Skip to main content
Category: HITRUST Assessment Types

AI Security Assessment

Also known as: AI Risk Assessment, AI Security Risk Assessment
Simply put

An AI Security Assessment is a systematic review of artificial intelligence systems, including their models, data pipelines, and supporting infrastructure, to identify and address security risks. The goal is generally to help an organization discover, evaluate, and prioritize risks that AI systems may introduce to its operations. It is one type of assessment offered by various vendors and frameworks, and its specific scope and methodology vary by provider.

Formal definition

An AI Security Assessment is the structured, risk-based evaluation of AI systems, models, data pipelines, and associated infrastructure intended to articulate, track, prioritize, and remediate security risks arising from those systems. Approaches vary by provider: for example, the HITRUST AI Security Assessment and Certification applies tailored security controls to provide validated assurance for AI systems, while other structured assessments (such as vendor programs from Microsoft, IBM with Palo Alto Networks, RAND, and SentinelOne) focus on discovering, assessing, and prioritizing AI-related risks across an organization's environment. Note that these assessments are distinct offerings and frameworks; a HITRUST AI Security Certification is a private certification and is not, by itself, a legal requirement nor does it establish HIPAA compliance. Where AI systems process electronic protected health information (ePHI), HIPAA Security Rule obligations and other applicable frameworks (including state law and the HITECH Act) may impose additional requirements beyond any AI security assessment, and readers should verify specific scope, controls, and certification criteria against the current source documentation and regulatory guidance.

Why it matters

AI systems introduce security risks that differ in character from those addressed by traditional application or infrastructure reviews. Models, training and inference data pipelines, and the infrastructure supporting them can create new avenues for compromise, and organizations increasingly need a structured way to articulate, track, and remediate the risks these systems introduce to business operations. An AI Security Assessment provides that systematic evaluation, helping an organization discover, evaluate, and prioritize AI-related risks before they affect operations.

For healthcare organizations, the stakes are heightened when AI systems process protected health information. Where an AI system handles electronic protected health information (ePHI), HIPAA Security Rule obligations continue to apply, and other frameworks, including state law and the HITECH Act, may impose additional requirements. An AI Security Assessment can support an organization's broader risk analysis efforts, but it is important to understand its limits: completing such an assessment does not by itself establish HIPAA compliance, and the specific scope and methodology vary considerably by provider.

Because AI Security Assessments are offered as distinct products and frameworks by different vendors, organizations should be careful about what any given assessment covers and what assurance it actually provides. A private certification such as the HITRUST AI Security Certification is not a legal requirement and does not substitute for meeting applicable regulatory obligations. Readers should verify the scope, controls, and certification criteria of any assessment against current source documentation and regulatory guidance.

Who it's relevant to

Security and Risk Officers
Security officers responsible for evaluating and prioritizing organizational risk can use an AI Security Assessment to systematically identify security risks that AI models, data pipelines, and supporting infrastructure introduce. It supports the articulation, tracking, and remediation of those risks, though it should be integrated with existing risk management processes rather than treated as a complete substitute.
Privacy and Compliance Officers in Healthcare
Where AI systems process ePHI, compliance officers should understand that HIPAA Security Rule obligations and other frameworks, including state law and the HITECH Act, may impose requirements beyond any AI security assessment. Completing such an assessment, or obtaining a private certification like HITRUST's, does not by itself establish HIPAA compliance, and its scope should be verified against current regulatory guidance.
IT and AI Development Teams
Developers and engineers building or deploying AI systems can use these assessments to surface risks across models, data pipelines, and cloud infrastructure. RAND's guide, for example, is described as a practical, risk-based resource for developers, security experts, and policy professionals navigating the AI security landscape.
Vendors and Business Associates
Organizations that provide AI-enabled services to covered entities may be asked to demonstrate that they have assessed the security of their AI systems. Note that specific obligations attach through defined relationships such as business associate agreements, and an AI Security Assessment is one form of evidence that should be evaluated alongside contractual and regulatory requirements.

Inside AI Security Assessment

Scope Definition and Asset Inventory
An AI Security Assessment generally begins by identifying the AI systems, models, data pipelines, and infrastructure in scope, along with any electronic protected health information (ePHI) that flows through them. Because the HIPAA Security Rule governs only ePHI, the assessment should clearly delineate which AI components create, receive, maintain, or transmit ePHI versus those that do not.
Risk Analysis Alignment
For covered entities and business associates, an AI Security Assessment is typically framed within the broader risk analysis obligation under the HIPAA Security Rule's administrative safeguards. It evaluates threats and vulnerabilities that AI systems introduce to the confidentiality, integrity, and availability of ePHI.
Safeguard Mapping
The assessment generally maps AI-related risks to the Security Rule's administrative, physical, and technical safeguard categories, and considers both required and addressable implementation specifications. Addressable specifications are not optional; where an addressable specification is not implemented as written, the reasoning and any equivalent alternative measure should typically be documented.
Data Flow and Training Data Considerations
Because AI models may ingest large volumes of data for training, tuning, or inference, the assessment typically examines how ePHI is used, whether uses are permitted under the Privacy Rule, and whether data minimization or de-identification could reduce exposure. Note that Privacy Rule considerations extend to PHI in all forms, not only electronic.
Vendor and Business Associate Relationships
Where an AI tool is provided or operated by a third party, the assessment should evaluate whether that vendor meets the definition of a business associate or subcontractor. HIPAA obligations generally attach through defined relationships documented in business associate agreements rather than automatically to every vendor that touches data.
Documentation and Evidence
An AI Security Assessment typically produces documented findings, identified gaps, and remediation plans. This documentation may support HIPAA Security Rule compliance efforts and, separately, may be used as evidence when pursuing a control framework such as the HITRUST CSF.

Common questions

Answers to the questions practitioners most commonly ask about AI Security Assessment.

Does HIPAA have a specific rule or requirement for conducting an AI security assessment?
No. HIPAA does not, as of the applicable regulatory text, contain a provision that specifically names or mandates an 'AI security assessment' as a distinct requirement. Where AI systems create, receive, maintain, or transmit ePHI, they generally fall within the scope of the existing Security Rule risk analysis and risk management obligations, which apply to ePHI regardless of the technology involved. An AI security assessment is best understood as a practice for satisfying those existing safeguard requirements in the context of AI, not as a separate legal mandate. Readers should verify specific obligations against the current regulation.
If our AI vendor is HITRUST certified, does that mean our AI security assessment obligations under HIPAA are satisfied?
Not by itself. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; a vendor's HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance for your organization or the vendor. A certification may provide useful assurance evidence, but a covered entity or business associate generally remains responsible for its own Security Rule risk analysis, for the terms of any business associate agreement, and for evaluating how the AI system handles ePHI. You should confirm the scope of any certification and verify details against the current HITRUST CSF version and current guidance.
Which Security Rule safeguard categories typically apply when assessing an AI system that handles ePHI?
An AI security assessment generally considers all three Security Rule safeguard categories: administrative safeguards (such as risk analysis, workforce training, and access management policies), physical safeguards (such as controls over the facilities and devices where the AI system and its data reside), and technical safeguards (such as access controls, audit controls, integrity controls, and transmission security applied to ePHI processed by the system). Remember that the Security Rule applies only to ePHI; PHI in oral or paper form falls under the Privacy Rule and is out of scope for these particular safeguards.
How should addressable implementation specifications be handled during an AI security assessment?
Addressable does not mean optional. For each addressable implementation specification relevant to the AI system, an organization generally must assess whether the specification is reasonable and appropriate in its environment, and then either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate and how the requirement is otherwise met. Required specifications must be implemented as stated. Documenting these determinations for AI systems is typically a core part of the assessment record. Verify the specific classifications against the current regulatory text.
How do business associate relationships factor into assessing a third-party AI service?
HIPAA obligations attach through defined relationships rather than to every vendor that touches data. If a third-party AI service creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate, that vendor generally functions as a business associate, and a business associate agreement is typically required to flow down applicable obligations. Any further subcontractors that handle the ePHI may also need agreements in turn. An AI security assessment should identify these relationships and confirm that the appropriate agreements and safeguards are in place; the precise obligations should be verified against current guidance.
Can an AI security assessment guarantee that our use of AI is HIPAA compliant or prevents breaches?
No assessment can guarantee compliance or prevent all breaches. An AI security assessment is generally a tool to identify and help mitigate risks to ePHI as part of the ongoing risk analysis and risk management process, and it typically needs to be revisited as systems, data flows, and threats change. Organizations should also be aware that state law, the HITECH Act, or other frameworks may impose additional requirements beyond HIPAA, and that HHS OCR enforces HIPAA. Treat the assessment as evidence of reasonable diligence rather than proof of compliance, and confirm obligations against current guidance.

Common misconceptions

Passing an AI Security Assessment or achieving HITRUST certification for an AI system establishes HIPAA compliance.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. HIPAA is enforced by HHS OCR, and an assessment or certification generally supports, but does not guarantee, compliance. Readers should confirm requirements against the current regulation and the current HITRUST CSF version.
An AI Security Assessment only needs to address technical controls such as model security and encryption.
The HIPAA Security Rule addresses administrative, physical, and technical safeguards. A thorough AI Security Assessment generally considers all three categories, including workforce training, access management, and physical protection of infrastructure, not technical measures alone.
HIPAA automatically regulates any AI vendor that processes healthcare data.
HIPAA obligations attach through defined relationships. A vendor is generally subject to HIPAA-derived obligations when it qualifies as a business associate or subcontractor and those obligations are established through a business associate agreement, not merely because it handles data.

Best practices

Clearly scope the assessment by mapping which AI systems and data flows involve ePHI, keeping in mind that the Security Rule governs only ePHI while the Privacy Rule covers PHI in all forms including oral and paper.
Integrate the AI Security Assessment into your organization's broader HIPAA risk analysis rather than treating it as a standalone exercise, and document identified risks and remediation decisions.
Evaluate each AI vendor to determine whether it is a business associate or subcontractor, and ensure appropriate business associate agreements are in place before ePHI is shared.
Address administrative, physical, and technical safeguards together, and document the rationale and any alternative measures whenever an addressable implementation specification is not implemented as written.
Consider data minimization or de-identification for AI training and inference data where feasible, and verify that any use or disclosure of PHI is permitted under the Privacy Rule.
Treat any HITRUST certification or assessment result as supporting evidence rather than proof of HIPAA compliance, and confirm penalty exposure, thresholds, and requirements against current HHS OCR guidance, applicable state law, the HITECH Act, and the current HITRUST CSF version.