Skip to content

HIPAA vs ISO 42001

By Sam Rivera, Founder, SentinelPanda · August 6, 2026 · 3 min read · HIPAA

HIPAA regulates the data a clinical model is trained on. It has essentially nothing to say about whether the model is any good, or fair, or safe to rely on.

Two regimes over one system

A clinical decision-support model trained on patient records sits squarely in both worlds, but they touch different parts of it. HIPAA governs the ePHI: how it was obtained, whether the use is permitted, how it is secured, who it may be disclosed to, and what happens if it leaks. Training data is PHI, inference inputs are PHI, and a vendor processing it for a covered entity is a business associate needing a BAA.

ISO 42001 governs the model: how it was developed, validated, monitored, and overseen; what impact it may have on the people it is used on; and who is accountable for that. HIPAA does not ask those questions at all.

What HIPAA does not cover

This is worth stating plainly because it surprises people. You can be fully HIPAA compliant while deploying a model that performs materially worse for one demographic group, that clinicians cannot interrogate, that has drifted badly since validation, and that nobody is monitoring. None of that is a HIPAA Security Rule concern — the Security Rule protects the data, not the decision.

The de-identification provisions add a wrinkle worth knowing. Data de-identified under Safe Harbor or Expert Determination falls outside HIPAA, which is a common route for building training sets. But de-identified data still carries the bias of its source population, and a model trained on it can still cause harm — moving outside HIPAA's scope removes the legal constraint without removing the risk. That gap is precisely ISO 42001's subject.

Where ISO 42001 helps commercially

  • Health systems buying clinical AI increasingly ask governance questions no HIPAA artefact answers.
  • HIPAA offers no certificate; ISO 42001 does, and a certificate travels through procurement in a way a self-assessment does not.
  • AI impact assessment maps naturally onto clinical safety review processes hospitals already run.
  • For vendors selling into both US and EU healthcare, ISO 42001 also positions you for EU AI Act obligations, where many clinical AI systems are high-risk.

Running both

Keep the boundary clear rather than merging them into one "AI compliance" workstream. HIPAA obligations attach to the data: BAAs with every party touching ePHI, minimum necessary applied to training data access, security risk analysis covering the AI infrastructure, breach procedures if a model or its training set is exposed.

ISO 42001 obligations attach to the system: documented impact assessment, validation evidence, monitoring for drift and performance disparity, defined human oversight, and a retirement path when the model stops being fit for use.

The shared substrate — access control, encryption, logging, vendor management — should be built once and evidenced to both. Duplicating it is how teams end up with two sets of records describing the same access review.

ISO 42001 impact assessment HIPAA de-identification HIPAA vs ISO 27001

Run your compliance program in one workspace.