Manage HIPAA, EU AI Act, and Medical Device Regulation obligations for your AI systems. Generate required documentation, track risks, and keep your compliance team ahead of audits.
€15M / 3%
max EU AI Act fine, high-risk non-compliance
High-risk
EU AI Act classification for most clinical AI
72 hrs
GDPR breach notification window
30 days
DSAR response deadline
Healthcare AI sits at the intersection of three regulatory regimes: HIPAA (US), the EU AI Act (risk-tiered from limited to high), and the Medical Device Regulation (MDR/IVDR). Failure to comply can mean fines up to €35M or 7% of global turnover (prohibited AI) / €15M or 3% (high-risk non-compliance), loss of CE marking, or OCR investigation.
EU AI Act high-risk classification
Clinical decision-support and diagnostic AI are classified as high-risk via Article 6(1) + Annex I (the product-safety/MDR route), not Annex III. Conformity assessments — folded into the existing MDR notified-body procedure under Article 43(3) — are required before deployment.
PHI in AI training data
Using patient data to train AI models requires explicit consent or a valid research exception under both HIPAA and GDPR Article 9. Most organisations lack documented evidence.
GDPR special category data
Health data is Article 9 special category data. Processing requires a legal basis beyond legitimate interest. Automated profiling is heavily restricted.
AI transparency to patients
EU AI Act Article 50 requires patients to be notified when AI is making or supporting material clinical recommendations about them.
MDR/IVDR AI classification
AI used for diagnosis or prognosis may be regulated as a medical device under MDR. Software classification rules are complex and often misapplied.
Sub-processor chain
Cloud AI vendors are data processors. GDPR Article 28 DPAs are required for each. Many healthcare orgs lack up-to-date sub-processor agreements.
AI system risk register
Catalogue every AI tool your organisation uses, auto-classify by EU AI Act risk tier, and generate required technical documentation.
DPIA & FRIA templates
Pre-built Data Protection Impact Assessment and Fundamental Rights Impact Assessment templates for healthcare AI, ready to fill and e-sign.
DPA builder for AI vendors
Generate GDPR Article 28-compliant Data Processing Agreements for every AI vendor, including sub-processor flow-down clauses.
GDPR consent management
Track consent records for AI-enabled health data processing, with audit trail and automatic expiry reminders.
Breach response workflow
Guided 72-hour GDPR breach notification workflow, pre-filled templates for ICO/DPA notification, and patient communication letters.
Employee AI policy & training
Generate and bulk-send an AI use policy to all clinical staff, with e-signature acknowledgment and completion tracking.
Is AI used for clinical decisions always high-risk under the EU AI Act?
Not always. General-purpose AI tools used by clinicians for research or communication may be limited-risk. However, any AI that outputs a recommendation influencing clinical decisions about specific patients is likely classified as high-risk via Article 6(1) + Annex I (the product-safety/MDR route that covers regulated medical devices), requiring a conformity assessment. Annex III's narrower "essential services" category can separately apply to some non-diagnostic healthcare use cases, such as emergency triage dispatch.
Do we need a DPIA for every AI tool we use?
A DPIA is required when processing is likely to result in high risk to individuals — which is the case for most clinical AI (health data, automated decision-making, large-scale processing). Article 35 lists circumstances requiring a DPIA; most healthcare AI systems will meet at least one.
How does Aegis Firma help with HIPAA?
Aegis Firma helps document your AI vendor relationships (BAA tracking), manage access controls, and maintain the audit logs and policies required under the HIPAA Security Rule. We do not replace your HIPAA Privacy Officer but give them the tools to stay compliant.
Can I use Aegis Firma to send the AI use policy to all clinical staff?
Yes. The Employee AI Policy template can be bulk-sent to your entire workforce via the Contracts module. Each recipient receives a personalised signing link; completion is tracked in real time with a cryptographic audit trail.
Cancel anytime · 7-day refund eligibility · no contracts