Private AI guide
Can a private AI system meet HIPAA requirements?
Self-hosting removes the hardest part of the problem. It does not make you compliant, and any vendor implying otherwise is selling you a risk.
What self-hosting genuinely solves
The hardest HIPAA question about AI is the third party. Sending protected health information to a model vendor makes them a business associate, which requires a BAA, a risk assessment covering them, and ongoing confidence in their controls.
Self-hosted, there is no third party. No BAA to negotiate, no sub-processor to review, no vendor terms to re-read each quarter. That is a material simplification and it is the reason clinical deployments end up here.
What remains entirely yours
- Access controls. Minimum necessary access, enforced. We implement this; you define who may see what.
- Audit controls. Logging of access to protected information, retained per your policy.
- A risk analysis covering the AI system as part of your environment.
- Policies and procedures governing what staff may do with it.
- Workforce training on those policies.
- Contingency planning, backups and recovery.
Worth saying: This is not a list we can complete for you. We build the technical controls — scoped access, audit logging, retention — and tell you plainly which administrative obligations stay with the practice. Felican AI does not provide legal or compliance advice, and a practice that treats a deployment as compliance has substituted a vendor claim for its own assessment.
The clinical boundary in the system itself
Separate from the regulation: a deployment in a practice must not give clinical advice, interpret symptoms or discuss results. That is a hard rule in the build, tested before go-live, not a tuning preference.
What it does instead is schedule, answer logistics and policy questions, retrieve from your own documented material, and route anything clinical to a person. See AI for medical and dental practices for how that is implemented.
How to document the decision
- Name the use case precisely. "Retrieval over practice policies for front-desk staff" is assessable. "AI" is not.
- Record what information it can reach and the access scope.
- Record the controls — access, audit, retention, encryption — and who verified them.
- Record what you decided not to do and why. This is the part that demonstrates judgement.
- Review it when the system or the use changes.
The question you will eventually be asked is not whether you used AI. It is whether you thought about it, and whether you can show the thinking.
Questions people actually ask
Before you call
Do we still need a BAA?
Not with a model vendor, because self-hosted there is no model vendor. You may still need one with us depending on whether our maintenance access touches protected information — we will tell you straight whether it does.
Is this legal advice?
No. We build technical controls and describe them accurately. Compliance determinations are yours, with your own advisors.
Can the AI talk to patients?
For scheduling, logistics and policy, yes. For anything clinical, no — it routes to a person, and that boundary is tested before go-live.
Still have the question?
Ask us directly. We answer these on calls all day.
