Healthcare AI Vendor Risk Management

VERITY — Healthcare AI Vendor Risk

AI Vendor Risk Management for Mid-Market Hospitals

Mid-market hospitals have signed dozens of Business Associate Agreements with vendors who have since added AI features to their products. In most cases the BAA predates the vendor’s AI feature set — the HIPAA-compliance, security, and operational implications of vendor AI features touching your PHI rarely got re-litigated when the vendor turned the features on. Armorstack’s AI vendor risk management posture — Pillar 4 governance work applied to healthcare — closes the gap.

The Landscape

The Healthcare AI Vendor Risk Landscape Today

Healthcare vendors have rapidly integrated AI features into their existing products — EHR vendors, RCM vendors, patient communication vendors, scheduling vendors, billing vendors, clinical AI vendors, infrastructure vendors. In most cases the vendor’s existing Business Associate Agreement does not explicitly contemplate six things.

AI Use of PHI for Service Delivery

The vendor’s AI feature processes PHI to deliver its core function — often undisclosed in the original BAA scope.

AI Training on PHI

Whether the vendor’s model is trained or fine-tuned on your PHI, and under what opt-out or contractual controls, if any.

AI Output Containing PHI

Generated summaries, drafts, or recommendations that reproduce or reference PHI, and where that output is stored or transmitted.

AI Prompt Logging

Prompts sent to the vendor’s AI feature may themselves contain PHI, and vendor logging/retention practices for those prompts.

Sub-Processor AI Relationships

The vendor’s AI feature likely runs on an infrastructure-layer sub-processor — OpenAI, Anthropic, Google, AWS Bedrock — whose own BAA posture matters.

AI-Specific Incident Notification

Whether the vendor’s breach-notification obligations explicitly cover AI-layer incidents, not just traditional data-access breaches.

These gaps are not necessarily HIPAA violations — the underlying BAA may continue to apply — but they are gaps in the operational and contractual posture. Mid-market hospitals discovering these gaps for the first time during an OCR audit are in a more difficult position than those who discovered them during routine vendor risk management.

Our Approach

Armorstack’s Healthcare AI Vendor Risk Approach

Pillar 4 governance work, applied to healthcare AI vendor risk, covers six areas.

Vendor Inventory of AI Use

The comprehensive list of vendors who have AI features in use against your PHI, produced from Pillar 1 discovery.

Vendor Classification

By the AI use case’s risk tier, the vendor’s documented AI security posture, and the gap between the existing BAA and what the AI use case requires.

BAA Addendum Language

For high-risk vendor relationships, specifically addressing AI use of PHI, AI training on PHI, AI output containing PHI, AI prompt logging, sub-processor disclosure, and AI-specific incident notification obligations.

AI-Calibrated Security Questionnaire

Not the generic SaaS security questionnaire your team uses today, but an AI-specific instrument designed for the actual questions vendors should be answering.

Reassessment Cadence

Aligned to your existing vendor risk management program, with AI-specific triggers — vendor AI feature release, vendor sub-processor change, AI-related public incident.

Incident Response Coordination

For vendor-side AI compromise affecting your PHI — from initial notification through remediation and documentation.

FAQ

Frequently Asked Questions — Healthcare AI Vendor Risk

How does this fit with our existing vendor risk management program?

The Pillar 4 vendor risk work is designed to extend, not replace, your existing program. Most mid-market hospitals have established vendor risk management (often centered on the SIG questionnaire, HITRUST CSF assessments, or NIST 800-66-aligned vendor reviews). The AI vendor risk work adds AI-specific instruments and reassessment triggers to the existing program rather than creating a parallel one.

How many of our vendors actually need a BAA addendum?

It depends on what discovery surfaces. Mid-market hospitals typically have 30-100 active vendor relationships involving PHI. Of those, a subset have meaningful AI features in active use. The Pillar 1 discovery and Pillar 2 classification work identify which specific vendor relationships warrant priority addendum negotiation. The framework does not recommend rewriting every BAA; it prioritizes the highest-risk subset.

What if a vendor refuses to sign an AI-specific BAA addendum?

Some vendors will. Pillar 4 governance includes escalation language for the executive sponsor relationship with that vendor, alternative-vendor evaluation criteria, and risk-acceptance documentation if your organization decides to continue the relationship despite the gap. The framework supports the decision either way; it ensures the decision is documented and defensible.

How does this connect to vendor AI sub-processors?

Healthcare AI vendors increasingly rely on infrastructure-layer AI vendors — OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI — as sub-processors of their AI features. Pillar 4 governance specifically addresses sub-processor disclosure: which infrastructure AI vendor is processing your PHI, what their downstream BAA posture is, what their data residency and training posture is. The chain of BAA coverage must extend through the sub-processor relationship to be defensible.

How does this affect our existing HITRUST CSF program?

HITRUST CSF’s vendor risk management controls map directly to the framework’s Pillar 4 vendor risk work. The framework’s deliverables can feed into HITRUST CSF self-assessment or external assessment evidence directly.

Does Armorstack maintain a healthcare AI vendor reference list?

Armorstack maintains operational knowledge of the major healthcare AI vendor ecosystem and updates this knowledge continuously through engagement work. The reference is not published as a public list (vendor situations change rapidly and a published list dates quickly) but is shared with clients during engagement.

Bring AI Vendor Risk Inside Your Existing Program

Apply for the free 30-day AI Risk Assessment. Pillar 4 governance work is sized for your existing vendor risk management program.

Or call 877-890-5508

Last reviewed: 2026-07-09. Authored by Dale Boehm, CEO Armorstack. CISA + CDPP.