AI Demand Letters and HIPAA: What PI Attorneys Must Know
AI Demand Letters and HIPAA: What PI Attorneys Must Know
Medical records require careful handling, but HIPAA applicability depends on the firm's role and the data flow. Here is where Business Associate Agreements fit — and why "HIPAA-compliant" is not a label a vendor can simply claim.
Here is a question we get from nearly every firm that evaluates an AI demand letter tool: "Is this HIPAA compliant?" It is the right question. It is also the wrong way to phrase it, because HIPAA compliance is not a checkbox a vendor ticks — it is a legal relationship that either exists or does not. This post is about what that relationship actually requires, and why the honest answer is more nuanced than a yes or no on a sales page.
Medical Records Do Not Answer the HIPAA Question by Themselves
A demand letter contains highly sensitive health information: diagnoses, treatment dates, provider names, and billing codes. But possessing those records does not automatically make every plaintiff PI firm a HIPAA covered entity or every vendor its business associate. HIPAA applicability depends on the parties' legal roles and the actual data flow.
That nuance is not permission to use consumer tools casually. Attorney confidentiality duties, protective orders, client instructions, state privacy laws, and vendor contracts may impose separate or stricter limits even when HIPAA does not govern the firm.
The ChatGPT Question, Answered Directly
This comes up constantly, so let's be direct about the operational answer: do not paste a client's identifiable medical records into ChatGPT, Claude, Gemini, or another public consumer AI interface. Consumer subscriptions are not the same contractual and technical service as an eligible enterprise API. Even where HIPAA does not apply to the firm, confidentiality and privacy obligations still require a controlled workflow.
This is not a knock on those AI products. They are built for general use, not regulated healthcare data, and they are upfront that they are not designed for it. The point is that "AI is smart enough to help" and "this AI tool is legally authorized to touch PHI" are two completely different questions, and only the second one matters here.
What a Real Business Associate Agreement Requires
A BAA is not a marketing checkbox. It is a binding contract that obligates the vendor to specific things: safeguard the data using HIPAA's Security Rule standards, restrict use of the data to the services being performed, name and control any sub-processors who also touch the data, and notify the covered entity within a defined window if a breach occurs.
That last point is easy to overlook and worth flagging: many commercial AI contracts default to a 30-day breach notification window. HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach — which means a vendor's slow notification can eat most of your own compliance deadline before you even know there was a problem. The BAA has to account for that.
"HIPAA-compliant" is not a label a vendor can self-certify. It is the outcome of a signed BAA plus the safeguards required underneath it — and a vendor can have excellent security and still be non-compliant without one.
The Sub-Processor Trap
This is the part that catches firms off guard, and it is directly relevant to any AI demand letter tool: most AI products do not run on a single model. They route requests through one or more underlying AI providers, plus a database layer, plus often a separate service for document processing. Each one of those is a sub-processor that touches PHI if the data flows through it.
A BAA that only covers the vendor's primary product, without naming every sub-processor in that chain, leaves a real gap. Before trusting any AI tool with real client records, the right question is not "do you have a BAA," but "does your BAA cover every system this data actually passes through."
| Public consumer AI | Properly governed AI vendor | |
|---|---|---|
| Signs a BAA | No | Yes — covering the full data flow |
| Sub-processors named | N/A | Should be explicitly listed |
| Breach notification | Not HIPAA-governed | Defined window, contractually set |
| Safe to enter real PHI | Never | Only once the BAA is in place |
Where Lexyno Stands Today
We think the honest answer here matters more than the convenient one, so here is the current position plainly: Lexyno has Business Associate Agreements with the two model API providers used in the product pipeline, OpenAI and Anthropic. Gemini was removed from the product pipeline rather than retained as an uncovered fallback.
Those agreements cover specific API services, organizations, endpoints, and eligible features; they do not cover public ChatGPT, Claude consumer interfaces, or every third-party tool. Lexyno therefore does not treat a signed BAA as a blanket "HIPAA compliant" label. Contractual coverage, access controls, data minimization, retention, incident response, and the customer's own legal role must still line up with the actual data flow.
What to Ask Any AI Vendor Before You Send Real Records
Whether you are evaluating Lexyno or anyone else, this is the actual checklist:
- Will you sign a BAA, and is it in place before any real PHI is processed?
- Does the BAA name every sub-processor the data passes through, not just the primary product?
- What is the contractual breach notification window, and does it leave you enough time to meet your own 60-day obligation?
- How is data used and retained — is it used to train the vendor's models, and for how long is it stored?
- Which exact service and configuration are covered, and is there any consumer interface or uncovered fallback in the path?
A vendor that answers these clearly, including admitting what is not yet in place, is a more trustworthy partner than one that just says "yes, we're HIPAA compliant" and moves on. Compliance is a process you can verify, not a label you take on faith.
Frequently asked questions
Do not put identifiable client medical records into a consumer chatbot. Whether HIPAA applies depends on the firm's legal role and the data flow, but confidentiality duties, protective orders, state privacy law, and vendor terms can still restrict disclosure. Use a governed product workflow whose contracts and controls cover the specific service handling the records.
A BAA is a legally binding contract used when a covered entity or business associate engages another party to handle protected health information. It defines permitted uses, safeguards, sub-contractor obligations, and breach duties. A plaintiff PI firm is not automatically a HIPAA covered entity simply because it possesses medical records, so the parties' roles and actual data flow must be assessed rather than inferred from the file type alone.
"HIPAA-compliant" is not a status a vendor can self-certify or a product can claim out of the box. Compliance is the result of a signed BAA plus the technical, administrative, and physical safeguards required by the Security Rule. A vendor can have strong encryption and access controls and still be non-compliant if no BAA is in place, or if the BAA does not cover the specific way PHI flows through the product.
Ask directly: will you sign a Business Associate Agreement, and does it cover every AI model or sub-processor that touches the data, not just the primary product? Many AI products route data through several underlying model providers, and a BAA that does not name those sub-processors leaves a gap. Also ask how data is used, retained, and whether it is used to train the vendor's models.
Removing or masking identifying details before data reaches an AI system is a recognized way to reduce HIPAA exposure while a vendor relationship matures, because properly de-identified data falls outside HIPAA's PHI definition. It is a reasonable interim safeguard during evaluation, but it is not a substitute for a signed BAA once a firm is processing real client records in production.
Related posts
The Real Cost of Manual Demand Letters for a 3-Attorney Firm
A demand letter does not show up as a line-item expense, so most firms never actually calculate what one costs. Run the math on a typical 3-attorney practice and the number is bigger than it looks.
Why Your AI Demand Letter Keeps Getting the Numbers Wrong
If your AI demand letter tool keeps getting figures and dates wrong, that is not a bug you can prompt your way around. It is how language models generate numbers in the first place. Here is the actual mechanism, and what to do about it.
Solo PI Attorney vs. Big Firm: How AI Levels the Playing Field
No single firm controls more than 5% of the $61.7B personal injury market — yet AI adoption is nearly three times higher at large firms than at solo practices. That gap, not talent, is what AI is positioned to close.
What's next?
Ready to see the difference in your next case?
Put these strategies to work. Try a mock demand generated by Lexyno today.
Request Evaluation Access