AI Compliance for Health Care

Deploy Clinical and Enterprise AI Without Putting PHI or Patients at Risk

Ambient scribes, imaging AI, prior-auth algorithms and patient chatbots all touch PHI and clinical decisions. Asenion turns HIPAA, nondiscrimination and device requirements into operational controls your CISO, compliance and clinical informatics teams can verify, monitor and evidence.

Schedule a Call

30 minutes with our AI compliance team.

What auditors and regulators will ask about

5 headline regulations and standards for AI in health care

Few of these were written only for AI. All of them apply to it.

US · Privacy and security

HIPAA Privacy and Security Rules

Protects PHI held by covered entities and business associates, and requires a security risk analysis plus administrative, physical and technical safeguards.

For AI: AI vendors handling PHI need BAAs. Prompts, outputs and training data containing PHI need access controls, audit logs and minimum-necessary use.

US · Nondiscrimination

ACA Section 1557 (45 CFR 92.210)

HHS rule requiring covered health programs to address discrimination risk from patient care decision support tools, in effect since May 2025.

For AI: Identify clinical algorithms and AI tools that use race, color, national origin, sex, age or disability, and make reasonable efforts to mitigate discrimination risk.

US · Medical devices

FDA AI-Enabled Device Software Functions

FDA oversight of AI as software as a medical device, including Predetermined Change Control Plans (PCCPs) for models that are updated after clearance.

For AI: AI that diagnoses or guides treatment may be a device. Model updates need a PCCP or a new submission, plus real-world performance monitoring.

Industry · Security assurance

HITRUST CSF and AI Security Assessment

The certifiable security framework health systems and payers most often ask vendors for, now with AI-specific security requirements.

For AI: Show AI security controls to procurement and third-party risk teams in a format they already accept.

EU · AI and devices

EU AI Act with MDR / IVDR

AI that is a medical device, or a safety component of one, is high-risk under the AI Act. Under the AI Omnibus, these obligations apply from August 2028.

For AI: Add AI Act risk management, data governance, logging and human oversight to your existing MDR or IVDR conformity assessment.

Use cases

Where AI meets these rules in health care

The AI use cases we see most often, and the requirements that follow them.

Clinical decision support and imaging AI

Diagnostic and triage models need validation across patient subgroups, bias mitigation and monitoring for performance drift after go-live.

FDA SaMD / PCCPSection 1557EU AI Act + MDR

Ambient scribes and GenAI documentation

Scribes process PHI in real time and draft notes clinicians sign. They need BAAs, hallucination testing, clinician review and retention controls.

HIPAAHITRUSTSection 1557

Prior authorization and utilization management

Algorithms that deny or delay care draw regulator scrutiny. Medical necessity decisions need individual clinical review and explainable criteria.

CMS-4201-F (Medicare Advantage)Section 1557Colorado SB 26-189

Patient-facing chatbots and agents

Scheduling, triage and billing assistants must disclose AI use, hand emergencies to humans and never leak PHI.

HIPAAEU AI Act Art. 50HITRUST
How Asenion helps

From regulation to operational control

One set of controls, applied from vendor intake through runtime, with evidence your privacy office, internal audit and regulators can rely on.

01 · CONTROLGEN

Policy Packs for health care

Start from Policy Packs for HIPAA, Section 1557, FDA AI guidance and the EU AI Act, combined with your own AI and clinical governance policies.

02 · VERIFY

Verify before release

Test clinical and GenAI tools for subgroup bias, hallucination, PHI leakage and prompt injection, with every result mapped back to a control.

03 · WITNESS

Govern at runtime

Apply context-aware controls to AI agents in production and capture tamper-resistant evidence of what happened, which controls applied and whether they worked.

Using SAS® AI Navigator? Asenion policy content is available there too. Learn more →
Case studies

Health AI we help build and adopt safely

From patient-facing chatbots to Canada's digital health research network.

Patient chatbot · CIHR-funded research

ChatRheum: a patient chatbot for rheumatology

Led by Dr. Carrie Ye at the University of Alberta and funded by the Canadian Institutes of Health Research, ChatRheum answers rheumatology patients' questions while they wait to see a specialist. In healthcare, a wrong or careless answer can cause real harm, so we help test that its responses are accurate, empathetic, readable and safe for patients.

Read about ChatRheum →
Digital health network · DHDP member

Digital Health and Discovery Platform (DHDP)

Asenion is a member of the Digital Health and Discovery Platform (DHDP). The Terry Fox Research Institute (TFRI) is the sole lead and governing body that manages and directs the DHDP. We support DHDP members in developing and adopting AI in healthcare with Asenion AI Assurance and the Asenion AI Control System, so health AI is tested, governed and evidenced from research through to clinical use.

Asenion on DHDP →

Make your clinical and enterprise AI audit-ready

In 30 minutes we'll map your AI use cases to the rules above, show the controls that apply, and point out where your AI governance has gaps.

Schedule a Call

No preparation needed.