Regulatory / HIPAA

Meridian and HIPAA AI oversight — inventory for Security Rule risk analysis

Meridian gives compliance teams the documented AI-system inventory and vendor view that feed Security Rule risk analysis — with a metering workflow designed not to require PHI.

What it expects

As of August 2026

  • When an AI system creates, receives, maintains, or transmits ePHI, evaluate it within the covered entity's or business associate's Security Rule risk-analysis and security-management process
  • Audit controls and activity review remain relevant concepts for systems that touch ePHI
  • Business-associate oversight applies to vendors that create, receive, maintain, or transmit ePHI on your behalf

There is no freestanding “HIPAA AI regime” separate from the Security Rule and related obligations; applicability depends on role and whether ePHI is in scope.

How Meridian supports it

ExpectationMeridian capabilityEvidence artifact
Documented AI estate as input to risk analysisAI systems and AI-related vendors detected in connected billing and usage sources, with owners and departmentsAgent estate report; ledger export
Operational records supporting inventory and vendor reviewSpend and usage metering designed not to require PHI (billing and usage-metadata-only configuration)Audit Evidence Export; Board Pack
Vendor AI oversight viewPer-vendor spend, usage, and drift across AI providersVendor detail; QBR report

Why billing-derived records hold up

A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use.

See it in your environment

Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).

FAQ

Do you need a BAA?
Depends on your configuration and whether PHI ever enters Meridian. Contact sales for the current BAA posture for your deployment.
Will OCR treat Meridian as a substitute for our Security Rule process?
No tool does. Meridian produces inventory and operational records that support your risk analysis and security-management process — they do not replace it.
Can we run this without clinical systems access?
Yes — Meridian connects to billing and usage sources. The metering workflow is designed not to require PHI.