Article

Beyond HIPAA: Managing healthcare privacy in an AI-driven era

Why healthcare organizations should act regardless of regulatory updates

September 16, 2026

Key takeaways

Line Illustration of a stethoscope

Act now, not later: Reduce risk regardless of potential HIPAA updates.

AI hand tapping a phone screen with a chart, representing mobile data monitoring technology.

AI raises the stakes: Strong governance, vendor oversight and BAAs are now essential.

Stacked coins with a dollar symbol and a blue circle overlay, representing cost or financial metrics.

Privacy extends beyond HIPAA: State laws are expanding consent and data control requirements.

#
Healthcare

The future of healthcare privacy is arriving before the compliance rules are finalized. Although proposed changes to the HIPAA Rule remain pending, regulators are already emphasizing many of the capabilities the updates would require. For organizations, that means compliance planning can no longer be tied solely to final rulemaking—it must begin now.

Privacy updates extend beyond HIPAA. The 2024 reproductive health privacy rule has been vacated. State consumer health data laws are expanding into new industries. Artificial intelligence is rewriting workflows faster than guidance can address it. Privacy officers cannot afford to wait for the rules to settle. The operational changes needed will take months to implement. Organizations should act now to address expected changes.

A new era of HIPAA: Stricter standards are coming

Over five years ago, the U.S. Department of Health and Human Services’ Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) to overhaul the HIPAA Privacy Rule. To date, that rule has not been enacted; however, with the administration’s 2026 Unified Agenda, the updates have moved one step closer to finalization. The specifics below should be treated as a forward-looking roadmap, not as current law.

AI breaks several HIPAA assumptions

HIPAA was built on assumptions that AI does not follow. For instance, the rule assumes data lives in identifiable systems, that access can be logged and explained, and that records can be deleted or controlled in predictable ways. AI, however, complicates each of these. Data flows through prompts, APIs, models and outputs. Model unlearning, the technical ability to remove a record's influence from a trained model, remains an unsolved research problem.

There is also an immediate operational risk related to the use of AI under HIPAA regulations. For example, a single prompt entered into the wrong system can constitute a reportable disclosure. Well-meaning employees may be using AI tools without fully understanding outcomes and consequences.

Regarding the use of AI, the regulatory response is fragmented:

OCR has not issued an AI-specific HIPAA rule. It has signaled that HIPAA applies to AI like any other technology, with particular concern for data leakage, data poisoning and the absence of BAAs with AI vendors.

The Office of the National Coordinator (ONC) for Health Information Technology HTI 1 Final Rule introduces transparency requirements for predictive decision support tools.

OCR's section 1557 guidance addresses AI-driven nondiscrimination and imposes additional obligations effective May 1, 2025.

In addition, telehealth can further compound complexity. When AI is embedded into telehealth workflows, each feature becomes another point of exposure. Organizations that establish AI governance processes now, including tool inventories, vendor oversight and data flow analysis, will be better positioned to comply with future privacy requirements and current enforcement expectations. In many cases, the controls needed to manage AI risk overlap with the capabilities regulators are increasingly focusing on across the healthcare industry. AI does not sit outside HIPAA. It can multiply the number of ways organizations can fail within it.

State consumer health data laws are pulling in new industries

HIPAA protects health information only within covered entities and business associates. It does not extend to the same information when it is obtained from consumers and lives in apps, devices or platforms. States are actively closing this gap, however.

Washington's My Health My Data Act applies broadly, defines health data expansively, requires opt-in consent, grants deletion rights and allows for private lawsuits. The first class action under the law was filed against Amazon in February 2025 and is now testing what qualifies as consumer health data. Nevada's SB 370 and Connecticut's SB 3 amendments are also in effect. New York's Health Information Privacy Act passed both chambers in January 2025 but was vetoed later that year, then reintroduced in 2026. These laws are not incremental. They pull companies into health privacy regulations even if they do not operate in traditional healthcare delivery.

Retailers, app developers and ad tech companies are now subject to these requirements whether they anticipated it or not. Vendors serving healthcare clients often lift their highest control standards across their customer base, extending HIPAA-inspired expectations outward and becoming the baseline for "reasonable security."

Where compliance actually breaks down: Consent

HIPAA allows data use for treatment, payment and operations without explicit permission each time. Consumer health laws require affirmative, purpose-specific consent. These models do not align. Organizations now operate under both simultaneously, however. Clinical systems follow HIPAA. Apps and digital platforms require opt-in consent. The legal distinction is clear. The systems are not, which is where compliance breaks down in practice.

Consent must be tracked at a level most systems were never designed to support:

  • What specific permissions did the user grant?
  • For what purpose?
  • In which system?
  • Has consent been withdrawn?

In theory, this is manageable, but in practice, most environments cannot support this level of tracking with confidence. AI can compound the problem. When data influences a model, removing the record is straightforward. Removing its effect is not.

A staged action plan

Now through the end of 2026 (before a final Privacy Rule), organizations should consider the following:

  • Understand where patient data resides and how it can be provided to patients near real time.
  • Identify where your organization can achieve operational efficiencies based on the proposed administrative overhead reduction.
  • Confirm that the 2024 reproductive health attestation has been retired and policies rolled back.
  • Inventory every AI tool that touches PHI. Obtain BAAs and document data flow risk analyses, including data leakage and prompt injection scenarios.

When the Privacy Rule updates are published:

  • Map existing controls against final requirements.
  • Build a compliance implementation plan against the final compliance deadline. Standard rulemaking practice provides approximately 240 days. Industry analysts have predicted OCR may stagger or extend timelines, particularly for small entities.
  • Renegotiate BAAs as necessary.

Ongoing:

  • Track state consumer health data laws for all consumer-facing services.
  • Treat OCR's Risk Analysis and Ransomware Initiatives as current enforcement reality.
  • Calibrate your program against enforcement patterns, not the absence of final rulemaking.

The takeaway

HIPAA remains important and is becoming stricter. It no longer defines the full privacy landscape. A single incident can now trigger action from federal regulators, state attorneys general and private plaintiffs simultaneously. Privacy is no longer about meeting one framework. It is about managing risk across overlapping systems that continue to evolve.

Healthcare organizations should use this period to strengthen patient access capabilities, evaluate AI-related risks and align privacy programs with emerging enforcement priorities. Those that act now will be better positioned regardless of rule updates and, more importantly, to navigate the evolving intersection of healthcare privacy, technology and patient trust.

RSM contributors

  • Lenny Levy
    Managing Director
  • Joseph Emerson
    Managing Director

Related solutions

RSM US MMBI

Cybersecurity special report

Our annual insights into cybersecurity trends, strategies and concerns shape the marketplace for midsize businesses in an increasingly complex risk environment.

Subscribe to Healthcare Leader Insights

Actionable insights to help healthcare industry leaders successfully navigate challenges and take advantage of opportunity.