AIAI Governance StackFree kit

HIPAA

Regulation

What HIPAA requires

HIPAA governs protected health information in the United States, and its Privacy and Security Rules constrain how AI systems in healthcare may access, process and disclose patient data. AI-specific pressure points include using PHI for model training, ensuring de-identification actually holds against re-identification attacks, vendor business associate agreements covering model providers, and audit logging sufficient to reconstruct who saw what. Tooling here tends to emphasise data-layer controls and access governance rather than model documentation.

Who it applies to

Covered entities and business associates deploying AI that touches protected health information.

17 tools that map to HIPAA

Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.

Policy, Compliance & GRC (8)

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

NIST AI RMFISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified

NIST AI RMFISO/IEC 42001GDPR

Security compliance automation vendor with ISO 42001 and real-time AI agent governance

ISO/IEC 42001EU AI ActSOC 2

Observability & Monitoring (7)

AI observability and evaluation platform for ML models, LLM apps, and agents

SOC 2HIPAAGDPROpen-source

AI performance, evaluation, and governance platform for ML, generative, and agentic systems

NIST AI RMFEU AI ActSOC 2Open-source

Enterprise AI observability, security, and governance control plane for models and agents

EU AI ActNIST AI RMFGDPR

AI quality, testing, and monitoring platform for evaluating and safeguarding models in production

ISO/IEC 42001GDPRHIPAAOpen-source

AI control platform combining ML observability with real-time guardrails for GenAI

SOC 2GDPRHIPAA

AI model testing roots now applied to document workflow automation for regulated industries

SOC 2HIPAA

Open-source-led testing, evaluation and monitoring for ML models and LLM applications

SOC 2GDPRHIPAAOpen-source

Enterprise Incumbents (2)

AI developer platform for experiment tracking, model management, and LLM observability

SOC 2HIPAA

Enterprise MLOps and governance platform for building and running AI in regulated industries

EU AI ActGDPRSOC 2

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.