The first question isn't "can Claude do this" - it's "does this touch PHI"
A surprising share of valuable healthcare back-office automation doesn't need to touch protected health information at all - drafting a generic appointment-reminder template, summarizing publicly available insurance policy language, or triaging a general inbound question about office hours can all be built without a single PHI field ever reaching the model.
Scoping the automation to avoid PHI where possible isn't a workaround - it's the fastest way to ship something useful without waiting on a full Business Associate Agreement and audit review for every feature.
When PHI is unavoidable, a Business Associate Agreement is the starting requirement, not the finish line
For the workflows where PHI genuinely has to be processed - intake summarization, clinical note drafting support, billing dispute follow-up - a signed Business Associate Agreement covering the AI provider is the non-negotiable starting point, not a box to check after the fact.
Past that, the same governance discipline applies as any other regulated AI deployment: scope the tool's access to exactly the fields the task requires, log every PHI-touching action for audit, and keep a human reviewing anything that leaves the practice's system - a drafted patient communication, a billing appeal - before it goes out.
Scope to the minimum PHI needed
A billing-follow-up assistant needs the balance and claim status - not the full clinical record.
Log every PHI-touching action
An audit trail of what was accessed, when, and why is a HIPAA expectation, not an optional extra for AI tooling specifically.
Where this pays off fastest
Scheduling and intake workflows tend to be the highest-value, lowest-risk starting point - most of the language involved (confirmations, reminders, form completion prompts) can be built PHI-light. Billing follow-up and prior-authorization drafting are higher value but need the full compliance path in place first.
Scoping a healthcare automation project and need to know where the PHI line actually falls? Talk to us before you build.
Key takeaways
- Map which fields in a healthcare workflow are actually PHI before designing the automation - a surprising share of valuable work can be built without touching it at all.
- For any workflow that does touch PHI, a signed Business Associate Agreement covering the AI provider is the starting requirement, not something to arrange after launch.
- Scope tool access to the minimum PHI the specific task needs, and log every PHI-touching action for audit - this is standard HIPAA discipline applied to AI tooling.
- Start with PHI-light workflows like scheduling and intake, and save PHI-heavy ones like billing appeals or clinical note drafting for after the compliance path is fully in place.
Zetrixweb