ISMS Copilot
HIPAA

HIPAA Copilot

Specialist AI guidance for the HIPAA Security and Privacy Rules

Risk analysis and policy documentation first: no ePHI in chats, and we do not sign BAAs.

What the HIPAA Copilot Can Do

Administrative, Physical, and Technical Safeguard guidance (45 CFR §164.308–§164.312)

Privacy Rule policies and Notice of Privacy Practices drafting

Risk analysis and risk management plan templates aligned to §164.308(a)(1)

Breach Notification Rule workflow (§164.400–§164.414)

Business Associate Agreement review and gap-checking against your existing contracts

Cross-mapping to ISO 27001, NIST 800-53, and HITRUST CSF

About HIPAA Copilot

HIPAA Copilot helps US covered entities and business associates understand and implement the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule. It is a guidance and policy-drafting assistant — not a HIPAA Business Associate. Do not paste protected health information (PHI) into chats.

Cross-framework mappings

Working across HIPAA and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

Is ISMS Copilot a HIPAA Business Associate?

No. ISMS Copilot is a compliance learning and policy-drafting tool, not a HIPAA Business Associate. We do not sign BAAs and you must not paste protected health information (PHI or ePHI) into chats. Use the Copilot to draft policies, understand requirements, and prepare for risk analysis. Keep ePHI in your dedicated HIPAA-compliant systems.

Who can use the HIPAA Copilot?

It is designed for compliance officers, privacy officers, security officers, and consultants working at US covered entities (health plans, healthcare providers, clearinghouses) and business associates who need to understand and document HIPAA obligations — not for end users handling patient data.

Does HIPAA apply to my organization?

It depends on the 45 CFR 160.103 definitions: health plans and clearinghouses are covered as such, providers only when they conduct HIPAA standard transactions electronically, and vendors through the business-associate chain. The free guide at /learn/do-i-need-hipaa walks that classification in prose. The free HIPAA Applicability Checker at /resources/hipaa-applicability-checker runs the same determination as a structured assessment, with the primary sources on the page.

Do I need HIPAA?

That is a 45 CFR 160.103 classification (covered entity, business associate, or neither), not a vibe. Walk the test at /learn/do-i-need-hipaa.

Where is my data hosted?

Database and document storage live in Frankfurt. AI processing is your choice: Mistral in the EU with zero retention, or Anthropic in the US under standard contractual clauses. That is independent of HIPAA: ISMS Copilot is not a Business Associate and you must not paste PHI, whichever inference region you pick.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.