Skip to content
Halsted AI

Privacy

Using AI without breaking HIPAA

Every practice owner asks this second, right after what it costs. Here is the answer in plain language, without the lawyer words. It is shorter than you expect.

What we usually find

Where the money is actually going

01

The rule has not changed; the tools have

HIPAA says nothing about AI, and it does not need to. It says protected health information may only be handled by people and companies bound by a business associate agreement, that you share the minimum necessary, and that you can show afterwards who saw what. Those three ideas cover AI cleanly. In practice most of the exposure comes from a helpful staff member pasting patient details into a free consumer tool to draft a letter faster.

02

The vendor question is simple and most people skip it

Will you sign a BAA. That is the whole question. If the answer is no then the tool cannot touch patient information, however good the demo was. Several very popular products answer no on their free tier and yes on their business tier. Same brand, same model, completely different contractual position, and that is the detail practices miss.

03

Minimum necessary is a design decision, not a policy document

The safest design never sends the sensitive field at all. An AI that books appointments does not need a diagnosis. One that answers billing questions does not need clinical notes. We design the flow so the risky information is not in the pipe, which removes most of the exposure before any security control is applied.

04

If you cannot show the log, you cannot show compliance

Every system we build records what it accessed, what it said and what it did, in a form you could hand to an auditor tomorrow. Quick automations skip this, because it is invisible until the day somebody asks.

What we'd build

Fixed price, quoted after the audit

from $14,500

Intake & Records

The paperwork fills itself in.

What a patient writes on a form arrives in the chart with nobody retyping it. Insurance checked before they walk in. A one-page summary on the provider's screen that morning.

  • Digital intake forms that land in the chart, not in a PDF pile
  • Insurance eligibility checked and flagged before the visit
  • Referral letters, scans and faxes read and filed automatically
  • A one-page pre-visit summary for the provider
  • Flags missing information while there's still time to fix it

Live in 4–6 weeks

How it goes

Audit, build, stay.

  1. 01

    We audit

    Two weeks watching how the work really moves. You get a written plan with dollar figures on it, and you keep it whether or not you hire us.

  2. 02

    We build

    Fixed price, three to six weeks. It connects to the software you already run. Staff are trained during the build, not on go-live day.

  3. 03

    We stay

    We watch it, fix what drifts, add one new thing each quarter. Cancel any month on thirty days' notice.

Who's doing the work

25,000
patients on a healthtech platform I built, then sold
$6.5M+
processed through it
$50M+
in credit issued on products I led
10 yrs
building software under real regulation

Founder and CTO of Slate. Built a healthtech platform used by 25,000 patients and sold it. Ten years shipping software in regulated industries. More about that.

The questions everyone asks

Can we use ChatGPT in the office?

Not with patient information on a consumer account. The business tiers of the major products will sign a BAA and those are usable. The real risk in almost every practice is not the system you bought. It is a well-meaning staff member pasting a history into a free tool because it saves them twenty minutes. That is a tooling and training problem and you can fix it in an afternoon.

Where does our data actually go?

Every build ships with a one-page data map. Each piece of information, the systems it passes through, who can see it, how long it is kept, how it gets deleted. If that diagram cannot be drawn simply then the design is too tangled to reason about, and we change the design rather than the diagram.

Do you keep our patient data?

No more than the system needs to work, and never to train anything. You set retention, it goes in the contract, and it is enforced in the code rather than promised in a PDF.

What about state privacy laws?

Several states go further than HIPAA, particularly on recorded calls and consent. The audit checks the rules for your state and your situation. It is also why disclosure that a caller is speaking to AI is standard in everything we ship rather than a setting you can turn off.

Two weeks from now you could have the plan.

The audit is $2,500. Refundable if it cannot pay for itself three times over, and the fee comes off anything you go on to build.