Patient information that cannot legally touch an unsecured tool: what HIPAA requires from AI video
A Learning and Development or Knowledge Management team in a healthcare organization producing training content faces a specific, higher bar than most other teams evaluating a video platform: if that content includes real, identifiable patient information, HIPAA applies, and HIPAA compliance is a meaningfully different, more specific requirement than general enterprise security certification like SOC 2 or ISO 27001, one that most general-purpose SaaS tools aren’t built to satisfy without a dedicated program behind it.
What HIPAA actually is
The Health Insurance Portability and Accountability Act governs how protected health information, commonly abbreviated PHI, is handled by covered entities, healthcare providers, health plans, and their business associates, vendors who handle PHI on a covered entity’s behalf. PHI includes any individually identifiable health information, not just diagnoses or treatment records, but also information like a patient’s name combined with any health-related detail, appointment information, or billing details tied to care. This scope is broader than most teams initially assume, which is part of why it’s worth confirming explicitly rather than relying on intuition about what counts.
Why HIPAA is a meaningfully different bar than SOC 2 or ISO 27001
SOC 2 and ISO 27001 are general information security frameworks that apply broadly across industries. HIPAA is a specific US federal law with its own distinct requirements, most notably the requirement that any vendor handling PHI on behalf of a covered entity sign a Business Associate Agreement, commonly called a BAA, a legal document that defines the vendor’s specific obligations around safeguarding PHI. A vendor can hold strong general security certifications, SOC 2, ISO 27001, and still not offer a BAA or maintain the specific technical safeguards HIPAA requires, since these are legally distinct requirements that don’t automatically transfer from one framework to another.
What the HIPAA Security Rule actually requires
For electronic PHI specifically, HIPAA’s Security Rule requires administrative safeguards, like designated security personnel and workforce training, physical safeguards covering facility and device access, and technical safeguards including access controls, audit controls, and encryption of PHI both at rest and in transit. A vendor claiming HIPAA compliance needs to demonstrate all three categories, not just general good security practice.
Why this matters specifically for training content
Healthcare organizations producing training video, onboarding content, compliance training, clinical process walkthroughs, sometimes reasonably want to use real patient scenarios for realism and relevance. This is exactly the point where HIPAA becomes directly relevant: real, identifiable patient information used in training content is PHI, regardless of the content’s educational purpose, and using it requires the same safeguards as any other clinical use of that information.
Who inside a healthcare organization should own this decision
Because this question sits at the intersection of content production and legal compliance, it’s worth explicitly deciding who owns it rather than leaving it to whichever content creator happens to be building a given piece of training material. In most healthcare organizations, this involves a compliance or privacy officer, not just the L&D or Knowledge Management team producing the content, and building a simple review step, confirming no real PHI is included before any healthcare-related training video gets finalized, into the standard production workflow avoids leaving this judgment call to an individual creator working under a deadline.
The safer default: de-identified or hypothetical content
For most training use cases, the practical and considerably lower-risk approach is building content around de-identified scenarios or entirely hypothetical patient examples rather than real patient data. This sidesteps HIPAA’s requirements for the content itself, since properly de-identified information, stripped of the specific identifiers HIPAA defines, no longer constitutes PHI, while still allowing training content to feel realistic and relevant to actual clinical situations.
Why de-identification needs to be done carefully, not casually
HIPAA defines de-identification specifically, either through a formal expert determination or by removing eighteen defined categories of identifiers, names, dates directly tied to an individual, geographic details more specific than state level, and others. Simply removing a patient’s name from a scenario while leaving in enough other detail, an uncommon diagnosis combined with a specific date and location, for instance, can still leave the information identifiable in practice, even without a name attached. Teams building “de-identified” training scenarios should apply this standard rigorously rather than assuming a quick edit is sufficient, since a scenario that’s still practically identifiable doesn’t actually get the legal benefit of de-identification.
What to verify before using any vendor with real PHI
Does the vendor offer a Business Associate Agreement at all? Not every SaaS vendor does, and without one, a covered entity legally cannot use that vendor to process real PHI, regardless of how strong the vendor’s general security posture otherwise looks.
What specifically does the BAA cover? Review the actual document rather than accepting a general assurance, confirming it addresses the specific ways your organization intends to use the platform.
Does the vendor’s infrastructure meet the Security Rule’s technical safeguards? Confirm encryption, access control, and audit logging specifically, rather than assuming general enterprise security certifications automatically satisfy HIPAA’s more specific technical requirements.
Velo’s current position on HIPAA
Velo currently maintains SOC 2 and ISO 27001 compliance along with a GDPR-aligned Data Protection Addendum, but does not currently offer a Business Associate Agreement or HIPAA-specific certification. Healthcare organizations should not use Velo, or any platform without a signed BAA in place, to process content containing real, identifiable protected health information, and should instead build training and other content around de-identified or hypothetical scenarios, or confirm current HIPAA readiness directly with the vendor before proceeding with real patient data.
Why this is worth getting right rather than assuming it’s fine
The consequences of mishandling PHI aren’t limited to a vague compliance risk, HIPAA violations carry real regulatory penalties, and a healthcare organization’s own patients and staff are the ones directly affected if protected information ends up somewhere it shouldn’t. This is a meaningfully different risk category than most of the enterprise governance concerns covered elsewhere, brand consistency, access controls, viewer tracking, since the downside here involves both legal exposure and genuine harm to real individuals, not just an internal process inefficiency. That difference is why HIPAA specifically deserves a more cautious, more deliberate default than most other platform evaluation questions.
When in doubt, de-identify or ask directly
If there’s any question about whether specific content constitutes PHI, the safer path is de-identifying it or building a hypothetical equivalent rather than assuming it’s fine. For any use case that genuinely requires real patient information, confirm BAA availability and HIPAA-specific safeguards directly and in writing before that information touches any platform.
Try Velo for free · See how it works
Related reading
- HIPAA-compliant AI video tools: what healthcare teams should actually check
- Video data that cannot say where it lives or who can access it: what GDPR requires
- A security review a video tool cannot pass: what ISO 27001 changes
- Governance checklist for Knowledge and L&D teams rolling out AI video
About the author
Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn