Artificial intelligence tools have entered home health operations at a pace that has significantly outrun the compliance frameworks most agencies have in place to govern their use. Care coordinators use ChatGPT to draft care plan language. Billing staff use AI writing assistants to generate prior authorisation documentation. Clinical supervisors use AI scheduling tools to optimise visit routing. Some EHR platforms have begun incorporating AI-generated documentation suggestions into clinical workflows. Each of these uses creates HIPAA documentation obligations that most home health HIPAA programmes have not yet addressed — not because administrators are negligent, but because the guidance has lagged the technology.
The HIPAA obligations that attach to AI tool use in home health are not new regulations created specifically for AI. They are the application of existing HIPAA Security Rule and Privacy Rule requirements to a new category of technology. Understanding how those existing requirements apply to AI tools — and what documentation they generate — allows home health agencies to use AI productivity tools compliantly rather than being forced to choose between productivity and compliance.
The Core HIPAA Obligation: If AI Touches PHI, It Must Be Managed Like Any Other System
The first and most important principle: any AI tool that creates, receives, maintains, or transmits PHI is a covered system under the HIPAA Security Rule and requires a Business Associate Agreement with the vendor. This principle applies regardless of how the tool is marketed, what its primary purpose is, or how incidentally it touches patient information. A care coordinator who pastes a patient's name, diagnosis, and care plan goals into ChatGPT to generate a draft care coordination letter has introduced that patient's PHI into a system operated by OpenAI — a system that does not have a BAA with the agency because the agency has not pursued one.
This is not a hypothetical compliance gap. It is the most common AI-related HIPAA gap I identify when assessing home health agencies in 2026. The administrative convenience of general-purpose AI tools — which are available immediately, require no procurement process, and deliver immediate productivity value — has consistently outpaced the compliance process of establishing BAA coverage for those tools before patient information is introduced into them.
Healthcare AI Tools With BAA Programmes vs. Consumer AI Tools
The AI tool landscape in 2026 has bifurcated into healthcare-specific tools with BAA programmes and consumer tools without them. Microsoft Copilot for Microsoft 365, when deployed through Microsoft 365 Business Premium or Enterprise agreements with a Microsoft HIPAA BAA in place, can process PHI within the Microsoft 365 environment with BAA coverage. Google Workspace AI features, when deployed through Google Workspace for Healthcare with the Google BAA, carry BAA coverage. Purpose-built healthcare AI tools — AI scribing tools, clinical documentation assistants, AI-powered coding support — typically provide BAAs as a standard feature.
Consumer versions of these tools — the public ChatGPT interface at chat.openai.com, the standard Google Bard or Gemini interface, the consumer version of Microsoft Copilot accessed outside a Microsoft 365 subscription — do not provide HIPAA BAAs. These tools must not be used with PHI, period. This prohibition should be explicit in the agency's acceptable use policy and AI use policy.
The Technology Asset Inventory Obligation for AI Tools
The 2026 HIPAA mandatory technology asset inventory — which must document all hardware and software that creates, receives, maintains, or transmits ePHI — must include AI tools that handle patient information. For each AI tool in use: the tool name and vendor, the category of PHI it accesses or generates, the BAA status (executed, pending, or not applicable if no PHI contact), the access control approach (who in the agency uses this tool and for what purposes), and the date added to the inventory. This inventory should be reviewed quarterly and updated whenever a new AI tool is introduced to agency operations.
The AI Use Policy: What Every Home Health Agency Needs in Writing
An AI use policy defines the boundaries for acceptable AI tool use in the agency's operations. At minimum it should specify: which AI tools are approved for use with patient information (by name, with BAA confirmation date); which AI tools are approved for use with non-PHI agency information; which AI tools are prohibited entirely for agency use; the requirement to obtain compliance review before introducing any new AI tool that may encounter patient information; and the staff reporting obligation when they discover they have introduced PHI into an unapproved AI tool.
Protecting your home health agency does not have to be complicated. It has to be done — completely, correctly, and documented in a way that holds up when it matters. ShieldForce makes that possible for organisations without IT departments, without compliance staff, and without the budget of a hospital system. Start with a free assessment.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Home Healthcare Cybersecurity — shieldforce.io/home-healthcare
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

