HIPAA & Health-AI

Patient data and AI. Assessed together.

Healthcare is deploying AI faster than it can govern it. Providers, digital-health vendors and their investors need to know a product can be trusted with patient data before it ships, before a deal closes, and before a regulator or a class action asks. Sentinel gives you that answer, independently.

What we assess

Scope, done right first

Which rules actually apply: HIPAA, the FTC Health Breach Notification Rule, or state health-privacy law. Not every “health app” is a “HIPAA app,” and getting this wrong is expensive.

The HIPAA core

Privacy and permitted use, the Security Rule safeguards, a defensible risk analysis, your Business Associate Agreement chain, and breach readiness.

The AI layer most reviewers miss

Where patient data enters your models, whether your AI vendor’s agreement actually covers it, de-identification, prompt and log retention, minimum-necessary retrieval, and human oversight of AI output.

Your website

Tracking pixels, analytics, chat and session replay that can quietly leak health-related activity, assessed against today’s legal reality, not last year’s headlines.

Generic HIPAA assessors and generic AI-governance tools each cover half the picture. The risk lives in the seam between them, and that seam is what we specialize in. Every finding is graded by strength of evidence and the verdict is one of three words: Cleared, Conditional, or Held.

Engagement tiers

EngagementBest forInvestment
HIPAA + AI Readiness Self-CheckA ten-minute self-assessment to see where you stand. Ask for it on the triage call.Free
Readiness SnapshotA fast, independent read on a single app, AI feature or site.from $5,000
Website Tracking-Tech ReviewFocused review of trackers and consent on a healthcare site.from $5,000
Gap Assessment + Security Rule Risk AnalysisThe defensible, documented assessment. AI-heavy engagements sit at the top of the range.$15,000–$25,000
AI Deployment Gate, HIPAA overlayA go / no-go decision on one clinical or patient-facing AI system, scored with the health-privacy controls inside the Gate.from $4,000
Lifecycle Gate retainerRe-gates as your product and its AI keep changing. Assessment only.from $3,000/mo

Indicative 2026 ranges, scoped to each engagement. Senior advisory available as a fixed-fee half day at $2,500. We do not offer hands-on remediation: we tell you what to fix and in what order, your team or your builder fixes it, and we re-assess.

What you get

A clear verdict

Cleared, Conditional or Held, with every finding graded by strength of evidence.

A risk analysis you can hand over

A Security Rule risk analysis and risk register for a partner, buyer or board.

A sequenced roadmap

Gaps and remediation priorities mapped to the specific rules, not to what is easiest to sell.

The vendor chain, reviewed

Your Business Associate Agreements and AI-vendor terms, read against where the data actually flows.

Why Sentinel for healthcare

Our leadership operates healthcare businesses that handle patient data every day, so we know these obligations from the inside, not just from the standard. We assess and attest; we do not sell the software we review, and our name goes on the report. Assurance and readiness, not legal advice: Sentinel does not issue HIPAA certifications, and formal legal determinations require your counsel.

Find out where you stand.
Free, 30 minutes, no deck.

The AI Risk Exposure call: we walk your AI footprint, flag your likely obligations, and tell you plainly whether and where you need help.

Book the call →