Guide · agent safety
HIPAA and AI agents
The HIPAA Security Rule does not mention AI agents, but it applies to them: an agent that reads or changes electronic protected health information is software accessing ePHI, and the technical safeguards in 45 CFR 164.312 — access control, audit controls, integrity, authentication and transmission security — apply to it the same way they apply to any other system. This guide maps each safeguard to the controls that produce evidence for it. It is not legal advice, and no product can make an organisation meet HIPAA on its own.
Access control — §164.312(a)(1)
Only authorised persons or software may access ePHI. For an agent that means its own identity (not a shared key), the specific actions it was granted, and refusal of everything else before it runs. Evidence: the agent registry, per-agent credentials, and refused actions with the rule that refused them.
Audit controls — §164.312(b)
Activity in systems that contain or use ePHI must be recorded and examinable. For agents: a decision record per action with its inputs, the policy version and the matched rule, in an append-only ledger. Information system activity review (§164.308(a)(1)(ii)(D)) is the practice of reading it.
Integrity — §164.312(c)(1)
ePHI must be protected from improper alteration or destruction. For agents: destructive and bulk actions held for a person or refused, and a kill switch that stops an agent immediately when it misbehaves.
Person or entity authentication — §164.312(d)
The identity of whoever seeks access must be verified. For agents: every request carries the agent’s own expiring credential, and the credential — not anything the agent says about itself — names the agent.
Transmission security — §164.312(e)(1)
ePHI in transit must be protected. This is a property of the networks and APIs the agent uses (TLS and the like) and sits outside what Agent Trust Cloud records; the evidence pack marks it as outside scope rather than implying coverage.
Business associate agreements
Agent Trust Cloud does not currently process PHI under a BAA. Configure agents to send Agent Trust Cloud action metadata — the agent, the action, the resource identifier, amounts and destinations — and not record contents. If your use would put PHI into Agent Trust Cloud, contact us before doing so.
Evidence you can export
The HIPAA Security Rule evidence pack lists, for each safeguard above, the records Agent Trust Cloud holds for the chosen period, and marks safeguards it does not record as outside scope. It supports your own risk analysis and audit; it does not replace them.