether existing and new AI vendors are business associates, what BAA terms are required, and how to handle vendors who refuse to sign — before PHI touches their systems.
Categorized inventory of AI tools your organization can use for patient-facing workflows, can use only in de-identified contexts, and must prohibit — with the HIPAA rationale and BAA status for each.
Role-specific training for clinicians, administrative staff, and IT on what constitutes PHI in AI prompts, how to identify whether a vendor is a business associate, and what to do when an AI tool hasn't been approved.
Documentation templates for logging AI contributions to clinical decisions — exam-ready for HHS OCR investigations, CMS audits, and any state-level AI disclosure requirements (including CA AB 3030).
GovernIQ is designed for physician groups, community health centers, specialty clinics, digital health startups, and regional health systems that need real AI compliance — without the enterprise vendor runaround. No sales call. No scoping exercise. Start in 5 minutes.
Legacy compliance platforms quote $50k–$200k/year before you've even seen a demo. GovernIQ starts free and delivers a HIPAA-specific action plan for $299.
| Feature | GovernIQ | OneTrust | Vanta | Drata | Holistic AI |
|---|---|---|---|---|---|
| Pricing published | ✅ Yes | ✗ Contact sales | ✗ Contact sales | ✗ Contact sales | ✗ Contact sales |
| Starting price | $0 / $299 | $50,000+ / yr | $10,000+ / yr | $7,500+ / yr | $200,000+ / yr |
| Free compliance assessment | ✅ Yes | ✗ No | ✗ No | ✗ No | ✗ No |
| HIPAA AI coverage | ✅ Included | Add-on module | Add-on module | Add-on module | Add-on module |
| Self-serve available | ✅ Yes | ✗ No | Partial | Partial | ✗ No |
| Same-day delivery | ✅ Minutes | Weeks | Weeks | Weeks | Months |
The free assessment scores your organization's AI governance across tools, data handling, staff training, and policy — in 12 questions. You'll know exactly where you're exposed, and what it costs to fix it.
Free assessment · Compliance Action Plan $299 · No subscription