Regulatory / HIPAA
Meridian and HIPAA AI oversight — inventory for Security Rule risk analysis
Meridian gives compliance teams the documented AI-system inventory and vendor view that feed Security Rule risk analysis — with a metering workflow designed not to require PHI.
What it expects
As of August 2026
- •When an AI system creates, receives, maintains, or transmits ePHI, evaluate it within the covered entity's or business associate's Security Rule risk-analysis and security-management process
- •Audit controls and activity review remain relevant concepts for systems that touch ePHI
- •Business-associate oversight applies to vendors that create, receive, maintain, or transmit ePHI on your behalf
There is no freestanding “HIPAA AI regime” separate from the Security Rule and related obligations; applicability depends on role and whether ePHI is in scope.
How Meridian supports it
| Expectation | Meridian capability | Evidence artifact |
|---|---|---|
| Documented AI estate as input to risk analysis | AI systems and AI-related vendors detected in connected billing and usage sources, with owners and departments | Agent estate report; ledger export |
| Operational records supporting inventory and vendor review | Spend and usage metering designed not to require PHI (billing and usage-metadata-only configuration) | Audit Evidence Export; Board Pack |
| Vendor AI oversight view | Per-vendor spend, usage, and drift across AI providers | Vendor detail; QBR report |
Why billing-derived records hold up
A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use.
See it in your environment
Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).
FAQ
- Do you need a BAA?
- Depends on your configuration and whether PHI ever enters Meridian. Contact sales for the current BAA posture for your deployment.
- Will OCR treat Meridian as a substitute for our Security Rule process?
- No tool does. Meridian produces inventory and operational records that support your risk analysis and security-management process — they do not replace it.
- Can we run this without clinical systems access?
- Yes — Meridian connects to billing and usage sources. The metering workflow is designed not to require PHI.