The first question isn't "can Claude do this" - it's "does this touch PHI"

A surprising share of valuable healthcare back-office automation doesn't need to touch protected health information at all - drafting a generic appointment-reminder template, summarizing publicly available insurance policy language, or triaging a general inbound question about office hours can all be built without a single PHI field ever reaching the model.

Scoping the automation to avoid PHI where possible isn't a workaround - it's the fastest way to ship something useful without waiting on a full Business Associate Agreement and audit review for every feature.

Before designing any healthcare automation, map exactly which fields in the workflow are PHI and which aren't. Features that avoid PHI entirely can often ship in weeks; features that touch it need a BAA and a much more careful review cycle first.

When PHI is unavoidable, a Business Associate Agreement is the starting requirement, not the finish line

For the workflows where PHI genuinely has to be processed - intake summarization, clinical note drafting support, billing dispute follow-up - a signed Business Associate Agreement covering the AI provider is the non-negotiable starting point, not a box to check after the fact.

Past that, the same governance discipline applies as any other regulated AI deployment: scope the tool's access to exactly the fields the task requires, log every PHI-touching action for audit, and keep a human reviewing anything that leaves the practice's system - a drafted patient communication, a billing appeal - before it goes out.

Scope to the minimum PHI needed

A billing-follow-up assistant needs the balance and claim status - not the full clinical record.

Log every PHI-touching action

An audit trail of what was accessed, when, and why is a HIPAA expectation, not an optional extra for AI tooling specifically.

Where this pays off fastest

Scheduling and intake workflows tend to be the highest-value, lowest-risk starting point - most of the language involved (confirmations, reminders, form completion prompts) can be built PHI-light. Billing follow-up and prior-authorization drafting are higher value but need the full compliance path in place first.

Scoping a healthcare automation project and need to know where the PHI line actually falls? Talk to us before you build.

Key takeaways

  • Map which fields in a healthcare workflow are actually PHI before designing the automation - a surprising share of valuable work can be built without touching it at all.
  • For any workflow that does touch PHI, a signed Business Associate Agreement covering the AI provider is the starting requirement, not something to arrange after launch.
  • Scope tool access to the minimum PHI the specific task needs, and log every PHI-touching action for audit - this is standard HIPAA discipline applied to AI tooling.
  • Start with PHI-light workflows like scheduling and intake, and save PHI-heavy ones like billing appeals or clinical note drafting for after the compliance path is fully in place.
This is general information, not legal or compliance advice. Whether a specific workflow requires a BAA or falls under HIPAA depends on your practice's exact data flows - consult qualified compliance counsel before deploying any PHI-touching AI feature.