4.2 Privacy in Emerging Technologies: AI, Telehealth, Cloud & Medical Apps

Key Takeaways

  • Artificial Intelligence (AI) and Machine Learning (ML) tools deployed in clinical or administrative workflows—such as ambient AI scribes and automated coding algorithms—require executed Business Associate Agreements (BAAs) if they access, ingest, or process PHI, and public/open AI models cannot ingest raw PHI without patient authorization.
  • Telehealth privacy compliance requires HIPAA-compliant audio/video platforms with end-to-end security and executed BAAs; following the expiration of OCR's COVID-19 Public Health Emergency enforcement discretion, standard HIPAA Privacy and Security Rule enforcement applies fully to virtual care delivery.
  • Cloud Service Providers (CSPs) and SaaS vendors that store, process, or transmit ePHI are classified as Business Associates under HHS guidance, even if the CSP maintains encrypted 'no-view' access and lacks the decryption keys.
  • Remote Patient Monitoring (RPM) and Internet of Medical Things (IoMT) devices require explicit patient privacy disclosures, encrypted transmission channels, role-based cloud access, and vendor BAA coverage for cloud backends.
  • Direct-to-Consumer (DTC) health apps and mHealth platforms that are not offered on behalf of a covered entity fall outside HIPAA jurisdiction and are regulated by the Federal Trade Commission (FTC) under the FTC Act and the FTC Health Breach Notification Rule (HBNR).
Last updated: August 2026

Privacy in Emerging Technologies: AI, Telehealth, Cloud & Medical Apps

Technological innovation in healthcare is advancing at an unprecedented rate. From ambient clinical artificial intelligence (AI) listening to patient-physician encounters to cloud-hosted Electronic Health Records (EHRs), telehealth platforms, Internet of Medical Things (IoMT) devices, and direct-to-consumer (DTC) mobile health applications, privacy compliance officers face an increasingly complex technical landscape.

Ensuring compliance in these emerging environments requires applying established statutory standards—such as Business Associate Agreements (BAAs), the Minimum Necessary Rule (45 CFR § 164.502(b)), and statutory De-Identification (45 CFR § 164.514)—while navigating emerging regulatory jurisdictions, including the Federal Trade Commission (FTC) Health Breach Notification Rule.


1. Artificial Intelligence (AI) & Machine Learning in Healthcare

Artificial intelligence applications in healthcare span generative AI ambient scribes (which record doctor-patient conversations to draft clinical notes), automated computer-assisted coding engines, predictive diagnostic imaging algorithms, and clinical trial matching systems.

+---------------------------------------------------------------------------------------------------+
|                         HEALTHCARE ARTIFICIAL INTELLIGENCE PRIVACY MATRIX                         |
|                                                                                                   |
|   AI USE CASE                  REGULATORY CLASSIFICATION    MANDATORY PRIVACY SAFEGUARDS          |
|   ---------------------------------------------------------------------------------------------   |
|   Ambient AI Clinical Scribe   Business Associate (BA)      - Executed BAA before deployment      |
|   (Real-time audio processing) (Processes live PHI)        - Zero-data retention on public model |
|                                                             - Explicit patient notice/consent     |
|                                                                                                   |
|   Predictive Diagnostic Tool   Business Associate (BA)      - Minimum necessary role access       |
|   (Ingests clinical records)   (Processes ePHI)             - Encrypted API transmission          |
|                                                             - Audit logging of algorithm access   |
|                                                                                                   |
|   Internal Model Training      Covered Entity / BA          - Full Safe Harbor De-ID (§ 164.514)  |
|   (Developing algorithms)      Research / Operations        - OR Expert Statistical Determination |
|                                                             - OR Patient HIPAA Authorization      |
|                                                                                                   |
|   Public / Consumer AI Models  Third-Party Platform         - STRICT PROHIBITION on inputting raw |
|   (e.g., ChatGPT, Claude)      (NO BAA in place)              PHI/ePHI into public prompts        |
+---------------------------------------------------------------------------------------------------+

Critical AI Privacy Compliance Rules:

  1. The BAA Requirement: Any AI vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a Business Associate under 45 CFR § 160.103. Deploying an AI tool without an executed BAA is a direct violation of HIPAA.
  2. Training Data & De-Identification: Using patient records to train, fine-tune, or validate machine learning models requires either:
    • Full statutory de-identification under 45 CFR § 164.514 (removing all 18 identifiers under the Safe Harbor method or securing a certified Expert Determination);
    • A Limited Data Set (LDS) accompanied by a binding Data Use Agreement (DUA) under § 164.514(e) if used for healthcare operations or research; or
    • Specific Patient Authorization authorizing the use of identifiable PHI for commercial algorithm development.
  3. The Public Generative AI Trap: Clinicians and administrative staff are strictly prohibited from copying patient records, diagnostic summaries, or operative notes into public, commercial generative AI tools that lack enterprise BAA coverage. Public tools frequently retain user prompts for continuous model training, resulting in an impermissible third-party disclosure under 45 CFR § 164.502.

2. Telehealth & Virtual Care Privacy Compliance

During the COVID-19 nationwide public health emergency (PHE), the HHS Office for Civil Rights issued temporary enforcement discretion allowing healthcare providers to use non-public-facing consumer video applications (such as Apple FaceTime, Skype, or Google Meet) for telehealth visits without risking HIPAA penalties.

+---------------------------------------------------------------------------------------------------+
|                     TELEHEALTH REGULATORY TRANSITION: PHE VS. CURRENT STANDARD                    |
|                                                                                                   |
|   COVID-19 PUBLIC HEALTH EMERGENCY (PHE)            CURRENT / POST-PHE REGULATORY MANDATE         |
|   [Enforcement Discretion Active]                   [Standard Enforcement Fully Reinstated]       |
|   -----------------------------------------------   -------------------------------------------   |
|   • Temporary OCR penalty waiver for good-faith     • Full HIPAA Privacy & Security Rule          |
|     telehealth delivery.                              enforcement active across all virtual visits.|
|   • Non-public video apps allowed (FaceTime, Skype) • Non-compliant consumer apps STRICTLY BANNED.|
|   • No formal BAA required for video vendors.       • Executed BAA MANDATORY for all platforms.   |
|   • Expired May 11, 2023 (with 90-day grace period  • End-to-end encryption & access control     |
|     ending August 9, 2023).                           logs required under 45 CFR Part 164 Subpart C|
+---------------------------------------------------------------------------------------------------+

Mandatory Telehealth Privacy Safeguards:

  • Platform Compliance & BAAs: Providers must use dedicated, enterprise-grade virtual care platforms (e.g., Zoom for Healthcare, Doxy.me, Epic MyChart Virtual Visits) with executed BAAs, AES-256 transmission encryption, and individual clinician authentication.
  • Physical Privacy in Virtual Visits: Clinicians conducting virtual visits must ensure private physical environments (closed doors, soundproofing, privacy screens, headphones) to prevent incidental disclosures to family members, coworkers, or passersby.
  • Multi-State Licensing & Preemption: Telehealth delivery across state lines requires compliance not only with HIPAA, but also with state medical board licensing rules and the privacy laws of the state where the patient is physically located at the time of the encounter.

3. Cloud Computing & Software-as-a-Service (SaaS)

Healthcare organizations rely heavily on cloud service providers (CSPs) for infrastructure (IaaS), platforms (PaaS), and software (SaaS) hosting EHRs, imaging archives (PACS), and email systems.

+---------------------------------------------------------------------------------------------------+
|                         HHS GUIDANCE: CLOUD SERVICE PROVIDERS AS BAs                              |
|                                                                                                   |
|   +-------------------------------------------------------------------------------------------+   |
|   |                   HHS OCR CLOUD GUIDANCE (45 CFR §§ 160.103 & 164.502)                    |   |
|   +-------------------------------------------------------------------------------------------+   |
|                                                 |                                                 |
|       +-----------------------------------------+-----------------------------------------+       |
|       |                                                                                   |       |
|       v                                                                                   v       |
|   [CSP STORES / TRANSMITS ENCRYPTED ePHI]                             ["NO-VIEW" SERVICE PROVIDER]|
|   - CSP maintains servers containing ePHI.                            - CSP holds encrypted data  |
|   - Data is encrypted in transit & at rest.                           - CSP does NOT have the     |
|   - CSP lacks the decryption key.                                       decryption key / access.  |
|       |                                                                                   |       |
|       +-----------------------------------------+-----------------------------------------+       |
|                                                 |                                                 |
|                                                 v                                                 |
|                       +---------------------------------------------------+                       |
|                       |            STATUTORY CLASSIFICATION:              |                       |
|                       |           THE CSP IS A BUSINESS ASSOCIATE         |                       |
|                       |     A SIGNED BAA IS MANDATORY BY FEDERAL LAW      |                       |
|                       +---------------------------------------------------+                       |
+---------------------------------------------------------------------------------------------------+

The "No-View" Encryption Doctrine

Under HHS OCR Cloud Guidance, a CSP that creates, receives, maintains, or transmits ePHI on its infrastructure is a Business Associate, even if the CSP only stores encrypted data and does not possess the decryption key (referred to as a "no-view" service). Storing ePHI constitutes "maintaining" PHI under 45 CFR § 160.103. Engaging a cloud vendor without an executed BAA violates HIPAA, regardless of encryption strength.


4. Remote Patient Monitoring (RPM) & Internet of Medical Things (IoMT)

Connected medical devices—including continuous glucose monitors (CGMs), Bluetooth blood pressure cuffs, cardiac telemetry patches, and smart hospital beds—generate continuous streams of sensitive physiological ePHI.

IoMT / RPM ComponentOperational Privacy VulnerabilityMandatory Compliance Control
Device TelemetryUnencrypted Bluetooth transmission vulnerable to eavesdropping.Mandate TLS 1.3 / AES encryption for all device-to-hub transmissions.
Home Gateway / Mobile AppDevice pairs with patient's unmanaged smartphone containing malware.Require dedicated containerized medical apps with independent authentication.
Cloud Backend & AnalyticsDevice manufacturer aggregates physiological data for commercial resale.Execute BAA restricting data use solely to treatment/operations; prohibit commercial data mining.
Patient Consent & NoticePatient unaware of continuous location or biometric tracking.Deliver clear, written device disclosures explaining data collection frequency and access rights.

5. Direct-to-Consumer (DTC) Health Apps & FTC Jurisdiction

A critical distinction on the CHPC exam is the regulatory dividing line between HIPAA (HHS OCR) and the FTC Act / FTC Health Breach Notification Rule (FTC).

+---------------------------------------------------------------------------------------------------+
|                     REGULATORY JURISDICTION: HHS OCR (HIPAA) VS. FTC (HBNR)                       |
|                                                                                                   |
|   CRITERION                  HHS OCR JURISDICTION (HIPAA)          FTC JURISDICTION (FTC ACT/HBNR)|
|   ---------------------------------------------------------------------------------------------   |
|   Entity Type                Covered Entities (Hospitals, Doctors, Non-Covered App Developers,    |
|                              Health Plans) & Business Associates   DTC Health/Fitness Platforms   |
|                                                                                                   |
|   Governing Rule             HIPAA Privacy, Security & Breach      FTC Act Section 5 (Unfair/     |
|                              Notification Rules (45 CFR 160/164)   Deceptive) & HBNR (16 CFR 318) |
|                                                                                                   |
|   Trigger Scenario           Hospital patient portal app; digital  Period tracking app; commercial|
|                              clinic app provided on behalf of CE.  mental health app; direct-to- |
|                                                                    consumer DNA kit app.          |
|                                                                                                   |
|   Data Sharing Standard      Strict TPO, Authorization, & BAA      FTC enforcement against sharing|
|                              mandates under 45 CFR Part 164.       health data with advertisers   |
|                                                                    (Google/Meta) without consent. |
+---------------------------------------------------------------------------------------------------+

FTC Health Breach Notification Rule (16 CFR Part 318)

Under the FTC Health Breach Notification Rule (HBNR) and recent FTC enforcement actions (e.g., FTC v. GoodRx, FTC v. BetterHelp, FTC v. Premom):

  • Non-HIPAA covered mobile health apps that collect identifiable health data are legally bound to protect consumer information.
  • Disclosing sensitive health information (such as prescription purchases, mental health counseling status, or ovulation cycles) to third-party advertising platforms (e.g., Meta Pixel, Google Analytics) without affirmative, express consumer consent constitutes an unauthorized disclosure and a breach under the HBNR.
  • Failure to notify consumers and the FTC of such unauthorized sharing triggers massive FTC civil penalties up to tens of thousands of dollars per violation per day.
Loading diagram...
Jurisdictional Decision Tree for Healthcare Emerging Technologies
Test Your Knowledge

A hospital contracts with a Cloud Service Provider (CSP) to store encrypted backups of its Electronic Medical Record database. The CSP holds the encrypted data on secure servers but does not possess the encryption keys and has no administrative ability to view or decrypt the underlying patient files. According to HHS OCR guidance, what is the regulatory status of the CSP?

A
B
C
D
Test Your Knowledge

A commercial mobile software developer releases a direct-to-consumer (DTC) smartphone application that allows users to track their fertility cycles, medications, and symptoms. The app was created independently and is not affiliated with any healthcare provider or health plan. The developer integrates third-party marketing tracking pixels that secretly transmit user symptom data and IP addresses to commercial advertisers. Which federal regulatory agency has primary enforcement jurisdiction over this data breach, and under what authority?

A
B
C
D
Test Your Knowledge

A healthcare system wants to implement a cutting-edge generative AI ambient clinical scribe that listens to physician-patient encounters in the exam room to automatically generate clinical notes. What compliance requirement must the Privacy Officer enforce before the tool is deployed in clinical care?

A
B
C
D