Skip to main content
Taylor Crossley

Taylor Crossley

Healthcare regulatory attorney and associate at Husch Blackwell LLP in Kansas City, focused on HIPAA privacy, behavioral health compliance, and hospice and palliative care.

Oct 7, 2026

1:41
Um, so, uh, what, what's your guidance regarding how providers should deal with AI in the vendor context?
1:49
Yeah.
1:50
Absolutely.
1:51
So vendor contracts, that's a big area to be considering.
1:54
Um, hospice organizations know, you know, that they need a business associate agreement, a BAA, with vendors who handle protected health information.
2:04
Um, however, many organizations' existing BAAs are not written with AI in mind, and oftentimes, standard vendor contracts, um, you know, talking about the underlying services agreement here, are also rare-rarely AI ven- uh, AI ready, um, and that gap creates some real exposure.
2:24
So there's four main areas that I recommend clients, um, pay attention to, um, kinda risk areas to look out for whenever you are engaging with or considering engaging with a new vendor or maybe you're looking at their contract and getting geared up to start working with them.

13 MINS LATER

15:55
Uh, do hospice patients have a right to know when AI is being used in some way in, in the context of the care they're receiving?
9:55
Well, and, and what about the compliance side? Is, is AI, uh, a, a tool that, uh, you're not, not providing real-time documentation assistance, but what about the compliance folks out there? Are they using AI?
10:10
Yeah.
10:10
We're starting to see compliance folks use AI, um, whenever they're going through documentation, maybe in an audit, um, or maybe they're just not even in an audit yet, um, but they're about to submit records for a claim for a patient.
10:26
Um, and compliance can use these tools to maybe run their records through, run a physician narrative through an AI software tool to see, are these physician narratives sufficient? Do they meet the requirements under the regulations? Um, do our plans of care have everything that they require per the regulations? Um, so this might be an area where compliance can use AI as a pre-billing review or a pre-billing audit, um, to kind of preview where there are maybe some, um, places for improvement or maybe where they can educate their providers, um, and their staff on the requirements for documentation for submitting claims.
11:09
Another area, um, that we're really seeing is, um, family communication.
11:14
So once we get through that kind of, um, you know, clinical use, you know, we're using it for billing, there's also the patient side of using AI.
11:23
Um, so maybe you're using AI to communicate with family.
15:30
So when it, when it comes to kind of building this government, governance structure, uh, what should the, the leadership of a provider, the fo- the folks who would construct that framework, what should be they be thinking about? What needs to be put in place?
9:52
Please continue.
9:52
Yeah, absolutely.
9:53
That's a great point of clarification there.
9:56
So once you've determined that you are a covered entity, you've got that default rule that I can't disclose protected health information without patient authorization.
10:05
Then you start looking at the exceptions under HIPAA to certain times where you can release information without patient authorization.
10:13
And one of those exceptions is legal process.
10:17
And I say one of those exceptions is There are a bunch of kind of sub exceptions under this legal process exception.

12 MINS LATER

22:13
What do you do to take into account whatever state law may exist in this situation?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.