About PHI — plainly
Most of what's above never touches protected health information, and that's deliberate. Referral timing, authorization dates, shift coverage, and recruiting are operational data. Building there means faster results and a much smaller risk surface for both of us.
If a project genuinely needs PHI — visit notes, assessments, clinical documentation — that is a different engagement and I'll say so before we scope it. It requires a signed Business Associate Agreement with me, and it requires that every service in the chain underneath me is also covered by one. That chain is the part most vendors wave at and don't actually have.
I do not describe myself as HIPAA compliant, because that phrase doesn't mean anything about a consultant. What I can tell you is exactly which services would process your data and what agreements each one is under, in writing, before you decide.
Ask any vendor this
Ask any AI vendor to name every subprocessor that would touch your data and show you the BAA for each. The answer to that question tells you more than any badge on their homepage.
How data is actually handled, including every subprocessor: data handling →